nanog mailing list archives

Re: [ARIN-consult] Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN’s Directory Services)


From: Job Snijders via NANOG <nanog () lists nanog org>
Date: Tue, 1 Sep 2026 11:09:44 +0000

On Sat, Aug 15, 2026 at 09:59:54AM -0400, Patrick Klos wrote:
Don't tell me that the text based WHOIS service creates a greater
"threat landscape" or "attack vector". Text based WHOIS has been
around for decades - by now, I'm sure it's quite hardened!

On Sun, Aug 16, 2026 at 12:59:31AM +0100, Lavender-Jamie via ARIN-consult wrote:
What excessive attack surface is there to operating whois? Yes, it is
an additional service, but whois, in some form, has been around since
forever and I am most certain that after so many years, there are well
hardened whois servers available.

The threat is in the use of the protocol. Port 43 Whois query/response
transactions are susceptible to man-in-the-middle attacks due to the
unauthenticated and unencrypted nature of the WHOIS protocol.

"Hardening" the Whois server does nothing to mitigate the risk of data
interception or undetected tampering: there is no transport security in
port 43 Whois. WHOIS-based services simply lack mechanisms for integrity
and confidentiality.

The above means that entities using port 43 are at significant risk if
they are making any kind of business decisions based on the WHOIS data
retrieved via an insecure channel.

Kind regards,

Job

ps. ARIN discontinued unsafe protocols before https://www.arin.net/announcements/20250204/
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/7APKQ2PO26UHB3A6ILBO6RP6N627HZJG/


Current thread: