nanog mailing list archives

Re: Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN???s Directory Services)


From: William Herrin via NANOG <nanog () lists nanog org>
Date: Tue, 1 Sep 2026 07:20:11 -0700

On Tue, Sep 1, 2026 at 4:05 AM Adam Maloney via NANOG
<nanog () lists nanog org> wrote:
Would it not need security updates?  Testing the updates before (so maybe a separate test environment), and testing 
after?

However infrequent, someone needs to be paid to do those things. Which costs money.

Hi Adam,

Any plausible WHOIS retirement schedule has a period of time in which
results are produced for both WHOIS and RDAP, right? ARIN proposed
about 3 years IIRC.

So during that 3-year period ARIN is doing one of two things: 1)
They're exporting RDAP data into WHOIS and maintaining the WHOIS
software. 2) They're implementing a user interface skin around RDAP to
provide WHOIS results.

Which is more expensive? A full whois infrastructure is complicated
enough and a UI skin around RDAP is trivial enough that as a computer
scientist with decades of experience I estimate that it'd be cheaper
to make a skin and retire the whois backend as soon as possible.

Suppose ARIN takes that very reasonable course of action. What's the
state of things when the prospective retirement date arrives?

Well, there's a complete UI skin providing WHOIS services. There's a
suite of regression tests to confirm that the skin still works
properly as improvements are made to the RDAP backend. All known
security issues have been addressed. What's the remaining maintenance
cost?

* If a regression test fails, it has to be investigated and fixed.
Given the trivial nature of the skin, the probability is that the
error was introduced to the RDAP backend, thus the cost is not
attributable to the WHOIS UI.

* If a security vulnerability is reported or discovered by a new
analysis tool, it has to be corrected. These will tend to be small
things. Buffer size errors. Uninitialized variables. Full cost
attributable to the WHOIS skin but not a high cost.

* If DOS mitigations are made to the RDAP front-end, they'll likely
have to be imported into the WHOIS front end. This is probably the
highest of these three costs but the attributable part is still an
integration task not a from-scratch development task.

And that's about it.

In exchange for ARIN undertaking these costs indefinitely, nobody else
has to deal with a forklift upgrade from WHOIS to RDAP. Hundreds,
thousands, maybe tens of thousands of organizations migrate to RDAP as
convenient with legacy tooling that keeps on keeping on.

So, suppose instead of retiring WHOIS after a sunset period, ARIN
demotes it to a second class service. Best efforts. Repaired during
business hours. You now have a minimal cost to a single organization
to keep it working for everybody indefinitely. Is that not an
objectively better outcome?

Regards,
Bill Herrin

-- 
For hire. https://bill.herrin.us/resume/
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/NHBF6ET2INXQ3I6C5ZZ2PEAET7Y32C25/

Current thread: