nanog mailing list archives

Re: [ARIN-consult] Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN’s Directory Services)


From: William Herrin via NANOG <nanog () lists nanog org>
Date: Tue, 1 Sep 2026 07:29:17 -0700

On Tue, Sep 1, 2026 at 4:09 AM Job Snijders via NANOG
<nanog () lists nanog org> wrote:
The threat is in the use of the protocol. Port 43 Whois query/response
transactions are susceptible to man-in-the-middle attacks due to the
unauthenticated and unencrypted nature of the WHOIS protocol.

Hi Job,

That threat you're talking about is to organizations which are not
ARIN. It is no more ARIN's place to tell those folks how to secure
their systems than it is ARIN's place to tell them how to run their
networks. ARIN has provided RDAP. Folks using whois in a manner which
is meaningfully at risk from in-flight data manipulation are free to
follow that upgrade path.

The greatest sin of IPv6 was failing to implement backward
compatibility. Have we learned nothing from that _expense_?

Regards,
Bill Herrin


-- 
For hire. https://bill.herrin.us/resume/
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/NWNHTIHMMYFK5I25JJKPUIFLTZKNNQDX/

Current thread: