nanog mailing list archives
Re: Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN???s Directory Services)
From: Nick Hilliard via NANOG <nanog () lists nanog org>
Date: Tue, 1 Sep 2026 16:57:37 +0100
borg--- via NANOG wrote on 01/09/2026 08:39:
Uh, first off all. Its not a service that needs constant babysitting. You set up it once and forget, probably forever. Second, its not 80s or 90s, compute is cheap.. very cheap. Are you saying that running such proxy is such a problem? I doubt it...
if it's a daemon running on the home server in your basement, you set it up once, then forget about it.
If it's a service run by an organisation like ARIN, you cost it, code it and run it as a formally supported service. You then monitor it and restart it when it falls over. You fix the occasional bug, keep the code up to date, and you need to take it into account when the underlying data store changes in any way. That includes looking at any part of the information stack sideways, because the more ancient the code base, the more fragile it is. You then test it to make sure nothing breaks. You train people up on the lifecycle of the product and write documentation, both internal and external. You throw the codebase into CI, you run security audits on the code, and then you answer the security auditor's queries about it. Despite all that, it's still got some weird stuff going on inside it, and there's probably only a single person in the organisation who knows how it all works. Handling it consumes time at meetings, it consumes technical time and because it's public facing, everyone across the organisation - from the board to the helpdesk - needs to have some awareness of it. Then you multiply all that by something approximating 4 to handle the 4 different directory protocols which are exposed by ARIN, and it turns out that the costs to do this are not just non-zero, they're actually substantial.
The costs here are the direct costs of the technical debt incurred in supporting legacy products and systems. These costs can't be magicked away by declaring all this to be silly, or by claiming that whois doesn't need much compute, or by stating that this is all unnecessary overhead and it would be much simpler to put in a small proxy (just a little one) to do the job instead.
People running a service in their basement have the privilege of ignoring all this because if the service falls over, it doesn't matter. If you're an ARIN, proper support of externally facing protocols really does matter.
Nick _______________________________________________NANOG mailing list https://lists.nanog.org/archives/list/nanog () lists nanog org/message/XPRIZWJFK5FJZMR74GZOP33GHUHXIWUP/
Current thread:
- Re: Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN???s Directory Services) borg--- via NANOG (Sep 01)
- Message not available
- RE: Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN???s Directory Services) Adam Maloney via NANOG (Sep 01)
- Re: Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN???s Directory Services) William Herrin via NANOG (Sep 01)
- RE: Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN???s Directory Services) Adam Maloney via NANOG (Sep 01)
- RE: Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN???s Directory Services) Adam Maloney via NANOG (Sep 01)
- Message not available
- Re: Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN???s Directory Services) Nick Hilliard via NANOG (Sep 01)
