nanog mailing list archives

Re: [ARIN-consult] Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN’s Directory Services)


From: Tom Beecher via NANOG <nanog () lists nanog org>
Date: Tue, 1 Sep 2026 13:09:26 -0400


Folks using whois in a manner which
is meaningfully at risk from in-flight data manipulation are free to
follow that upgrade path.


There is no way to use WHOIS that is NOT at risk of in-flight manipulation.

That's the point.

On Tue, Sep 1, 2026 at 10:30 AM William Herrin via NANOG <
nanog () lists nanog org> wrote:

On Tue, Sep 1, 2026 at 4:09 AM Job Snijders via NANOG
<nanog () lists nanog org> wrote:
The threat is in the use of the protocol. Port 43 Whois query/response
transactions are susceptible to man-in-the-middle attacks due to the
unauthenticated and unencrypted nature of the WHOIS protocol.

Hi Job,

That threat you're talking about is to organizations which are not
ARIN. It is no more ARIN's place to tell those folks how to secure
their systems than it is ARIN's place to tell them how to run their
networks. ARIN has provided RDAP. Folks using whois in a manner which
is meaningfully at risk from in-flight data manipulation are free to
follow that upgrade path.

The greatest sin of IPv6 was failing to implement backward
compatibility. Have we learned nothing from that _expense_?

Regards,
Bill Herrin


--
For hire. https://bill.herrin.us/resume/
_______________________________________________
NANOG mailing list

https://lists.nanog.org/archives/list/nanog () lists nanog org/message/NWNHTIHMMYFK5I25JJKPUIFLTZKNNQDX/
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/LYJC2FPDEPI5PHJOP7BR4EGSNUTPJ3WG/

Current thread: