Alban Kwan 0:00 We don't want to see ourselves as policing the Internet. That's certainly not something that either the domain name or the IP address community would like to but the matter of fact is that we are the custodian of a important Internet resources, and we are indeed a policy makers for those resources that we're responsible for managing as well. So if abuse happened, we need to find a way to deal with it as we are the custodian. Now the problem then is, what would be the limit of that custodianship? And to one extreme is that, you know, we are only, you know, custodian, and we're not responsible for it. To the other extreme, it would be most likely, most of the government would be towards the other extreme, that they think that we are basically responsible for dealing with all the things. So we need to find the right balance. George Michaelson 1:01 You're listening to ping, a podcast by APNIC, discussing all things related to measuring the Internet. I'm your host. George Michaelson, this time on ping, I'm talking to Alban Kwan from TNN, the trusted notifier network. Alban is a co founder of TNN, formed after a long career in brand services and domain name abuse mitigation with CSC in Australia and Hong Kong and with Melbourne IT. I met Alban after the apricot meeting in Jakarta, where he had been attending Policy and Governance discussions with an interest in the online abuse problem. Alban is interested in bridging the gap between the business and technical communities when it comes to a response, business tends to focus on brand integrity and the real world cost of mitigation when their products and services are abused, used for spam or fraud or suffer inbound attacks against them, the technical community tends to be focused on things like network traffic level views of problems. They're found in deep packet inspection, running honey nets, looking at firewall logs and in turn, drive security activities in network technology. In the context of these packet level distributed threats on previous episodes of ping. We've talked with Adli Wahid from APNIC and with Leslie Daigle from global cyber Alliance. Both times we discussed honey nets, Leslie has raised her concern that we're going to need a conversation in civil society about the governance issues to address this problem space. Technology alone can't solve what's clearly a societal problem. TNN is part of that civil society response to online abuse, albeit in a slightly different form, and Alban has an interesting analytical model of how to think about the problem. I think it's interesting to look at his engagement with business process and how people build mutuality and trust dealing with abuse problems of any kind. Alban, welcome to ping. Alban Kwan 3:09 Thank you, George. Thank you for inviting me. George Michaelson 3:11 Could you just give people a little bit of an insight into who you are and what you do? Alban Kwan 3:18 Yeah, of course. So my name is Alban Kwan. So my background is that I've been always working in the commercial side, starting in the kind of the Internet industry, domain industry, about 18 years ago, and in helping the previous two business employer, Melbourne IT and CSC, respectively, to grow the Asia-Pac market, working directly with large brand owners and helping them with the detection advisory on how they deal with a lot of the problems on the Internet and stuff like that. So that's really my background. You know, I live in Australia. I'm Australian, but I was born in Hong Kong. A lot of the customer I have actually around the whole APAC region. George Michaelson 4:03 So we met at apricot and had a wonderful conversation on the flight back where you explained to me that you've recently co founded a group called the trusted notifier network, or TNN. That's right? Alban Kwan 4:20 that's correct. George Michaelson 4:20 On ping. We've previously had recordings with Adli Wahid, who runs APNIC Honeynet project and has been very active in the Asia Pacific footprint, looking at all kinds of online abuse and bad traffic. And also we've spoken with Leslie Daigle from global cyber Alliance, who also runs a Honeynet project, and Leslie in particular, brought to the surface this thing that the classic technological attempts to deal with problems online abuse online essentially, in some sense, they failed. They've reached the limits of what they can do. And she made an observation that we're actually going to have to construct more socialized frameworks for business and civil society and government to come and talk about this problem. And I believe that TNN is kind of in this space. You've actually taken some steps into this space? Alban Kwan 5:22 Yeah, I think so. You know, the TNN or Trusted Notifier Network is an idea that I had a couple of years ago. And the reason why we want to do this is because we see exactly the same problem, you know, when we try to, you know, finding the abuse is one thing, and forcing and solving the problem is another thing, and I think that's, you know, efforts needs to be put into both. And in the middle, there's also the policy side on as well, because if you don't know exactly what these appeals, you know, what's the limit of our enforcement and stuff like that, you can't really be effective. So TNN is really trying for us to really build something like this, not merely from a technological perspective, but also, how do we cooperate together, and how do we actually come up with some, some kind of, you know, Alliance, so to speak, that actually make everyone job easier basically, George Michaelson 6:18 Your years working in the domain name space, you'd be familiar with the ideas that lie behind registrar registry processes. And for people who don't routinely work with domain names, they may not understand that outside of the DNS there's a whole process around registration of people and entities to be the guardians, the stewards, the delegates of a name. And at first glance, you would think those processes provide a primary mechanism for people to understand who to deal with in connection with abuse relating to a name. But the process is in some ways, it's weak, isn't it? Alban Kwan 7:02 Alban, it's getting better. The problem for domain name enforcement is pretty similar to IP address, if we talk about APNIC community as well. Because we are not regulator in a traditional sense, but we are a George Michaelson 7:19 we're not the police Alban Kwan 7:20 Exactly. We don't want to see ourselves as policing the Internet. That's certainly not something that either the domain name or the IP address community would like to do. But the matter of fact is that we are the custodian of a important Internet resources, and we are indeed policy makers for those resources that we're responsible for managing as well. So if abuse happened, we need to find a way to deal with it as we are the custodian. Now the problem then is, what would be the limit of that custodianship? And to one extreme is that you know, we are only you know custodian, and we're not responsible for it. To the other extreme, it would be most likely, most of the government would be towards the other extreme, that they think that we are basically responsible for dealing with all the things. So we need to find the right balance. George Michaelson 8:12 Yeah. So there's a quite common belief, I think, on the part of government, legal structure, laws, enacted, national boundaries that if you step forward and register intent to hold a name as an asset or Internet addresses as an asset, you are in some sense, taking responsibility for the behaviors of that name and those Internet addresses. So their sense of custodianship kind of hits the road when you signed an agreement, you made an agreement to be the custodian, and they see their role as saying we have enforceable powers, but you're saying as a community, we have a slightly softer view. We know that we're potentially offering service to other people, to our customers, our clients, third parties, and so we're not looking to take all the responsibility for all the things they do, but it's a kind of shifting space, isn't it? You need a mechanism to allow anyone to stand up and say, I feel I'm under attack. I'm being abused, and you appear to be a custodian in due sense, over these resources. Help me. Alban Kwan 9:19 Yeah, and the problem also become even harder to distinguish, because when we only talk about technical abuse, like a DDoS attack, is kind of easily identifiable. You know, technically, you can see all these different DDoS coming out from these IP addresses or domain name as well. But in a wider society, the resources that we're custodian of are also being used for other types of abuse that are harder to distinguish. For example, scam. Now, scam necessitates some kind of content because, you know, there's no such thing as a purely technical scam. It needs to have some kind of social engineering behind this. [George: Yeah]. Now you. Talking especially about this kind of abuses to enforce it. It's also like upon us, the domain name industry and the IP address industry to actually stop the resolution of those services who are being used for the scam. Now this bury the line a little bit more as well. So this is to some extent, we as an industry needs to find ourselves. What would be our role, and how do we actually deal with this? George Michaelson 10:26 Well, if you think about the techniques we use in things like honey nets or in Stateful Packet interception, you're not actually going to see packet flows that in any sense tickle the detectors, because this will just look like legitimate web traffic. Alban Kwan 10:41 Yeah, exactly. George Michaelson 10:41 But if you consider a website that's hosting videos, and the videos start to be a feed of maybe AI generated fake Warren Buffett's telling people to invest in this new technology, you know, nothing in the technology space that we do looking at the flows is going to say this is obviously abuse traffic, but people are going to be conned by the scammers into making investments unwisely, and this is social engineering and a social problem. But we now have effectively, four parties. We've got organizations like yours, the trusted notify network. We've got the affected clients who did things because they were misled. We've got the people owning the domain name and presumably delegating the website to some server. And we have the advertising feed, [George: yeah]. And so we've maybe got four or more parties in the mix here. Alban Kwan 11:37 yeah, one of the key reasons why we want to establish the TNN is precisely what you just mentioned. There are multiple parties, multiple industry as well, and this industry don't talk to each other so well. ICANN theoretically include both in naming and numbering community. But even if you look into ICANN having these two components, the Naming community, don't really talk. George Michaelson 12:00 They run in two separate ways. They have separate channels of conversation. There's no real bridge between them. Alban Kwan 12:07 Yeah, exactly. And if you add in the social media company who are most likely the distribution network of these scams, they need to be involved as well. Hosting providers typically needs to be involved as well, because in the ICANN kind of regulation, ICANN has explicitly exclude any responsibility regarding content abuse. Now, scam is a content abuse from a policy perspective, it needs to be dealt with by the hosting service provider. Now, hosting service provider doesn't have a community. The closest that we have would be the IP address community, because they need to get the IP address to actually host the resources. They are by default the resource holder George Michaelson 12:53 Sitting out there in different economies, distributed at large, are the consumers who have local consumer councils and have local advocacy agencies, but again, these are very informal groups that don't have a lot of interplay and interchange, do they? Alban Kwan 13:08 So that makes it really hard, because there are so many holders around the world, so many different players, it's almost impossible to get a policy cooperation among everyone. Now that actually created a bigger problem, because let's just presume that you are an LEA a law enforcement agency. Now, if you have a big scam that happened in that particular country that affect a lot of people, so a lot of people lose money. Is in the best interest for everyone to fix that problem now, but this particular host, it hosting outside of that country, in a domain name that is maybe a ccTLD that the LEA have no jurisdiction on, George Michaelson 13:47 And the ccTLD could actually be completely divorced from the economy of host exactly so you have affected people in economy A, using a virtually hosted service in economy B, hosting a domain name registered in the economy, C 3, different legal jurisdictions, Alban Kwan 14:04 yeah, and because of this, holes are typically harder to find because they are numerous smaller holes. So this actually push the LEA and the government going into the higher level of the structure. Domain name is easier to find. Like registrar, you can almost always identify it in the Whois record, and certainly you can identify the registry as well. So we see a trend where the LEA and government are desperate to resolve a lot of these problems, so they're pushing all these problems into the community that should not be really dealing with this if they're hosting service provider, should I just shut down the entire domain name? That domain name could be just a sub domain as well. So, you know, there's a lot of this problem that you know, scammers and fishers can use to make George Michaelson 14:56 innocent third parties potentially suffer damage because of. Of taking action with the only point of reference they have. Yes, this feels like a variation of a problem we see in the finance industry called KYC. Know your customer. And the problem here is that the only people who have done any KYC that anyone trusts are the registrars. And even then, there are some question marks. How much KYC do they do? So this, I think, brings us to these two words from your mission statement, trust and accountability. We've got a problem with identifying who is accountable, and governments and LEA tend to go in the top, and we have a trust problem kind of coming up, floating in the middle. How do we know to trust the people we're talking to? Is that how you kind of capture the problem? Alban Kwan 15:49 Yeah, yeah. And because I work in the commercial side, I work with the service provider who are actually in charge of finding a lot of these issues and helping the brand owners, the bank and the insurance company and stuff like that to solve the problem. So the way that we see it, the problem is actually quite different, because the problem that we just described, the traditional way, how we want to resolve this problem is social responsibility. We try to find, define who is responsible for certain things, and then we try to force them to to be responsible for it. Now the problem about this particular approach is that social responsibility always have a limitation, and that limitation normally would be the cost, because if it costs too much, we can't bear the responsibility any further. I was once told by a particular large registrar that they are only able to process about 7% of all the abuse report that they received. 7% Yeah, that's what I was told, George Michaelson 16:55 wow. It's so costly for registrars to intercede that they have to take a tiny cohort of what they see as high risk, high consequence and deal with that, but the vast majority of abuse complaints, they don't have budget in time, materials, labor to deal with. Alban Kwan 17:13 Yeah. So that's why, when we see this problem from my commercial perspective, I'm really trying to think about this. Otherwise we don't have the resources to properly handle it in the long term. And you know, especially the matter of fact is that abuse, phishing and scams and all this is going to increase in the future as well. So the cost is forever increasing. But if we only focusing on forcing people to deal with this and investing more and more of their profits into dealing with this is not going to be a good situation for the community as well. George Michaelson 17:48 Where does the conversation about the problem take place and where does the conversation about emerging solutions take place? Alban Kwan 17:58 Well, there are a lot of talking at the moment in different areas. So ICANN certainly is a is a platform for such discussion. We have the global south alliance that you mentioned. They are having a lot of discussion. I believe there's also a new organization called Internet infrastructure forum that has kind of started a couple of meetings to get the cloud service provider and hosting provider involved in the whole conversation as well. They're typically not involved. So there are multiple people trying to get this conversation going. I would describe TNN is also one of the platform, but we are more practical in some sense as well, because, you know, the idea of trust and notifier has already exist for, like, you know, more than 10 years. And even in the EU, they have a particular regulation called Digital Services Act. And in that DSA, they have mandated Europe to identify certain providers, who they call trusted flagger. The concept is exactly the same. To resolve this problem, we need to establish a system of trust. But the problem is, we can always talk about, how do we do this? But you know, what we're trying to do is, all right, we have talked about it. Let's try to operationalize this concept of trusted notifier or trusted flagger and get everyone involved. Now that we start doing it, George Michaelson 19:27 if I take those words at face value, to me, it sounds like if I am an end user suffering abuse or a corporate entity suffering abuse, one of the primary problems has been I don't have somewhere to go that is generally useful, except the specific entity that I've identified. And if I say to them, I'm suffering abuse, they have to, in some senses, question, Are you really telling me the truth? Because at some level, some of the spam, fraud, bad behavior is false accusation. Businesses attempting to vilify other businesses, [Alban: yes], and cause them reputational harm. So the trusted notifier Is this a mechanism to establish a channel that when they pop up in a company's face and say, we've had reports of abuse, this is no longer a random engagement. This is an entity with some process and a sense of purpose and is understood in advance, is that where you're going, Alban Kwan 20:26 Yes, and we need a mechanism to monitor the trust level and stuff like that, whether they are abusing the trust. So this is what TNN want to do. But let me take one small step back to explaining the concept a little bit. This is what you describe. Is one of the key concept. We have three key concepts, and what we call a unfair cost transfer and the reversal of commercial best interest is kind of theoretical, but let me explain it to you a little bit. [George: Okay], so what happened at the moment is that the Fisher or the scammer, by the action of creating that scam or phishing attack create a cost that passed to, let you say, like ANZ bank, for example. Now ANZ suffer loss. They have to manage their costs as well. So they typically would be outsourcing this to a service provider, be it a professional online brand protection service provider, law firm or law enforcement, right? They have to pass on that cost, because they just suffer a lot of case George Michaelson 21:25 so the cost might seem at first glance, the amount of money that a scammer successfully took from a client, but it does go beyond that, because they now suffer reputational harm and loss of brand, legal costs, process costs, remediation costs. It's not as straightforward as you now have to return $10,000 you actually incur all these other process costs inside yourself. [Alban: Yes], so you're saying, viewed from a corporate perspective, abuse coming to your door is modeled as a business cost, [Alban: exactly] and that cost has to be managed through people like legal or your own abuse management team or some form of outsource. Alban Kwan 22:10 Yeah, they typically, even for a large organization, they will have to outsource because of the economy of scales and expertise. So when they pass on the cost to various different service provider. The service provider basically act as an accumulator of all these costs, right? Because they work with a number of different customer for one particular service provider, they might be doing 1000s of take downs on behalf of many customer per day. Now this become a tremendous cost for them as well. So they have to manage their costs. Now that is where the problem starts, because when the service provider have to manage 1000s of take down per day, what they do is that they automate take down. They use AI to craft the bills, take down report requests, and they automatically set so that every three hours, they send you one reminders or whatever. Now basically what that does is that they pass on all these costs to the Internet intermediary community that included the registry, registrar and hosting service wide, ISP, cloud service provider and all that. George Michaelson 23:19 So they're now receiving the aggregated outputs of these intermediaries, but they also represent a pretty constant load that they have to engage with or they're suffering reputational harm. [Alban: Yes], so the cost is moving along a pipeline [Alban: exactly] of entities Alban Kwan 23:36 the community, then, because we are the custodian, right, we have to be the one who make the decision of whether we take action according to this report that we receive. So basically, we have to spend a lot of operational costs and also a lot of legal risk to actually deal with a lot of this problem. And when I told you about that, that large registrar who can only manage like 7% that's that's the reason, right? So this is a cost issue for them. And one of the other problem that actually gets created is because, let's just say, if I'm that particular registrar, I can only manage certain amount with my profits that I can kind of reallocate into abuse management. I have to reduce my cost base as well my expenses. What I can do is that I can basically tighten my policy. So whatever that I don't want to deal with that the gray areas I would allow to say, no, that's not something that within my policy I can deal with. And I can also tighten the process as well, so you have to follow my process and give me certain evidence that I demand. Now this actually makes a lot of the gray area, like scams, is a really gray area, so no one wants to deal with it. So a lot of these cases basically just got ignored. And because of this, we can still see the society suffer a lot of fishing attempts, Ad scams and stuff like that. George Michaelson 25:01 If you look at a corporate entity that lives or dies by the amount of sales in services like names or hosting, having a group within the company saying we've decided you shouldn't sell to that class of customer is really difficult for people who are paid by volume of sales. It's directly impacting their bottom line. So there is always going to be tension around that border line. Couldn't I do this one? Aren't they possibly Okay? Looks to me like they fit inside the rules. When you're sitting there as the trusted abuse mitigation department saying no, there's no way this is going to work, you've signed a contract with people we can foresee is going to be a future burden, but for the person who does the sale, that was their income for the month, so there's an internalized pressure they want the business Alban Kwan 25:50 and I who could frame them, because they a private company, so they have to look after their employees and shareholders and something like that as a primary objective for them. So if we look into the whole online abuse problem from this perspective, from the cost transfer perspective, you can see why it doesn't get resolved, no matter how much more technology that we put onto it and the other cooperation, it doesn't get resolved. We have to solve that cost transfer problem. And going back to that idea that you raised before about trust within this cost transfer problem, there's a intrinsic distrust inbuilt into the process as well. So let's presume that I am a service provider, and I have a customer, say, a particular large bank in the world, so they pay me a lot of money per year to handle their bills problem. So let's just say that if I detect 1000 case for them in a month, and I know that 100 cases out of that 1000 are actually not what we find as DNS appeals, so they're just logo abuse, for example. Now the customer want me to take it down as well, because they consider this as a problem. What can I do? I would basically just push it to everyone that I can, I can find, because it cost me nothing. I automated my process already. [George: Yeah], my commercial best interest. George Michaelson 27:09 Yeah, this is a classic externality, isn't it, that I'm incurring a consequence by saying, I'll take the business and solve your problem, and then I look at the problem and go, Oh, wow, half of this isn't in me. It's in someone else. I'll push it to them, but I'm still going to take the bill for all of it. These externalities filter out into the surface of Internet provider. It almost sounds adversarial. Alban. It sounds like people are pushing the problem around, trying not to solve it because solving it costs money. Alban Kwan 27:43 Yeah, well, I came from that community, so I know exactly how it works, and it works exactly like this and so, so we can see why both sides are kind of blaming each other. The brand owners and the service wise are blaming the Internet intermediary are not taking action fast enough, and the other side basically say, Well, I can't trust you, because I still receive a lot of report that are basically incorrect, you know, not according to the policy. So I have to deal with every single one myself. And you know, it just takes time. George Michaelson 28:15 I'm led to two thoughts in connection with this, and they're both difficult. One is this is crying out for some level of regulation. Now, regulation is a dirty word in the technology space. We all try so hard to ignore the role of the regulator, but I feel this is the missing word in the litany of discourse in this problem space, we need something that is an engagement with the regulator. That's the first thing. And the second thing is a word, a concept that's coming to mind is insurance and functionally, levies that the industry self regulation, or under some process with a regulator probably has to take on a burden, a mandated burden, to incur a cost, like a levy for abuse management or something similar, and actually put money behind coordinating a response here. Alban Kwan 29:09 Yeah, well, you basically precisely describe what we want to do with the TNN. Basically what we want to do is to facilitate both of these in a particular way. So let me, let me explain this a bit more, because the transfer of cost and the commercial alignment that I described, what we need to do to resolve that problem is that we need to find a way to reverse that cost transfer in some sense, and then we have to realign the commercial best interest without going into way too much detail. Just presume that we have coordination body in non profit in middle. We basically say, All right, we can give you some value. If you for service provider, we can give you some value in return for you to doing the right thing and don't send all these craps to us. So. I'm I need to ensure that every 100% of your report is, you know, 100% accurate. Now, if you do this, I'll give you something in return, in terms of a faster take down. So you get something, I get something. George Michaelson 30:13 This is not a zero sum. We both benefit if we behave in this way Alban Kwan 30:17 Exactly. Basically what we asked the Internet intermediate to do is that, if they, if we have a trusted notifier network, give us a "green channel", in a sense that you prioritize a review of these trusted notices. And on the other side, we basically just say that anything that you know, we have to make sure that all the reports are verified, and we need to establish some indemnity processes. So when we take action, we are not legally liable, and all the automated notices need to be stopped. You know, we need this to be humanly review in some set, in some senses, can be 100% automated. So when we do this, there are enough Internet intermediary stand behind the TNN, something really interesting happened, which is the reversal of commercial best interest. If we get the top 10 registry and registrar and a number of hosting service providers joining the network, the value of that green channel would be tremendous for the service provider now, if they already obtain that trust status, the risk of the business, risk of losing that status would be extremely large as well, because their competitor will go in and get their business. So that basically changed the commercial best interest calculation. Their commercial best interest is no longer just acting on behalf of the customer, it would be to maintain as a trusted the definition of trust and notifier. So we change the commercial interest of the service provider. Also change the commercial interest of the brand owners themselves as well. Because if I'm a large bank, I have that 1000 case, if I can have a situation where I can quickly resolve 900 of those problems. In return, I have to sacrifice a 10% of those local abuse. I just take time. You know, we just don't go through that green channel. We resolve it appropriately. We don't force it towards the wrong, wrong Internet intermediary. Now they would probably say, Yeah, I would rather deal with all these 900 cases quicker. And so everyone from the brand owners to the service provider to the Internet intermediary, they all align in their commercial interest, George Michaelson 32:33 And you've kind of flipped the problem round, from being a net cost and an externality pushing game to being a value proposition that actually, as itself, enhances the value of the entity. Preserve this flagging, deal with these problems effectively and efficiently. Your brand value rises. Your costs drop. It's in everyone's interest to play, Alban Kwan 32:57 yeah, and I think this is the key value of trust and notify network, because I came from that commercial background, as I mentioned, this is the missing piece. At the moment. We have a lot of technology, you know, the [indistinguishable] and a lot of this kind of technology going around to help out. We basically supplement this technology solution with this kind of, you know, commercial interest realignment, cost interest realignment so and the second value that we try to bring is to solve the legal problem as well. Because even if we have this trusted notify network definitely be some false positive as well. It's just an unavailable if they are false positive. And the Internet intermediary as a custodian, the entity who needs to take action? We means to be extremely careful. We just can't trust it. So I have to do the proper election on every single case. So the solution is that we have to build in a chain of indemnity. So if part of the policy for TNN is that every single case that password TNN must be verified by the victim, which is the, let's say ANZ in this example. So when ANZ verify it, they have to also provide an indemnity for the Internet intermediate to take action on what they claim to be an infringement or phishing attacks. [George: Yeah], that got passed on to the service provider, and service provider passed on to TNN is one of the mandatory policy. If a service provider needs to join TNN, they have to establish the indemnity, and then we just pass on all the indemnity to the Internet intermediary so everyone along the chain have legal protection. George Michaelson 34:36 I suspect, as consumers, we've grown used to the idea that if fraud happens, and we use the credit card, we have the opportunity to reverse the transaction because the credit card provider offers us that service. And what we skip over is that if you request the reversal, you the individual, are actually taking on liability and risk. You're saying I was scammed. And card provider at that point is saying, fine, I'll reverse the transaction and give you the money back. But if you actually did get the goods and services and you weren't scammed, there are consequences for you in telling me to make a reversal. And people kind of let that through and forget about it. The processes that are analogous. In things like credit card fraud, people are reminded of their legal obligations, and it feels like you're saying a very similar thing. If we're going to create a network of high trust, green channel notifiers that component of risk can't just vanish. It has to be acknowledged and it has to be accounted for, and the consequences have to be understood, Alban Kwan 35:43 yeah And at the moment, the situation is really bad because that the complainer are not bearing that responsibility at the moment. Now there's no mechanism to say that. All right, your complaint is actually incorrect. You are actually the one who are scamming and abusing, [George: yeah] And absolutely no consequence at the moment, so that's the case. You bet that there will be incorrect reports. So we as a community needs to rebuild that liability and responsibility as part of the trust and notify network for it to work. George Michaelson 36:14 You have, I think, told a cohesive story in respect of FinTech, banks, corporate entities with high brand value dealing with customers and abuse problems. I think that I can see a story you've talked about the role of the channel high in the name space, and the inevitability that the registrar acquires burdens in the current world because of their knowledge of the customer. KYC behavior. I haven't totally understood how you're bringing ISPs, network providers, data centers, CDNs, into this conversation. Have they already started to become aware that they are necessarily going to have to sit in the same room in a circle and come to some agreement? Alban Kwan 37:00 I think some are starting to understand because I think, unfortunately, it takes a bit of governmental pressure to make it happen. And then let's go back into your what you mentioned about regulation as well. So the unfortunate fact is that if the industry cannot self regulate and come up with policy to deal with this, then the government needs to come out and regulate. So we are actually seeing this happening in Europe. A lot of regulation are being made, and sometimes hosting service provider CDN, are liable now by the regulation, which is not a very good situation to give example, I think in Italy, the court basically say that a CDN needs to help remove a particular type of infringement within certain hours, and that caused one of the biggest CDN service provider to claim that, if that's the rule, I have to basically exit that entire market. Now this is the worst case scenario we don't want the situation become, you know, a particular country regulating only part of the world, and then we have to deal with it with different jurisdiction and the different regulation. It would be much better if we as a community can come up with a solution ourselves, a policy in a multi stakeholder model to do with this? George Michaelson 38:20 Yeah, I've felt from conversations I have had with people who work in regulatory roles that signals from an industry self regulation group. This is the kind of behavior we think we understand amongst ourselves. Are incredibly useful. They head off expensive, consequential legal costs and framing of laws and national agendas, because it's obvious this solution is the one that people have said, we think we can agree to do this. It doesn't mean that it's always the right way, but it's a lot better for an industry group to proffer an approach than to have one imposed, particularly when you think that each national jurisdiction is going to impose different versions. If the global industry comes together in forums like ICANN or at the NOG meetings and say this is what we think we could do collectively in the abuse space, it's much more likely to be reflected in their obligations under national regulation, isn't it? Alban Kwan 39:18 Yeah, exactly when I start coming to APNIC. I wasn't aware of this, but when I start coming, then I realized, hey, actually, there is no definition about what IP address abuse is. Certainly, IP address can be abused because we have mandate and abuse contact, but if we have a contact for abuse, probably we should also define what abuse means, yes, and we need to build measurements, right? If, if there's like, there's something called a bulletproof host, right? It exists. So bulletproof host, by definition, are basically hosting service either who will not respond to any takedown requests. They are basically just ignore. Everything. So are we. are we we allowing this kind of behavior what would be a reasonable timeframe for us? All right, that whole discussion happens in the Naming community through ICANN, but in the IP address community, I think we also need to come up with some conversation ourselves. And the good thing is that in the Naming community, the conclusion throughout all this conversation, partially, would be that we, yeah, we have to really establish this kind of trusted notifier or the trusted flagger in the EU but it takes them, like, 10 years to come to a practical resolution. But we do have this in place. So when we kind of perfect our policy, we can also kind of move into a situation where we don't have to dramatically increase our costs, because we can rely upon building a industry cooperation, trust and notify concept. It doesn't need to be my particular organization. It could be something else as well, but we need to look into both the policy as in what our responsibility and also a solution when we deal with this, how do I actually minimize our cause and legal liability together in our policy making process? If we do this correctly, hopefully we can actually deal with the problem effectively without costing everyone too much money. George Michaelson 41:26 You've been at the most recent APNIC APRICOT meeting held in Jakarta. Do you think you're going to be coming back regularly? Is there potential for a working group or a special interest group to emerge in this space? Alban Kwan 41:39 I am exploring this. I think within the community, many people recognize this as a problem, but bringing up the conversation is not easy. I do talk to APNIC as well too. There's a couple of ideas that we are kind of in discussion, which may may not be able to be opened since it is not finalized, but certainly I'm hoping that in the next APNIC Meeting, I'll start introducing some policy change, some PDP, at least, just to start the conversation going. I think the last PDP around abuse was passed number of years ago, is overdue for update. And rather, this turns into a SIG Special Interest Group, which depends on, you know, what the people are interested to continue the discussion. Then, yeah, yeah, so, but I, personally, I certainly feel that this is something that we need to talk together, right? APNIC is a really appropriate platform to have this discussion, because we have the cyber security people, we have the ISP, we have the hosting provider, we have some of the cloud service provider all coming together in the region already. George Michaelson 42:48 They might have been focused to date on things like DDoS attacks and inappropriately forwarded packets and routing hijacking, but the social dimension of abuse needs to be put in context and discussed by the same people. We might as well say, Hey, here's this other bucket of problems. Alban Kwan 43:08 Yeah, I think the problem is that, because the presumed cost of starting that discussion would be too high, [George: yeah] so everyone doesn't want to start, George Michaelson 43:17 the cost of ignoring that conversation is even higher. Alban Kwan 43:21 I agree, yeah, and it's coming. You know, the governments are starting to make policy, so it's about time for us to really start having that discussion. George Michaelson 43:31 Alban, it feels like this is something we just have to do. It's inescapable. And I think the time has come for us to kind of sit back and think about the scale of the problem here. We can't ignore this. Can we? Alban Kwan 43:44 Yeah, definitely, in my opinion, is definitely coming. The risk is increasing. If you look into the global policy development trend is definitely coming, and they are realizing that the hosting provider, the CDN and Telco provider, are a critical part of it George Michaelson 44:01 as well. Thank you very much for coming on PING and talking about this. If people are interested in getting in touch with you, there's a website you'd like them to look at. Alban Kwan 44:10 Yeah, the website address would be trustednotifier.network, not.net but the food work network, and you can find more information there. George Michaelson 44:20 Thanks very much. Alban, Alban Kwan 44:21 thank you very much, George. Thanks for your time and your invitation. George Michaelson 44:27 If you've got a story or research to share here on ping, why not get in contact by email to ping@apnic.net or via the APNIC social media channels. Also remember the measurement@apnic.net mailing list on orbit. Is there to discuss and share relevant collaborative opportunities, grants and funding opportunities, jobs and graduate placings, or to seek feedback from the community on your own measurement projects, be sure to check out the APNIC website for all your resource and community needs. Until next time.