RE: Whois using these ARIN services?? (fwd: Consultation on the Future of ARIN???s Directory Services)
-----Original Message----- From: borg--- via NANOG <nanog@lists.nanog.org>
Uh, first off all. Its not a service that needs constant babysitting. You set up it once and forget, probably forever.
Would it not need security updates? Testing the updates before (so maybe a separate test environment), and testing after? However infrequent, someone needs to be paid to do those things. Which costs money. (And all the other ancillary things involved with your typical "set-it-and-forget-it" service) Adam
On Tue, Sep 1, 2026 at 4:05 AM Adam Maloney via NANOG <nanog@lists.nanog.org> wrote:
Would it not need security updates? Testing the updates before (so maybe a separate test environment), and testing after?
However infrequent, someone needs to be paid to do those things. Which costs money.
Hi Adam, Any plausible WHOIS retirement schedule has a period of time in which results are produced for both WHOIS and RDAP, right? ARIN proposed about 3 years IIRC. So during that 3-year period ARIN is doing one of two things: 1) They're exporting RDAP data into WHOIS and maintaining the WHOIS software. 2) They're implementing a user interface skin around RDAP to provide WHOIS results. Which is more expensive? A full whois infrastructure is complicated enough and a UI skin around RDAP is trivial enough that as a computer scientist with decades of experience I estimate that it'd be cheaper to make a skin and retire the whois backend as soon as possible. Suppose ARIN takes that very reasonable course of action. What's the state of things when the prospective retirement date arrives? Well, there's a complete UI skin providing WHOIS services. There's a suite of regression tests to confirm that the skin still works properly as improvements are made to the RDAP backend. All known security issues have been addressed. What's the remaining maintenance cost? * If a regression test fails, it has to be investigated and fixed. Given the trivial nature of the skin, the probability is that the error was introduced to the RDAP backend, thus the cost is not attributable to the WHOIS UI. * If a security vulnerability is reported or discovered by a new analysis tool, it has to be corrected. These will tend to be small things. Buffer size errors. Uninitialized variables. Full cost attributable to the WHOIS skin but not a high cost. * If DOS mitigations are made to the RDAP front-end, they'll likely have to be imported into the WHOIS front end. This is probably the highest of these three costs but the attributable part is still an integration task not a from-scratch development task. And that's about it. In exchange for ARIN undertaking these costs indefinitely, nobody else has to deal with a forklift upgrade from WHOIS to RDAP. Hundreds, thousands, maybe tens of thousands of organizations migrate to RDAP as convenient with legacy tooling that keeps on keeping on. So, suppose instead of retiring WHOIS after a sunset period, ARIN demotes it to a second class service. Best efforts. Repaired during business hours. You now have a minimal cost to a single organization to keep it working for everybody indefinitely. Is that not an objectively better outcome? Regards, Bill Herrin -- For hire. https://bill.herrin.us/resume/
-----Original Message----- From: William Herrin <bill@herrin.us>
On Tue, Sep 1, 2026 at 4:05 AM Adam Maloney via NANOG <nanog@lists.nanog.org> wrote:
Would it not need security updates? Testing the updates before (so maybe a separate test environment), and testing after?
However infrequent, someone needs to be paid to do those things. Which costs money.
Hi Adam,
Any plausible WHOIS retirement schedule has a period of time in which results are produced for both WHOIS and RDAP, right? ARIN proposed about 3 years IIRC.
<snip the rest of William's very well thought out response> My questions were meant to be rhetorical, not to stake out a position. I was just pointing out that the assertion "You set it up once and forget it, probably forever" was a bit pie-in-the-sky (for any solution). </delurk> Adam
participants (2)
-
Adam Maloney -
William Herrin