I’m a lone soldier on this one. “If the community wishes to have a point past which a claim against a completed transfer is too late to bring, then there simply needs to be clear policy developed and ARIN will implement the policy to the best of its ability.”
I agree with this. Though it tends to take someone getting caught by it before anyone thinks to write the policy, and that is where I came in. The gap was there the whole time. It only surfaced because it landed on a buyer who had done nothing wrong and a seller who happened to still be reachable ten years on. This can come back on an IP brokerage, on the buyer, and on the seller. I don’t represent any of them. I’m speaking from having been on the wrong end of it, and I have nothing to lose here either way, by experience or as a legacy holder. That is probably why I’m the one saying it. It’s an interesting question and one that has never been definitively defined or argued. Should it be? I think so. I don’t see anyone else out there anymore who is reachable as legacy or cares /jsk [sorry, it’s hard to compose this stuff from a phone] On Sun, Jul 26, 2026 at 5:49 PM John Curran <[email protected]> wrote: > Jeremy - > > Presently there is no stated bound, so ARIN will attempt in good faith to > remedy any credible reported error in transfer processing, since there’s > the possible of an otherwise harmed party without clear recourse (e.g. who > has been a wrong end of a skillful hijacking) – even if such occurred years > ago. > > If the community wishes to have a "a point past which a claim against a > completed transfer is too late to bring”, then there simply needs to be > clear policy developed and ARIN will implement the policy to the best of > its ability. > > I will make two observations in considering such a policy: > > (1) The good news is that now nearly 95% of the number resources are under > registration services agreement (all of which involved having a certain > level of vetting of claim of association with those resources) and as such > we no longer see a large number of resources which are being brought before > ARIN for the very first time to clean up their provenance, but … > > (2) the situations that do arise now are often resources with a more > colorful lineage (e.g. involving competing firms & claims, multiple mergers > and splits, etc.) and that means that they can at times be rather > challenging to untangle – and would become even more so if there were a > limitation on consideration added to the mix. > > And perhaps obviously, if any policy development is undertaken in this > area, it will be essential – back on the subject of policy development & > handling of existing versus new – to understand if the intention is to > apply to transfers going forward, or if those transfers that have already > occurred are to be included… (as policy that would be applied against past > transfers implies a high level of outreach during policy development so as > to avoid impacting parties without also providing an amply-communicated > opportunity to participate therein.) > > Thanks! > /John > > John Curran > President and CEO > American Registry for Internet Numbers > > On Jul 26, 2026, at 9:27 PM, Jeremy Koski <[email protected]> wrote: > > I should have also included a mention regarding abuse contacts or anything > related to that. It is an interesting argument I had not considered. While > I was never told any specifics, it came down to ARIN giving us a hard time > and needing confirmation this was a legitimate transaction. My grievance > with the matter is how much time can pass before something is revisited, > and whether it is perpetual and can be revisited at any time, even beyond > the 10 years I experienced. In this case I was still reachable. After so > long, the chances of an email, number, or address still working become less > and less. There are bad actors out there and always will be. But that was > not information I was given as to the reason [bad actors is an example John > related to for revisiting]. I don't know the trigger here. There could > have been any number of reasons, from a simple mistake to lost > documentation, or even someone challenging the transfer ten years later for > personal gain or something in that realm. A line has to be drawn somewhere > and the book closed on the matter. That this could happen ten years later, > with no predetermined time limit, is still an issue, and it does fall > somewhat in line here with policies, changes, retiring terms, and so on. > Whatever the trigger was, there should be a point past which a claim > against a completed transfer is too late to bring, and as far as I can tell > there is none. Ten years on, I do not think I had any real obligation to > produce anything, I did so in good faith, notarized and sent the documents > anyway, so the buyer would hopefully not have any future issues or problems. > > /jsk > > *From: *Jeremy Koski <[email protected]> > *Date: *Sunday, July 26, 2026 at 2:28 PM > *To: *John Curran <[email protected]> > *Cc: *William Herrin <[email protected]>; ARIN PPML <[email protected]> > *Subject: *Re: [arin-ppml] Request for Comment & Feedback: Draft Policy > ARIN-2025-3: Change Section 9 Out Of Region Use Minimum Criteria > > Hi John, thanks for the response. > > Simply put: the buyer purchased through an IP broker around 2014, and ARIN > approved it; a transfer of the business, the domain, and the legacy IPv4 > space. Around 2024 I was told the block would be reclaimed unless I > produced a notarized document stating I signed it over around ~2014. I > signed copies, had them notarized and sent them to the buyer and to ARIN, > so it has essentially been resolved. But neither of us was ever told what > prompted it. A competing claim? A documentation issue, or something else? > It seemed to me ARIN was revisiting an approval it had already granted 10 > years after the fact. > > That's also why the terminology matters to me. "Grandfathered" named > holders whose resources predate the rules being written about them, and the > practical question isn't the word, it's whether an approval given under the > rules in effect at the time stays given. For me and the buyer, it became a > legitimate and potentially serious issue 10 years later. > > Either way, IP brokers and their buyers should know this can happen going > in. It happened to a legacy holder here, and I don’t know how many are > left these days. The purchaser could have had a real mess on his hands if I > hadn't been reachable. > > Jeremy > > > > > *From: *John Curran <[email protected]> > *Date: *Sunday, July 26, 2026 at 12:01 PM > *To: *Jeremy Koski <[email protected]> > *Cc: *William Herrin <[email protected]>; ARIN PPML <[email protected]> > *Subject: *Re: [arin-ppml] Request for Comment & Feedback: Draft Policy > ARIN-2025-3: Change Section 9 Out Of Region Use Minimum Criteria > > Jeremy - > > If you want to transfer your rights to an IP address block in the ARIN > registry, it’s advisable to contact ARIN to have the entry updated in a > timely manner – this is the best way to avoid any future over who holds the > rights. > > If ARIN does have another party contact us and indicate that a mistake has > been made and credibly assert they are actually the proper rights holder, > then indeed we will investigating the situation to help resolve the > matter. This may result in us contacting you even after a transfer to > obtain additional information (particularly because some of the earliest > transfers were made without the current level of rigor that we require > today.) > > Note that policy developed by this community applies to all entries in the > ARIN registry – ARIN instantiates the cooperation that this community > develops, and the benefits of participation in the registry comes with > obligation to follow the community developed policy. For example, when > new NRPM policy indicates that you have to register an Abuse contact, it’s > not optional for any registry users and applies regardless of when you > obtained your number resources. > > This is why it’s important to be aware of (and participate if interested > in) the ARIN community’s policy development process. > > With respect to the particular proposal being discussed, the question is > simply regarding handling of existing parties already on the waiting list > (i.e. in order to avoid confusion, it would be best if any policy that > changed criteria for the waiting list provided clarifying guidance > regarding the handling of those already on the waiting list.) > > Thanks! > /John > > John Curran > President and CEO > American Registry for Internet Numbers > > > On Jul 25, 2026, at 5:55 AM, Jeremy Koski <[email protected]> wrote: > > Section 9 doesn't reach my legacy space, but "grandfathered" does. That > was the narrow point, and it's the one getting left behind. > > The word is being retired as dated terminology, and as drafting that's > fine. I guess. It'll never go away. But it named a real category of holder, > and some of us in it spent years on the receiving end of what came after. > rDNS updates gated on signing. Fee demands in the thousands. And years > later, a transfer ARIN itself had approved getting second guessed a decade > after the fact, with a clawback threat aimed at a buyer who had done > nothing wrong. Retiring the word is cosmetic. Whether the deference to pre > existing status survives it is the part I care about. > > I addressed the original note to John because he was there for all of it > and would remember the specifics. If he wants to or dare reply. Remember > CNN, John? A couple of years ago ARIN went to the buyer of one of my blocks > and told him they would claw back the /19, which carried a reserve to /18, > unless I signed and mailed a notarized document confirming I had sold him > the business. Ten years after the sale ARIN had already been approved. If > my email had changed, or I had died, or I had simply not answered, he would > have been out the block he paid for. > > IP brokerages firms should and must be aware of such frivolous antics. > > On Tue, Jul 21, 2026 at 12:38 AM William Herrin <[email protected]> wrote: > > On Mon, Jul 20, 2026 at 9:08 AM Jeremy Koski <[email protected]> wrote: > > Grandfathered in may not be the proper term but it is an active > argument. Now John may not know this, but I received a large number of > addresses in the USA through InterNIC when I was 12. It was justifiable and > granted. > > > > Restrictions, reverse dns and other problems came there after when ARIN > was formed. Then I began to get threats for $2500 to $5000 but I refused to > opt in. > > > > Does one exempt or simply apply new rules where you seem to have > forcibly opted in… > > Hi Jeremy, > > The draft on the table is a change to section 9 of the policy manual. > It applies to qualification for _additional_ IP addresses. If you ask > ARIN for _more_ IP addresses than you currently use, those addresses > you acquired when you were 12 matter. Section 9 then talks about > whether use of those old addresses elsewhere in the world qualifies as > "in use" for the purpose of justifying the *NEW* addresses. Not > justifying the old ones, justifying the *new* ones. > > If you're not asking for more addresses for the same registrant then > section 9 is not applicable to your legacy addresses at all. > > Regards, > Bill Herrin > > _______________________________________________ > ARIN-PPML > You are receiving this message because you are subscribed to > the ARIN Public Policy Mailing List ([email protected]). > Unsubscribe or manage your mailing list subscription at: > https://lists.arin.net/mailman/listinfo/arin-ppml > Please contact [email protected] if you experience any issues. > > > >
_______________________________________________ ARIN-PPML You are receiving this message because you are subscribed to the ARIN Public Policy Mailing List ([email protected]). Unsubscribe or manage your mailing list subscription at: https://lists.arin.net/mailman/listinfo/arin-ppml Please contact [email protected] if you experience any issues.
