Part 2 of 3 · The proposed solution

Keep the record. Make the keeper replaceable.

The Internet still needs one reliable record of who uses which numbers. It does not need a gatekeeper. My proposal shrinks the registry back to that record, lets every network check it and leave a keeper that fails it, and returns every other decision to the people who run networks, to contracts and to the courts.

Summarised from Notes 1–74, December 2025 – September 20266 min read

In figures

11
Rights every network should hold against its registry, set out on a single page. Note 72
3
Design rules for a shared record: a minimum specification, local decisions, voluntary adoption. Note 64
10
Business days to record an ordinary transfer, in my draft rules for AFRINIC. Note 71

The short version

  1. One test for every rule: what do running networks actually need?
  2. Share only a thin layer: unique numbers, proof of control, accurate records and security. The rest belongs to operators.
  3. Record transfers instead of approving business plans, and take addresses away only for defined, reviewable reasons.
  4. Make leaving possible, then move in stages towards a record every network can verify for itself.

Start from what running networks need

The Internet was built on a simple engineering discipline: rough consensus and running code. Standards earned their authority because they worked on real networks, not because a committee declared them. The registries borrowed their legitimacy from that tradition and then turned it around, using policy to overrule networks that were already running.

I call the repair running-code primacy. Every registry rule should face one question: what breaks in the running Internet if this is not decided centrally? If the answer is uniqueness, interoperability, accurate records, security or continuity, the rule may belong in the shared layer. If nothing breaks, the rule is not coordination. It is power, and it belongs somewhere else.

“When registry procedure conflicts with running networks, running networks prevail.”

Note 72 · The Bill of Rights of Uniqueness Coordination

A thin shared layer, and everything else local

In Note 64 I set out three design rules for any shared record of this kind. Minimum initial specification: write down only what every participant must share, in a form each can verify. Localized future decision: let each operator decide later changes for itself. Voluntary adoption: a new rule becomes real when networks choose to run it, and choosing not to is not a violation.

Applied to the registries, the shared layer keeps only what running networks require. Leasing, customers’ locations, pricing, financing and business models go back to the operator, to contracts and markets and, where force is needed, to public law and the courts. The numbers inside an IP address work everywhere because nobody licenses them; the record that keeps them unique should be just as unremarkable.

“The best governance problem is the one the system design removes.”

Note 65 · Running-Code Primacy: The Patch Needed to Preserve the Internet’s Original Design

Record transfers; stop approving business plans

A land registry records who owns a field without asking whether the new owner’s plans are wise. A registry of Internet numbers should work the same way. It should verify that a transfer is genuine, that the numbers are not registered twice and that the record is right, and then record it within fixed deadlines: in my draft for AFRINIC, ten business days for an ordinary transfer and twenty between registries. It should refuse only for listed defects, with written reasons, evidence and a right of appeal.

Taking addresses away should be just as limited: a court order or independent decision, proven fraud, a duplicate that cannot be resolved, written abandonment, a short and reviewed security emergency, or non-payment after notice. The security records that protect routing must stay neutral, never a lever over members. When holders disagree, the record should show the dispute and hold the last verified state while an independent forum decides. A registry should never be recordkeeper, claimant, judge and executioner at once.

“The registry may verify that a transfer does not break the Internet. It may not decide whether the transfer deserves to exist.”

Note 72 · The Bill of Rights of Uniqueness Coordination

Make leaving possible

Accountability starts with the ability to leave. You can change mobile provider and keep your number, and your provider behaves accordingly. A network should be able to move the registration of its addresses, with the record, the proof of control and the security information, to a qualified successor, without renumbering and without asking permission from the registry it is leaving.

This is not about a company changing its membership from one registry to another. It is about the resource: a particular block of addresses must not stay trapped inside one institution’s failure, capture or dispute.

Continuity has to be designed, not assumed. The registry’s state should be versioned, independently audited and copied beyond the control of any single organisation. Directory services need tested failover, and the security system needs a planned succession of keys and repositories, because a static backup is not enough. The registries’ own contingency discussions already accept that another operator can take over the service. They have not yet accepted that the choice cannot rest with the same club.

“Indispensable infrastructure requires replaceable administrators.”

Note 70 · The Registry Continuity Fallacy — Protect the Ledger, Not the Gatekeeper

In the long run: a record every network can check

Today a network has to take the registry’s word for what its record says. The end state I argue for is different: the state of the record is shared and verifiable, so that any network can check for itself who holds which numbers, and no single institution is the source of validity. A distributed ledger is one way to build it. What matters is independent verification and portability, not a particular technology, token or currency.

It does not have to arrive by rupture. The path runs in stages: make the system visible, protect the continuity of running networks, coordinate the holders at risk, and only then move to a thinner architecture. During the transition the existing registries can go on maintaining records and publishing services, once they no longer judge commerce. AFRINIC itself may continue, as a narrow, accountable and replaceable operator.

The engineering is real work: authentication, conflicting histories, compromised keys and secure succession all have to be solved. I would rather name those problems than pretend they are not there.

“The longer-term target is independently verifiable, portable state—not a replacement committee administering the same needs test.”

Note 74 · Need Base and Pre-Approval — The RIR Veto over IPv4 Transfers

Why not new managers, a government or a bigger global body?

New managers. A better board can improve a registry for a while, but the next board inherits the same veto. The aim is not a kinder sovereign. It is to end the claim to sovereignty.

Governments. States can and should enforce their own laws through their own courts, and that is where coercive decisions belong. Handing the numbering system itself to governments would invite censorship, fragmentation and political pressure on routing, and nearly two hundred states will never agree on a single register.

A bigger global body. Giving ICANN, the registries’ coordinating body or a United Nations forum more authority would build a larger version of the same gate. A permanent forum is still a forum.

More liability alone. Making registries pay for the harm they cause would put a price on it, but liability does not buy a right to rule. The better cure is to remove the power that causes the harm.

“Record-keeping is not sovereignty.”

Note 53 · On Internet Number Resources Are Not Political Property

Questions readers ask

Is this a blockchain project?

No. The design needs records that any network can check independently and take with it. A distributed ledger may be the right tool for that, but the proposal does not depend on any token, currency or crypto project. It depends on verifiability, portability and continuity.

From the NotesNote 58Note 64Note 65

Won’t portability fragment the Internet?

Portability prevents fragmentation rather than causing it. When networks cannot leave, they route around a registry they no longer trust, and that is how competing records appear. A defined way to move keeps one shared record. Moving has costs, such as more entries in routing tables; they should be managed, not used as a reason for lock-in.

From the NotesNote 67Note 71

If the registry cannot take addresses back, who stops abuse and fraud?

The same people who stop it everywhere else: operators, their customers, contracts, courts and law enforcement. A registry should publish a way to reach each network and correct forged records. Taking a network’s addresses away punishes its innocent customers along with any wrongdoer.

From the NotesNote 28Note 70Note 71

Do you want IP addresses to become private property?

The proposal does not depend on that word. It asks registries to stop treating their record as a source of ownership. Holders may have legal and economic interests under the law that applies to them; the registry neither owns those interests nor creates them. Its job is to record.

From the NotesNote 53Note 71Note 72

Would the existing registries disappear?

Not necessarily. They hold valuable operational knowledge and systems, and they can keep running services during a transition. What has to go is the claim to rule. A registry may continue for as long as it records accurately, stays narrow and can be replaced.

From the NotesNote 67Note 70

The Notes behind this page

Every section above is a summary. These are the Notes where the argument is made in full.

  1. Note 72The Bill of Rights of Uniqueness CoordinationThe whole proposal on one page: eleven rights every network holds.
  2. Note 64Minimum Initial Specification, Localized Future Decision, and Voluntary Adoption for Internet Coordination SystemThree design rules for a shared record without a permanent authority.
  3. Note 65Running-Code Primacy: The Patch Needed to Preserve the Internet’s Original DesignRunning-code primacy: the repair to the Internet’s original design.
  4. Note 70The Registry Continuity Fallacy — Protect the Ledger, Not the GatekeeperWhat continuity really requires, and a plan to secure it.
  5. Note 67When the Water Company Says Your House Belongs to ItWhy a network must be able to take its addresses and leave.
  6. Note 71The Policy MirrorA full set of amendments that would turn a registry back into a record-keeper.
  7. Note 74Need Base and Pre-Approval — The RIR Veto over IPv4 TransfersWhy registries should verify transfers, not approve investments.
  8. Note 13On Decentralising Global IP Address Registration with Distributed Ledger TechnologyMy first outline of a distributed register of IP addresses.
All Notes