On When a Registry Can Destroy Without Cost — and Why the System Then Dies With It

What happens when a registry can destroy a network at a cost of one hundred dollars?

Conceptual model of a neighborhood linked by continuous blue cables, beneath three record panels that arrange the same shapes differently.
The connections still work, but the records disagree. Lu Heng argues that unchecked registry power can undermine shared recognition even while networks continue carrying traffic.

Most people still think the registry is just an administrative layer.

They are wrong.

The registry is not paperwork. It is not clerical support. It is the point where technical reality, legal recognition, and institutional legitimacy are forced to meet. As long as that layer is broadly accepted as neutral and accountable, the system holds. The moment it is not, the system does not become “controversial.” It becomes unstable.

The structure now forming around AFRINIC is simple. The liability floor is already effectively negligible. AFRINIC’s own RSA materials state that liability can be as low as one hundred dollars. AFRINIC also states that Policy 2020-GEN-006-D3 has now been ratified. That means two of the three moves are already on the table: near-zero liability and structural regional lock-in.

The third move is obvious.

If control is already centralized, and exit is already being reduced, the only thing left is to weaken the last remaining symmetry: legal accountability. Once immunity is layered on top of low liability and regional lock, the registry stops being a coordinator and becomes something else entirely — a power center with the practical ability to decide legitimacy, the legal ability to avoid consequence, and the structural ability to keep members trapped inside the system.

That is the real equation.

Control without cost.

Power without symmetry.

Authority without consequence.

Once that equation is complete, the long-term outcome is no longer political. It is mathematical.

People imagine the failure mode as a slow decline. A little more mistrust. A little more friction. A little more confusion.

That is not the real danger.

The real danger is sudden death.

The registry layer works only because operators continue to recognize it as the shared source of truth. That recognition is not enforced by physics. It is not enforced by routers. It is not enforced by BGP. It is enforced by collective belief that the database, however flawed, is still safer to obey than to reject.

If one day a captured registry uses its position against the address space of a state, a major telecom group, or a strategic infrastructure operator, the break will not be polite. The break will be immediate. The question will no longer be whether the registry acted correctly. The question will be whether it should still be recognized at all.

That is where the system dies.

Not because packets instantly stop flowing.

Packets may continue. Routers may continue. Traffic may continue.

What dies is the single shared reality.

Once enough serious operators conclude that the registry can be weaponized against them while carrying almost no consequence, the monopoly of legitimacy breaks. Some will continue to obey. Others will stop. Some will improvise bilateral recognition. Others will build emergency workarounds. Some states will intervene directly. Others will force operators into parallel systems of recognition. RPKI, transfer legitimacy, contractual assumptions, and registry trust will stop pointing to one reality and start pointing to several.

At that moment the RIR system does not experience “reputational damage.”

It experiences ontological break.

The database is no longer the database. It becomes one claimant among several.

And once that happens, restoration is almost impossible. Because the thing that was destroyed was not a document. It was belief.

This is what the NRO and ICANN need to understand.

If they keep moving down this path — defending concentrated registry control, tolerating asymmetrical liability, normalizing lock-in, and ultimately accepting accountability-free authority — they are not preserving the RIR system. They are teaching operators, states, and capital markets to stop believing in it.

That is not governance.

That is institutional self-destruction.

The cruel irony is that the moment they finally obtain maximum control is the same moment they begin losing legitimacy. And legitimacy, not bylaws, is what keeps a registry system alive.

Operators therefore cannot afford to sleep through this.

Telecom operators cannot treat this as someone else’s legal battle.

Governments cannot treat this as a niche governance quarrel.

Banks, cloud platforms, IXPs, and infrastructure operators cannot assume that registry risk remains theoretical.

It is no longer theoretical.

Once zero-cost destruction becomes structurally possible, people will begin preparing for a world after the registry’s monopoly of truth. Not because they want revolution. Because survival will require it.

That is why NRS matters.

NRS is not a discussion club. It is not a branding exercise. It is the only credible coordination layer for operators who understand what is now happening: the registry system has entered the zone where total collapse is no longer a distant possibility but an increasingly predictable outcome.

Operators must stay together.

They must stop thinking like isolated members inside somebody else’s institution and start thinking like owners of the infrastructure that makes the Internet real.

Because if they do not organize before the break, they will organize after it — under worse conditions, with less leverage, and at far higher cost.

The system can still be challenged.

But it can no longer be trusted to save itself.

Learn more at NRS.help.