Artículos del equipoPoder y gobernanza

When an Internet Registry Fails, What Actually Breaks?

A registry does not carry every packet, but its records can still shape whether networks are recognised and can keep operating. This guide separates records, routing, authority and the exit a resilient system needs.

Índice

A dark directory kiosk beside buildings still linked by blue cables.
A recordkeeper can fail while the network keeps running. The harder question is whether its records and dependencies can survive a change of administrator.

A registry failure is not one single outage

Start with an ordinary network. It operates equipment, connects to other networks and uses number resources so that other networks can distinguish its traffic from someone else’s. A registry helps keep the records of those resources unique and usable. It is a coordination layer, not the wire carrying every packet.

That distinction matters when asking what failure means. A registry can become unavailable, lose the ability to maintain trustworthy records, face a dispute over its mandate or impose a condition that an operator cannot practically escape. The network may still have power, customers and working routers while its administrative foundation becomes uncertain.

Four different questions are usually collapsed into one

When people say that a registry controls the Internet, they often mix together four different roles: who operates a network, who records a number resource, who decides whether a route is accepted, and who has authority to bind the people affected by a decision.

A record can be important without making its administrator the owner of the network. A routing filter can protect an operator without giving the filter’s author a political mandate. Separating these roles makes the failure visible: the technical service may continue while the institution that other systems depend on becomes difficult to replace.

  • Operational control: who can keep the network and its customers running?
  • Record integrity: can other networks verify which resource is associated with which operator?
  • Routing acceptance: which technical systems will accept an announcement, and on what evidence?
  • Mandate and liability: who authorised the decision, and who bears the consequences?

The dangerous part is dependence without an exit

Redundancy inside one institution is useful, but it is not the same as a replaceable institution. Several servers, offices or committees can still belong to one administrator that nobody can leave without renumbering, losing recognition or renegotiating every dependency.

That is the power problem Lu Heng traces in Note 42 and Note 52. The administrator’s clerical role can acquire economic force when operators, customers and other networks have built their systems around its records. The institution may be small, while the cost of changing it is distributed across an entire market.

What a resilient replacement must preserve

The answer is not to abandon common records or allow several incompatible authorities to claim the same numbers. Other networks still need a dependable answer to the question of uniqueness. The answer is to make the coordinating administrator replaceable while preserving the evidence that lets the wider network recognise the resource.

Note 72 gives this proposal its clearest shape: accurate records, verifiable control, continuity and a workable right to change coordinators. A replacement path must be designed before a crisis, because an exit negotiated after failure leaves the failing institution in control of the terms.

Why waiting for the failure is already too late

A dispute exposes the difference between a theoretical right and an operational one. Can the operator keep its numbers while changing the record keeper? Can another administrator verify the same facts without creating duplicate claims? Can routes, security assertions, contracts and customer allow-lists survive the transition?

These questions take time to answer and test. Note 37 frames the urgency as an infrastructure question: decentralisation is useful when it gives a working network a real way to survive institutional failure, not when it merely distributes meetings across more participants.

The reader’s practical test

Choose one address block or network identity your organisation relies on. Write down who operates it, who records it, who can change the record, which routing and security systems depend on it, and what would happen if the record keeper became unavailable. Then ask the decisive question: can another qualified coordinator take over without making the network start over?

If the answer is no, the risk is not limited to a registry’s uptime. It is a dependency on an administrator that the system has made difficult to replace. That is the problem this series follows through routing, business continuity and board-level infrastructure decisions.