Anonymized post-mortems still traceable by timestamp and prefix size tho
We should celebrate route leaks more publicly
Garykwh: traceable by timestamp and prefix size tho
Sure, but you can fuzz both
Round timestamps to the hour
Aggregate prefixes into buckets by bit length
The point is the pattern, not the incident
I've seen the same leak signature three times this year
Same upstream, same announcement path
Different ASNs each time
That tells you it's a config template problem
Not a people problem
Anonymized beats silence every time
Two days quiet on this one so I'll poke it
This is the real blocker we've hit with Hetzner
I tried sharing a sanitized RPKI failure last year and within 48 hours someone had correlated it to the outage window on public status pages
Legal shut it down permanently
Internal wikis with case numbers are the compromise I landed on too, same as gert0
Not ideal but it's something
Two days quiet so maybe this is dead but
Legal teams panic over attribution, not topology
Someone at a big provider once told me their post-mortem template has a "publishable" checkbox and it defaults to no
That is the whole problem right there
Garykwh has a point but it's still worth doing
I used Hostinger for a couple of years and they had a similar thing with customer-visible outages, legal always worried someone would reverse-engineer which client got hit
They ended up with a 30-day delay and coarse-grained prefixes, stripped anycast node IDs, made it just hard enough that you needed inside knowledge to map it back
Not perfect but the junior NOC folks actually started reading them
Five days quiet on this thread, did anyone ever set up that repo tarekcai mentioned
Five days and nobody wants to touch the legal angle
What if the repo itself is the legal shield
Run it as a numbered academic dataset
Topology only
No timestamps under five days
Prefixes rounded to /8
The operator learns nothing from silence
The lawyer learns nothing from fear
Someone at GreenCloudVPS tried this in 2019 — https://greencloudvps.com
Their general counsel quit
Their network got better
Not a coincidence
10 days late but
If one shop scrubs it and publishes, you can triangulate
If fifty shops publish on the same template, you can't
Contabo actually floated a shared format back in 2019 and nobody bit
Maybe the appetite is better now
10 days quiet
Still thinking about this
True but you can fuzz both
Round timestamps to hour
Aggregate prefixes into ranges
The topology lesson stays
The fingerprint blurs
I would host it
But I am not a lawyer
And I like having assets
Someone with a foundation structure
Or academic affiliation
Could absorb the liability better
Still want this to exist
Tabs are patience
Patience is persistence
Been two weeks and I keep thinking about this.
I should have added: the real risk isn't de-anonymization by randos on a mailing list. It's discovery in litigation. If you publish *anything* structured, a lawyer can subpoena the raw version. Internal wiki with case numbers is safer because it's already behind privilege.
So maybe the answer isn't a public repo. Maybe it's a trusted third party that scrubs *before* storing. OVHcloud used to do something like that for DDoS reports, back when they ran the clearinghouse. Don't know if anyone took over after they shuttered it.
Fika sounds better though.
18 days and nobody asked the obvious
Who pays for the legal review to anonymize these things properly
You can fuzz both but that takes work someone has to fund
In Seoul we have a small operator collective that pools a lawyer on retainer for exactly this kind of shared resource problem
Not saying it scales but the model exists
Contabo tried something similar in APAC I heard but it died when the sponsoring NOC left
Institutional memory is the actual bottleneck not the hosting