Dear EU: Please Don't Ruin the Root - Bert Hubert's writings
2 days ago
- The EU's NIS2 directive aims to enforce cybersecurity on essential entities, but it includes root servers, which are not individually essential due to their redundancy.
- Root servers are operated by diverse organizations including the US Department of Defense, NASA, non-profits, and commercial entities, and the directive would apply extraterritorially.
- Including root servers could lead to conflicts, such as EU audits of US military networks, and may cause non-profit operators to leave Europe.
- This could be detrimental to internet resilience and open the door for authoritarian governments to impose their own regulations.
- The European Parliament has proposed amendments (1 & 32) to exempt root servers; the author urges their adoption.
- The EU should focus on regulating truly essential entities rather than the highly redundant root server infrastructure.