ARIN Passkey Security: Why a One-Admin Account Is Now a Liability
Here is a pattern I logged over and over before I understood it. A client opens a ticket, frantic, because the one person who held their ARIN Online credentials has left, and the laptop went home in a box. One of ours hit exactly that in March. The departing admin took the device, and the organization could not reach its own number-resource records for three days while we walked them through identity verification by phone. Under the old system that same lockout would have closed itself: a self-service email reset and a coffee break. The recent news is what finally explained why that pattern is about to get worse.
On 26 May 2026, ARIN published a routine-looking service update to ARIN Online, its secure web-based portal for managing IP records, resource requests, and correspondence. Two lines in the release notes matter more than the rest. Multifactor authentication now includes industry-standard passkeys. And email-based Point of Contact recovery has been retired. Customers who lose access must now open an Ask ARIN ticket or call the Registration Services Help Desk at +1.703.227.0660, weekdays 7:00 AM to 7:00 PM ET.
That is a security upgrade I support fully. It is also a change that quietly converts a routing-data registry into something with no back door, run by a 106-person organization with limited support hours. If your account depends on a single person, ARIN just removed your safety net, and I do not think most holders have noticed yet.
What the 26 May update actually does
A passkey is a cryptographic key pair. The private half stays on your device; the public half registers with ARIN and answers a login challenge. Nothing reusable crosses the network, which is why passkeys shrug off the phishing and credential-stuffing attacks that plague passwords. ARIN added them to the existing MFA menu rather than forcing a swap. The release expands your options and publishes a tested-device list, so you enroll a passkey alongside your current method, not instead of it.
The retirement of email-based recovery is the half that changes operations. Previously, a locked-out Point of Contact could trigger an automated email reset. That path is gone. The source is explicit: customers needing Point of Contact access or recovery "should contact ARIN Registration Services through an Ask ARIN ticket." A phone line backs it up. Both are staffed by humans, on a clock.
So here is the new failure mode, no drama added. ARIN has not published a recovery-time figure, and I will not invent one. What I can tell you from doing this work every day is the shape of it. Recovery is no longer instant, no longer self-service, and no longer available outside business hours. For a registry account, that is a meaningful shift in your incident calculus.
When your one admin walks out the door, who gets you back in?
This is the part I want every client to sit with. The security model is sound. The trouble is that it swaps one risk for another: it used to be "your password gets phished," and now it is "your one admin is unreachable." That second one is the risk most small holders are actually living with, even if nobody has said it out loud.
Walk the chain. A passkey is device-bound. Lose the device to theft, hardware death, or an employee who leaves, and the private key goes with it. There is now no email reset to fall back on. The only route back in runs through Ask ARIN or a phone call during business hours, with identity verification against your existing Point of Contact records. If the one person who can pass that verification is the person who just left, you are not locked out for an hour. You are locked out until the help desk opens and someone with organizational authority can vouch for you.
This is not hypothetical risk-padding. ARIN Online is the gateway to controls that have real consequences: the Route Origin Authorization Change Log, incoming-reassignment filters that protect you from bad actors, and IRR route objects. An organization tracking ROA changes for routing security needs at least one administrator who can always get in. Lose that and your route-origin posture goes stale precisely when you cannot fix it.
The mitigation is dull and entirely in your control: more than one administrator, each with an independent, enrolled credential. I work through the specifics below.
Why the timing raises the stakes
ARIN Online is not a low-traffic system you touch once a year. The platform's throughput tells you how central it has become. On 13 January 2026, ARIN fulfilled 149 requests off the IPv4 waiting list from 59 cleared blocks in a single distribution. The waiting list itself has grown past a year deep, with the oldest active request dated 20 March 2025. The portal is also where a long, slow queue of acquisitions lives or dies.
The money rides on it too. Effective 1 January 2026, ARIN's Registration Services Plan fees run from $275/year at the 3X-Small tier up through $2,205 at Small, with increases capped at 5% annually. Legacy resource holders under pre-2024 agreements sit at a $250 annual cap. None of that is optional spending; it is the cost of keeping your resources in good standing. An account lockout does not pause your obligations. It just removes your ability to manage what you are paying for.
And ARIN is not a marginal registry whose decisions you can ignore. It administers 45% of the global allocated IPv4 pool, roughly 1.66 billion of about 3.7 billion addresses, far ahead of APNIC (24%), RIPE NCC (23%), LACNIC (5%), and AFRINIC (3%). When the dominant registry hardens its access model, that is no niche policy footnote. It is a change every holder in the region inherits whether they read the release notes or not.
Recovery paths after the change: a decision table
When access breaks, your route back depends on what you still hold. This is the map I give clients. Read each row by checking what you actually have, then weigh the good answer against why it changes the call.
| What to check | A good answer | Why it changes the call |
| Can you still log in somewhere with a second credential? | ||
| Yes, you have an active session on another enrolled device | Enroll a replacement passkey from security settings and revoke the lost one; no help desk needed | |
| Is it currently weekday business hours? | ||
| Yes, Mon, Fri, 7 AM, 7 PM ET | Call +1.703.227.0660 or open an Ask ARIN ticket and pass identity verification against POC records | |
| Did the lockout hit after hours or on a weekend? | ||
| No path is open until the desk reopens | Prepare your verification documents now and queue for the help desk opening; nothing self-service remains | |
| Is your only credential held by an admin who has departed? | ||
| Only organizational-authority verification will clear it | Escalate via Registration Services and expect delay while authority is re-established |
Look down the table and the pattern jumps out. Every row that ends in pain is a row with only one credential holder. So the work that matters is done long before the lockout, and it is structural.
A pre-incident plan worth ten minutes this quarter
You cannot fix an access crisis during the crisis, because the new design has removed the self-service path that used to bail you out. The defenses are simple, and each one closes a different way the account can strand you.
Start by enrolling passkeys on at least two people. Each administrator registers a device-resident credential independently, so one device loss can no longer strand the account. Then back up every passkey to that person's platform sync or to a second hardware key. An un-backed passkey on a single device is a single point of failure, security badge or not.
From there, audit your Point of Contact list. Confirm that at least two trusted individuals hold active, independent login credentials and that their contact details are current for voice verification. Update your runbook to match: strike the line that says "reset by email," because it is permanently false now, and replace it with the help desk number, hours, and the documents your team needs to pass verification. Finally, check the Message Center before you escalate. The 26 May release confirmed all systems normal, and a dashboard alert often explains an apparent fault faster than a ticket queue will.
About
I am Nikita Sinitsyn, a Customer Service Specialist at InterLIR, the Berlin-based IPv4 marketplace. Eight years in telecommunications technical support and customer service sit behind that title. My days run inside RIPE and ARIN database operations: KYC checks, resource transfers, and the reconciliation that decides whether a client's block is clean and reachable. I write about ARIN's platform for a simple reason. When ARIN Online changes how access works, it changes how fast I can get a stranded client back to managing their own resources, and that gap is where I spend my working life.
Conclusion
Here is where I land. ARIN made the right call. Passkeys are stronger than passwords, and email-based recovery was a phishing surface worth closing. But strong authentication with no automated fallback turns preparation into your only real defense, and right now a great many holders are running their entire registry presence through one person and one device.
The cost of that has shifted. It used to be a minor inconvenience and an email. It is now business-hours-only recovery, identity verification under pressure, and a queue that does not care that your routing data is going stale. The fix is cheap and low-tech. It is a second administrator with a backed-up passkey and a runbook that tells the truth about how recovery now works. Stand that up this quarter, while it is still a ten-minute task you control, and the next departing laptop stops being an outage you cannot self-serve out of.
Frequently Asked Questions
There is no automated email reset anymore. You must open an Ask ARIN ticket or call the Registration Services Help Desk at +1.703.227.0660 during business hours and pass identity verification against your Point of Contact records. If you have a second enrolled credential, enroll a replacement passkey yourself and skip the queue entirely.
No. Email-based Point of Contact recovery has been retired as of the 26 May 2026 update. Recovery now runs only through an Ask ARIN ticket or a call to Registration Services, both staffed by people during weekday business hours.
No, they expand the menu. ARIN added industry-standard passkeys to the existing multifactor options and publishes a tested-device list, so you enroll a passkey alongside your current method rather than swapping it out.
Because the automated fallback is gone. Previously a locked-out contact could self-reset by email; now recovery depends on a human at the help desk verifying organizational authority during business hours. If your one admin holds the only credential and leaves, you wait until the desk opens and someone can re-establish authority.
Enroll passkeys on at least two administrators and back each one up to a second device or hardware key. That one change converts a total lockout from a multi-day help-desk ordeal into a self-service replacement you handle in minutes.