European regulators reject latest proposal by ICANN over its Whois data service
theregister.co.uk
theregister.co.uk
- abuse contact info
- registration date
(The latter is used in spam score calculations, I've heard.)Neither of those are the registrant's private information. I don't understand why we're pushing to have private data in a public directory in the first place. (I never understood this, but being young, I first registered a domain around 2008, long after it was common to ring Joe from USAF up because their FTP was down.) The registrar has to store it for billing anyway, so if a domain is used for something illegal, the police can get at the info anyway...
So ideally, in case they don't provide an email, one would not do that.
I get offers for my domains, all unwanted.
If I at some point decide to sell one of those to one of them, all the cold approaches from the past don't suddenly get legitimized.
edit: as I'm writing this, I remember that this is quite similar to the selling of social media IDs. Some random crypto start up decided that they should try to bully me to sell them my three letter Twitter handle. Really annoying.
My state department of motor vehicles maintains a database of vehicles registered in the state and the contact information for their owners. While they do not have a convenient website for querying this data themselves, they make it available to third parties in bulk, and I can obtain individual records for those third parties convieniently using their websites.
Both these databases are mandated by my state legislature. So it seems the same reasoning does apply.
Another difference is that this contact information does not, AFAIK, include recipient-paid [1] contact methods such as mobile phone (including text) and e-mail. Also, methods such as phone are generally considered far more intrusive that, for example, paper mail.
[1] nowadays this is mosty nominal, but we're not quite at zero
Not true. Many people don't realize the value of what they have. And/or they won't see a message because of spam etc (could argue that this happens with whois also but generally the more clues the better).
Note that with physical real estate it is often purchased by someone wanting a property that has no sale sign. Also (per my other comment) there are many people who don't know the value of what they have.
So it's not a signal at all in many cases (I have over 2 decades of first hand knowledge of this btw.)
Besides it all comes down to price. You may not want to sell your house but if someone comes to offer you 3x what you paid you might listen to them. You may 'not want to sell' for what the market price is. Selling prices for domains are all over the map.
But I do see your point. On the one hand, I'd suggest an optional "reach the owner" part of whois, where one could list a physical or digital address (doesn't even have to be email, I sometimes list social network presence on "about" pages as contact method for unimportant sites, to prevent spam). But on the other hand, we already have a place where you can optionally put your contact details: the very website we're talking about. And there you can apply any anti-spam measures you want, which you cannot do if it's in a public directory somewhere.
I think it's fine if people have to publish their contact info themselves.
If the registrar is in the middle, they have a considerable interest in failing to deliver sales inquiries, because they will tend to lose out on them. Same with certain types of abuse inquiries. The registrar has a conflict of interest with most forms of legitimate inquiry on a domain. If the registrar allows unfiltered messages, or messages whose content is entirely unknown to the registrar, then you're back to square one, because the end address ultimately has to filter the spam.
Simply write delivery into the contract, and require fees paid to the registrar from any party sending mail through the service (i.e. stamps).
Critically, if one were going to do this, allow the domain owner to black hole all communication via this path if they're not interested.
Think figuring out who a given prefix belongs to, what routes are advertised by an AS, what BGP communities does an AS honor, how to contact an organization's NOC ...
(yes, whois is for more than just domain names)
Those who buy and sell domains are another group who are annoyed that it is no longer public. They can easily solve the sell-side issue but when they want to buy a domain, if the owner is not specifically trying to sell it then it becomes more difficult to get ahold of them to make an offer.
However I will add something else.
If it becomes hard for people/companies/startups who want to buy domains (.com as you know is all that typically counts) (or for brokers etc) then there will be a shift away from .com because of that frustration. Right now people start perhaps with another TLD but once they get successful they try to get .com almost always. And that supports the market price of .com
So sure the big time people (who charge 'high' prices) will make it possible to be reached. However there is another tier that either forgets to put up contact info (or it's out of date on a web page that gets spam) or does not even know they have something of value. Those owners, if they can't be reached, will miss out. And the buyers would be more likely to then go for another TLD. Hence .com in general could loose value. [1] Not overnight but will happen.
[1] I both own domains (since 90's) and help people buy domains. This is actually my big concern with 'help people buy domains'.
As for buying and selling a domain, I've commented on that in an earlier sibling thread:
> If it's important enough, I guess the registrar could be used as relay.
>But I do see your point. On the one hand, I'd suggest an optional "reach the owner" part of whois, where one could list a physical or digital address (doesn't even have to be email, I sometimes list social network presence on "about" pages as contact method for unimportant sites, to prevent spam). But on the other hand, we already have a place where you can optionally put your contact details: the very website we're talking about. And there you can apply any anti-spam measures you want, which you cannot do if it's in a public directory somewhere.
> I think it's fine if people have to publish their contact info themselves.
There are a bunch of people in this thread claiming that "WHOIS ... won't be missed" or "nobody uses WHOIS properly these days", and it just gives me the impression that a) they operate delinquent, abusive domains for which they receive calls or b) they think that because they haven't used WHOIS productively, they never will. You'll miss opiates when you're in pain.
https://www.recordedfuture.com/whois-gdpr-icann/
The reason that security researchers have had success with using WHOIS data is twofold. The first is that many attackers, even sophisticated attackers, have had poor OPSEC (operational security) when it comes to registering domains. A surprisingly large number of attackers simply didn’t bother to take steps to hide their identity or create unique, fake aliases when registering domains. Spammers were notoriously bad at hiding their identity, making it easy to identify newly registered domains as belonging to a known spammer and immediately adding it to block lists and real-time blackhole lists (RBLs).
Secondly, even attackers who realized their mistake and changed the WHOIS information of their domains after the fact, or added privacy services to the domain, were out of luck because certain companies, such as DomainTools, keep track of historical WHOIS data, and researchers could easily see the original WHOIS information.
Apart from my dayjob I have whois objects in DNS registries so i know there is the other side of the coin. I see the bad stuff from choosing not to hide my ID.
As far as I understand, the WHOIS system was made in the 80s when it was useful to be able to look and ring someone up. Literally everything was in beta on the arpanet, and direct communication makes debugging a lot easier. But it's 2018, and I do not want 4chan to be able to look up my home address in that system. That creates more mayhem than it's worth by far.
Thinking about what use I ever had from the whois system, I guess it's only abuse email addresses for IP addresses. And I hear that people make use of the registration date of domains to calculate spam scores. Neither of those require the registrant's private information to be in there.
I was in the WHOIS as was from SRI-NIC. I kept GM85 in my current nic-hdl for resources as a memory of the days gone by: they even published a paper copy of the listing.. the phone book of the internet, how .. quaint.
Yes, the protocol is designed for days gone by. but the GDPR laws apply to RDAP, even though it has HTTPS and could in principle use Oauth or similar to constrain whats shown to open access.
whois has been useful to me in the past for finding out whether a DNS name is held by the foundation/company/trust/whatever or if it's held by a private individual who set up the foundation/trust/whatever. When a whois lookup shows a certain private individual listed as owner, admin, and tech contact for some DNS name, then I can know the foundation is a sham created to make it look like the open source product is community controlled, when in fact it's really just one narcissist pulling the strings.
I say keep the whois service as is.
Which governments, where, and at what time? North Korea has a NIC, so does Eritrea. Should the dictator of Eritrea have more privileged access to your WHOIS information than somebody who could actually give you a productive tip? (i.e. "Hey, your mailserver keeps trying to relay this message, which is not destined for where it's being routed", or "a host under your domain is ICMP flooding my IoT gateway, maybe you have an unwanted access on your hands"). I've used WHOIS productively in the last year, and WHOIS proxies work to get your address off the registry, I just don't think that the actual owner of the domain (you, domains by proxy, etc.) should be permitted to register a domain without somebody being directly responsible for its behaviour in some way which is a step before a civil suit (which seems to be the only way your system would work). You need an address for your corporation as well, it's mostly the same idea.
But there is no need for a full postal address of real email addresses that people might use for personal contacts or a real name. That just leads to more abuse.
Same for phone numbers.
The registrars have an interest in not delivering requests for sale or even abuse reports, because it's likely that they will result in the domain either being decommissioned or moved to another registrar.
WHOIS Privacy Services have been doing exactly this for a long time and they are usually paid by the domain registrar.
I think that problem is more imagined since there doesn't seem to be this problem in the real world.
Yes, but crucially they are not the domain registrar, and that's because this was already a problem.
Honest and good registrars don't have a problem with WHOIS services, you claim they would since the emails they forward could lead to lost sales.
The WHOIS service is just as incentivized to filter out certain mails since they are paid by the registrar and thus get profit of sold domains.
How can this be?
You don't have to publish any contact information on non-commercial websites.
The E-mail address does not need to be your personal address, Lufthansa uses impressum_de@lufthansa.com and I don't see a reason why this would not be acceptable.
The postal address does not need to be your personal address, a business address is fine. Well, if you are a 1 person business run from home I am not sure. Go to court and have it tested up to the constitutional court, why Carsten Spohr (CEO of Lufthansa) gets better data protection than you do.
Yes, your real name has to be on a business web site. That's obviously the price to pay to run a business. As a potential customer wasting my money on fake service or otherwise suffering from a breach of contract, I think this is a good thing.
Edit: actually after a bit more thought, it’s more nuanced than my somewhat glib response lets on (since there’s also an exemption for contractual obligations).
The answer is likely that a) the law hasn’t been tested in the courts under GDPR and/or b) the Government requirement has the additional test of providing a service, which may alleviate the privacy cost sufficiently.
Get a Postfach for a few euros a year, put it on there, and be done.
The imprint requires an address that permits receiving legal notices (ladungsfähig), ie, an Address where you as a person can be found.
In that case, shouldn't the trick via a UG (Haftungsbeschränkt) still work?
ICANN is illegally collecting protected data when requiring personal data for WHOIS without having any reason to do so, and that's the problem here, the conflict. But in the impressum, it is you that is releasing data, not someone collecting, and that is not conflicting with the DSGVO.
Maybe it would be possible to argue that Germany is collection that data de facto, or that it is illegally enabling illegal data collection by third parties, and suing the country for that in an EU court. But that is not a winnable fight, they'd argue that they are not collecting the data, and that there is a valid reason to force the release of the data.
To simplify though, services and goods aren't priced purely according to what they cost to produce. You're thinking "the cost of production is the same, but a source of secondary profit is gone, so they have to raise the price of domains to compensate".
But actually the price also depends on what people are willing to pay. And that hasn't changed.
Even using "whois privacy protection", I've always anonymized my contact information. I've used a working email address, of course, so I can manage the domain. But there's no reason to provide a physical address or telephone number. I tend to use hostels and business hotels.
Also, while this will protect those registering or obtaining domains going forward, historical data is widely available.
Except for that ICANN rule that if your information is incorrect, your domain name can go bye-bye at any time.
And for critical domains, you can just hire trusted third parties to manage them. There are law firms that specialize in stuff like that.
Well, I guess that means it will never happen in the future either then.
So you've lied on the form. While this may have worked for you, it obviously cannot be the standard way. The law cannot be made on the assumption that users can just lie.
Given ICANN is a US based company, I believe they can terminate the contract with all European registries for unable to fullfill the terms in contract.
I think it makes a lot of sense for a domain registrar to keep basic information in the long-term, about who registered what. I find it odd that this has become a point of contention.
Less clear why ICANN needs to store that data too, I think it's right that they should have to properly justify that. ICANN has made up rules however they liked forever and ignored warnings about privacy for over a decade, and about GDPR specifically for years, so I have to admit I have little compassion for their self-created problem here.
Paraphrased:
Yes, of course you can keep registration data for your own legitimate usage. Contact information for the lifetime of the domain is fine.
Storing it for 2 years after expiry is not necessarily problematic, but you need to document why you legitimately need it.
You can't make private contact information public without consent.
However, you can disclose it to 3rd parties who make a legitimate request, but you should record the request.
GDPR is a negative development for openness, tranparancy and interconnectivity.
Well its certainly beneficial for privacy. There are very few social media sites in the world where publishing other people's contact details without their permissions is allowed. Its banned here. Its banned on Reddit. And a ton of other sites. There is really very little difference.
How would you feel if all HN submitters had to list a personal phone number? Why is running a website any different?
GDPR does not limit the collection of data that has a legitimate business use as long as it is used for that business use only and removed when the use no longer exists. Otherwise how could you do billing?
Plus, things keep moving so fast (almost arbitrarily sometimes) that I wonder whether it's worthwhile. Fundamentally, the issue is this:
US intellectual property lawyers are very well organized and have the backing of big corporations. As a result, they have a disproportionate influence in US organizations - in this case, ICANN.
With each new proposal, each new rule, each new policy, these (very smart) IP lawyers find ways around it to suit their main goals. And because ICANN, unfortunately, has no moral or ethical center, it tends to bend its own policies to accommodate whoever is the most powerful and/or loudest on any given issue. In this case, the American IP lawyers are very driven to retain the existing system.
But in this particular case of Whois they have come up against a brick wall of decided European law.
And they have been trying to find ways around it, pressuring ICANN into a series of policy positions that are very clever but can't go anywhere because the law is settled.
Plus the data regulators are the people in charge of deciding how it is interpreted. And they, naturally, have a fairly strict interpretation of GDRP.
It's worth noting btw that European governments have often ignored the data regulators in favor of their own corporations (just take a look at the whole Privacy Shield debate). But in the case of GDPR, the data regulators are in the driving seat. At least for now.
So I could give a detailed rundown of what ICANN has proposed, and how it has changed, and how it is going to change again. But in truth it doesn't matter - ICANN and the IP lawyers will try on any new interpretation they can think of to get what they want - access to the contact details of every domain name - and they will discard any or all of them as soon as they no longer further that goal.
What's really happening is that ICANN has, for the first time, hit a situation where it doesn't get to decide for itself what happens.
As such this Whois/GDPR process is shining a spotlight on the dangerously flawed policy-making process of this critical organization where it keeps insisting on transparently bad policies, keeps putting forward arguments that don't make sense, and keeps trying to bend its own processes to fit with a pre-determined conclusion.
And the Europeans look at it, say No, and the whole facade comes crumbling down. And that is causing massive temporal dissonance at the organization in charge of the internet's naming and numbering systems.
That's what this article is about. And it's unlikely to be the last.
Well then I'm not surprised, if they keep coming back to the point where information is public... no matter what additional things you think of, if the fundamental issue is not solved, I cannot see how it would ever be compliant with any privacy law (either GDPR or even the DPA from 1995).