Apart from my dayjob I have whois objects in DNS registries so i know there is the other side of the coin. I see the bad stuff from choosing not to hide my ID.
Apart from my dayjob I have whois objects in DNS registries so i know there is the other side of the coin. I see the bad stuff from choosing not to hide my ID.
As far as I understand, the WHOIS system was made in the 80s when it was useful to be able to look and ring someone up. Literally everything was in beta on the arpanet, and direct communication makes debugging a lot easier. But it's 2018, and I do not want 4chan to be able to look up my home address in that system. That creates more mayhem than it's worth by far.
Thinking about what use I ever had from the whois system, I guess it's only abuse email addresses for IP addresses. And I hear that people make use of the registration date of domains to calculate spam scores. Neither of those require the registrant's private information to be in there.
I was in the WHOIS as was from SRI-NIC. I kept GM85 in my current nic-hdl for resources as a memory of the days gone by: they even published a paper copy of the listing.. the phone book of the internet, how .. quaint.
Yes, the protocol is designed for days gone by. but the GDPR laws apply to RDAP, even though it has HTTPS and could in principle use Oauth or similar to constrain whats shown to open access.
whois has been useful to me in the past for finding out whether a DNS name is held by the foundation/company/trust/whatever or if it's held by a private individual who set up the foundation/trust/whatever. When a whois lookup shows a certain private individual listed as owner, admin, and tech contact for some DNS name, then I can know the foundation is a sham created to make it look like the open source product is community controlled, when in fact it's really just one narcissist pulling the strings.
I say keep the whois service as is.
Which governments, where, and at what time? North Korea has a NIC, so does Eritrea. Should the dictator of Eritrea have more privileged access to your WHOIS information than somebody who could actually give you a productive tip? (i.e. "Hey, your mailserver keeps trying to relay this message, which is not destined for where it's being routed", or "a host under your domain is ICMP flooding my IoT gateway, maybe you have an unwanted access on your hands"). I've used WHOIS productively in the last year, and WHOIS proxies work to get your address off the registry, I just don't think that the actual owner of the domain (you, domains by proxy, etc.) should be permitted to register a domain without somebody being directly responsible for its behaviour in some way which is a step before a civil suit (which seems to be the only way your system would work). You need an address for your corporation as well, it's mostly the same idea.
But there is no need for a full postal address of real email addresses that people might use for personal contacts or a real name. That just leads to more abuse.
Same for phone numbers.
The registrars have an interest in not delivering requests for sale or even abuse reports, because it's likely that they will result in the domain either being decommissioned or moved to another registrar.
WHOIS Privacy Services have been doing exactly this for a long time and they are usually paid by the domain registrar.
I think that problem is more imagined since there doesn't seem to be this problem in the real world.
Yes, but crucially they are not the domain registrar, and that's because this was already a problem.
Honest and good registrars don't have a problem with WHOIS services, you claim they would since the emails they forward could lead to lost sales.
The WHOIS service is just as incentivized to filter out certain mails since they are paid by the registrar and thus get profit of sold domains.