Save .org
savedotorg.org
savedotorg.org
https://www.theregister.co.uk/2019/11/20/org_registry_sale_s...
"Former ICANN CEO Fadi Chehade personally registered the domain name currently used by Ethos Capital in May and it was registered as a limited company in the US state of Delaware on May 14. That date is significant because it is one day after ICANN indicated it was planning to approve the lifting of price caps through its public comment summary.
As such it appears that the plan to purchase the .org registry was predicated on the price caps going ahead and that those behind the deal had intricate knowledge of ICANN’s internal processes."
I worked at one of the main TLDs for years and was on one of the ICANN boards and got to know the industry well.
It is well know amongst the domain name community that ICANN is a poorly run organization, whose directors have in recent years have used their position of leadership to lead decisions from which they are afterwards benefiting themselves economically, in many cases by rushing decisions such as in these case.
Peter Dengate Thrush was famous for pushing for the new domain extensions (.anything) as chief executive of ICANN and quitting a month later to become the CEO for a company that was the main bidder for a large number of extensions. Fadi Chehade is doing the same with .ORG by lifting the price cap on the prices of an established domain name and then gobbling up the company that sells those domains.
Sadly, ICANN has little oversight and since its kind of in the air and doesn’t report to anyone, the directors get away with what would be legally considered corruption in most of the world. The fact that the internet community and most Internet companies have never care about it makes doesn’t help, since a lot or times the “multistakeholder” model that they claim to use in reality doesn’t work.
Ultimately, this is why the DNS and domain name industry feels so shady in general and why for most companies getting a name on the internet is a tortuous process that feels very scammy, which is unfair and costs more than it probably should. But so far we don’t have any good alternatives to the current system.
Full disclosure, I was one of those at-large members and they made it very clear that we weren't being good little peons.
Now ICANN? They seem a bad choice, as this story demonstrates. Tolerable as long as the internet wasnt very important, but today, a UN international body seems the obvious choice.
For example, ITU also controls country code assignment for phone numbers. Does that translate to any meaningful capacity to censor? So far as I know, the only practical restriction that comes out of it is that unrecognized states don't get one assigned, but that's also generally true with TLDs.
At the time, consensus in the media seemed to be that this would have little effect. However, the debate was quite politicized, as the transfer to ICANN occurred towards the end of the Obama administration, with fruitless opposition from high-profile Republicans.
There is a reason for this, the American media is laregly Anti-American today. They believe in idea of "American Imperialism" and that America is the cause of most of the worlds problem. Thus they believed anything was better than "Corrupt American Control" over the internet.
There were many many people that predicted bad outcomes from this transfer, most are starting to come true
This article suggests Public Interest Registry's costs for third party technical services were about half their revenue, with the beneficiary of the rest of the funds being the Internet Society https://domainnamewire.com/2019/10/28/pir-org-slashes-regist...
Still, you can see why those kind of margins and the ability to raise prices were an attractive combination to private equity
I use Cloudflare Registrar these days for .com and .org. They claim to offer wholesale prices. My last .org bill was $9.90 + ICANN fee. And according to [1], Cloudflare directly work with PIR to offer .org, so unless they're lying, they are actually charged $9.90 per domain per year by PIR. Now, the article you linked to claims that PIR paid less than $2 per domain to the for-profit contractor who did everything technical for them (what's left? PR?). I wonder where the remaining $7.90 went...
[1] https://www.cloudflare.com/tld-policies/
Edit: Apparently overlooked the beneficiary part. Not a fan of mandatory donations but at least the numbers sort of add up now.
Setting up the peering replication and nameservers around the world is considerably harder, but it's definitely not a $10 billion+ problem (the current value of registrars and certificate authorities.) A startup funded by YC could handle that easily.
Dealing with all the companies trying to sue you over others squatting their domains and having to decide who has the better claim would be the most expensive part.
I really hate to say it because it's so cliche and overused, but a blockchain-like system could remove the central authority, the server costs, and the lawsuit risks. But it would introduce concerns over trust, most likely.
The really hard, unsolvable part is the unwillingness of the browser vendors to support an alternative domain name system. If Chrome, Firefox, and Safari all supported a new TLD outside of ICANN's control as a public service (let's call it "Let's Resolve" which would offer free domains and would be funded through donations), it would be very successful. If even one of them didn't support it, nobody would ever consider using it for their websites. Browser extensions, even if they allowed access to intercept domain name lookups, would not work. It would have to be supported out of the box in every major browser, and well, good luck with that. Anything failing to herd those three cats right out of the starting gate is absolutely dead on arrival.
Who knows though, maybe they'll raise .org prices just a bit too much, and piss off an established non-profit enough to start a huge campaign to create an alternative. But probably not.
Not sure I understand your proposal. Say every single browser in the world supports Let's Resolve. byuu.org is registered with ICANN; but someone now wants to register byuu.org with Let's Resolve. Do you let them? What about the other way round? And what if someone attempts to register byuu.org with ICANN, while another attempts to register byuu.org with Let's Resolve at the same time, causing a race. Who wins?
Also, unique, meaningful and memorable identifiers are a scarce resource. Offering free domains just open up the floodgate of squatting and hoarding (at unprecedented ease).
Edit: Parent suggested a new TLD; I read it as a whole alternative system. Well, the new TLD idea was already implemented as .bit AFAIK, and it's pretty crap.
http: and https: use ICANN, httplr: and httplrs: use LR
If not specified, browser tries LR first, then falls back on ICANN.
Doesn't feel as solid to me, but they could also register a placeholder TLD that would be use for redirecting requests to LR, or the other way around:
google.com.lrns would tell the browser to resolve google.com in the LR root (hardcoded), or google.com.icann would tell the browser to resolve google.com in the ICANN root. When falling back from one to the other, the browser would display the hostname with the fallback TLD on it.
Just some ideas off the top of my head, I haven't fully considered the implications yet.
I think it could be better to just accept that unique global names are not a great idea, and start identifying parties by certificates rather than name. Various chain of trust & reputation type arrangements can be used to ensure people won't confuse Their Bank (certificate issued by/for Their Bank) for Their Bank (certificate issued by & for scammer in Ukraine). Legit entities will have every reason to include information that minimizes likelihood of confusion.
Come on, I can have more than one James Smith in my phone's contact book too.. let's stop fighting over names.
The problem of course is that as you said, you still need authorities or a chain of authorities to tell you which one is the genuine Debian and which ones are trying to shove malware onto your machines. Today we go to debian.org, see the valid TLS cert, and assuming there’s no fraudulent issuance of debian.org cert and no attacker injected their cert into our device CA store, we can be reasonably sure the PGP key listed there is genuine.
You only need to look at .onion to see how well the keys without authorities idea turned out.
For example, I'll be happy to add and pin my government's authority for the services that they control. I'll be happy to add a group of FLOSS hobbyists issuing certs for open source projects, as long as they are transparent and can demonstrate that they have a handle on security. In both cases, there must be some way to limit the scope of their authority, and ideally do things like pinning the authority so that one can't sneakily take over the other in an attack that results from e.g. misconfigured scope.
I think establishing identity is something that we should learn to do. When John Smith gives me his phone number, I'm probably looking at his face and I know which John it is that is giving me their number. I should also be able to go to my bank and get their cert when I sign up for an account & credit card. I'd like to have additional confirmation of their identity (-> reputation) e.g. from my government, but I don't know if I want them to be automatically trusted just because there happens to be a chain that checks out.
If I'm looking at some entity that I cannot meet in person, I should be able to see who have vouched for their cert and make a judgement based on that.
Kinda like PGP I guess, at a larger scale and with better infrastructure (geek signing parties and wide open keyservers are not good enough). The system does not need to be centralized.
It should be possible to have certs signed by multiple parties, to help establish trust without having everyone agree on a single source of trust. (At this point, I'd like to use a term that sounds smaller and less powerful than authority)
I'm not particularly happy with the model where the chain of trust in every case is established starting at some international megacorps that do who know what, and countless issuers are directly or indirectly "trusted" from the get-go until someone points out their abuse and removes their certs.
I don't know how we stop squatters, maybe a one-time registration fee would be reasonable, but that would be discriminatory as $100 would be trivial for developers in the US, and impossible for service workers in Mozambique that just want a personal website.
It's not as though .com/.net/.org (and heck, even a lot of the new gTLDs) aren't absolutely filled to the brim with squatters already.
us.whatever: $100 mz.whatever: $0.80
I would agree with you in principle however, in which case there's an even more impossible goal: get Microsoft, Apple, Google, and every Linux/BSD distro to agree to a new OS-level alternate domain name resolver that functions out of the box. And also stop Google and Mozilla from rolling out browser-level DoH.
Then it wouldn't need to be done by any browsers... if the DNS-over-HTTPS end point provider does the additional name resolution, it should "just work".
I see what you’re saying in theory, but it can’t be cloudflare or a private company or else it’s more of the same.
Browsers should respect the OS instead of trying to circumvent it.
Lastly, DNS is properly decentralized out of the box. I don't get that some people who argue for a decentralized internet also argue for DoH.
DNS is also not decentralized. It's centralised on ICANN and whatever company owns your TLD which is why this thread is here.
Someone tell the guys pushing DNS over HTTPS that.
See DNS Wars, Episode 6: "Resolverless DNS":
* https://blog.apnic.net/2019/11/04/dns-wars/
* https://www.ietf.org/mailman/listinfo/Resolverless-dns
('Amusingly' I cannot view the mailman page because Cloudflare DDoS protection is blocking me. The same CF that is doing DoH for Mozilla.)
Fully automated system will only care about keys and cannot hand apple.com over from Apple Inc to Tim Apple because of his name.
Not if the owner lost all proof of ownership, which is the assumption your argument is based on.
You don't walk into a court and have the judge say "what you don't have the receipt?! case dismissed!!" -- the judge isn't a parking meter.
Browsing adoption is tricky, but people can point their DNS to Handshake resolvers pretty easily — it’s equivalent to switching to ‘S 1.1.1.1 service which many people already do.
The blockchain idea could work. There is a coin called namecoin which attempts to do this. I think on end user devices we should still use DNS so you don't have to store a 1tb blockchain on your device but the blockchain could be what the DNS servers source their data from.
(2) Every major OS has has a way to plug an alternative DNS resolver (except maybe iOS), and every major browser has a control to switch off the DNS-over-https resolver. With any goodwill from the major mobile OS vendors, a new resolver could be rolled out to 99% of consumer devices or so, and work transparently.
(3) A new name resolution system should not clash with the DNS namespace. It could allow to copy established DNS domains (not parked) to the new namespace for a nominal fee.
(4) Many DNS tricks, like load-balancing, could go away. Running your own name server can become harder. The transition, should it occur, would not be fast.
Namecoin though has always been around to reserve names and in particular domain names.
The only way I can think to end the corruption is to take away the financial incentive, and AFAIK that would mean either the government runs anything that makes a profit, or to remove price completely.
Shady is putting it lightly.
I once tried to register a nice .wiki domain in order to host a wiki for myself. Those domains weren't available anywhere. I had to "request" one from the company that managed the TLD. So I emailed them and they asked me about my "plans" for the domain. Eventually they just said they'd host it on my behalf. They created a wiki on the domain I wanted, threw ads around it and told me to start contributing.
It's not really an equal playing field where anyone can buy a domain. They gatekeep not only by charging huge prices but also by simply refusing to sell the domain if they think you're not important enough.
People should start making more onion services.
A practical DNS replacement would be nice. Something not amenable to governmental or legal attacks, or straight-up corruption like this.
You might be interested in checking out https://handshake.org which is trying to create an alternative to the existing ICANN system that is resistant to censorship and seizure. The technology is really interesting and we’re building on it ourselves.
When you remove/replace the buzzwords that sounds exactly like a CT log, which is also a Merkel tree.
This is why the US Dept of Commerce should have never given up control
That is one good way to bring corruption into light.
That's right but the right to get rich by corruption is the most important and most appreciated unalienable entitlement of US weenies, even more important than food or shelter or life itself. After all, in a thoroughly corrupt system all of those can be bought. Only corruption itself cannot be bought if the system doesn't already have the necessary level of corruption. It is the US's holiest mission to convince the rest of the world of the fundamental importance and indispensability of our way of corruption.
Here's the initial letter being sent from EFF & others to ICANN and the Internet Society: https://www.eff.org/document/coalition-letter-sale-public-in...
(Disclaimer: I work for the Internet Archive, and we are one of the initial signatories to this letter.)
With a better governance model.
.ORG should be properly managed and regulated, we shouldn't need to attempt to rebuild something because ICANN is corrupt and Internet Society is selling out non profits they promised to serve.
Do you even know how many accounts have that email address as either the primary, or backup/recovery email?
An email address is central to identity management these days.
Lose a long established domain, and you might lose access to most of your other internet accounts, especially the ones you don't use every day and are hard to remember.
I find it just awfully sad (and probably corrupt) that this happened at all, and I really hope there's some higher authority that can roll this back - or at minimum bring back the price-cap.
Very sad times.
Imagine a world where whomever has the most money can control your brand. What happens when McDonalds buys the Burger King brand because BK was priced out?
.com, .org, and .net are long standing shared resources that should not have unlimited prices. They should be capped forever.
It will be more site the kind of wikileaks that could get effectively removed without having to go legal routes. Just have your friends price them out of their domains. Nobody needs to even buy the domains, they just need to be expensive enough to stay unused.
There are ways to circumvent DNS so long as IP works (I mean the "Internet Protocol suite"[1], "TCP/IP", the real-world implementation of OSI if you've been taught that theoretical model).
Maybe a 'public darknet' (a parallel "white net" really, nothing shady about it, by "darknet" I refer to how it works technically[2]) wherein we don't care about a global DNS, and use links + light VPNs to browse internal (firewalled) resources — I'd wager it's doable using tokens to auto-validate public VPN access like we'd greenlight an SSL connection, essentially, probably some 3-way handshake. The whole thing would be public, just circumventing DNS/TLD hierarchy, so indexes etc. would work just the same (it doesn't break Google Search).
A neat bonus is that companies could use whatever name scheme they like, "store.sony" would work, and even collisions could be resolvable through aliases.
Whatever works but if current DNS/TLD's become a corrupted theft, the world will definitely move away from it — and we don't exactly look back for these major PITA standards.
Just look how quickly DoH is being rolled out, or Google's QUIC.
Realistically if Google, Mozilla, Cloudflare, Apple, Microsoft, and a few others agree that this move is bad, and wanted to stand up a new .org TLD...they could, and I don't believe it'd be illegal (IANAL).
What's to stop them from being just as corrupt? It's too much for any one country to have control over. It'd be far better to come up with a way to take the power out of the hands of any one entity so that we don't have to keep moving it around when the people holding all the power are inevitably corrupted by it.
I think we actually experience a mild version of this today, where entities publish their all their Twitter/Facebook/Instagram/Snapchat/Whatsapp/Linkedin etc profiles.
I can't help but see whatever this distributed DNS replacement is as basically being this situation but without the backstop of globally-accessible websites and e-mail addresses. You should have no doubt that, for example, Facebook would make a "the internet" which was 100% Facebook-operated sites.
DNS worked just fine with nonprofits and government entities who weren’t leeches.
And you don't see companies posting their addresses on those things. They still advertise "example.org" not "if you're in {county} use {county-specific address}, or on Tor use {onion address} or using {decentralized DNS} use example.com".
> A dominant decentralized system
How does this result in a different situation then the "centralized" DNS we have today?
If, for instance, the DNS entries were tied to entries in a blockchain, such as namecoin, then no 3rd party would be involved in a transaction to transfer the domain, no annual fees would be required, and no one could block or remove an entry.
AOL already tried that back when they were still sending floppies through the mail. They were the largest ISP on earth and couldn't keep people in their little walled off corner of the internet. I don't think anyone else is going to be more successful.
Remember when TV commercials would tell you a company’s AOL keyword?
At AOLs peak, it had about 35 million subscribers. Comcast alone has nearly that many.
Handshake Name Service (HNS) is working on this problem from an interesting angle, with some significant institutional support.
The DNS equivalent technology there is DHT(distributed hash tables) [3] which was used in torrent technology for a few years. Ever wondered about how you can find the torrent seeders without a centralized entity? The Bittorrent DHT is the underlying tech.
[0] https://ipfs.io/
The Bittorrent DHT is not fully decentralized, it needs a list of hardcoded bootstrap nodes. https://stackoverflow.com/questions/1181301/how-does-a-dht-i...
Anyone can make an alternative client that uses the exactly same tech with different bootstrap nodes, and once they gain popularity, there will be people using that.
Democratic, I would say.
So in practice you can get peers from the list of previous peers, PEX (peer exchange), or a tracker for a given torrent.
So in practice once you talk to a few bittorrent peers (of millions) you likely are talking to another DHT peer and can bootstrap. Also given that there's typically millions of peers in the DHT, even brute forcing it by search IPv4 (4 billion addresses) for a few million peers is likely to only involve a few 1000 UDP packets or so.
We could achieve the same result with laws. Just make what is happening illegal, corruption is already illegal.
Furthermore, decentralization won't solve the basic economy rules of offer/demand. Even with a decentralized system, website will still be referenced by natural words ("domains"), which can be owned by only one site-owner at a time, which means there will always be people ready to spent a lot of money to acquire a domain/reference.
I'm for decentralization in general, but in the current case I fail to see how decentralization alone will make domain owning fairer
The problem is that organisations have to rent their domains from a central authority that can hike the rent for an entire TLD to some fantasy price.
So the hierarchical structure of DNS is clearly what creates an opportunity for corruption and extortion.
And let's not forget that DNS is ultimately a global issue, which means that the rule of law cannot be taken for granted.
Laws have to be part of the solution. But it's easier to legislate effectively if the underlying structure doesn't invite corruption, authoritarian abuse and market dysfunction in the first place.
I think this strongly points towards ccTLDs being the best solution. It is very difficult to get all the different countries to agree on common rules/governance for the legacy TLDs, but if everyone gets their own independent corner then that should be easier to get agreements on.
Dividing the control by country also conveniently avoids any single one being able to cause as much damage as ICANN now is.
The companies and/or owners of those services do operate under a certain legal aegis, though. It’s not like they are stateless.
I just happened to read the text on a food product; it had text in three languages, and the www.* domains listed in the three texts were in the ccTLD for each country. No .com was mentioned anywhere.
Should I really have to remember going to apple.ie because that's where the Apple shop happens to be legally based at the moment? Or should it be apple.eu because consumer protection is an EU matter? Or apple.us because that's where Apple's headquarter is located?
And when a company gets sold to a different country, should all their URLs have to change?
A company is an entirely legal construction, and, as such, is entirely bound to the laws of a certain country.
History proves that to be false
Further "just make it illegal" under which nations laws? That was the problem ICANN was suppose to solve, no one wanted the internet to be operated under the Laws of the US, which is why in 2016 the US removed itself from Internet Governance.
So do we put the Internet under the laws of China? or the EU both of which have Free Expression issues....
Which nation? or maybe the UN which has Dictators and human rights abusers in positions of power...
Decentralization is far far far better than looking to a government resolution
I think a good solution is to switch to using petnames instead of global names.
https://www.schneier.com/blog/archives/2006/02/petnames.html
GNU is also on .org.
Also languages, at least Python, Ruby, Haskell, Rust, Go, Clojure, Racket, Zsh, etc.
.org seems to be the go-to TLD for open source projects.
This is an incredibly awful move, I'm completely astounded that it was allowed to happen.
Why not just move to a different domain, and while your old one is still "cheap", do a redirect etc?
It completely depends on what they do, I've renewed for 10 years so I have time now, if they put the fees to >500 a year then I'll definitely move.
Do you own a domain yourself that people have been using for 10 years? You might feel differently about the ease of "just moving"
Or these project having to plonk a significant amount of money in paying for their domains rather than <insert thing which is actually useful>.
> Goldman Sachs & Co LLC. is serving as financial adviser to both the Internet Society and PIR.
https://www.bizjournals.com/washington/news/2019/11/15/resto...
> This timeline charts the most significant events in the sales scandal that erupted at Wells Fargo [in 2016]
https://www.fool.com/investing/2017/09/24/a-timeline-of-well...
> Wells Fargo(WFC)charged customers a monthly service fee to maintain a checking account that many customers assumed was free and the bank is mulling how to respond to people who feel cheated, according to the bank and sources familiar with the accounts.
https://thecapitolforum.com/wp-content/uploads/2019/09/Wells...
> Wells Fargo and an insurance company it worked with have agreed to pay $432 million to settle a class-action lawsuit brought by customers who say they were charged premiums for auto insurance they did not need.
https://www.newsobserver.com/news/business/article237666879....
IMO only fools and masochists would continue to bank with Wells Fargo.
Anyhow, Goldman Sachs have no business being anywhere near DNS or ".org" at all, at all. They're a bunch of crooks who make Monty Burns look sympathetic in comparison.
https://en.wikipedia.org/wiki/Goldman_Sachs#Controversies_an...
Whether it is this, Greece debt, 1MDB in Malaysia. Goldmans have no regard for their own reputation so we should assume anytime Goldman are advisors that the deal is a massive ripoff for which people should be going to jail. Goldmans may not have always been this way but they sure are now! They're a leading indicator of gross corruption.
It's interesting to compare ISOC's blog (https://www.internetsociety.org/blog/2019/11/the-internet-so...) and the followups like EFF's blog (https://www.eff.org/deeplinks/2019/11/nonprofit-community-st...) and SaveDotORG (https://savedotorg.org). They touch on a lot of similar themes of community and transparency - which, on paper, makes it sound like there's some meeting-ground.
As an outsider to the discussion, questions would be:
1. What are some specific problems facing the ".org" registration process for which capital/investment would be helpful? (Obviously, there's no perfect answer. But as an outsider, it looks like ".org" registration already works about as well as anywhere else, so one needs some examples to animate the problem.)
2. Would any of these folks care to improve their engagement/trust with each other? Talking more specifics about "Stewardship Council" and "Community Enablement Fund" might help. Or is some reason for bad blood?
3. What kind of track record does this private-equity shop have? Have they worked with other non-profit or socially-oriented endeavors? Maybe some founders/staff/customers can give some positive or negative testimonials?
I'm not really sure how to address the idea that we shouldn't attempt to understand and interpret what things happening now might mean for the future.
From the peanut gallery, it looks like the ball is in ISOC's+Ethos' court to demonstrate their good faith as stewards...
Now it is time to mention the 1 positive that the USA has that other countries(visibly) don't:
> The willingness and ability to sue as a collective
.org is a domain used by everyone from Wikipedia, UN, Debian and your national dog shelter.
Private Equity cares only about one thing: making money. Anybody with a toe in the finance world knows that these are the same people that will do "hostile takeovers" to strip companies of their assets, pile on debt and push out a sale.
A class-action lawsuit targeting the PE firm(or parties involved in the sale of .org) and then pushing your State Attorneys to investigate these corrupt individuals at a personal level will have the desired effect that appeals to the moral high-ground won't.
This of course is why ICANN was created, to bring governance of the Internet closer to the community that developed and maintained it. But now ICANN has become just as remote and unaccountable as the bureaucrats and contractors it replaced. And Postel is long gone, and the Internet community has grown so big and fragmented that no one person will ever have anywhere near the towering position he once did.
So now what do we do?
ICANN is accountable to nobody, whatsoever, in any capacity.
Bad at math.
Motivations:
* This issue of .org being sold for profit
* The fact that OpenNIC had to rename their TLD domains (e.g. .free to .libre) when ICANN created a colliding .free domain, demonstrating clearly that they are not peers.
Internet technologies such as browsers and operating systems should recognize ICANN and OpenNIC roots as peers, with DNSSEC to both. Should ICANN decide to create a .libre domain, existing browsers and operating systems should consider it a DNS attack and not recognize it. I think an organization like Mozilla ought to (1) flesh out any technical challenges, (2) support OpenNIC and (3) push for this.
- Their resolvers are not consistently available. Many of them are hosted on public cloud hosts (which also raises some questions about their security), and outages are not uncommon.
- It's not clear that they support DNSSEC, or that they have any plan to do so.
- The governance of the OpenNIC-specific zones that they offer is even shoddier than the DNS root itself. Most of them have no registry/registrar distinction, no domain transfer process, no WHOIS services, and sketchy to nonexistent abuse policies.
- Since OpenNIC TLDs cannot be resolved on the public Internet, it's impossible to issue a SSL certificate for one.
The last point is only true because they aren't recognized, which recognition would immediately fix, therefore it is moot.
I could be convinced that a community-based restructuring of DNS could be for the better. But I don't think that OpenNIC is the right project to base that around. The technical aspects of what they've built are not complicated, and much of that would need to be changed anyway to operate at scale; good governance is a lot harder to build.
Knowing the maintainers of the project and the community at large, I doubt they'd take kindly to opening up the project to Mozilla's support/control. They've ran a tight game, relying on their own money and individual donations. Opening it up to Mozilla's big money would bring the democracy aspect of the project into compromise.
Personally, I'd find it interesting to see where OpenNIC would go with that kind of investment, though. I've poured plenty of my time and money into the project, and would like to see it grow. Perhaps not at the expense of the projects principles, though.
What does Andrew Sullivan get for this move? Is Jon Nevett connected as well considering his ties to Donuts which is connected to Abry Partners which was managed by now Ethos Capital CEO?
So many questions, all this happening in shadows means we shouldn't give any benefit of the doubt.
It only needs Google, Mozilla, Apple and Microsoft to agree and ICANN can be made irrelevant overnight.
If you want oversight and international consensus it cannot be placed within a country. Only option I see is to put it under the UN but that will probably ramp up the politics.
Of course not. The Web is only a small part of the Internet. DNS is used by way more services than Web browsers.
To be honest I don't see this happening any time soon with the major commercial OSes. But in Linux you can install some programs to e.g. send all your DNS queries through a certain encrypted tunnel, and nearly every application installed on that box will happily use that tunnel.
Actually, I bet by now it doesn't even matter that much even there any more. Consider how the search in google already forms an effective alternative dns for many actual humans attempting to manually go somewhere.
If you have a .org domain, you can change all the non-browser uses of the domain pretty easily. The tools in the background of things don't care what the names are. You can change them and it's really not that much of a disruption.
Once someone finds your site, via their browser, you can populate that site with whatever kinds of urls and directions and references you want. Just like no one really cares how ugly and long all the urls to actual things other than the front page are. Your site can include say, the directions to access your API, and those directions don't have to say foo.org in them. Even existing api users that break if you have to change your name, can react to that change easily enough.
Email is probably the biggest problem. We will all simply have to never pin too much dependency on any single email address. But we already have to do that, so no loss.
If you had set up your own domain so you weren't at the mercy of google killing your gmail account and killing your ability to prove ownership of everything else in your life, well you would just need to have more than one email registered with everything like paypal etc. So me@mydomain.org can break and you don't die from it.
You just better realize your domain is going to break and unregister those emails everywhere before it goes into someone else's hands. Because when someone else owns a domain, then they can receive all emails sent to any name at that domain, including "reset password" mails.
It's not the most fun passtime, but it's not necessarily the end of the world either.
It really is human interactive web browser usage where the exact name matters most. So if cloudflare and google simply sent browsers to the right place and ignored the traditional root authority for .org, or any other name lookup, that would pretty much be good enough.
Google could do it already without even violating dns just through search results.
https://www.namecheap.com/blog/keep-domain-prices-in-check/
https://www.reddit.com/r/programming/comments/bi6gg5/help_ke...
https://news.ycombinator.com/item?id=19769952
https://news.ycombinator.com/item?id=19763078
I guess when the gTLD explosion didn't result in massive new profits for the new TLDs (some are $100+/year!), the powers that be decided to focus on existing TLDs instead where there's extensive decades-long lock-in effects at play. No one needed company-name.ninja, but good luck giving up your company-name.org to a squatter or worse, your competition.
Today, it's relatively easy to create something like a piece of software and a db of alternative roots. And any clients which have that kit installed are suddenly simply ignoring pieces of what the traditional roots say.
Yes it would be fractured for a while. But it's no worse than say, dns over https, and the way say, you can't reach archive.is while your browser is using doh, but can when you turn doh off. (unless they finally fixed that, but that was the situation for a ridiculously long time after both cloudflare and archive.is were made aware.)
We already have such things today, so might as well employ it as well as suffer it.
I'd like to know to whom are we giving our email addresses, and what are they going to do with them?
ICANN is currently suing a Tucows company in Germany [1] over their refusal to comply with WHOIS data collection, and ICANN published a Temporary Specification that allows/requires every other registry to hide WHOIS data globally pending the result of the GDPR court case [2].
Of course, that doesnt prevent savedotorg.org from posting their own "About Us" webpage explaining who they are.
[1] https://www.icann.org/news/announcement-2018-05-25-en
[2] https://www.icann.org/resources/pages/gtld-registration-data...
AFAIK GDPR protects personal data only, so if the savedotorg.org registrant is an entity of any kind then it shouldn't be any problem publishing that info.
What could I do in person to emphasize the point?
There is absolutely nothing defensible about this move that I can see.
Is there any argument that this is beneficial to anyone except Ethos and Internet Society? Is it even clear they have the right to sell it?
Has every person at ISOC submitted conflict statements? Are they willing to commit to never benefit financially from Ethos controlled entities for 10+ years?
At the last NANOG, the keynote speaker described three instances where companies have "hijacted" the DNS.
https://blog.apnic.net/2019/11/04/dns-wars/
The first "hijack" was Versisign wildcarding unregistered .com and .net domains (https://en.wikipedia.org/wiki/Site_Finder). The second was OpenDNS redirecting Google searches to an OpenDNS proxy (http://web.archive.org/web/20120518025819/http://www.opendns...).[1] The third is the EDNS client subnet extension.[2]
1. Acording to the keynote this led to the creation of Google Public DNS "within 45 days".
2. If I am not mistaken, OpenDNS was an early proponent of EDNS client subnet adoption.
Why would someone so greedy and tone deaf possibly give a damn about such a letter? He's walking away a rich man and he already made his choice fully knowing.
If you want to Save .org, abolish ICANN. It's time to take our medicine, ICANN with no oversight has predictably led us to an internet controlled by greed and corruption of a few wealthy elite.
Appealing to the greedy will get us nowhere.
We need to seize power, not to plead.
It appears to be a corrupt inside job.
I don’t mean this as a serious suggestion, but as an example we could have a “drop dot org” month where resolvers refuse to forward queries to the ORG nameservers.
Not a great example because it would have a pretty negative impact on the domain holders, and no impact on ICANN. Can anyone think of a better example, equivalent to saying to ICANN “if you go ahead with this then we’re going to boycott dot org in a way that makes it worthless”?
But .eu/EURid seems to be a non-profit.
This would be useful if we could register our marks and tie it to a domain, along with the standard application fee. At least for certain TLD's (.com would be a good candidate).
FWIW, I have a long history of dragging registrars through the mud to get clients' domains back. As of this time, I am in a dispute with GoDaddy over a domain that was deleted because GoDaddy sells a 'business registration' service. My client renewed this thinking it was for his expired domain, GoDaddy updated the WHOIS nameserver records and the site came back online. 45 days after the initial expiration GoDaddy dropped the domain without notice and a broker picked it up. I can't even go through UDRP on this because the client never registered their trademark.
It is rent seeking.
I know it's work however if done right (or better) a .org should be low cost for a NGO and how about a decent non profit tld so they could have it lower cost or free?
Sure it sounds hard but the automation and handling enrolling new domains is the real work
You can do the math.
Then there are people like me. My org domain is so old it can legally drink and soon be able to run for Congress. What is it worth to me? $200/year? $500? $1,000? I don’t know and it sucks to have to consider yet another astoundingly high cost of “living” in a world that keeps going up in cost.
In the aggregate, that's many, many millions of dollars going into Ethos Capital's pockets at the expense of charities and other non-profit organizations.
Who says it stops at $15, too?
They could charge x.org $15 and y.org $150,000.
The few other types this happened, it has resulted in exorbitant prices across the board.
This gives the registry huge leverage over you. That 3$ that it actually costs them to run it can increase to whatever price they think you will be willing to pay and you can't not pay it...you would lose your spot and identity on the internet. Its not like with registrars, like godaddy, ghandi, bluehost, etc... that you can switch between in like 24 hrs.
IIRC .orgs were price controlled, so the price couldn't rise, but with this takeover, the price controls have gone away.
Regardless, I don't see how moving .org's operations from a non-profit (PIR) to a private equity firm benefits anyone, except the owners of said private equity firm. You're basically taking something that could operate at-cost and giving it a mandate to turn a profit-- the only way that happens is if prices go up. Likely a lot.
Important point: just before this rigged bid went through, ICANN conveniently decided to remove the price cap for .org registry prices.
Yes, ICANN granted a monopoly to ISOC in the form of PIR, who have been allowed to increase prices consistently for years but at a capped rate. And they wanted more. As costs have gone down.
Then everyone at ICANN talks about not being a price regulator and free markets. Ignoring the fact it's a monopoly, and not one ISOC/PIR played any role in creating, it was a gift from ICANN. A perpetual, no bid, contract with ever increasing prices on a decreasing cost monopoly good.
https://www.theregister.co.uk/2019/11/20/org_registry_sale_s...
> The power to implement processes to suspend domain names based on accusations of “activity contrary to applicable law.” The .ORG registry should not implement such processes without understanding how state actors frequently target NGOs with allegations of illegal activity.
Under the previous rules, the registry level could (more or less) resist being bullied into taking down a domain due to government pressure, though the government could implement a firewall and threaten other service providers. Now, though, a large country could say "we will block .org domains, or .org DNS resolutions, if you don't suspend an activist organization's domain globally," and there would then be a PROFIT MOTIVE to take down the domain GLOBALLY, as the value of the registrar would decrease if .org domains were blocked in that country. And this would be permitted by the 2019 rules. This gives censors tremendous leverage to implement censorship around the globe.
I'm all for the role of private equity in helping companies to grow - while there are certainly firms that operate in bad faith, the PE industry overall doesn't deserve the bad rap it gets in the media.
But IMO this sale should absolutely be disallowed from a humanitarian and international security perspective. The incentives are just too badly aligned.
The worldwide non-commercial Internet being controlled by an unaccountable private corporation is evil on its face. Burden is on someone to prove otherwise.
Let every site have a UUID, kinda like TOR addresses, and let the host/servers as well as users specify multiple human-readable shortcuts for that UUID.
So HN might get o4u20j4c9qwybv3u0p2hnxjq4k1n4vmcsvtvm2666kjn123 and no other site should ever get the same ID until the heat death of the universe, and you could access it by any name you want.
Something like that would be resilient to impersonation, takeovers, brand renaming, and other issues.
https://www.wholewhale.com/podcast/152-why-we-should-save-or...
Is .org really a valid way to verify legitimacy of a non-governmental organization? Should we be looking for another solution here or is this the right hill to die on?
Some TLDs do indeed have stronger requirements. I remember that for a long time getting a .fr was a bit of a pain because you had to prove that you were a french citizen or a french company IIRC.
I'm done with it. I don't want to partake anymore, I don't want to fight it anymore, I don't want to care anymore.
Let the Google's and Facebook's have the old Internet. I'm done with it.
The dream is over. The magic is gone for me. The old Internet is gone. Let them have the rest.
Maybe then, and only then we will rise up like a Phoenix, with a solution that cannot be stolen out from under us.
Who is "us"?
The internet is available to more people in more countries than ever before. There's more content on the internet than ever before. It's a part of every day life for nearly everyone in the world.
That's what's happening to the internet. It's no longer a corner where quirky tinkerers were the only ones who could access it.
And the promise of the internet was never to be just that.
It was meant to be a vehicle for humanity (along with all it's warts). That's what you're seeing. The rest of humanity coming on-line.
The attitude of "this isn't what it was meant to be" presumes that it was meant to be anything at all. Similar to a kid that doesn't want to share their legos with the rest of the class.
It isn't shifting towards an oligopoly unless you count things like Wikipedia as a monopoly. Which it isn't, Wikipedia is probably about as close to an ideal democracy as any human project ever attempted.
There was a project similar to Wikipedia, but for semantic data. It lasted for a little while before being swallowed up by Google and shut down[1]. Granted there are some alternatives, but after investing some time working with freebase data, I should be allowed to hold a grudge.
Google played a key role in muzzling more widespread usage of RSS[2], along with Twitter and Facebook discontinuing support for it. Similarly, jabber[3], XMPP[4].
These days it's risky to even host your own mail server, since most people you correspond with are likely to use one particular email service that may arbitrarily block messages from lesser-known mail services[5].
[0] https://en.wikipedia.org/wiki/Censorship_of_Wikipedia
[1] https://groups.google.com/forum/#!topic/freebase-discuss/WEn...
[2] https://www.fastcompany.com/3013890/reader-may-have-died-to-...
[3] https://blog.twitter.com/en_us/a/2006/use-twitter-by-instant... (couldn't easily find press of the discontinuation of this service)
[4] https://news.ycombinator.com/item?id=9266769
[5] https://www.tablix.org/~avian/blog/archives/2019/04/google_i...
Why not shake them down for those sweet donations?
Im saddened by the death of rss too, but i think its a lot to blame that soley on google. If the rss ecosystem was so weak, that shutting down a single rss client killed it, it couldn't have been long for this world anyways.
Google made it impossible for existing solutions or upstarts to compete with their free tools, then slowly killed off marketing it and supporting it. The final straw was when they killed their reader.
Google killed RSS and they are actively killing other vital parts of the Internet in favor of their tech (forcing the use of their AMP tech for the best spots on their search engine results is anti competitive, Their web browser Chrome has saturated the market and is also making decisions which will undermine the Internets open protocols, but literally hiding the protocol in URLs, hiding the path in URLs, thus forcing people to search more).
Google is not alone in using it's capital as a destructive force on open protocols and standards. Facebook, Amazon, and Twitter are the same way.
wikipedia has their own drama. it has contributors who shape the content into what they want the world to see instead of staying objective on certain topics. often articles on simple topics are so complex because they are written by enthusiasts and aren't trying to inform beginners or curious.
we need better!
You're being disingenuous and needlessly insulting.
We wanted to bring the freedom and egalitarianism of the early internet to everyone. Instead we got the jaded, corporate internet, but at least it's available to everyone. The GP is obviously mourning the quality, not the exclusivity.
.org is gone, use .com or .net or any of the other hundred of domains.
> .org is gone, use .com or .net or any of the other hundred of domains.
What about all the broken MX records?
Changing the domain of a site is very effective at killing a site, and a business or organisation, because all existing links to it break, emails to it break.
And if you give up the domain, it will usually get squatted quickly, so the links and emails carry on working - they just go to the squatter's site instead.
There is no way to update the majority of links to your site, if it's been around for a while. You can search for links and ask other site operaters to update, but it just doesn't happen much, and it's also extremely expensive to do when measured in time to write to thousands of site operators individually.
And when you have to change the name at the same time (because your name is squatted on other TLDs), you're effectively deleting the name recognition, literature, old podcasts, matching name you already have on Twitter, etc.
If you had a good name for a long time, chances are you will struggle to find another one like it, and even if you do, most people will think the new name is something else.
On top of that, your email is probably linked to your .org, and people aren't going to stop sending to that for years, no matter how much you tell people to via other channels. You can't know everywhere your email address and main web address are being kept by someone to use later.
And wherever there is a long-standing email domain, there are probably thousands of internet accounts that have that email as their primary or backup/recovery, which you will need to keep if you don't want to start losing access to other accounts. Updating those is very difficult unless you have been extremely diligent at keeping a database of every account you ever created. In practice, even very diligent organisations who attempt to do this don't succeed because accounts tend to be created bydifferent people.
Perhaps in extreme startup land where people start a new business from scratch every couple of years, and pay a lot in SaaS costs so hiked domain fees may sseem relatively cheap, this might not seem to matter.
But many .orgs have been around for decades, and are low budget but very well esablished.
Any many other .orgs are individuals, with email and thousands of online accounts linked to their domain.
There is no "just" to a domain name change.
Changing that would be a proper PITA, and I'd hate to have to do it just because ICANN sold out in such a transparently corrupt way.
Your tiny cool self-regulating community, will either die, be eaten by Facebook or become Facebook.
Granted, I'm holding out hope that someone surprises us with a technical solution. I just don't have high hopes there.
Ignore everyone's ring. If you aren't hosting a part of the internet you want. Why would you expect others to?
Earlier today I was trying to Google a website I found on my PC a while back. (Backing up its disk atm, and don't use Chrome sync.)
Clicked on an unrelated link, and was already in the process of reaching for the Back button when I realized I was looking at a cert failure (wrong domain in certificate). Heh. Idly curious I hit Continue... And was presented with my first
> Content Denied
> Access to this website has been disabled by an order of the Federal Court of Australia because it infringes or facilitates the infringement of copyright.
> 1800 086 346 for information.
https://i.imgur.com/fwXRlTN.png
After recovering from the shock - this sort of thing only happens in 3rd world repressive countries, right??? - I went back and tried the domain referenced in the cert.
Haha I've probably lit a billion lists up like Christmas trees now... I got this: https://i.imgur.com/w37jfFt.png
Here's the cert error, for reference: https://i.imgur.com/dZmEcnd.png
I have no idea what the second site was.
I’ve never heard of anyone get arrested for low level piracy here, so I wouldn’t be all that concerned with requests that hit the piracy filters.
Domains registrars?
The fact that data caps ever gained traction doesn't reflect well on the old timers ability to explain and protect the true value of their creations for the wider public.
Which is weird because they were obviously able to do that with cryptographic algorithms which are way more esoteric.
It's like teaching a generation of craftspeople to build all the intricate parts of a piano but never noticing nor caring that for some reason they're all selling pianos that have a single key.
There's certainly many problems with something this gargantuan, but I get very skeptical when people nostalgize and eulogize "the good old days" of anything.
I'll add, I say this with empathy to your feelings. I regularly feel a very strong nostalgia for those late nights of discovery on the Internet. But I do recognize that Internet involved a fraction of a fraction of the people using it today who are discovering and creating and sharing all kinds of stuff with greater ease than ever before.
Could you explain how you got to that conclusion?
It would be impossible for non-tech-savvy people to share things on the internet if there were no omni-present surveillance, manipulation, and centralization, because ... ?
"It's bad that X has happened!"
"But Y has happened, too, and that is good!"
Yeah, so what? Unless Y happening is predicated on X happening, that is just completely irrelevant to the discussion?
harder to use as publishing platform by who? don't you mean businesses & corporations?
people have always been fine. myspace anyone? geocities? irc? icq? aol? msn? yahoo? the list goes on... also the remarkable thing is that people just move to newer and better back then.
Unfortunately, getting to their creations is ultimately harder: eg. searches for anything will now throw you at some lame stuff on pinterest, which will attempt to lure you into signing up just to find out if they have what you are looking for.
Basically, ability to really "browse" that humongous web is now gone. And most of those creations never reach their intended audience.
If you feel like you got a bone yo pick with a current state of internet, post about a technology that addresses the problem so that people can become aware of it. And save the virtue signaling for reddit/facebook.
Even with the usual governmental bureaucracy overhead I bet it’s be a rounding error. Seems a good fit for something like the UN to take over.
https://www.ssllabs.com/ssltest/analyze.html?d=savedotorg.or...
"This site is blocked due to a security threat that was discovered by the Cisco Umbrella security researchers."
Wait, what???
Sadly, it's my business to deal with flamewars, personal attacks, trolling, and other abuses of HN. If flames are allowed to burn this place to a crisp, HN won't be HN anymore. And eventually there wouldn't be anything worth running or anyone to run it for.
How high is it ok for the PE to go on fees? Why? (Tone is to point out how arbitrary this all is, genuinely curious otherwise)
If they had all domains at the same price, price hikes would be much less of an issue.
But seriously I don’t see what’s wrong with this sale. There are no restrictions on who can use a .org domain anyways, and the only people price increases really affect are domain squatters (real organizations can afford 10x the current price without batting an eye). I don’t see what’s wrong with this sale
Ethos Capital paid $1.135 billion for total, unconditional, purchase of the PIR from ISOC.
ISOC just "grabbed the opportunity when Ethos presented it,"
ISOC have reviewed Ethos’s governance plans and approved them, but will have no means to enforce compliance with those plans.
The deal must be approved by the end of the 1st Quarter 2021 or it fails. The exact date is still confidential.
It must be approved by two bodies – ICANN and the Pennsylvania Orphans Court, which is a specialist court for estates and trusts.
The PIR is incorporated in Pennsylvania and this court must approve changes in the PIR charter in order for Ethos Capital to take ownership.
This is because “the Orphans’ Court judge is the ultimate defender and protector of the fund in question, and the Orphans’ Court will protect that fund and ensure that the fund is distributed to the correct beneficiary”
There is a good introduction to this court at https://www.skhlaw.com/pennsylvania-orphans-court-101-all-th...
This means that if the Pennsylvania Orphans Court has not reached a determination by 1st April next year, or if that decision is being challenged in a manner which delays implementation, the deal fails.
You're certainly welcome to participate as a community member, which means following the guidelines at https://news.ycombinator.com/newsguidelines.html and using the site as intended, for intellectual curiosity. But it's not ok to use it as a platform for a cause, no matter how good a cause it may be.
Also, please don't copy/paste comments here. That lowers signal/noise ratio and breaks the site guidelines, which call for curious conversation.