ICANN races towards regulatory capture: the great .org heist
blogs.harvard.edu
blogs.harvard.edu
1) CEO: A Harvard MBA with typical PE experience
2) “Chief purpose officer” - Former SVP at ICANN responsible for corporate outreach.
The structure of this stinks. I’d be not at all surprised to learn of some kind of back channel dealing.
Edit: The former (2016) CEO of ICANN registered ethoscapital.com? After ICANN he went to the former PE firm of (1) above. He is certainly involved in this now, even if not named.
Unbelievable. This heist was planned for years with money raised specifically for it. I can’t believe this is legal.
I doubt that it is. The directors of a non-profit can't wake up one morning and decided to pillage the org's resources for their benefit. They must transact their business at arm's length. Chehadé buys Donuts from Nevett, Nevett turns around and sells dot-org to Chehadé's PE firm. This looks like a kickback scheme.
PIR is headquartered in Virginia, we should be calling and writing to the Attorney General there.
We can rage all we want on HN but you’re actually showing us how to make a difference by going through the proper channels.
What would be great is if someone at PIR turned whistleblower. Given the size of the transaction the reward money could be in the millions.
(Details may be incorrect. IANAL.)
Maintaining namespaces is just hard and the DNS, with groups of people running TLDs, is the best we’ve come up with so far. I personally thought namecoin was a creative alternative and I’m a little disappointed it hasn’t become more popular but until something like that does we’re going to continue seeing things like this.
Is it? I'm not very familiar with the domain, so I'm actually asking. Generally, I'm very cautious when someone says that current state of affairs is the best we have come up with, because it doesn't acknowledge the inertia to keep things as they are.
There are a few other projects that decentralise domains and fix security issues, but our current federated system has become a heavily established billion dollar industry and the people in control of it have no incentive to give up that control.
Any move to a new system will have to come from end users who don't know there are issues, and don't care enough to spend the effort understanding the issue and solution.
https://en.wikipedia.org/wiki/Namecoin
>A 2015 study found that of the 120,000 domain names registered on Namecoin, only 28 were in use.
An empirical study of Namecoin and lessons for decentralized namespace design
http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.698...
>Based on all the empirical evidence we present, we are left to conclude that the Namecoin ecosystem is dysfunctional. The vast majority of registered names represent squatting and there is little evidence of a secondary market for names. While there could be many factors that explain the lack of adoption, there appears to be clear room for improvements in the design to minimize squatting and other problems. To this end, in Section 6, we explore the design space of decentralized namespaces and make recommendations.
Why Namecoin Didn't Take Off: A Cautionary Tale
https://cointelegraph.com/news/why-namecoin-didnt-take-off-a...
>Cointelegraph: You used to be one of Namecoin's biggest cheerleaders. What happened?
>Michael Dean: So here's my opinion, which is really going to get me hated, but I think Namecoin as a decentralized DNS-type system is dead.
>[...] The biggest flaw is the clunky wallet that takes ten minutes to open. The other biggest flaw is that the near-zero expense of registering domains encouraged domain squatting. All the good names are taken. Someone registered every noun in the dictionary as Dot-Bit.
>And these squatters didn't even do it right. When you go to any of these squatted domains, they don't go to a place holder with a page that says "to buy your site in Dot-Bit, email me here and make me an offer." The sites just don't resolve! These people are unclear on the semi-scummy concept of domain squatting. In Namecoin, even that gets done wrong!
>Also, Dot-Bit is actually vulnerable to a hostile takeover from ICANN. If ICANN decided to support Dot-Bit and decide where things would resolve contrary to where the Namecoin wallet was resolving things, and corporate DNS servers sided with the ICANN (which they largely would), it would create consumer confidence chaos with the Namecoin system.
I'm not an advocate for blockchain it has only one very narrow use case global distributed consensus on ownership of a virtual token that's perfect for money and domain names and nothing else.
I'm sorry if you bought some flim flam mans marketing spin but I only ever look at the tech.
All of these issues with people not using their domains just backs up my argument, that people don't care enough to use it, hell even the squatters don't care enough to use it.
Ultimately ICANN could have given them the TLD but didn't because they have no incentive to give up that control.
Thank you for backing up my argument with links :)
What made you think I believed any bullshit, or that I'm evangelizing? What company did I endorse? And the links prove you're evangelizing Namecoin as a "properly decentralised domain name project", but it's actually a complete failure, which you conveniently neglected to mention. Your statements are the exact opposite of the truth. Speak for youself, and stop projecting.
You claimed that Namecoin was "properly decentralised" and "uses blockchain to control ownership of domains and zone edits in a more secure way". Yeah, all 28 domains in use. You're the one evangelizing a spectacular failure.
Yes that was my argument, we are both in agreement why are you so upset?
I mention namecoin as a single example of decentralised dns and mention that there are other projects (thats not advocating or evangelising namecoin).
I then point out the major problem with all of these alternative dns, no one uses them because few have incentive to do so.
You responded by calling me a con-man (sounds reasonable) because I had the audacity to mention a technology in one of the only use case's its good at.
> I'm not at all upset (and you're projecting again) -- I'm being sarcastic, and it whooshed right over your head.
I got the sarcasm, I got the name calling, it's childish. If I got more upvotes would you consider my words instead of the con-man image you are projecting? I don't think so.
It may not have an obvious change with a single new domain registered, but surely there are significant variable costs.
(To be clear, I oppose this transaction, just not on the grounds that root name servers are all fixed costs.)
This on the face of it sounds reasonable, but the cost difference is likely marginal.
If you're going to provide a highly available DDoS resistant infrastructure to deal with a large scale of customers, the majority of the costs are going to come from building that distributed infrastructure across many parts of the world.
The costs may go up between 1 million lookups vs 1 billion lookups, but if there is an increase, the order of increase will be closer to 10x than it is 1000x.
As another comment says, most of the cost will be in building and maintaining a robust, scalable, attack-resistant distributed system. The linear scaling costs (such as bandwidth and processors) will be small in comparison.
(Of course at much higher numbers, mathematically O(N) starts to dominate again, but 1 billion lookups per day isn't enough for that.)
[1] https://www.theguardian.com/technology/2015/sep/21/icann-int...
BTW I was a member of poptel who owned the .coop registry.
> Vint Cerf, former Chairman of the Board of ICANN and founding President of the Internet Society, said in a statement: “When the Internet Society won the bid to operate the .ORG registry, it enabled a productive and sustainable future for the organisation. Public Interest Registry exercised its stewardship to the benefit of the registrants and the Internet Society’s mission. I am looking forward to supporting Ethos Capital and PIR in any way I can as they continue to expand the utility of the .ORG top-level domain in creative and socially responsible ways.”
And then an outline of what "expand" might mean in that context:
> Going forward, PIR and Ethos Capital are planning to launch several new initiatives aimed at promoting and supporting the .ORG Community, including: Establishing a Stewardship Council that will serve to uphold PIR’s core founding values and provide support through a variety of community programs; Launching a Community Enablement Fund to support the financing of current and additional initiatives undertaken by key Internet organisations; and Expanding a program to award .ORG prizes to promote the success and positive impact of non-profit organisations.
Which is surely the most transparent flimflam imaginable and which anybody in the business world would interpret as doing absolutely nothing at all. /s I can't wait to see the fabulous prizes /s...
[1] http://www.domainpulse.com/2019/11/14/pir-eyeing-growth-etho...
Jokes aside, this sort of stuff is complicated. Seen from Vint Cerf's position it might sound legitimate. Certainly some form of reorganization which might collect more funding for development and maintenance of the internet in the public interest wouldn't by itself be bad on its face.
It wouldn't be the first time some up-in-the-clouds authority had too much trust in their friends and colleagues that what they were up-to was actually kosher and, as a result, carelessly dispensed with the required ritual corporate-speak niceties only to suffer embarrassment later.
You should also keep in mind that any time you see someone quoted in a press release there is a very high chance that the press release author wrote the quote. It's the norm to suggest copy and pass it over for approval. Some people have their staff accept boring pap like that from friendly organizations without ever seeing it themselves.
I personally never let someone write a quote for me and I found that this turned me into a nuisance... but lots of people do (presumably they don't like being nuisances!). I think they deserve what they get for it, but understanding what might have happened can make it more explicable if not more excusable.
Most of the time people do not see themselves as the villain, even those committing a fraud find all kinds of way to justify their actions
People live one day, one decision at a time. Without a clear 'mission statement' and a clear knowledge of the risk carried by each decision, we all tend to be very conservative. Which means, support the status quo for now in hope of better change in the future. Which might never come.
WTF?
So, non-profits collect donations from people who want to support their respective missions, and now these scammers come along and want to use a monopoly to redistribute those donations based on what they think who the donations should go to, and then even want to be recognized for their "work" of forcing the redistribution of donations?
If there is one thing the .org registry could do to "promote the success and positive impact of non-profit organisations", then that would be to optimize their business as much as possible and offer the cheapest domain registrations on the market, so that non-profits can keep as much of their money as possible to spend on their core mission.
Even these bullshit "promises" would still be blatant corruption, you really have to wonder how much of a moron Vint Cerf is for not seeing that.
With the amount of negative PR already generated by the proposed move, it’s hard to see a way forward for ICANN that is untainted.
It is not at all unlike what is captured by the phrase: justice has to be seen to be done.
Apparently it is under Californian State law so US law.
> As of Saturday, October 1, the federal National Telecommunications and Information Administration no longer exercises control over the Internet Corporation for Assigned Names and Numbers (ICANN)
> Instead, as an autonomous not for profit organization, ICANN will now answer to international stakeholders across the internet community, including a governmental advisory committee, a technical committee, industry committee, internet users, and telecommunications experts.
According to https://en.m.wikipedia.org/wiki/ICANN
> From its founding to the present, ICANN has been formally organized as a nonprofit corporation "for charitable and public purposes" under the California Nonprofit Public Benefit Corporation Law. It is managed by a 16-member board of directors composed of eight members selected by a nominating committee on which all the constituencies of ICANN are represented; six representatives of its Supporting Organizations, sub-groups that deal with specific sections of the policies under ICANN's purview; an at-large seat filled by an at-large organization; and the President / CEO, appointed by the board
> There are currently three supporting organizations: the Generic Names Supporting Organization (GNSO) deals with policy making on generic top-level domains (gTLDs); the Country Code Names Supporting Organization (ccNSO) deals with policy making on country-code top-level domains (ccTLDs); the Address Supporting Organization (ASO) deals with policy making on IP addresses.
So yes, the State Of California has jurisdiction but no control. AFAIK California has no power to intervene in the internal affairs of any corporation if they keep the law and while this whole thing stinks, I doubt it broke any laws.
which ones you think of
It's likely to only get worse, until an alternative DNS-like system arises.
1. Dot org 2. Dot net 3. Dot com 4. The world!
Dot org will only be the testing ground and only the beginning if they pull it off.
That’s barely over 4 years away.
They have domains like .geek, .cyb, .null, .libre, .oss, and you use them by simply switching your DNS server to one of OpenNIC's mirrors. They also support TLDs for "emerging nations" like .ku for Kurdish people, .uu for Uigurs, .ti for Tibet.
Though I'm not sure what would happen if ICANN decides to sell one of those domains one day.
Well, I guess mainland Chinese people won't be using this.
If you a interested, in the details of any given 501c3 look for the tax form “990”. It’s where the 501c3 report income, governance, and expenditure out to the IRS. Any nonprofit worth their salt will have a copy published on their website. They typically run 2, 3 years behind the calendar year, so right now expect 2017.
Example 990: https://www.icann.org/en/system/files/files/icann-fy-2017-fo...
Googling in general, it seems that when 501-c-3's cease to exist, any assets they had end up being donated to some other existing 501c3, as decided by the 501c3 board. (I am sure some amount of bonuses to salaried staff can also happen, but probably not a significant proportion of a $1 billion acquisition price, without seeming illegal).
$1 billion is a pretty big number. Still curious where $1 billion paid to acquire PIR will end up going. Obviously existing 990s for past fiscal years from PIR won't tell us that (even less so existing 990s from ICANN, which I don't think is involved in ownership of PIR or a party to the transaction at all?).
> In November 2019, the Public Interest Registry (PIR) was sold by its initial owner, the Internet Society, to investment firm Ethos Capital for an undisclosed amount. The PIR also announced it would abandon its non-profit status to become a B Corporation.
So, it seem like they plan to forgo their nonprofit status to became a for-profit company?
I'll try to keep that blog post up to date. Today: PIR posted an official response -- low on content, no additional redeeming tidbits. https://www.keypointsabout.org/
Tellingly, they do not once mention the word "endowment" or derisking [for ISOC]... which seemed like the one plausible argument in favor of this move: ISOC sacrificing the public registry for the rest of its mission.
Write to news outlets. If this blows up in the mainstream media, public pressure may be too high for them to go ahead with this deal.
That isn't alien language, and whilst not strictly true, it isn't stretching the truth more than the news already does habitually.
https://thenew.org/the-internet-society-public-interest-regi...
Maybe a broader look at corruption within ICANN is needed.
Yes, UN is a bureaucratic hell but I see no other existing option.
You see no other existing options because the premise is to raise the cost significantly and make it unavailable for most people. It clearly doens't have to be that way. And you don't solve anything by funneling that money into an extremely inefficient organization.
They are, though, since each domain can only point to one server (per RR type). Or at least meaningful ones are, but if you're okay with a random meaningless string of characters rather than something memorable then it doesn't really matter whether it's under any particular TLD. Moreover, when it comes to .org domains the money you're paying for registration is supposed to cover some background checks to verify that the buyer is really a non-profit organization and not some scammer, to maintain the reputation and integrity of the .org TLD. That takes labor, and labor is a scarce resource.
The UN is too political for this kind of governance.
Gentrification comes to the internet. No thank you.
First domain $3/yr Second $8/yr Third $20/yr ...etc
No idea how you could track/enforce this. Make domains tied to an individual or company type thing. Shelf companies would add too much cost to have one per few domains I imagine.
the price for domains should remain cheap, for many reasons, not the least of which one should not be gate keeping.
Second, nothing should be in the control of the UN, they are a terrible corrupt organization that should have as small amount of power as possible.
Would ICANN have any recourse if, after allowing this sale, the established registry dramatically raised prices?
One Namecoin inspired blockchain project that has solved Zooko's Triangle is Handshake [2].
[1] https://en.m.wikipedia.org/wiki/Zooko%27s_triangle [2] https://handshake.org/