Icann bids to stop Iran web domain seizure
bbc.com
bbc.com
That's a pretty warped view of justice. ccTLDs are not 'assets' that you should be able to seize but registries. Imagine trying to seize the land registry of Iran or their registry of vehicles because Iran refuses to pay some foreign entity.
This is an excellent illustration of why ICANN should be replaced by a system that is distributed enough that nobody would ever think of even attempting to do something like this ever again.
What a tremendously misguided lawsuit, even if we're not getting into the 'x supported y and y did harm' part of the argument, which makes this even more tenuous.
If everybody that suffered from the meddling of some country through indirect sponsorship had a legitimate grievance and was given the power to shut down some large chunk of the internet as a remedy in order to extract some amount of money then that would open up a huge can of worms, .COM would be the first to go.
That's the least problematic issue and yes, you're routinely expected to pay for deeds of some larger organization, your government in particular. Every time the government is sued and loses for example, you foot the bill.
This however has the potential of completely breaking routing of any global network. If they can seize IP addresses, domains, then why not phone prefixes.
Such as?
DNS is useful because it is authoritative. What would happen if two parts of this 'distributed' ICANN disagreed on something? Different parts of the internet would see a completely different state (e.g. who owns gov.uk?), Thus rendering DNS effectively useless.
The only alternative I could see to ICANN being a US organisation is for it to be given authority by treaty. And that would open up a whole other can of worms. ICANN run like the ITU?
http://www.forbes.com/sites/irswatch/2014/02/03/swiss-bank-s...
This problem can be solved in distributed system using bitcoin-like proof of work scheme. If two parts of the network disagree, the bigger part is considered right. Namecoin project is trying to implement distributed DNS using this technique - http://namecoin.info/ .
If you want some authoritative distributed hash map, you can use namecoin like you said. But think about why you actually need an authoritative registry.
Hyperlinks? The document embedding the hyperlink can also embed the IP number. In fact, that's how the underlying IP routing system works. BGP isan interesting target for spoofing as of late.
At the very least, a website wishing for others to find it by its domain name should tell more than one registry, so there isn't a single point of failure. In the trade-off between consistency and having no single point of failure, you can think of the latter as failover or backup plan.
Do you see any problem with that?
After that success, this is an attempt to go one step further and knock out fundamental civilian and government communications systems... though we can be sure that virtually all internet, satellite, radio and telephony communications out of Iran are already logged and searched by similar parties, seizure of network addresses would be an extremely damaging move.
>But there are other possibilities, Darshan-Leitner said. “ICANN may decide that it just isn’t worth their while to do business with Iran anymore, because all the money coming in will go to the terror victims.” In that case, Darshan-Leitner said, ICANN could “pull the plug” on Iran’s Internet, suspending use of the .ir domain and disconnecting Iranian IP addresses from the web. Even if ICANN decided not to do that, Shurat Hadin could demand an auction of the Iranian Internet assets, arguing that it could realize more compensation money that way – meaning that Iran would no longer be in control of its own websites. http://www.timesofisrael.com/israeli-us-terror-victims-now-o...
>Plaintiffs hold several money judgments against the governments of Iran, Syria and North Korea (collectively, the “defendants”). Plaintiffs endeavor, with the Writs of Attachment, to attach the .IR, .SY and .KP country code top-level domains (“ccTLDs”), related non-ASCII ccTLDs, and supporting IP addresses (collectively, the “.IR, .SY and .KP ccTLDs”), all of whichrepresent a space on the Internet for use by the citizens of Iran, Syria and North Korea. - https://www.icann.org/en/system/files/files/ben-haim-motion-...
If you use the RPKI to protect the internet against BGP attacks, you provide a technical mechanism which governments, or other actors, could use to seize addresses. I just presented a paper on this[2].
IP takedowns are a risk, the Iranian case is not the only example, for instance RIPE was ordered to seize IP Space by a dutch court[3].
[1]: http://en.wikipedia.org/wiki/Resource_Public_Key_Infrastruct...
[2]: See paper "From the Consent of the Routed" http://www.cs.bu.edu/~goldbe/papers/RPKImanip.html
[3]: http://www.internetgovernance.org/2013/08/09/court-says-ripe...
http://www.northkoreatech.org/the-north-korean-website-list/
It's still pretty ridiculous, of course. I'm not sure how, or if, it's even technically possible to "repossess" a TLD, let alone sell it for cash.
It is also possible the family already knows all this, and don't care. It is conceivable that they aren't after money so much as looking for ways to hurt Iran.
More likely it would trigger a change in how DNS works. The only reason that DNS can work the way it does is that things like this don't happen.
ICANN can't force anybody's DNS resolver to point at their root servers. The root servers operate based on consensus. The only reason everyone uses the same ones is that everyone agrees how they should resolve top level domains. As soon as you start forcing decisions using courts and politics you destroy the consensus and blow the whole thing up.
Russia would be one of the parties supporting such a decentralized system, China quite possibly as well and even the US would probably not want a judgement in favor of the plaintiffs in this case.
This is why an organization that manages something as important as IP addresss distribution and Domain management, can NOT be part of 1 country. Why does 4 families and a judge have the power to basically kill all internet access in a country, because someone got killed, no matter how they died.
The attempt to grab the domains is part of a court case begun by the families of four Americans injured in a suicide bombing in Jerusalem in 1997 for which Hamas claimed responsibility.
That's what will happen, if they succeed in seizing these TLDs.
In effect, this would create a new Iron Curtain, but this time it'll be initiated by our governments.
This time it might be initiated by western governments, because the Chinese, Russians and others wont accept TLD seizures at will by the US.
Not that it would necessarily be the only intranet at a (inter)national level; I'm sure that the Chinese government would love a political excuse to cut off their citizens' access to parts of the internet outside their borders.
Essentially this would break the internet as we know it.
I'm not that optimistic. As far as I can tell, the argument being made in this case is: According to US law, country X owes me money and hasn't paid. You, ICANN, a US entity, provide thing-of-value to country X. You should give thing-of-value to me instead (as compensation and/or increased leverage towards getting my debt paid).
While the precise contours of the problem would depend on exactly how ICANN hypothetically loses, I see no reason why that template wouldn't also apply to OpenDNS, Google, Comcast, AT&T or Level 3. If too many pieces of the Internet's infrastructure are "within legal reach", it doesn't matter what technical wizardry someone comes up with - it couldn't be deployed.