If a company uses whois privacy I don't do business with them as a rule.
If a company uses whois privacy I don't do business with them as a rule.
While a company should definitely have a whois page, most startups make it abundantly clear how to get ahold of someone at the company with large "Contact Us" buttons.
I've never contacted a startup to report a security issue, gotten a response (some don't respond), and had it not be from someone in a position to have the issue worked on immediately.
Dropbox uses the same number for all three.
Neither company uses whois privacy. Agreed that for plenty of companies you'd end up in an IVR system but that seems to go for every kind of company these days, not just internet companies.
I don't really understand the way ICANN currently rhymes their 'whois data should be accurate' policy with the 'we allow the use of anonymization services' exception on that policy.
In the UK whois privacy is only for non-trading individuals (i.e. for personal Web sites) and always has been I think.
Then again, it's totally up to ccTLD operators to decide on what details are published in WHOIS. gTLDs (those longer then two letters long) have to stick to ICANN's policies.
Now, what is the case is that there's been a crackdown, due to pressure from law enforcement agencies, on incorrect details being set on domains. However, this actually has no effect on what's published in WHOIS because the only actual requirement is that the registrar have the correct details for the domain on record and escrowed. So long as the registrar has correct details, the registrar can mask the detail in WHOIS however is applicable, so long as it's clear that WHOIS privacy is in place.
There's hiding and then there's hiding.
If the number leads to a phone center the business contracted with and there's no real way out of that to the people who make decisions, is that not a form of hiding?
Except the overwhelming majority of customers has no idea what 'whois' even is and couldn't care less what info yours may or may not contain...
The only people who do care are spammers and scammers.
Whois-databases are a goldmine for them, and that's why whois-anonymization is a Very Good Idea™.
There are reasons to want privacy of course but not in the case of a business with a business address that most likely (say the local cake shop?) already puts their address on their website.
As a business, why wouldn't you want your contact info to be public? It's another piece of marketing.
Even more absurd to me is people who own domains who clearly want to sell them (let's say they are listed on SEDO or Afternic etc.) and they have privacy on their whois record. I mean get a PO box if you don't want your home address and you don't have a business address. If your domain is so valuable or if you own many we are talking $100 per year approx for an address. Use a google voice number for the phone number.
Lastly, lack of public info on ownership (so no trail of ownership at whois history) makes it much harder to prove you own the domain if something happens at the registrar. You are depending on them to have all their records in order. If they get hacked, go out of business and so on you could have a problem proving ownership. (However small it's not worth the risk).
ICANN does require registrars to archive whois data (with Iron Mountain) however since we don't offer privacy I'm not sure whether they require the underlying ownership (if you want to call it that) to be archived. Also many of the early privacy programs actually put ownership in the registrar's hands but had a separate contract with the actual registrant (not sure if that is needed anymore).
Personally, I don't think WHOIS privacy is something a business ought to be using, but it's perfectly legitimate for private individuals to use it.
> The large registrars push this as a profit center and/or some kind of benefit to enhance their offerings.
It is, because it's something the registrar can do at little or no cost. Given registrars work at thin margins, there are good reasons why even smaller registrars tend to offer WHOIS privacy.
> Lastly, lack of public info on ownership (so no trail of ownership at whois history) makes it much harder to prove you own the domain if something happens at the registrar. You are depending on them to have all their records in order. If they get hacked, go out of business and so on you could have a problem proving ownership. (However small it's not worth the risk).
That's precisely what data escrow through Iron Mountain is intended for, and why ICANN have been enforcing RDE since the failure of RegisterFly.
The key thing to keep in mind is that what is shown in WHOIS isn't necessarily what needs to be escrowed. A registrant is meant to provide accurate data to the registrar, and it's this data that has to be escrowed, but this data doesn't have to be what's published in WHOIS. This is why the only way to legitimately do WHOIS privacy is through the registrar of record. Anybody who's dumb enough to use a third party is asking for trouble.
If you're not escrowing the underlying ownership information (that is, the real registrant, admin, tech and billing contact details), then you're in breach of the RAA.
> Also many of the early privacy programs actually put ownership in the registrar's hands but had a separate contract with the actual registrant (not sure if that is needed anymore).
That can be solved by making it clear in the WHOIS details that the details displayed in WHOIS are for an agent acting the actual registrant. The registrar I work for also forwards any details sent to the email address published in WHOIS with WHOIS privacy on to the actual contact behind the scenes. Also, the registrar is required to escrow the real details.