Unfortunately, we have renewed our ICANN accreditation
iem.easydns.com
iem.easydns.com
It would cost the registrars something to do so, obviously, but so does this. And a basic level of privacy should never have been allowed to become a premium service to begin with.
And i don't mean to imply that the computer scientists of yesteryear were somehow more honest people. It's just a lot less likely for someone to cheat in a group of a few hundred, where everyone is at most one degree of social separation from everyone else, and everyone is in any case very similar in background. Harder to screw over someone you see at all the conferences than some random stranger online, and if you do there will be social, not just legal, consequences.
(If any Registrar reads this, could you explain the extra cost of providing free whois privacy? It seems like the cost associated would be minimal, and the payback would be huge? I heard the true cost to a company for a .com domain is around $7.00? Go ahead and add one or two dollars to the domain for profit. Just be consistent, honest, and no shenanigans. Oh, I looked into Gandi--and they are just to much money.)
An extract [FR] : http://www.chemla.org/textes/voleur.html
This, finally, is the most pure form of security theater I have ever seen. There is no possible argument that this would deter any bad actor from doing bad things with their DNS domain - totally useless policy.
I mean, geez, a false positive from a spam filter can cause you to lose your domain!
However, even before now, you could easily lose your domain due to a missed email. For instance, if you don't have your domain on autorenew, it can end up in redemption (which is expensive), and eventually deleted. And, as of the 2013 RAA, if you don't renew your domain, your registrar is required to park the domain with a non-renewal notice a few days after its expiration date.
Fun, eh?
If you've provided invalid contact information on the domain, you're in breach of the TOS, as ICANN requires that domains have accurate contact data on them.
And I really question how useful it is for even the purpose you outlined. Considering that a) your registrar could easily be subpoenaed for this information if there's a genuine need and b) Anyone who has the tech savvy to register a domain with plans to do something illegal with it surely also realizes they can register a free email under a bogus name.
Of course that was within a year or so of taking down the old domain, and haven't had issue since... just the same, it's interesting how painful an option can be at times.
It sucks, and I'm saying that as somebody who works for a registrar.
i.e. Just because it hasn't happened yet, doesn't mean it won't now.
The WAP emails you'll be receiving are something different, and you will be required to respond. If the email bounces, or if you don't confirm the email within 15 days, you risk your domain being suspended.
You can read the spec here: https://www.icann.org/resources/pages/approved-with-specs-20...
If you'd like to read the specification, it's here: https://www.icann.org/resources/pages/approved-with-specs-20...
If I really have concerns about losing a domain in a legal process, (I'm a corporation, or ongoing business) - I would use the services of a domain name portfolio management company, like MarkMonitor. https://www.markmonitor.com/services/domain-management.php
Domain Services
As a full-service, corporate registrar, MarkMonitor offers a complete range of domain services:
.Brand Registrar Services Trademark Clearinghouse Services Registrations, renewals and transfers Domain recovery, snapping and masking Enterprise DNS UDRP administrative services Local presence Domain locking Mission-critical domain security, including Two Factor Authentication SSL certificates
Check out https://www.markmonitor.com/solutions/role_based_solutions-l... for some of the services they offer.
The Whois Accuracy Program is different, and requires contacts actually confirm stuff.
This is part of the reason why you should use your registrar's WHOIS privacy service rather than some third-party one: by providing the registrar with incorrect details, you're in breach of terms of service ICANN requires registrars enforce.
I had to spend a good 30 minutes trawl through Dreamhost's forums to get an official "OK" that this was a legit email.
Nope, that's pretty much it.
https://www.mywot.com/en/scorecard/name-services.com?utm_sou...
For any phishers out there, there is an obvious opportunity waiting.
- gives you an email address for the whois as a proxy
- automatically follows the link given in the email and clicks the stupid button
- waits for the confirmation email
- if after 48 hours you haven't received confirmation then the system escalates it to a human proxy to click the stupid button (Turk maybe)
Reminds me of Lost
- Generates real-looking names
- Generates a "social live" across the internet, with pictures, Linkedin profiles, and "friends"
- Generates "obviously valid" email addresses
- Provides an email forwarding service to your real address as above
- Provides a "Post office box" pseudo-service so that you can add that as your "real address"
- Generates extensions for a (800) we all can use to as to protect our real phone numbers
- Signs up to your registrar's information and updates it
You just got yourself a "valid" info set in the eyes of ICAAN (without having to pay anon services).
Honestly, this would work without the social aspect. Just wiring together a registered agent service (though used...improperly) and a registrar.
Another suggestion - the service keeps a public gpg key you supply, and posts the email, after encrypting it to you, to usenet/pastebin/wherever searchable (perhaps by the key fingerprint?), and maybe publishes notifications of that somewhere distributed (maybe a has tagged Tweet where that hashtag is the key fingerprint?)
Sign up over TOR, and you could have a pretty good "air gap" between you and any messages it receives for you. Wouldn't matter if they get subpoenaed or NSLed - they'd never be able to see who's _reading_ those messages.
We haven't yet begun to see how ugly this stupid new program is going to get.
This slow crawl of both policy and protocol toward greater bureaucracy will have a much more permanent effect than say the NSA/GCHQ spying.
The web is being decentralized. Pseudonymous expression will not die. It will flourish.
And on their customers.
Nobody's happy with this crap.
For some reason people assume that these whois-anonymization tools are just used by squatters and spam websites, but I use it to someone overloading my physical/digital/voice mailbox.
I also asked the company and they said that it was legit, but came from some kind of service provider.
Finally, the web site, I was directed to also looked very suspicious and less than professional (something, a hacker could have made up in a weekend -- and again no names, logos or information that could make up a connection to my business contacts).
I really would appreciate, when they could make the process more transparent and less phishing-prone -- so anybody could make up a nice sounding domain and fire eMails to people with domains ...
Somebody could think, that domain registration authorities have at least basic knowledge of internet threats ...
(in all seriousness, I expect the high end registrars probably will do this. Shame they're apparently not permitted to exercise discretion and not kill your website that nobody has objected to)
Let's just say I don't have too much time for their moaning and griping now. They should've engaged with the registrar constituency back when the negotiations were happening.
BTW, you should get involved in the IETF provreg and eppext WGs: we need a stronger registrar voice there, and the more registrars involved, the better.
That said, if the test email bounces, that might be required to start the countdown anyway?
I have very little expectation that the boneheads who came up with this scheme considered this possibility, and therefore exempted test e-mails from the bounce-trigger requirement.
The imaginary black-hat that hangs out on my left shoulder has already suggested that spoofing a bounce message for a correctly delivered registered e-mail could be used for mischief. Phishing the domain customers is entirely too obvious for him, though the imaginary white-hat that hangs out on my right shoulder seems quite concerned about it. They both agree that black-hat wins this round.
Or if I didn't want to do anything actually illegal, I'd probably have an enhanced chance of success in pulling off the Domain Registry of America scam and convince people they must update their details [by transferring to my registrar] in the next 15 days.
Seems almost certain to become the most frequent uses of the contact details ICANN has kindly ensured will be up to date and accurate.
I have to guess than ICANN is filled with some very smart people. So their must be some reasoning here.
One other complains is that this verification procedure is really weak: "just send a mail with a link to the address provided"
Imagine if ICANN changed their rules so that a more substantial verification process of the MANDATORY fields was required? Like if they didn't make it optional to verify the telephone number, what would easyDNS do then? From their post, I presume they would go insane, declare Holy war on the ICANN, and then start assaulting ICANN officers with the sharp edges of their ibook 12"
They also complain that its a huge phishing opportunity because they must send mails with a link for people to click, but according to the ICANN spec they link to the actual requirement is[1]: """ [...] sending an email requiring an affirmative response through a tool-based authentication method such as providing a unique code that must be returned in a manner designated by the Registrar """ So the mails looking very phish-y is entirely their their own choice, the spec does not mandate that the title is "Look at these funny pictures, friend" or anything.
Finally, they complain this will lead to a lot of big sites going down because they are forced to suspend domains if people don't take certain action within a certain time (although they don't clearly argue that the time is too short or something like that). But big sites already go down because the dns owner has been negligent with their interactions with their registrar, like failing to pay their fees for instance.
So this is not a new type of problem really, you actually already have good reason to read the mail from your registrar, who knew? (Not Sony online: http://www.pcworld.com/article/2454820/sony-gaming-websites-...)
[1]: https://www.icann.org/resources/pages/approved-with-specs-20...
I know this, because I work for a registrar and was privy to the 2013 RAA negotiations.
No doubt, some assholes out there will try it, but I know we won't.
"there's no real need to charge people to unsuspend the domain"
By that token there is no need to charge people for many things that businesses charge for that don't cost them any money at all (or a nominal amount) and are pure profit. Or even to charge for bringing a domain out of redemption over and above the actual reimbursed cost for doing so. The fact also that some registrars charge typically or don't charge shouldn't really enter into the picture of "scummy" or "not scummy" by any company that chooses to have a different process.
Not that by what I am saying it should matter but the mere fact that you are putting a name on hold means that your support or customer service costs should in theory increase. If a name is on hold then that means a customer could call or write an email which has to be addressed by a person possibly. And there is a cost to providing that service. It is not zero obviously.
"The Net interprets censorship as damage and routes around it" should be the ideal we aspire to. LEA and intelligence-agency intervention in the Internet system is typically damage to our liberty-printing machine, one way or another. Their incentive structure offers no benefits and poses a lot of difficulties in dealing with a free Internet. Pressure from them should be expected as an open adversary to the free Internet, and defended against.
Believe it or not, what the LEAs were looking for in the first place was significantly more extensive then what ended up in the RAA. Here are their recommendations: https://www.icann.org/en/system/files/files/raa-law-enforcem...
No matter what the registrar does, the phisher can obtain and alter a copy of it.
The only way to stop the phisher is to inconvenience the customer in a much more annoying way. The registrar could remove all hardpoints to which any phisher could attach his payload, such as by omitting phone numbers, clickable links, scripts, or customer-identifying information. That leaves, "Contact your registrar as soon as you are able, or your domain may be disabled within 15 days."
Anything that anyone does to make the validation process easier could be hijacked to put the customer in the phisher's false reality.
What would occur if ICANN, at the behest of law enforcement, changed their rules to require a phone conversation explaining what the domain is for, forms filed in triplicate, a cheek swab, a rectal exam, and 1% ownership in the company?
If ICANN turns into an unacceptably bad actor for whatever reason, where does that leave the Internet, what is its recourse?
Good luck getting anyone to agree on which one though.
"If you find that your domain contact data is current and accurate, there's no need to take action. If, however, your domain contact information is inaccurate, you must correct it."
This was sent on May 5th - when does this new policy take effect or does it only effect when you renew/transfer/register?
Edit: I RTFA again and see that the date is June 23rd(?)
If it was accurate, GoDaddy is correct - there is nothing further for you to do.
If, on the other hand, the email they sent you would've bounced back as undelivered then you would've ended up into the next phase. "Click this within 15 days or else."
OVH also just sends an email that you can ignore if the information is accurate.
That email you got out was a WDRP email; the WHOIS Accuracy Program is a different policy.
Personally, I don't think it'll happen any time soon. The only successful DNS fork is North Korea's.
Many ccTLD registries have stricter policies when it comes to WHOIS data, and actively audit their contact databases for dubious data, place restrictions on contact updates, or actively review registrations and contact updates to ensure that the contact data provided is valid.
.me, .co, .io, .ac, .sh, and a few others, are relatively easy-going. .us is straightforward enough too, and though there are technically restrictions on who can register .us domains, they're not really enforced all that actively by Neustar. I really like the .me registry: they're good people.
You can argue that ICANN could have done better. And part of me still cares, but of course ICANN fucked up the existing root. In the current business and legal climate, it's basically a foregone conclusion.
A better system would be something based on a cryptographic blockchain/ledger, like Namecoin. Thus, no reliance on a central authority to decide which domains are or aren't valid; you instead just look at the ledger (which is maintained decentrally by network participants).
Actually, all my traffic is v6 by default using Telenet (Belgium) and XS4ALL (the Netherlands). And yes, those are mainstream ISPs. Lots of services, most noticeably Google and thus Youtube, use it by default as well.
We're nowhere near 100% yet, but as the need increases we are getting there.
It was a side point. I'm on dual stack Comcast, so I already knew what you're telling me, and I made the point nonetheless.
So I do not understand how you can say we cannot deploy v6. You are running dual stack as well, clearly we are on the way there? And yes of course we first need widespread deployment before we can turn off v4 entirely, but the fact that we both have it means that people are getting it and that we can turn off v4 at some point in the future.
And as an aside, we don't actually need 100% exactly: at 99% (or something) it's not going to be cost effective to get v4 addresses for everything anymore and more stuff will become v6-only.
If namecoin were to take off it would just collapse under it's own weight once squatters move in. So, outside of ICANN pushing huge and onerous changes down to their TLDs, I don't really see the utility for namecoin beyond providing resolution for services that would get their domains revoked by a registry for policy reasons or following legal orders.
And that's all you'll find. So who knows. It's a pain in the ass.
Should web surfers have to right to see who owns a domain (via whois) even if the domain owner doesn't publish that info on the site? Should they have the right to (try to) contact the domain owner via the whois and have a reasonable expectation that that email is going to get to the domain owner (even if they choose to ignore it)?
I actually think the rights of web surfers are far more infringed upon by being unable to access a website because the contact at the organisation that built and paid for it was on holiday or ignored an email (or possibly didn't even see it because the spam filter thought it looked like a phishing attempt)
I cannot believe you are defending this.
And for the record, as a domain owner I actually don't think you necessarily have a right to email me or the non-technical administrative contacts to try to sell us similar domains or persuade me to switch to your dodgy registrar. Even if I don't provide an email address there's always the option of taking it up with the registrar if there's a genuine legal issue with the domain or what it points to.
I also don't see any obvious reason for why this particular technical problem would count as violating the users rights by denying access and others would not. So for instance you can claim that broken dns records violates the users rights by denying access, but then you also must agree that a broken device driver is violating the users rights of access. Have fun with that.
But if you asked me to choose between a 'right' to access a website the owner had intended to make available to me or a 'right' to reach the owner's administrative contact, I think I'd consider the former more important. Then again, I'm not a lawyer, a phisher or a spammer, so ICANN's policy change isn't really meant for me.
If we even allow anyone to view a whois record, then should it be accurate? So, why not just get rid of whois entirely if it's going to either contain false information or no information at all?
I totally agree with you that people shouldn't ben able to email you at-will, just trying to sell you something, sell you a similar domain, or try to switch you into moving to another registrar. (Generally those would fall under email spam, anyway?)
There are other reasons why people need to contact site owners, though. Like because of DMCA requests, or maybe even their site is broken, contact form on site broken, or something similar.
But again, if the whois data is going to be inaccurate, missing, or just false then why even have it in the first place?
By "who owns", this means, "give out their name, address, phone number and e-mail address."
So in that context, that depends. If they are a business, then yes. There should be corporate contact information there.
If they are a non-commercial hobbyist site, then no. Absolutely not. Think about the incredible harm this would have on stalking victims. Or how about enabling more swatters?
Like domain registrars and certificate authorities; domain proxy services are just another tax on citizens wanting to participate on the web.
Fortunately it was a domain I was going to let lapse so I didn't bother trying to deal with their support but I swear I verified it 3 different times and never once did it say it successfully went through. Very frustrating experience.
Imagine my surprise when they wrote back, telling me it was legit.
What an awful, awful program.
Is that an option? Seems to sidestep these rules, but these rules seem silly.
Even the guy who invented WDRP later admitted it as a useless program which should die. http://www.circleid.com/posts/20120719_a_confession_about_ic...
This is much much worse.
What happens if you become sick or get in an accident and must go to a hospital? Game over?
For a moment there, you had me thinking that Amazon had purchased Gandi! But no, I see they are just partnering with them. Phew.
Let's not throw the baby out with the bathwater.
Projects like the WAL actually do help prevent the spread of malicious sites. Some TLD registries go into great length to ensure that the identity of their registrants is valid (address, phone, email).
Valid whois data is a necessity when processing some of these cases (from a legal point of view). I see this in practice every day.
The potential burden for the majority of domain owners (those who don't plan to do anything illegal with their little piece of internet real estate) is undeniably an issue, but projects like WAL have very real merit for the internet as a whole.
This looks exactly like security theater to me.
Disclaimer: I may or may not have a domain registered in the name of my cat.
Secondly, I'm not even sure how you'd reasonably do this in a country like the United States where there's a functioning government if only because there's 50 states plus other territories to deal with. How would you go about verifying that "Walter P. Fluffington" exists and lives at some arbitrary address in Puerto Rico? It seems extremely time-consuming unless you are going to exclude people who have driver's licenses or some kind of government ID issued to them, or are foreign citizens living and working there under a visa of some sort.
This also doesn't even come close to addressing what happens when you register a domain with someone else's name.
The whole thing is completely pointless. If South Korea can't do it, nobody can.
Compare to how we verify certificates. Trusted CAs issue certs and we verify the chain of trust.
A) What does that even mean? What's considered valid? There's got to be at last 100 different forms of this in the United States alone. How can anyone be familiar enough with all of these forms to verify them? Then consider there's several hundred countries around the world, each with equally quirky identification systems.
B) So the "face to photograph" method of identification depends on someone supplying a photograph of themselves? Since when is this part of the process for applying for a domain name? Secondly, it's impossible to verify that the photograph is of the applicant. Are we applying for domains at the DMV now? What about people who have identification where their face is concealed, or is a woman no longer allowed to register a domain in places like Saudi Arabia?
C) Why should having government-issued identification be a pre-requisite for owning a domain name? What if you're 10 and want "billyslemonadestand.com", paid by Bitcoin?
This isn't a trust issue. Owning a domain name shouldn't be terribly difficult. This isn't like an EV SSL certificate where a notary is going to be involved. Their entire process is complete bullshit and does nothing to improve the security of anything.
No doubt valid WHOIS data is helpful when wanting to know the identity of a domain administrator, but again the point is WAL does absolutely nothing to ensure that in any case where the owner doesn't actually want to be identified.
Outlawing encryption helps catching terrorists. Ruling that the use of Tor is justification for a full search of all of one's electronics helps catch child abusers. Forcing every email to be tied to a real life identity helps stop spam.
None of that is justified.
This is laughably implemented.
I would discourse further on the silliness of this policy, but they stated it best: "You can thank ICANN...because if it were up to us, and you tasked us with coming up with the most idiotic, damaging, phish-friendy, disaster prone policy that accomplishes less than nothing and is utterly pointless, I question whether we would have been able to pull it off at this level. We're simply out of our league here."
* New domain registration
* Domain transfer
* Upon receipt of an NDN (bounce) in some other mailing
We'll be putting together a mini-FAQ based on questions and feedback of this.
Does it look the same as "a seat on the exchange" in the financial world - trade on an exchange, you and your counterparty both get skimmed by a "broker" as well as by the exchange.
Anything to make something as simple as putting a tiny entry into a database more of a pain and hassle justifies the ridiculous fees. The worse they do it the better it works for them. Incentive, yeah, let's make sure this screws up and looks like phishing, then they'll really need us and we can claim to be the good guys with utterly ignorant law enforcement who don't understand what they're asking for being the bad guys.
If this cost the intermediaries money rather than being something that will turn out to be lucrative for the industry as a whole, you'd have a very different result.
Now watch the downvotes and screams from the intermediaries and their apologists. Hi, enjoy your money!
One thing I can think of off the top of my head is that it makes domain squatting a bit more expensive. $10 instead of 2c is 500 times less domains for the same amount of money. At the same time, $10/year is a reasonable entry price for "I'm seriously considering using this domain"
Domain names are a scarce resource, it makes sense to charge a good amount of money for them
If you want to make the argument of the necessity of a tax who gets it? Those who were on it early enough to capture the regulator. Interestingly on a philosophical level both republicans and democrats claim to hate regulatory capture.
Republicans would want to open ICANN and it's intermediaries up for competition, democrats would prefer to nationalise the lot, yes I know, that's just the ideology not the behaviour of elected official much of late.
I downvoted you for this grandstanding, not for the rest of your post (which I agree with, for the most part, I think it's a crock). The "conspiracy behind every hedge" rhetoric stinks, and I wish we wouldn't do it here.
Watch the responses, see whether flagging what I think they will be in advance is a useful thing or not.
Grandstanding from an anonymous account? Really?
Can we be adults now. /me watches for the avalanche of downvotes that always happen when you point this kind of thing out around here.
> Resist commenting about being downvoted. It never does any good, and it makes boring reading.
> Please don't bait other users by inviting them to downvote you.
I think predicting it on the back of a reasonable post when you know what is going to happen despite it's reasonable nature kind of highlights the problem that exists here. I think I have a pretty good sense of when a post is going to get slammed in downvotes rather than responded to sensibly, so testing it with a proper demonstration seems to be the right thing. YMMV. I have tried the other way too by the way.
I didn't bait nor invite, I predicted. And did so correctly. But I don't believe in calling people names like "conspiracy theorist" I think that is intellectually lightweight. I wonder if you do too?
If you put your real name, address, phone number, and email in your domain registration, and keep it updated, there's no problem. I've had real contact info on all my domains for two decades. I get maybe one phone call a year, two or three email spams, and a letter or two.
Quit whining.
If you happen to be a not-savvy domain holder, you get a letter that looks like it's for a domain renewal, you fill it out and return it with a check, and that gives DRA the authority to transfer your domain registration.
And getting it back away from them is an unpleasant process at best.
For boring, non-interactive sites, I think that's probably fine.
I never put real information into WHOIS data (except for my email) because I have absolutely no desire for people who check to know who I am. I'm not running businesses and I've never made a dime off any of my sites.
I just think of all the community drama I've seen and how much worse it would be if they had my real name, phone number, and address. Not even considering all the other places I post under the same screenname, there's been plenty of nonsense on the forums I've run, and people have been perfectly happy to dox and harass other people whose personal information they could find out over incredibly trivial things.
No thanks.
Free speech? Nah, fuck it. Opening a venue for people to harass and threaten others is more important.
If people have a valid need to contact the admin there is an admin@domain.com they can email that does not give my full name and home address.
Having to pay a company to hide these details is extortion at best. It's like the mafia asking for "protection money". If you don't pay them, they have someone pay you a little visit and convince you it's worth the investment.