/ Most Viewed

You Just Signed a Registry Contract With ICANN. What Are Your Plans?

Back on February 4, 2013, I wrote a CircleID post entitled 'How the registrar Cash Flow Model Could Collapse with New ICANN gTLDs.' My key point back then was this: new gTLD applicants need to be mindful of how the cash flow policies of their registry (and of their back-end service provider) could impact whether their TLD is actively promoted by ICANN registrars... registries have historically assumed near-zero risk. This is going to change. more

Domain Enforcement in a Post-GDPR World

The implementation of the General Data Protection Regulation (GDPR), and ICANN's conservative temporary policy, which favors privacy and limits registrar liability, has made domain enforcement against cybersquatters, cyber criminals and infringement more difficult, expensive and slow. With heightened concerns over privacy following high-profile breaches of consumer data and its subsequent illicit use and distribution, there is no question that consumer data protection practices would come under scrutiny. more

Internet Users: Is It Time For A Declaration Of Independence?

Although, undoubtedly, it is disappointing, it is not surprising that after four years of experimenting with Internet governance, the first corporate entity to take on the ambitious task -- the Internet Corporation for Assigned Names and Numbers (ICANN) -- has not achieved the legitimacy of a global consensus-based manager of the Internet's domain name system. Simson Garfinkel explains, in his insightful piece in the March 2003 issue of Technology Review, that it has become conventional wisdom that "ICANN serves as a model for systematically shutting the public out" of its policy making activities. It should go without further explanation that the ICANN model is a particularly bad governance model, if consensus-building is supposed to be the corporation's linchpin of legitimacy. Among a few other concerns, ICANN, unmistakably, suffers from power-sharing phobia. more

Is NTIA’s Transition Decision the Right Dose of Chemotherapy to Repair Trust in Multistakeholderism

Proper, transparent, accountable U.S. NTIA's Transition of its oversight of the Internet to something other than a single country oversight is something I have always believed in and spoke and written about repeatedly for years and is long overdue. But NTIA's March 14th declared intent to transfer "Key" Internet roles is not only very ambiguous but leads to new questions and concerns that must be answered before anything starts taking place. more

Haste Makes Waste: Comments on ICANN CWG IANA Transition Proposal Indicate Serious Process Problems

On December 1, 2014 the Cross Community Working Group (CWG) on Naming Related Functions published a Draft Transition Proposal. The comment period on the Proposal extended for twenty-one days; due to a requirement imposed by the separate IANA Coordination Group (ICG) that a final proposal be received by mid-January, there was no provision for a follow-up reply comment period as is standard ICANN Practice for issues of far less consequence. more

Ongoing Internet Emergency and Domain Names

There is a current ongoing Internet emergency: a critical 0day vulnerability currently exploited in the wild threatens numerous desktop systems which are being compromised and turned into bots, and the domain names hosting it are a significant part of the reason why this attack has not yet been mitigated. This incident is currently being handled by several operational groups. This past February, I sent an email to the Reg-Ops (Registrar Operations) mailing list. The email, which is quoted below, states how DNS abuse (not the DNS infrastructure) is the biggest unmitigated current vulnerability in day-to-day Internet security operations, not to mention abuse. more

Wow! BIND9 9.10 Is out, and What a List of Features!

Today the e-mail faerie brought news of the release of BIND9 9.10.0 which can be downloaded from here. BIND9 is the most popular name server on the Internet and has been ever since taking that title away from BIND8 which had a few years earlier taken it from BIND4. I used to work on BIND, and I founded ISC, the home of BIND, and even though I left ISC in July 2013 to launch a commercial security startup company, I remain a fan of both ISC and BIND. more

Proposal for .sport, a New Top-Level Domain

OK. Now my lawyer has given me the green light, I can officially announce I am working on a proposal for a .sport TLD, to be submitted to ICANN for consideration as a new TLD next year. There is still a long way to go in terms of getting the proposal ready, but I this this one is a winner... more

New gTLDs: The Registry Lock

Last week, The New York Times website domain was hacked by "the Syrian Electronic Army". Other famous websites faced the same attack in 2012 by the Hacker group "UGNazi" and, in 2011 by Turkish hackers. Basically, it seems that no Registrar on the Internet is safe from attack, but the launching of new gTLDs can offer new ways to mitigate these attacks. more

SIP Co-Author Henning Schulzrinne Appointed CTO of the FCC

In a move to be celebrated by many of us with a VoIP background, the United States Federal Communications Commission (FCC) announced today the appointment of Henning Schulzrinne as Chief Technology Officer (CTO). As the release indicates, Henning's role as CTO will be to: ...guide the FCC's work on technology and engineering issues, together with the FCC's Office of Engineering and Technology. more

Russian Minister of Telecom and Mass Communications Talks About Cyrillic Domain Names

Igor Schegolev, the Russian Minister of Telecom and Mass Communications spoke at the opening of the InfoCom 2008 exhibition in Moscow. Among other things, which made news (for example, that the Russian government will be implementing a free and open source based operating system on all computers in the Russian schools), he also made the following remarks - translated by me in English. more

Cryptography is Hard

In the debate about "exceptional access" to encrypted conversations, law enforcement says they need such access to prevent and solve crimes; cryptographers, on the other hand, keep saying it's too complicated to do safely. That claim is sometimes met with skepticism: what's so hard about encryption? After all, you learn someone's key and just start encrypting, right? I wish it were that simple - but it's not. more

Deeply, Deeply Flawed Economic Report and Analysis of New gTLDs Posted by ICANN

The reports and analysis by Dr. Dennis Carlton are deeply, deeply flawed. I will prepare a long rebuttal to it in the coming weeks, but wanted to go on the record early as to its weaknesses. The analysis appears to be based on a very limited review of the market for domain names, and utilizes little actual data. It fails to even consider how nuanced the market for domain names has become, and how registry operators can exploit those nuances, including tiered-pricing... more

How to Handle an Outage Like a Pro

In just the last two weeks, there were three major DNS outages between Google, Microsoft Azure, and Fonality. But only one of these companies was able to make even bigger waves with the way they handled their blunder. Fonality, who sells VoIP services and business phone systems, offered a very rare and transparent analysis of their outage. In a detailed statement from Chief Marketing Officer Jeff Valentine, readers were given crucial insight on how to prevent the same mistakes from happening to other companies. more

Call Spoofing: Congress Calls on FCC, Russia and China Answer

It is both amusing and dismaying. Last year, Congress passed Ray Baum's Act telling the FCC to do something about those pesky incoming foreign SPAM calls and texts with the fake callerIDs. The FCC a couple of weeks ago responded with a chest thumping Report and Order claiming it has "extraterritorial jurisdiction" that is does not have, and promising it will do something. Don't hold your breath on that one. more