/ Most Commented

Letting DNS Loose

RFID tags, UPC codes, International characters in email addresses and host names, and a variety of other identifiers could all go into DNS, and folks have occasionally proposed doing just that. Its really just a question of figuring out how to use the DNS -- its ready to carry arbitrary identifiers. And by the way, this isn't a new idea, see RFC 1101 for proof, although even earlier I designed the DNS in the early 1980s to allow it to be so, but it seemed too far fetched to document for a while. ...I was in Geneva for a WSIS meeting of CTOs, and was surprised that the various organizations (ITU, ICANN, ISOC) haven't figured out that they need each other to make this technology work, rather than asserting ownership. more

The Irrationality of Deploying IPv6

For the past few decades, there's been a relatively straightforward narrative on the economics behind the IPv6 transition that goes something like this: sooner or later, IPv4 scarcity will drive costs up until they exceed those of deploying IPv6. A competitive market will then make the rational choice and transition to a more efficient mode of production and deploy IPv6. This is textbook economics, and - with the disclaimer that I'm not a trained economist - it appears to be incorrect. more

ICANN and Attorneys General: Ends, Means and Unintended Ends

In a move, unprecedented in scale, ISOC moved to sell PIR, the registry for .ORG, to a for-profit entity which intends, in turn, to convert PIR into a for-profit entity itself. This move has, understandably, raised concerns from around the Internet community and cast a bright light on ICANN, the nature of its contracts with Registries and the responsibilities of the ICANN Board... As the Vice Chair for Policy of the At-Large Advisory Committee (ALAC), I've tried to navigate a consensus involving ALL of those parties because of our diverse membership. more

ICANN IPC & BC to Host Cross-Community Call on Accreditation/Access Model for Non-Public WHOIS Data

The ICANN Intellectual Property Constituency (IPC) and Business Constituency (BC) will be hosting a community-wide discussion regarding the proposed accreditation and access model for non-public WHOIS data, which was first circulated to the community during ICANN 61. The discussion will take place via ICANN-supported remote participation and/or audio bridge this Friday, April 6, 2018, from 1400-1600 UTC. more

Loudmouths Wanted for ICANN WHOIS Replacement Work

TL;DR? It's worth reading, BUT, if not -- ICANN has yet another group looking at WHOIS, and there is a huge push to redact it to nothing. I spend easily half my day in WHOIS data fighting online crime, losing it would not make my job harder, it will make it impossible. PLEASE JOIN THE ICANN GROUP and help us fight back against people who are fighting in favour of crime. more

Can We Stop IP Spoofing? A New Whitepaper Explores the Issues

In March 2013, Spamhaus was hit by a significant DDoS attack that made its services unavailable. The attack traffic reportedly peaked at 300Gbps with hundreds of millions of packets hitting network equipment on their way. In Q1 2015, Arbor Networks reported a 334Gbps attack targeting a network operator Asia. In the same quarter they also saw 25 attacks larger than 100Gbps globally. What is really frightening about this is that such attacks were relatively easy to mount. more

ICANN Should Curb Anonymous Domain Name Abuses

E-commerce has revolutionized how businesses sell to consumers -- including those involved in illicit activities, such as websites peddling illegal narcotics, pirated movies and music, or counterfeit handbags. For example, 96 percent of Internet pharmacies do not comply with U.S. laws, and as they ship pills tainted with paint thinner, arsenic, and rat poison, they put the health and safety of consumers at risk. Why don't law enforcement officials do more to combat this problem? Partly because of the difficulty of identifying who is actually operating the illegal pharmacies. It is time to fix this, while allowing anonymity for those who deserve it. more

DNSSEC - Failure to Launch

DNSSEC is a mechanism where clients can verify the authenticity of the answers they receive from servers. There are two sides here. The server must supply signed answers, and the client must verify the signatures on those answers. The validation/verification side is widely implemented, but there are very few signed zones... However, if no one signs their zones, those validating resolvers don't have many signatures to check. more

Ensuring Trust in Internet Governance

This week in Singapore, important decisions are being made about the future of the Internet at the Internet Corporation for Assigned Names and Numbers (ICANN) 52 conference. At stake are fundamental questions: Should the American people surrender stewardship over core technical functions that have preserved the open and neutral operation of the Internet since its inception? Should the Obama Administration cede this authority to an organization many consider to be non-transparent, unaccountable and insular? more

The Empire Strikes Back: “New” Verisign Hums a Familiar Tune

Losing your monopoly must be hard. True, few companies ever experience that particular breed of angst, but if Verisign's reply to even modest success in the new gTLD marketplace is any indication, it must be very hard to say goodbye. We understand why they're worried... The quality of newly registered .COM names is dropping and has been for years. And there is nothing Verisign can do about it. So welcome to the fire sale. more

Experience and Evidence Point to Strong Renewal Rates for New TLDs

In the tenth month of the revolutionary expansion of generic top-level Internet domains, global registrations in new gTLDs reached more than three million addresses, providing the clearest illustration yet of the strong international appetite for new, relevant addressing options. As we near the first full year of new gTLD availability, focus now shifts to another critical metric -- renewals -- which we expect to show similar strength based on history and data analysis. more

Anti-Spoofing, BCP 38, and the Tragedy of the Commons

In the seminal 1968 paper "The Tragedy of the Commons" , Garrett Hardin introduced the world to an idea which eventually grew into a household phrase. In this blog article I will explore whether Hardin's tragedy applies to anti-spoofing and Distributed Denial of Service (DDoS) attacks in the Internet, or not... Hardin was a biologist and ecologist by trade, so he explains "The Tragedy of the Commons" using a field, cattle and herdsmen. more

What Did we Learn Today About .XXX From IFFOR Tax Return

The 2011 Tax return for IFFOR has been filed and our friend George Kirikos of Leap.com found it.. IFFOR's tax return is important for two reasons. First IFFOR return shows us how how much money the non-profit, which is suppose to receive $10 for each .XXX registration, actually received from ICM the operator of the .XXX TLD and how IFFOR spent the money. Second the return is important to see how the money ICM the registry operator of the .XXX TLD paid to IFFOR matches up to ICM reported number of .XXX domain name registrations. more

SEC Filing Reveals Facebook Network Equipment Valued Over $1B at Close of 2011

"Facebook reported in its SEC filing that it owns 'network equipment' valued at $1.016 billion at the close of 2011," reports Rich Miller of Data Center Knowledge. "The number reflects the expense of rapidly building a massive Internet infrastructure, including Facebook's shift from buying vendor gear and leasing data centers to building its own servers, racks and custom data centers." more

The Invisible Hand vs. the Public Interest in IPv4 Address Distribution

In the efforts to promote the public interest over that of monied interests in Internet Governance few issues are clear cut. One issue that has recently been discussed is that of requiring a "needs assessment" when transferring IP addresss blocks from one organisation to another (in the same or different RIR regions) or indeed when requesting IP resources from your friendly RIR. more