The year 2010 is turning out to be the "year of DNSSEC" from Registry implementations, Registrar implementations, ISP support, to the Root being signed this summer. Because we are dealing with such critical infrastructure, it is important to not lose sight of careful implementations. more
FireEye announced a new piece of malware yesterday named MULTIGRAIN. This nasty piece of code steals data from Point of Sale (PoS) and transmits the stolen credit card numbers by embedding them into recursive DNS queries. While this was definitely a great catch by the FireEye team, the thing that bothers me here is how DNS is being used in these supposedly restrictive environments. more
By this time next year the allocation of the new Internet namespace will be complete. Several hundred contention sets, ranging from likely blockbusters like .WEB to somewhat less obvious money-makers like .UNICORN, will be decided by some method. One way to resolve contention is to form a joint venture... That works well when there are only two competitors and there's a good basis of trust, and it's a great solution because there are no losers. But if there are three or more competitors, or if you don't like and trust your prospective partner-to-be, this really isn't an option. more
A recent report by NS1 provides a comprehensive look at global DNS traffic trends. It reveals that public resolvers dominate the internet, accounting for nearly 60% of recursive DNS usage. Telecom giants represent nearly 9%, with Google the clear front-runner at a little over 30%, followed by Amazon Web Services at 16%. more
Well, it's that time of year again. The time of year when I look back at all of the biggest domain news stories from the last twelve months, and also reflect on my predictions from last year. As expected, GDPR has had a major impact on the ability to access domain ownership information. And we did indeed see a number of M&A transactions over this last year. However, there wasn't a lot of new .Brand activity. This is one prediction where I may have missed the mark... more
"Is Your Internet Up-To-Date?" Does your existing Internet connection work with IPv6 and DNSSEC? Do your web sites support IPv6, DNSSEC and TLS? Is there a quick way to find out? Earlier this month a new site, Internet.nl, was launched to make this all easy for anyone to test. All you do is visit the site at en.internet.nl (also available in Dutch) and just follow the very easy links. more
The purpose of the Uniform Dispute Resolution Policy, known as the UDRP (hereafter the "Policy"), is to determine disputes relating to the registration or acquisition of domain names in bad faith. To succeed in a UDRP action (i.e. to obtain cancellation or transfer of the disputed domain name) it is necessary for the party bringing the complaint (the complainant) to show that (i) the disputed domain name is identical with or confusingly similar to a trademark or service mark in which the complainant has rights; (ii) the domain name holder (known as the respondent) has no right or legitimate interest in respect of the domain name; and (iii) the domain name was registered and is being used in bad faith. Each of the aforesaid three elements must be proved by the complainant to warrant relief.
more
In a recent interviewed with Roger Collins, president of ProProject and the new owner of Afternic.com, CircleID investigates the logics behind ProProject's strong belief in the domain name secondary market. Once known as a primary domain name auction site, Register.com had purchased Afteric.com in the September of 2000 for $48 million in cash and stock -- 2 years later the site was shut down as money-losing unit until ProProject came along. more
It seems like there is more disturbing news every day about Chinese infiltration of our telecommunications networks. A recent headline said that nine large ISPs have now been infiltrated. Tom Wheeler, a previous Chairman of the FCC, recently wrote an article for the Brookings Institute that speculates that the ability of the Chinese to infiltrate our networks stems back to decisions made decades ago that have never been updated for the modern world of sophisticated hacking. more
As if we didn't have a long enough list of problems to worry about, Lumen researchers at its Black Lotus Labs recently released a blog that said that it knows of three U.S. ISPs and one in India was hacked this summer. Lumen said the hackers took advantage of flaws in software provided by Versa Networks being used to manage wide-area networks. more
We are on the brink of the most serious threat to the open and public Internet for decades. ICANN, under pressure from domain name registrars and EU data protection authorities, has proposed an "interim" plan that will hide critical information in WHOIS. Security, threat intelligence, and anti-abuse professionals rely on WHOIS to track down bad guys and keep the Internet as safe and secure as possible. more
In a developing cybersecurity concern, IT experts and researchers warn of potential misuse of Google's new .zip and .mov top-level domains (TLDs), which they argue could be exploited for phishing attacks and malware distribution. more
What better way to kick things off than to review the domain aftermarket, three years after my then infamous "Domain Aftermarket Overdue For An Asset Repricing" article which caused a bit of a stir at the time. I said then that there was a big recession coming, in it everything would suffer severe price declines, and that domain names would not be exempt. I went on to say that the low-hanging fruit in the domain industry had been picked: type-in activity would go into secular decline over time, and that domainers would face increasing competition from other avenues such as DNS resolvers, ISPs and web browsers. It didn't go over well. more
A few weeks ago I wrote about Apple's IPv6 announcements at the Apple Developers Conference. While I thought that in IPv6 terms Apple gets it, the story was not complete and there were a number of aspects of Apple's systems that were not quite there with IPv6. So I gave them a 7/10 for their IPv6 efforts. Time to reassess that score in the light of a few recent posts from Apple. more
In the last three years, almost 1,000 new generic top-level domains (new gTLDs) have entered the market, increasing the previous 22 options for generic domain name extensions, like .com, .net and .org, by almost 5,000 percent. While expanded choice can be good for consumers, small businesses and website owners may be overwhelmed by the many different options and have a lot of questions about which domain extension is right for them or their brand. Recently I spoke with editors at WIRED about what their readers should ask themselves when determining how to choose the right domain name and it came down to the following seven key questions. more