The Wall Street Journal is reporting that antitrust enforcement in telecommunication is being ramped up by the Obama Administration, after relatively lax times. In a piece entitled Telecoms Face Antitrust Threat it indicates that investigators are weighing up the roles of the large carriers and whether they are abusing the market power amassed under the Bush Administration. more
The information security industry, lacking social inhibitions, generally rolls its eyes at anything remotely hinting to be a "silver bullet" for security. Despite that obvious hint, marketing teams remain undeterred at labeling their companies upcoming widget as the savior to the next security threat (or the last one -- depending on what's in the news today). I've joked in the past that the very concept of a silver bullet is patently wrong... more
ICANN has launched a micro-site to serve as the online source for New Generic Top-Level Domain (New gTLDs) Program. From ICANN's announcement: "ICANN is in the midst of a major campaign to raise awareness around the world about the impact and possibilities of new gTLDs. The new site represents a foundational expression of the campaign. Many more new articles, tools, and materials will be made available in the coming days and weeks." more
Last November, ICANN launched a ticketing system for those interested in obtaining domain name registration data ("WHOIS"). Titled Registration Data Request Service, or RDRS, the portal aims to direct requests for WHOIS data to participating registrars, who then decide whether or not to disclose the data. more
President Donald Trump expected to sign an executive order on cyber security on Tuesday. more
Michael Berkens reporting in TheDomains.com blog reports: National Association of Secretaries of State (NASS) is an organization whose members include Secretaries of State and Lieutenant Governors of the 50 U.S. states and territories send a letter to ICANN in late July that was just published today, that the new gTLD's .INC, .LLC, .CORP and .LLP.should only be allowed to be registered by 'entities that are appropriately registered and in good-standing with the Secretary of State or other appropriate state agency." more
Dan Coats, Director of US National Intelligence warns China and Russia are increasingly using cyber operations to steal information, influence citizens and to disrupt critical infrastructure. more
The American National Standards Institute (ANSI) and the Internet Security Alliance (ISA) released today a new action guide to assist business executives in the analysis, management and transfer of financial risk related to a cyber attack. In 2004, the Congressional Research Service estimated the annual economic impact of cyber attacks on businesses -- which can come from internal networks, the Internet or other private or public systems -- to be more than $226 billion. In 2008, U.S. Department of Homeland Security Secretary Michael Chertoff named cyber risks one of the nation's top four priority security issues. more
No, this topic hasn't yet been exhausted: There's still plenty more conversation we can and should have about the proposed sale of the .ORG registry operator to a private firm. Ideally, that conversation will add more information and more clarity about the issues at stake and the facts that underpin those issues. That's why I'm planning to attend today's event at American University where the sale's proponents, opponents and undecideds will have a tremendous opportunity to better understand one another. more
In response to Russia's horrific invasion and war against the Ukrainian nation ordered by Dictator Putin that will live in infamy, an array of nations, organizations, and companies have responded to shun and shut off Russia in every possible manner. The actions include no-fly zones, removal from ICT network services, and essentially universal declarations of condemnation. For the first time ever, all Russian proposals to the International Telecommunication Union (ITU) quadrennial standards body plenary known as the WTSA have been "bracketed"... more
The Bug Bounty movement grew out a desire to recognize independent security researcher efforts in finding and disclosing bugs to the vendor. Over time the movement split into those that demanded to be compensated for the bugs they found and third-party organizations that sought to capitalize on intercepting knowledge of bugs before alerting the vulnerable vendor. Today, on a different front, new businesses have sprouted to manage bug bounties on behalf of a growing number of organizations new to the vulnerability disclosure space. more
The Internet Society today expressed concern over the recent order from the United States District Court for the Central District of California requiring Apple to bypass or disable the auto-erase function on a seized iPhone and to enable the FBI to more effectively conduct a brute force attack on the device. more
At a speech during the Security and Defense Agenda meeting on 30 January Vice-President of the European Commission, Neelie Kroes, showed how the Commission envisions public-private cooperation on cyber security. more
Two leading US senators, John Thune, chairman of the Senate Committee on Commerce, Science, and Technology, and ranking member Brian Schatz have signed a letter warning that without "significant accountability reforms that empower the community," Congress will not support the transition of the IANA contract from the US government to ICANN. more
On 11 February, I participated in a discussion about the pending sale of PIR at American University Washington College of Law, appropriately titled, The Controversial Sale of the .ORG Registry: The Conversation We Should Be Having. It was great to have a balanced discussion, free of some of the emotions that have often made it hard to discern the realities of the transaction. Certain misapprehensions arose in the discussion that we lacked the time to explore fully, so I want to take those up here. more