<- Back
Comments (35)
- SpaceLawnmowerThis article is pretty light on details. The linked presentation goes into a lot more detail with statistics about which registrars and organizations are the worst offenders etc.https://view.officeapps.live.com/op/view.aspx?src=https%3A%2...
- TLDRisk> Any additional measures should not require ICANN to assume the role of a global content regulator or criminal-law authority.> The community should instead consider whether contractual and operational arrangements adequately enable registries and registrars...Those are things that are easy to say and hard to do. From the perspective of a good faith registrant, the enforcement is already too complex. There are hundreds of registries and thousands of registrars, all enforcing their own interpretation of the rules, so you end up with massive inconsistency.No one wants their 10+ year old domain revoked for DNS abuse if they've been the victim of a security incident and it got misused, but dealing with that is hard and the economic structure of the industry isn't conducive to "intelligent" handling of complaints. Any solutions will scale the same as big tech with massive, automated systems that turn good faith participants into collateral damage.A big problem for the domain industry is the way registries are shielded from liability and registrants. The registrars operate on thin margins and take on all the liability and customer support.I don't think the registries will be given more responsibility. That's based on a personal bias though. I think the industry is set up to benefit the registries at the expense of registrars and registrants.The registrars are the most likely party to be saddled with extra responsibility and I don't think that's a good solution because they have an economic incentive to look the other way. It's also a weakest link industry so, even if Porkbun, etc. are working overtime to keep bad actors off their platform, there's always someone willing to onboard a scammer for a few dollars.In my opinion, there should be more talk about a centralized system funded by fees that ICANN collects. As a good faith registrant I want consistent, well defined rules with an appeals process, transparency etc.. I also don't care if I have to pay an extra dollar or two a year for my domains if it improves the industry overall.Semi-related, does anyone know if there are any lists or decent sources for finding domains that have previously been suspended or put on block lists? That would be useful info for would-be registrants. No one wants to get surprised with a tainted domain.
- xp84While I'm definitely not inclined to trust whoever wants to introduce new barriers, part of me actually thinks that the availability of second-level names (e.g. example.com), instantly, for trivially-low prices... maybe you could make a case that we get more harm than good from it.If you're starting a new commercial venture, something that cost $1000 and took a week would still be one of the cheapest and fastest parts of that process. If you're doing a hobby project or a speculative startup, using a subdomain would be fine. It worked for Altavista.digital.com and Google.stanford.edu.The argument for shifting (back) to a model like that would be that the hierarchial DNS served as a chain of responsibility. Today a lot of companies irresponsibly use dozens of domains, presumably either because they think people are too stupid to learn to type an additional period in a name, or because their internal dysfunction makes provisioning a subdomain an 11-month project. It's terrible that citibankonline.com, citibank.com, citicards.com, citientertainment.com, citi.com, and citigroup.com are all official domains that Citigroup uses. A user seeing a link to, say, 'citicardbenefits dot com' has zero methods of establishing provenance.And of course, under conditions where 2LDs were expensive again, 'free subdomains' would certainly still be a thing, as they even back were when .coms were $50 or whatever. We had cjb.net, a bunch of clever '.to' domains, afraid.org, etc.Under the 'modern' system, the problem of "who do we need to contact about an obvious scam site" has been pushed up to the largest possible scale - the GTLD registries, whereas a scammer abusing a "free subdomain" would be shut down by the admins at that second level.In the end though, I admit we're stuck with the current way, or, (possibly) some hare-brained KYC scheme that will subject everyone to a high level of government censorship and make anonymity unavailable to good actors who really deserve it.
- inigyouMy opinion is that as long as criminal organisations exist, there's no reason they shouldn't be allowed DNS names. That will just help the police track the actual organisation.
- azeembaI agree with the premise but this article doesn't really provide a strong argument. It mentions stats about child exploitation but doesn't show how that's related to gtlds.Stats about the block list are good (10% of gtld domains are blocked) but thay requires comparing it with a baseline. How many of non gtld domains are blocked?
- edentI have some experience of dealing with this when working for .gov.ukA registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims.By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists.At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless.
- thataccountThe internet DNS system is broken in multiple ways. We would do better to have a shared DHT table with unique keys addressable to names.
- jeffbeeSlide 17 is the one people should read before they get on their blog complaining that their emails are rejected by Google and Microsoft. The entities associated with your domain and network, the DNS hosts, registrars, network blocks, and all that each have their own reputation. It is easy for the unwitting to fall in with criminals.
- inigyougTLDs themselves are a scam, but because it's rich people running that scam it gets a pass
- seanyJust just seems like a reason to have a truely distributed DNS system that is censorship resistant. The complaints presented should be _unfixable_ since they are a feature, not a bug.
- jonathanstrangeWhy should alleged "cybercriminals" not be be allowed to register domain names? There are procedures of seizing domain names in various countries, and these are in my opinion already somewhat questionable, but the premise of this article seems to go far beyond that and suggest that what they call "malicious actors" should somehow be deprived of infrastructure because they are suspected criminals. The rationale for that is that they later show up on blocking lists...?That seems beyond any reasonable due process and legal standards. Or am I missing some international legal standard and judicial oversight that would play a role here? I'm genuinely confused.
- TZubiriIf you are thinking of launching your own TLD, or second level tld, or effective TLD (like vercel.app). I suggest being creative instead of making yet another TLD with the standard checkbox rules.If your TLD is location based for example, consider verifying and linking the TLD to an identity, by local means, like a national ID.
- fenestella[dead]
- thinkafter[flagged]