Showing posts with label IID. Show all posts
Showing posts with label IID. Show all posts

2015-12-08

Blocking New gTLDs, ICANN's 'Shadiest' Top-level Domains, 'Wholesale'

"ICANN is not a regulator and we have limited expertise or authority to assess the legality of ... [a new gTLD registry operator's] activities."Allen Grogan, ICANN Chief Contract Compliance Officer, 09 Apr 2015 (emphasis added)
For internet users, safety and security on the web is becoming more and more problematic due, in part, to ICANN's money-grab, the new gTLDs program, which unleashed hundreds of unwanted and unneeded new gTLDs (new generic top-level domains) onto the internet without any regulatory oversight from internet authority ICANN, or otherwise. The results have been dismal, for internet users and the domain name industry:
“Most new gTLDs have failed to take off and many have already been riddled with so many fraudulent and junk registrations that they are being blocked wholesale,” said IID President and CTO Rod Rasmussen recently.
The answer? Other than being sure your OS and Browser are updated and utilizing all security features available, consider blocking ICANN's 'shadiest' new gTLDs "wholesale" as indicated by IID's Rod Rasmussen, who, according to IID's website, is:
"... Co-chair of the Anti-Phishing Working Group’s (APWG) Internet Policy Committee and serves as the APWG Industry Liaison, representing and speaking on behalf of the organization at events around the world ... and is a member of ICANN's Security and Stability Advisory Committee (SSAC). Rasmussen is a member of the Online Trust Alliance’s (OTA) Steering Committee. He is a member of the FCC's Communications Security, Reliability and Interoperability Council (FCC CSRIC) ..."
And IID is hardly alone among respected security firms:

The shadiest characters in the world of top-level domains | ZDNet"In order to safeguard themselves against unwanted, suspicious traffic, Blue Coat recommends that the enterprise consider blocking traffic which leads to the riskiest top-level domains, and users should take caution against linking [or clicking] on links based on these TLDs if received over email or social networks." (emphasis, and link added)

How to block new gTLDs, or any Top-Level Domain, be it a gTLD or ccTLD, so your computer, smartphone, tablet or other device is not infected with malware, hijacked, etc.? Network administrators and even nations (see, e.g., China's Great Firewall), can block TLDs 'wholesale.' For individual users, it depends.

Using OpenDNS is one answer for individual users to protect themselves from ICANN's shadiest new gTLDs--see Block .xxx .info etc.. : OpenDNS"You can already block any domain you want, including the TLDs you mentioned, by adding them to your blacklist." 

A list of ALL top-level domains (TLDs) is here--be sure to allow legacy gTLDs .COM, .NET, .ORG, (and if you are in the U.S., also .EDU, .GOV, .MIL), and the ccTLD of your country.

More options for blocking 'wholesale' all of ICANN's shady new gTLDs, as well as other 'bad news' TLDs, will likely emerge in response to the warnings issued by respected security firms such as IID and Blue Coat, as well as due to increasing public demand for safety, security, consumer protection, and consumer choice on the internet!

Caveat Emptor!

See also on Domain Mondo:



DISCLAIMER

2015-12-05

Chinese Cybercrime Reshapes Geopolitics, US-China Joint Dialogue

Chinese Cybercrime Reshapes Geopolitics
Security firm IID* [internetidentity.com; twitter: @iidactivetrust] predicts that if the downturn in the Chinese economy continues, this could drive exponential growth of organized cybercriminal enterprises within China. IID expects that by 2017 “persistent criminal enterprises” in China will rival and ultimately surpass Eastern European organized cybercrime in scope, size and complexity. IID also predicts that the Russian Chinese Cyber Alliance will dissolve by 2019, after Chinese cybercriminal organizations begin targeting Eastern European citizens, companies and even rival cybercrime organizations. IID also predicts that by 2020, China will become a leading proponent of Internet security in response to its own citizens and banks being increasingly victimized by cyberattacks that threaten the Chinese economy.

US-China Joint Dialogue
The United States Department of Justice announced that on December. 1, 2015, in Washington, D.C., Attorney General Loretta E. Lynch and Department of Homeland Security Secretary Jeh Johnson, together with Chinese State Councilor Guo Shengkun, co-chaired the first U.S.-China High-Level Joint Dialogue on Cybercrime and Related Issues. Pursuant to the commitments made by U.S. President Barack Obama and Chinese President Xi Jinping during the state visit in September 2015, the primary objectives of the dialogue were to review the timeliness and quality of responses to requests for information and assistance with respect to cybercrime or other malicious cyber activities and to enhance cooperation between the United States and China.

In addition to members of the Departments of Justice and Homeland Security, representatives from the Department of State, National Security Council and Intelligence Community participated for the United States, while the Chinese delegation included representatives from the Committee of Political and Legal Affairs of CPC Central Committee, the Ministry of Public Security, the Ministry of Foreign Affairs, the Ministry of Industry and Information Technology, the Ministry of State Security, the Ministry of Justice and the State Internet Information Office.

Discussions included ways to enhance cooperation within the bounds of each nation’s legal framework and assessments of progress made on cases identified during their discussions in September 2015. Specific outcomes:

1. Guidelines for Combatting Cybercrime and Related Issues. Attorney General Lynch, Secretary Johnson and State Councilor Guo reached agreement on a document establishing guidelines for requesting assistance on cybercrime or other malicious cyber activities and for responding to such requests. These guidelines will establish common understanding and expectations regarding the information to be included in such requests and the timeliness of responses.

2.Tabletop Exercise. Both sides decided to conduct a tabletop exercise in the spring of 2016 on agreed-upon cybercrime, malicious cyber activity and network protection scenarios to increase mutual understanding regarding their respective authorities, processes and procedures. During the tabletop exercise, both sides will assess China’s proposal for a seminar on combatting terrorist misuse of technology and communications, and will consider the U.S.’s proposal on inviting experts to conduct network protection exchanges.

3. Hotline Mechanism. Both sides decided to develop the scope, goals and procedures for use of the hotline before the next High-Level Dialogue.

4. Enhance Cooperation on Combatting Cyber-Enabled Crime and Related Issues. Both sides decided to further develop case cooperation on combatting cyber-enabled crimes, including child exploitation, theft of trade secrets, fraud and misuse of technology and communications for terrorist activities, and to enhance exchanges on network protection. Both sides decided to improve cooperation among the relevant agencies, within the framework of the high-level dialogue, on network protection issues. U.S. and Chinese cyber incident and network protection experts will meet on Dec. 3, 2015, and will continue to meet regularly during future dialogues.

5. Second U.S.-China High-Level Joint Dialogue on Cybercrime and Related Issues. Attorney General Lynch, Secretary Johnson and State Councilor Guo decided to schedule the second U.S.-China High-Level Dialogue on Combatting Cybercrime and Related Issues in June 2016. The dialogue will take place in Beijing, China. Source: OPA | Department of Justice

*See also on Domain Mondo: Cybersecurity Firm IID Predicts New gTLD Websites Will 'Go Dark'




DISCLAIMER

2015-12-04

Cybersecurity Firm IID Predicts New gTLD Websites Will 'Go Dark'

Cybersecurity firm IID says it "anticipates a spate of new gTLD failures, leading to demise of websites relying on them"--

"When the Internet Corporation for Assigned Names and Numbers (ICANN), which oversees the Domain Name System, began the process to issue hundreds of new gTLDs in 2013, the possibilities seemed limitless. Today, gTLDs run the gamut from “.apartments” to “.dentist” to “.porn” and so on. But looking ahead, many of these TLDs, as well as websites and other services that rely on them, could be short-lived because their adoption has been much smaller than anticipated.

"IID anticipates an unprecedented series of domain registry failures as a result of the lack of gTLD popularity by 2017 in the form of bankruptcies and abandonment. “Most new gTLDs have failed to take off and many have already been riddled with so many fraudulent and junk registrations that they are being blocked wholesale,” said IID President and CTO Rod Rasmussen. “This will eventually cause ripple effects on the entire domain registration ecosystem, including consolidation and mass consumer confusion as unprofitable TLDs are dropped by their sponsoring registries.”

"Should a gTLD go down, it would take any resident websites, email or other services with it, forcing their owners to scramble for new virtual real estate. There is a process in place to continue support of struggling registry operations until a larger registry or organization buys them in auction and rescues them. However, questions abound as to who would risk an investment in poorly performing TLDs, especially as they start to number in the hundreds. “That’s why eventually some are going to just plain go dark,” added Rasmussen." (source: IID; emphasis added)

IID is a cybersecurity company. Its flagship product, ActiveTrust, is one of the world’s largest commercial cyberthreat data exchanges. Domain name: internetidentity.com.

On Twitter: @iidactivetrust


See also on Domain Mondo


Caveat Emptor!



DISCLAIMER

Domain Mondo archive