Showing posts with label homograph. Show all posts
Showing posts with label homograph. Show all posts

2019-06-09

News Review | Corruption at ICANN Metastasizing the Internet?

graphic "News Review" ©2016 DomainMondo.com
Domain Mondo's weekly internet domain news review (NR 2019-06-09) with analysis and opinion: Features •  1) Corruption at ICANN Metastasizing the Internet? 2) ICANN EPDP Phase 2 Meetings, 3) a. IDN Homographs, b. Michael Gleissner, c. Dark Web Domains, 4) ICYMI: a. Data Privacy & Healthcare, b. U.S. v. Assange, c. Internet Freedom? and more, 5) Most Read.

1) Corruption at ICANN Metastasizing the Internet?
graphic "ICANN | Internet Corporation for Assigned Names and Numbers"
a. ".... We are witnessing corruption metastasizing at the root of the Internet at a breakneck pace. ICANN's precocity and opacity with alternative revenue sources is nothing short of remarkable. The spirit of cooperation that exists between ICANN and its largest ratepayer [Verisignis unseemly, to say the very least. The stakeholder community that was supposed to serve as the check and balance on the ICANN organization has gone AWOL — bought off by the promise of a pittance and sung to sleep by fanciful lullabies of castles in the sky."--Greg Thomas, Managing Director of The Viking Group LLC (vikinginsight.com) (emphasis added) in ICANN and Voodoo Economics in Wonderland | circleid.com.

"... ICANN itself is probably Verisign's biggest "risk factor" -- see Weinstein case ... ICANN insists it is not a "regulator" and it could [and probably will] be replaced by the "global internet community" fed up with ICANN's incompetence [corruption] and shortcomings ("ICANN multistakeholderism does not work" has already become a common refrain in some sectors). ICANN has not had any governmental mandate since the IANA transition in 2016, and Verisign's .COM Registry Agreement with ICANN may not be worth the paper it is printed on, if ICANN is replaced, or a new internet root is adopted by most of the world. That is why the U.S. government refused to sign registry agreements with ICANN for the .MIL and .GOV [g]TLDs after [during] the IANA transition in 2016 (the U.S. maintains it has governmental "sovereignty" over the .GOV and .MIL [g]TLDs due to the anomaly of its historical "stewardship" over the internet.)"--comment on SeekingAlpha.com | VeriSign For A Defensive Strategy (emphasis, link, and [notes] added).

Editor's noteexcerpt from transcript of US Senate Hearing Sept 14, 2016, Larry Strickling, NTIA Administrator, testifying:
"So ... the United States does not wish to cede any sovereignty that we may have over .mil and .gov. And that is why we have done this as an exchange of letters. The United States prior to the creation of ICANN, had the complete authority and control over .mil and .gov; that condition exists today and will continue on in the future." 
Later in the same hearing, Paul Rosenzweig testifying:
"But, I am puzzled by the argument that entering into a [registry] contract [with ICANN] about these [.MIL and .GOV gTLDs] is somehow a derogation of sovereignty. I had not heard that until Assistant Secretary Strickling said that earlier today or -- and so, I haven't had the chance to think about that."
Note also this video clip about Verisign's "hostile letter threatening witnesses" delivered just prior to that same hearing. Full video of that US Senate subcommittee hearing here.

ICANN Form 990 (pp. 53-54 of 83) 2017 Calendar Year compensation:
Who's missing? Correct answer here.

PTI FORM 990:  "PTI's vendors are paid by PTI's sole member, ICANN ... during the reportable time period of calendar year 2017, PTI had no employees. ICANN employees performing PTI activities were paid by ICANN, its sole member, and ICANN issued their form W-2. Compensation was reported under PTI as paid by a related organization (ICANN). PTI reimburses ICANN for all employee compensation related to PTI activities." [PTI Form 990 pp.29-30 of 40.]

Editor's note: ICANN spent $15 million in legal fees in connection with the IANA transition, in part to set up PTI as a separate entity apart from ICANN for the "IANA functions." To what end?

PTI FORM 990, PART III, LINE 4A (p.29 of 40):
"PTI is an affiliate of the Internet Corporation For Assigned Names and Numbers ("ICANN"). PTI was established in August 2016 under the laws of the State of California as a non-profit public benefit corporation and ICANN is its sole member. ICANN is responsible for the performance of the Internet Assigned Numbers Authority ("IANA") functions. the IANA functions include the maintenance of the registry of technical internet protocol parameters, the administration of certain responsibilities associated with internet DNS root zone and the allocation of internet numbering resources. Through contracts and subcontracts, ICANN has delegated the performance of the IANA functions to PTI effective October 1, 2016. PTI's sole purpose is the performance of the IANA functions as delegated by ICANN under a direct contract with PTI as well as three subcontracts. through this series of agreements, ICANN is obligated to provide PTI with all funding necessary for PTI to perform the agreements. PTI has no other funding source."

c. Andean Presidential Council's Special Declaration on the use of .AMAZON (pdf):

Editor's note: the above letter should never have had to be written had ICANN acted in the global public interest and done its job properly from the beginning, but as most of us know, ICANN is incompetent, corrupt and unfit. "Sovereignty" is not just a prerogative reserved for the U.S. and China. The .BRAND (i.e., trademark) new gTLDs were an ICANN corruption of the concept of "generic top-level domains" (see RFC1591). A "brand" a/k/a "trademark" is neither a monopoly nor generic. The entire ICANN new gTLDs program was, from the beginning, and still is, ill-conceived and corrupt. It is no surprise that new gTLDs are failing. A report published by afnic.fr this week indicates the future belongs to ccTLDs and .COM [at least as long as .COM is regulated by the U.S. government]:
"... main market trends in 2018: with 142 million names, the .COM remains the market heavyweight. Its market share increased by 0.5 points in 2018, rising from 42.6% to 43.1%, as a result of a growth rate that increased sharply in 2018 (5.2% vs. 2.8% in 2017) ..." --afnic.fr
ICANN has yet to be held accountable for the billions of dollars (US) in capital destruction and malinvestment it has caused through its ill-conceived and corrupt new gTLDs program. Another sad tale (among many) came to light this week: DigitalTown “clean up efforts” to avoid bankruptcy--DomainNameWire.com.

2) ICANN GNSO EPDP Phase 2 | Next EPDP Meeting June 13
Next EPDP Meeting Thursday, June 13, at 14:00 UTC (10am EDT), agenda, etc., here; observers' audiocast / phone (if needed). June 6 meeting notes and action itemsLinks to the EPDP meetings' recordings and transcripts (when available) are posted on the GNSO calendarOther EPDP Links: wikipublic mail listGNSO mail listworksheets, purposes template (pdf, updated Jun10).

Steve Crocker presentation background document (pdf). Note alsoWorking Definitions draft June 5, 2019 (pdf)--'access' vs 'disclosure' for third parties-- the EPDP Team failed to come to a "consensual compromise" but the new [updated] revised "working definitions" are here.

EPDP subgroup meetings:
See also
  • EDPS flags data protection issues on EU institutions’ websites--edps.europa.eu.

3) Names, Domains & Trademarks
graphic "Names, Domains & Trademarks" ©2017 DomainMondo.com
a. 10 important academic findings about trademarks from the past 12 months--#8. IDN homograph domain names are a major threat to online brands.

b.  WTR infographic about the trademark activity of Michael Gleissner: 4400 trademark applications and 5300 domain names are linked to Gleissner, who was born in Germany but reportedly now lives in the Philippines.

c. The Dark Web is tiny and unreliable: analysis of 55K onion domains on the Tor network finds only 8,400 had a live site, with many having poor uptimes--recordedfuture.com.

4) ICYMI Internet Domain News 
graphic "ICYMI Internet Domain News" ©2017 DomainMondo.com
a. Data Privacy & Healthcare: a primer on complying with U.S. healthcare regulations on data privacy--9 Indispensable Steps to Becoming a HIPAA Hipster | PsychologyToday.com. The Health Insurance Portability and Accountability Act was enacted in 1996 and is applicable to the entire healthcare industry in the U.S.  The most common HIPAA violations are impermissible disclosures of protected health information.

b. U.S. v. Assange: The U.S. Government’s Indictment of Julian Assange Poses a Clear and Present Danger to Journalism, the Freedom of the Press, and Freedom of Speech | eff.org.

c. Internet Freedom?
d. Hong Kong's Tiananmen vigil attracts record turnout--nikkei.com: "The annual candlelight vigil at Victoria Park drew over 180,000 people this year, according to the organizer, the Hong Kong Alliance in Support of Patriotic Democratic Movements of China. This number ties with the peak year of 2014."

e. Russia: the Russian plan for a “sovereign internet” will use deep packet inspection for censorship and a backup domain name system--FT.com.

5) Most Read this past week on DomainMondo.com: 
graphic "Domain Mondo" ©2017 DomainMondo.com
-- John Poole, Editor  Domain Mondo 

feedback & comments via twitter @DomainMondo


DISCLAIMER

2018-07-01

News Review | ICANN Brought Its GDPR Train Wreck To ICANN62 Panama

graphic "News Review" ©2016 DomainMondo.com
Domain Mondo's weekly internet domain news review (NR 2018-07-01) with analysis and opinion: Features •  1) ICANN Brought Its GDPR Train Wreck To ICANN62 Panama,  2) Other ICANN news: a. New gTLD .AFRICA--ICANN Facing Fraud Allegations in California State Court Trial, b. New gTLD .WEB: Afilias vs ICANN et al? c. SSAC2, and more 3) Names, Domains & Trademarks: IDN homograph attacks, and more, 4) ICYMI: EU, China, and more, 5) Most Read.
 ICANN's GDPR Train Wreck  ©2018 DomainMondo.com
1) ICANN Brought Its GDPR Train Wreck to ICANN62 Panama
 ICANN62 | Panama City  ©2018 DomainMondo.com
ICANN CEO & President Goran Marby and GNSO Chair Heather Forrest at ICANN62
Can you tell which one's "brain just melted"?
"One of the more frustrating aspects of the current GDPR crisis that ICANN has been struggling with, is the repeated assertions from folks who should know better in [ICANN org] senior management, that the GDPR was a complete surprise, that these data protection obligations are new, and that the data protection commissioners are not well informed about ICANN and its role. The GDPR passed in 2016 after years of fractious and well-publicised debate, during which US multinational corporations played an active role in Brussels to influence outcomes. While the size of the fines might be a surprise, the requirements were not. Furthermore, the NCSG and its precursor the NCUC have been bringing data commissioners and their staff to ICANN meetings for the better part of two decades. I myself spoke at an ICANN privacy workshop in 2005 while working for the Privacy Commissioner of Canada and said pretty much the same things I say today. More importantly, Giovanni Buttarelli, now the European Data Protection Supervisor and arguably one of the most important data protection commissioners in the world, came to an ICANN meeting in 2004 when he was working in the Italian Data Protection Authority. He returned in 2017 to the meeting in Copenhagen March 13th and repeated the same messages, yet even then the response from ICANN to the upcoming challenges was still not swift and effective. One wonders why."--Stephanie Perrin, June 21, 2018, ncuc.org (emphasis added). Editor's note: Why? "An Incompetent ICANN Management Team."

See also Working Paper (pdf) on Privacy and Data Protection Issues with Regard to Registrant data and the WHOIS Directory at ICANNInternational Working Group on Data Protection in Telecommunications, 62nd meeting, 27-28 November 2017, Paris, France.
Editor's note: "Truncated timeframe" = just 4 months for deliberations and publication of the initial EPDP report.
Read more at Synopsis of ICANN62 via a Twitter Feed & GAC Communique, and last week's News Review. Editor's note: details of the EPDP (expedited policy development process) initiated by the GNSO Council as a result of the ICANN Board's adoption of the Temporary Specification, such as scope and working group membership, should be released in the coming weeks (see ICANN video). Follow discussions here and here, and read the transcription (pdf) of the ICANN62 Panama
GNSO Council Wrap-Up meeting, Thursday, 28 June 2018.

Next ICANN meeting: ICANN63, 20th Annual General Meeting, 20-25 Oct 2018, Barcelona, Spain.
ICANN63 | Barcelona  ©2018 DomainMondo.com (graphic)

2) Other ICANN News
graphic "ICANN | Internet Corporation for Assigned Names and Numbers"
a. New gTLD .AFRICA--ICANN Facing Fraud Allegations in California State Court Trial:
The Superior Court of California, County of Los Angeles, Court Calendar for Case BC607494
For more info, read "Dot-Africa saga going to jury trial... thousands of miles away in America | theregister.co.ukICANN faces fraud allegations in continent's top-level-domain dispute" by Kieren McCarthy, 26 Jun 2018. See also ICANN.org's litigation documents page.

b. New gTLD .WEB: Afilias vs ICANN et al?
New gTLD .WEB Reconsideration Request 18-8 to ICANN, from Afilias Domains No. 3 Limited, 22 June 2018: Request 18-8 [pdf 799 KB--18 pages] embed below, and Exhibits 1 to 34 [pdf 130 MB--963 pages]:


c. SSAC2 Review Assessment Report published for community input 21 June 2018, by Analysis Group, the independent examiner performing the second review of ICANN's Security and Stability Advisory Committee (SSAC)--assessment report [PDF, 761 KB]. Public Comments on the report are encouraged and can be sent to mssi-secretariat@icann.org until 23:59 UTC on 20 July 2018.

Analysis Group will host a webinar on Thursday, 12 July at 20:00 UTC (4pm EDT), during which participants will have the opportunity to provide initial feedback and ask questions. To request dial-in information for the webinar, please send an email to mssi-secretariat@icann.org. The goal of the assessment report is to achieve maximum agreement between the wider ICANN community and the independent examiner as to which areas of the SSAC work well and which may benefit from improvements. No recommendations are included in the assessment report. Recommendations will be included in the final report, expected to be published in November 2018. More info here and also the executive summary [PDF, 85 KB].

Editor's note: I'd like to see the Analysis Group address SSAC's inexplicable failures in regard to new gTLDs--failures subsequently acknowledged, implicitly, by SSAC's ICANN Board liaison--read: More Problems Crop Up With Universal Acceptance of Top Level Domains by Ram Mohan, Feb 07, 2014, particularly in view of ICANN's contract provision with new gTLDs registry operators:
"1.2 Technical Feasibility of String.  While ICANN has encouraged and will continue to encourage universal acceptance of all top-level domain strings across the Internet, certain top-level domain strings may encounter difficulty in acceptance by ISPs and webhosters and/or validation by web applications.  Registry Operator shall be responsible for ensuring to its satisfaction the technical feasibility of the TLD string prior to entering into this Agreement." (emphasis added)
And further, SSAC failing to demand or even recommend that either ICANN or the new gTLDs' registry operators and registrars warn prospective registrants of new gTLDs' domain names "failing to work as expected on the internet."

How could a group of otherwise competent professionals be so irresponsible and negligent? I can only speculate, but I attribute it to "conflicts of interest"--for example, Ram Mohan, a member of the SSAC and ICANN Board (2008-present) is employed by Afilias, a new gTLDs applicant and TLD registry operator, including providing new gTLDs' backend registry services.

What we now know is that apparently no one tested for "technical feasibility" before hundreds of new gTLDs were negligently and irresponsibly delegated by ICANN into the global internet root:
UASG017: Evaluation of Websites for Acceptance of a Variety of Email Addresses
UASG017 (pdf): "Conclusion: There is much work to be done to get many of the world’s websites UA and EAI-ready. Where we thought we could address just a few applications and code repositories, that does not appear to be the case."
But domain name registrants still are not warned that their new gTLDs' domain names may "fail to work as expected on the internet." Occasionally they show up at an ICANN meeting to complain, but no one of consequence at ICANN cares about domain name registrants--"it's all about the money."

Also note:
SSAC2018-017 | SSAC Input to the Chartering of GNSO EPDP (Expedited Policy Development Process) on Temporary Specification of gTLD Registration Data 26 Jun 2018 ssac2018-17-26jun18-en.pdf [pdf 99.1 KB].

Ongoing dysfunction (pdf) in planning for the next round of new gTLDs--ICANN is rushing through the whole process:

d. Information Transparency Initiative (ITI)--How the ITI Technical Infrastructure Works | ICANN.org.

e. GNSO Overtasked?--GNSO active projects list (pdf).

3) Names, Domains & Trademarks
graphic "Names, Domains & Trademarks" ©2017 DomainMondo.com
a. IDN homograph attacks--registration of homographic domain names is akin to typosquatting, the major difference being that in homograph spoofing the perpetrator deceives victims by presenting visually indistinguishable hyperlinks. [Editor's note: ICANN enables and encourages cybercrime and domain name abuse via homograph attacks through its IDN new gTLDs program.] See also:
  • Hackers ‘Using International Characters To Create Scam Sites’--silicon.co.uk
  • "... a problem that exists because of ICANN's failure to generate a coherent and universally applicable set of standards for registration of IDNs to prevent this type of abuse"--techrepublic.com.
  • “Chilling results”: new domain name homograph report shows rising threat to online brands--worldtrademarkreview.com.

b. EURid (eurid.eu), registry operator for ccTLD .eu, and the International Anti-Counterfeiting Coalition (IACC.org) team up to fight cybercrime--businesswire.com June 27, 2017.

c. France.com: using a domain name for many years will not necessarily provide a business or any registrant with a right to registration of the domain name as a trade mark--an EU court has ruled against Florida-based France.com which had argued that its 'france.com' mark should also be registered as an EU trade mark. The court reasoned France.com was too similar to an existing trade mark "france" owned by the French government--out-law.com, 26 Jun 2018. [Editor's note: the applicant has already lost the domain name france.com as a result of a separate French legal judgment that resulted in the transfer of the france.com registration to an agency of the French government.]

d. Trademarkers: New data reveals the most prolific trademark applicants in the United States last year--Leading the list was a 71-year-old New York physician with more than 300 applications--Expert suggests [trademark] filers lists “might not be dominated by large corporations in the future”--worldtrademarkreview.com.

e. Who needs GDPR or an EPDP? Free WHOIS Privacy at Namecheap.com--how to add WhoisGuard to your Namecheap domains.

f. F is for Family: branches of Rothschild empire settle dispute over family name ... Under the deal, the groups cannot use the name Rothschild by itself ... Rothschild & Co will stop using the rothschild.com domain name--ft.com.

4) ICYMI Internet Domain News 
graphic "ICYMI Internet Domain News" ©2017 DomainMondo.com
a. European Union: EU votes for copyright law that would make internet a 'tool for control'--TheGuardian.com and ZDnet.com: ​European Union prepares to wreck internet with new copyright law--"If passed, Article 13 will force all websites to check any and all posts for copyright violations. That will include photos, videos, words, tweets, memes, software code, etc, etc. Think about that for a minute, and shudder."

b. China & Internet Governance: "Beijing Wants to Rewrite the Rules of the Internet - Xi Jinping wants to wrest control of global cyber governance from the market economies of the west"--TheAtlantic.com:
"China’s model appeals to these countries because it provides them with tools to take control of an open internet. Online platforms used for terrorism and political dissent threaten national stability. The Edward Snowden revelations and crippling cyber attacks like WannaCry and Mirai create a sense of vulnerability that China’s model promises to fix."   
c. US & Net Neutrality: Lawmakers must level the field for all players in the internet ecosystem--Robert McDowell, former FCC commissioner (2006-13) in Richmond.com.

d. Internet Society: Internet Society Names Andrew Sullivan as New President & CEO  29 June 2018.

e.  UPDATE: Deadline to respond to the NTIA notice of inquiry has been extended to July 17, 2018, 5:00 pm EDT.

5) Six Most Read Posts this past week on DomainMondo.com: 
graphic "Domain Mondo" ©2017 DomainMondo.com



-- John Poole, Editor, Domain Mondo 

feedback & comments via twitter @DomainMondo


DISCLAIMER

Domain Mondo archive