Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

2019-06-23

News Review | ICANN65 June 24-27: EPDP, AMAZON & ICANN

graphic "News Review" ©2016 DomainMondo.com
Domain Mondo's weekly internet domain news review (NR 2019-06-23) with analysis and opinion: Features •  1) ICANN65, Marrakech, Morocco, June 24-27: EPDP, .AMAZON & ICANN, 2) Other ICANN news: New gTLD .AFRICA Litigation Update, 3) a. Voice.com Record Sale Price, b. Website Security & Malware, 4) ICYMI: The Internet Is Changing Africa, 5) Most Read.

1) ICANN65, Marrakech, Morocco, June 24-27
 ICANN65 Marrakech ©2019 DomainMondo.com (graphic)
Date & Time (24-hour clock) in Marrakech:

The ICANN Policy Forum is the second meeting in ICANN's three-meeting annual cycle, duration is four (4) days, and format is focused on SO/AC/SG/C policy work and outreach, and therefore:  no welcome ceremony;  no public forum(s);  no public board meeting.

ICANN65 Schedule (all times local Marrakech), *Schedule Highlights below:

*GAC: New gTLDs Subsequent Procedures Discussion 15:15 - 16:15, Mon, Jun 24 [10:15am EDT in U.S.] "Assess progress of PDP WG deliberations on issues of importance to the GAC. Discuss formation and operation of the GAC Focal Group on Subsequent Rounds of gTLDs."

*GNSO-EPDP Phase 2 Meeting (1 of 2)  8:30 - 15:00, Tue, Jun 25 --Notes & Action Items

*GNSO-EPDP Phase 2 Meeting (2 of 2)  8:30 - 15:00, Thu, Jun 27 --Notes & Action Items

EPDP background: CPH comments on Purposes (pdf), SO/AC/SG/C early input, and last week's News Review 2)b. Links to the EPDP meetings' recordings and transcripts (when available) are posted on the GNSO calendarOther EPDP Links: wikipublic mail list, legal memos & mail listGNSO mail listworksheetsdefinitions. Jun 20 meeting notes / action items.

*GAC: DNS Abuse Mitigation and dot Amazon Discussions 8:30 - 10:15, Tue, Jun 25
.AMAZON gTLD vs. Amazon homeland (graphic)
Editor's note: read Amazon wins ‘.amazon’ domain name, aggravating South American region and undermining digital commons | theconversation.com, excerpt:
"... At its inception, the internet was a great equaliser. It meant large and small businesses could compete with one another on a level playing field. ICANN has been entrusted with administering the internet and protecting it. That means protecting its broader purpose in society. ICANN appears to have forgotten that part of its role. It now charges costs USD$185,000 for a top-level domain name like “.amazon”. It’s not surprising that a company whose 2018 profits were reportedly USD$11.2 billion – for which it paid no federal taxes – was able to purchase the domain before an indigenous community in Brazil. The implications for the future of the internet are troubling. What was a global commons may become an exclusive field where those who have the most can acquire more. Those who have the least meanwhile lose even the right to use the name of their homeland." (emphasis added) [See also the author's letter to ICANN Board (pdf)]
The .AMAZON issues illustrate how ill-conceived and corrupt the entire .BRAND new gTLDs program is--a "brand" a/k/a "trademark" is neither monopoly nor generic, and therefore all ".BRAND gTLDs" fail as "generic top-level domains" (gTLDs), see RFC 1591. The .BRAND new gTLDs program was a way for incompetent, corrupt, unfit ICANN, and some of its contracted parties, i.e., registry service providers, to make money by extorting trademark holders--"apply for a .BRAND new gTLD or ICANN may sell your .BRAND (trademark) gTLD to someone else"-- e.g., see .PING testimony. Most .BRAND gTLDs are primarily a costly expense in trademark defense (instead, ICANN should have given trademark holders a right to block any gTLD application that infringes a legitimate distinctive trademark, and governmental authorities the right to block any gTLD application that is for a recognized or protected geographic term under applicable law). Unsurprisingly, many .BRAND gTLDs have been abandoned and returned to ICANN, while .BRANDs like .GOOGLE (and .AMAZON), in effect, contribute to the splintering of the internet into a few monopolistic platforms, smothering all competitors, undermining the digital commons and the core internet principle that all TLDs are "global public resources"--see U.S. amicus brief in the Weinstein case.
"... ICANN is a corrupt racketeering organization. It's a crime syndicate that advances interests of a few insiders at the expense of the masses and the general good. They have abused their power and their role ..."
The GAC-ICANN Board discussion re: .AMAZON (1:07:50-1:55:00) Wednesday morning via Livestream below:

*Evolving the Effectiveness of ICANN's Multistakeholder Model  17:00 - 18:30, Tue, Jun 25  (Livestream video below)

*Impacts of EPDP Phase 1 Recommendations on Other ICANN Policies and Procedures 15:15 - 16:45, Thu, Jun 27, 2019 (10:15am EDT) slide deck, Livestrean video below:

ICANN Meeting & Media Resources:
  • "A simple way to focus your attention is to listen with the intention of summarizing the other person’s point of view. This stops you from using your mental energy to work out your reply, and helps store the other’s words in your memory as well as identify any gaps in your understanding so you can ask questions to clarify."--fs.blog.

2) Other ICANN News
graphic "ICANN | Internet Corporation for Assigned Names and Numbers"
New gTLD .AFRICA Litigation Update: 
new gTLD .AFRICA (graphic)
DotConnectAfrica Trust, a Mauritius Charitable Trust, Plaintiff, v. Internet Corporation for Assigned Names and Numbers (ICANN), a California Corporation; ZA Central Registry, a South African non-profit company; and DOES 1-50, inclusive; Defendants:
new gTLD .AFRICA litigation in Los Angeles (case style)
May 21, 2019: "On the Court's own motion, the Trial Setting Conference scheduled for 05/21/2019, and NonJury Trial On Phase I (Estoppel) scheduled for 05/21/2019 are continued to 07/11/19  [July 11, 2019] at 10:00 AM in Department 53 at Stanley Mosk Courthouse ..."

3) Names, Domains & Trademarks: Website Security & Malware
graphic "Names, Domains & Trademarks" ©2017 DomainMondo.com
a. Largest publicly reported all cash domain name sale in history revealed June 18, 2019, the $30 million sale of Voice.com, more than double the previous record of $13 million paid for Sex.com in 2010.

b. Website Security & Malware: More Than 150,000 Small-Business Websites in the U.S. could be infected with malware at any given moment--in one case, security firm SiteLock (sitelock.com) discovered the hackers had exploited a security hole in a Wordpress plugin--see A Cybersecurity Checklist for the Modern Small BusinessAlso: FBI warns users to be wary of phishing sites abusing HTTPS.

4) ICYMI Internet Domain News 
graphic "ICYMI Internet Domain News" ©2017 DomainMondo.com
The Internet Is Changing Africa: cheap smartphones are flooding Africa, bringing internet access to many for the very first time, but there are problems: gambling, particularly sports betting in Africa's more developed nations, with about 60 million Nigerians aged between 18 and 40 betting daily.  China is investing in infrastructure, but with that comes Huawei equipment, e.g., China built the African Union building in Ethiopia, including installation of tapped networking equipment [the building was built in 2012 by the Chinese, the African Union's IT staff later discovered that the entire content of its servers was being transferred to China.]

WeChat Is Watching: WeChat's data centralization has inextricably linked it to all aspects of daily life in China and made it a cornerstone of the government's social-credit system.

2017-11-23

Quad9: A Safer Internet Experience, A Free Global DNS Service

Internet Security & Privacy In a Few Easy Steps: Quad9
IBM's new Quad9 [domain: quad9.net] Domain Name System (DNS) offering. Created in collaboration with Packet Clearing House (PCH) and the Global Cyber Alliance (GCA), Quad9 goes far beyond standard DNS name resolution, with four key areas of focus.--securityintelligence.com
  • Privacy: Unlike many other DNS services, Quad9 makes use of aggregated data, but by design does not store, correlate or otherwise employ any personally identifiable information (PII). Quad9 does not and never will share any of its data with marketers, nor will it use this data for demographic analysis.
  • Security: Quad9 makes security a chief priority to deliver superior protection against cybercrime networks and malware, integrating security analysis from individual machines’ DNS queries to global trends.
  • Scalability: Quad9 leverages PCH’s long history of providing highly robust DNS back-end infrastructure, including over 160 points of presence around the world.
  • Ease of use: Administrators can easily configure endpoint devices to point to the Quad9 DNS server at address 9.9.9.9.
Safer Internet Experience for South Africa Announced | allAfrica.com: "... a free new global Domain Name System (DNS) service ... Quad9 provides an immunisation service against malware. It supports end-to-end encryption. The system has been in pilot for a year, with almost 1 million users globally ..."





feedback & comments via twitter @DomainMondo


DISCLAIMER

2017-10-22

News Review | Brazil Opposes Draft Report re: ICANN U.S. Jurisdiction

News Review | ©2016 DomainMondo.com
Domain Mondo's weekly internet domain news review (NR 2017-10-22) with analysis and opinion: Features • 1) Brazil Opposes Draft Report re: ICANN U.S. Jurisdiction2) Other ICANN news: ICANN60, GDPR, CPE Review, auDA FOI, 3) Names, Domains & Trademarks: Malware Domains, Vanity.com sale, Q3 Verisign $VRSN, 4) ICYMI: Digital Data & Privacy, 5) Most Read Posts.

Update: see ICANN Jurisdiction: CCWG-Accountability WS2, Friday Oct 27, Abu Dhabi

UPDATE: CCWG-ACCT WS2 Jurisdiction draft report. Brazil's revised dissenting statement Oct 25, 2017--"Dear Co-Chairs, Dear All, Please find attached the revised version of Brazil's dissenting statement, which I submit on behalf of Brazil, and which is to be attached to the draft report on jurisdiction. Best regards, Thiago"--Brazil's revised dissenting statement (pdf) embed below:

1) ICANN Accountability WS2: Brazil Opposes Draft Report on ICANN Jurisdiction (U.S.) 
Excerpt from Statement of Brazil (pdf) highlighting added
[CCWG-ACCT] Jurisdiction Subgroup. Draft Report. Statement of Brazil | ICANN.org"On behalf of the Brazilian Government, I hereby submit the "Statement of Brazil" and its annex, which are to be annexed to the draft report of the jurisdiction subgroup, submitted on 11 October 2017, for consideration by the CCWG plenary."--Thiago Braz Jardim Oliveira, Sun Oct 15, 2017--Statement of Brazil, Brasília, 13 October 2017 (pdf).

See also Tunis Agenda for the Information Society (2005):
"... 29. We reaffirm the principles enunciated in the Geneva phase of the WSIS, in December 2003, that the Internet has evolved into a global facility available to the public and its governance should constitute a core issue of the Information Society agenda. The international management of the Internet should be multilateral, transparent and democratic, with the full involvement of governments, the private sector, civil society and international organizations. It should ensure an equitable distribution of resources, facilitate access for all and ensure a stable and secure functioning of the Internet, taking into account multilingualism ..."
The Accountability-Cross-Community October 2017 mail list select responses (links) below (nationality of each respondent in parenthesis):
  • Milton Mueller (US)16 Oct 2017: "This is a disappointing statement [from Brazil], but it needs to be understood that this is a dissent from a tiny minority whose ideas were not accepted because they were unrealistic and unattainable. It was already known that proposals for an intergovernmental organization governed by some as-yet-nonexistent form of international law had support from only two or three people, and overwhelmingly strong opposition from everyone else. And it was also clear that petitioning the Trump administration and a Republican Congress for an act of Congress granting ICANN immunity would be a blunder of unprecedented magnitude that would achieve exactly the opposite of the proponents' stated objectives. While a small minority was wasting time on a futile attempt to turn the clock back to 1997, the rest of us were confronting real, practical jurisdictional issues. We came up with tangible progress on OFAC and choice of law. These recommendations enjoy overwhelming consensus. Thus, I do not see that this dissent causes any problems. Let them display their petulance and in Abu Dhabi  we can discuss and debate it as needed to expose their fallacies and move on."
Notes for CCWG Accountability Plenary #24 | 18 October 2017 Action item: "Co-Chairs to consider various suggestions made as to the way forward for the Jurisdiction report [pdf] and post their decision to the list." (emphasis and link added)

CCWG-Accountability-WS2-Plenary-Jurisdiction | Co-Chairs Statement on way forward | 20 Oct 2017: "... the Co-Chairs would propose that Brazil submit its revised minority opinion to the plenary list by 23:59 UTC 25 October so that the members and participants can consider it prior to the 27 October plenary. In order to be responsive to the issues raised, we will change the format of the face to face meeting and will be providing ample room for opinions and positions to be expressed and put on the record. This will allow for our group to recognize the different viewpoints and challenges that either could not be dealt with in the report or could not be reflected in the report to everyone’s satisfaction. During this time slot, we will be offering Brazil the opportunity to present its revised minority opinion to the plenary and answer questions on it from the members and the participants. Jurisdiction challenges have been discussed and caused controversial debates since ICANN’s inception and we hope and expect that these discussions will not end with the completion of work stream 2. Thus, a record of this discussion will surely serve as a valuable source of information to inform further discussions beyond the contents of our report. The Co-Chairs also recommend that the second reading of the Jurisdiction draft recommendations be conducted at the 27 October face to face meeting as staff have confirmed that any significant delay in approving these recommendations could endanger their inclusion in the WS2 Final Report. This would allow for the Jurisdiction draft recommendations to be published for public consultation soon after ICANN 60 and would allow the entire community to comment on the recommendations as well as the minority opinions. Although not a perfect solution we believe that this is the one which represents the majority of views." (emphasis and link added)

2) Other ICANN news
a. ICANN60, Annual General Meeting, takes place 28 Oct - 3 Nov 2017, in Abu Dhabi, United Arab Emirates (UAE):
Pre-ICANN60 Policy Open House Oct 19th slides (pdf)
Friday-Saturday, October 27-28, 2017, (times are local Abu Dhabi time unless otherwise indicated):
Next week's News Review will have more on ICANN60, from Sunday, October 29 through November 3, 2017.

Also note that ICANN61 is scheduled for 10-15 Mar 2018 in San Juan, Puerto Rico, which is recovering from the devastation caused by a direct hit from a category 4 (at landfall) hurricane on Sep 20, 2017. AT&T has restored, as of Oct 20, wireless service to 60% of Puerto Rico's population, and has limited LTE connectivity in remote areas in partnership with Project Loon.

b.  GDPR--Data Protection and Privacy Update | ICANN.org--"... we engaged the European law firm Hamilton to provide an independent legal analysis, that will be developed in phases ... the first part of the initial independent legal analysis was published (pdf, 252KB) ... which includes an appendix with the general questions we provided to Hamilton as "food for thought" in analyzing GDPR in relation to gTLD registration data ..."
See also ICANN Correspondence | ICANN.org
  • 19 October 2017 Letter from Rafik Dammak to Theresa Swinehart and Akram Atallah[Published 20 October 2017] Policy Committee Chair | Non-Commercial Stakeholders Group re General Data Protection Regulation (GDPR) Concerns 
  • 13 October 2017 Letter from Paul Diaz and Graeme Bunton to Göran Marby [Published 19 October 2017] Registries Stakeholder Group & Registrars Stakeholder Group re General Data Protection Regulation (GDPR) Concerns
  • 10 October 2017 Letter from Jean-Jacques Sahel to Elena Plexida - ICANN Vice President of Stakeholder Engagement & Managing Director, Europe | ICANN Fact-finding exercise on GDPR
  • 09 October 2017 Letter from Jetse Sprey to Göran Marby [Published 19 October 2017] Versteeg Wigman Sprey Advocaten FRL Registry B.V. Registry Agreement (.FRL): "... ICANN states that my clients are in breach of Clause 2.5 of the RA. My clients believe ICANN’s position is mistaken. Publishing all of the registrants’ data as required by the RA is a clear breach of the EU Regulation 2016/679 (the General Data Protection Regulation, “GDPR”) that will go into effect 25 May 2018 and also a breach of the Dutch Data Protection Act which is based on the EU Directive 95/46/EC. In particular when the registrants are private citizens ..." (emphasis added)

c.  CPE Review: Letter from Chris Disspain to Arif Ali | ICANN.org re: CPE Review for Dot Gay LLC disspain-to-ali-10oct17-en.pdf  (pdf 507KB)

d. Community Travel Support at ICANN--ICANN.org: 16 Oct 2017 community-travel-support-consultation-questionnaire-16oct17-en.pdf [pdf -731 KB]

e. .au Historical Financial Irregularities? - a Freedom of Information request to Department of Communications and the Arts | righttoknow.org.au--Ron Andruff made this Freedom of Information request to Department of Communications and the Arts (Sep 15, 2017)--".... we request access to the following documents: • a copy of the PPB Report;  • copies of any findings or reports relating to "the under-reporting of FBT to the ATO" as noted in item 4(a) of the minutes of the Board meeting held on 13 February 2017;  • internal meeting minutes or any other record (in any form) of matters discussed at in-camera discussions held during auDA's board meeting on 24 March 2016 relating to the termination of the ex-CEO Chris Disspain (excluding the board minutes dated 24 March 2016 which are published on the auDA website); and  • copies of any reports or other records relating to expenses incurred by the ex-CEO Chris Disspain during the period(s) the subject of the PPB Review and rational for extensive international travel and explanation of benefit to auDA and the Australian public in general ...." (link and emphasis added). [Editor's Note: At ICANN60, auDA ex-CEO Chris Disspain will become Vice-Chair of the ICANN Board of Directors. .auDA (.au) is a member of ICANN's ccNSO.]

f. About FY18 ICANN Board Activities & Priorities | ICANN.org

g. Framework for Registry Operator's Response to Security Threats--ICANN.org 20 Oct 2017: "The Internet Corporation for Assigned Names and Numbers today announced a voluntary Framework for Registry Operator's Response to Security Threats (Framework). The Framework provides guidance to registry operators to respond to security threats ..."

3) Names, Domains & Trademarks
Malware Domains"Swift on Security said the developer used Cyrillic Unicode characters in the extension name allowing the malicious plugins to again sidestep Google’s malware filters.--Google Busy Removing More Malicious Chrome Extensions from Web Store | Threatpost.com--We need to stop Unicode until we can get a handle on the situation,” Swift on Security said. No more Unicode [i.e., use of Unicode characters to represent Cyrillic and Greek alphabets in order to mimic Latin characters and fool users into thinking they’ve landed on a legitimate domain]." [Editor's Note: see News Review | Report: ICANN's New gTLDs As Global DNS Malware.]

Notice at http://www.hilcostreambank.com/assets/vanity-intellectual-property-assets
Vanity Shop selling Vanity.com domain name and Vanity® brand in Chapter 11 Auction "... The auction will open with a stalking horse bid from Media Options S.A. for the Vanity.com and Vanity.net domain names for $100,000. The minimum overbid amount for the domain names is $115,000. The opening price for the Vanity® brand and related customer data has been set at $67,500. Interested parties have until Monday, October 23, 2017 @ 5:00PM CST to submit competing bids. If competing bids are received, an auction will be held on Wednesday, October 25, 2017 @ 10:00AM CST ..."--hilcostreambank.com

Q3 2017 Earnings Webcasts Oct 26: .COM & .NET Registry Operator Verisign, Inc. $VRSN, and Twitter, Inc. $TWTR, Alphabet Inc. $GOOGL $GOOG, Amazon.com Inc. $AMZN.

4) ICYMI Internet Domain News 
•   US: (a) Trump to Nominate Antitrust Lawyer Joseph Simons to Lead FTC--Bloomberg.com. (b) The internet IS interstate commerce | aei.org.

•  Digital Data & Privacy: U.S. Supreme Court to decide whether law enforcement officials conducting a criminal investigation can demand data held overseas by Microsoft Corp. and other technology companies in a high-stakes clash over digital privacy.--Bloomberg.com

•  Study: One in four emails from a federal .gov account is a fraud | TheHill.com"There is a newer protocol that can automatically authenticate emails, known as DMARC. That protocol double-checks that messages were sent by their listed senders, allowing fake emails to be deleted or sent to spam. The Department of Homeland Security (DHS) this week issued a directive requiring all federal agencies to implement DMARC."

•  Pass the Protecting Data at the Border Act | Electronic Frontier Foundation | eff.org"... The Department of Homeland Security (DHS) claims that border officers—from Customs and Border Protection (CBP) and Immigration and Customs Enforcement (ICE)—can freely ransack travelers’ smartphones and laptops and the massive troves of highly personal information they contain. This practice is an unconstitutional invasion of privacy and free speech rights. Congress can and should fix this problem by enacting the bipartisan Protecting Data at the Border Act (S. 823 and H.R. 1899). The need for reform is urgent ..."

•  NSA Declassifies Internet Surveillance Files from 2011 Case: In response to a Freedom of Information Act lawsuit by The New York Times, the National Security Agency (NSA) has declassified previously secret documents from  a 2011 case before the Foreign Intelligence Surveillance (FISA) Court. The case concerned problems with the NSA's so-called "upstream" Internet spying conducted under the FISA Amendments Act warrantless surveillance program, and resulted in a then-secret ruling, made public in August 2013, that the agency had violated the Fourth Amendment. The NSA previously released two other tranches of files--NYTimes.com.

•   First Amendment protects the right to disclose government requests for telephone and Internet services subscriber information | Reporters Committee for Freedom of the Press | rcfp.org"the Reporters Committee for Freedom of the Press and a coalition of 20 media organizations submitted a friend-of-the-court brief to the U.S. Court of Appeals for the 9th Circuit in the case of In re National Security Letter."

•  China: President Xi Nails Shut Chinese Internet's Coffin | international.thenewslens.com"... weeks ahead of the Congress, which is expected to renew Xi’s mandate for another five years, the U.S. encrypted messaging app WhatsApp suddenly began malfunctioning in China ... control of the Chinese internet has grown day by day for more than a year. President Xi ... has established a very sophisticated system of information censorship and surveillance in recent years, one that has now gone to a whole new level ..." and China's Xi lays out vision for 'new era' led by 'still stronger' Communist Party | Reuters.com.

•  EU: The European Union's first annual review of the EU-U.S. Privacy Shield framework"On the whole, the report shows that the Privacy Shield continues to ensure an adequate level of data protection. However, there is room for improvement."--European Commission | ec.europa.eu. 

•  EU--"Rather than allowing the internet monopolies to call the tune ["false digital freedom”], we should try to establish a system of smart governance and regulation, out of a sense of European self-awareness, leading to the installation of a regulatory framework enabling us to benefit fully from our fundamental rights and civil liberties on the internet. The example of Commissioner for Competition Margrethe Vestager, who is in the vanguard of a progressive competition policy with her proactive approach towards Apple, Google & co in the US, shows that this can be done. The first ideas for new structures and instruments are close at hand, with a more robust right to access algorithm-linked data for citizens coming into force in May 2018. New tax models for digital companies trading in Europe are being drawn up by the Commission ..."--EURACTIV.com 

•  UK eyes regulating Google and Facebook like news providers--cnbc.com

5) The Top 5 Most Read Posts this past week on DomainMondo.com: 

2. News Review (Oct8) | RySG Requests $$$ and "Detailed Accounting" From ICANN

3. Automotive Disruption: Electric Car Dreams Come At A Cost (video)

4. Technology To Disrupt Fossil Fuels: Solar, Wind, Batteries, Electric Vehicles

5. News Review (Oct1) | Esther Dyson Interview, ICANN Founding Board Chair

-- John Poole, Editor, Domain Mondo 

feedback & comments via twitter @DomainMondo or via email.


DISCLAIMER

2017-09-28

Europol Report: 2017 Top Threat In Cybercrime Epidemic Is Ransomware

 EUROPOL | EC3 European Cybercrime Centre
Internet Organised Crime Threat Assessment (IOCTA) 2017 | Europol.europa.eu--excerpts:
"... Ransomware attacks have eclipsed most other global cybercrime threats, with the first half of 2017 witnessing ransomware attacks on a scale previously unseen following the emergence of self-propagating ‘ransomworms’, as observed in the WannaCry and Petya/NotPetya cases. Moreover, while information-stealing malware such as banking Trojans remain a key threat, they often have a limited target profile. Ransomware has widened the range of potential malware victims, impacting victims indiscriminately across multiple industries in both the private and public sectors, and highlighting how connectivity and poor digital hygiene and security practices can allow such a threat to quickly spread and expand the attack vector. The extent of this threat becomes more apparent when considering attacks on critical infrastructure." (emphasis added)
"Cryptocurrencies continue to be exploited by cybercriminals, with Bitcoin being the currency of choice in criminal markets, and as payment for cyber-related extortion attempts, such as from ransomware or a DDoS attack. However, other cryptocurrencies such as Monero, Ethereum and Zcash are gaining popularity within the digital underground." (emphasis added)
Full report (pdf) embed below:




See also: Europol: Ransomware top threat in 2017 cybercrime 'epidemic' | Reuters.com

feedback & comments via twitter @DomainMondo

2017-08-27

News Review | Report: ICANN's New gTLDs As Global DNS Malware

News Review | ©2016 DomainMondo.com
Domain Mondo's weekly internet domain news review (NR 2017-08-27) with analysis and opinion: Features •  1) Report: ICANN's New gTLDs As Global DNS Malware, 2) Names, Domains & Trademarks: .COM Still King, Verisign, GoDaddy, Ted Cruz, ICANN & NTIA, New gTLDs Reality Check, .GAY, .MUSIC, 4) ICYMI Internet Domain News, 5) Most Read Posts.

1) ICANN's new gTLDs as global DNS malware--see "Statistical Analysis of DNS Abuse in gTLDs" below--ICANN Public Comment periods closing in September:
Figure 23, Report p. 13
SIDN Labs and TU Delft deliver final report for ICANN study | sidnlabs.nl: "... An interesting finding of our study is a clear upward trend in the absolute number of phishing and malware domains in new gTLDs while these numbers remain relatively constant in legacy gTLDs. Also, we discovered that new gTLDs have affected the number of domains used for spam in legacy gTLDs: abused domains in new gTLDs do not increase the number of total malicious registrations. Instead we observe a shift from legacy gTLDs to new gTLDs. Our findings suggest that some new gTLDs have increasingly become a target for malicious actors. For example, Spamhouse blacklisted at least 10% of all registered domains in as many as 15 new gTLDs at the last quarter of 2016See the report [pdf] for more details ... We conducted the SADAG study for the Competition, Consumer Choice, and Consumer Trust Review Team. The CCT Review Team was established to review how the New gTLD Program impacts competition, consumer choice and consumer trust." (emphasis and links added)

Let's review all the ways ICANN's new gTLDs are now known to be global DNS malware:

1. New gTLDs are known to  "break stuff" and cause "collisions;"

2. New gTLDs are known to "fail to work as expected" on the internet--the so-called "Universal Acceptance" (UA) problem--which ICANN knew about long before (since at least 2003) it expanded the gTLDs from just 22 to over 1200 beginning in early 2014, which is why ICANN tried to absolve itself of liability--even though it has failed to warn consumers (registrants)--see Base Registry Agreement Section 1.2:
1.2   Technical Feasibility of String.  While ICANN has encouraged and will continue to encourage universal acceptance of all top-level domain strings across the Internet, certain top-level domain strings may encounter difficulty in acceptance by ISPs and webhosters and/or validation by web applications.  Registry Operator shall be responsible for ensuring to its satisfaction the technical feasibility of the TLD string prior to entering into this Agreement. (emphasis added)
3. Absolute unlimited monopolistic pricing powers granted to new gTLD registry operators, including the right to unlimited increases in domain name registration and renewal fees--ICANN and its "ICANN community" (which is effectively controlled by registry operators and registrars) rejected the recommendation and advice of the the U.S. Department of Justice Antitrust Division to protect consumers (registrants). New gTLD Registry Operators are free to "rape and pillage" the global domain names marketplace and consumers (registrants) worldwide, thanks to ICANN.

4. The Electronic Frontier Foundation (EFF) has warned registrants to avoid new gTLDs due to ICANN's new gTLDs' flawed and overreaching RPMs.

5. And now, the icing on ICANN's global malware cake, SIDN Labs and Delft University of Technology's report (pdf), characterizing new gTLDs as "phishing and malware domains."

Is it any wonder some desperate new gTLD registry operators have tried giving away new gTLD domain names for free? Is it any wonder that new gTLD domain name registrations are collapsing--new gTLD Statistics by Top-Level Domains | ntldstats.com--new gTLDs' registrations are now "falling off a cliff":
 New gTLDs' domain name registrations collapsing
This is what happens when you let special interests (a/k/a lobbyists) run internet governance via a governance model known as "multistakeholderism," limiting and excluding governments from their proper role in protecting the public interest. Add to that the dysfunctional ICANN organization which created for its new gTLDs, a new "Global Domains Division" (try to find any reference to that in the ICANN Articles or Bylaws), primarily staffed by incompetent cronies of ICANN's equally inept ex-CEO who quit 3½ years into a 5-year contract. As I've said before, ICANN has proven to be unfit for the purpose for which it was originally intended.

2) Names, Domains & Trademarks
•  .COM Still King10 tips for choosing the perfect domain | SearchEngineLand.com August 22, 2017: "... 3. Go for a .COM [domain name]--If you are serious about building a long-term brand online, there is nothing better than a .com. Using a 301-redirect to drive traffic to a .net or .org is totally fine, but owning the .com or the equivalent TLD for your target market country is critical ..."

•  VerisignWarren Buffett's Stake In The Internet--"VeriSign [domain: verisign.com, NASDAQ: VRSNis the manager of the .com and .net domain registers - they serve as a monopolistic gatekeeper to the Internet. There are three catalysts for this company's stock appreciation: pricing powers, the Internet's global expansion, and share buybacks. I believe this stock's long-term risk/reward ratio is greatly weighted towards reward ..."--SeekingAlpha.com  Aug. 22, 2017.

•  GoDaddy (domain: godaddy.com) (NYSE: GDDY) announced Tuesday that CEO Blake Irving would retire effective December 31, 2017, and Scott Wagner, GoDaddy President and COO, would assume the CEO role thereafter. Irving will continue to serve on GoDaddy's Board of Directors through June 2018.

•  Ted Cruz, ICANN & NTIATed Cruz should stop obstructing Trump’s [NTIA] nominee [David Redl] for telecom chief | rstreet.org by Joe Kane, Aug 22, 2017: "... Redl has been the subject of a largely unrelated fight waged by the junior senator from Texas over the Internet Assigned Numbers Authority [IANA]. Cruz continues to raise objections about the now-completed transfer of stewardship of IANA functions from NTIA to the Internet Corporation for Assigned Names and Numbers [ICANN]. ICANN is a private, nonprofit company ..." [Editor's note: Cruz has said he wants "assurances" from Redl, and frankly, I would have expected no less.]

•   New gTLDs Reality CheckThe Great Domain Correction of 2017? | pinkybrand.com"... China. China is HARD. You will not be successful there, as a foreign registry operator, at a minimum, unless you understand that you will likely lose money or barely break even for several years and are prepared to deal with that reality. You must be in it for the long term. Long term, at a minimum, is 5 years of sweating it out (flying back and forth on a near monthly basis) before things *might* work out. Over the short to medium term the domain industry is likely to shed inefficient registry and registrar operators and investors, especially some of those who banked on new domain extensions (new gTLDs) that have no real consumer traction—which are many— and can no longer, or are just unwilling, to fund the basic holding/operating costs, let alone fund any marketing team or person. For sure there is an easily foreseen correction—if not outright registration numbers recession—going on right now for some in the domain industry ... This includes ICANN, that may need to shed some personnel as a result of what may be "The Great Domain Correction of 2017"..."

•  .GAYRequest 17-3: Dotgay LLC | BAMC Recommendation on Reconsideration Request 17-3 | ICANN.org 23 Aug 2017: "BAMC [Board Accountability Mechanisms Committee] recommends that the Board deny Request 17-3."

•  .MUSIC:  Request 17-2: DotMusic Limited | BAMC Recommendation on Reconsideration Request 17-2 - ICANN.org 23 Aug 2017: "BAMC recommends that the Board deny Request 17-2."

4) ICYMI Internet Domain News 
  • "We’re currently living in a time digital strategists have deemed the data wild west. The next decade the data policies set could determine the basis of digital rights for the foreseeable future."--TechCrunch.com
  • Inciting Violence vs Freedom of Speech | Namecheap.com: "... The real danger in my opinion is what lies invisible yet is the most dangerous force that anyone of us will ever know. That is the insidious and dangerous force of power. The power to control our thoughts, our privacy, our opinions and most importantly our speech that lies within the dark nature of absolute power itself and takes over seemingly well meaning politicians, presidents, governments, movements that then use this power against us. This is the real danger that we must all be watchful for ..."--Richard Kirkendall, Namecheap CEO

[Editor's note: Investing has moved to the weekly Tech Review.]

5) Most read posts (# of pageviews Sun-Sat) this past week on DomainMondo.com: 
1. News Review: Last Round of ICANN New gTLD .AFRICA Litigation?
2. Explaining Swings in Bitcoin’s Price, Cryptocurrency Primer (video)

-- John Poole, Editor, Domain Mondo 

feedback & comments via twitter @DomainMondo


DISCLAIMER

Domain Mondo archive