Latest news of the domain name industry

Recent Posts

ICANN reports .sucks to the FTC over “predatory” pricing

ICANN has referred .sucks registry Vox Populi to the US Federal Trade Commission over concerns from intellectual property owners that its pricing is “predatory”.

The organization has asked the FTC and the Canadian Office of Consumer Affairs to determine whether Vox Pop is breaking any laws.

It asks both agencies to “consider assessing and determining whether Vox Populi is violating any laws or regulations enforced by your respective offices”.

If it is determined that laws are being broken, ICANN said it would be able to “enforce remedies” in the .sucks registry agreement.

ICANN goes on to say that it is “evaluating other remedies” in the registry’s contract.

The shock news comes two weeks after the Intellectual Property Constituency of ICANN complained that Vox Pop’s $2,000 sunrise fee is just a “shakedown scheme”.

The IPC said March 27 it was:

formally asking ICANN to halt the rollout of the .SUCKS new gTLD operated by Vox Populi Registry Inc. (“Vox Populi”), so that the community can examine the validity of Vox Populi’s recently announced plans to: (1) to categorize TMCH-registered marks as “premium names,” (2) charge exorbitant sums to brand owners who seek to secure a registration in .SUCKS, and (3) conspire with an (alleged) third party to “subsidize” a complaint site should brand owners fail to cooperate in Vox Populi’s shakedown scheme.

The IPC is also pissed off that there’s a Sunrise Premium fee that applies to the most famous brands, regardless of when they register.

Vox Pop CEO John Berard told DI tonight that the company’s pricing and policies are “well within the rules”, meaning both ICANN’s rules and North American laws.

He asked why ICANN has referred the matter to the FTC, given that Vox Populi is a Canadian company.

He said that a senior ICANN executive had told him it was because many IPC members are US-based. He described this as “appeasement” of the IPC interests.

Greg Shatan, president of the IPC, whose letter sparked ICANN’s outreach to the FTC and OCA, said that the word “justice” is more appropriate than “appeasement”. He told DI tonight:

We’re looking forward to the FTC and OCA taking a look at Vox Populi’s behavior. And there’s lots to look at. The punitive TMCH Sunrise, where a “rights protection mechanism” intended to protect trademark owners has been turned into a scheme to extort $2,500 and up… The eternal Sunrise Premium of the far-from-spotless .SUCKS registry. The mysterious “everybody.sucks” — purportedly a third party, purportedly providing a “subsidy” to registrant — would anyone be surprised if that was a sham?

With reference to the FTC referral, Shatan also told DI tonight:

I don’t think ICANN wants to waste the FTC’s time. It’s far more rational to think that ICANN informed the FTC because Vox Populi’s activities are within the jurisdiction of the FTC. Mr. Berard’s remarks seem to indicate that he believes that Vox Populi operates beyond the reach of US laws.

With a tech contact in Bermuda and an admin contact in the Caymans, that may have been Vox Pop’s intention. Vox Pop may be operating outside US laws, but I doubt they are operating beyond their reach.

Vox Populi is incorporated in Canada, hence ICANN’s outreach to the Canadian regulator. According to its gTLD application, its only 15%+ owner is Momentous, another Canadian company.

But its IANA record lists an address in Bermuda for its technical contact and Uniregistry’s office in Grand Cayman as its administrative address.

There’s been rumors for months that Uniregistry or CEO Frank Schilling helped bankroll Vox Populi’s participation in the .sucks auction, which saw it splash out over $3 million.

ICANN is asking the US and Canadian agencies to respond to its letter with “urgency”, as .sucks is currently in sunrise and is due to go to general availability May 29.

Trademark owners and celebrities are already registering their names in the .sucks sunrise period.

ICANN confirmed in a separate letter today to IPC chair Greg Shatan that Vox Pop has paid ICANN a unique $100,000 start-up fee, and has promised to pay an extra $1 per transaction, due to now-defunct Momentous subsidiaries defaulting on “substantial payments”.

As DI reported last week, ICANN says that the fee is “not related to the nature” of .sucks, but it could give the appearance that ICANN is a beneficiary of the .sucks business model.

This article was published quite quickly after the news broke. It was updated several times on April 9, 2015. It was updated with background material. It was then updated with comments from Vox Pop. It was then updated with comments from the IPC. Later commenters had the benefit of reading earlier versions of this post before they submitted their comments.

Will new gTLDs really increase phishing?

Kevin Murphy, December 17, 2011, Domain Policy

The US Federal Trade Commission has come out swinging against ICANN’s new generic top-level domains program, saying it will increase online fraud and should be scaled back.

In an open letter to ICANN’s top brass yesterday, the FTC’s four commissioners claimed that “the dramatic introduction of new gTLDs poses significant risks to consumers”.

Saying that more gTLDs will make it easier for scammers to acquire domain names confusingly similar to existing brands, the commissioners said the program should be rolled out as a limited pilot.

The FTC commissioners wrote (pdf):

A rapid, exponential expansion of gTLDs has the potential to magnify both the abuse of the domain name system and the corresponding challenges we encounter in tracking down Internet fraudsters. In particular, the proliferation of existing scams, such as phishing, is likely to become a serious challenge given the infinite opportunities that scam artists will now have at their fingertips. Fraudsters will be able to register misspellings of businesses, including financial institutions, in each of the new gTLDs, create copycat websites, and obtain sensitive consumer data with relative ease before shutting down the site and launching a new one.

The letter demands better Whois accuracy enforcement, better ICANN compliance programs, and a cap on approved new gTLDs in the first round perhaps as low as a couple dozen.

The FTC’s claims that new gTLDs will increase phishing may not be supported by reality, however.

The latest data (pdf) from the Anti-Phishing Working Group shows that in the first half of the year only 18% of domain names used in phishing attacks were registered by the attacker.

That was down from 28% in the second half of 2010. Phishers are much more likely to compromise a domain belonging to somebody else – by hacking a web server, for example.

Of the 14,650 maliciously registered domains 10,444 (70%) were used to phish Chinese targets, “overwhelmingly” the e-commerce site Taobao.com, the APWG found.

Furthermore, only 2% of these domains – just 1,816 over six months – were judged to have been registered due to their confusing similarity with the brands they target.

The APWG said (emphasis in the original):

These are the lowest numbers we have observed in the last past four years, and show that using domain names containing brand strings has fallen further out of favor among phishers.

the domain name itself usually does not matter to phishers, and a domain name of any meaning, or no meaning at all, in any TLD, will usually do. Instead, phishers almost always place brand names in subdomains or subdirectories

The APWG found only one gTLD that ICANN has introduced – .info, with 4.5% – in its top ten phishing TLDs. The .com space accounts for 48.9% of all phishing domains.

Will the increase in the number of gTLDs reverse these trends? The FTC seems to think so, but the claims in its letter appear to be based largely on guesswork and fear rather than data.

I suspect that the FTC’s letter is more concerned with ICANN’s ongoing bilateral talks with registrars over law enforcement-demanded amendments to the Registrar Accreditation Agreement.

These talks are completely separate and distinct from the new gTLDs program policies, but in the last few weeks we’ve seen them being repeatedly conflated by US lawmakers, and now the FTC.

This may be ignorance, but it could just as well be an attempt to apply political pressure on ICANN to make sure the RAA talks produce the results law enforcement agencies want to see.

ICANN does not want to be forced into an embarrassing retreat on its hard-fought gTLD expansion. By producing a strong RAA, it could deflect some of the concerns about the program.