Latest news of the domain name industry

Recent Posts

Thick Whois coming to .com next year, price rise to follow?

Kevin Murphy, October 27, 2016, Domain Registries

Verisign could be running a “thick” Whois database for .com, .net and .jobs by mid-2017, under a new ICANN proposal.
A timetable published this week would see the final three hold-out gTLDs fully move over to the standard thick Whois model by February 2019, with the system live by next August.
Some people believe that Verisign might use the move as an excuse to increase .com prices.
Thick Whois is where the registry stores the full Whois record, containing all registrant contact data, for every domain in their TLD.
The three Verisign TLDs currently have “thin” Whois databases, which only store information about domain creation dates, the sponsoring registrar and name servers.
The model dates back to when the registry and registrar businesses of Verisign’s predecessor, Network Solutions, were broken up at the end of the last century.
But it’s been ICANN consensus policy for about three years for Verisign to eventually switch to a thick model.
Finally, ICANN has published for public comment its anticipated schedule (pdf) for this to happen.
Under the proposal, Verisign would have to start offering registrars the ability to put domains in its thick Whois by August 1 2017, both live via EPP and in bulk.
It would not become obligatory for registrars to submit thick Whois for all newly registered domains until May 1, 2018.
They’d have until February 1, 2019 to bulk-migrate all existing Whois records over to the new system.
Thick Whois in .com has been controversial for a number of reasons.
Some registrars have expressed dissatisfaction with the idea of migrating part of their customer relationship to Verisign. Others have had concerns that local data protection laws may prevent them moving data in bulk overseas.
The new proposal includes a carve-out that would let registrars request an exemption from the requirements if they can show it would conflict with local laws, which holds the potential to make a mockery out of the entire endeavor.
Some observers also believe that Verisign may use the expense of building and operating the new Whois system as an excuse to trigger talks with ICANN about increasing the price of .com from its current, frozen level.
Under its .com contract, Verisign can ICANN ask for a fee increase “due to the imposition of any new Consensus Policy”, which is exactly what the move to thick Whois is.
Whether it would choose to exercise this right is another question — .com is a staggeringly profitable cash-printing machine and this Whois is not likely to be that expensive, relatively speaking.
The proposed implementation timetable is open for public comment until December 15.

ICANN faces first post-transition test of UN power (for real this time)

Kevin Murphy, October 7, 2016, Domain Policy

The ICANN community and United Nations agencies are heading for a clash, with governments accused this morning of trying to bypass the ICANN policy-making process.
According to the leader of an ICANN volunteer working group, governments and UN-affilated intergovernmental organizations (IGOs) have circumvented the usual ICANN consensus-building process in order to extract the policies they want directly from the ICANN board of directors and staff.
It’s the first time since the IANA transition, which happened less than a week ago, that governments have been accused of exploiting their special access to the board, and it may become a hot topic at next month’s ICANN 57 meeting in India.
Governments and UN agencies now stand accused of “bypassing the ICANN community” in order to achieve their policy goals.
But the policy being debated is not directly linked to the IANA transition, nor to the thoroughly debunked notion that the UN has taken over ICANN.
Indeed, the issue in question — the permanent protection of IGO acronyms in gTLDs — is almost embarrassingly narrow and predates the announcement of the IANA transition by at least three years, going back to at least 2011.
Basically, the policy questions that look set to cause even more conflict between governments and others are: should IGO acronyms be protected, and if so, how?
IGO acronyms are strings such as WIPO, UNESCO and OECD.
The ICANN board punted this question in May 2014, when it received conflicting advice from the Governmental Advisory Committee and Generic Names Supporting Organization.
Since then, a GNSO Policy Development Process working group has been working on recommendations. It has not yet issued its initial findings, but is close.
Simultaneously and separately, members of ICANN’s board and staff have been quietly talking to a handful of GAC members and IGOs about the same issue in what has become known as the “small group”.
Because it’s small. And a group.
Yesterday, ICANN divulged the consensus of the small group in a letter (pdf) to the leaders of the GNSO Council.
Its recommendations conflict in almost every respect with what the GNSO working group intends to recommend.
The small group wants ICANN to create IGOs-acronyms-only versions of the Trademark Clearinghouse database, Trademark Claims service and UDRP and URS dispute resolution mechanisms — basically “functionally equivalent” mirrors of almost all of the rights protection mechanisms currently only available to trademark owners.
They would be administered at least partially by the GAC and at no cost to the IGOs themselves (presumably meaning ICANN would pick up the tab).
It seems like a disproportionate amount of faff considering the problem ICANN is trying to solve is the vanishingly small possibility that somebody attempts to cybersquat the United Nations Entity For Gender Equality And The Empowerment Of Women (UNWOMEN) or the Postal Union Of The Americas Spain And Portugal (PUASP).
A lot of it is also in direct opposition to what the GNSO WG plans to recommend, according to chair Phil Corwin and the current draft of the WG’s recommendations.
The WG currently plans to recommend that IGOs should be allowed to use the existing URS and UDRP mechanisms to take down or take over domains that use their acronyms in bad faith. It does not currently seem to recommend anything related to Trademark Claims.
A foundational disagreement relates to the status of IGOs under the law. While IGOs in the small group seem to think they are in a special category of entity that is not subject to regular trademark law, the WG hired expert legal counsel that determined the contrary.
Corwin, in his initial response to the small group letter, said that the implications of the debate go beyond how IGO acronyms should be protected.
IGOs carried out a “near boycott” of the GNSO PDP discussions, he wrote, preferring instead to talk to the small group “behind closed doors”. He wrote:

we continually urged members of the GAC, and IGOs, to participate in our WG. That participation was so sporadic that it amounted to a near-boycott, and when IGO representatives did provide any input they stressed that they were speaking solely as individuals and were not providing the official views of the organizations that employed them.
Of course, why should they participate in the GNSO policy processes when they are permitted to pursue their goals in extended closed door discussions with the Board, and when the Board seeks no input from the GNSO in the course of those talks?

He directly linked the timing of the small group report to the expiration last Friday of ICANN’s IANA functions contract with the US Department of Commerce, and suggested that the IGO acronym issue could be a litmus test for how ICANN and governments function together under the new oversight regime.

I note that transmission of the letter has been delayed until after the completion of the IANA transition, and that the post-transition role of governments within ICANN was a central controversy surrounding the transition.

What is at stake in this matter goes far beyond the relatively rare instance in which a domain registrant infringes upon the name or acronym of an IGO and the IGO seeks relief through a CRP [Curative Rights Protection mechanism]. The larger issue is whether, in a post-transition ICANN, the GAC and the UN agencies that comprise a large portion of IGOs, will participate meaningfully in GNSO policy activities, or will seek their policy aims by bypassing the ICANN community and engaging in direct, closed door discussions with the Board.

The financial effects of this seemingly interminable debate on the gTLD industry are probably pretty minor.
Currently, all new gTLDs have temporarily blocked, from launch, all of the IGO acronyms in question. That’s roughly 200 domains per gTLD that could otherwise be sold.
Many of the strings are three, four and five-letter acronyms that could fetch “premium” prices in the open market (though, in my judgement, not much more than a couple hundreds bucks in most cases).
A small number of the acronyms, such as WHO and IDEA, are potentially more valuable.
Off the top of my head and the back of an envelope, I’d put the cost to the industry as a whole of the IGO acronym blocks probably somewhere in the very low millions.
The harms being prevented are also very minor, in my view. With a small handful of exceptions, the IGOs in question are not attractive cybersquatting targets.
But, as is so often the case in ICANN matters, the arguments in this case boil down to matters of law, principle and process much more than practical impact.

Next new gTLD round could start sooner than expected

Kevin Murphy, August 11, 2016, Domain Policy

The ICANN board of directors is wondering whether the next new gTLD application round should kick off sooner than expected.
Chair Steve Crocker reached out to the Generic Names Supporting Organization this week to ask whether the next round could start before all GNSO policy work has been completed.
Or, he asked, are there any “critical issues” that need to be resolved before ICANN starts accepting more applications.
Akram Atallah, head of ICANN’s Global Domains Division, said in May that 2020 is the earliest the next round could feasibly begin, but Crocker’s letter this week (pdf) suggests that that date could be brought forward.
Crocker asked “whether a future application process could proceed while policy work continues”.
There are a number of reviews that ICANN has committed to carry about before the next round starts.
There’s a consumer choice, competition and trust survey to be completed, for example, and a review of trademark protection mechanisms.
Atallah said in may that these would likely be complete by the end of 2017.
But the GNSO is also conducting policy work designed to highlight flaws and inefficiencies in the current 2012 and recommend changes and improvements.
It’s this so-called GNSO Policy Development Process (PDP) Working Group on New gTLD Subsequent Procedures (or NewgTLD-WG) that Crocker is interested in. He wrote:

assuming all other review activities are completed, it would be helpful to understand whether the GNSO believes that the entirety of the current Subsequent Procedures PDP must be completed prior to advancing a new application process under the current policy recommendations. The Board is cognizant that it may be difficult to provide a firm answer at this stage of the process as the reviews are still underway and the PDP is in its initial stages of work, but if any consideration has been given in relation to whether a future application process could proceed while policy work continues and be iteratively applied to the process for allocating new gTLDs, or that a set of critical issues could be identified to be addressed prior to a new application process, the Board would welcome that input.

The current plan for the NewgTLD-WG is to wrap up two years from now, in the third quarter of 2018 (though this may be optimistic).
Members of the group seem to think that we’re looking at a post-2020 next round with 10,000 to 15,000 applications.
It’s difficult to imagine a second round (or fourth, if you’re a pedant) beginning a whole lot earlier than 2020, given the snail’s pace ICANN and its community moves at.
The WG was chartered over half a year ago and the conversations going on are still at a depressingly high level.
Perhaps Crocker’s letter is an early indication that board will not be the significant drag factor on the process.

Burr to replace Tonkin on ICANN board

Kevin Murphy, April 19, 2016, Domain Policy

ICANN lifer Becky Burr is to replace Bruce Tonkin on the ICANN board of directors when his term expires in November.
She’ll take the seat reserved for the Contracted Parties House of the Generic Names Supporting Organization, following a vote by registries and registrars a few weeks ago.
Tonkin, CTO of Aussie registrar Melbourne IT, has held the seat for the last nine years. He’s limited to three consecutive three-year terms under ICANN bylaws.
Burr, a lawyer by trade, is currently chief privacy officer at TLD registry Neustar, a position she has held since 2012.
Before that, she was a partner at the law firm Wilmer Hale.
But way back in 1998, in a senior role at the US National Telecommunications and Information Administration, she was one of the key people responsible for ICANN’s creation under the Clinton administration.

Pirates lose privacy rights under new ICANN rules

Kevin Murphy, January 22, 2016, Domain Registrars

People operating piracy web sites would have a harder time keeping their personal information private under new ICANN rules.
ICANN’s GNSO Council last night approved a set of recommendations that lay down the rules of engagement for when trademark and copyright owners try to unmask Whois privacy users.
Among other things, the new rules would make it clear that privacy services are not permitted to reject requests to reveal a domain’s true owner just because the IP-based request relates to the content of a web site rather than just its domain name.
The recommendations also contain safeguards that would allow registrants to retain their privacy if, for example, their safety would be at risk if their identities were revealed.
The 93-page document (pdf) approved unanimously by the Council carries a “Illustrative Disclosure Framework” appendix that lays out the procedures in some depth.
The framework only covers requests from IP owners to proxy/privacy services. The GNSO was unable to come up with a similar framework for dealing with, for example, requests from law enforcement agencies.
It states flatly:

Disclosure [of the registrant’s true Whois details] cannot be refused solely for lack of any of the following: (i) a court order; (ii) a subpoena; (iii) a pending civil action; or (iv) a UDRP or URS proceeding; nor can refusal to disclose be solely based on the fact that the Request is founded on alleged intellectual property infringement in content on a website associated with the domain name.

This fairly explicitly prevents privacy services (which in most cases are registrars) using the “we don’t regulate content” argument to shoot down disclosure requests from IP owners.
Some registrars were not happy about this paragraph in early drafts, yet it remains.
Count that as a win for the IP lobby.
However, the new recommendations spend a lot more time giving IP owners a quite strict set of guidelines for how to file such requests in the first place.
If they persistently spam the registrar with automated disclosure requests, the registrar is free to ignore them. They can even share details of spammy IP owners with other registrars.
The registrar is also free to ignore requests that, for example, don’t give the exact or representative URL of an alleged copyright infringement, or if the requester has not first attempted to contact the registrant via an email relay service, should one be in place.
The registrant also gets a 15-day warning that somebody has requested their private details, during which, if they value their privacy more than their web site, they’re able to relinquish their domain and remain anonymous.
If the registrant instead uses that time to provide a good reason why they’re not infringing the requester’s rights, and the privacy service agrees, the request can also be denied.
The guidelines would make it easier for privacy service operators to understand what their obligations are. By formalizing the request format, it should make it easier to separate legit requests from the spurious requests.
They’re even allowed to charge IP owners a nominal fee to streamline the processing of their requests.
While these recommendations have been approved by the GNSO Council, they need to be approved by the ICANN board before becoming the law of the ‘net.
They also need to pass through an implementation process (conducted by ICANN staff and GNSO members) that turns the recommendations into written procedures and contracts which, due to their complexity, I have a hunch will take some time.
The idea is that the rules will form part of an accreditation program for privacy/proxy services, administered by ICANN.
Registrars would only be able to use P/P services that agree to follow these rules and that have been accredited by ICANN.
It seems to me that the new rules may be quite effective at cracking down on rogue, “bulletproof” registrars that automatically dismiss piracy-based disclosure requests by saying they’re not qualified to adjudicate copyright disputes.

ICANN confirms domain privacy is for all

Kevin Murphy, January 22, 2016, Domain Policy

Commercial entities will not be excluded from buying domain privacy services, ICANN’s GNSO Council has confirmed.
The Council last night voted unanimously to approve a set of recommendations that would make it compulsory for privacy and proxy services to be accredited by ICANN for the first time.
The recommendations govern among other things how privacy services are expected to behave when they receive notices of trademark or copyright infringement.
But missing is a proposal that would have prevented the use of privacy for “transactional” web sites, something which caused a great deal of controversy last year.
The newly adopted recommendations clearly state that nobody is to be excluded from privacy on these grounds.
The Council voted to adopt the final, 93-page report of the Privacy and Proxy Services Accreditation Issues (pdf) working group, which states:

Fundamentally, P/P services should remain available to registrants irrespective of their status as commercial or non-commercial organizations or as individuals. Further, P/P registrations should not be limited to private individuals who use their domains for non-commercial purposes.

The minority view that web sites that process financial transactions should not be able to use privacy came from intellectual property, anti-abuse and law enforcement community members.
However, opponents said it would infringe the privacy rights of home business owners, bloggers, political activists and others.
It could even lead to vicious “doxing”-related crimes, such as “swatting”, where idiots call in fake violent crime reports against rivals’ home addresses, some said.
It also turned out, as we revealed last November, that 55% of US presidential candidates operate transactional web sites that use privacy on their domains.
Two separate registrar initiatives, one backed by the Electronic Frontier Foundation, started letter-writing campaigns that resulted in over 20,000 comments being received on the the PPSAI’s initial report last July.
Those comments are acknowledged in the PPSAI final report that the GNSO Council just approved.
The adopted recommendations (which I’ll get into in a separate article) still have to be approved by the ICANN board of directors and have to undergo an implementation process that puts the rather broad policies into concrete processes and procedures.

Bladel romps home in ICANN election re-run

Kevin Murphy, November 24, 2015, Domain Policy

Go Daddy VP of policy James Bladel has been elected chair of ICANN’s Generic Names Supporting Organization Council.
The result came a month after the GNSO Council embarrassingly failed to elect a chair to replace outgoing Jonathan Robinson.
This time Bladel ran unopposed, securing the unanimous support of both his own Contracted Parties House and the Non-Contracted Parties House, which did not field a candidate.
In the October vote, the NCPH had nominated academic Heather Forrest.
Due to personal friction between commercial and non-commercial NCPH Council members, Bladel lost that election to “none of the above” by a single vote.
Forrest has been elected vice-chair, along with Neustar’s Donna Austin.
Volker Greimann and David Cake, who had been running the Council on an interim basis for the last month, have stepped aside.

Why did the GNSO fail to pick a new leader?

Kevin Murphy, October 22, 2015, Domain Policy

Political infighting between sections of the Generic Names Supporting Organization seems to be responsible for the GNSO Council’s failure to elect a new chair yesterday.
Rumor has it that Contracted Parties House pick James Bladel, a VP at Go Daddy, only lost because of ructions in the Non-Contracted Parties House.
I stress these are just rumors — nobody with any first-hand knowledge of the situation was prepared to go on-record with me today — but they come from multiple sources.
As I reported earlier today, Bladel failed to secure the support of over 60% of the NCPH — the threshold to be elected chair — despite having the unanimous support of the CPH.
Roughly 47% of the NCPH chose to vote for “none of the above” instead, resulting in the GNSO Council now lacking a chair.
But I gather that this was not a diss against Bladel, his employer, or the CPH per se.
Rather, the story I’m hearing is that some councilors gave an empty chair their votes as a result of disagreements between the commercial and non-commercial sides of the NCPH.
Some say a deal had been made under which NCPH candidate Heather Forrest would receive at least 60% of the vote in round one, but some voters reneged on the deal, meaning she was knocked out of the running.
I don’t know if that’s true or not, but what it implies is that some votes that would have otherwise gone to Bladel in round two of voting were withheld, essentially out of spite.
Bladel only needed one additional NCPH vote to hit his 60%.
If this sounds like childish bickering, you may be right, but it wouldn’t be the first time a GNSO constituency has disrupted the council in order to make a point.
The last time that happened to a significant degree was over three years ago, when non-commercial users exploited a timing issue to protest new rights protection mechanisms for the Olympics, risking the new gTLD program timeline.
That led some at the time to predict the “death” of the GNSO.
That’s not happening this time. If anything, the wagons are circling.
Hastily reappointed council vice chair Volker Greimann, who became de facto chair at least for today, described the current situation as “business as usual” today, pointing out that ICANN bylaws envisaged and accounted for this kind of power vacuum.
The next vote on the chair’s position will take place at least a month from now.

Whois privacy reforms incoming

Kevin Murphy, May 6, 2015, Domain Policy

Whois privacy services will become regulated by ICANN under proposals published today, but there’s a big disagreement about whether all companies should be allowed to use them.
A working group has released the first draft of its recommendations covering privacy and proxy services, which mask the identity and contact details of domain registrants.
The report says that P/P services should be accredited by ICANN much like registrars are today.
Registrars should be obliged to disclose which such services they operate or are affilated with, presumably at the risk of their Registrar Accreditation Agreement if they do not comply, the report recommends.
A highlight of the paper is a set of proposed rules governing the release of private Whois data when it is requested by intellectual property interests.
Under the proposed rules, privacy services would not be allowed to reject such requests purely because the alleged infringement deals with the content of a web site rather than just the domain.
So the identity of a private registrant of a non-infringing domain would be vulnerable to disclosure if, for example, the domain hosted bootleg content.
Registrars would be able to charge IP owners a nominal “cost recovery” fee in order to process requests and would be able to ignore spammy automated requests that did not appear to have been manually vetted.
There’d be a new arbitration process that would kick in to resolve disputes between IP interests and P/P service providers.
The 98 pages of recommendations (pdf) were drafted by the Generic Names Supporting Organization’s Privacy & Proxy Services Accreditation Issues Working Group (PPSAI) and opened for public comment today.
There are a lot of gaps in the report. Work, it seems, still needs to be done.
For example, it acknowledges that the working group didn’t reach any conclusions about what should happen when law enforcement agencies ask for private data.
The group was dominated by registrars and IP interests. There was only one LEA representative and only one governmental representative, and they participated in a very small number of teleconferences.
There was also a sharp division on the issue of who should be able to use privacy services, with two dissenting opinions attached to the report.
One faction, led by MarkMonitor and including Facebook, Domain Tools and fake pharmacy watchdog LegitScript, said that any company that engages in e-commerce transactions should be ineligible for privacy, saying: “Transparent information helps prevent malicious activity”.
Another group, comprising a handful of non-commercial stakeholders, said that no kind of activity should prevent you from registering a domain privately, pointing to the example of persecuted political groups using web sites to raise funds.
There was a general consensus, however, than merely being a commercial entity should not alone exclude you from using a P/P service.
Currently, registrar signatories to the 2013 RAA are bound by a temporary P/P policy that is set to expire January 2017 or whenever the P/P accreditation process starts.
There are a lot of recommendations in the report, and I’ve only touched on a handful here. The public comment period closes July 7.

For only the second time, ICANN tells the GAC to get stuffed

Kevin Murphy, November 3, 2014, Domain Policy

ICANN’s board of directors has decided to formally disagree with its Governmental Advisory Committee for what I believe is only the second time in the organization’s history.
In a letter to new GAC chair Thomas Schneider today, ICANN chair Steve Crocker took issue with the fact that the GAC recently advised the board to cut the GNSO from a policy-making decision.
The letter kick-starts a formal “Consultation Procedure” in which the board and GAC try to reconcile their differences.
It’s only the second time, I believe, that this kind of procedure — which has been alluded to in the ICANN bylaws since the early days of the organization — has been invoked by the board.
The first time was in 2010, when the board initiated a consultation with the GAC when they disagreed about approval of the .xxx gTLD.
It was all a bit slapdash back then, but the procedure has since been formalized somewhat into a seven-step process that Crocker outlined in an attachment to his letter (pdf) today.
The actual substance of the disagreement is a bit “inside baseball”, relating to the long-running (embarrassing, time-wasting) saga over protection for Red Cross/Red Crescent names in new gTLDs.
Back in June at the ICANN 50 public meeting in London, the GAC issued advice stating:

the protections due to the Red Cross and Red Crescent terms and names should not be subjected to, or conditioned upon, a policy development process

A Policy Development Process is the mechanism through which the multi-stakeholder GNSO creates new ICANN policies. Generally, a PDP takes a really long time.
The GNSO had already finished a PDP that granted protection to the names of the Red Cross and Red Crescent in multiple scripts across all new gTLDs, but the GAC suddenly decided earlier this year that it wanted the names of 189 national Red Cross organizations protected too.
And it wasn’t prepared to wait for another PDP to get it.
So, in its haste to get its changing RC/RC demands met by ICANN, the GAC basically told ICANN’s board to ignore the GNSO.
That was obviously totally uncool — a slap in the face for the rest of the ICANN community and a bit of an admission that the GAC doesn’t like to play nicely in a multi-stakeholder context.
But it would also be, Crocker told Schneider today, a violation of ICANN’s bylaws:

The Board has concerns about the advice in the London Communiqué because it appears to be inconsistent with the framework established in the Bylaws granting the GNSO authority to recommend consensus policies to the Board, and the Board to appropriately act upon policies developed through the bottom-up consensus policy developed by the GNSO.

Now that Crocker has formally initiated the Consultation Procedure, the process now calls for a series of written and face-to-face interactions that could last as long as six months.
While the GAC may not be getting the speedy resolution it so wanted, the ICANN board’s New gTLD Program Committee has nevertheless already voted to give the Red Cross and Red Crescent the additional protections the GAC wanted, albeit only on a temporary basis.