ICANN decision to cancel Hamburg was NOT unanimous

Kevin Murphy, June 19, 2020, Domain Policy

Surprisingly, ICANN’s decision last week to cancel its Hamburg annual general meeting in favor of Zoom did not receive the unanimous support of its board of directors.

Two directors — Ihab Osman and Ron da Silva — voted against the majority in the June 11 resolution, minutes published last night show.

The resolution noted that the global path of the coronavirus pandemic is currently too unpredictable to ensure that an in-person ICANN 69 could go ahead safely or legally in October.

But the two directors dissented, pushing instead for a “hybrid” model meeting, with a greatly reduced in-person attendance propped up with online participation.

According to the minutes:

Ron expressed concerns that the decision to conduct ICANN69 as a purely virtual meeting is premature and indicated a preference for the President and CEO to explore with the SO and AC leadership the implications, costs and logistics around a hybrid approach for ICANN69. Ihab expressed concerns that the proposed resolution does not allow for the possibility of some sort of physical hybrid model for ICANN69.

Osman went further, arguing that ICANN should set an example by going ahead with Hamburg:

Ihab Osman pointed out that large parts of the world are moving towards opening up, and that ICANN, as global community and global player, has a responsibility to do its part to bring the world back to some level of normalcy.

While CEO Göran Marby came back with a bunch of reasons a physical meeting would be impractical and potentially unsafe, both directors were unconvinced and voted against the 13-person majority anyway.

Notes released alongside the minutes reveal that ICANN stands to save a lot of money by remaining online-only.

Not only will it not have to pay for hundreds of flights and hotel rooms for staff and subsidized community members, but it had not yet signed contracts with the venue or local hotels, so it won’t be losing any deposits either.

Virtual cocktails coming to ICANN meetings. Really.

Kevin Murphy, June 18, 2020, Domain Policy

Fancy a virtual coffee? How about a virtual cocktail? These are both real events coming to ICANN’s public meetings, which for the rest of the year are online-only due to coronavirus restrictions.

It’s part of an effort to better capture the sense of socializing and community-building found at normal, in-person ICANN meetings.

The schedule for ICANN 68, which kicks off on Monday, has just been updated to include several 30-minute “virtual coffee” sessions, which of course will be conducted over Zoom.

ICANN’s calling these “Fika” sessions.

It’s not an acronym, but rather a reference to the Swedish workplace tradition of taking a break to drink coffee, eat cake, and chat with colleagues. I’m guessing Swedish CEO Göran Marby had a hand in the naming.

Each Fika session comes with a number of sub-rooms, in which participants can discuss issues such as “Bingeworthy: My Favorite Shows and Movies During Quarantine” or “I’ve Got the Time Now: Quarantine DIY Projects”.

It’s all very sweet and cuddly.

There’s no confirmed “virtual cocktail” sessions (which strike me as an exceptional excuse for day-drinking, depending on your time zone) on the ICANN 68 schedule yet, but the idea has been floated as part of ICANN org’s plan for enhancing its virtual meetings.

This plan is part of a draft four-phase plan to eventually re-open physical meetings when it becomes safe and permitted.

In the current Phase 0, ICANN’s going to encourage greater use of remote video — by all participants, not just the ICANN hosts — and sponsorship opportunities in a virtual “exhibition hall”.

ICANN’s even thinking about arranging for the shipping of schwag bags filled with sponsor loot.

Phase 1 would see the return of in-person meetings, but only at the local or regional level, Phase 2 would see a return to in-person ICANN public meetings, but with a “hybrid” approach that would retain the current online components.

Phase 3 would be essentially a return to business as usual.

The decision to enter a new phase would be guided by issues such as pandemic status, government guidelines, venue safety, and so on.

There’s no chance of up-phasing public meetings this year. ICANN has already confirmed that ICANN 69, originally set for Hamburg, will also be online-only.

But it does seem that this year’s meetings will be slightly friendlier affairs.

Fortunately for female participants, haptic technology has not sufficiently advanced to accurately replicate the experience of being sexually harassed in a hotel bar by a bearded middle-aged man who stinks of virtual vodka.

GoDaddy, PorkBun and Endurance win domain “blocking” court fight

Kevin Murphy, June 17, 2020, Domain Policy

Three large registrar groups last week emerged mostly victorious from a court battle in which a $5.4 billion-a-year consumer goods giant sought to get domains being used in huge scam operations permanently blocked.

Hindustan Unilever, known as HUL, named Endurance, GoDaddy and PorkBun in a lawsuit against unknown scammers who were using cybersquatted domains to rip off Indians who thought they were signing up to become official distributors.

The .in ccTLD registry, NIXI, was also named in the suit. All of the domains in question were .in names.

Among other things, HUL wanted the registrars to “suspend and ensure the continued suspension of and block access to” the fraudulent domains in question, but the judge had a problem with this.

He’d had the domain name lifecycle explained to him and he decided in a June 12 order (pdf) that it was not technically possible for a registrar to permanently suspend a domain, taking into account that the registration will one day expire.

He also defined “block access to” rather narrowly to mean the way ISPs block access to sites at the network level, once again letting the registrar off the hook.

Judge GS Patel of the Bombay High Court wrote:

Any domain name Registrar can always suspend a domain that is registered. But the entire process of registration itself is entirely automated and machine-driven. No domain name registrar can put any domain names on a black list or a block list.

Where he seems to have messed up is by ignoring the role of the registry, where it’s perfectly possible for a domain name to be permanently blocked.

NIXI may not have its hands directly on the technology, but .in’s EPP registry is run by back-end Neustar (now owned by GoDaddy but not directly named in the suit), which like all gTLD registries already has many thousands of names permanently reserved under ICANN’s direction.

Patel also seems to assume that NIXI doesn’t get paid for the domain names its registrar sells. He wrote:

The relief against Defendants Nos. 14 and 15, the dot-IN registry and NIEI [NIXI] at least to the extent of asking that they be ordered to de-register or block access is misdirected. Neither of these is a registrar. Neither of these receives registration consideration. Neither of these registers any domain name. The reliefs against them cannot therefore be granted.

NIXI actually charges INR 350 ($4.60) per second-level .in name per year, of which a reported $0.70 goes to Neustar.

The judge also ruled that the registrars have to hand over contact information for each of the cybersquatters.

He also ordered several banks, apparently used by the scammers, to hand over information in the hope of bringing the culprits to justice.

You won’t need a password for ICANN 68 after all

Kevin Murphy, June 17, 2020, Domain Policy

ICANN has ditched plans to require all ICANN 68 participants to enter a password whenever they enter one of the Zoom sessions at the meeting next week.

The org said today that it will use URLs with embedded passwords, removing the need for user input, after reviewing changes Zoom made last month.

These included features such as a waiting room that enables meeting hosts to vet participants manually before allowing them to enter the meeting proper.

ICANN said: “Please use these links cautiously, only share them on secure channels such as encrypted chat or encrypted e-mail, and never post them publicly.”

ICANN had said last month, before the Zoom changes, that it would require passwords in order to limit the risk of Zoombombing — where trolls show up and spam the meeting with offensive content. One ICANN Zoom session had been trolled in this way in March.

The org also said today that participants will be asked to give their consent to be recorded upon entry to a session.

“It is our hope that this small change empowers attendees by providing quick access and more control over the acceptance of our policies as it relates to attending virtual meetings,” ICANN lied, to cover for the obvious piece of legal ass-covering.

Refuse consent and see how far you get.

ICANN confirms Hamburg cancellation

Kevin Murphy, June 16, 2020, Domain Policy

With ICANN 68 due to start online next Monday, ICANN has confirmed that its annual general meeting in October is going to be online-only also.

ICANN 69 will now be held on Zoom, instead of at Hamburg’s new convention center, the organization confirmed on Friday.

It’s because of coronavirus, of course. ICANN’s taking the depressing yet realistic view that mass gatherings of international travelers will still be inadvisable and maybe even illegal four months hence.

It’s bad news for ICANN’s core staff in Los Angeles who, if ICANN sticks to the Hamburg time zone as it has with canceled meetings in Cancun and Kuala Lumpur, will start their working day at 0130 local time for a week straight.

It’s particularly bad news for me. I had a whole range of Ombudsman-enraging jokes lined up related to “sausage fests”, “69s”, etc.

Still, I suppose it could be wurst.

ICANN board tries to redefine mediocrity — literally

Kevin Murphy, June 9, 2020, Domain Policy

After 21 years of covering this stuff, the volume and extent of ICANN’s navel-gazing no longer amazes me, but every now and then I stumble upon something that forces a little angry smile from my lips.

It appears the ICANN board of directors is seeking to redefine mediocrity itself, in a very literal way, and it may well cost your money to do so.

I’ll explain.

Every two years, the board conducts a self-evaluation via a survey put together by ICANN staff. That survey recently came up for review by the board’s seven-person Board Governance Committee.

According to the meeting’s minutes, the BGC decided it was unhappy with the word “neutral” to describe a score of #3 on what I’m guessing is a five-point scale used for rating directors’ performances.

The word “seems somewhat vague”, the BGC noted, asking staff to “consult with external resources and suggest replacement for the term ‘neutral’ on the rating scale”.

I really hope “consult with external resources” means “google it” rather than “piss away registrants’ money on pricey consultants”, but I’m not confident.

The word I’d use is “mediocre”. If you have a better suggestion there’s a comments section below.

Will ICANN swap Hamburg for Zoom for 69?

Kevin Murphy, June 8, 2020, Domain Policy

ICANN’s board of directors is meeting this week to discuss arrangements for ICANN 69, and I think there’s a reasonable chance it will decide to take the meeting online-only.

The last official word from ICANN was that it is working on the assumption that normality will have resumed by September, and that October’s meeting could go ahead in Hamburg, Germany as planned.

But will it?

Current German coronavirus-related travel restrictions, which have been in place since March, forbid non-citizen incoming travelers from pretty much anywhere, even elsewhere in the EU.

Some travelers are being asked to self-quarantine for 14 days upon entry, which is obviously impractical for conference travel.

However, German is loosening its rules next week for EU travelers and will treat countries on a case-by-case basis, based on how many infections they’re recording at the time.

Americans will still not be allowed to travel to Germany and there’s no word on when the ban will be lifted.

German guidelines also currently prohibit any large gatherings of people, including conferences, until at least the end of August.

ICANN’s obviously going to have to do a bit of crystal ball-gazing, to guess whether business travel is going to be safe and permitted in October.

It’s also going to have to guess whether a large enough number of people will actually want to attend to make an in-person meeting worthwhile.

With many medical experts predicting a third-quarter resurgence of the pandemic, the so-called “second wave”, inviting guests from every continent to gather in the same room might be seen as risky.

Conferences in other industries that had been due to take place in Germany in October have been canceled or postponed.

Notably, Oktoberfest in Munich (which starts in September but runs into October) is not going ahead this year, but I’ve found examples of conventions in publishing, gaming and catering sectors that have also been canceled.

However, some events due to take place in March and April have been postponed UNTIL October, suggesting a level of confidence that the virus will be low-risk by that time.

Top-level reshuffle as ICANN loses its COO

Kevin Murphy, June 4, 2020, Domain Policy

ICANN today announced a series of organizational changes at the highest level of management after its COO decided to quit.

Susanna Bennett, senior veep and chief operations officer, will leave July 1 for pastures new after seven years on the job, and her role will be split between other senior figures.

ICANN also said today that Theresa Swinehart has been appointed head of the Global Domains Division, a role she’s been filling on an interim basis since Cyrus Namazi quit a few months back.

She’s also senior VP of multistakeholder strategy and strategic initiatives and CEO Göran Marby’s co-deputy. She’ll be keeping both of those jobs too.

In terms of ops, Bennett’s functions will be split between CFO Xavier Calvez, senior VP of HR Gina Villavicencio, and general counsel John Jeffrey. Calvez will also take on some of the MSSI responsibilities previously held by Swinehart.

The fact that Bennett and Namazi, who together were compensated to the tune of $860,000 in ICANN’s fiscal 2019, had functions that can be easily redistributed among other staffers does rather beg the question of whether ICANN has been spending domain registrants’ money as efficiently as possible.

Still, the rejigger will presumably be welcomed by those who believe that ICANN has in recent years become overly bloated and bureaucratic.

ICANN recently slashed its FY21 budget by 8% due to the expected impact of the coronavirus-related recessions.

Is ICANN chickening out of Whois access role?

Kevin Murphy, May 26, 2020, Domain Policy

As talks over a centralized system for Whois access enter their eleventh hour, confusion has been sown over whether ICANN still wants to play ball.

The ICANN working group tasked with creating a “unified access model” for Whois data, currently rendered private by the GDPR privacy law, was forced last week to ask ICANN’s board of directors three blunt questions about how it sees its future role.

The group has been working for two years on a system of Whois access based around a central gateway for requests, which could be made only by those given credentials by an accreditation authority, which would also be able to revoke access rights if abused.

The proposed model as a whole has come to be known as SSAD, for System for Standardized Access/Disclosure.

The assumption has been that ICANN would act in these roles, either hands-on or by subcontracting the functions out to third parties, largely because ICANN has given every indication that it would and is arguably inventor of the concept.

But that assumption was thrown into doubt last Thursday, during a working group teleconference, when ICANN board liaison Chris Disspain worried aloud that the group may be pushing ICANN into areas beyond its remit.

Disspain said he was “increasingly uncomfortable with the stretching of ICANN’s mandate”, and that there was no guarantee that the board would approve a policy that appeared to push it outside the boundaries of its mission statement and bylaws.

“While it may be convenient and it might seem to solve the problem to say ‘Well, let ICANN do it’, I don’t think anyone should assume that ICANN will,” he said.

He stressed that he was speaking in his personal capacity rather on behalf of the board, but added that he was speaking based on his over eight years of experience on the board.

He spoke within the context of a discussion about how Whois access accreditation could be revoked in the event that the user abused their privileges, and whether an ICANN department such as Compliance should be responsible.

Several working group members expressed surprise at his remarks, with Milton Mueller of the Non-Commercial Stakeholders Group later calling it “a sudden and rather suspicious departure from nearly two years of ICANN Org statements and activities”.

The confusion comes at a critical juncture for the working group, which has to wrap up its work before chair Janis Karklins quits on June 30.

Karklins wrote to the board late last week to ask:

If SSAD becomes an adopted consensus policy, would ICANN Org will perform the Accreditation Authority function?

If SSAD becomes an adopted consensus policy, would ICANN Org will perform the central Gateway function?

If SSAD becomes an adopted consensus policy, would ICANN Org enforces compliance of SSAD users and involved parties with its consensus policy?

It’s a kinda important set of questions, but there’s no guarantee ICANN will provide straight answers.

When the working group, known as the EPDP, wraps up, the policy will go to the GNSO Council for approval before it goes to the board.

Irony alert! Data protection agency complains it can’t get access to private Whois data

Kevin Murphy, May 26, 2020, Domain Policy

A European data protection authority has complained to ICANN after a registrar refused to hand over one of its customers’ private Whois records, citing the GDPR data protection regulation, according to ICANN.

Compounding the irony, the DPA wanted the data as part of its probe into an alleged GDPR violation at the domain in question.

This is the frankly hilarious scenario outlined in a letter (pdf) from ICANN boss Göran Marby to Andrea Jelinek, chair of the European Data Protection Board, last week.

Since May 2018, registrars and registries have been obliged under ICANN rules to redact all personally identifiable information from public Whois records, because of the EU’s General Data Protection regulation.

This has irked the likes of law enforcement and intellectual property owners, who have found it increasingly difficult to discover the identities of suspected bad actors such as fraudsters and cybersquatters.

Registrars are still obliged to hand over data upon request in certain circumstances, but the rules are vague, requiring a judgement call:

Registry and Registrar MUST provide reasonable access to Personal Data in Registration Data to third parties on the basis of a legitimate interests pursued by the third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Registered Name Holder or data subject pursuant to Article 6(1)(f) GDPR.

While an ICANN working group has been attempting to come up with a clearer-cut set of guidelines, administered by a central body, this so-called SSAD (System for Standardized Access/Disclosure) has yet to come to fruition.

So when an unidentified European DPA recently asked a similarly unidentified non-EU registrar for the Whois data of somebody they suspected of GDPR violations, the registrar told it to get stuffed.

It told the DPA it would “not act against a domain name without any clear and unambiguous evidence for the fraudulent behavior” and said it would respond to legal requests in its own jurisdiction, according to ICANN.

The DPA complained to ICANN, and now ICANN is using that complaint to shame the EDPB into getting off the fence and providing some much-needed clarity about when registrars can declassify Whois data without breaking the law.

Marby wrote that registrars are having to apply their “subjective judgment and discretion” and will most often come down on the side of registrants in order to reduce their GDPR risk. He wrote:

ICANN org would respectfully suggest to the EDPB that a more explicit recognition of the importance of certain legitimate interests, including the relevance of public interests, combined with clearer guidelines on balancing, could address these problems.

ICANN org would respectfully suggest to the EDPB to consider issuing additional specific guidance on this topic to ensure that entities with a legitimate interest in obtaining access to non-public gTLD registration data are able to do so. Guidance would in particular be appreciated on how to balance legitimate interests in access to data with the interests of the data subject concerned

ICANN and the EDPB have been communicating about this issue for a couple of years now, with ICANN looking for some clarity on this largely untested area of law, but the EDPB’s responses to data have been pretty vague and unhelpful, almost as if it doesn’t know what the hell it’s doing either.

Will this latest example of the unintended consequences of GDPR give the Board the kick up the bum it needs to start talking in specifics? We’ll have to wait and see.