Latest news of the domain name industry

Recent Posts

MMX to pay $5.1 million to get out of terrible .london deal

Minds + Machines will pay its partner on .london roughly $5.1 million in order to put the catastrophic deal to bed for good.
That’s a reduction from the $7.9 million liability it had previously estimated.
The company said last week that it will pay an unspecified partner the $5.1 million “as full and final settlement for any further liability or contractual spend” after renegotiating the contract.
In April, MMX said that the deal had cost it $13.7 million since the outset.
While MMX has never publicly fingered the contract in question, which has been a pair of concrete boots for years, its deal with .london’s London & Partners is the only one that fits the bill.
The registry secured L&P, the marketing arm of the London Mayor’s office, as a client during the mayoral reign of Boris Johnson, the man set to be anointed the UK’s next prime minister this week.
It agreed to make millions of dollars in guaranteed payments over the duration of the contract, because it expected to sell a shedload of .london domains.
That never happened. The gTLD peaked at 86,000 names in March 2018 and was down to 54,000 a year later, evidently a fraction of what MMX had planned for.
The renegotiated deal — I believe at least the second time the deal has been amended — is “in principle” for now, with formal approval expected soon.
In its trading statement last week, MMX also said that the first half of the year ended with a 19% increase in regs, ending June at about 1.82 million.
It said it has “stabilised” declining billings in its acquired ICM Registry portfolio of porn-themed TLDs at $2.8 million, and that it has a “clear pathway” to growth from the four zones.
It’s hoping “further new initiatives” — likely a reference to a new trademark-blocking service — will help out in the current half.
MMX also said that it’s spending $1 million of its cash reserves on a stock buyback.

Comment Tagged: , , , , , ,

ZADNA boss canned for “misconduct”

The CEO of South African ccTLD manager ZADNA has been fired after a “misconduct” investigation lasting over half a year.
Vika Mpisane had been suspended from the role since early December, according to local reports, with Peter Madavhu taking his place.
Madavhu will continue as acting CEO until further notice, ZADNA told its members last week. A July 17 letter from chair Motlatjo Ralefatane, seen by DI, said:

Members would recall that Mr Vika Mpisane was on suspension pending the disciplinary hearing, which has been concluded.
Stemming from those disciplinary actions, Mr Vika Mpisane’s employment as the Chief Executive Officer of ZADNA has been terminated with effect from 16 July 2019.

The specifics of Mpisane’s alleged wrongdoings are not known. The fact that he had been suspended was not even public knowledge until MyBroadband scooped the story in May.
It has previously been reported that he was suspended for “for serious hybrid acts of misconduct including mismanagement of ZADNA funds”.
A disciplinary process that kicked off in January has reportedly been delayed multiple times, during which time Mpisane continued to draw a salary.

Comment Tagged: , ,

ICANN’s new conferencing software has a webcam security bug

Kevin Murphy, July 10, 2019, Domain Tech

ICANN can’t catch a break when it comes to remote participation security, it seems.
Having just recently made the community-wide switch away from Adobe Connect to Zoom, partly for security reasons, now Zoom has been hit by what many consider to be a critical zero-day vulnerability.
Zoom (which, irrelevantly, uses a .us domain) pushed out an emergency patch for the vulnerability yesterday, which would have allowed malicious web sites to automatically turn on visitors’ webcams without their consent.
Only users of the installable Mac client were affected.
According to security researcher Jonathan Leitschuh, who discovered the problem, Zoom’s Mac client was installing a web server on users’ machines in order to bypass an Apple security feature that requires a confirmatory click before the webcam turns on.
This meant a web site owner could trick a user into a Zoom session, with their camera turned on by default, without their knowledge or consent.
If you’re in the habit of keeping your webcam lens uncovered, that’s potentially a big privacy problem, especially if you do most of your remote coverage of ICANN meetings from the toilet.
It appears that Leitschuh, who reported the problem to Zoom three months ago, took issue with what he saw as the company’s ambivalent attitude to fixing it in a timely fashion.
When he finally blogged about it on Monday, after giving Zoom a 90-day “responsible disclosure” period to issue a patch, the problem still hadn’t been fully resolved, he wrote.
But, following media coverage, Zoom’s new patch apparently removes the covert web server completely. This removes the vulnerability but means Apple users will have to click a confirmation button before joining Zoom meetings in future.
Zoom is used now for all of ICANN’s remote participation, from sessions of its public meetings to discussions of its policy-making working groups.
I really like it. It feels a lot less clunky than Adobe, and it’s got some nifty extra features such as the ability to skip around in recordings based on an often-hilarious machine-transcription sidebar, which makes my life much easier.
One of the reasons ICANN made the switch was due to a bug found in Adobe Connect last year that could have been used to steal confidential information from closed meetings.
ICANN actually turned off Adobe Rooms for remote participants halfway through its public meeting in Puerto Rico due to the bug.
The switch to Zoom was hoped to save ICANN $100,000 a year.

Comment Tagged: , , , ,

ICANN explains how .org pricing decision was made

ICANN has responded to questions about how its decision to lift price caps on .org, along with .biz and .info, was made.
The buck stops with CEO Göran Marby, it seems, according to an ICANN statement, sent to DI last night.
ICANN confirmed that was no formal vote of the board of directors, though there were two “consultations” between staff and board and the board did not object to the staff’s plans.
The removal of price caps on .org — which had been limited to a 10% increase per year — proved controversial.
ICANN approved the changes to Public Interest Registry’s contract despite receiving over opposing messages from 3,200 people and organizations during its open public comment period.
Given that the board of directors had not voted, it was not at all clear how the decision to disregard these comments had been made and by whom.
The Internet Commerce Association, which coordinated much of the response to the comment period, has since written to ICANN to ask for clarity on this and other points.
ICANN’s response to DI may shed a little light.
ICANN staff first briefed the board about the RA changes at its retreat in Los Angeles from January 25 to 28 this year, according to the statement.
That briefing covered the reasons ICANN thinks it is desirable to migrate legacy gTLD Registry Agreements to the 2012-round’s base RA, which has no pricing controls.
The base RA “provides additional safeguards and security and stability requirements compared to legacy agreements” and “creates efficiencies for ICANN org in administration and compliance enforcement”, ICANN said.
Migrating old gTLDs to the standardized new contract complies with ICANN’s bylaws commitment “to introduce and promote competition in the registration of domain names and, where feasible and appropriate, depend upon market mechanisms to promote and sustain a competitive environment in the DNS market”, ICANN said.
They also contain provisions forcing the registry to give advance notice of price changes and to give registrants the chance to lock-in prices for 10 years by renewing during the notice period, the board was told.
After the January briefing, Marby made the call to continue negotiations. The statement says:

After consultation with the Board at the Los Angeles workshop, and with the Board’s support, the CEO decided to continue the plan to complete the renewal negotiations utilizing the Base RA. The Board has delegated the authority to sign contracts to the CEO or his designee.

A second board briefing took place after the public comment periods, at the board’s workshop in Marrakech last month.
The board was presented with ICANN’s staff summary of the public comments (pdf), along with other briefing documents, then Marby made the call to move forward with signing.

Following the discussion with the Board in Marrakech, and consistent with the Board’s support, the CEO made the decision for ICANN org to continue with renewal agreements as proposed, using the Base gTLD Registry Agreement.

Both LA and Marrakech briefings “were closed sessions and are not minuted”, ICANN said.
But it appears that the board of directors, while not voting, had at least two opportunities to object to the new contracts but chose not to stand in staff’s way.
At the root of the decision appears to be ICANN Org’s unswerving, doctrinal mission to make its life easier and stay out of price regulation to the greatest extent possible.
Reasonable people can disagree, I think, on whether this is a worthy goal. I’m on the fence.
But it does beg the question: what’s going to happen to .com?

4 Comments Tagged: , , , , , , , , ,

Zimbabwe wants to rebuild its domain market from scratch

Zimbabwe has put out a call for feedback on plans to modernize its almost non-existent domain name industry.
The local ccTLD manager, Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), has issued a consultation document discussing plans to essentially architect the .zw market from scratch.
.zw currently has no automated registration process, no Whois, no formal registry-registrar framework, no DNSSEC, no IPv6, and no governing policies.
POTRAZ is proposing to adopt “best practices” from fellow ccTLDs in Africa and elsewhere, by appointing a new registry operator that will work with a registrar channel under policies created by POTRAZ, as sponsoring organization, itself.
It looks rather like the contract to run the ccTLD could soon be up for grabs.
But first, POTRAZ wants to know how much involvement the Zimbabwean government should have in the operations of the TLD, presenting four options ranging from full governmental control to industry self-regulation.
Currently, POTRAZ, a government regulator, has handed off registry operations for .zw to state-owned telecoms company TelOne.
It has a three-level structure, with TelOne looking after .org.zw, the Zimbabwe Internet Service Providers Association looking after .co.zw and the University of Harare managing .ac.zw.
Interestingly, POTRAZ has not yet decided whether .zw domains should be free or paid for, and whether annual renewals should be required.
The consultation is open until August 9.
Zimbabwe has a population of about 16 million and, according to Internet World Stats, 6.8 million internet users.

Comment Tagged: , , , , ,

Net 4 India gets brief reprieve from ICANN suspension

India registrar Net 4 India has been given a bit of breathing space by ICANN, following its suspension last month.
ICANN suspended the registrar’s accreditation a month ago, effective June 21, after discovering the company had been in insolvency proceedings for some time.
But on June 20 ICANN updated its suspension notice to give Net4 more time to comply. It now has until September 4, the same day its insolvency case is expected to end, to provide ICANN with documentation showing it is still a going concern.
The registrar was sued by a debt collector that had acquired some Rs 1.94 billion ($28 million) of unpaid debts from an Indian bank.
ICANN’s updated suspension notice adds that Net4 is to provide monthly status updates, starting July 18, if it wants to keep its accreditation.
The upshot of all this is that the registrar can carry on selling gTLD domains and accepting inbound transfers for at least another couple months.

Comment Tagged: , , , , ,

Luxembourg tops 100,000 .lu domains

Luxembourgish ccTLD .lu has grown to more than 100,000 domain names for the first time.
ccTLD operator Restena said last week that the domain crossed the threshold June 21. At the end of the month, it had 100,056 domains under management.
While it’s certainly not a lot for a ccTLD, it is when compared to the size of the country it represents.
Luxembourg has a population of under 600,000, so in theory 1 in 6 Luxembourgish people own a .lu domain.
That’s close to the ratio as you’d see in the UK, with its 66 million inhabitants and 12 million .uk domains, though it trails Germany’s 1:5 and the Netherlands’ 1:3.
The per capita numbers are probably not all that useful, however. Restena said that 75% of its domains are in corporate hands.
Many companies are “based” in Luxembourg for tax reasons, which may have some impact on reg numbers.
Restena said that about 3,000 names of the 100,000 are “reserved” and not actively used.
The growth of .lu has not been particularly fast. My records show it has only grown by about 3,000 names over the last year.

Comment Tagged: , , ,

China domain smaller than expected

The Chinese national ccTLD registry has reported 2018 registration figures below what outsiders had estimated.
CNNIC said last week (in Chinese) that it ended last year with 21.24 million .cn domain names under management.
That’s quite a lot below the 22.7 million domains reported by Verisign’s Q4 Domain Name Industry Brief (pdf).
It would also slip .cn into second-place after .tk in the ccTLD rankings, and into third place overall, if the DNIB’s estimate of .tk’s 21.5 million domains is accurate.
Tokelau’s repurposed ccTLD is unusual in that the registry does not delete domains that expire or are suspended for abuse, meaning it’s often excluded from growth comparisons.
China would still be comfortably ahead of Germany’s .de, the next-largest “real” ccTLD, with 16.2 million domains.
CNNIC added that it ended 2018 with 1.72 million registered domains in .中国 (.xn--fiqs8s), which is the Chinese name for China and the country’s internationalized domain name ccTLD.
CNNC has been coy about its reg numbers for the last couple of years.
It stopped publishing monthly totals on its web site in February 2017, when it had 20.8 million .cn domains under management.

Comment Tagged: , , , , ,

Charities “could move to .ngo” if .org prices rise

File this one under “wrong-headed argument of the day”.
The head of policy at the Charities Aid Foundation reportedly has said that the recent removal of price increase caps at .org could lead to charities moving to other TLDs, “like .ngo”, which would cause confusion among charitable givers.
Rhodri Davies told The Telegraph (registration required) newspaper:

One of the benefits at the moment is you have at least at least one very well known and globally recognised domain name, that indicates to people that what they’re looking at is likely to be a charity or a social purpose organisation. If in the future, the pricing changes, and suddenly organisations have all sorts of different domain names, it’s going to be much harder for the public to know what it is they’re looking at. And that will get confusing and will probably have a negative impact on on people’s trust

The Telegraph gave .ngo (for non-governmental organization) as an example of a TLD they could move to. It’s not clear whether that was the example Davies gave or something the reporter came up with.
While Davies’ argument is of course sound — if charities were forced en masse to leave .org due to oppressive pricing, it would almost certainly lead to new opportunities for fraud — the choice of .ngo as an alternative destination is a weird one.
.ngo, like .org, is run by Public Interest Registry. It also runs .ong, which means the same thing in other languages.
But as 2012-round new gTLDs, neither .ngo or .ong have ever been subject to any pricing controls whatsoever.
At $30 a year, PIR’s wholesale price for .ngo is already a little more than three times higher than what it charges for .org domains. I find it difficult to imagine that .org will be the more expensive option any time soon.
.org domains currently cost $9.93 per year, and PIR has said it has no current plans to increase prices.
PIR does not have a monopoly on charity-related TLDs. Donuts runs .charity itself, which is believed to wholesale for $20 a year. It’s quite a new TLD, on the market for about a year, and has around 1,500 domains under management compared to .org’s 10 million.
Of course, .charity doesn’t have price caps either.
In the gTLD world, the only major TLDs left with ICANN-imposed price restrictions are Verisign’s .com and .net.

Comment Tagged: , , , , , ,

Airline hit with $230 million GDPR fine

Kevin Murphy, July 8, 2019, Domain Policy

British Airways is to be fined £183.39 million ($230 million) over a customer data breach last year, by far the biggest penalty to be handed out under the General Data Protection Regulation to date.
This story is not directly related to the domain name industry, but it does demonstrate that European data protection authorities are not messing about when it comes to GDPR enforcement.
About 500,000 BA customers had their personal data — including full payment card details — stolen by attackers between June and September last year, the UK Information Commissioner’s Office said today..
It is believed that they obtained the data not by hacking BA’s database, but rather by inserting a script hosted by third-party domain that executed whenever a customer transacted with the site, allowing credentials to be captured in real time.
The ICO said its decision to fine $183.39 million — which amounts to more than 1.5% of BA’s annual revenue — is preliminary and can be appealed by BA.
Under GDPR, which came into effect in May 2018, companies can be fined up to 4% of revenue.
The biggest pre-GDPR fine is reportedly the £500,000 penalty that Facebook was given due to the Cambridge Analytica scandal.
GDPR is of course of concern to the domain industry due to the ongoing attempts to make sure Whois databases are compliant with the laws.

1 Comment Tagged: , , , , , ,