Latest news of the domain name industry

Recent Posts

Kevin Murphy, March 31, 2011, Domain Services

Too many ideas, not enough time.
These are some of the stories I would have covered today, if only there were more hours in the day.
Joan Rivers dies after head transplant surgery
UK government banishes cybercrime sites to .au
Transparency review calls for ICANN reality show
UDRP panelist returns Taiwan to China
Bob Parsons shoots BigJumbo CEO
“Pigeon shit” blamed for Playboy plague
Hank Alvarez named ICANN compliance chief
Constantine Roussos says DNS needs “more cowbell”
NATO apologizes for Bit.ly bombing
Blacknight unveils leprechaun mascot
RIAA says .so domains “haven for piracy”
DomainTools merges with DomainJerks
BBC to apply for .cotton
ICANN successfully delays heat death of universe
Parsons apologizes, resurrects elephant
There’s at least 15 stupidly obscure in-jokes there. Probably more. How many did you “get” without Googling?
15 – Congratulations! You’re me. Or a potential future spouse. Call me!
10-14 – You truly are a domain name industry nerd, the depth and breadth of your knowledge covering both domaining and ICANN politicking. You’ve probably been to ICANN meetings and DomainFest. You should be both immensely proud and profoundly ashamed of yourself.
6-10 – I’m proud to have you as a reader. You’re exactly the type of well-balanced individual I’m hoping to attract to this site. Why not try visiting one of my advertisers and purchasing something?
1-5 – Must try harder! Your insight into the industry is sadly lacking. Perhaps consider subscribing to my RSS and Twitter feeds, which can be found at at the top of the left-hand sidebar, in order to bulk up your knowledge base.
0 — You appear to have visited this blog by mistake. Were you searching for “group porn”? I get a lot of hits for that. Nothing to see here, please move along.

VeriSign’s upcoming battle for the Chinese .com

Kevin Murphy, February 16, 2011, Domain Registries

Could VeriSign be about to face off against China for control of the Chinese version of .com? That’s an intriguing possibility that was raised during the .nxt conference last week.
Almost as an aside, auDA chief Chris Disspain mentioned during a session that he believes there are moves afoot in China to apply to ICANN for “company”, “network” and “organization” in Chinese characters. In other words, .com, .net and .org.
I’ve been unable to find an official announcement of any such Chinese application, but I’m reliably informed that Noises Have Been Made.
VeriSign has for several quarters been open about its plans to apply for IDN equivalents of its two flagship TLDs, and PIR’s new CEO Brian Cute recently told me he wants to do the same for .org.
While neither company has specified which scripts they’re looking at, Chinese is a no-brainer. As of this week, the nation is the world’s second-largest economy, and easily its most populous.
Since we’re already speculating, let’s speculate some more: who would win the Chinese .com under ICANN’s application rules, VeriSign or China?
If the two strings were close enough to wind up in a contention set, could VeriSign claim intellectual property rights, on the basis of its .com business? It seems like a stretch.
Could China leapfrog to the end of the process with a community application and a demand for a Community Priority Evaluation?
That also seems like a stretch. It’s not impossible – there’s arguably a “community” of companies registered with the Chinese government – but such a move would likely stink of gaming.
Is there a technical stability argument to be made? Is 公司. (which Google tells me means “company” in Chinese) confusingly similar to .com?
If these TLDs went to auction, one thing is certain: there are few potential applicants with deeper pockets than VeriSign, but China is one of them.
UPDATE: VeriSign’s Pat Kane was good enough to post a lengthy explanation of the company’s IDN strategy in the comments.

Olympics tells ICANN to abandon new TLD launch or get sued

Kevin Murphy, November 29, 2010, Domain Registries

The International Olympic Committee has threatened to sue ICANN unless it gives IOC trademarks special protection in its new top-level domains program.
The IOC’s critique of ICANN’s new Applicant Guidebook is the first to be filed by a major organization in the current public comment period.
The organization has accused ICANN of ignoring it, preferring instead to take its policy cues from the domain name industry, and said it should “abandon its current timeline” for the launch.
ICANN currently plans to start accepting TLD applications May 30, 2011.
Calling the guidebook “inherently flawed”, the IOC’s director general Urs Lacotte wrote:

If these critical issues are not fully resolved and ICANN chooses not to place the Olympic trademarks on the reserved names list, then the IOC and its National Olympic Committees are prepared to employ all available legislative, regulatory, administrative and judicial mechanisms to hold ICANN accountable for damage caused to the Olympic movement.

(That language looks like it could have been cut-n-paste from a separate letter from the financial services industry, which I reported on last week).
The IOC said that it has opposed the new TLD program 11 times – asking for its trademarks to be placed on the AGB’s reserved strings lists, but received no response.
Special pleading? Perhaps, but the IOC’s trademarks are already specifically protected by legislation in numerous countries, including the US, UK, Canada and China.
The IOC also wants stronger trademark protection mechanisms, such as mandatory typosquatting protections in sunrise periods and extending dispute proceedings to registrars.
Expect many more such missives to start showing up on the ICANN web site over the next 11 days before the ICANN board of directors meets to approve the AGB in Cartagena.
This may be the last chance many organizations get to ask for the changes they want in the AGB before the first round of new TLD applications opens, and I expect them to seize it with both hands.

Register.com settles Baidu domain hijacking lawsuit

Kevin Murphy, November 25, 2010, Domain Registrars

Register.com has apologised to Chinese portal company Baidu for allowing its domain, baidu.com, to be hijacked by the Iranian Cyber Army hacker group.
The two companies have announced that the lawsuit, which alleged gross negligence among other things, has now been settled. Terms were not disclosed.
If Baidu’s complaint was to be believed, the hackers took over baidu.com with a trivial social engineering attack that relied upon a Register.com tech support employee being asleep at the wheel.
The company is one of China’s largest internet firms, employing over 6,000 people and turning over well over $600 million a year. But for the period of the hijack, visitors to baidu.com instead just saw the hackers’ defacement message instead.
The registrar had argued in court that its terms and conditions released it from liability, but the judge didn’t buy it.
Register.com, which was acquired by Web.com for $135 million in June, said yesterday:

After an internal investigation, we found that the breach occurred because Register’s security protocols had been compromised. We have worked with United States law enforcement officials and Baidu to address the issue. We sincerely apologize to Baidu for the disruption that occurred to its services as a result of this incident.

Baidu said it accepted the apology. And the check, I imagine.

Internet closes in on 200 million domain names

Kevin Murphy, September 21, 2010, Domain Registries

The internet will almost certainly break through the 200 million domain names milestone before the end of the year, judging from VeriSign’s latest Domain Name Industry Brief.
There were about 196.3 million registered domains at the end of June, according to the report, up by 3 million on the first quarter and 12.3 million on the second quarter 2009. That’s 2% and 7% growth, respectively.
The drag factor on the overall market caused by the mass expiry of millions of Chinese .cn domains seems to have levelled off, making the growth a little more encouraging than in the first quarter.
Regardless, VeriSign said that 76.3 million domains were registered in the ccTLDs, basically flat when compared to the March numbers and a 2.5% increase year-on-year.
The ccTLDs may see a growth spurt in the third-quarter DNIB, due to the influence of .co’s launch, assuming another .cn situation does not arise in another TLD.
VeriSign doesn’t say as much, but if the ccTLDs only grew by a net 63,000 names, that means the bulk of the 3 million new domains were in the gTLDs, but it doesn’t break the number down by gTLD.
It doesn’t even say precisely how many .com/.net domains it manages, or what its growth rates were, just that the two TLDs’ combined total now exceeds 100 million.

US seeks powers to shut down domains

Kevin Murphy, September 20, 2010, Domain Policy

COICA is the new acronym we’ll all soon be talking about — it’s the law that could give the US its very own Great Firewall of China.
A bipartisan group of US senators today introduced the Combating Online Infringement and Counterfeits Act, legislation that would enable the government to quickly turn off domain names involved in piracy.
The bill would enable the Department of Justice to seek a court order against a domain name it believes is involved in piracy or selling counterfeit goods.
If the sponsoring registrar or registry is located in the US, the order would force it to stop the domain from resolving and lock it down.
The likely effect of this would be to force piracy sites out of .com and into offshore registrars. But the bill has thought about that too.
If it’s a non-US registrar and registry, injunctions could be sought to block the domain at the ISP level.
That’s right folks – if this bill passes, the US would get its very own Chinese-style national firewall.
The bill would allow the domain registrant to petition the court to lift the order.
“By cracking down on online piracy of television shows and movies, we hope this bill will encourage copyright owners to develop innovative and competitive new choices for consumers to watch video over the internet,” said Sen. Herb Kohl.
Which is about as disingenuous a statement as it gets, when you think about it, given that it essentially eliminates a major incentive for business model innovation.

Russian domain crackdown halves phishing attacks

Kevin Murphy, August 20, 2010, Domain Tech

Phishing attacks from .ru domains dropped by almost half in the second quarter, after tighter registration rules were brought in, according to new research.
Attacks from the Russian ccTLD namespace fell to 528, compared to 1,020 during the first quarter, according to Internet Identity’s latest report.
IID attributed the decline to the newly instituted requirement for all registrants to provide identifying documents or have their domains cancelled, which came into effect on April 1.
The report goes on to say:

Following a similar move by the China Internet Network Information Center in December 2009, spam researchers suggested that this tactic only moves the criminals to a new neighborhood on the Internet, but has no real impact on solving the problem.

I wonder whose ccTLD is going to be next.
The IID report also highlights a DNS redirection attack that took place in June in Israel, which I completely missed at the time.
Apparently, major brands including Microsoft and Coca-Cola started displaying pro-Palestine material on their .co.il web sites, for about nine hours, after hackers broke into their registrar accounts at Communigal.

DNS Made Easy whacked with 50Gbps attack

Kevin Murphy, August 9, 2010, Domain Services

The managed DNS service provider DNS Made Easy was knocked offline for 90 minutes on Saturday by a distributed denial of service attack estimated at 50Gbps.
This could be the largest DDoS attack ever. The largest I’ve previous heard reported was 49Gbps.
The company, which promises 100% uptime, tweeted that the attack lasted eight hours, but only saw one and a half hours of downtime.
Here are some tweets from the company, starting on Saturday afternoon:

Out of China. Over 20 Gbps…. Don’t really know how big actually. But it’s big. We know it’s over 20 Gbps
Update…. Over 50 Gbps… we think. Since core Tier1 routers are being flooded in multiple cities…..
Trying to organize emergency meeting with all Tier1 providers. We probably have over 50 senior network admins looking into this.
This is flooding the provider’s backbones. By far the largest attack we have had to fight in history.

And, post-attack:

The good: Not everyone was down, not all locations were down at once. The bad: There were temporary regional outages.
Almost back to normal in all locations. Full explanation, details, and SLA credits will be given to all users as soon as possible.
We did not see a 6.5 hour long outage. That would be ultra-long. DDOS attack was 8 hours. Less than 1.5 hours of actual downtime.

It will prove costly. The company’s service level agreement promises to credit all accounts for 500% of any downtime its customers experience.
Quite often in these cases the target of the attack is a single domain. Twitter and Facebook have both suffered performance problems in the past after attackers went after a single user for political reasons.
For a DNS provider, any single domain they host could be such a target. I’d be interested to know if that was the case in this incident.

ICANN threatens to shut down registrar flipper

ICANN has said it will terminate one of its registrars for non-payment of fees, the thirteenth such threatening letter the organization has sent out this year.
The unfortunate recipient is #1 Host Brazil, which has just a couple hundred domains under its belt in the generic top-level domains.
I may be wrong, but based on some cursory research I’m inferring that the registrar is basically a shell accreditation, acquired in order to flip to a larger registrar.
There are 10 other “‘#1 Host” registrars, such as #1 Host Australia and #1 Host Canada, listed on ICANN’s list of accredited registrars, almost all of which were awarded in late 2005 to the same Texan.
They all use the same logos and, due to the hash sign, all appear at the top of alphabetical lists of ICANN-accredited registrars.
Apart from the Brazil and Israel variants, most of the other “#1” accreditations have been acquired by Moniker at various times over the last few years, according to Internic and Whois records.
#1 Host Brazil faces de-accreditation (pdf) on August 24 unless it pays almost $9,000 in ICANN fees and provides evidence of $500,000 in commercial liability insurance.

Chinese TLDs now live, broad adoption achieved in just seven days

Check it out: 教育部。中国.
That’s one, but by no means the only, of the first live, fully Chinese-script domain names. It’s China’s Ministry of Education.
Previously, it had been announced that the .中国 internationalized country-code TLD would not go live until August.
But on Friday CNNIC said that 90% of China’s ministries have got their .中國 domains already, along with 95% of news websites, 90% of universities and 40% of China’s Top 500 enterprises.
Not only was that level of adoption achieved very quietly, it was also achieved very quickly. According to IANA, .中國 was delegated just seven days earlier, on July 9.
IANA also reports that .中國, the IDN for Hong Kong went live on July 12. Taiwan’s .中國 was delegated on July 14.
All of these Chinese-script TLDs were approved by ICANN’s board at the conclusion of the Brussels meeting last month.
It’s perhaps not surprising that ICANN did not broadly announce the latest delegations. It got burnt for pre-empting Arab nations’ publicity when the first IDN TLDs went live in May.
I wonder whether this will help CNNIC reverse the trend of declining registrations in its namespace. According to the latest statistics, the .cn has halved in size over the last year.