Google beats USPS in LRO, Defender loses another
The United States Postal Service and Defender Security have both lost Legal Rights Objections over the new gTLDs .mail and .home, respectively.
In both cases it’s not the first LRO the objector has lost. USPS, losing here against Google, lost a similar objection against Amazon, while Defender has previously racked up six losses over .home.
The Defender case (pdf) this time was against .Home Registry Inc. The objection was rejected by the World Intellectual Property Organization panelist on pretty much the same grounds as the others — Defender acquired its trademark rights purely in order to be able to file LROs against its .home rivals.
In the USPS v Amazon case (pdf) the WIPO panelist also decided along the same lines as the previous case.
The decision turned on whether USPS, which owns trademarks on “U.S. Mail” but not “mail”, could be said to have rights in “mail” by virtue of the fact that it is the monopoly postal service in the US.
USPS argued that .mail is like .gov — internet users know a .gov domain is owned by the US government, so they’re likely to think .mail belongs to the official US mail service.
The panelist decided that users are more likely to associate the gTLD with email:
A consumer viewing the string <.mail> in the context of a domain name registration or an email address is presumably even more likely to think of the electronic (“email”) meaning, rather than the postal meaning, of the term “mail,”
WIPO has now decided 20 LRO cases. All have been rejected. Several more were terminated after the objector withdrew its objection.
First new gTLD objection scalps claimed
Employ Media has killed off the Chinese-language gTLD .招聘 in the latest batch of new gTLD objection results.
Amazon and DotKids Foundation’s respective applications for .kids also appear to be heading into a contention set with Google’s bid for .kid, following the first String Confusion Objections.
All three objections were marked as “Closed, Default” by objection handler the International Center For Dispute Resolution a few days ago. No full decisions were published.
This suggests that the objectors have won all three cases on technicalities (such as the applicant failing to file a response).
Employ Media vice president for policy Ray Fassett confirmed to DI that the company has prevailed in its objection against .招聘, which means “recruitment” in Chinese and would have competed with .jobs.
The String Confusion Objection can be filed based on similarity of meaning, not just visual similarity.
What’s more, if the objector is an existing TLD registry like Employ Media, the only remedy is for the losing applicant to have their application rejected by ICANN.
So Hu Yi Global Information Resources, the .招聘 applicant, appears to be finished as far as this round of the new gTLD program is concerned.
But because there’s no actual ICDR decision on the merits of the case, it seems possible that it, or another company, could try for the same string in a future round.
In Google’s case, it had objected to both the Amazon and DotKids applications for .kids on string confusion grounds. The company is applying for .kid, which is obviously very similar.
The String Similarity Panel, which created the original pre-objection contention sets, decided that singular and plurals could co-exist without confusion. Not everyone agreed.
Because .kid is merely an application, not an existing TLD, none of the bids are rejected. Instead, they all join the same contention set and will have to work out their differences some other way.
Applicants are under no obligation to fight objections; they may even want to be placed in a contention set.
IAB gives dotless domains the thumbs down
The Internet Architecture Board believes dotless domain names would be “inherently harmful to Internet security.”
The IAB, the oversight committee which is to internet technical standards what ICANN is to domain names, weighed into the debate with an article apparently published yesterday.
In it, the committee states that over time dotless domains have evolved to be used only on local networks, rather than the internet, and that to start delegating them at the top level of the DNS would be dangerous:
most users entering single-label names want them to be resolved in a local context, and they do not expect a single name to refer to a TLD. The behavior is specified within a succession of standards track documents developed over several decades, and is now implemented by hundreds of millions of Internet hosts.
…
By attempting to change expected behavior, dotless domains introduce potential security vulnerabilities. These include causing traffic intended for local services to be directed onto the global Internet (and vice-versa), which can enable a number of attacks, including theft of credentials and cookies, cross-site scripting attacks, etc. As a result, the deployment of dotless domains has the potential to cause significant harm to the security of the Internet
The article also says (if I understand correctly) that it’s okay for browsers to interpret words entered into address bars without dots as local resources and/or search terms rather than domain names.
It’s pretty unequivocal that dotless domains would be Bad.
The article was written because there’s currently a lot of talk about new gTLD applicants — such as Google, Donuts and Uniregistry — asking ICANN to allow them to run their TLDs without dots.
There’s a ban in the Applicant Guidebook on the “apex A records” that would be required to make dotless TLDs work, but it’s been suggested that applicants could apply to have the ban lifted on a case by case basis.
More recently, ICANN’s Security and Stability Advisory Committee has stated almost as unequivocally as the IAB that dotless domains should not be allowed.
But for some reason ICANN recently commissioned a security company to look into the issue.
This seems to have made some people, such as the At Large Advisory Committee, worried that ICANN is looking for some wiggle room to give its new gTLD paymasters what they want.
Alternatively, ICANN may just be looking for a second opinion to wave in the faces of new gTLD registries when it tells them to take a hike. It was quite vague about its motives.
It’s not just a technical issue, of course. Dotless TLDs would shake up the web search market in a big way, and not necessarily for the better.
Donuts CEO Paul Stahura today published an article on CircleID that makes the case that it is the browser makers, specifically Microsoft, that are implementing DNS all wrong, and that they’re objecting to dotless domains for competitive reasons. The IAB apparently disagrees, but it’s an interesting counterpoint nevertheless.
Google beaten in new gTLD contention set
When it comes to new gTLDs, Google is not invulnerable.
Japanese web portal NTT Resonant, a subsidiary of the country’s incumbent national telco, has drawn first blood against the search giant, apparently forcing Google to withdrawn its application for .goo.
NTT has also applied for .goo, the name of its primary portal site, which competes with Google for Japanese-language searchers.
The company had filed a formal legal rights objection with WIPO. The withdrawal demonstrates that the mechanism can protect trademark owners, at least insofar as it can scare off competing applicants.
Google’s bid was marked as withdrawn on ICANN’s web site overnight. It’s the fourth withdrawal from the company, following three misjudged geographic applications, leaving it with 97 active bids.
There are now 82 withdrawn and 1,848 live applications. The maximum number of delegated strings remains steady at 1,365. More program status stats can be found over on DI PRO.
Microsoft objects to Google’s dotless domains plan
Microsoft has strongly urged ICANN to reject Google’s plan for a “dotless” .search gTLD.
In a letter sent a couple of weeks ago and published last night, the company says that Google risks putting the security and stability of the internet at risk if its .search idea goes ahead.
David Tennenhouse, corporate vice president of technology policy, wrote:
Dotless domains are currently used as intranet addresses controlled by private networks for internal use. Google’s proposed amendment would interfere with that private space, creating security vulnerabilities and impacting enterprise network and systems infrastructure around the globe.
It’s a parallel argument to the one going on between Verisign and everyone else with regards to gTLD strings that may conflict with naming schemes on internal corporate networks.
While they’re subtly different problems, ICANN recently commissioned a security study into dotless domains (announced 11 days after Microsoft’s letter was sent) that links the two.
As Tennenhouse says in his letter, ICANN’s Security and Stability Advisory Committee, which has Google employees on it, has already warned about the dotless name problem in SAC053 (pdf).
He also claims that Google had submitted follow-up comments to SAC053 saying dotless domains would be “actively harmful”, but this is slightly misleading.
One Google engineer did submit such a comment, but it limited itself to talking about clashes with internal name certificates, a slightly different issue, and it’s not clear it was an official Google Inc comment.
The new gTLD Applicant Guidebook currently outlaws dotless domains through its ban on “apex A records”, but that ban can be circumvented if applicants can convince a registry services evaluation panel that their dotless domain plans don’t pose a stability risk.
While Google’s original .search application envisaged a single-registrant “closed generic”, it later amended the proposal to make it “open” and include the dotless domain proposal.
This is the relevant bit of the amended application:
Charleston Road Registry will operate a service that allows users to easily perform searches using the search functionality of their choice. This service will operate on the “dotless” search domain name (http://search/) and provide a simple web interface. This interface operates in two modes:
1) When the user has not set a preference for a search engine, they will be prompted to select one. The user will be provided with a simple web form that will allow them to designate a search engine by entering the second level label for any second level domain registered with in the TLD (e.g., if “foo.search” was a valid second level domain name, the user could indicated that their preferred search engine was “foo”). The user can also elect to save this preference, in which case a cookie will be set in the userʹs browser. This cookie will be used in the second mode, as described below. If the user enters an invalid name, they will be prompted again to provide a valid response.
2) If the user has already set a preferred search engine, the redirect service will redirect the initial query to the second level domain name indicated by the userʹs preference, including any query string provided by the user. For example, if the user had previously selected the “foo” search engine and had issued a query for http://search/?q=bar, the server would issue a redirect to http://foo.search/?q=bar. In this manner, the userʹs query will be consistently redirected to the search engine of their choice.
While Google seems to have preempted some concerns about monopolistic practices in the search engine market, approval of its dotless search feature would nevertheless have huge implications.
Make no mistake, dotless domains are a Big Deal and it would be a huge mistake for ICANN to treat them only as a security and stability issue.
What’s weird about Google’s proposal is that by asking ICANN to open up the floodgates for dotless domains, it risks inviting the domain name industry to eat its breakfast, lunch and dinner.
If ICANN lets registries offer TLDs domains without dots, the new gTLD program will no longer be about delegating domain names, it will be about auctioning exclusive rights to search terms.
Today, if you type “beer” into your browser’s address bar (which in all the cases I’m aware of are also search bars) you’ll be directed to a page of search results for the term “beer”.
In future, if “beer” is a domain name, what happens? Do you get search or do you get a web page, owned by the .beer registry? Would that page have value, or would it be little better than a parking page?
If browser makers decided to implement dotless domains — and of course there are plenty of reasons why they wouldn’t — every borderline useful dictionary word gTLD would be sold off in a single round.
Would that be good for the internet? I’d lean toward “no”.
Three gTLDs that Google doesn’t treat as gTLDs
Google this week reportedly updated its Webmaster Tools service to treat more ccTLDs as non-geography-specific, but it still seems to be overlooking two gTLDs altogether.
According to its refreshed FAQ, only 19 gTLDs are treated as “gTLDs that can be geotargeted in Webmaster Tools”.
The list does not include .post, which has been in the DNS since August 2012 and available to buy since October, or .xxx, which was delegated and went to general availability in 2011.
While the .arpa gTLD also does not appear (for perfectly sane reasons), the list does include tightly controlled and restricted gTLDs such as .int and .mil, however.
Google treats .asia the same as the ccTLD .eu: a “regional top-level domain” that can be geo-targeted in the same way as a regular gTLD.
The rules appear to apply to the geo-targeting function in Webmaster Tools, which allows webmasters to specify whether their site is designed for only a certain nation or region.
Assuming the list, which was updated this week, is accurate, it’s just the latest example of Google dragging its feet on gTLD acceptance.
One would assume, with Google being an applicant for almost 100 new gTLDs, that before long its gTLD team will be able to affect change elsewhere in the company in a more timely fashion.
Google domain hijacked in Kenya
Google’s Kenyan web site was reportedly inaccessible yesterday due to a hijacking of the company’s local domain name.
Google.co.ke briefly redirected users to a site bearing the slogan “hacked” on a black background, according to the Daily Nation. A change of DNS was blamed.
Google Kenya reportedly said:
Google services in Kenya were not hacked. For a short period, some users visiting www.google.co.ke and a few other website were re-directed to a different website. We are in contact with the organisation responsible for managing domain names in Kenya.
Google is of course a high-profile target; hackers often exploit weaknesses at third-party providers such as domain name registries in order to take down its satellite sites.
Its Irish site was taken down in October last year, after attackers broke in through a vulnerability in IEDR’s Joomla content management system.
Chutzpah alert! “Tube” domainer objects to Google’s .tube gTLD bid
Remember the “mystery gTLD applicant” that had promised to campaign against Google’s closed generic gTLD applications?
It turns out the company behind the campaign is actually Latin American Telecom, one of the three applicants for .tube, and that part of its strategy is a Legal Rights Objection.
According to a copy of the LRO kindly provided to DI this week, LAT claims that if Google gets to run .tube it would harm its Tube brand, for which it has a US trademark.
If you haven’t heard of Latin American Telecom, it, despite the name, appears to be primarily a domainer play. Founded in Mexico and based in Pittsburgh, its main claim to fame seems to be owning Mexico.com.
The company says it has also been building a network of roughly 1,500 video sites, all of which have a generic word or phrase followed by “tube.com” in their domains, since 2008.
It owns, for example, the domains IsraelTube.com, MozartTube.com, LabradorTube.com, AmericanWaterSpanielTube.com, DeepSeaFishingTube.com… you get the idea.
They’re all cookie-cutter microsites that pull their video content from Vimeo. Most or all of them appear to be hosted on the same server.
I’d be surprised if some of LAT’s domains, such as BlockbusterTube.com, PlaymateTube.com, FortyNinersTube.com and NascarTube.com, didn’t have trademark issues of their own.
But LAT was also granted a US trademark for the word TUBE almost a year ago, following a 2008 application, which gives it a basis to bring an LRO against Google.
According to its LRO:
The proposed purposes of and registrant limitations proposed for .TUBE by Google demonstrate that the intended purpose of Google’s .TUBE acquisition is to deprive other potential registry operators of an opportunity to build gTLD platforms for competition and innovation that challenge YouTube’s Internet video dominance. It is clear that Google’s intended use for .TUBE is identical to Objector’s TUBE Domain Channels and directly competes with Objector’s pre-existing trademark rights
There’s quite a lot of chutzpah being deployed here.
Would LAT’s ramschackle collection of –tube domains have any meaning at all were YouTube not so phenomenally successful? Who’s leveraging whose brand here, really?
For LAT to win its objection it has to show, among other things, that its TUBE trademark is famous and that Google being awarded .tube would impair its brand in some way.
But the company’s LRO is vague when it come to answering “Whether and to what extent there is recognition in the relevant sector of the public of the sign corresponding to the gTLD”.
It relies surprisingly heavily on its Twitter accounts — which have fewer followers than, for example, DI — rather than usage of its web sites, to demonstrate the success of the TUBE brand.
I don’t think its objection to Google’s .tube application is a sure thing by any stretch of the imagination.
There is a third .tube gTLD applicant, Donuts, but it has not yet received any LROs, according to WIPO’s web site.
Google starts supporting DNSSEC
Google has started fully supporting DNSSEC, the domain name security standard, on its Public DNS service.
According to a blog post from the company, while the free-to-use DNS resolution service has always passed on DNSSEC requests, now its resolvers will also validate DNSSEC signatures.
What does this mean?
Well, users of Public DNS will get protected from DNS cache poisoning attacks, but only for the small number of domains (such as domainincite.com) that are DNSSEC-signed.
It also means that if a company borks its DNSSEC implementation or key rollover, it’s likely to cause problems for Public DNS users. Comcast, an even earlier adopter, sees such problems pretty regularly.
But the big-picture story is that a whole bunch of new validating resolvers have been added to the internet, providing a boost to DNSSEC’s protracted global roll-out.
Google said:
Currently Google Public DNS is serving more than 130 billion DNS queries on average (peaking at 150 billion) from more than 70 million unique IP addresses each day. However, only 7% of queries from the client side are DNSSEC-enabled (about 3% requesting validation and 4% requesting DNSSEC data but no validation) and about 1% of DNS responses from the name server side are signed. Overall, DNSSEC is still at an early stage and we hope that our support will help expedite its deployment.
One has to wonder whether Google’s participation in the ICANN new gTLD program — with its mandatory DNSSEC at the registry level — encouraged the company to adopt the technology.
Google-backed new gTLD industry group appears at WhatDomain.org
The formative domain name industry trade association that DI has blogged about a few times recently has found itself a web site.
The Google-backed initiative can be found now at WhatDomain.org, which currently carries a bit of brief information about the organization’s rough plans and a call for potential members to get in touch.
The site states:
We are organizing to help educate the world on the coming changes in the domain landscape and to support the interests of the domain name industry. We are inviting any organization with a similar interest in domains to join us in working to create and launch an organization that will enable us to work together to achieve these objectives.
The association will eventually have membership tiers and fees, but those details have yet to be arranged.
We understand that while new gTLD applicant Google is doing most of the “heavy lifting” getting the project off the ground, the company wants to go as arms-length as possible very quickly.
The first informal meeting of what may or may not become officially known as WhatDomain took place at during an intersessional ICANN meeting in Amsterdam this January.
The idea is to promote new gTLDs and domain names in general, raise the reputation of the industry and promote the universal acceptance of TLDs among software developers.
During a session here at the Digital Marketing & gTLD Strategy Congress in New York yesterday, ICANN head of stakeholder engagement Sally Costeron seemed to commit ICANN to help support the initiative.






Recent Comments