<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">My two cents is that a) I like David's
      statement and think we should sign on it, and b) I worry about
      ICANN taking an operational role in cybersecurity.  Frankly, I
      worry about ICANN taking an operational role in just about
      anything, other than IANA. I think ICANN does well within a
      limited scope -- as a multistakeholder group with a narrow
      technical/policy mission. <br>
      <br>
      I think ICANN can foster communication, even encourage good
      practices such as DNSSEC.  I could see ICANN as a forum for
      discussion of DNS Security issues, but I am not sure how
      well-suited we are to *making decisions* on cybersecurity. It
      would like lead to a lot of closed meetings, in which many of us
      would not be present.  Like content, I think I would leave this to
      other forums.<br>
      <br>
      Best,<br>
      Kathy:<br>
    </div>
    <blockquote cite="mid:966B1DC5-31AE-4F20-854A-1E2D51834F20@isoc.be"
      type="cite">
      <div>I agree with Edward's proposed text, not much that I could
        add to it. </div>
      <div><br>
      </div>
      <div>ICANN has a well defined duty and getting involved in content
        debates would be more than dangerous. However, ICANN can help in
        tackling the cyber-criminality if such is done by abusing the
        domain name space. Some of the cyber-attacks are using the
        domain name space and can create a lot of damage to the
        consumers (private and business). In this perspective I'm
        convinced ICANN has a collaborative task and can not just stand
        aside.</div>
      <br>
      <div>
        <span class="Apple-style-span" style="border-collapse: separate;
          color: rgb(0, 0, 0); font-family: 'Andale Mono'; font-style:
          normal; font-variant: normal; font-weight: normal;
          letter-spacing: normal; line-height: normal; orphans: 2;
          text-align: -webkit-auto; text-indent: 0px; text-transform:
          none; white-space: normal; widows: 2; word-spacing: 0px;
          -webkit-border-horizontal-spacing: 0px;
          -webkit-border-vertical-spacing: 0px;
          -webkit-text-decorations-in-effect: none;
          -webkit-text-size-adjust: auto; -webkit-text-stroke-width:
          0px; font-size: medium; "><span class="Apple-style-span"
            style="border-collapse: separate; color: rgb(0, 0, 0);
            font-variant: normal; letter-spacing: normal; line-height:
            normal; orphans: 2; text-align: -webkit-auto; text-indent:
            0px; text-transform: none; white-space: normal; widows: 2;
            word-spacing: 0px; -webkit-border-horizontal-spacing: 0px;
            -webkit-border-vertical-spacing: 0px;
            -webkit-text-decorations-in-effect: none;
            -webkit-text-size-adjust: auto; -webkit-text-stroke-width:
            0px; ">
            <div style="word-wrap: break-word; -webkit-nbsp-mode: space;
              -webkit-line-break: after-white-space; "><span
                class="Apple-style-span" style="border-collapse:
                separate; color: rgb(0, 0, 0); font-variant: normal;
                letter-spacing: normal; line-height: normal; orphans: 2;
                text-align: -webkit-auto; text-indent: 0px;
                text-transform: none; white-space: normal; widows: 2;
                word-spacing: 0px; -webkit-border-horizontal-spacing:
                0px; -webkit-border-vertical-spacing: 0px;
                -webkit-text-decorations-in-effect: none;
                -webkit-text-size-adjust: auto;
                -webkit-text-stroke-width: 0px; ">
                <div style="word-wrap: break-word; -webkit-nbsp-mode:
                  space; -webkit-line-break: after-white-space; "><span
                    class="Apple-style-span" style="border-collapse:
                    separate; color: rgb(0, 0, 0); font-variant: normal;
                    letter-spacing: normal; line-height: normal;
                    orphans: 2; text-align: -webkit-auto; text-indent:
                    0px; text-transform: none; white-space: normal;
                    widows: 2; word-spacing: 0px;
                    -webkit-border-horizontal-spacing: 0px;
                    -webkit-border-vertical-spacing: 0px;
                    -webkit-text-decorations-in-effect: none;
                    -webkit-text-size-adjust: auto;
                    -webkit-text-stroke-width: 0px; ">
                    <div style="word-wrap: break-word;
                      -webkit-nbsp-mode: space; -webkit-line-break:
                      after-white-space; "><span
                        class="Apple-style-span" style="border-collapse:
                        separate; color: rgb(0, 0, 0); font-variant:
                        normal; letter-spacing: normal; line-height:
                        normal; orphans: 2; text-align: -webkit-auto;
                        text-indent: 0px; text-transform: none;
                        white-space: normal; widows: 2; word-spacing:
                        0px; -webkit-border-horizontal-spacing: 0px;
                        -webkit-border-vertical-spacing: 0px;
                        -webkit-text-decorations-in-effect: none;
                        -webkit-text-size-adjust: auto;
                        -webkit-text-stroke-width: 0px; font-size: 12px;
                        ">
                        <div style="word-wrap: break-word;
                          -webkit-nbsp-mode: space; -webkit-line-break:
                          after-white-space; "><font
                            class="Apple-style-span" face="Geneva">Rudi
                            Vansnick<br>
                            Member NPOC policy committee</font></div>
                      </span></div>
                  </span></div>
              </span></div>
          </span></span>
      </div>
      <br>
      <div>
        <div>Op 22-apr-2013, om 19:00 heeft Alain Berranger het volgende
          geschreven:</div>
        <br class="Apple-interchange-newline">
        <blockquote type="cite">Thanks for your work David.
          <div><br>
          </div>
          <div>I agree with Edward's most interesting development. Does
            Rudi have anything to say about that?<span></span></div>
          <div><br>
          </div>
          <div>Alain<br>
            <br>
            On Monday, April 22, 2013, Edward Morris wrote:<br>
            <blockquote class="gmail_quote" style="margin-top: 0px;
              margin-right: 0px; margin-bottom: 0px; margin-left: 0.8ex;
              border-left-width: 1px; border-left-color: rgb(204, 204,
              204); border-left-style: solid; padding-left: 1ex;
              position: static; z-index: auto; ">Thanks for your work
              David.
              <div><br>
              </div>
              <div>Regardless of ICANN's public statements or strategic
                plans, I am not sure ICANN can be in accordance with
                customary International Humanitarian  Law with the
                statement "ICANN does not have a role in the use of the
                Internet related to cyber-espionage and cyber-war" (page
                7). I am equally not sure ICANN is not in accordance
                with customary International Humanitarian Law with that
                statement and I remain  open to arguments as to whether
                ICANN should be involved in these issues or could be
                commanded by IG treaty or agreement to exercise
                responsibilities thereof. </div>
              <div><br>
              </div>
              <div>These are not simple issues. ICANN is a unique
                organisation that does not neatly fit into any typical,
                comfortable structure. IHL, of course, is state centric
                in terms of responsibility but ICANN on one, fairly
                superficial level,  is almost supreme being like in it's
                coordination of the Internet. Cyber-espoinage, no
                problem, ICANN is not involved. However, imagine a
                situation where there are massive cyber attacks on
                civilian infrastructures in third countries by state
                actors that ICANN could operationally prevent. Mass
                civilian death, mass civilian injury, mass destruction
                of property and infrastructure. Mass death of
                noncommercial users, mass injury of noncommercial users,
                mass loss of property of noncommercial users.  Do we
                truly represent these people with a position of "not our
                problem?"</div>
              <div><br>
              </div>
              <div>ICANN is a non state actor but it's operational
                coordination abilities allow those who want, and they
                exist, to inpune state responsibility to it through a
                number of intellectual gymnastics involving the
                definition of territory and control. I doubt I'll ever
                buy into those arguments and I don't think they'll ever
                be majority opinion. I could be wrong. I am concerned,
                though, with rules 139 (Respect for IHL), 149
                (Responsibility for Violations of IHL) and 161
                (International Cooperation in Criminal Proceedings) of
                the ICRC's Study on Customary International Law. As of
                today  ICANN as a non state actor does not have any
                responsibility under these rules, but as more people
                examine the nature of ICANN, the ever changing role of
                the GAC, the uniqueness of ICANN as it is constructed, I
                can conceive of a consensus being developed in the IHL
                community that extends responsibility under these rules
                to ICANN as a unique non state actor. It won't happen
                tomorrow, it won't happen next year, but it may happen,
                and I don't want to get myself locked into a position
                today that prevents me from having options several years
                down the road.</div>
              <div><br>
              </div>
              <div>For those who haven't read it the Tallinn Manual  <a
                  moz-do-not-send="true"
                  href="http://www.ccdcoe.org/249.html" target="_blank">http://www.ccdcoe.org/249.html</a>
                 is an exceptional first effort at porting IHL into the
                cyber arena. Mike Schmitt did an exceptional job at
                coordinating input from some pretty diverse people in
                creating the guidance, and from my perspective they did
                a near perfect job for what it is. ICANN is not
                mentioned in the Manual. However at cocktail discussions
                in Estonia last year with some of those involved in the
                project, there was an interest in thinking about ICANN
                and where it fit into all of this, post Manual
                production.  Interest varied, many did not understand
                how ICANN was constituted ( at CyCon's public sessions
                it was described, variably, as an NGO, an IGO, but never
                as a unique MS organisation), but as much as  ICANN
                would like everyone to forget about it in this context
                it simply is not going to happen. The salience of
                cyberwar as an  issue, for reasons often having to do
                more with private economic interests than security, is
                going nowhere but up and there will be some response on
                an international level that  will impact or involve
                ICANN, desired or not.</div>
              <div><br>
              </div>
              <div>As we exist in 2013  I'm happy to sign off on David's
                statement. I do so, though, reserving the right to
                change my view as events and thoughts develop and change
                regarding cyberwar activities. That ICANN should not be
                involved in content, obvious. That we do not want to
                extend it's competence to cybercrime and cyberespionage,
                of course. Certain forms of cyberwar, though, are
                different in that in some areas it isn't something an
                entity can or should be able to opt out of. I'm just not
                personally sure today where ICANN does or should fit
                into all of this. It would be a lot easier if we had
                competing private Internets but until we do I have
                questions in this area  and reserve the right to come
                back in a few years time with views that are different
                than what I can accept today. These are complicated
                issues and I'm not sure best handled with a  bumper
                sticker like perspective. Then again...</div>
              <div><br>
              </div>
              <div><br>
              </div>
              <div><br>
              </div>
              <div><br>
              </div>
              <div>
                <div class="gmail_quote">On Mon, Apr 22, 2013 at 3:36
                  PM, Brenden Kuerbis <span dir="ltr"><<a
                      moz-do-not-send="true"
                      href="javascript:_e({},%20'cvml',%20'bkuerbis@internetgovernance.org');"
                      target="_blank">bkuerbis@internetgovernance.org</a>></span>
                  wrote:<br>
                  <blockquote class="gmail_quote" style="margin:0 0 0
                    .8ex;border-left:1px #ccc solid;padding-left:1ex">
                    <div dir="ltr">+1, thanks David. Minor typo in last
                      para, "explicit acknowledge[ment]..." </div>
                    <div class="gmail_extra">
                      <br clear="all">
                      <div>---------------------------------------<br>
                        Brenden Kuerbis<br>
                        Internet Governance Project<br>
                        <a moz-do-not-send="true"
                          href="http://internetgovernance.org/"
                          target="_blank">http://internetgovernance.org</a></div>
                      <br>
                      <br>
                      <div class="gmail_quote">On Mon, Apr 22, 2013 at
                        8:21 AM, David Cake <span dir="ltr"><<a
                            moz-do-not-send="true"
                            href="javascript:_e({},%20'cvml',%20'dave@difference.com.au');"
                            target="_blank">dave@difference.com.au</a>></span>
                        wrote:<br>
                        <blockquote class="gmail_quote" style="margin:0
                          0 0 .8ex;border-left:1px #ccc
                          solid;padding-left:1ex">
                          <div style="word-wrap:break-word"><span
                              style="white-space:pre-wrap"> </span>This
                            document has been out for public comment. <a
                              moz-do-not-send="true"
href="http://www.icann.org/en/news/announcements/announcement-06mar13-en.htm"
                              target="_blank">http://www.icann.org/en/news/announcements/announcement-06mar13-en.htm</a>
                            <div>
                              <br>
                            </div>
                            <div><span style="white-space:pre-wrap"> </span>I've
                              missed the deadline on public comment for
                              this by a day or two, but I'd still like
                              to see if we can make a small comment on
                              it if we can. 
                              <div><span style="white-space:pre-wrap"> </span>Here
                                is my draft comment - if NCSG could
                                approve it (quickly), that would be
                                great, otherwise I'll just put it in as
                                a personal comment. </div>
                              <div><span style="white-space:pre-wrap"> </span>Any
                                additions or disagreement? </div>
                              <div><br>
                              </div>
                              <div><span style="white-space:pre-wrap"> </span>Regards</div>
                              <div><span style="white-space:pre-wrap"> </span>David</div>
                              <div><br>
                              </div>
                              <div>----------</div>
                              <div>
                                <p class="MsoNormal">The regular update
                                  of the Security, Stability and
                                  Resiliency Framework is a very
                                  important
                                  part of ICANNs SSR function, as
                                  attested by its inclusion in the
                                  Affirmation of
                                  Commitments.</p>
                                <p class="MsoNormal">NCSG notes the
                                  significant effort involved in
                                  preparing the FY13 Security, Stability
                                  and Resiliency Plan, and the progress
                                  towards implementing the
                                  recommendations of the Security,
                                  Stability and Resiliency Review Team
                                  Report.  While work so far has seen
                                  the completion of only some
                                  recommendations, we note planning and
                                  progress has been made for all the
                                  recommendations, and we appreciate the
                                  commitment to full implementation. </p>
                                <div>
                                  <br class="webkit-block-placeholder">
                                </div>
                                <p class="MsoNormal">NCSG supports the
                                  definition of ICANNs SSR role and
                                  remit.
                                  In particular, NCSG values the
                                  acknowledgement of areas that lie
                                  outside ICANNs
                                  remit, and NCSG strongly agrees that
                                  ICANNs role does not include law
                                  enforcement or determining what
                                  constitutes illicit conduct.</p>
                                <p class="MsoNormal">NCSG welcomes the
                                  explicit acknowledge of the necessity
                                  of a
                                  continued multistakeholder approach to
                                  security, and notes the inclusion of
                                  civil society within all discussions
                                  of the Internet and security
                                  ecosystem,
                                  and particularly welcomes the
                                  inclusion of engagement with civil
                                  society on
                                  privacy and free expression issues as
                                  a commitment for FY14. </p>
                                <p class="MsoNormal"><br>
                                </p>
                                <div><br
                                    class="webkit-block-placeholder">
                                </div>
                                <div>
                                </div>
                              </div>
                            </div>
                          </div>
                        </blockquote>
                      </div>
                      <br>
                    </div>
                  </blockquote>
                </div>
                <br>
              </div>
            </blockquote>
          </div>
          <br>
          <br>
          -- <br>
          Alain Berranger, B.Eng, MBA
          <div>Member, Board of Directors, CECI, <a
              moz-do-not-send="true"
              href="http://www.ceci.ca/en/about-ceci/team/board-of-directors/"
              target="_blank">http://www.ceci.ca</a><br>
            <div>Executive-in-residence, Schulich School of Business, <a
                moz-do-not-send="true"
                href="http://www.schulich.yorku.ca/" target="_blank">www.schulich.yorku.ca</a></div>
            <div>Treasurer, Global Knowledge Partnership Foundation, <a
                moz-do-not-send="true"
                href="http://www.gkpfoundation.org/" target="_blank">www.gkpfoundation.org</a></div>
            <div>NA representative, Chasquinet Foundation, <font
                color="#0a246a" face="'Times New Roman', Times, serif"><a
                  moz-do-not-send="true"
                  href="http://www.chasquinet.org/" target="_blank">www.chasquinet.org</a></font><br>
              Chair, NPOC, NCSG, ICANN, <a moz-do-not-send="true"
                href="http://npoc.org/" target="_blank">http://npoc.org/</a><br>
              O:+1 514 484 7824; M:+1 514 704 7824<br>
              Skype: alain.berranger<br>
            </div>
          </div>
          <div><br>
          </div>
          <div>
            <div><br>
            </div>
            <div>AVIS DE CONFIDENTIALITÉ</div>
            <div>Ce courriel est confidentiel et est à l’usage exclusif
              du destinataire ci-dessus. Toute personne qui lit le
              présent message sans en être le destinataire, ou
              l’employé(e) ou la personne responsable de le remettre au
              destinataire, est par les présentes avisée qu’il lui est
              strictement interdit de le diffuser, de le distribuer, de
              le modifier ou de le reproduire, en tout ou en partie . Si
              le destinataire ne peut être joint ou si ce document vous
              a été communiqué par erreur, veuillez nous en informer sur
              le champ  et détruire ce courriel et toute copie de
              celui-ci. Merci de votre coopération.</div>
            <div><br>
            </div>
            <div>CONFIDENTIALITY MESSAGE</div>
            <div>This e-mail message is confidential and is intended for
              the exclusive use of the addressee. Please note that,
              should this message be read by anyone other than the
              addressee, his or her employee or the person responsible
              for forwarding it to the addressee, it is strictly
              prohibited to disclose, distribute, modify or reproduce
              the contents of this message, in whole or in part. If the
              addressee cannot be reached or if you have received this
              e-mail in error, please notify us immediately and delete
              this e-mail and destroy all copies. Thank you for your
              cooperation.</div>
          </div>
          <div><br>
          </div>
          <br>
        </blockquote>
      </div>
      <br>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 


</pre>
  </body>
</html>