<div>Hi,<br><br>I would just like
to clarify the intent of my comments, and the outcome I am seeking.<br><br>My comments are only
in relation to record retention. I am of the view that ICANN has a
responsibility to retain all emails sent through the various listservs in an
appropriate electronic system which:<br></div><ul><li>Preserves their original content, context, and
structure;<br></li><li>Can associate the messages with their sender;<br></li><li>Are protected against unauthorised alteration,
deletion, or use; and<br></li><li>Can be located, retrieved, presented, and
interpreted for the retention period that the community has set.<br></li></ul><div>ICANN’s email
archives are a phenomenal resource, full of problems identified and solved,
drafts written, revised and later published, issues debated diligently. As a
matter of principle I am not comfortable with these records being altered, no
matter how minor the edit may be. I am even less comfortable with these
archives having their hyperlinks replaced with URLs that may in the future –
however likely or unlikely – become broken.<br></div><div><br></div><div>ProofPoint exists
today and for now the new URLs are redirecting to the correct place. For many
organisations with non-vital records or records which need to be retained for
exceedingly short periods of time, this solution is probably very appropriate. If
it was just the link in, say, the ICANN newsletter that was masked, I would not
care. But we are talking about records that we want to safeguard and retain for
a long period of time. Conversations between staff and community, for instance,
on the current At-Large Review which could see this advisory committee take on
policy making functions. We have no guarantees that ProofPoint will be around
in five or ten or 100 years time. We need these records retained, unaltered,
for future retrieval and study.<br></div><div><br></div><div>As it is, many of
the email archives from pre-2007 are missing their attachments. This media
decay is not acceptable and I would like ICANN to take steps to ensure its
email records, moving forward, do not suffer from technology obsolescence. <br></div><div><br></div><div>My remarks are not
in regards to the value of ProofPoint in securing and controlling inbound and
outbound email. I am not qualified to make an assessment on whether or not
ICANN should be using ProofPoint for security, though I do appreciate there is
a need for ICANN as an organisation to protect its assets from threats and
nuisances. But in my opinion, ICANN also has an obligation to preserve all of the community's public records so that
they can be identified and retrieved in their original form in the future.<br><br>Best wishes,</div><div><br></div><div class="protonmail_signature_block "><div class="protonmail_signature_block-user "><div>Ayden Férdeline<br></div><div><a title="http://www.linkedin.com/in/ferdeline" href="http://www.linkedin.com/in/ferdeline">linkedin.com/in/ferdeline</a><br></div></div><div class="protonmail_signature_block-proton protonmail_signature_block-empty"><br></div></div><div><br></div><blockquote type="cite" class="protonmail_quote"><div>-------- Original Message --------<br></div><div>Subject: Re: External links & archives<br></div><div>Local Time: 15 February 2017 9:14 PM<br></div><div>UTC Time: 15 February 2017 21:14<br></div><div>From: stephanie.perrin@MAIL.UTORONTO.CA<br></div><div>To: NCSG-DISCUSS@LISTSERV.SYR.EDU<br></div><div><br></div><div> <br></div><p><span class="size" style="font-size:undefinedpx"><span class="font" style="font-family:Lucida Grande">good news for us
non-geeks! Thanks James.</span></span><br></p><p><span class="size" style="font-size:undefinedpx"><span class="font" style="font-family:Lucida Grande">SP</span></span><br></p><div><br></div><div class="moz-cite-prefix">On 2017-02-15 14:26, James Gannon
wrote:<br></div><blockquote type="cite"><div class="WordSection1"><p class="MsoNormal"><span class="colour" style="color:windowtext"><span class="font" style="font-family:Calibri, sans-serif"><span class="size" style="font-size:11pt">Being
very honest, this is not a question we should be spending
time on in my opinion, Proofpoint is used by millions of
users and thousands of companies and governments, we wont
change anything on their side and ICANNS use of it is a good
thing for security.</span></span></span><br></p><p class="MsoNormal"><span class="colour" style="color:windowtext"><span class="font" style="font-family:Calibri, sans-serif"><span class="size" style="font-size:11pt"> </span></span></span><br></p><p class="MsoNormal"><span class="colour" style="color:windowtext"><span class="font" style="font-family:Calibri, sans-serif"><span class="size" style="font-size:11pt">-James</span></span></span><br></p><p class="MsoNormal"><span class="colour" style="color:windowtext"><span class="font" style="font-family:Calibri, sans-serif"><span class="size" style="font-size:11pt"> </span></span></span><br></p><div><div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in"><p class="MsoNormal"><b><span class="colour" style="color:windowtext"><span class="font" style="font-family:Calibri, sans-serif"><span class="size" style="font-size:11pt">From:</span></span></span></b><span class="colour" style="color:windowtext"><span class="font" style="font-family:Calibri, sans-serif"><span class="size" style="font-size:11pt"> NCSG-Discuss [<a rel="noreferrer nofollow noopener" class="moz-txt-link-freetext" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU</a>] <b>On Behalf Of </b>Stephanie Perrin<br> <b>Sent:</b> Wednesday, February 15, 2017 5:51 PM<br> <b>To:</b> <a rel="noreferrer nofollow noopener" class="moz-txt-link-abbreviated" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br> <b>Subject:</b> Re: External links & archives</span></span></span></p></div></div><p class="MsoNormal"> <br></p><p><span class="size" style="font-size:13.5pt">Great. and if Proof point gets bought and
killed, my next question is then what?</span><br></p><p><span class="size" style="font-size:13.5pt">Stephanie Perrin</span><br></p><p class="MsoNormal"> <br></p><div><p class="MsoNormal">On 2017-02-15 12:23, Ayden Férdeline
wrote:<br></p></div><blockquote style="margin-top:5.0pt;margin-bottom:5.0pt"><div><p class="MsoNormal"></p><div>Greetings, all-<br></div><div> <br></div><div> I have received a message from ICANN staff regarding the
lifespan of access to masked hyperlinks. I have copied and
pasted their response verbatim: <br></div><p></p></div><div><p class="MsoNormal"> <br></p></div><div><p class="MsoNormal"><i>hi - i heard back from the security
team - Great question!There is a long answer and a short
answer.In short, the links will always work as long as
Proofpoint is still a company J.The long answer is once
the URL is re-written it will always be re-written. For
example, if you forward an email to another company that
does not own proofpoint but that email you sent has a
proofpoint re-written link, they can still open it. It
will always re-direct to the proofpoint servers and then
to the final destination. If for some reason you leave
proofpoint, those links will still work just so long as
Proofpoint is still a company.Hope this answers your
question!</i><br></p></div><div><p class="MsoNormal"> <br></p></div><div><p class="MsoNormal">Best wishes,<br></p></div><div><p class="MsoNormal"> <br></p></div><div><div><div><p class="MsoNormal">Ayden Férdeline<br></p></div><div><p class="MsoNormal"><a rel="noreferrer nofollow noopener" href="http://www.linkedin.com/in/ferdeline" title="http://www.linkedin.com/in/ferdeline">linkedin.com/in/ferdeline</a><br></p></div></div><div><p class="MsoNormal"> <br></p></div></div><div><p class="MsoNormal"> <br></p></div><blockquote style="margin-top:5.0pt;margin-bottom:5.0pt"><div><p class="MsoNormal">-------- Original Message --------<br></p></div><div><p class="MsoNormal">Subject: External links &
archives<br></p></div><div><p class="MsoNormal">Local Time: 2 February 2017 12:43 PM<br></p></div><div><p class="MsoNormal">UTC Time: 2 February 2017 12:43<br></p></div><div><p class="MsoNormal">From: <a rel="noreferrer nofollow noopener" href="mailto:icann@ferdeline.com">icann@ferdeline.com</a><br></p></div><div><p class="MsoNormal">To: <a rel="noreferrer nofollow noopener" href="mailto:NCSG-DISCUSS@listserv.syr.edu">NCSG-DISCUSS@listserv.syr.edu</a> <a rel="noreferrer nofollow noopener" href="mailto:NCSG-DISCUSS@listserv.syr.edu"><NCSG-DISCUSS@listserv.syr.edu></a><br></p></div><div><p class="MsoNormal"> <br></p></div><div><p class="MsoNormal">I really dislike this masking of
hyperlinks when we receive an email from ICANN staff
now. When I read email archives, I can't see the real
URL to ascertain at a glance what I am really clicking
on, and must trust it will take me to the ICANN website.
I rarely click on every hyperlink in an email, as I can
see from the URL whether it is an announcement, a PDF,
taking me to the wiki, or somewhere else. Now I am often
left to click all the links to try to find the relevant
material. This is a but a small inconvenience, and not
my biggest concern. What I worry about is how we archive
these links. In five or ten years time, will
"urldefense.proofpoint.com" plus the string of 200 or so
random characters still redirect to the linked content?
We don't need these third party redirects, it does not
make us any safer, and it feels very much us vs. them.
Is it possible that we can get some meaningful
assurances from ICANN staff that these masked links will
redirect to the correct URLs in perpetuity? Thanks<br></p></div><div><p class="MsoNormal"> <br></p></div><div><div><div><p class="MsoNormal">Ayden Férdeline<br></p></div><div><p class="MsoNormal"><a rel="noreferrer nofollow noopener" href="http://www.linkedin.com/in/ferdeline" title="http://www.linkedin.com/in/ferdeline">linkedin.com/in/ferdeline</a><br></p></div></div><div><p class="MsoNormal"> <br></p></div></div><div><p class="MsoNormal"> <br></p></div></blockquote><div><p class="MsoNormal"> <br></p></div></blockquote><p class="MsoNormal"> <br></p></div></blockquote></blockquote><div><br></div>