<html><head><meta http-equiv="Content-Type" content="text/html; charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">Hi<div class=""><br class=""></div><div class="">NTIA speaketh, read it and weep. <strong style="background-color: rgb(255, 255, 255);" class=""><span style="color: rgb(149, 79, 114); font-weight: normal;" class=""><a href="https://www.ntia.doc.gov/speechtestimony/2018/remarks-assistant-secretary-redl-state-net-2018" class="">https://www.ntia.doc.gov/speechtestimony/2018/remarks-assistant-secretary-redl-state-net-2018</a></span></strong></div><div class=""><font color="#954f72" class=""><span style="background-color: rgb(255, 255, 255);" class=""><br class=""></span></font></div><div class=""><font color="#954f72" class=""><span style="background-color: rgb(255, 255, 255);" class=""><br class=""></span></font><div><br class=""></div><div><blockquote type="cite" class=""><blockquote type="cite" class=""><span class="" style="orphans: 2; widows: 2; background-color: rgb(255, 255, 255); display: inline !important;">Here are the facts: the text of the GDPR balances the interests of cybersecurity, law enforcement, and consumer protection, and many European officials have noted that limited changes to the WHOIS would be necessary to achieve GDPR compliance. Still, there are some who are trying to take advantage of the situation by arguing that we should erect barriers to the quickly and easily accessible WHOIS information. Some have even argued that the service must go dark, and become a relic of the Internet's history. </span></blockquote></blockquote><div class=""><blockquote type="cite" class=""><span class="" style="orphans: 2; widows: 2; background-color: rgb(255, 255, 255); display: inline !important;"><br class=""></span></blockquote></div></div><div><br class=""></div><div>I guess we are opportunistic barrier advocates? :-)</div><div><br class=""></div><div>Bill</div><div><br class=""></div><div><br class=""><blockquote type="cite" class=""><div class="">On Jan 29, 2018, at 20:00, Kathy Kleiman <<a href="mailto:Kathy@kathykleiman.com" class="">Kathy@kathykleiman.com</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><p style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class="">Milton, I understand the comments below and I wish I could support them as the whole of the NCSG comments, but I cannot. However, I support much of them -- and let me share:</p><p style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class="">1. "The purpose of Whois must be strictly tied to ICANN's mission." ==> that's absolutely true but we don't have that purpose yet (and I have to tell you that the RDS Working Group is not doing a great job of analyzng "purpose" right now (it is not closely following the strict legal rules of the GDPR and other comprehensive data protection laws -- this will be debated on Tuesday). But we (ICANN) does not have that "purpose" yet, and won't in the next 3 months (since any recommendation of the RDS WG would take months for review and acceptance, and the WG is nowhere near publishing it). But right now, we do have an open and public WHOIS system - all available all the time (unless you have signed up for a proxy or privacy service) - with<span class="Apple-converted-space"> </span><i class="">unlimited "all you can eat access" by everyone,<span class="Apple-converted-space"> </span></i>including intellectual property attorneys and law enforcement. That is happily going to change!!<br class=""></p><span style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); float: none; display: inline !important;" class="">2. "Whois service, like the DNS itself, should be globally uniform and not vary by jurisdiction." ==> Yes, and that's what the ECO Model and Model 2B provide. But, unfortunately, that's Model 3 does not provide uniformity; Model 3 provide great differentiation of protection, with only private individuals being protected, and not the political, sexual, religious, educational groups that I discussed in one of my recent emails - the array of groups that we protect engaged in huge amount of controversial and critical speech and services.<span class="Apple-converted-space"> </span></span><b style="font-style: normal; font-variant-caps: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class="">The ICANN Model 3 here is very clear:<span class="Apple-converted-space"> </span></b><span style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); float: none; display: inline !important;" class="">"</span><b style="font-style: normal; font-variant-caps: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class="">Display unless field includes personal data." (ICANN's Proposed Interim Models for Compliance, pages 12-14).</b><span style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); float: none; display: inline !important;" class=""> Thus, for noncommercial organizations, exposure of Registrant/Admin/Tech name, address, phone and email will remain completely open. Model 2B and ECO do better and protect legal and natural persons. That's hugely important - and a tribute to our years of work on this subject!</span><br style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><br style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><span style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); float: none; display: inline !important;" class="">3. "No tiered access solution that involves establishing new criteria for access can feasibly be created in the next 3 months." ==> We are unlikely to go from infinite public access to completely restricted private access right now. The Multistakeholder Process won't support that. But the ECO model does a lot to help on this particular issue. I'll outline in my next email.</span><br style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><br style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><span style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); float: none; display: inline !important;" class="">Overall, it's great to have models and options. After fifteen years working in this WHOIS space, and I am optimistic that we are about to see the biggest change of our lifetimes coming up in this space. We have waited a long time!</span><br style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><span style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); float: none; display: inline !important;" class="">Best,<span class="Apple-converted-space"> </span></span><br style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><span style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); float: none; display: inline !important;" class="">Kathy</span><br style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><br style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><span style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); float: none; display: inline !important;" class="">On 1/26/2018 6:00 PM, Mueller, Milton L wrote:</span><br style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><blockquote cite="mid:BN3PR0701MB126542154BE3020610BA792EA1E70@BN3PR0701MB1265.namprd07.prod.outlook.com" type="cite" style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><div class="WordSection1" style="page: WordSection1;"><div style="margin: 0in 0in 0.0001pt;" class="">I offer the following as a first draft of the NCSG position on the 12 January 2018 call for comments released by ICANN org.<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">Principles<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">Our evaluation of the models offered by ICANN are based on three fundamental principles. No model that fails to conform to all three is acceptable to the NCSG.<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">1. The purpose of whois must be strictly tied to ICANN's mission. That is, the data that is collected and the data that are published must directly and demonstrably contribute to ICANN's mission as defined in Article 1 of its new bylaws. We reject any definition of Whois purpose that is based on the way people happen to make use of data that can be accessed indiscriminately in a public directory. The fact that certain people currently use Whois for any purpose does not mean that the purpose of Whois is to provide thick data about the domain and its registrant to anyone who wants it for any reason.<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">2. Whois service, like the DNS itself, should be globally uniform and not vary by jurisdiction. ICANN was created to provide globalized governance of the DNS so that it would continue to be globally compatible and coordinated. Any solution that involves fragmenting the policies and practices of Whois along jurisdictional lines is not desirable.<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">3. No tiered access solution that involves establishing new criteria for access can feasibly be created in the next 3 months. We would strongly resist throwing the community into a hopeless rush to come up with entirely new policies, standards and practices involving tiered access to data, and we do not want ICANN staff to invent a policy that is not subject to community review and approval. <o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">Based on these three principles, we believe that Model 3 is the only viable option available. Model 3 minimizes the data publicly displayed to that which is required for maintaining the stability, security and resiliency of the DNS. Model 3 could be applied across the board, and would be presumptively legal regardless of which jurisdiction the registrar, registry or registrant are in. And Model 3 relies on established legal due process for gaining access to additional information.<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">There is room for discussion about how much data could be publicly displayed under Model 3 consistent with ICANN's mission. E.g., it may be within ICANN's mission to include additional data in the public record, such as an email address for the technical contact and even possibly the name of the registrant.<span class="Apple-converted-space"> </span><o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">The process of gaining access to additional data in Model 1 is completely unacceptable. Self-certification by any third party requestor is, we believe, not compliant with GDPR nor does is such access justified by the purpose of Whois or ICANN's mission.<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">Model 2 might possibly be acceptable if an suitable set of criteria and processes were devised, but it simply is not feasible for such a certification program to be developed in 3 months. A certification program thrown together in a rush poses huge risks for loopholes, poor procedures, and a legal challenge to ICANN, either from DPAs or from individuals affected.<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">Dr. Milton L. Mueller<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">Professor, School of Public Policy<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class="">Georgia Institute of Technology<o:p class=""></o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div><div style="margin: 0in 0in 0.0001pt;" class=""><o:p class=""> </o:p></div></div></blockquote><br style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255);" class=""><br class="Apple-interchange-newline"></div></blockquote></div><br class=""><div class="">
<div style="color: rgb(0, 0, 0); font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;"><div class="">***********************************************<br class="">William J. Drake<br class="">International Fellow & Lecturer<br class=""> Media Change & Innovation Division, IPMZ<br class=""> University of Zurich, Switzerland<br class=""><a href="mailto:william.drake@uzh.ch" class="">william.drake@uzh.ch</a> (direct), <a href="mailto:wjdrake@gmail.com" class="">wjdrake@gmail.com</a> (lists),<br class=""> <a href="http://www.williamdrake.org" class="">www.williamdrake.org</a><br class="">***********************************************<br class=""></div><br class=""></div><br class="Apple-interchange-newline">
</div>
<br class=""></div></body></html>