<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
My personal opinion is we spent a huge amount of political capital fighting for a limited mandate and for ICANN to stay out of areas not related to the root zone during the IANA transition, if we now turn around and say the opposite because its something we
 are interested in I think we burn a lot of creditability I think.<br class="">
<div><br class="">
<blockquote type="cite" class="">
<div class="">On 24 Jan 2019, at 09:25, David Cake <<a href="mailto:dave@davecake.net" class="">dave@davecake.net</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
What ICANN can contractually mandate, and what it can discuss, or consider in policy creation, best practice docs, comments, etc are very different things. And also, ICANN communities overlap with over Internet communities of practice quite a bit - no reason
 discussions in ICANN can’t comment on what goes on elsewhere.
<div class="">Also, how registrars operate with regards to RDAP totally is being considered within ICANN at this point, and is not a 100% disjoint discussion.  <br class="">
<div class=""><br class="">
</div>
<div class="">David<br class="">
<div class=""><br class="">
<blockquote type="cite" class="">
<div class="">On 24 Jan 2019, at 4:19 pm, James Gannon <<a href="mailto:james@cyberinvasion.net" class="">james@cyberinvasion.net</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
I think that if ICANN tried to define how a registarar operates or mandates 2FA for their clients we would see quite quickly that that is very much outside of the bylaws interpretation in my opinion =)
<div class=""><br class="">
</div>
<div class="">Not saying its not important, just out of scope for ICANN.<br class="">
<div class=""><br class="">
<blockquote type="cite" class="">
<div class="">On 24 Jan 2019, at 09:16, David Cake <<a href="mailto:dave@davecake.net" class="">dave@davecake.net</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
Registrar procedures are kind of within ICANN scope, or at least on the edges of it - but certainly procedures of groups that are definitely outside ICANNs remit have definitely been considered as part of ICANN policy processes. That is, ICANN may not in any
 way control processes like CAs, but it can (and does) consider the needs of such providers when looking at policy issues like RDS. 
<div class=""><br class="">
</div>
<div class="">David<br class="">
<div class=""><br class="">
<blockquote type="cite" class="">
<div class="">On 24 Jan 2019, at 4:03 pm, James Gannon <<a href="mailto:james@CYBERINVASION.NET" class="">james@CYBERINVASION.NET</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
DNS below the root is out of scope for ICANN so I don’t agree that that is even a possibility.<br class="">
<div class=""><br class="">
<blockquote type="cite" class="">
<div class="">On 24 Jan 2019, at 08:59, Vladimer Svanadze <<a href="mailto:00000585df4969dc-dmarc-request@LISTSERV.SYR.EDU" class="">00000585df4969dc-dmarc-request@LISTSERV.SYR.EDU</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div class="WordSection1" style="page: WordSection1; caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class="">Hello,<o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class=""><o:p class=""> </o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class="">Thank you, Sam, for your email, and information provided us.<o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class=""><o:p class=""> </o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class="">I agree with David in sort of around the edges of ICANNs remit, but security of DNS is a very important process, and also it is a main target for criminals in
 the near future. This problem is not only National level, it is a globally problem, and challenge for all DNS Community.<o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class=""><o:p class=""> </o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class="">It is not a problem only for the US, it is problem for every infrastructure. I think that will be very important for a stability and security of infrastructure
 of all countries, if registrar use more technical tools with Unified International Standards of protection, and include secure authentication, multi-factor authentication, as David say.<span class="Apple-converted-space"> </span><o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class=""><o:p class=""> </o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class="">Also I would like to add that will be good if around of ICANN will be a discussion about Security and Stability of DNS, and ICANN will develop policy/strategy
 with recommendation for DNS SSR, as a National, also as a Global level.<o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class=""><o:p class=""> </o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class="">And once again I absolutely agree with David in issues of DNS SSR can be tackled solely at the ICANN level.<o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class=""><o:p class=""> </o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class="">Lado<o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class=""><o:p class=""> </o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class=""><o:p class=""> </o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);" class=""><o:p class=""> </o:p></span></div>
<div class="">
<div style="border-style: solid none none; border-top-width: 1pt; border-top-color: rgb(225, 225, 225); padding: 3pt 0in 0in;" class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<b class=""><span style="font-size: 11pt; font-family: Calibri, sans-serif;" class="">From:</span></b><span style="font-size: 11pt; font-family: Calibri, sans-serif;" class=""><span class="Apple-converted-space"> </span>NCSG-Discuss [<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU" class="">mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU</a>]<span class="Apple-converted-space"> </span><b class="">On
 Behalf Of<span class="Apple-converted-space"> </span></b>David Cake<br class="">
<b class="">Sent:</b><span class="Apple-converted-space"> </span>Wednesday, January 23, 2019 10:47 AM<br class="">
<b class="">To:</b><span class="Apple-converted-space"> </span><a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU" class="">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br class="">
<b class="">Subject:</b><span class="Apple-converted-space"> </span>Re: ICANN Remit: Security & Stability of the DNS System<o:p class=""></o:p></span></div>
</div>
</div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
Thanks for brining this up, Sam. Some of this is sort of around the edges of ICANNs remit, but I think very useful for the DNS community to discuss. <o:p class=""></o:p></div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<o:p class=""> </o:p></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
These are issues for US infrastructure of  course, but the same attacks, and the same mitigations, apply to all DNS use. It is important for all registrar services to include secure authentication, multi-factor authentication, etc. And supporting Certificate
 Transparency is definitely outside ICANNs direct remit, but a very interesting topic for discussion. <o:p class=""></o:p></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<o:p class=""> </o:p></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
A valuable reminder that DNS security is a real, and complex, issue even if many aspects of it are at the edges of ICANNs mission, and not all DNS SSR issues can be tackled solely at the ICANN level. <o:p class=""></o:p></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<o:p class=""> </o:p></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
David<o:p class=""></o:p></div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<o:p class=""> </o:p></div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<br class="">
<br class="">
<o:p class=""></o:p></div>
<blockquote style="margin-top: 5pt; margin-bottom: 5pt;" class="" type="cite">
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
On 23 Jan 2019, at 9:44 am, Sam Lanfranco <<a href="mailto:lanfran@YORKU.CA" style="color: purple; text-decoration: underline;" class="">lanfran@YORKU.CA</a>> wrote:<o:p class=""></o:p></div>
</div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<o:p class=""> </o:p></div>
<div class="">
<div class="">
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-family: Tahoma, sans-serif;" class="">Excuse me if this is too far off base. It does serve as a quick primer on the kinds of threats that the DNS system is up against on a daily basis.<span class="Apple-converted-space"> </span></span><span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class=""><o:p class=""></o:p></span></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class=""><o:p class=""> </o:p></span></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">As we work within the ICANN remit it might be useful to on occasion look out there at the ongoing daily threats to the security and stability of the DNS system. We are keenly aware of
 when various actors "turn off" the Internet but most of us are less aware of the other forms of attack on DNS security and stability. Here is a link to, and a few words from, the U.S. Department of Homeland Security on recent attacks on the DNS system.<span class="Apple-converted-space"> </span><o:p class=""></o:p></span></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class=""><o:p class=""> </o:p></span></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-family: Tahoma, sans-serif;" class=""><a href="https://cyber.dhs.gov/ed/19-01/" style="color: purple; text-decoration: underline;" class="">https://cyber.dhs.gov/ed/19-01/</a></span><span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class=""><o:p class=""></o:p></span></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class=""><o:p class=""> </o:p></span></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class=""><br class="">
</span><span style="font-family: Tahoma, sans-serif;" class="">This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s<span class="Apple-converted-space"> </span><a href="https://cyber.dhs.gov/assets/report/ed-19-01.pdf" style="color: purple; text-decoration: underline;" class="">Emergency
 Directive 19-01</a>, “<em class=""><span style="font-family: Tahoma, sans-serif;" class="">Mitigate DNS Infrastructure Tampering</span></em>”.</span><span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class=""><o:p class=""></o:p></span></div>
</div>
<div class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class=""><o:p class=""> </o:p></span></div>
</div>
<div style="margin-bottom: 0.05in;" class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<b class=""><i class=""><span style="font-family: Tahoma, sans-serif;" class="">Excerpts:<span class="Apple-converted-space"> </span></span></i></b><b class=""><span style="font-family: Tahoma, sans-serif;" class=""><a href="https://www.us-cert.gov/ncas/current-activity/2019/01/22/CISA-Emergency-Directive-DNS-Infrastructure-Tampering" style="color: purple; text-decoration: underline;" class="">CISA
 Emergency Directive on DNS Infrastructure Tampering</a><o:p class=""></o:p></span></b></div>
</div>
<div class="">
<div style="margin-bottom: 0.05in;" class="">
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<i class=""><span style="font-size: 9pt; font-family: Tahoma, sans-serif; color: rgb(102, 102, 102);" class="">01/22/2019 06:48 PM EST<o:p class=""></o:p></span></i></div>
</div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class=""><br class="">
Original release date: January 22, 2019<o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">The U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive to address ongoing incidents associated with global
 Domain Name System (DNS) infrastructure tampering. CISA is aware of multiple executive branch agency domains that were impacted by the tampering campaign and has notified the agencies that maintain them. The directive requires Federal agencies to take specific
 steps and comply with reporting procedures to mitigate risks from undiscovered tampering, prevent illegitimate DNS activity, and detect unauthorized certificates.<o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">Federal agencies should review<span class="Apple-converted-space"> </span><a href="https://cyber.dhs.gov/ed/19-01/" style="color: purple; text-decoration: underline;" class="">Emergency
 Directive 19-01</a><span class="Apple-converted-space"> </span>for required actions and reporting procedures.<span class="Apple-converted-space"> </span><o:p class=""></o:p></span></div>
<h3 id="background" style="margin-right: 0in; margin-left: 0in; font-size: 13.5pt; font-family: "Times New Roman", serif;" class="">
<span style="font-family: Tahoma, sans-serif;" class="">Background<o:p class=""></o:p></span></h3>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">In coordination with government and industry partners, the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) is tracking a series of incidents<sup id="fnref:1" class=""><a href="https://cyber.dhs.gov/ed/19-01/#fn:1" style="color: purple; text-decoration: underline;" class="">1</a></sup><span class="Apple-converted-space"> </span>involving
 Domain Name System (DNS) infrastructure tampering. CISA is aware of multiple executive branch agency domains that were impacted by the tampering campaign and has notified the agencies that maintain them.<o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">Using the following techniques, attackers have redirected and intercepted web and mail traffic, and could do so for other networked services.<o:p class=""></o:p></span></div>
<ol start="1" type="1" style="margin-bottom: 0in;" class="">
<li class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">The attacker begins by compromising user credentials, or obtaining them through alternate means, of an account that can make changes to DNS records.<o:p class=""></o:p></span></li><li class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">Next, the attacker alters DNS records, like Address (A), Mail Exchanger (MX), or Name Server (NS) records, replacing the legitimate address of a service with an address the attacker controls.
 This enables them to direct user traffic to their own infrastructure for manipulation or inspection before passing it on to the legitimate service, should they choose. This creates a risk that persists beyond the period of traffic redirection.<o:p class=""></o:p></span></li><li class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">Because the attacker can set DNS record values, they can also obtain valid encryption certificates for an organization’s domain names. This allows the redirected traffic to be decrypted,
 exposing any user-submitted data. Since the certificate is valid for the domain, end users receive no error warnings.<o:p class=""></o:p></span></li></ol>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">To address the significant and imminent risks to agency information and information systems presented by this activity, this emergency directive requires the following near-term actions
 to mitigate risks from undiscovered tampering, enable agencies to prevent illegitimate DNS activity for their domains, and detect unauthorized certificates. <span class="Apple-converted-space"> </span><o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">See:<span class="Apple-converted-space"> </span><a href="https://cyber.dhs.gov/ed/19-01/" style="color: purple; text-decoration: underline;" class="">Emergency Directive 19-01</a><o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: "Times New Roman", serif;" class="">
<span style="font-size: 10pt; font-family: Tahoma, sans-serif;" class="">Posted by: Sam L. NPOC</span></div>
</div>
</div>
</div>
</blockquote>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div>
<br class="">
</div>
</div>
</blockquote>
</div>
<br class="">
</div>
</div>
</div>
</blockquote>
</div>
<br class="">
</div>
</div>
</div>
</blockquote>
</div>
<br class="">
</div>
</div>
</div>
</div>
</blockquote>
</div>
<br class="">
</body>
</html>