<div dir="ltr"><div>Dear Farzaneh,</div><div><br></div><div>Thanks for the update. Personally, I think considering how important the authcode is to domain ownership, multi-factor authentication makes sense. I imagine most requests for the authcode will be via the panel when initiating a domain transfer. So securing the panel with multi-fac authentication might be all that is necessary. <br></div><div><div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><br></div>Tomslin</div></div></div></div></div></div></div></div></div></div></div></div><br></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, 22 Sept 2021 at 04:09, farzaneh badii <<a href="mailto:farzaneh.badii@gmail.com">farzaneh.badii@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">As some of you know Wisdom and I represent NCSG at the Transfer policy group. <div><br></div><div>This group is very important especially for operational side of things when domain name registrants want to transfer their domain name from one registrar to another.</div><div><br></div><div>Some issues that have been raised: </div><div><br></div><div>There is generally some hostility towards multi-factor authentication and  making it compulsory for registrars to provide it for the registrant.  Some argue that resellers don’t have the means either. Akinremi, Wisdom and I discussed this and we believe that the more secure transfer the better. But also it came up whether we are asking for multifactor authentication to the panel or just when the authentication code for the transfer is being issued. We believe pushing for both is good but well since this is transfer policy group might be stretching it. </div><div><br></div><div>Some questions that we have from you especially if there are non-commercial resellers here (because sometimes individuals have reseller credentials doing things privately) or if you are a domain name registrant whether you are comfortable with multi-factor authentication. </div><div><br></div><div>In general I sense that the policy group lacks two things: a desire for coming up with a policy (they don’t want to bind themselves to anything which well defeats the purpose of our work!) and we lack the domain name registrants voice. Registrars and ICANN talk about their experience which is good but I still think would have been nice to hear from the registrants. </div><div><br></div><div>There bound to be some privacy issues that come up later on but we have not been dealing with that yet. </div>
<br><br>-- <br><div dir="ltr"><div><font face="verdana, sans-serif">Farzaneh </font></div></div><br>
</blockquote></div>