<div dir="ltr"><span id="gmail-docs-internal-guid-4f0d6977-7fff-8475-9860-996349195024"><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">Hi Farzaneh,</span></p><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">Thank you for this important update.</span></p><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">I personally support an NCSG perspective that any system for disclosure of domain registration data must carefully balance the need for accountability and transparency (especially from LEAs and registrars) with strong privacy protections for domain name registrants, especially those in vulnerable contexts.</span></p><br><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">Since we are still in the pilot stage, I believe your recommendation for a lightweight authentication can be a good approach for non-LEAs. </span></p><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">The challenge is how to provide guides on </span><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:700;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">how to keep a balance in the </span><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">implementation of the process without abuse.</span></p><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">Full authentication may add more overhead and bottleneck on the process and may make it more difficult to adopt or implement.</span></p><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">Also, just as you have said, the emphasis for authentication should be LEAs at the moment.</span></p><br><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">On another note, what do you think of the inDrive car-hailing app creating a data-sharing platform for LEAs in Nigeria, just to manage the many requests they get from the authorities? (Also, the issue of balance between safety and user privacy was mentioned)</span></p><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><a href="https://punchng.com/indrive-unveils-law-enforcement-data-request-platform/" style="text-decoration-line:none"><span style="font-family:Arial,sans-serif;background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;text-decoration-line:underline;vertical-align:baseline">https://punchng.com/indrive-unveils-law-enforcement-data-request-platform/</span></a></p><br><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">Kind regards,</span></p><p dir="ltr" style="line-height:1.38;margin-top:12pt;margin-bottom:12pt"><span style="font-family:Arial,sans-serif;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;vertical-align:baseline">Benjamin </span></p></span><br class="gmail-Apple-interchange-newline"></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Wed, May 28, 2025 at 8:58 AM Michaela Nakayama Shapiro <<a href="mailto:00001b332dc2b5b0-dmarc-request@listserv.syr.edu">00001b332dc2b5b0-dmarc-request@listserv.syr.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="msg8244005044467175358">
<div lang="EN-US" style="overflow-wrap: break-word;">
<p style="font-family:Calibri;font-size:10pt;color:rgb(0,128,0);margin:5pt;font-style:normal;font-weight:normal;text-decoration:none" align="Left">
INTERNAL<br>
</p>
<br>
<div>
<p style="font-family:Calibri;font-size:10pt;color:rgb(0,128,0);margin:5pt;font-style:normal;font-weight:normal;text-decoration:none" align="Left">
INTERNAL<br>
</p>
<br>
<div>
<div class="m_1015267124950062903WordSection1">
<p class="MsoNormal"><span style="font-size:12pt">Hi Farzi,<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt">Thank you for sharing this update!<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt">One question that I keep coming back to is who/what are we talking about when we say “non-LEAs”? Having a better sense of who these entities are and why they would be requesting this information would be helpful
to answer your question.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt">Regardless, my two cents is that non-LEA accreditation is needed. I think the best-case scenario is that we should have both: full accreditation mechanisms for non-LEAs (+1 to
<a id="m_1015267124950062903OWAAM076A1E6E3B8F644AB7ED59773FAC0BB1" href="mailto:emmanuelvitus@gmail.com" target="_blank">
<span style="font-family:Aptos,sans-serif;text-decoration:none">@Emmanuel Vitus</span></a>’s concerns here)
<b><u>and</u></b> reports by registrars on these requests. That may not be a popular opinion in the RDRS SC, but I think it’s important and something we can reiterate in our session.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt">Best,<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt">Michaela<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
<div style="width:450px;height:352px;padding:15px 17px;background:white;display:inline-flex">
<table id="m_10152671249500629030.6evagjsosej" style="width:100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" style="width:100%;font-family:Arial;font-size:10pt">
<table id="m_10152671249500629030.5rql29567p5" style="width:416px">
<tbody>
<tr>
<td valign="top" style="width:100%;font-family:Georgia;font-size:12pt"><b>Michaela Nakayama Shapiro </b><span style="font-size:9pt">(she/her/hers)</span></td>
</tr>
<tr>
<td valign="top" style="width:100%;font-family:Georgia;font-size:9pt">Programme Officer - Censorship</td>
</tr>
<tr>
<td valign="top" style="width:100%">
<table id="m_10152671249500629030.gs1591r0dmr" style="width:100%">
<tbody>
<tr valign="center">
<td style="width:109px"><a href="https://www.article19.org" target="_blank"><img src="cid:ii_197172b51df1e8f307d1" border="0" width="109" height="56" id="m_10152671249500629030.19x5svj14de" alt="Logo.png" style="width: 109px; height: 56px;"></a></td>
<td colspan="3" style="width:297px;font-family:Georgia;font-size:10pt">Defending freedom of expression<br>
and information</td>
</tr>
<tr>
<td colspan="4" valign="top" style="width:100%;height:10px"></td>
</tr>
<tr>
<td valign="center" style="font-family:Georgia;font-size:8pt">
<a href="https://www.article19.org" title="" style="text-decoration:none;color:rgb(0,0,0)" target="_blank"><b>www.article19.org</b></a></td>
<td valign="center" style="width:10px"></td>
<td valign="center" style="width:160px;border-left:2px solid rgb(0,0,0);padding-left:15px;font-family:Georgia;font-size:8pt;text-align:left">
<a href="https://www.article19.org/ie-sign-up/" title="" style="text-decoration:none" target="_blank"><span style="color:rgb(0,0,0)">Subscribe to our Newsletter</span></a><span style="color:rgb(0,0,0)"> </span></td>
<td style="width:132px"><a href="https://www.article19.org/ie-sign-up" target="_blank"><img src="cid:ii_197172b51e0aecb87322" width="19" height="20" style="width: 19px; height: 20px;"></a>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td valign="top" style="width:416px;font-family:Georgia;font-size:10pt">
<table id="m_10152671249500629030.9lo3zx5bj9e" style="width:416px">
<tbody>
<tr>
<td colspan="3" valign="top" style="border-top:2px solid rgb(0,0,0);width:100%;height:10px">
</td>
</tr>
<tr>
<td valign="top" style="width:416px;font-family:Georgia;font-size:8pt">Follow us</td>
</tr>
<tr>
<td valign="top" style="width:416px">
<table id="m_10152671249500629030.4oofbpvnzcq" style="width:100%">
<tbody>
<tr>
<td valign="center" style="width:25px;height:25px"><a href="https://bsky.app/profile/article19.bsky.social" target="_blank"><img src="cid:ii_197172b51e0b3a0372b3" border="0" id="m_10152671249500629030.s1zabge7uum" alt="Bluesky1x.png"></a></td>
<td valign="top" style="width:15px"></td>
<td valign="center" style="width:25px;height:25px"><a href="https://www.facebook.com/article19org/" target="_blank"><img src="cid:ii_197172b51e0da82e1e64"></a></td>
<td valign="top" style="width:15px"></td>
<td valign="center" style="width:25px;height:25px"><a href="https://www.youtube.com/channel/UCDB6E_x0xRSfF62b872n9YQ" target="_blank"><img src="cid:ii_197172b51e09d64e4b15"></a></td>
<td valign="top" style="width:15px"></td>
<td valign="center" style="width:25px;height:25px"><a href="https://www.linkedin.com/company/article19" target="_blank"><img src="cid:ii_197172b51e01fa7dc5a6"></a></td>
<td valign="top" style="width:15px"></td>
<td valign="center" style="width:25px;height:25px"><a href="https://www.instagram.com/article19org/" target="_blank"><img src="cid:ii_197172b51e0a7ee2f077"></a></td>
<td valign="top" style="width:15px"></td>
<td valign="center" style="width:25px;height:25px"><a href="https://twitter.com/intent/follow?screen_name=article19org" target="_blank"><img src="cid:ii_197172b51e08eec89cf8"></a></td>
<td></td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td valign="top" style="width:416px"><a href="https://www.article19.org/equally-safe/?mtm_campaign=Clicks%20on%20email%20signature%20banner" target="_blank"><img src="cid:ii_197172b51e0988756aa9" border="0" width="416" height="102" id="m_10152671249500629030.a402r8opzz" alt="women-journalists-banner.jpeg" style="width: 416px; height: 102px;"></a></td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td valign="top" style="width:416px;font-family:Georgia;font-size:8pt"></td>
</tr>
</tbody>
</table>
</div>
<div id="m_1015267124950062903mail-editor-reference-message-container">
<div>
<div>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(181,196,223);padding:3pt 0in 0in">
<p class="MsoNormal" style="margin-bottom:12pt"><b><span style="font-size:12pt;color:black">From:
</span></b><span style="font-size:12pt;color:black">NCSG-Discuss <<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU" target="_blank">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>> on behalf of Tomslin Samme-Nlar <<a href="mailto:mesumbeslin@GMAIL.COM" target="_blank">mesumbeslin@GMAIL.COM</a>><br>
<b>Date: </b>Wednesday, 28 May 2025 at 03:35<br>
<b>To: </b><a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU" target="_blank">NCSG-DISCUSS@LISTSERV.SYR.EDU</a> <<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU" target="_blank">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>><br>
<b>Subject: </b>Re: [Important/Question and note] Note on Accreditation and Requestor Validation in the Registration Data Request Service (RDRS)<u></u><u></u></span></p>
</div>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:12pt">Hi Farzi, all,<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12pt">I hope everyone is well.<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12pt">You asked: <i>what should we decide? Should we insist on full accreditation of non LEAs or should we settle on having some lightweight authentication and ask ICANN and registrars to report on the requests. </i><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12pt">I think it depends on which problem we are trying to solve.<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><b><span style="font-size:12pt">Problem: Time it takes for registrars to respond to request</span></b><span style="font-size:12pt">s - Here I think adequate authentication is required. B3cause even if disclosure is denied, response
of that decision will be quicker. Whether it can be lightweight, well, I believe will depend on the technical story of how it will be done. <u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><b><span style="font-size:12pt">Problem: Balancing authentication & disclosure</span></b><span style="font-size:12pt"> - Here I think policy should be clear that
<i><u>authenticated</u></i> doesn't mean auto-disclosure.<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12pt">Remain blessed, <br>
Tomslin<u></u><u></u></span></p>
</div>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size:12pt">On Sun, 25 May 2025, 09:58 farzaneh badii, <</span><a href="mailto:farzaneh.badii@gmail.com" target="_blank"><span style="font-size:12pt">farzaneh.badii@gmail.com</span></a><span style="font-size:12pt">> wrote:<u></u><u></u></span></p>
</div>
<blockquote style="border-top:none;border-right:none;border-bottom:none;border-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin:5pt 0in 5pt 4.8pt">
<div>
<div>
<p><span style="font-family:Arial,sans-serif">As you know I am your rep on RDRS SC, which is the triage system for sending the disclosure of domain name registrants data to the registrar. It's a pilot project. </span></p>
<p><span class="m_1015267124950062903gmaildefault"><span style="font-family:Arial,sans-serif">We are providing our report and based on the result of the experiment we are providing the recommendations for consideration of SSAD(the disclosure policy that was adopted in the past). </span></span></p>
<p><span class="m_1015267124950062903gmaildefault"><span style="font-family:Arial,sans-serif">For NCSG a few things matter: privacy of the domain name registrants, accountability and transparency of the system, the requesters and the registrars.</span></span></p>
<p><span class="m_1015267124950062903gmaildefault"><span style="font-family:Arial,sans-serif">One of the issues that we are discussing is accreditation of non LEAs. See the brief below, and my question is: what should we decide? Should we insist on full accreditation of non LEAs
or should we settle on having some lightweight authentication and ask ICANN and registrars to report on the requests. I lay out the pros and cons of the approaches below.</span></span></p>
<p><strong><span style="font-family:Aptos,sans-serif">Background:</span></strong><br>
As part of the ongoing evaluation of the Registration Data Request Service (RDRS), several concerns have emerged regarding requestor validation and accreditation, particularly in relation to non-law enforcement third parties.</p>
<p><strong><span style="font-family:Aptos,sans-serif">EPDP Phase 2 Context:</span></strong><br>
The EPDP Phase 2 Final Report recommended the creation or designation of an <strong>
<span style="font-family:Aptos,sans-serif">Accreditation Authority</span></strong> as a critical component of any long-term solution for lawful disclosure of domain registration data. This recommendation has significant implications for the <span class="m_1015267124950062903gmaildefault"><span style="font-family:Arial,sans-serif">
disclosure system</span></span></p>
<p><strong><span style="font-family:Aptos,sans-serif">S</span></strong><span class="m_1015267124950062903gmaildefault"><b><span style="font-family:Arial,sans-serif">ome observations</span></b></span></p>
<p><span class="m_1015267124950062903gmaildefault"><b><span style="font-family:Arial,sans-serif">Why LEA authentication is needed:</span></b></span></p>
<ol start="1" type="1">
<li class="MsoNormal">
<strong><span style="font-size:12pt;font-family:Aptos,sans-serif">Misclassification of Requests:</span></strong><span style="font-size:12pt"><br>
RDRS experience indicates that a number of data disclosure requests were improperly categorized as originating from law enforcement authorities, raising concerns about the accuracy and integrity of requestor self-identification.<u></u><u></u></span></li><li class="MsoNormal">
<b><span style="font-size:12pt">Lack of Requestor Validation:</span></b><span style="font-size:12pt"><br>
The absence of an accreditation or identity validation mechanism may have contributed to delayed responses from registrars, who are unable to confidently assess the requestor’s legal standing and purpose.<u></u><u></u></span></li><li class="MsoNormal">
<strong><span style="font-size:12pt;font-family:Aptos,sans-serif">Authentication vs. Disclosure Balancing:</span></strong><span style="font-size:12pt"><br>
N</span><span class="m_1015267124950062903gmaildefault"><span style="font-size:12pt;font-family:Arial,sans-serif">ote </span></span><span style="font-size:12pt">that authentication </span><span class="m_1015267124950062903gmaildefault"><span style="font-size:12pt;font-family:Arial,sans-serif">is</span></span><span style="font-size:12pt">
not inherently difficult. The core challenge lies in balancing a validated requestor’s documented purpose against the registrant’s right to privacy, particularly in borderline or ambiguous cases.<u></u><u></u></span></li></ol>
<div>
<div>
<p class="MsoNormal"><b><span style="font-size:12pt;font-family:Arial,sans-serif">Non LEAs</span></b><span style="font-size:12pt;font-family:Arial,sans-serif"><u></u><u></u></span></p>
</div>
<p class="MsoNormal"><span style="font-size:12pt"><u></u> <u></u></span></p>
</div>
<ol start="1" type="1">
<li class="MsoNormal">
<strong><span style="font-size:12pt;font-family:Aptos,sans-serif">Risk of Abuse by Authenticated Non-LEAs:</span></strong><span style="font-size:12pt"><br>
W</span><span class="m_1015267124950062903gmaildefault"><span style="font-size:12pt;font-family:Arial,sans-serif">e have concerns </span></span><span style="font-size:12pt">about the
<strong><span style="font-family:Aptos,sans-serif">potential for misuse of access</span></strong> by authenticated third-party requestors, especially those operating in jurisdictions with weak human rights protections. Authentication alone does not safeguard
against disproportionate or abusive requests.<u></u><u></u></span></li></ol>
<p><strong><span style="font-family:Aptos,sans-serif">Recommendations for Follow-up System Design:</span></strong></p>
<ul type="disc">
<li class="MsoNormal">
<strong><span style="font-size:12pt;font-family:Aptos,sans-serif">Initial Focus on Law Enforcement :</span></strong><span style="font-size:12pt"><br>
I</span><span class="m_1015267124950062903gmaildefault"><span style="font-size:12pt;font-family:Arial,sans-serif"> think we should</span></span><span style="font-size:12pt"> generally agree that future iterations or alternatives to RDRS should prioritize
<strong><span style="font-family:Aptos,sans-serif">a</span></strong></span><span class="m_1015267124950062903gmaildefault"><b><span style="font-size:12pt;font-family:Arial,sans-serif">uthentication</span></b></span><strong><span style="font-size:12pt;font-family:Aptos,sans-serif">
of law enforcement requestors</span></strong><span style="font-size:12pt"> as a first step, both to build trust and to test implementation.<u></u><u></u></span></li><li class="MsoNormal">
<b><span style="font-size:12pt">Need for Further Policy </span></b><span class="m_1015267124950062903gmaildefault"><b><span style="font-size:12pt;font-family:Arial,sans-serif">refinement:
</span></b></span><span class="m_1015267124950062903gmaildefault"><span style="font-size:12pt;font-family:Arial,sans-serif">Discuss how to refine accreditation for third party non LEAs so that we bring transparency and accountability but also not be entangled in a "trusted
flagger" system where accreditation could lead to positive answers from the registrars without any balance of fundamental rights and disclosure. </span></span><span style="font-size:12pt"><u></u><u></u></span></li></ul>
</div>
<div>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:12pt;font-family:Verdana,sans-serif">Farzaneh </span><span style="font-size:12pt"><u></u><u></u></span></p>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></blockquote></div>