Question on Bullet Proof Hosting
Kris Seeburn
seeburn.k at GMAIL.COM
Fri Aug 3 11:01:18 EEST 2018
> Actually.. you got it right. I agree that ICANN should not conflate realistically but can surely ensure the Registrars do so within the scope of GDPR as well. I found a lot of leaked personal information and hacked information which are readily available for a dollar available for the grabs. These are in fact not limited to companies but all sorts of personal information you may want. Hackers or let’s put it some people with the intentions to create havoc use the bullet proof hosting to get the data from anywhere and dump them on the hosting servers and mainly actually those who are hidden either by proxy services etc.,
>
> They are registered as normal activities within the Whois and ICANN has those details. When law enforcement comes in to get more details of the registrar they are brushed away and continue to exist by just changing IP allocation and that it is the Hosting provider registered with it’s registry or registrar who protect same. Incidentally, these are within the whois both from a domain registration perspective and IP space perspective. As much as it comes to GDPR, when it comes to PII we are merely talking of Individuals to be protected and not the organisation. So finding those details and the added need for law enforcement on the matter becomes important.
>
> And yes wholeheartedly should have a policy in that line to address and also protect the Individuals. Whilst it is not an issue with proxy or paying an extra to not reveal an Individual most of these registrants are companies. So on this end a policy is important. So much as SPAM and other issues exist within. That grey area needs to be taken up. More if you look at the last reports on spam etc., one grey area is still the bullet proof hosting which of course is also domains which hops IP as well for pedophiliia and so much societal damaging effects.
>
> So, yes… all of these people need a policy to address the issue and also the protection required within GDPR to do just that. Last but not the least it is also important to remind ICANN that they are within the bounds of the California new laws which will take effect in 2020 which is focused the same way as GDPR when it comes to PII. So they should start working also to align. They like it or not it will eventually fall.
>
> ICANN plays the role of a data processor like it or not but in situations they are also data controller. The main whois and DNS are within the bounds of ICANN, if they were not related they would not request Registrars and Registries to update Domains if they were not interested to doing same.
>
> The core of the main dark internet issue is hosted within Bullet Proof services and am very partisan to address the issue with a Policy that covers the individuals and not the organisations at large so it is a one shot that we need and definitely need to address as we move else we will never do so. Most techies also know that more than 90% is within the dark web and which have a legitimacy as well. So a proper policy to address this within bounds would be good thing.
>
> My two cents.
> On Aug 3, 2018, at 19:15, Amr Elsadr <aelsadr at icannpolicy.ninja <mailto:aelsadr at icannpolicy.ninja>> wrote:
>
> Hi Kris,
>
> [Changing the Subject for this thread]
>
> The scope of this EPDP is very narrow (as the scope of EPDPs are meant to be), and it basically covers whether the GNSO would like to adopt or make changes to the temporary specification on gTLD registration data <https://www.icann.org/resources/pages/gtld-registration-data-specs-en/> drafted by staff and adopted by the ICANN Board. The question of hosting is not within ICANN’s mission, and surely not within the scope of this EPDP.
>
> However, if you’re suggesting that the successor of the temporary specification should include some sort of policy that uses gTLD domain name registration data to address this issue, and particularly taking into consideration the applicability of the EU’s GDPR, please clarify this.
>
> Personally, I do not believe that gTLD registration data should be used for this purpose. More importantly, I don't think the GDPR allows third-party access to this data for that purpose, but I’m not an authority on this. My main reasoning for this is that I don’t believe that solving the problem you have referred to is within the scope of ICANN’s mission. ICANN is not a global enforcement body for all things evil on the Internet. Some of the articles in the GDPR (as well as input on them from EU data protection experts in the past) have suggested that ICANN should not conflate the interests of third-party special interests with its own mission. The nuances of this are meant to be addressed by this EPDP.
>
> For the purpose of this EPDP, I suggest that the NCSG adopt a position that protects the fundamental right of privacy for gTLD domain name registrants…, at least to the extent that this right is protected under applicable law.
>
> Thanks.
>
> Amr
>
>> On Aug 3, 2018, at 4:49 PM, Kris Seeburn <seeburn.k at gmail.com <mailto:seeburn.k at gmail.com>> wrote:
>>
>> Amr
>>
>> What do you make of the “Bullet Proof Hosting”.They cause spams, hacks, ransomware and so much more in a safe and unprecedented way. These are creating more problems than anything else. Whilst these eat up not only protected and no laws apply to them. These hosts also the underground web as well as eating up loads of IP space as well. It is both a problem and issue which also needs to be tackled in a very subtle way but needs to be taken care of. We cannot escape this issue and we need to ascertain some level of assurance for the civil society.
>>
>> This is taking more and more space and creating problems that we need to tackle and we seem to get away from it and do not even want to accept that this issue is very real to all. We definitely need a way to control this either via the Registrar or Registry but also from ICANN perspective there is a need to ascertain legitimacy. These go both domain wise and IP wise.
>>
>>> On Aug 3, 2018, at 18:40, Amr Elsadr <aelsadr at ICANNPOLICY.NINJA <mailto:aelsadr at ICANNPOLICY.NINJA>> wrote:
>>>
>>> Hi,
>>>
>>> The first GNSO EPDP on Temporary Specification for gTLD Registration Data took place on Wednesday, 1 August 2018. The notes, action items and recordings for this call can be found on the meeting’s wiki page here: https://community.icann.org/x/ugBpBQ <https://community.icann.org/x/ugBpBQ>
>>>
>>> As per action item 5 (which I believe should be action item 6), the NCSG appointed members and alternates are considering our responses to the first part of a 4-part survey. The first part of the survey is due on Monday, 6 August 2018 at 19:00 UTC. This deadline is in a few days, as the responses provided by the different GNSO SGs/Cs, as well as the different ICANN SOs/ACs participating in the EPDP will be reviewed during the next EPDP Team call on Tuesday, 7 August 2018.
>>>
>>> We’ve created a google doc to collaborate on the responses we submit. You can find this google doc here: https://docs.google.com/document/d/1GcE0Q_Fq8rXF8_Dt_bcNDdp5-1uKwcRRJjKmQbnkvoQ/edit?usp=sharing <https://docs.google.com/document/d/1GcE0Q_Fq8rXF8_Dt_bcNDdp5-1uKwcRRJjKmQbnkvoQ/edit?usp=sharing>
>>>
>>> Permission rights for the google doc only allow NCSG-appointed members and alternates of the EPDP Team to comment and edit the document, but anyone with the link can view it. So if anyone within the broader NCSG membership has comments or input, please start a new thread to share and discuss those here on NCSG-DISCUSS.
>>>
>>> For those who don’t have access to google services, staff have exported the survey questions to a MS Word document, which is attached to this email. You won’t be able to view any edits or comments made on the google doc, but this is the best we could right now (apologies for that).
>>>
>>> If you have any additional questions for your representatives on the EPDP Team, please don’t hesitate to ask.
>>>
>>> Thanks.
>>>
>>> Amr
>>>
>>> <Part 1 EPDP Survey MS Word.docx>
>>
>>
>>
>>
>>
>>
>>
>> Kris Seeburn
>> seeburn.k at gmail.com <mailto:seeburn.k at gmail.com>
>> LinkedIn: linkedin.com/in/kseeburn/ <http://www.linkedin.com/in/kseeburn/>
>>
>> "Life is a Beach, it all depends at how you look at it"
>>
>> <KeepItOn_Social_animated.gif>
>>
>
Kris Seeburn
seeburn.k at gmail.com <mailto:seeburn.k at gmail.com>
LinkedIn: linkedin.com/in/kseeburn/ <http://www.linkedin.com/in/kseeburn/>
"Life is a Beach, it all depends at how you look at it"
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180803/2e70b9b7/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: KeepItOn_Social_animated.gif
Type: image/gif
Size: 51490 bytes
Desc: not available
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180803/2e70b9b7/attachment.gif>
More information about the Ncsg-discuss
mailing list