Question on Bullet Proof Hosting

David Cake dave at DAVECAKE.NET
Mon Aug 6 21:01:58 EEST 2018


Issues connected to ‘bullet-proof’ hosting should not be part of the EPDP process specifically (which has very limited scope and time), but access to non-public registration data by law enforcement, etc will be an important part of access to non-public data discussion, to the extent that is within the EPDP.
Certainly all issues related to the numbers side of dealing with ‘bullet-proof’ hosting are clearly out of scope for the EPDP (and in many cases, outside of the ICANN global policy process and should be addressed within the RIRs).

I agree with Amr that the DPAs have been quite clear that access to data to address concerns of third party special interests, and I would add that just because a third party believes themselves to be a vital part of maintaining a secure internet does not make it so.

I strongly agree that within the short timeline of the EPDP, the NCSG priority should be protecting privacy, as a universal human right and as protected by laws such as the GDPR.

David



> On 3 Aug 2018, at 11:15 pm, Amr Elsadr <aelsadr at ICANNPOLICY.NINJA> wrote:
> 
> Hi Kris,
> 
> [Changing the Subject for this thread]
> 
> The scope of this EPDP is very narrow (as the scope of EPDPs are meant to be), and it basically covers whether the GNSO would like to adopt or make changes to the temporary specification on gTLD registration data <https://www.icann.org/resources/pages/gtld-registration-data-specs-en/> drafted by staff and adopted by the ICANN Board. The question of hosting is not within ICANN’s mission, and surely not within the scope of this EPDP.
> 
> However, if you’re suggesting that the successor of the temporary specification should include some sort of policy that uses gTLD domain name registration data to address this issue, and particularly taking into consideration the applicability of the EU’s GDPR, please clarify this.
> 
> Personally, I do not believe that gTLD registration data should be used for this purpose. More importantly, I don't think the GDPR allows third-party access to this data for that purpose, but I’m not an authority on this. My main reasoning for this is that I don’t believe that solving the problem you have referred to is within the scope of ICANN’s mission. ICANN is not a global enforcement body for all things evil on the Internet. Some of the articles in the GDPR (as well as input on them from EU data protection experts in the past) have suggested that ICANN should not conflate the interests of third-party special interests with its own mission. The nuances of this are meant to be addressed by this EPDP.
> 
> For the purpose of this EPDP, I suggest that the NCSG adopt a position that protects the fundamental right of privacy for gTLD domain name registrants…, at least to the extent that this right is protected under applicable law.
> 
> Thanks.
> 
> Amr
> 
>> On Aug 3, 2018, at 4:49 PM, Kris Seeburn <seeburn.k at gmail.com <mailto:seeburn.k at gmail.com>> wrote:
>> 
>> Amr
>> 
>> What do you make of the “Bullet Proof Hosting”.They cause spams, hacks, ransomware and so much more in a safe and unprecedented way. These are creating more problems than anything else. Whilst these eat up not only protected and no laws apply to them. These hosts also the underground web as well as eating up loads of IP space as well. It is both a problem and issue which also needs to be tackled in a very subtle way but needs to be taken care of. We cannot escape this issue and we need to ascertain some level of assurance for the civil society.
>> 
>> This is taking more and more space and creating problems that we need to tackle and we seem to get away from it and do not even want to accept that this issue is very real to all. We definitely need a way to control this either via the Registrar or Registry but also from ICANN perspective there is a need to ascertain legitimacy. These go both domain wise and IP wise.
>> 
>>> On Aug 3, 2018, at 18:40, Amr Elsadr <aelsadr at ICANNPOLICY.NINJA <mailto:aelsadr at ICANNPOLICY.NINJA>> wrote:
>>> 
>>> Hi,
>>> 
>>> The first GNSO EPDP on Temporary Specification for gTLD Registration Data took place on Wednesday, 1 August 2018. The notes, action items and recordings for this call can be found on the meeting’s wiki page here: https://community.icann.org/x/ugBpBQ <https://community.icann.org/x/ugBpBQ>
>>> 
>>> As per action item 5 (which I believe should be action item 6), the NCSG appointed members and alternates are considering our responses to the first part of a 4-part survey. The first part of the survey is due on Monday, 6 August 2018 at 19:00 UTC. This deadline is in a few days, as the responses provided by the different GNSO SGs/Cs, as well as the different ICANN SOs/ACs participating in the EPDP will be reviewed during the next EPDP Team call on Tuesday, 7 August 2018.
>>> 
>>> We’ve created a google doc to collaborate on the responses we submit. You can find this google doc here: https://docs.google.com/document/d/1GcE0Q_Fq8rXF8_Dt_bcNDdp5-1uKwcRRJjKmQbnkvoQ/edit?usp=sharing <https://docs.google.com/document/d/1GcE0Q_Fq8rXF8_Dt_bcNDdp5-1uKwcRRJjKmQbnkvoQ/edit?usp=sharing>
>>> 
>>> Permission rights for the google doc only allow NCSG-appointed members and alternates of the EPDP Team to comment and edit the document, but anyone with the link can view it. So if anyone within the broader NCSG membership has comments or input, please start a new thread to share and discuss those here on NCSG-DISCUSS.
>>> 
>>> For those who don’t have access to google services, staff have exported the survey questions to a MS Word document, which is attached to this email. You won’t be able to view any edits or comments made on the google doc, but this is the best we could right now (apologies for that).
>>> 
>>> If you have any additional questions for your representatives on the EPDP Team, please don’t hesitate to ask.
>>> 
>>> Thanks.
>>> 
>>> Amr
>>> 
>>> <Part 1 EPDP Survey MS Word.docx>
>> 
>> 
>> 
>> 
>> 
>> 
>> 
>> Kris Seeburn
>> seeburn.k at gmail.com <mailto:seeburn.k at gmail.com>
>> LinkedIn: linkedin.com/in/kseeburn/ <http://www.linkedin.com/in/kseeburn/>
>> 
>> "Life is a Beach, it all depends at how you look at it"
>> 
>> <KeepItOn_Social_animated.gif>
>> 
> 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180806/ccd3a9a7/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: Message signed with OpenPGP
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180806/ccd3a9a7/attachment.sig>


More information about the Ncsg-discuss mailing list