Whois compliance models, and the confusion of the PC

Stephanie Perrin stephanie.perrin at MAIL.UTORONTO.CA
Tue Jan 30 12:46:01 EET 2018


I  will try to answer some of your questions, with the caveat that I am 
not a lawyer :-)See responses inline.

Thanks for your thoughtful comments!

Stephanie Perrin


On 2018-01-30 00:38, Ron Wickersham wrote:
> I have a question regarding responding to court orders.  Even if we don't
> have that as the _only_ option for gaining access to the registration 
> data
> (however brief or extensive it gets decided in the end) won't the law
> enforcement, and other parties, government and intellectual property 
> lawyers still have the option to request and obtain court orders even
> if that option is not included in the ICANN policy?
Not all nation states require court orders.  One of the arguments for a 
central repository is to try to force better due process
>
> How can ICANN enforce contracts to ignore local or international court
> orders, or even force contractors to resist in any manner when presented
> with what appears to be a court order?  I can't see ICANN revoking 
> Verisign's
> contract to operate .com based solely on complying with a court order for
> a person/organization in the EU even if a court in the EU would not issue
> such an order for a European-based registrar, for instance.
good point, I agree.  see comment above
>
> My concern is that if we have the option that is proposed (and the 
> position
> is well stated and convincingly argued for) that sets up special 
> rights for
> law enforcement and other parties, then it appears to me that we also get
> the option 3 as well.   Thus we have to attempt to monitor both 
> mechanisms
> which makes it more difficult to ensure that the those individuals and
> organization that we are arguing should be protected are actually 
> protected.
Special access for law enforcement and other parties is a problem, but 
in my view it is unrealistic to try to ignore this....the goal is to 
force better processes, better accreditation and control, better 
transparency, and end user rights.  This will be difficult, but ignoring 
the problem favours less transparent work around options (see you 
previous point)
>
> Also, no matter what the mechanism, I would like to see disclosure of 
> data
> breaches disclosed immediately by registries and registrars even if local
> laws do not require public reporting of intrusions.   And if security of
> the data from intrusion is part of the contract then auditing and 
> enforcement
> of data security practices directly by ICANN should be incorporated 
> for user's protection.
the provisions in the GDPR say 72 hours. you tell me whether that is 
reasonable.  My experience is in government, and let me tell you  72 
hours would have been tight for my govt to figure out a data breach, so 
asking for a more prompt response may yield confusion and no better 
results.  Obviously in operating systems there is more urgency, but I am 
talking about static data here....
>
> If the registry or registrar contracts out proxy services, then the
> registry or registrar should be required to have that proxy service make
> themselves subject to ICANN policies through direct agreement with ICANN
> along with auditing and verification of security as well.  If the 
> registrar
> or registry goes belly-up then ICANN needs to step in immediately and see
> that the data stays protected.   This should also be required of 
> archiving/
> backup/escrow services.
check the documents in the ongoing privacy proxy accreditation 
implementation process....available here.  I must confess I have not had 
time to follow this working group as closely as I had wished, there is a 
huge volume of work going 
on....https://www.icann.org/resources/pages/ppsai-2016-08-18-en
>
> It may be just conspiracy theories, but if state actors and powerful 
> criminal
> elements can penetrate any conceivable defenses, then any ICANN 
> policies are
> really ultimately ineffective if the data is collected at all. So I agree
> that minimum data for current purposes must be part of the policy, not 
> the
> traditional WHOIS menu -- because shouldn't employees (technical and
> administrative contacts) have the same protection as the owner of the 
> domain?
This is why data minimization is key.  The ECO report does go into 
employee rights, briefly, and I agree that this is a concern.  The ECO 
report supports dropping tech contacts, and I agree.
>
> Thanks for the great work of our representatives on the policy forming
> areas of ICANN and for the informative comments on the mailing list.
>
> -ron wickersham
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180130/4c1d647f/attachment.htm>


More information about the Ncsg-discuss mailing list