Maintaining the security, stability and resiliency of the Domain Name System/ lawful access

farzaneh badii farzaneh.badii at GMAIL.COM
Sun Nov 4 04:48:44 EET 2018


Is granting access to sensitive personal information of domain name
registrants in ICANN mission?


Among the purposes, EPDP has come up with for ICANN to process WHOIS data I
very much dislike: "Maintaining the security, stability and resiliency of
the Domain Name System in accordance with ICANN’s mission through the
enabling of lawful access for legitimate third-party interests to data
elements collected for other purposes identified herein"

This purpose conflates security, stability and resiliency (SSR) with
enabling of lawful access for legitimate wrong interests to achieve their
other purposes. I have said it many times before there are so many issues
here:

1. SSR is not maintained through providing access to the legitimate third
party to use UDRP or enforce their intellectual property. Putting the term
here can be interpreted as such.

2. The term  "In accordance with ICANN mission" was added to make it better
because some argue that "access" is in ICANN mission, therefore, we can
have this as a purpose and it's narrow. This suggestion came from Board
liaison to EPDP. Well, I totally disagree. Granting access to domain name
registrants data is not in ICANN mission. It is true that Annex G1 of the
bylaws says:

"maintenance of and access to accurate and up-to-date information
> concerning registered names and name servers;"[1]


But one needs to read the paragraph in conjunction with the main Mission
clause that says: "[ICANN]*coordinates the development and implementation
of policies *concerning the registration of second-level domain names in
generic top-level domains ("gTLDs"). In this role, *ICANN's scope is to
coordinate the development and implementation of policies."*


Obviously, ICANN's mission is not to "grant" access to personal data of
domain name registrants.ICANN's mission is* to coordinate the development
and implementation of policies that maintain access to WHOIS*. All my
worries were that this was going to lead to ICANN becoming the organization
that actually grants access. And my fear might not be baseless since ICANN
clearly has the intention and Contracted Party obviously asked ICANN to
explore its options. And bloating up SSR ... not a good idea

Anyhow, I hope these thoughts are useful
















****
[1] section 1.1. MISSION
(a) The mission of the Internet Corporation for Assigned Names and Numbers
("ICANN") is to ensure the stable and secure operation of the Internet's
unique identifier systems as described in this Section 1.1(a) (the
"Mission"). Specifically, ICANN: [....] (i) Coordinates the allocation and
assignment of names in the root zone of the Domain Name System ("DNS") and
coordinates the development and implementation of policies concerning the
registration of second-level domain names in generic top-level domains
("gTLDs"). In this role, ICANN's scope is to coordinate the development and
implementation of policies: For which uniform or coordinated resolution is
reasonably necessary to facilitate the openness, interoperability,
resilience, security and/or stability of the DNS including, with
respect to gTLD
registrars and registries, policies in the areas described in Annex G-1 and
Annex G-2;


Farzaneh
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20181104/d9797067/attachment.htm>


More information about the Ncsg-discuss mailing list