Whois/privacy and the SSAD

Mueller, Milton L milton at GATECH.EDU
Wed Jan 5 10:45:48 EET 2022


Thanks, Farzaneh
A bit surprised that yours is the only comment but perhaps it's the holidays and the rest of the SG will wake up.

Regarding your first comment, we cannot have a precise estimate of the cost because cost depends on usage and usage depends on how costly it is to use and what the alternatives are, which we won't know for sure until it is implemented.

The risk of re-litigating issues is real, but I think ICANN and various SGs have made it clear that the final disclosure decision has to be made by the contracted parties. So you are right, the SSAD is basically a triage of requests + accreditation.

I agree with you that the whole issue of accrediting governments (and major users such as brand protection and so-called cybersecurity researchers) is concerning and problematic. That is why I would like to find a way to dump accreditation altogether and slim down the SSAD into nothing more than a centralized request system. I am afraid that accreditation will confer some kind of de facto expectation or right to disclosure, and to mass, automated requests. Especially for governments.

I know that some privacy advocates believe that accreditation is going to be protective rather than enabling. I think this is an incorrect view and needs to be more realistic about what will happen if ICANN creates a globalized accreditation and access system.

If we (you, me, NCSG) can agree on that, we can then discuss what next steps would help us get to that goal (the goal being a slimmed down SSAD basically a centralized intake system for requests).

--MM
________________________________
From: farzaneh badii <farzaneh.badii at gmail.com>
Sent: Tuesday, January 4, 2022 4:49 PM
To: Mueller, Milton L <milton at gatech.edu>
Cc: NCSG List <NCSG-DISCUSS at listserv.syr.edu>
Subject: Re: Whois/privacy and the SSAD

Hi Milton,

I looked at the cost report of this and they really don't have enough information and data to actually estimate the cost. Obviously the Intellectual property crowd claims they submit "many" requests but others say otherwise.  I am more inclined to see if they can pilot an implementation and see what sort of problems they face (as laid out in the note you sent). Opening another EPDP or getting back to council and EPDP is going to risk re-litigating issues for sure. If we have to take one of those paths, I go with number 1 (reluctantly, because I don't know how the Board is going to articulate the reasons)

Isn't this system just a "triage" of request and an accreditation model? That the final decision is by the registries and registrars? I hear a lot of people thinking this is "disclosure" mechanism, which adds to the complexity.

There are many unknown issues about the implementation of SSAD. Even the governments don't want to accredit their own law enforcement themselves (as mentioned in a letter from the GAC chair, they just want to verify identity). https://gnso.icann.org/sites/default/files/file/field-file-attach/ismail-to-fouquart-15dec21-en.pdf

And anyhow that recommendation that governments each get to accredit their own law enforcement is unfortunately a terrible idea. And what will happen to sanctioned countries that are usually authoritarian and have law enforcement to suppress opposition? will they get access to personal information of people while people suffer from sanctions? Or perhaps the contracted parties deny them access. (I raised the issue at an NCSG meeting last year,implicitly, but I guess the ship has sailed)


Best regards,


Farzaneh


On Tue, Jan 4, 2022 at 3:04 PM Mueller, Milton L <milton at gatech.edu<mailto:milton at gatech.edu>> wrote:
Greetings all and happy new year.
As one of your representatives on the EPDP dealing with Whois and privacy, I want to inform you of the latest development.

You will remember that a lot of sensitive domain name registration data is now redacted (hidden), because ICANN had to come into compliance with GDPR. The SSAD (Standardized System of Access and Disclosure) was an elaborate mechanism developed by the EPDP to allow people who want to see the hidden data to request its disclosure. The proposed SSAD had an elaborate mechanism for accrediting users of the system, including a process for each national government to accredit its own law enforcement and government agencies.

ICANN Org has done a study of the costs of the proposed SSAD and estimates that it will be very expensive and will take a long time to implement. The ICANN board has indicated that it may not approve the SSAD recommendation because of these problems.

So now we are faced with a question about what to do next.

There are basically two options being presented to us:

  1.  Let the ICANN Board formally refuse to adopt the recommendation, tell us what's wrong with it, and then let the Council and the EPDP adopt a supplemental recommendation that fixes the problems
  2.  Re-convene the EPDP and work out its own modification of the recommendation.

I've attached a more detailed analysis of the options that the ICANN staff circulated today. I have my own opinion about this - I think the SSAD does need to be simplified and agree with the staff's concerns about its complexity and cost. But I am not sure what is the best way procedurally to fix this problem. Hope we can discuss this as a SG and reach a unified position.

Cheers,


Dr Milton L Mueller, Professor

School of Public Policy

Georgia Institute of Technology

Internet Governance Project<https://internetgovernance.org>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20220105/4e9eb018/attachment.htm>


More information about the Ncsg-discuss mailing list