[Ncsg-discuss] Important Law Enforcement Agencies, Authentication, Accountability and Safeguards
Johan Helsingius
00001963cc94b85a-dmarc-request at LISTSERV.SYR.EDU
Tue Dec 2 11:49:57 EET 2025
I agree with sending this ASAP.
Julf
On 01/12/2025 5:16 pm, farzaneh badii wrote:
> Hi everyone,
>
> There is support for this letter and I haven't seen an objection. I am
> going to ask our NCSG chair, Rafik Dammak to send it off as soon as he can.
>
> Best regards,
>
> Farzaneh
>
>
> On Sun, Nov 30, 2025 at 1:34 AM farzaneh badii <farzaneh.badii at gmail.com
> <mailto:farzaneh.badii at gmail.com>> wrote:
>
> Hi all,
>
> Thanks a lot.
>
> Ken I think that would be useful. I have added it. (see below)
>
> Gopal, I am not sure about adding this point to the current letter
> but we can have a conversation about it.
>
> I will ask Rafik to send the letter on Monday.
>
> Here are the two paragraphs based on Ken's suggestions.
>
> "NCSG respectfully requests that the Board revise its explanatory
> text to reflect the full policy implications of law-enforcement
> authentication. In particular, the text should acknowledge that
> authentication must be accompanied by safeguards, transparency,
> accountability, and meaningful consideration of registrant and end-
> user rights, and that this is not merely an operational matter.
>
> We also urge the Board to recognise explicitly that registrants and
> end users are central stakeholders affected by these decisions, and
> to reflect this in its assessment of community impact. NCSG stands
> ready to support the Board in developing a rights-respecting and
> accountable framework for law-enforcement authentication."
>
>
> Farzaneh
>
>
> On Wed, Nov 26, 2025 at 6:49 PM gopal <gopal at annauniv.edu
> <mailto:gopal at annauniv.edu>> wrote:
>
> Thank you Farzaneh.
>
> How does this take into account GDPR Right to Erasure / to be
> Forgotten" @ https://gdpr.eu/right-to-be-forgotten/
> #:~:text=In%20Article%2017%2C%20the%20GDPR,that%20individual%20withdraws%20their%20consent. <https://gdpr.eu/right-to-be-forgotten/#:~:text=In%20Article%2017%2C%20the%20GDPR,that%20individual%20withdraws%20their%20consent.>
>
> Gopal T V
> 0 9840121302
> https://vidwan.inflibnet.ac.in/profile/57545 <https://
> vidwan.inflibnet.ac.in/profile/57545>
> https://www.facebook.com/gopal.tadepalli <https://
> www.facebook.com/gopal.tadepalli>
> ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
> Dr. T V Gopal
> Retired Professor
> Department of Computer Science and Engineering &
> Retired Director, Centre for Applied Research in Indic
> Technologies [CARIT]
> College of Engineering, Guindy Campus
> Anna University
> Chennai - 600 025, INDIA
> Ph : (Off) 22351723 Extn. 3340
> (Res) 24454753
> ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
> ------------------------------------------------------------------------
> *From:* NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU
> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>> on behalf of farzaneh
> badii <farzaneh.badii at GMAIL.COM <mailto:farzaneh.badii at GMAIL.COM>>
> *Sent:* 23 November 2025 22:33
> *To:* NCSG-DISCUSS at LISTSERV.SYR.EDU <mailto:NCSG-
> DISCUSS at LISTSERV.SYR.EDU> <NCSG-DISCUSS at LISTSERV.SYR.EDU
> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>>
> *Subject:* Important Law Enforcement Agencies, Authentication,
> Accountability and Safeguards
>
> Dear all,
>
> I want to provide an update on where things currently stand
> regarding law-enforcement (LEA) authentication, the work of the
> practitioner group, and the implications of the ICANN Board’s
> October 2025 resolution.
>
> Given recent developments, I believe NCSG should consider a
> coordinated response. Several months ago, when PSWG(public
> Safety Working Group) Gabriel briefed us on their intention to
> work with ICANN Org to validate LEA domain names, NCSG agreed
> that LEA could submit domain namesof Law Enforcement Agencies to
> the RDRS, but only if specific safeguards and conditions were met.
>
> We conveyed these conditions clearly at the time, yet we have
> not received any indication that these concerns are being
> incorporated intoPSWG's planning. To remind everyone of what
> NCSG agreed to:1) a verified LEA domain can serve only as a
> supplementary signal and not as a standalone authentication
> mechanism. 2) Disclosure decisions must still be grounded in
> rights-balancing, necessity, and a clear legal basis. 3) We
> stressed that domain validation does not prove identity;
> spoofing remains a serious risk, and both registrars and ICANN
> must be equipped to handle that. 4) We also emphasized that any
> “verified LEA domain list” must include renewal, periodic
> review, and removal processes to prevent stale or misused
> entries—especially for agencies that operate multiple domains.
> In addition, we were explicit that domain-based checks can only
> be a temporary measure while a more robust, accountable
> authentication system is being developed.5) We recommended a
> six-month review period to evaluate registrar confidence,
> safeguard effectiveness, and progress toward a long-term solution.
>
> Importantly, we made clear that any authentication mechanism
> must incorporate safeguards, transparency, oversight, and
> avenues for redress for registrants whose data may be accessed.
>
> The Board’s October 2025 resolution intersects <https://
> www.icann.org/en/board-activities-and-meetings/materials/
> approved-resolutions-regular-meeting-of-the-icann-
> board-30-10-2025-en> with this work by encouraging expanded LEA
> authentication efforts and urging alignment of SSAD-related
> policies with disclosure mechanisms. However, the Board’s
> rationale focuses almost exclusively on RDRS continuity,
> registrar/requestor satisfaction, voluntary participation, and
> ICANN’s operational resources. What is missing is any
> acknowledgment of the safeguards, accountability requirements,
> or user-impact considerations that NCSG has raised repeatedly in
> meetings, letters, and contributions to the RDRS Standing
> Committee report. Registrants and end users—who are directly
> affected—are absent from the Board’s “community impact” framing.
>
> Given this gap between what NCSG has consistently recommended
> and what the Board has recognized, I suggest that NCSG take two
> steps.
>
> First, send a short letter to the ICANN Board reaffirming that
> we support LEA authentication only if safeguards, transparency,
> oversight, and renewal mechanisms are integral to the system,
> and noting that the resolution omits the impact on registrants
> and end users.
>
> Second, develop a concise Human Rights Impact Assessment (HRIA)
> of the Board resolution and the related RDRS/SSAD work, mapping
> risks to privacy, due process, non-discrimination, and access to
> remedy, particularly around cross-border LEA requests.
>
> I can prepare a first draft of the Board letter and a short HRIA
> scoping note for review.
>
> Best regards,
>
> Farzaneh
>
More information about the Ncsg-discuss
mailing list