HRIA guidelines for DNS abuse mitigation
Niels ten Oever
lists at DIGITALDISSIDENTS.ORG
Thu Mar 13 07:34:27 EET 2025
And there is even an updated one I see!
https://www.article19.org/wp-content/uploads/2020/07/Human-Rights-Impact-Scoping-Model-Internet-Registries-January-2020.pdf
On 13-03-2025 13:33, Niels ten Oever wrote:
> Hi all,
>
> You are all probably very aware of this, but initially we created this sheet for doing such an analysis - not sure people still have it at the front of their minds. Hope it might be helpful.
>
> https://www.article19.org/wp-content/uploads/2017/12/Sample-ccTLD-HRIA-Dec-2017.pdf
>
> Best,
>
> Niels
>
> On 10-03-2025 17:15, Michaela Nakayama Shapiro wrote:
>> INTERNAL
>>
>>
>> INTERNAL
>>
>>
>> Hi Tapani,
>>
>> Thank you for your feedback on the session! I’m really glad to hear it went well (it can be hard to gauge when participating remotely!).
>>
>> On your suggestion, I completely agree that a resource with that kind of information (what each actor can vs cannot in the process of DNS abuse mitigation) would be helpful. This is something that @farzaneh badii <mailto:farzaneh.badii at gmail.com> and I can certainly think about developing as we work with registrars to finalize the set of guidelines/principles for DNS abuse mitigation.
>>
>> This is something we could either integrate into the guidelines themselves or as a separate accompanying doc laying out the pathways for DNS abuse mitigation, which would show in what situations and at what stage of the DNS abuse mitigation the registrar should reach out to another actor (for example, if in the investigation phase it’s determined that the abuse is at the level of the hosting provider rather than at the domain level, the registrar should then contact them to address the issue).
>>
>> Best,
>>
>> Michaela
>>
>> *Michaela Nakayama Shapiro *(she/her/hers)
>> Programme Officer - Censorship
>> Logo.png <https://www.article19.org> Defending freedom of expression
>> and information
>> *www.article19.org* <https://www.article19.org> Subscribe to our Newsletter <https://www.article19.org/ie-sign-up/> <https://www.article19.org/ie-sign-up>
>>
>> Follow us
>> Bluesky1x.png <https://bsky.app/profile/article19.bsky.social> <https://www.facebook.com/article19org/> <https://www.youtube.com/channel/UCDB6E_x0xRSfF62b872n9YQ> <https://www.linkedin.com/company/article19> <https://www.instagram.com/article19org/> <https://twitter.com/intent/follow?screen_name=article19org>
>>
>> women-journalists-banner.jpeg <https://www.article19.org/equally-safe/?mtm_campaign=Clicks%20on%20email%20signature%20banner>
>>
>> *From: *NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> on behalf of Tapani Tarvainen <ncsg at TAPANI.TARVAINEN.INFO>
>> *Date: *Monday, 10 March 2025 at 15:41
>> *To: *NCSG-DISCUSS at LISTSERV.SYR.EDU <NCSG-DISCUSS at LISTSERV.SYR.EDU>
>> *Subject: *HRIA guidelines for DNS abuse mitigation
>>
>> [You don't often get email from ncsg at tapani.tarvainen.info. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification <https://aka.ms/LearnAboutSenderIdentification> ]
>>
>> Dear all,
>>
>> On the session on developing human rights impact assessment guidelines
>> for DNS abuse mitigation Farzaneh had us do a little exercise in
>> hypothetical scenarios. It went very well, especially given how little
>> time there was, with some very illuminating ideas - like, demanding a
>> quick response from the registrant can be a problem if the registrant
>> is in jail - and if we keep pushing we could well come up with
>> actually useful guidelines.
>>
>> One thing I wanted to highlight is our discussion about what the
>> registrar can do directly and where they'd have to reach out to the
>> hosting provider or dns provider. The latter we didn't actually
>> discuss much, it was only mentioned in passing, most people perhaps
>> thinking that dns provider is usually same as registrar. That is
>> indeed often the case (some registrars even insist on it) but not
>> always (some registrars don't even offer it as a service, notably
>> including ISNIC where ncsg.is is registered).
>>
>> Perhaps it would be a good exercise to make a list of what things each
>> actor - registrar, dns provider, hosting provider - can and can't do.
>>
>> --
>> Tapani Tarvainen
>>
>
--
Niels ten Oever, PhD
Co-Principal Investigator - critical infrastructure lab - University of Amsterdam
Assistant Professor - Department of European Studies - University of Amsterdam
W: https://criticalinfralab.net
W: https://nielstenoever.net
PGP: 4254 ECD5 D4CF F6AF 8B91 0D9F EFAD 2E49 CC90 C10C
More information about the Ncsg-discuss
mailing list