[Ncsg-discuss] Important Law Enforcement Agencies, Authentication, Accountability and Safeguards
farzaneh badii
farzaneh.badii at GMAIL.COM
Sun Nov 23 19:03:58 EET 2025
Dear all,
I want to provide an update on where things currently stand regarding
law-enforcement (LEA) authentication, the work of the practitioner group,
and the implications of the ICANN Board’s October 2025 resolution.
Given recent developments, I believe NCSG should consider a coordinated
response. Several months ago, when PSWG (public Safety Working Group) Gabriel
briefed us on their intention to work with ICANN Org to validate LEA domain
names, NCSG agreed that LEA could submit domain names of Law Enforcement
Agencies to the RDRS, but only if specific safeguards and conditions were
met.
We conveyed these conditions clearly at the time, yet we have not received
any indication that these concerns are being incorporated into PSWG's
planning. To remind everyone of what NCSG agreed to:1) a verified LEA
domain can serve only as a supplementary signal and not as a standalone
authentication mechanism. 2) Disclosure decisions must still be grounded in
rights-balancing, necessity, and a clear legal basis. 3) We stressed that
domain validation does not prove identity; spoofing remains a serious risk,
and both registrars and ICANN must be equipped to handle that. 4) We also
emphasized that any “verified LEA domain list” must include renewal,
periodic review, and removal processes to prevent stale or misused
entries—especially for agencies that operate multiple domains. In addition,
we were explicit that domain-based checks can only be a temporary measure
while a more robust, accountable authentication system is being developed.
5) We recommended a six-month review period to evaluate registrar
confidence, safeguard effectiveness, and progress toward a long-term
solution.
Importantly, we made clear that any authentication mechanism must
incorporate safeguards, transparency, oversight, and avenues for redress
for registrants whose data may be accessed.
The Board’s October 2025 resolution intersects
<https://www.icann.org/en/board-activities-and-meetings/materials/approved-resolutions-regular-meeting-of-the-icann-board-30-10-2025-en>
with this work by encouraging expanded LEA authentication efforts and
urging alignment of SSAD-related policies with disclosure mechanisms.
However, the Board’s rationale focuses almost exclusively on RDRS
continuity, registrar/requestor satisfaction, voluntary participation, and
ICANN’s operational resources. What is missing is any acknowledgment of the
safeguards, accountability requirements, or user-impact considerations that
NCSG has raised repeatedly in meetings, letters, and contributions to the
RDRS Standing Committee report. Registrants and end users—who are directly
affected—are absent from the Board’s “community impact” framing.
Given this gap between what NCSG has consistently recommended and what the
Board has recognized, I suggest that NCSG take two steps.
First, send a short letter to the ICANN Board reaffirming that we support
LEA authentication only if safeguards, transparency, oversight, and renewal
mechanisms are integral to the system, and noting that the resolution omits
the impact on registrants and end users.
Second, develop a concise Human Rights Impact Assessment (HRIA) of the
Board resolution and the related RDRS/SSAD work, mapping risks to privacy,
due process, non-discrimination, and access to remedy, particularly around
cross-border LEA requests.
I can prepare a first draft of the Board letter and a short HRIA scoping
note for review.
Best regards,
Farzaneh
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20251123/bf8e6ff9/attachment.htm>
More information about the Ncsg-discuss
mailing list