[Ncsg-discuss] Important Law Enforcement Agencies, Authentication, Accountability and Safeguards

Johan Helsingius 00001963cc94b85a-dmarc-request at LISTSERV.SYR.EDU
Mon Nov 24 11:34:53 EET 2025


I support the letter - thank you, Farzaneh!

	Julf


On 24/11/2025 2:03 am, farzaneh badii wrote:
> Hi all,
> 
> I have drafted the letter about the Board resolution: https:// 
> docs.google.com/document/d/1oHj3zPZtjNQrgEWJsx70F4e2K6kskYNaUbmmclzhnuM/ 
> edit?usp=sharing <https://docs.google.com/document/ 
> d/1oHj3zPZtjNQrgEWJsx70F4e2K6kskYNaUbmmclzhnuM/edit?usp=sharing>
> 
> Please comment.
> 
> 
> 
> 
> 
> Farzaneh
> 
> 
> On Sun, Nov 23, 2025 at 12:03 PM farzaneh badii 
> <farzaneh.badii at gmail.com <mailto:farzaneh.badii at gmail.com>> wrote:
> 
>     Dear all,
> 
>     I want to provide an update on where things currently stand
>     regarding law-enforcement (LEA) authentication, the work of the
>     practitioner group, and the implications of the ICANN Board’s
>     October 2025 resolution.
> 
>     Given recent developments, I believe NCSG should consider a
>     coordinated response. Several months ago, when PSWG(public Safety
>     Working Group) Gabriel briefed us on their intention to work with
>     ICANN Org to validate LEA domain names, NCSG agreed that LEA could
>     submit domain namesof Law Enforcement Agencies to the RDRS, but only
>     if specific safeguards and conditions were met.
> 
>     We conveyed these conditions clearly at the time, yet we have not
>     received any indication that these concerns are being incorporated
>     intoPSWG's planning. To remind everyone of what NCSG agreed to:1) a
>     verified LEA domain can serve only as a supplementary signal and not
>     as a standalone authentication mechanism. 2) Disclosure decisions
>     must still be grounded in rights-balancing, necessity, and a clear
>     legal basis. 3) We stressed that domain validation does not prove
>     identity; spoofing remains a serious risk, and both registrars and
>     ICANN must be equipped to handle that. 4) We also emphasized that
>     any “verified LEA domain list” must include renewal, periodic
>     review, and removal processes to prevent stale or misused entries—
>     especially for agencies that operate multiple domains. In addition,
>     we were explicit that domain-based checks can only be a temporary
>     measure while a more robust, accountable authentication system is
>     being developed.5) We recommended a six-month review period to
>     evaluate registrar confidence, safeguard effectiveness, and progress
>     toward a long-term solution.
> 
>     Importantly, we made clear that any authentication mechanism must
>     incorporate safeguards, transparency, oversight, and avenues for
>     redress for registrants whose data may be accessed.
> 
>     The Board’s October 2025 resolution intersects <https://
>     www.icann.org/en/board-activities-and-meetings/materials/approved-
>     resolutions-regular-meeting-of-the-icann-board-30-10-2025-en> with
>     this work by encouraging expanded LEA authentication efforts and
>     urging alignment of SSAD-related policies with disclosure
>     mechanisms. However, the Board’s rationale focuses almost
>     exclusively on RDRS continuity, registrar/requestor satisfaction,
>     voluntary participation, and ICANN’s operational resources. What is
>     missing is any acknowledgment of the safeguards, accountability
>     requirements, or user-impact considerations that NCSG has raised
>     repeatedly in meetings, letters, and contributions to the RDRS
>     Standing Committee report. Registrants and end users—who are
>     directly affected—are absent from the Board’s “community impact”
>     framing.
> 
>     Given this gap between what NCSG has consistently recommended and
>     what the Board has recognized, I suggest that NCSG take two steps.
> 
>     First, send a short letter to the ICANN Board reaffirming that we
>     support LEA authentication only if safeguards, transparency,
>     oversight, and renewal mechanisms are integral to the system, and
>     noting that the resolution omits the impact on registrants and end
>     users.
> 
>     Second, develop a concise Human Rights Impact Assessment (HRIA) of
>     the Board resolution and the related RDRS/SSAD work, mapping risks
>     to privacy, due process, non-discrimination, and access to remedy,
>     particularly around cross-border LEA requests.
> 
>     I can prepare a first draft of the Board letter and a short HRIA
>     scoping note for review.
> 
>     Best regards,
> 
>     Farzaneh
> 


More information about the Ncsg-discuss mailing list