[Ncsg-discuss] Important Law Enforcement Agencies, Authentication, Accountability and Safeguards

farzaneh badii farzaneh.badii at GMAIL.COM
Sun Nov 30 08:34:36 EET 2025


Hi all,

Thanks a lot.

Ken I think that would be useful. I have added it. (see below)

Gopal, I am not sure about adding this point to the current letter but we
can have a conversation about it.

I will ask Rafik to send the letter on Monday.

Here are the two paragraphs based on Ken's suggestions.

"NCSG respectfully requests that the Board revise its explanatory text to
reflect the full policy implications of law-enforcement authentication. In
particular, the text should acknowledge that authentication must be
accompanied by safeguards, transparency, accountability, and meaningful
consideration of registrant and end-user rights, and that this is not
merely an operational matter.

We also urge the Board to recognise explicitly that registrants and end
users are central stakeholders affected by these decisions, and to reflect
this in its assessment of community impact. NCSG stands ready to support
the Board in developing a rights-respecting and accountable framework for
law-enforcement authentication."

Farzaneh


On Wed, Nov 26, 2025 at 6:49 PM gopal <gopal at annauniv.edu> wrote:

> Thank you Farzaneh.
>
> How does this take into account GDPR Right to Erasure / to be Forgotten" @
> https://gdpr.eu/right-to-be-forgotten/#:~:text=In%20Article%2017%2C%20the%20GDPR,that%20individual%20withdraws%20their%20consent.
>
> Gopal T V
> 0 9840121302
> https://vidwan.inflibnet.ac.in/profile/57545
> https://www.facebook.com/gopal.tadepalli
> ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
> Dr. T V Gopal
> Retired Professor
> Department of Computer Science and Engineering &
> Retired Director, Centre for Applied Research in Indic Technologies [CARIT]
> College of Engineering, Guindy Campus
> Anna University
> Chennai - 600 025, INDIA
> Ph : (Off) 22351723 Extn. 3340
>        (Res) 24454753
> ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
> ------------------------------
> *From:* NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> on behalf of
> farzaneh badii <farzaneh.badii at GMAIL.COM>
> *Sent:* 23 November 2025 22:33
> *To:* NCSG-DISCUSS at LISTSERV.SYR.EDU <NCSG-DISCUSS at LISTSERV.SYR.EDU>
> *Subject:* Important Law Enforcement Agencies, Authentication,
> Accountability and Safeguards
>
>
> Dear all,
>
> I want to provide an update on where things currently stand regarding
> law-enforcement (LEA) authentication, the work of the practitioner group,
> and the implications of the ICANN Board’s October 2025 resolution.
>
> Given recent developments, I believe NCSG should consider a coordinated
> response. Several months ago, when PSWG (public Safety Working Group) Gabriel
> briefed us on their intention to work with ICANN Org to validate LEA domain
> names, NCSG agreed that LEA could submit domain names of Law Enforcement
> Agencies to the RDRS, but only if specific safeguards and conditions were
> met.
>
> We conveyed these conditions clearly at the time, yet we have not received
> any indication that these concerns are being incorporated into PSWG's
> planning. To remind everyone of what NCSG agreed to:1)  a verified LEA
> domain can serve only as a supplementary signal and not as a standalone
> authentication mechanism. 2) Disclosure decisions must still be grounded
> in rights-balancing, necessity, and a clear legal basis. 3) We stressed
> that domain validation does not prove identity; spoofing remains a serious
> risk, and both registrars and ICANN must be equipped to handle that. 4) We
> also emphasized that any “verified LEA domain list” must include renewal,
> periodic review, and removal processes to prevent stale or misused
> entries—especially for agencies that operate multiple domains. In addition,
> we were explicit that domain-based checks can only be a temporary measure
> while a more robust, accountable authentication system is being developed.
> 5) We recommended a six-month review period to evaluate registrar
> confidence, safeguard effectiveness, and progress toward a long-term
> solution.
>
> Importantly, we made clear that any authentication mechanism must
> incorporate safeguards, transparency, oversight, and avenues for redress
> for registrants whose data may be accessed.
>
> The Board’s October 2025 resolution intersects
> <https://www.icann.org/en/board-activities-and-meetings/materials/approved-resolutions-regular-meeting-of-the-icann-board-30-10-2025-en>
> with this work by encouraging expanded LEA authentication efforts and
> urging alignment of SSAD-related policies with disclosure mechanisms.
> However, the Board’s rationale focuses almost exclusively on RDRS
> continuity, registrar/requestor satisfaction, voluntary participation, and
> ICANN’s operational resources. What is missing is any acknowledgment of the
> safeguards, accountability requirements, or user-impact considerations that
> NCSG has raised repeatedly in meetings, letters, and contributions to the
> RDRS Standing Committee report. Registrants and end users—who are directly
> affected—are absent from the Board’s “community impact” framing.
>
> Given this gap between what NCSG has consistently recommended and what the
> Board has recognized, I suggest that NCSG take two steps.
>
> First, send a short letter to the ICANN Board reaffirming that we support
> LEA authentication only if safeguards, transparency, oversight, and renewal
> mechanisms are integral to the system, and noting that the resolution omits
> the impact on registrants and end users.
>
> Second, develop a concise Human Rights Impact Assessment (HRIA) of the
> Board resolution and the related RDRS/SSAD work, mapping risks to privacy,
> due process, non-discrimination, and access to remedy, particularly around
> cross-border LEA requests.
>
> I can prepare a first draft of the Board letter and a short HRIA scoping
> note for review.
>
> Best regards,
>
> Farzaneh
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20251130/10d8ca46/attachment-0001.htm>


More information about the Ncsg-discuss mailing list