[Ncsg-discuss] PIR and Autistici/Inventati

farzaneh badii 00001deb507b73c5-dmarc-request at LISTSERV.SYR.EDU
Tue Sep 8 13:48:21 EEST 2026


We have a policy meeting on Wednesday. Tomorrow. we can allocate a chunk of
time to this topic and how to write a statement. Please join; however, if
you cannot attend, you can converse here and we will take your comment into
consideration.
transparency and access to Internet infrastructure, along with overcoming
sanctions barriers have been discussed extensively at NCSG and in my
opinion  we can build on our common position. The conversation is not about
whether to act, but what action to take.

My opinion is that we generally can’t be so reactive and the statement
should not focus only on the recent case. We should come up with a plan and
I ask anyone who is bothered by this issue to step up.

In my opinion we can’t stop at transparency and process . They have been
doing “transparency” reporting. Those reports have to be more detailed.

Sanctions have affected people's access for many years. By now,  there is
abundance of evidence to demonstrate that economic sanctions and counter
terrorism frameworks have devestating effects on access to the Internet and
digital services and cannot be proportional and in effect not always
aligned with the rule of law and human rights principles, and working on
process in my opinion cannot on its own be sufficient, I think it might get
us closer to advocating for not using these mechanisms for governing the
Internet but not sufficient.

I used to advocate for waivers and licenses and carve outs. But these
things can be just revoked or imposed at the whim of a government ( and I
am not only talking about the US here). Compliance is hard and we live in a
world where the companies are so risk-averse that they don't even ask the
government for clarification. They just block. And these are companies with
commitments to keep the Internet open and interoperable...








Farzaneh

On Mon, Sep 7, 2026 at 2:13 PM Carlos Vera <
000022318a8e4197-dmarc-request at listserv.syr.edu> wrote:
>
> Dear Nils et all:
>
> I believe there is a concrete role for NCSG here beyond debating whether
PIR should have acted differently.
>
> The public record does not yet allow us to clearly establish what PIR was
legally required to do, what discretion it had, if any, and why serverHold
was the appropriate response. Before drawing conclusions, these facts
should be sufficiently documented by the relevant parties.
>
> NCSG can help identify the information that is missing, seek
clarification from the relevant actors within the ICANN ecosystem, and
determine whether this case reveals a broader transparency or procedural
gap.
>
> More importantly, NCSG could formulate what minimum transparency should
be expected when national legal measures result in actions affecting
globally used DNS resources: enough to understand the legal basis, the
Registry Operator’s role and discretion, the action taken, and the
available mechanisms for review.
>
> That would give us both a sound basis for assessing this case and a
concrete contribution toward making future cases clearer and more
accountable.
>
> Carlos
>
> > El sept 7, 2026, a la(s) 09:20, Niels ten Oever <
lists at digitaldissidents.org> escribió:
> >
> > Dear Carlos,
> >
> > In my initial post I did _not_ write that PIR should not comply, but
rather the problem is that they did not make any statement.
> >
> > PIR isn't a generic intermediary with no independent human rights
posture. It has publicly committed to exactly the kind of assessment you're
describing as unreasonable to expect. It worked with ARTICLE 19 and the
Danish Institute for Human Rights on a human rights impact assessment, has
built commitments to freedom of expression, access to information, and
access to effective remedy into its policies, and has stood up an appeal
process for .ORG registrants precisely so takedown decisions aren't simple
administrative pass-throughs [0]. If that framework means anything, it
should apply with more force here, not less, given the scale of impact.
> >
> > So I don't think this is purely a question of whether the designation
is justified versus whether PIR complied lawfully. The manner and speed of
compliance is itself a human rights and due-process question, and one PIR
has already told the public it takes seriously. I'd like to see it apply
that framework here rather than treat immediate, full termination as the
only legally available response.
> >
> > If you're interested in the relation between business and human rights,
you could have a look at the UN Guiding Principles on Business and Human
Rights [1].
> >
> > Best,
> >
> > Niels
> >
> >
> > [0]
https://pir.org/news-insights/assessing-human-rights-impacts-at-public-interest-registry/
> > [1]
https://www.ohchr.org/sites/default/files/documents/publications/guidingprinciplesbusinesshr_en.pdf
> >
> >
> >
> >> On 9/7/26 16:06, Carlos Vera wrote:
> >> Thank you both for your thoughtful responses. I think we are
fundamentally concerned about many of the same principles, even if we
approach them from different perspectives and place different emphasis on
some of them.
> >> I agree that human rights remain relevant in counter-terrorism
measures, and that impacts on legitimate third parties should not be
ignored. I also agree that government decisions can and should be subject
to scrutiny and challenge.
> >> Where I differ is on what follows from those concerns for an
infrastructure operator such as PIR.
> >> A designation does not become optional simply because it is
administrative, contested, or because the underlying evidence has not been
made fully public. While it remains legally in force, an organization
subject to that jurisdiction is required to act accordingly. PIR cannot
reasonably be expected to conduct its own assessment of whether OFAC has
met the evidentiary burden for the designation and then decide whether to
comply.
> >> The impact on journalists, activists or other legitimate users of A/I
services is a serious concern. But that raises questions about the design
of sanctions, due process, proportionality, and effective mechanisms for
review. It does not necessarily mean that PIR should delay or weaken a
measure it is legally required to implement.
> >> I therefore see two distinct issues that should not be conflated:
whether the OFAC designation itself is justified and provides adequate
safeguards and avenues for challenge; and whether PIR acted lawfully and
within its obligations in responding to a designation already in force.
> >> Human rights and the rule of law are not opposing principles. Both
matter, including when dealing with terrorism.
> >> Carlos
> >>> El sept 7, 2026, a la(s) 08:21, Niels ten Oever <
lists at digitaldissidents.org> escribió:
> >>>
> >>> Dear Carlos,
> >>>
> >>> Thank you for your response. Let me explain my points:
> >>>
> >>> - Not all measures taken by a government are lawful merely because
they are labelled as such;
> >>>
> >>> - No evidence has been provided that Autistici/Inventati is engaging
in, or supporting, terrorism;
> >>>
> >>> - Autistici/Inventati is an association enabling freedom of
expression, access to information, and other human rights. It isn't just
"the designated entity" whose operational capabilities we'd be defending
for their own sake — it's infrastructure (secure email, hosting,
communication tools) that journalists, activists, and human rights
defenders have relied on for many years, often with no comparable
alternative;
> >>>
> >>> - Limiting the human rights of a party requires meeting a significant
burden of proof;
> >>>
> >>> - No such proof has been provided.
> >>>
> >>> Shutting the service down doesn't only affect A/I as an organization;
it removes access for the population that actually depends on it for
freedom of expression, access to information, freedom of association, and
more.
> >>>
> >>> So this isn't a case of shielding an actor from consequences; it's a
case of the collateral damage falling on exactly the people whose rights
you agree matter. Furthermore, since A/I is itself an association, its own
right to freedom of association is at stake here too — not only its role as
an intermediary for others' rights.
> >>>
> >>> Best,
> >>>
> >>> Niels
> >>>
> >>>> On 9/7/26 14:59, Carlos Vera wrote:
> >>>> I do not see a human-rights conflict merely because a lawful measure
is enforced against an entity formally designated under a counter-terrorism
regime.
> >>>> Human-rights concerns may arise where innocent third parties are
affected, and those effects deserve consideration. But that is different
from suggesting that the designated entity itself should be protected from
the consequences of the measure, or that lawful enforcement should be
delayed in order to preserve its operational capabilities
> >>>> Carlos Vera
> >>>>> El sept 7, 2026, a la(s) 06:44, Niels ten Oever <00001ded0bc22afd-
dmarc-request at listserv.syr.edu> escribió:
> >>>>>
> >>>>> Hi all,
> >>>>>
> >>>>> It is very sad to share the news that Autistici/Inventati is
closing down under the pressure:
> >>>>>
> >>>>> https://keepitfree.ai/announcements/a/i-shuts-down-stay-human/
> >>>>>
> >>>>> ISOC, PIR and Identity Digital have not made a public statement yet
about this (as far as I know), but I think that the optics that a Public
Interest Registry prioritizes legal compliance over human rights is quite
negative for the latter, and could set bad precedents.
> >>>>>
> >>>>> I hope that everyone here who has influence and inroads with ISOC,
PIR, and Identity Digital can bring it to their attention. I think it would
look very good if we as NCSG could do a statement about it.
> >>>>>
> >>>>> Best,
> >>>>>
> >>>>> Niels
> >>>>>
> >>>>>
> >>>>> On 9/2/26 11:01, Kenechukwu Okekenta wrote:
> >>>>>> I agree that the ability to seek clarifications on what happened
and demand for possible review and/or corrections are acceptable
safeguards, which may not be obtainable in many other jurisdictions.
> >>>>>> Nonetheless, the issue may also have brought to limelight, the
possible consequences of having a "blanket online terrorism attribution"
for every resiliently dissenting voice.
> >>>>>> I also agree that terrorism is real and should be given the
attention it needs, but given the currently available details and events we
have witnessed in recent past, it might be obvious that any legal
framework, policy or directive that may have motivated this "blanket online
terrorism attribution", may have been hastily done and didn't consider all
the possible consequences of such directive.
> >>>>>> Just as someone hinted, this may have come as a result of looking
the other way, when sanctions against dissenting online voices targeted
"our" perceived, "enemy".
> >>>>>> Therefore, I think it's important that we try not to fall for
certain decisions out of mere emotions, but rather to pursue rationality,
regardless of convenience. It would appear that at one point or another, we
often get measured for, using the same cups we have used for others.
> >>>>>> In any case, I look forward to a possible clarification, appeal
and the decisions, that might follow.
> >>>>>> *Engr. Kenechukwu Okekenta fNSIG*
> >>>>>> *IT **Project Coordinator, **Support Specialist, **Security
Analyst,* *CDPO and Educator*
> >>>>>> *LinkedIn <http://linkedin.com/in/kenechukwu-okekenta>
> >>>>>> *
> >>>>>> On Wed, Sep 2, 2026, 07:25 Carlos Vera <000022318a8e4197-dmarc-
request at listserv.syr.edu <mailto:000022318a8e4197-dmarc-
request at listserv.syr.edu>> wrote:
> >>>>>>    I wonder whether we should also ask a different question: in
which
> >>>>>>    other jurisdictions or institutional settings would a discussion
> >>>>>>    like this one be possible — and, more importantly, protected?
> >>>>>>    Terrorism is real, and states necessarily have legal frameworks
to
> >>>>>>    confront it. Those frameworks inevitably create difficult
tensions
> >>>>>>    when they reach Internet infrastructure: security, due process,
> >>>>>>    proportionality, freedom of expression and continued access
will not
> >>>>>>    always point in the same direction.
> >>>>>>    Changing jurisdiction does not eliminate those tensions. The
> >>>>>>    relevant comparison should therefore not simply be which
> >>>>>>    jurisdiction exercises less power, but which systems provide
> >>>>>>    meaningful safeguards when that power is exercised:
transparency,
> >>>>>>    the ability to challenge the legal basis, independent review,
appeal
> >>>>>>    and the possibility of correcting a decision.
> >>>>>>    The fact that we can openly question what happened to
autistici.org
> >>>>>>    <http://autistici.org>, examine OFAC’s legal basis and GL36,
ask PIR
> >>>>>>    to explain the measure, and debate whether serverHold was
actually
> >>>>>>    required does not establish that the decision was correct. But
the
> >>>>>>    possibility of having that discussion, and of challenging the
> >>>>>>    decision through institutional and legal mechanisms, is itself
an
> >>>>>>    important safeguard.
> >>>>>>    I am not sure that the same discussion, with the same
guarantees,
> >>>>>>    would necessarily be possible in every alternative jurisdiction
we
> >>>>>>    might consider.
> >>>>>>    So the problem is therefore not jurisdiction alone, but how we
> >>>>>>    preserve effective counter-terrorism measures while ensuring
that
> >>>>>>    their effects on global Internet infrastructure are legally
> >>>>>>    justified, reviewable and no broader than necessary.
> >>>>>>    Carlos Vera
> >>>>>>>    El sept 1, 2026, a la(s) 21:05, farzaneh badii
<00001deb507b73c5-
> >>>>>>>    dmarc-request at listserv.syr.edu <mailto:00001deb507b73c5-dmarc-
> >>>>>>>    request at listserv.syr.edu>> escribió:
> >>>>>>>
> >>>>>>>    
> >>>>>>>    This particular  problem is primarily not about ICANN
> >>>>>>>    jurisdiction. It has to do with the registry jurisdiction.
> >>>>>>>    Diversifying registries jurisdiction would be a great solution.
> >>>>>>>
> >>>>>>>    But lets say we need to change ICANN jurisdiction. where
should it
> >>>>>>>    go? The EU? They have a sanction regime that has now started
> >>>>>>>    sanctioning individuals for their speech. They also have an
anti-
> >>>>>>>    terrorism regime.
> >>>>>>>    Canada has its own sanctions regime. The UK, has one of the
worst
> >>>>>>>    sanction regimes with terrible terrorism laws that apply online
> >>>>>>>    and have led to prosecution and prison. Australia also has a
> >>>>>>>    sanction regime. Should ICANN be an international org?
> >>>>>>>    International orgs also have a sanction regime, for terrorism
> >>>>>>>    specifically.
> >>>>>>>
> >>>>>>>    When we warned against using terrorism framework to punish
online
> >>>>>>>    activities and diminish online existence, people didn’t mind it
> >>>>>>>    because it was being used against the people they didn’t agree
> >>>>>>>    with. When we said don’t use sanction framework for Internet
> >>>>>>>    infrastructure it’s never proportional, people again didn’t
mind
> >>>>>>>    it and wanted to use it against the “enemy”.
> >>>>>>>
> >>>>>>>    Also in jurisdiction work stream 2 we worked hard to at least
get
> >>>>>>>    some OFAC licenses. Progress is slow but they are required to
look
> >>>>>>>    into obtaining an ofac license.
> >>>>>>>
> >>>>>>>    The problem is our legal systems and jurisdictions “globally” .
> >>>>>>>    The problem is terrorism framework and sanctions. This is why
we
> >>>>>>>    should speak up against using these frameworks that threaten
> >>>>>>>    online presence, regardless of who is being deprived of access.
> >>>>>>>
> >>>>>>>    Registries based in the US and other countries have been
> >>>>>>>    confiscating people’s domain names from sanctioned countries
for
> >>>>>>>    years. Registries in the US  say domain name registrant should
go
> >>>>>>>    and get an ofac license. Everybody passes the ball onto
somebody
> >>>>>>>    else. There will be a surge of registration at CCTLD level.
> >>>>>>>
> >>>>>>>    We weren’t successful at encouraging registries to receive ofac
> >>>>>>>    licenses or appeal a ruling or discuss with ofac or help the
> >>>>>>>    domain name registrant with restoring access legally. Tech
> >>>>>>>    companies usually don’t do that, except GutHub. But maybe this
> >>>>>>>    will allow for alternative jurisdictions to become popular for
> >>>>>>>    registering domains and maybe we should encourage domain
> >>>>>>>    registration in multiple jurisdictions for resiliency.
> >>>>>>>
> >>>>>>>
> >>>>>>>    Farzaneh
> >>>>>>>
> >>>>>>>    On Tue, Sep 1, 2026 at 9:32 PM Michael Karanicolas
> >>>>>>>    <0000235aca298685-dmarc-request at listserv.syr.edu
> >>>>>>>    <mailto:0000235aca298685-dmarc-request at listserv.syr.edu>>
wrote:
> >>>>>>>
> >>>>>>>        I don't mean to open up any old wounds from folks who were
> >>>>>>>        involved in
> >>>>>>>        the jurisdiction debates in Workstream 2 (or earlier...),
but
> >>>>>>>        given
> >>>>>>>        the directions things have been going in the U.S. it's
honestly
> >>>>>>>        irresponsible that they continue to wield this level of
> >>>>>>>        influence over
> >>>>>>>        the DNS, and that organizations like ICANN and PIR haven't
> >>>>>>>        done more
> >>>>>>>        to hedge against the inevitable abuses that are likely
coming
> >>>>>>>        down the
> >>>>>>>        pike.
> >>>>>>>
> >>>>>>>        On Tue, Sep 1, 2026 at 5:11 PM Kathy Kleiman
> >>>>>>>        <00001e85639e37fc-dmarc-request at listserv.syr.edu
> >>>>>>>        <mailto:00001e85639e37fc-dmarc-request at listserv.syr.edu>>
wrote:
> >>>>>>>        >
> >>>>>>>        > Hi Niels and All,
> >>>>>>>        >
> >>>>>>>        > I checked with PIR and learned the following:  This was
an
> >>>>>>>        instance
> >>>>>>>        > where the US Office of Foreign Assets Control (OFAC), a
> >>>>>>>        financial
> >>>>>>>        > enforcement agency of the US Department of the Treasury
> >>>>>>>        specifically put
> >>>>>>>        > these specific domain names on the “Specially Designated
> >>>>>>>        National” or
> >>>>>>>        > “SDN” list. The action was taken by Identity Digital
> >>>>>>>        (handling Registry
> >>>>>>>        > Service Provider processes), which is legally required to
> >>>>>>>        monitor the
> >>>>>>>        > SDN list for domains and if there’s a direct match,
suspend
> >>>>>>>        the name to
> >>>>>>>        > comply with US OFAC obligations as a service provider. As
> >>>>>>>        US-based
> >>>>>>>        > companies, both ID and PIR are bound to follow US law.
> >>>>>>>        >
> >>>>>>>        > OFAC maintains an appeals process for someone seeking to
get
> >>>>>>>        their name
> >>>>>>>        > removed from the list:
> >>>>>>>        > https://ofac.treasury.gov/specially-designated-nationals-
> >>>>>>>
list-sdn-list/filing-a-petition-for-removal-from-an-ofac-list
> >>>>>>>        <https://ofac.treasury.gov/specially-designated-nationals-
> >>>>>>>
list-sdn-list/filing-a-petition-for-removal-from-an-ofac-list>.
> >>>>>>>        > If the domain names get removed from the SDN list, the
> >>>>>>>        suspensions can
> >>>>>>>        > be lifted.
> >>>>>>>        >
> >>>>>>>        > -------------------------
> >>>>>>>        >
> >>>>>>>        > Best regards, Kathy
> >>>>>>>        >
> >>>>>>>        > >
> >>>>>>>        > > On 8/28/2026 11:42 AM, Niels ten Oever wrote:
> >>>>>>>        > >> Hi all,
> >>>>>>>        > >>
> >>>>>>>        > >> Who is currently our representative on the PIR board?
It
> >>>>>>>        is quite
> >>>>>>>        > >> unsettling that PIR has taken away the .org
registration
> >>>>>>>        from an
> >>>>>>>        > >> Italian NGO following Trump government's executive
order.
> >>>>>>>        > >>
> >>>>>>>        > >> https://sabotmedia.noblogs.org/the-server-called-
> >>>>>>>        paranoia-defend-autistici-inventati-before-september-25/
> >>>>>>>        <https://sabotmedia.noblogs.org/the-server-called-paranoia-
> >>>>>>>        defend-autistici-inventati-before-september-25/>
> >>>>>>>        > >>
> >>>>>>>        > >>
> >>>>>>>        > >> Best,
> >>>>>>>        > >>
> >>>>>>>        > >> Niels
> >>>>>>>        > >>
> >>>>>>>        > >>
> >>>>>>>        > --
> >>>>>>>        > Kathy Kleiman
> >>>>>>>        > Past President, Domain Name Rights Coalition
> >>>>>>>
> >>>>>
> >>>>> --
> >>>>> Niels ten Oever, PhD
> >>>>> Co-Principal Investigator - critical infrastructure lab -
University of Amsterdam
> >>>>> Assistant Professor - Department of European Studies - University
of Amsterdam
> >>>>>
> >>>>> W: https://criticalinfralab.net
> >>>>> W: https://nielstenoever.net
> >>>>> PGP: 4254 ECD5 D4CF F6AF 8B91 0D9F EFAD 2E49 CC90 C10C
> >>>
> >>> --
> >>> Niels ten Oever, PhD
> >>> Co-Principal Investigator - critical infrastructure lab - University
of Amsterdam
> >>> Assistant Professor - Department of European Studies - University of
Amsterdam
> >>>
> >>> W: https://criticalinfralab.net
> >>> W: https://nielstenoever.net
> >>> PGP: 4254 ECD5 D4CF F6AF 8B91 0D9F EFAD 2E49 CC90 C10C
> >>>
> >
> > --
> > Niels ten Oever, PhD
> > Co-Principal Investigator - critical infrastructure lab - University of
Amsterdam
> > Assistant Professor - Department of European Studies - University of
Amsterdam
> >
> > W: https://criticalinfralab.net
> > W: https://nielstenoever.net
> > PGP: 4254 ECD5 D4CF F6AF 8B91 0D9F EFAD 2E49 CC90 C10C
> >
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20260908/730ffc5a/attachment-0001.htm>


More information about the Ncsg-discuss mailing list