Oh no, you're thinking, yet another cookie pop-up. Well, sorry, it's the law. We measure how many people read us, and ensure you see relevant ads, by storing cookies on your device. If you're cool with that, hit “Accept all Cookies”. For more info and to customise your settings, hit “Customise Settings”.

Review and manage your consent

Here's an overview of our use of cookies, similar technologies and how to manage them. You can also change your choices at any time, by hitting the “Your Consent Options” link on the site's footer.

Manage Cookie Preferences
  • These cookies are strictly necessary so that you can navigate the site as normal and use all features. Without these cookies we cannot provide you with the service that you expect.

  • These cookies are used to make advertising messages more relevant to you. They perform functions like preventing the same ad from continuously reappearing, ensuring that ads are properly displayed for advertisers, and in some cases selecting advertisements that are based on your interests.

  • These cookies collect information in aggregate form to help us understand how our websites are being used. They allow us to count visits and traffic sources so that we can measure and improve the performance of our sites. If people say no to these cookies, we do not know how many people have visited and we cannot monitor performance.

See also our Cookie policy and Privacy policy.

Uncle Sam slams plans to give govts final say over domain privacy

ICANN throws itself under bus to hit GDPR deadline


A plan by ICANN to let governments collectively decide who is allowed to bypass new European privacy rules over domain names has been blasted by its most powerful member, the United States.

At a meeting of DNS oversight organization ICANN, the US government representative told colleagues from across the globe his country didn't like the idea of the Governmental Advisory Committee (GAC) to decide which groups should be granted access to the full "Whois" data.

It should instead be a self-regulatory effort with groups that have a legitimate need for such information working together to create their own accreditation system, the USG rep argued.

That message was reiterated in a speech by Assistant Commerce Secretary David Redl at ICANN's meeting in Puerto Rico, when he talked about the proposed "interim" model put forward by the organization to address the General Data Protection Regulation (GDPR) coming into force in May.

"The United States would encourage revisions to the model that would permit access to the most amount of registration data as possible," Redl said. "We think there is more that can be done to achieve this."

Redl also criticized the very short amount of time that ICANN had provided to come up with an accreditation process and worried that the time crunch would mean that law enforcement and IP lawyers would lose access to the Whois database because of the tardy response.

"The United States will not accept a situation in which Whois information is not available or is so difficult to gain access to that it becomes useless for the legitimate purposes that are critical to the ongoing stability and security of the Internet," he pointedly noted.

Noisy

Indeed, ICANN's last-minute patchwork of plans in an effort to hit the GDPR deadline has already created more noise than agreement.

In what appears to have been an effort to be pragmatic, the organization's staff proposed that the world's governments, through its GAC body, come up with a system for deciding who should be allowed to view the full details of who owns a particular domain – including their name, phone number and email address.

That approach has been heavily criticized however as going directly against ICANN's multi-stakeholder ethos – where everyone impacted by a decision, from the technical community to business to civil society to governments, gets an equal say in the solution.

The fact that it is the US government that has had to rebuke ICANN for its suggested government-centric approach is particularly poignant: the US gave up its formal oversight of ICANN over a year ago amid concerns that it had too much influence on decision-making.

This week's events have led to a number of notable internet figures privately question whether ICANN was ready to assume its full responsibilities.

On the flipside, however, the internet community has tried and failed for over 20 years to devise a replacement for the outdated Whois service. The only reason a plan is even being debated this month is because of the impending EU deadline.

Hamster wheel

ICANN as an organization has become adept at constantly pushing back deadlines: it was first informed that the Whois broke European law nearly a decade ago. Unfortunately the same institutional effort that is put into putting off decisions has not been applied to building decision-making systems that embrace compromise.

In this case, however, things may be turned upside down in that the group which most often prevents new policies from being introduced – the registries and registrars that fund ICANN and are responsible for the registration and transfer of domain names – are those that have the most to lose.

If ICANN does not introduce a system for protecting the private information of domain name registrants by the end of May, it will be the companies publishing those details that face massive fines.

For once, the frequently marginalized civil society representatives within ICANN are happy to watch the industry-led impasse. Let it fail, some representatives are saying behind the scenes, because it is the businesses that will be hit with lawsuits and fines. Then, the theory goes, they will be willing to come back and negotiate. ®

Narrower topics


Other stories you might like

  • How ICE became a $2.8b domestic surveillance agency
    Your US tax dollars at work

    The US Immigration and Customs Enforcement (ICE) agency has spent about $2.8 billion over the past 14 years on a massive surveillance "dragnet" that uses big data and facial-recognition technology to secretly spy on most Americans, according to a report from Georgetown Law's Center on Privacy and Technology.

    The research took two years and included "hundreds" of Freedom of Information Act requests, along with reviews of ICE's contracting and procurement records. It details how ICE surveillance spending jumped from about $71 million annually in 2008 to about $388 million per year as of 2021. The network it has purchased with this $2.8 billion means that "ICE now operates as a domestic surveillance agency" and its methods cross "legal and ethical lines," the report concludes.

    ICE did not respond to The Register's request for comment.

    Continue reading
  • Fully automated AI networks less than 5 years away, reckons Juniper CEO
    You robot kids, get off my LAN

    AI will completely automate the network within five years, Juniper CEO Rami Rahim boasted during the company’s Global Summit this week.

    “I truly believe that just as there is this need today for a self-driving automobile, the future is around a self-driving network where humans literally have to do nothing,” he said. “It's probably weird for people to hear the CEO of a networking company say that… but that's exactly what we should be wishing for.”

    Rahim believes AI-driven automation is the latest phase in computer networking’s evolution, which began with the rise of TCP/IP and the internet, was accelerated by faster and more efficient silicon, and then made manageable by advances in software.

    Continue reading
  • Pictured: Sagittarius A*, the supermassive black hole at the center of the Milky Way
    We speak to scientists involved in historic first snap – and no, this isn't the M87*

    Astronomers have captured a clear image of the gigantic supermassive black hole at the center of our galaxy for the first time.

    Sagittarius A*, or Sgr A* for short, is 27,000 light-years from Earth. Scientists knew for a while there was a mysterious object in the constellation of Sagittarius emitting strong radio waves, though it wasn't really discovered until the 1970s. Although astronomers managed to characterize some of the object's properties, experts weren't quite sure what exactly they were looking at.

    Years later, in 2020, the Nobel Prize in physics was awarded to a pair of scientists, who mathematically proved the object must be a supermassive black hole. Now, their work has been experimentally verified in the form of the first-ever snap of Sgr A*, captured by more than 300 researchers working across 80 institutions in the Event Horizon Telescope Collaboration. 

    Continue reading
  • Shopping for malware: $260 gets you a password stealer. $90 for a crypto-miner...
    We take a look at low, low subscription prices – not that we want to give anyone any ideas

    A Tor-hidden website dubbed the Eternity Project is offering a toolkit of malware, including ransomware, worms, and – coming soon – distributed denial-of-service programs, at low prices.

    According to researchers at cyber-intelligence outfit Cyble, the Eternity site's operators also have a channel on Telegram, where they provide videos detailing features and functions of the Windows malware. Once bought, it's up to the buyer how victims' computers are infected; we'll leave that to your imagination.

    The Telegram channel has about 500 subscribers, Team Cyble documented this week. Once someone decides to purchase of one or more of Eternity's malware components, they have the option to customize the final binary executable for whatever crimes they want to commit.

    Continue reading
  • Ukrainian crook jailed in US for selling thousands of stolen login credentials
    Touting info on 6,700 compromised systems will get you four years behind bars

    A Ukrainian man has been sentenced to four years in a US federal prison for selling on a dark-web marketplace stolen login credentials for more than 6,700 compromised servers.

    Glib Oleksandr Ivanov-Tolpintsev, 28, was arrested by Polish authorities in Korczowa, Poland, on October 3, 2020, and extradited to America. He pleaded guilty on February 22, and was sentenced on Thursday in a Florida federal district court. The court also ordered Ivanov-Tolpintsev, of Chernivtsi, Ukraine, to forfeit his ill-gotten gains of $82,648 from the credential theft scheme.

    The prosecution's documents [PDF] detail an unnamed, dark-web marketplace on which usernames and passwords along with personal data, including more than 330,000 dates of birth and social security numbers belonging to US residents, were bought and sold illegally.

    Continue reading

Biting the hand that feeds IT © 1998–2022