Live data from Hacker News

As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

blog.easydns.org

61–70 of 71 posts

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#61
post #4

Can this be done via a "click here to confirm" email, or does this require phone conversations with the registrar? I don't like registering domains using my real name.

I got such an email from Namecheap yesterday, and confirmed it with one click. And unlike the intended trigger for verification ("changes to contact information"), I didn't make any changes to my domain. Either a WHOIS cloak expired, or some other action by Namecheap triggered the verification step.

It can also be triggered by using the same contact with another domain being registered. Registrars aren't required to verify any existing contacts, but the moment there's an update, they have to. That said, if they want to, they can.

Also, Namecheap is an eNom reseller, so you actually got that email from them, not Namecheap.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#63
post #7

Can this be done via a "click here to confirm" email, or does this require phone conversations with the registrar? I don't like registering domains using my real name.

Isn't there some rule that a domain must be registered with a real name, or it doesn't really belong to you (and all anonymization services for domains are therefore suspect)?

Only if the privacy service isn't ran by the registrar the domain is managed by. You should have a read over ICANN's 2013 RAA: http://www.icann.org/en/resources/registrars/raa/approved-wi...

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#64

This bit me kind of bad yesterday. I was about to drive out of cell range and got a text that client's site had some strange page displaying. Unfortunately, they repoint the dns servers of the domain, and the client had the contact email mx records associated with same domain. The actual site gets 'dns hikacked' by icann until you fill out a captcha on your site's new page and it emails the whois email account on rec…

How do they email you if your contact email is on the domain they just suspended? Time to set a TTL of 100 years, or something, I guess.

You get the emails before the DNS suspension date. Here's the policy in question: http://www.icann.org/en/resources/registrars/consensus-polic...

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#65

This bit me kind of bad yesterday. I was about to drive out of cell range and got a text that client's site had some strange page displaying. Unfortunately, they repoint the dns servers of the domain, and the client had the contact email mx records associated with same domain. The actual site gets 'dns hikacked' by icann until you fill out a captcha on your site's new page and it emails the whois email account on rec…

ICANN didn't 'hijack' the domain.

The domain was suspended from DNS because you hadn't paid your renewal bill. The "strange page" was put up by your registrar to notify any visitors of this and to direct them towards their billing system. The idea is to effectively shame people into paying their bills in a timely manner. Your registrar would've sent you at least three different emails before and shortly after the domain's expiration including a notice of what would happen if you didn't pay on time. If you didn't receive these, then that's on you for not keeping your contact details up to date and correct, which you're required to under your registration contract, and which is why you get those emails out periodically asking that you verify that the details they have for you are correct.

If you don't pay your phone bills, electricity bills, rent, &c. on time, you'd expect the service to be removed. Why would domain names be any different?

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#66
post #57

Earlier quoted context omitted.

I got email from the people who run .us domains demanding a photo of my driver's license to prove I'm American. They did not understand why I might think they were scammers and want them to verify their identity first, nor did they understand how to verify their identity.

I would love to hear how that played out, actually, if you don't mind.

Well their SSL cert on their website was invalid (just expired) and there was some kinda mention of them on some government site somewhere that wasn't quite clear enough IMO.

they got bored of trying to prove their identity and just said like "whatever, verify your identity or you'll lose your domain". i ended up phoning them with the number on the site with the invalid SSL certificate, getting the person i'd been emailing with, and she said i could black out the driver's license number on the photo. i ended up sending it that way. i think they were just stupid, not scammers. that was years ago and nothing bad has happened yet to my knowledge.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#67

This is apparently so the physical mail spammers can send me more physical mail along the lines of "This is the Domain Registry of America! Pay us $1000 to keep your domain!" Uh, no. Where's the FTC when I need it...

I got email from the people who run .us domains demanding a photo of my driver's license to prove I'm American. They did not understand why I might think they were scammers and want them to verify their identity first, nor did they understand how to verify their identity.

Are you sure it was them? Having a verified personal identity is not a requirement to have a .us domain. All you need to prove is that you have "a bona fide presence in the United States of America or any of its possessions or territories [Nexus Category 3]."

(It goes into detail claiming that you need to "state" your country of citizenship, but not that you need to "prove" your country of citizenship. An identity document is massively overreaching, IMHO. I never had to prove anything to get jrock.us, and if I have to, I will move the domain.)

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#68

Earlier quoted context omitted.

I got email from the people who run .us domains demanding a photo of my driver's license to prove I'm American. They did not understand why I might think they were scammers and want them to verify their identity first, nor did they understand how to verify their identity.

Are you sure it was them? Having a verified personal identity is not a requirement to have a .us domain. All you need to prove is that you have "a bona fide presence in the United States of America or any of its possessions or territories [Nexus Category 3]." (It goes into detail claiming that you need to "state" your country of citizenship, but not that you need to "prove" your country of citizenship. An identity do…

I ended up thinking it was not a scam but being uncomfortable. It's possible I had originally put a fake address for my whois info, possibly triggering this, I forget. I'm not 100% sure.

Here's the people, i spoke with them on the phone: http://www.neustar.us

here is their first email in april 2011:

Greetings,

As you may be aware, in November 2001, the United States Department of Commerce ("DOC") selected NeuStar, Inc. ("NeuStar") to be the Administrator of the .US top-level domain ("usTLD"), the official top-level domain for the United States of America. As Administrator of the usTLD, NeuStar has agreed to perform random "spot checks" on registrations in the usTLD to endure that they comply with the usTLD Nexus Requirements which can be found at http://www.neustar.us/content/download/2659/32865/ustld_nexu... ("Nexus Requirements").

Our records indicate that you are the registrant of the domain name CURI.US.

On April 28, 2011, this domain name was selected for Nexus revalidation and confirmation. According to the information you provided with your registration of this Domain Name, you indicated that you qualify under:

Category 1 - You are a US citizen or permanent resident

As part of our verification process, we ask that you provide to us by no later than ten (10) days after the date set forth above, a written response describing how you qualify under the above Nexus category.

In addition, please verify that the name-servers that you have selected to use are also physically located within the United States as required by the Nexus Requirements.

In some instances, we may request additional documentary evidence from you to demonstrate that you meet the Nexus requirements.

You should be aware that if you either (i) do not respond within the ten (10) days, or (ii) are unable to adequately explain or demonstrate through documentary evidence that you meet any of the Nexus Requirements, NeuStar may issue a finding that your entity or organization has failed to meet the Nexus Requirements. Upon such a finding, you will then be given a total of ten (10) days to cure the US Nexus deficiency. If you are able to demonstrate within ten (10) days that your entity or organization has remedied such deficiency, you will be allowed to keep the domain name. If, however, you either (i) do not respond within the ten (10) days of such a finding of noncompliance, or (ii) are unable to proffer evidence demonstration compliance with the Nexus Requirements, the domain name registration will be deleted from the registry database without refund, and the domain name will be placed into the list of available domain names.

Thank you for your cooperation in this matter. Please let us know if you have any questions.

Kind Regards,

John .US Nexus Compliance ___________________________________________ NeuStar .US America's Internet Address Email: nexus-compliance@neustar.us

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#69
post #39

ICANN is a mafia! They did this to actually force some old domains to get back into the market. ICANN as an organization will profit little from this, but the people bribing them (domainers, auction sites, domain escrows, etc.) will vastly profit from it. Imagine what would happen if somebody sends you a letter and they get back a letter saying that you cannot receive the letter as you didn't verify your name with US…

Actually, this whole this was included under pressure from law enforcement agencies (LEAs). Registrars, registries, and ICANN themselves would much prefer we stuck with the old WDRP regime where all that happens is that the registrars periodically ask that registrants verify that the information provided is correct. This new LEA-mandated nonsense is nothing but a drain on registrars (which is a business with thin mar…

No, ICANN is legitimized fraud. You can be 90-day overdue with utilities and you pay a relatively small fee. Phone companies don't give your phone number to your competitor or auction it. This is ridiculous! If the annual fee is $10-15, one shouldn't charge $150 a redemption (i.e. extortion fee)!

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#70
post #69

Earlier quoted context omitted.

Actually, this whole this was included under pressure from law enforcement agencies (LEAs). Registrars, registries, and ICANN themselves would much prefer we stuck with the old WDRP regime where all that happens is that the registrars periodically ask that registrants verify that the information provided is correct. This new LEA-mandated nonsense is nothing but a drain on registrars (which is a business with thin mar…

No, ICANN is legitimized fraud. You can be 90-day overdue with utilities and you pay a relatively small fee. Phone companies don't give your phone number to your competitor or auction it. This is ridiculous! If the annual fee is $10-15, one shouldn't charge $150 a redemption (i.e. extortion fee)!

It's called an 'expiration date' for a reason: that's the date you're supposed to have paid for continued service by. The grace period (and the redemption period) are leeway. It's in no way an extortion fee: you're given plenty of notice before the domain expires, and if it ends up in redemption, you only have your own incompetence to blame.

Also, you don't own the domain, it's a lease. If you let a domain expire and a competitor snaps it up, that's on you, not the registrar. You can initiate UDRP actions to recover it, but it's your fault.

Post reply on HN