Live data from Hacker News

WHOIS blackout period likely starting in May

cooley.com

111–120 of 163 posts

Re: WHOIS blackout period likely starting in May

#111
post #34

Earlier quoted context omitted.

When you buy a house, your name and the purchase price are public information. Any one at any time can look up who owns a house, how much they paid for it, and how much they pay in property tax every year. I get a ton of spam because of this. However, I'd rather have this system than one in which all the owners are secret. I've had to look up owner information before to contact owners of various properties, and havin…

If this is true in Europe, I'm curious what the implications are w.r.t. GDPR.

Probably very little. The data will be being made public under a law mandating that, and the GDPR allows for that:

> Processing shall be lawful [...if...] processing is necessary for compliance with a legal obligation to which the controller is subject

https://gdpr-info.eu/art-6-gdpr/

Re: WHOIS blackout period likely starting in May

#112
post #29
post #21

Earlier quoted context omitted.

I like what CIRA (the .ca registration authority) does. The default is for them to hide your contact information. You have to opt-in to make it public. They then handle all communications people want to send to you. More registration authorities should take stances like this. Now if only they could get DNSSEC support...

I like how people responsible for .pl (Poland) domain handle this. First of all, they list only very basic data, with no names, addresses, etc. when you query their whois. To see the full data, you have to go to their website and type the captcha, which filters out at least some of the bots. But even there they display the data if it belongs to a company, they won't show any details if it's registered to a private pe…

> you have to go to their website and type the captcha

I'd prefer that they'd charge me 5 eurocents per query rather than using my time and effort to feed Google's AI.

Re: WHOIS blackout period likely starting in May

#113
I'm just wondering why ICANN is "scrambling to get it GDPR-compliant" just now, at the eleventh hour. They had just as much time as rest of the world to do it sooner, without any interim modes, and without any rush and all the problems that can come from hastiness.

Re: WHOIS blackout period likely starting in May

#114
post #109

Earlier quoted context omitted.

Whois can also be used to identify who owns IP blocks. Which is crucial to many applications such as security. If you don't want your personal information to be visible thats very different to the full range of what whois can do. You can always use a proxy so there are options for privacy available. I've never got a single spam email/call from my whois data.

ARIN already provides public APIs for this without the need for WHOIS.

WHOIS the protocol is not the problem, it is the data it is used to publish. Then GDPR-related mitigations required would be the same whether you are publishing with WHOIS, RDAP or something else.

Also, ARIN only has allocations made in North America. Plus, ARIN only covers North American allocations.

Re: WHOIS blackout period likely starting in May

#115

Earlier quoted context omitted.

But the thing is - not only officials can get that data. Its simply not that easily available (so you can't harvest it like mails on the Web) As for house market - in other counties (where dará is more hidden) it still works. and as far as I know housing market in the US is quite... weird, so it seems this data doesn't help that much?

A housing market that's full of fraud and that has extra-high interest rates still "works". I don't think you're understanding my point at all, or maybe you don't mind fraud. But in any case, those are the problems that transparency are trying to help solve.

You seem to be repeating the talking point without addressing the counter-argument. Why is a system where people can access that data, just with a couple of roadblocks to avoid mass harvesting, not enough to avoid fraud?

Re: WHOIS blackout period likely starting in May

#116
post #99
post #85

Earlier quoted context omitted.

When I used to work in security, I used Whois every day. In many cases it was to notify a domain owner that their domain had been compromised and was being used for spam. I also used it a lot to track down bad actors because most of them are dumb and don’t hide their Whois.

In germany there is an imprint requirement so you'll always have a contact point for these things. Unlike WHOIS it's on a website so you can protect this information much more easily from scraping and spamming.

Not all domains have public websites.

Re: WHOIS blackout period likely starting in May

#117

Earlier quoted context omitted.

If this is true in Europe, I'm curious what the implications are w.r.t. GDPR.

Probably very little. The data will be being made public under a law mandating that, and the GDPR allows for that: > Processing shall be lawful [...if...] processing is necessary for compliance with a legal obligation to which the controller is subject https://gdpr-info.eu/art-6-gdpr/

EDIT: nevermind, misread the context.

Re: WHOIS blackout period likely starting in May

#118
post #113

I'm just wondering why ICANN is "scrambling to get it GDPR-compliant" just now, at the eleventh hour. They had just as much time as rest of the world to do it sooner, without any interim modes, and without any rush and all the problems that can come from hastiness.

A big factor is that ICANN is comprised of multiple stakeholder communities of competing interests that have to come up with consensus to make new policies. Refining the model of what is published in the WHOIS has been the subject of working groups in ICANN for over 10 years, but consensus was never reached because you had a huge spread of opinions that never converged. Privacy advocates argued for no WHOIS, whereas interests from law enforcement, security research and intellectual property arguing for full disclosure.

Re: WHOIS blackout period likely starting in May

#119

Earlier quoted context omitted.

Probably very little. The data will be being made public under a law mandating that, and the GDPR allows for that: > Processing shall be lawful [...if...] processing is necessary for compliance with a legal obligation to which the controller is subject https://gdpr-info.eu/art-6-gdpr/

EDIT: nevermind, misread the context.

I believe the parent is talking about the example of a land ownership database.
Post reply on HN