Live data from Hacker News

WHOIS blackout period likely starting in May

cooley.com

141–150 of 163 posts

Re: WHOIS blackout period likely starting in May

#141
ICANN is scrambling to be compliant they write... We've all had 2 years notice since the GPDR has been adopted! And if you 'didnt know', you have bigger organizational problems.

I understand it is a lot of annoying work, but adtech and data brokers (etc etc) have been gutting privacy and the internet for long enough. We've let it come this far, now we get regulated.

(disclaimer: I only started working on compliance this year, do as I say, not as I do ;))

Re: WHOIS blackout period likely starting in May

#142
Having a public register that tells you who owns a particular domain or IP address could be useful for a lot of things. Sure, they could take away a lot of fields that are not necessary and might be a privacy problem, like address and phone number, today it's useless, and maybe instead add a GPG public key, so much useful, and keep name and email address.

But don't remove it, it's a useful thing I use a lot, most of the times for security purpose, you see a suspicious IP address or domain while observing a packet capture, WHOIS tells you who owns it, you find in a log an IP address that tries to bruteforce into your server, WHOIS tells you who it is and gives you an address to contact and ask explanations, you need to find a person to contact if you have a problem with a website, contact the email address in the WHOIS record of the domain, you are sure that you are contacting the right person, even if the site gets hacked in the worst way the WHOIS record can't change.

Re: WHOIS blackout period likely starting in May

#143
post #79

Earlier quoted context omitted.

Choose a registrar that doesn't charge you extra? Your name stays in, of course, but your (electronic and snail) mail addresses and phone number can be replaced by registrar-managed ones where they forward you incoming stuff and (mostly) keep the spam. It's a pretty common thing with European providers, I think.

For example namesilo doesn’t charge for privacy protection.

Another vote for Namesilo. They seem to be out to create a genuinely good service and not a money grab.

Re: WHOIS blackout period likely starting in May

#144
post #34

Earlier quoted context omitted.

When you buy a house, your name and the purchase price are public information. Any one at any time can look up who owns a house, how much they paid for it, and how much they pay in property tax every year. I get a ton of spam because of this. However, I'd rather have this system than one in which all the owners are secret. I've had to look up owner information before to contact owners of various properties, and havin…

If this is true in Europe, I'm curious what the implications are w.r.t. GDPR.

It's not true where I am in Europe, this sort of info is accessible to government employees only.

Re: WHOIS blackout period likely starting in May

#145

In the short term WHOIS is going to be limited to just the registrant organization, state, country and a masked email address (Admin and Technical fields will be removed save email). This is short term to come into compliance with GDPR. Long term ICANN intends to create a privileged group (other registrars, law enforcement, etc) Who will be able to get to the full whois data. So a sort of tiered system. Expect this t…

> Expect this to take a minimum of a year. GDPR was announced over 2 years ago, why are they only just starting now?

They aren't but the nature of the process is "Everyone gets an opinion" that takes a lot of time. So they spent over a year soliciting opinions, sorting out legal issues etc, and came up with "we need some kind of authorization system on top of whois" but they've got to build it and they have 0 competence in that realm, so it will need to be put back out to committee. A process will have to be devised, a spec written, spec adopted etc. Its a huge slow bureaucracy. 2 years is fine to expect a business to be compliant with something, for a pseudo governmental organization its not nearly enough time.

Re: WHOIS blackout period likely starting in May

#146
post #82

In the short term WHOIS is going to be limited to just the registrant organization, state, country and a masked email address (Admin and Technical fields will be removed save email). This is short term to come into compliance with GDPR. Long term ICANN intends to create a privileged group (other registrars, law enforcement, etc) Who will be able to get to the full whois data. So a sort of tiered system. Expect this t…

> Long term ICANN intends to create a privileged group (other registrars, law enforcement, etc) And trademark owners, of course. So that the Three Letter Corporation (TLC) can continue sending lawyers to wrestle away control over the domain of Theodore L. Clark's personal homepage initially set up in 1995 (and enthusiastically maintained since). Because chaos and mayhem would result if there's even a single ccTLD whe…

This is exactly why privacy and proxy services will still be necessary - it will essentially re-balance what GDPR has unbalanced (no judgement on whether that is favorable or not)

Re: WHOIS blackout period likely starting in May

#147
post #134

Earlier quoted context omitted.

The GDPR was proposed in 2012 and has been heavily discussed since then. It was adopted in 2016 and as of 25 May 2018 will be enforceable. Anyone who uses the data of EU citizens should have known about it. They certainly had plenty of time to consider the effects of it on their own operations.

ICANN is a US company. Technically, the rules don’t apply to them, because it is an EU law, not a global one. However, the maliciousness that the EU is proposing to go after any company, whether they operate in the EU or not, is going to break things in ways they have not thought of. So regardless of how long ago it came out (and trust me, 2 years is nothing for dealing with something like this), it still wasn’t well…

If the laws didn't apply to them, they would just ignore them. The fact that they haven't proves otherwise.

The GDPR has been discussed for well over 2 years. It came out in 2012. Before then, it was being discussed publicly. Its predecessor, the Data Protection Directive, has been around for a long time.

You really have no justification for calling it horribly thought through. Laws like this don't appear overnight and without wide consultation. In any case, if the requirement was to apply the law out every scenario before implementing it, pretty much no law would ever be implemented.

The aim of the GDPR is to make organisations treat personal information properly, not to penalise them for every little infringement. I very much doubt there will be enough capacity to deal with every minor offence; it's more likely that large companies or those with many complaints against them will be the first targets.

Ultimately, if you're not sure about something, you most likely aren't the only one. Things will become clearer as regulations and guidelines appear, and the first complaints are dealt with. If you believe you're behaving fairly, you're probably fine or at least that's something you can argue.

Re: WHOIS blackout period likely starting in May

#148
post #128
post #99

Earlier quoted context omitted.

In germany there is an imprint requirement so you'll always have a contact point for these things. Unlike WHOIS it's on a website so you can protect this information much more easily from scraping and spamming.

That's where WHOIS protection comes in handy. If you don't want to get even more spam (the imprint has to be clear text, no obfuscation so gets spammed a lot) but a website that could target Germans (or you're in Germany), you'll quickly get costly letters from specialised lawyers. Having Whois protection usually helps, they tend to give up if they can't get your address easily.

Some minor Obfuscation should be okay "mail at example dot com" => "mail@example.com" and similar.

Plus I'm fairly certain providing temporary mail addresses (with decent lifetime) would also be okay.

Specialised Lawyer isn't quite right, a business that competes with you needs to file a complaint (IIRC from law course).

Re: WHOIS blackout period likely starting in May

#149

Earlier quoted context omitted.

A housing market that's full of fraud and that has extra-high interest rates still "works". I don't think you're understanding my point at all, or maybe you don't mind fraud. But in any case, those are the problems that transparency are trying to help solve.

You seem to be repeating the talking point without addressing the counter-argument. Why is a system where people can access that data, just with a couple of roadblocks to avoid mass harvesting, not enough to avoid fraud?

I'm just describing the problems that the current system appears to be designed to solve. If you want to design a new system, great, have at it. I don't have an opinion about that, other than that you probably should try to solve the same problems.

Re: WHOIS blackout period likely starting in May

#150

ICANN is scrambling to be compliant they write... We've all had 2 years notice since the GPDR has been adopted! And if you 'didnt know', you have bigger organizational problems. I understand it is a lot of annoying work, but adtech and data brokers (etc etc) have been gutting privacy and the internet for long enough. We've let it come this far, now we get regulated. (disclaimer: I only started working on compliance t…

It's worse than that. Article 29 Working Party (WP29) - which deals with data protection has said since 2003 (well over a decade!) that Whois is not compatible with EU law [0]. They just didn't have a way to enforce it before GDPR.

But ICANN are delusional idiots, maybe because they get so much money from US intellectual property interests. They did nothing, and then seemed to think that they could get a moratorium on enforcement. But even their own Non-Commercial Stakeholders Group basically told them to get lost [1].

It's a fascinating story of just how terrible ICANN is. As always, the Register has a great write-up [2].

One thing it clear, they deserve it. I do feel bad for registrars though, and hope they had more sense than ICANN and developed a plan B.

[0] http://ec.europa.eu/justice/article-29/documentation/opinion...

[1] https://www.icann.org/en/system/files/files/gdpr-comments-nc...

[2] https://www.theregister.co.uk/2018/04/25/icann_whois_gdpr/

Post reply on HN