ICANN81: A summit at a crossroads between challenges and difficulties 

ICANN81: A summit at a crossroads between challenges and difficulties 

Thursday 14 November saw the close of the 81st ICANN Summit, the Internet’s governing body. The summit took place on the banks of the Bosphorus between Asia and Europe, in Istanbul, Turkey. This summit is the last meeting of the global Internet community for the year 2024 before turning to 2025.

Tripti Sinha, who has just been reappointed Chair of the ICANN Board of Directors, opened her remarks at the Opening Ceremony of the 81st ICANN Summit with the observation: ‘The past year (editor’s note: 2024) has been a complicated for ICANN’.

ICANN, an organisation challenged on several fronts

Tensions between Russia, China and the West have never been so high. A geopolitical context that is putting the multipartite model of a globalised Internet under pressure, as ICANN is an organisation governed by American law, even if it claims to be apolitical. The conflict in the Middle East is never far away either. In particular, it has resurfaced at previous ICANN summits this year. Challenged about its role and legitimacy, ICANN is also faced with the change of presidency in the White House with a second term for Donald Trump, which gave rise to some unusual questions at the public forum that closed the summit. One participant referred to the unpredictability of the future President of the United States, which ‘increases the risk of conflict’, going so far as to wonder whether ‘ICANN can take control of American military systems’. While the answer to this question is, of course, no, Tripti Sinha has also raised the issue of ICANN’s liability, with legal action being taken against ICANN, and financial challenges, speaking of ‘financial difficulties’. ICANN’s operating costs have risen significantly in recent years, partly as a result of inflation. Inflation has led to significant increases in domain name prices, which in turn have led to a downturn in the market. ICANN, which derives part of its resources from domain names in return for a tax on each generic domain name, has also been affected.

A transition of presidency at the head of the organisation

Erik Lindqvist, the new President of ICANN, will officially take office on 9 December 2024.
Erik Lindqvist, the new President of ICANN, will officially take office on 9 December 2024.

At the opening of the summit, Erik Lindqvist, the future President of ICANN, gave a short speech to introduce himself and talk about his career. He will officially take up his new post on 9 December, taking over from Sally Costerton, who was applauded for her successful interim role.

Among the tasks expected of the new President, who will be based in Geneva, Switzerland, is a review of the organisation’s financial situation. Avenues for savings and new sources of funding were discussed, and a number of clear-cut opinions emerged. For example, should attendance at summits be made fee-paying, or should the venues chosen for these international meetings be rationalised to generate savings? The interaction of the new President with the various bodies is also expected and acclaimed. Defending the multi-stakeholder governance model in the current difficult context and ICANN’s ethical policies are two other important issues raised by the contracting parties.

New series of new generic extensions confirmed for 2026

Among the difficulties, ICANN must also succeed with the new series of new generic extensions. First of all, this means meeting the April 2026 deadline for the application window, a date that has been hammered home for several summits. Reassuringly, the recommendations of the Subsequent Procedures (Subpro) policy development process are being implemented at a good pace. The future application guide is on schedule, with a final version due to be delivered within a year. The future registry contract for new registry operators is also being considered. Unlike the candidates for the 2012 round, this new contract should be a single document covering all types of TLDs: open, community, brand and internationalised (editor’s note: in native language). It will include fourteen specifications, compared with the current thirteen, with the fourteenth covering TLD variants for multilingual TLDs.

Other issues on which ICANN reached a decision, there should be no private auctions to decide between candidates for the same TLD in 2026. Like a symbol or perhaps a marker, at the very end of the summit, the ICANN Board adopted the applicant support program for future applicants, a program that will involve a communications campaign in disadvantaged geographical areas at the beginning of 2025.

Capitalising on experience feedback

A number of issues recently initiated by ICANN are currently being evaluated. These include abuse of the domain name system. In April 2024, specific obligations came into force to compel registries and registrars to take action in the event of clear abuse. ICANN81 provided an opportunity to take stock of these measures after an initial six-month implementation phase. ICANN Compliance reports that it has initiated 363 complaints, often involving several domain names. Unsurprisingly, the most common abuses involved phishing campaigns.

Another element being tested is the Registration Data Request Service (RDRS). This is a prototype designed to gauge interest in a standardised platform for submitting and processing requests for access to domain name registration data for legitimate purposes. Over the course of a year, the RDRS collected requests for 13,000 names, a volume that remains low compared to the 170 million generic names. A related issue is the depreciation of the Whois protocol for domain name registration databases. This protocol, which has been in use since the 1980s, is due to give way to the RDAP protocol for generic domain names at the end of January 2025. ICANN Org has pointed out, however, that this new protocol is very rarely correctly deployed at this stage.

The tense international context was largely reflected at this summit on an organisation that will be starting 2025 with a new president at its head and a change of administration in the White House. ICANN has made no secret of the fact that it is facing a number of difficulties. The success of the next series of new gTLDs, a series that will have taken fourteen years to complete between 2012 and 2026, will be decisive in helping the organisation to emerge from this turbulent period. The stakes are high, firstly because ICANN is committed to holding this series in April 2026. A postponement of the date would further damage its credibility.

This series is also important given the investment required to prepare and hold it. The significantly higher application fees than in 2012, with a base amount of USD 227,000, may act as a brake. Investors, for their part, may not appreciate the abolition of private auctions to decide between applicants for the same TLD, with ICANN seeking, on the contrary, to curb speculation.  Nameshield, for its part, is convinced of the merits of this new round and, in particular, of dot brand extensions, the benefits of which will more than offset the investment required if applicants are properly accompanied. Nameshield is ready to help future project owners by providing them with a complete solution for their entire project cycle. If you have an Internet extension project, contact our experts who will be delighted to support you.

SSL/TLS certificate duration reduced to 45 days by 2027:Apple takes the first step

On October 9, Apple revealed to the CA/Browser Forum that it had posted a draft ballot for comment on GitHub regarding two important SSL/TLS certificate lifetime events:

  • Gradually reduce the maximum duration of public SSL/TLS certificates to 45 days by 2027;
     
  • Gradually reduce the reuse period for DCV challenges to 10 days by 2027.

In March 2023, in its “Moving Forward, Together” roadmap, Google announced its intention to offer the CA/B Forum a reduction on the maximum possible validity period for public TLS certificates going  from 398 days to 90 days. Since this announcement, the market has been feverishly awaiting for Google’s confirmation but most of all, for the implementation’s timetable… without success. For its part, Mozilla announced, a few weeks ago, its intention to follow Google’s lead on its Firefox browser, without adding any further detail.

Apple ultimately took the first step last week, announcing on October 9th its intention to both reduce the lifetime of certificates to 45 days (when the entire market was expecting 90 days) and to limit the duration of the DCV challenge to 10 days, according to the schedule below. A true bombshell:

Sep-15-2025 => certificates and DCV validation times reduced to 200 days

Sep-15-2026 => certificates and DCV validation times reduced to 100 days

Apr-15-2027 => certificates and DCV validation times reduced to 45 days

Sep-15-2027 => DCV Validation time: 10 days

Information on the background and analysis of this announcement, the expected outcomes and how to prepare for them will undoubtedly be useful:

Context and Analysis:

At this stage, the publication is likely to be commented by market players prior to the formal drafting of the ballot within the CA/B Forum, which itself will be voted on by its members: the Internet browser publishers on the one hand (Google, Mozilla, Apple and Microsoft…) and the Certification Authorities on the other. Amendments are bound to be made, but the general idea remains and the machine is up and running.

Indeed, software publishers are all aligned on the need to reduce the lifetime of certificates, and among Certification Authorities, Sectigo, one of the major players in the certificate industry, is already supporting the initiative. It is likely that things will move rapidly from now on, with few comments and a ballot drafted in the coming weeks or months. We will then know more about the confirmation of the durations and timetable, and will of course make sure to keep you informed.

Expected Outcomes:

  • Certificate lifetime: whether 90 days, 45 days or even less, this reduction is no longer a surprise, and will have a major impact on public certificate portfolio. The certificates can no longer be managed manually. The market has begun its transition to automation, notably through CLMs (Certificate Lifecycle Managers). The issue at stake for companies and organizations will be to rely on partners who can offer as many interconnections as possible between Organizations, Certification Authorities and CLMs.
     
  • DCV challenge duration: Reducing the duration of the DCV challenge to 10 days, if validated, would have a considerable impact, perhaps even more so than reducing the lifetime of certificates. Up until now, the industry has pre-validated domain names for 398 days, using the DCV challenge only once. Apple’s announcement would thus force the use of a DCV challenge for virtually all orders, which would be a major paradigm shift and would involve interconnections with an additional brick in the ecosystem: the DNS. The DCV (Domain Control Validation) challenge involves intervening in the zone of the domain name(s) listed in the certificate, ideally instantaneously, to validate it.
     
  • Organization authentication duration: Apple has not announced anything on the subject of the validity period of organization authentication for OV certificates, which is currently 825 days. However, rumors are circulating that this may be reduced to 398 days or even 365 days.

How to be ready:

The key to successful certificates management lies in automation. A 45 days certificate lifetime represents 9 interventions per year per certificate. Manual management thus becomes utopian. We therefore need to rely on:

  1. Certificate Provider/Certification Authority (CA): a trusted partner who will support through your organizational and domain authentication issues. Service level is key to good management. A multi-CA partner is thus recommended to limit dependence on a single CA, as in the case of Entrust’s recent setbacks. 
     
  2. Registrar / Primary DNS: mastering the primary DNS of domain names listed in certificates will become the key to delivery. Each time a certificate is issued, a TXT or CNAME will be installed on the zone(s) in question. An interconnection between the CA and the DNS is vital.
     
  3. CLM editor: the CLM’s role is to inventory the certificate portfolio, to define certificate portfolio management rules and automate the entire process of orders, from the generation of CSRs to the deployment of certificates on servers. To function properly, the CLM relies on connectors with CAs or certificate suppliers.

Getting ready thus means identifying the most suitable solution, based on these three dimensions, and undertaking this analysis to understand the impacts in terms of process, technology, and budget – in an ideal world – before the end of the first half of 2025.

Nameshield’s approach:

Nameshield holds a unique position in the market as a registrar and supplier of multi-AC certificates. For over 10 years, we have been managing the day-to-day issues associated with authenticating organizations and domains using certificates. On the one hand, we have a privileged relationship with the biggest CAs on the market (Digicert, Sectigo, GlobalSign), and on the other, we master the DNS brick for DCV validation. As a result, we can issue public certificates almost instantaneously. Last but not least, Nameshield has connectors with the major players in the CLM market, allowing you to ensure a comprehensive connection between the various components involved in certificate management. This way, we can support you in anticipating all the issues mentioned above.

SSL/TLS certificate duration reduced to 45 days by 2027:Apple takes the first step

For more information, please contact our Sales team or our Certificates team.

Nameshield will be at the 38th Annual Marques Conference – From September 24 to 27, 2024 in Stockholm

Nameshield will be at the 38th Marques Annual Conference

Join the Nameshield team at the 2024 Annual Marques Conference, taking place from September 24 to 27, 2024 at the Radisson Blu Waterfront Hotel in Stockholm.

Nameshield is an ISO27001-certified software publisher and sovereign registrar, with 30 years of experience, that protects and defends its customers’ strategic domain names against cyber threats.

We consider that protecting online brands is more crucial than ever in the face of an increasing number of infringements, including:

  • Cybersquatting, which can damage brands’ reputations and mislead customers,
  • Fraud and scams, where similar domain names are used to create fraudulent websites, counterfeiting or fake shops,
  • Customer diversion, which redirects customers to competitors or malicious sites and trigger the loss of customers’ confidence in the brand, and in turn, the loss of revenue.

Nameshield has consequently developed a Brand Safety Chain (BSC) solution in order to shield brands’ safety, integrity, reputation and revenue in the digital ecosystem, with:

  • Continuous domain name monitoring and detection of fraudulent domain names,
  • Remediation services and support on the best action plan and procedures to implement.
  • Anti fake shop solutions, including detection, analysis reports and takedowns.

Come and meet us at stand 7.

Our team of trademark and intellectual property experts will be there to answer all of your questions.

For more information, please visit the event website : 2024 Marques Annual Conference.

ICANN80: Rwanda joins the small circle of sub-Saharan states to have hosted ICANN

ICANN80: Rwanda joins the small circle of sub-Saharan states to have hosted ICANN

Following on from Paris, which hosted the ICANN Contracted Parties Summit last May, the Rwandan capital has just hosted its first ICANN Summit devoted to Internet governance policy issues. Here’s a look back at what we learned from the event.

ICANN has found its new face

ICANN80 kicked off with the official appointment of Kurt Erik “Kurtis” Lindqvist as the future President and CEO of the organization. The 49-year-old Finn will officially succeed his predecessor Goran Marby, of Swedish origin, who resigned at the end of 2022. Sally Costerton’s interim appointment will therefore end on December 4, 2024, with Mr. Lindqvist officially taking office on December 5, 2024. Mr. Lindqvist has been CEO of the London Internet Exchange (LINX) since 2019. His appointment is the culmination of a long process that began with the creation of a search committee for a CEO. Initially, some 100 candidates representing over 20 countries in North and South America, Africa, Europe, Asia and Australasia were identified. After further evaluation, the list was whittled down to seven people (three women and four men) who were interviewed by the CEO’s selection committee. The selection process ended with the ICANN Board unanimously approving the choice of Mr. Lindqvist at a session held just before ICANN80. A first, the new CEO will be based in Geneva in Switzerland.

Spotlight on the Internet in Africa

You have to go back to June 2017 to find a city in sub-Saharan Africa hosting ICANN. Johannesburg, South Africa’s most populous city, hosted ICANN59. In June 2024, ICANN finally returned to Africa, with Rwanda as host country. A very good thing, given that Africa is still largely under-resourced when it comes to Internet access. The International Telecommunication Union estimated that by the end of 2021, 14.3% of African households had access to the Internet, compared with 57.4% worldwide. Fixed Internet connection is also more expensive than in other regions of the world in proportion to income. It represents 18.6% of gross national income (GNI) per capita, compared with a global average of 2.8%. The GAC, the body representing governments at ICANN, took advantage of the event in Kigali to organize a “High Level” governmental meeting. This brought together 50 countries with four sessions on the multi-stakeholder model, cooperation and governance, digital inclusion and support for connectivity. These issues are also at the heart of the United Nations’ Global Digital Compact, which calls for a more inclusive and equitable Internet. The African At-Large Regional Organization (AFRALO), one of the five At-Large regional organizations within ICANN (At-Large represents end-users), kicked off ICANN80 week with a round-table discussion on improving Internet infrastructure in Africa. For its part, ICANN Org recalled during the week’s Summit that in 2022 and 2023 two root servers have been made operational in Nairobi, Kenya and Cairo, Egypt. Most DNS root queries based on Africa therefore are now resolved in Africa. For example, the root server in Nairobi, Kenya, handles 40% of all DNS root requests for the continent. Prior to its installation, 35% to 40% of DNS query traffic traveled outside Africa for resolution. The two installations also increase the resilience of the global root server system for Internet users on the continent, and help to cope with the exponential increase in traffic expected on the continent over the next few years.

The promise of the next round of new generic extensions : an estimate of application fees finally made public

No fewer than eight sessions held on the first day of the summit addressed the future series of new generic extensions. ICANN Org pointed out that this program is designed to make the Internet more inclusive, relying in particular on the success of Internet extensions in users’ own languages – the so called internationalized extensions or IDNs. To date, there are 91 internationalized extensions among the 1172 generic extensions, a relatively low proportion. In country-code Top Level Domains (ccTLDs), the proportion of internationalized extensions is almost three times bigger, representing nearly 20% of the total. ICANN Org promotes this new series by pointing out the opportunity to create new generic extensions in native languages. For its part, the GAC is pushing for greater support for less-favored geographical areas. The intention is to make the new program more accessible to these areas with financial and operational support. ICANN Org has considered an amount of 2 million USD for this item, whereas the GAC estimates that the needs are more in the region of 10-16 million USD. The GAC has indicated that it hopes to be able to support at least 45 applications. 

These considerations obviously have to be set against the costs of a future application for a new gTLD project. On this much-anticipated point, ICANN Org has presented projections based on the number of applications received. While in 2012 there were 1,930 applications leading to some 1,240 delegated extensions, some of which have since been abandoned, we don’t know how successful the next round, which opens in April 2026, will be.

To recover its costs, ICANN Org estimates that the application fee should be 293,000 USD for 500 applications, 242,000 USD for 1,000 applications and 208,000 USD for 2,000 applications. In 2012, the application fee was 185,000 USD. It should also be noted that the median value of application fees submitted is around 259,000 USD.

A partial reimbursement of costs is considered if the costs retained prove to have been overestimated in view of a higher-than-estimated volume of applications. The question has been raised of how to reduce these fees, which means cutting budgets. ICANN Org has indicated that 13 million USD will be allocated to this program over 2025, for example, in staffing costs. As ICANN already has an operating budget that covers its payroll costs, question has been raised if these expenses are not covered twice (by the operational budget and the new gTLD program budget).

DNS abuse: first lessons from the contract amendments

ICANN80 was also an opportunity to take stock of the implementation of contractual amendments by registries and registrars to include remediation obligations for obvious DNS abuses such as phishing, malware or pharming practices. These measures came into force on April 5. ICANN’s Compliance Department reported that it had received 1,558 abuse-related complaints. 1,382 were invalid, either because they were not sufficiently substantiated or documented, or because they fell outside the organization’s scope of action. Some of them concerned ccTLDs (country code Top Level Domains) where ICANN has no jurisdiction. ICANN also reiterated that obvious abuses must first be reported to the registry operators and registrars who manage the concerned domain names.

ICANN80 remained above all a working summit with few announcements even if the new face of the organization was made official, information that nevertheless had been leaked a few days earlier. The appointment of « Kurtis » Lindqvist should not overshadow the fact that Sally Costerton has been acting as interim president of the organization for almost a year and a half now, and that during this time her determination has undoubtedly ensured that some topics move significantly forward, in particular the next series of new generic extensions which is now well underway. Work on implementing the policies and the future bidding applicant guide is progressing, and the bidding window envisaged for April – June 2026 now seems attainable. The range of application fees announced remains imprecise, ranging from 208,000 to 293,000 USD, depending on the volume of applications expected. While internationalized extensions were in the spotlight, it is above all geographical extensions and trademark extensions, the so called dot brands that are the most relevant. They will be an ally in the service of the security, performance and reputation of their owners. A genuine asset in an increasingly complex regulatory and legislative environment where cyber attacks are becoming increasingly sophisticated.  To make a success of your future extension project and benefit from optimized solutions for your online assets, the key is to be well accompanied.

From May 7 to 9, Paris hosted the ICANN Contracting Parties Summit

From May 7 to 9, Paris hosted the ICANN Contracting Parties Summit.

The last time Paris hosted ICANN was in 2008 for ICANN32. Sixteen years later, ICANN returns to the French capital for the Contracted Parties Summit. The latter is a special event in the organization’s agenda, as it is not a policy-oriented event like the three annual summits flanked by the edition number (Editor’s note: ICANN79, for example). Before the covid pandemic, ICANN met its stakeholders once a year at a dedicated event. These summits, highly focused on operational aspects, only resumed in 2022 and now only take place every two years.

Over the course of three days, the contracting parties – registry operators and registrars – have the opportunity, during working sessions, to communicate their needs to the organization by directly questioning the ICANN Board of Directors, and to exchange views on common issues. In particular, these meetings provide an opportunity to compare approaches to policy changes and contractual modifications to be implemented, while also taking into account changes in the regulatory and legislative framework. One of the three days was entirely devoted to workshops on the abuses to which the contracts of the contracting parties have evolved in 2024.

Although only 150 to 250 people in total took part in the event, with the public holiday no doubt having a negative impact on attendance, it has to be said that there was plenty to do on the subjects that directly impact the contracting parties.

As a consequence of the GDPR in force since 2018, a perennial policy, the Registration Data Policy has just been promulgated to replace the Temporary Specification. This must be implemented by August 2025. Stakeholders also had to implement two amendments to their contracts with ICANN. The first was a protocol transition from Whois to RDAP (Registration Data Access Protocol). The second concerns abuse, with new obligations that make contractors more accountable in the event of proven abuse. The summit provided an opportunity to hear initial feedback on this major issue, to which some service providers are more exposed than others. To this the legislative framework can be added, in particular the European NIS2 cyber security directive, which will also have a major impact on registries, DNS resolution service providers and registrars.  It will come into force in October of this year. The most advanced countries in terms of transposition into national law, notably Croatia and Belgium, have shown that they are fully in line with the initial text voted by the European Parliament at the end of 2022. And the next round of new generic extensions must be prepared for the next application window announced for April 2026.  

From now on, ICANN will be meeting the Internet community in Kigali, Rwanda, from June 10 to 13, to discuss developments in Internet naming policies. This will be ICANN80.

.TR: Extended priority period for the .TR extension in category 3

.TR Extended priority period

On February 14, we announced the opening of .TR registrations in category 3. This period was initially open until May 14, 2024.

TRABİS recently announced that this priority period for the “.TR” (category3) application for domains holders will be extended until August 7, 2024.

You still have until August 2024 to apply for a .TR equivalent to your existing .COM.TR / .ORG.TR / .NET.TR domain names.

The .TR opening to all is therefore also postponed, and will be announced at a later date.

Do not hesitate to contact your consultants and account managers if you have not yet reviewed your domain names portfolio in Turkey.

User trust at the heart of the latest CSA Summit in Cologne

From 22 to 24 April, Cologne hosted the Certified Senders Alliance Summit on the theme of “Trust fuels the future”. The event marked the 20th anniversary of the initiative.

Corporate communications have changed dramatically over the last 20 years with the rise of social networks. For example, Instagram now has more than 2 billion monthly users, YouTube more than 2.5 billion and Facebook more than 3 billion. These platforms were all launched between 2004 and 2010. While they have become an integral part of companies’ communications plans for addressing their users, the use of email is still very high, as there are still so many uses for email: sending email campaigns, newsletters, invoices or for example order confirmations. According to Statista, the overall volume of emails increased by 4.3% in 2023 compared with the previous year, with almost 347.3 billion emails sent worldwide every day. Another fact: on average, a person receives around 121 emails a day. These figures underline that email is not about to disappear.

Gartner nevertheless points out that concerns about email security are growing, with few companies escaping security incidents, with increasingly sophisticated phishing attacks using malicious links or attachments, for example, and data losses often linked to careless behaviour or human error. With this in mind, every year CSA brings together experts from the email ecosystem to discuss best practices and solutions for improving email quality and trust. The event is organised around a series of workshops, sessions, conferences and masterclasses.

Nameshield, which sponsored the event, pointed out that there can be no email security without secure domain names, which are critical business assets, and without a robust, high-performance DNS infrastructure. Email security therefore depends on the choice of your domain name provider and the cyber-security solutions it is able to offer its customers. These include the DMARC protocol, which protects users against fraudulent messages. Customised brand extensions also known as dot brands are another way of building brand confidence in the run-up to the next round of new generic extensions scheduled for April 2026.

Contact your Nameshield consultant for more information on all our solutions.

ICANN79: A summit that builds on decisions taken in 2023

ICANN79

After ICANN29 in 2007 and ICANN61 in 2018, Puerto Rico hosted its third Internet Governance Summit, ICANN79, at the beginning of March. Six days of meetings, exchanges and encounters in a studious atmosphere, with ongoing issues moving forward. The star topic: the next round of new generic extensions. Other major subjects, such as the NIS2 European cybersecurity directive and the appointment of a new President for the organisation, were discussed on the sidelines.

Three women at the centre of ICANN: Tripti Sinha on the left, Manal Ismail in the centre and Sally Costerton on the right

The next round of new generic extensions, a priority topic

On Saturday 2 March, the launch day of ICANN79, a session was held on the implementation of the recommendations from the Subpro policy development process (PDP), which aims to enable the launch of the next series of new generic Top level domains. This constituted an initial focus on this central issue, which is now bound to come to a conclusion as the next application window has been set for April 2026.

At this first session, attention was focused on the recommendations that the ICANN Board had not adopted as part of a resolution on the PDP passed in March 2023. At the previous summit (ICANN78), 14 recommendations remained outstanding, 6 were rejected. The body responsible for generic policies, the GNSO (Generic Naming Supporting Organization), which has got into the habit of creating small teams to work on blocking issues, has invited a small team to address these recommendations. At the same time, an implementation team is working on other recommendations approved by the ICANN Board and on the new version of the Applicant guide book. This central document for future applications is currently being written. Its finalised version should be available by the end of next year at the latest. At the end of ICANN79’s week of debates, it was clear that the work carried out during the many sessions on the next round had been fruitful. The Small Team found a compromise on the recommendations not approved by the ICANN Board and was even able to avoid a meeting scheduled in the summit agenda.

At least twelve ongoing topics

A GNSO session on Sunday provided an inventory of the policy development processes underway and those still being studied, such as the accuracy of registration data. The list includes at least twelve topics, some of which are blocked and where, due to the length of the process, the history is sometimes difficult to find for current GNSO members. This is the case for the protection of the names of inter- and non-inter-governmental organizations. Examples include the International Olympic Committee (IOC) and the Red Cross. In 2012, a PDP was launched to study the question of specific protection for the names of these bodies, bearing in mind that the contracts of the registry operators of the new generic extensions resulting from the 2012 round require them to be blocked from registration. At the beginning of 2019, the ICANN Board adopted the final recommendations of an extended PDP, which should enable them to be implemented. However, the body representing governments, the GAC, considered that not all the issues had been addressed, in particular that of specific protection for the acronyms of these organizations. This issue is still open today, and the recommendations have not yet been implemented.

Three women honoured at the Opening Ceremony

Monday marked the official launch of the summit, with the much-anticipated opening ceremony, which always takes place on a Monday morning. Tripti Sinha, Chair of the ICANN Board of Directors, recalled that the previous ICANN summit in San Juan took place “just after the devastating hurricane Maria”. She also referred to 2023, a year in which Sally Costerton took on the role of interim President of ICANN and in which ICANN celebrated its 25th anniversary in Hamburg. On the appointment of a new President for ICANN, participants were informed that the process is underway after listening to stakeholders in 2023. A group of candidates has emerged and will now lead to the selection of the future ICANN President and CEO. For her part, Sally Costerton repeatedly used the expression “superpower” to refer to ICANN’s mission to maintain a single global Internet. A difficult mission in a shifting geopolitical and technological context. But perhaps the most striking moment of the summit was the image of a third woman, Manal Ismail, who joined Tripti Sinha and Sally Costerton at the opening ceremony. Manal Ismail, who played an important role in the IANA transition and as chair of the GAC for more than five years, was honoured with the ICANN Community Excellence Award 2024.

Decisive milestones reached in 2023 which will materialize over the next three years

To the credit of ICANN’s current president, it must be said that many issues have moved forward under her leadership in 2023. If 2024 marks the entry into force of new obligations for registries and registrars on malicious uses, this is indeed the fruit of the work carried out last year. This central issue for Internet users had given rise to years of fruitless debates. The next round of new generic TLDs has made significant progress, with the adoption of recommendations and a roadmap towards a new application window now set for April 2026. We can add the Registration Data Policy, which will replace the Temporary Specification resulting from the GDPR (General Data Protection Regulation) by 2025. A related issue is the future Standardized System for Access to registration Data, which has entered an experimental phase in an attempt to reconcile protection with the need to respond to real needs for access to registration data. The inclusive Internet is entitled to a dedicated international day following the launch of the first UA Day (Universal Acceptance Day) in 2023. Finally, “ICANN grant”, a programme aimed at financially supporting projects to unify and make the Internet more inclusive, has also been launched. It is based on the substantial amounts raised by the 2012 auctions of new generic extensions. An envelope of USD 10 million will be allocated at the end of March.

We’re not winning on all fronts

While progress has been made on a number of fronts, there has been little progress on others. This is the case with a new holistic review of ICANN and the review of the organisation’s Accountability and Transparency. These reviews are necessary to bring about improvements in security and consumer choice, in the services associated with domain name registration databases, and in the security, stability and resilience of the DNS. This important subject is impacted by the many projects currently underway, and ICANN has also embarked on a continuous improvement project that could replace these processes.

As far as the European directive on NIS2 cybersecurity is concerned, the main point to note is that the contracting parties and the ICANN Board of Directors have emphasised that this legislation does not conflict with the ICANN policies in place. For the Board, which has indicated that it is working with the European Commission on this subject, there are, however, issues such as data accuracy that need to be considered.

While ICANN79 was not the subject of any noteworthy announcements, the main thing to remember is the studious atmosphere after a pivotal year in which many subjects passed decisive milestones towards their implementation. This is the case for the next series of new generic extensions, the previous one having been introduced twelve years ago. If a form of agility seems to have won over ICANN under the leadership of Sally Costerton and Tripti Sinha, this approach is also that of Nameshield, which adapts to your needs to provide you with tailor-made answers on the new TLD projects and many others.

Artificial intelligence, NIS2 Directive, our society model: some of the topics debatted at Domain Pulse 2024

On 22 and 23 February, Domain Pulse was held in Vienna, Austria. This symposium brings together all the stakeholders in the domain name industry once a year around the registries of Austria (nic.at), Germany (DENIC eG) and Switzerland (SWITCH). The event was a resounding success, with a mix of conferences and networking opportunities.

Domain Pulse 2024
Neil Harbisson, the “cyborg artist” as he describes himself attracted a great deal of attention

For those who thought that cyborgs – human beings who have been grafted with mechanical or electronic parts – only existed in science-fiction literature or cinema, such as Fritz Lang’s masterpiece ‘Metropolis’, released almost 100 years ago, Domain Pulse 2024 was a wake-up call. The event’s star guest, Neil Harbisson, a self-styled cyborg artist, caused quite a stir at the opening of the event. The British artist was the first human to have an antenna implanted in his skull, back in 2004. This additional “organ” enables him to perceive colour frequencies differently. With the help of a software layer, he can even translate these perceptions into sound. He likes to explain that he can “eat songs” by transforming the perception of a dish into sounds, or “make sound portraits” of people. He shared that “King Charles III was able to listen to his sound portrait”. He also explained that for him, skin colours are simply variations on the colour orange. Another facet of his transformation is the “obstacle course” he went through to obtain the possibility of renewing his passport. Grafting technological tools raises ethical issues and is not normally allowed on passports. In the end, however, he obtained the right to have a passport with his antenna on his photo. To hear him tell it, augmented reality is already a thing of the past, since we are now talking about revealed reality.

He did not, however, overlook the fact that, like all technologies, these have their share of promises and dangers. In the case of the former, more impactful uses are possible, such as the fact that such “organs” could one day enable humans to “see at night”, thus saving energy, or to “regulate their body temperature instead of air-conditioning”. On the downside, there are risks of infection or clinical rejection, tools that are still dependent on conventional energy sources, problems of acceptability to society and, of course, the risk that these tools will be hacked, with impacts that are difficult to identify and assess.

The NIS2 directive also featured prominently in the discussions at Domain Pulse. This cybersecurity legislation must be transposed into the national laws of the Member States of the European Union by 17 October 2024 at the latest. At Domain Pulse, DNS service providers were warned that they will have to upgrade their cyber capabilities, risk management and reporting capacities, as well as cooperation and information exchange – the three pillars of the directive. On Article 28 of the text, which specifically targets domain name registration databases, a panel of specialists questioned the consistency of the approach: “The European Commission is going back on the accuracy of registration data and legitimate interests. This cyber approach runs counter to the need to publish less data”, said Thomas Rickert.

Other notable presentations included a reflection on our model of society around the question “Is the future in the virtual communities that will replace states? A projection by the Einstein Center allowed us to project ourselves into such a model.

The second day of the event focused on Artificial Intelligence. Implemented in a wide range of fields, AI has already shown that it is capable of surpassing human capacities. Its ability to adapt was also discussed, using the example of captcha input. Captcha are tests based on human image or sound analysis capabilities that differentiate automated requests from human requests. ChatGPT did not manage to enter a captcha, but went to a website where it is possible to request human assistance for specific needs. In the help forum, the support team asked ChatGPT if it was a robot. As a human would probably have done to achieve the desired end, ChatGPT lied and replied that it was not a robot. As if to echo the technological bodies mentioned the day before, AI offers interesting prospects for making faster progress in sectors such as research, for example. But the other side of the coin is that AI can be used for malicious purposes. Just as there is the Dark Web, there is also Dark AI. AI is capable of creating phishing emails and scams (internet fraud). It will become increasingly difficult to tell the difference between what is real and what is fake, for example with deepfakes (editor’s note: multimedia synthesis techniques based on AI that can generate fake audio or video sequences).

Another challenge and issue of the moment is the war on Europe’s doorstep. The Ukrainian conflict was discussed in the form of feedback from the Ukrainian registry operator in the context of the war and the lessons learned from an operational point of view. These included the preferred use of hosting companies offering a resilient infrastructure and “SMEs which are more responsive than large structures”, “choosing the right people to work with” and the fact that in a crisis situation “people are more reliable than machines”.

Domain Pulse 2024 skilfully reconciled issues specific to the domain name industry, such as cybersecurity and the regulatory aspect of the NIS2 directive, as well as technological issues. Feedback from the Ukrainian registry echoed Nameshield’s values and customer approach and solutions. This Domain Pulse also provided an opportunity for participants to reflect on the model of society we want for ourselves and our children, as humanity seems to be at a turning point in this area.

Nameshield at the CSA Summit in Cologne – From April 22 to 24, 2024

Celebrate the 20th anniversary with us and be part of the discussion about the future of commercial emails.

For 20 years, the CSA (Certified Senders Alliance) has been committed to strengthening trust in email as a communication channel. Building bridges between email senders and email providers has been the central goal of the CSA from the very beginning – this year’s anniversary summit will examine the success factors of the future under the motto ‘Trust Fuels the Future’.

Nameshield is a Gold Sponsor of the event – our team would be delighted to meet you there. Gain market-leading expertise with CSA’s insights and evolving best practices. We are particularly looking forward to the discussion around the implementation of DMARC, which is becoming a new standard.

Join an international network of brands, agencies, email service providers and mailbox vendors for a dynamic exchange of information in the well-connected email ecosystem! The CSA Email Summit is not just an event, it’s your path to realising your full potential in the ever-evolving landscape of commercial email.

The CSA Email Summit is supported by various industry associations and provides a solid platform for conversations that offer valuable insights into the future of email marketing. Learn from industry experts in workshops, sessions, short talks and masterclasses to enhance your expertise.

Please contact the Nameshield team for more information and to make an appointment at the Summit!