ICANN78: Ahoy, the ICANN boat sails for 25 years

From 21 to 26 October, Hamburg in Germany, hosted the 78th ICANN Summit, the Internet’s regulatory body. Hamburg, the connected city par excellence and Germany’s leading intelligent city, succeeds Berlin as the second German city to host such a summit. Berlin hosted ICANN2 in 1999. This 78th edition brought together more than 1,600 participants from 175 countries and territories. It also marked the 25th anniversary of ICANN and the 20th anniversary of the Generic Names Supporting Organization (GNSO), the body responsible for policies applying to domain names in generic extensions.

De Elbschippers at the ICANN78 Welcome Ceremony, on October 23, 2023
De Elbschippers at the ICANN78 Welcome Ceremony, on October 23, 2023

ICANN faces new challenges

“On 30 September 1998, ICANN was incorporated as a private, not-for-profit organisation in the State of California”. With these words, Tripti Sinha, the Chair of ICANN’s Board of Directors, began a dense speech at the Welcome ceremony of ICANN78. She reminded us that most of today’s Internet tools, including smartphones, have been developed and launched during this period, and that while “25 years is not much”, “the world has changed remarkably” in the meantime. Today, it is the context of wars and technological transformations, in particular “artificial intelligence and quantum technology”, that constitute major challenges for the multiparty model. To these can be added alternatives to domain names that use the DNS, such as blockchain domains, which are outside the scope of ICANN. These were highlighted at ICANN78. Their protagonists like to call them “domain names”, while others would like to differentiate them by talking about “wallet domains”. ICANN’s interim President, Sally Costerton, made a point of emphasising the word “trust” in her introductory speech. “Trust is a fragile thing” she said, “difficult to build and easy to lose”.

On the subject of trust, Sally Costerton pointed out during the ICANN Board’s question and answer session that significant progress has been made on a number of important issues since her appointment in December 2022. In March of this year, for example, the first international Universal Acceptance Day was held, or how to make the Internet more inclusive and thus closer to the way its users use it. At the ICANN76 summit, also in March, the next series of new generic extensions was confirmed. More recently, the Registration Data Request Service (RDRS), a prototype of the future System for Standardized Access to Domain name registration data (SSAD) for legitimate requests, was launched. And the year 2023 will have seen a concrete proposal to strengthen the means of combating abuse of the DNS after years of fruitless exchanges. A proposal to revise the contracts of registry operators and registrars is currently being put to a vote by the parties concerned, with adoption expected between December 2023 and January 2024.

Registration Data Policy: Let it go let it go

The fact that ICANN represents numerous sensibilities whose interests are often divergent, but also that it operates with consensus as its totem, partly explains why the finish line is often far removed in time from the starting line. The Registration Data consensus Policy has not escaped this reality. This policy is intended to replace a Temporary Specification implemented as a matter of urgency on 17 May 2018, eight days before the General Data Protection Regulation (GDPR) came into force thus to integrate the GDPR requirements into the DNS ecosystem. The Registration Data Consensus Policy is the culmination of phase 1 of a Policy Development Process (PDP) initiated on this occasion. While a final report with a view to its implementation was issued at the beginning of this year, it was ICANN78 that enabled the implementation review team work to be concluded. The blocking point on the wording relating to the deadlines granted to operators to deal with urgent requests for access to registration data in the event of law enforcement, could be removed. The policy, which now has a permanent framework, will now be implemented by the parties concerned, registry operators and registrars.

The next round of new generic extensions

The next round of new generic extensions remained another major topic of this edition. While ICANN is now putting forward the date of April 2026 for the next application window (editor’s note: the previous window took place between January and April 2012), ICANN78 highlighted the progress made in implementing the recommendations arising from the Policy Development Process known as “PDP Subpro” (editor’s note: Subsequent Procedures). Earlier in March, some thirty recommendations had not been adopted by the ICANN Board and had been referred to the GNSO for clarification. Thanks to the work of a Small team, 12 additional recommendations have just been adopted by the ICANN Board, bringing the total number of adopted recommendations to 104. 13 remain in the balance and 7 have been rejected. For the latter, we will now have to assess their impact and consider remedies. The implementation team can therefore make progress on just over 80% of the recommendations arising from the Subpro PDP. The revised guide for future applicants is progressing in line with initial forecasts with at least 18 months to go.

The issue of closed generic extensions and diacritical letters

Considered but not proposed due to a lack of consensus in 2012, then discussed for five years, the topic of closed generic extensions was relaunched in 2022 with a view to a new series of generic extensions. In practice, they would allow organisations under certain conditions to use a generic term (editor’s note: for example .CHARITY) with the same rights as a brand extension. Access to the extension to create new domain names would therefore be very restricted. A year ago, a discussion group comprising the Governmental Advisory Committee (GAC), which represents governments, the At-Large Advisory Committee (ALAC), which represents end-users, and the GNSO was set up to try to address this issue. Last July, they proposed a framework detailing the many aspects to be considered to introduce this new type of extensions. However, at the end of their work, each body sent a separate letter to the ICANN Board of Directors, proof that their positions remained far apart. Barring any surprises, there should therefore be no closed generic extensions in the next round.

Québec, whose .QUEBEC was integrated into the DNS root in April 2014, has also invited itself into the discussions concerning the next series of new generic extensions. In 2012, Québec announced its wish to obtain .QUEBEC as well as .QUÉBEC. Although in the end they only applied for the non-accented version, they had hoped to be able to use .QUÉBEC as well. They were not granted this right because of a risk of similarity. ICANN78 highlighted the fact that perceptions remain different depending on whether or not .QUÉBEC is a variant of .QUEBEC. The pronunciation for French speakers is the same, but the presence of a diacritical letter (editor’s note: letters to which signs such as the acute accent, the grave accent, the circumflex accent, the umlaut are added) makes encoding in ASCII characters different and technically feasible. While their request has little chance of success, it has also served to focus attention on important issues for registry operators, where the answers provided are often ill-suited to their needs.

ICANN78 was ICANN’s last annual summit. All eyes now turn to 2024. A new year is approaching, which may or may not see the conclusion of contractual amendments to registry and registrar contracts, with specific obligations to remedy malicious use, the continuation of implementation work on the next series of generic extensions, the likely launch of an ICANN holistic review or even the prospect of the scheduled Sunset of the Whois protocol in early 2025.

For Europeans and companies operating on European territory, it is the NIS2 directive that will crystallise all attention, as it must be transposed into the national laws of the Member States by October 2024. On this subject, ICANN representatives indicated at the traditional closing Public Forum that the policies for generic extensions are not “in contradiction with the NIS2 directive and that the parties concerned have the latitude to implement measures to comply”. The European Top Level Domain Information Sharing and Analysis Center (European TLD ISAC) is to be commended on this point, as it will be a useful relay in implementing the NIS2 Directive in the domain name industry.

Nameshield, an independent European company that has been ISO 27001 certified since 2017, will comply with the directive and will be keen to help its customers to comply. Nameshield also has the expertise to manage your projects for new generic extensions.

Finally, in terms of leadership, the GNSO, the body responsible for generic extensions, now has a new Council team appointed at ICANN78, while ICANN Org will be appointing a new president in 2024. See you next year.

Image source : ICANN‘s website

[New gTLDs] Google launches .ING and .MEME

[New gTLDs] Google launches .ING and .MEME

Google enriches its catalog as a registry and launches two new extensions: .ING and .MEME.

Launch of .ING

With .ing, unleash your creativity and put your domain names into action: design.ing, writ.ing, lov.ing, eat.ing…

.ING launch schedule

  • Sunrise phase: from 20/09/2023 to 24/10/2023

Phase reserved for holders of trademarks registered in the TMCH.

  • Early Access Period (EAP): from 31/10/2023 to 05/12/2023

Anyone can register available domains in .ing for an extra fee, which decreases leading up to General Availability.

  • General availability: as of 05/12/2023

Registration of .ing domain names is open to all, on a “first come, first served” basis.

Launch of .MEME

Funny and easy to share, “memes” are phenomena that have been massively reproduced and adapted, and are driving the web today. With .meme, use the codes of web culture for your online presence.

.MEME launch schedule

  • Sunrise phase: from 20/09/2023 to 24/10/2023

Phase reserved for holders of trademarks registered in the TMCH.

  • Limited Registration Period (LRP): from 31/10/2023 to 28/11/2023

Reserved for content creators specializing in the creation and distribution of Internet memes.

  • Early Access Period (EAP): from 28/11/2023 to 05/12/2023

Anyone can register available domains in .meme for an extra fee, which decreases leading up to General Availability.

  • General availability: as of 05/12/2023

Registration of .meme domain names is open to all, on a “first come, first served” basis.

If you have any questions about registering your .ING or .MEME domain name, please contact your Nameshield consultant.

News from Turkey! Liberalization of the .TR

Changes in the administration of Turkish extensions

Domain names in Turkey have undergone a major process of change and development in recent years. Last year, we announced the liberalization of domain names under the com.tr, net.tr and org.tr extensions.

It’s now a project to open .TR live. The allocation of .TR will be carried out according to a defined schedule with categories under a process called “a.tr Transition Process“:

BTK announces the opening according to these 3 categories:

CATEGORY 1: since 14/09/2023 for a period of 2 months (end of period November 2023):

In this category, priority is given to holders of domain names with the extensions .gov.tr, .edu.tr, .tsk.tr, .bel.tr, .pol.tr and .k12.tr respectively.

For example, for the domain name turkiye.tr, the holder of the domain name turkiye.gov.tr has the right of priority allocation.

CATEGORY 2: from November 2023 to February 2024

In this category, priority will be given to holders of domain names with the “org.tr” extension assigned before 25.08.2023.

The category will be given priority to the following institutions (holder of .org.tr):

  • Professional organizations that are public institutions,
  • Public interest associations and foundations benefiting from tax exemption,
  • Professional organizations of employees or employers.

CATEGORY 3: the date has not yet been announced, but we can deduce that it will be from February 2024.

In this category, holders of domain names under these extensions will have priority: .com.tr, .net.tr, .gen.tr, .web.tr, .info.tr. For this last category, the rules have not yet been defined.

We will keep a close eye on future announcements of the registry and will keep you informed as soon as we have more precise dates for the last category. Please note that the dates of the different periods can be modified if necessary.

Don’t hesitate to prepare your orders and contact your consultants and account managers to review your domain names portfolio in Turkey.

ICANN confirms DENIC Services as sole ICANN designated registrar data escrow agent

ICANN confirms DENIC Services as sole ICANN designated registrar data escrow agent

In 2018, ICANN, which is in charge of allocating domain names and IP addresses, confirmed DENIC eG as the data escrow agent for registrars on behalf of the ICANN organization, alongside provider Iron Mountain, which has since been taken over by NCC Group. Five years later, on July 17, following a new call for tenders, ICANN has confirmed DENIC Services as its sole accredited escrow agent for the next five years. A fine recognition for this European player and subsidiary of DENIC eG, which notably manages .DE, Germany’s geographical extension with over 17 million domain names.

Stefan Pattberg, Director of DENIC Services, took the opportunity to answer our questions.

Could you please remind us what the role of a data escrow agent is?

It is important for the stability of the global Internet that domain names are not only being granted but accessible all the time, independently from the financial, operational, or legal status of the managing registrars or registries at a certain time. Obviously, the registration data is an important asset for a registrar or a registry, often the most important one, because it represents the relationship to the customer and is the source of income for the service providers. But it is not only of economic importance. There are also additional policy requirements and even legal regulation like GDPR to consider when handling such data.

The role of the Data Escrow Agent is to ensure that the registration data that is belonging to a domain is always safe and available, even in case that a registrar or a registry in charge of managing a domain are failing. In such a case the mission of the Data Escrow Agent is to release the registration data to another service provider taking on board the role of the previous failed party. That is a very important security feature for domain holders, making sure that their domain will always be available, and the ownership is always certain. If there is no need to release such a deposit, it is the duty of the Escrow Agent to safeguard the registration data according to all relevant policies and regulation in a manner, that there is no risk for the depositor that the data could be lost to a competitor or anybody else not being authorized to access it. Registries and Registrars using Data Escrow are delivering the registration data, daily or weekly, as so-called deposits to the Escrow Agent. A deposit is a composition of all relevant registration data in a special form, highly encrypted and even electronically signed by the sender. The agent validates the deposit. That means the agent checks whether the received deposit is from the right sender, is intact in its full integrity and that the data format is compliant to the international standards. The result of the validation is then being reported to all parties involved, the depositors and the beneficiaries. That creates transparency and transparency creates trust.

In what way is the designation of DENIC Services as the sole ICANN-accredited escrow agent significant from the point of view of data protection and security?

When ICANN started the Data Escrow program well back in 2007, there was only one Data Escrow Agent that has been chosen as Designated Escrow Agent for registrars. Designated Escrow Agent means that ICANN has selected this agent in a very ambitious process, checking the technical, financial, and operational capacities of such an agent, and that ICANN is paying this agent for the service being delivered to the registrars. So, if a registrar is working with a Designated Escrow Agent there should be high certainty about the stability and the quality of the service which is free of charge for the registrar. If the registrar wants to deposit with a non-designated data escrow agent, fees must be paid and the registrar needs to do all the checks, that ICANN is performing during the selection process, on its own.

The sole Data Escrow Agent in 2007 was an US-American company, following the US law and regulation. ICANN saw the upcoming need in 2017 to offer a solution being GDPR compliant. GDPR increased the level of data privacy in advantage of domain holders but raised questions about locations of data storage, transfer of deposits in and out of the European Union etc. After a Request for Proposal process in early 2018 , ICANN decided to nominate a second Designated Escrow Agent which was DENIC. To get the best focus on the service quality for customers, DENIC created DENIC Services as the new service provider for Data Escrow and Anycast DNS services to the Domain Name Industry. That was only five years ago.

As a German company and GDPR on the horizon, we have decided to build the new Data Escrow application with privacy-by-design. The two data centers that we are using for a GDPR-compliant 365 days, 24 by 7 service are within the European Union, one in Frankfurt and the second one in Amsterdam. Since the beginning of DENIC Services it was important, that we proof trustworthiness to our customers, especially in IT security, business continuity and data privacy. We are certified according to ISO27001 and ISO22301. The data centers are operated by DENIC which is having a famous track record in running critical infrastructure without downtime and in a safe and secure manner for more than 25 years. So, I think that using DENIC Services as the sole ICANN-accredited escrow agent takes a lot of worries away from registrars. They can focus on their core business, and we promise that “WE PROTECT YOUR BUSINESS.”

In March this year, ICANN started a new selection process for one or more global Designated Data Escrow Agents. We understood this as a challenge to show that we are not only the best option for those registrars and registries being under the GDPR regime, but even for others that must respect other legislation and data privacy regulation. Hence, we have built a second Data Escrow infrastructure in North Virginia in the USA. That means, registrars and registries have the choice now, where their deposits should be stored. Both infrastructures deliver the same kind of security and safety and run accordingly to the same service level agreements provided by ICANN.

The top reputation that we have in the market today, our track record of annual innovations, and the aspect of being able to give registrars the choice for the location of storage seem to be compelling to ICANN and now we are the Sole Designated Escrow Agent for all ICANN accredited registrars around the globe.

How did you feel about this designation?

We are very proud to be selected for this role which is of high importance for the stability of the global Internet. We see this designation as an appreciation for our hard work over the past five years. We did not only rethink Data Escrow from scratch, but we have also delivered new innovations all the time. We wanted to be the market leader in technology, service quality and customer satisfaction since day one, and we have achieved it. But we also accept this challenge with a certain humility. We know how big the task is and that despite all the preparation, we will experience things that are unplanned and unforeseen. But I’m sure that we have the right attitude, motivation, the necessary expertise and also the joy of serving our customers in our team to cope with it.

Do you think it will help to consolidate the multi-stakeholder model that was initiated by ICANN with the IANA transition completed in 2016?

That is one of the challenges for us. We must proof within the next five years that having one sole Designated Escrow instead of two, ends up with a better service and better results for the community. Having a working multi-stakeholder model in place, which is accepted by almost all parties involved, is a value per se in our today’s world. Is there room for improvement? For sure. We have many ideas how to improve the Data Escrow process and how to get more value out of it. But most of the times, we withdraw new ideas because it seems to be too complicated to come to a conclusion in a timely manner. With all the advantages in having a multi-stakeholder model in place, time is always an issue. If you look at the discussion and the planning around gTLD 2.0, I have the feeling since my beginning, that it is always happening in two years from now, but we are never coming closer to it. Having only one Designated Escrow Agent being in direct communication with all accredited registrars should help us, to re-gain some of the speed that we may have lost.

What are the next steps envisaged by DENIC Services to organise the transition to this new responsibility?

We are planning a transition period of around 12 months which is managed and monitored closely by ICANN. More than 2,500 registrars will join us in that period. This will multiply the number of our customers and the number of domains being escrowed with us. The good news is that we are well prepared for this. As soon as a customer has passed the data escrow change process with ICANN, we send out credentials to the customer for our Data Escrow Control Center. This portal not only delivers all kind of information about the daily business with 365 days, 24 by 7 approach, it offers a new on-boarding feature that puts the registrar in control of the on-boarding and offers a semi-automated process up to the successful delivery of the first deposit to us. For registrar groups or families, we offer a special server-to-server communication via Restful API, so that the technical service provider is controlling the whole on-boarding process in a fully automated manner. These two innovations only have reduced the time needed for on-boarding from weeks to days by purposefully reducing the number of potential error sources.

Registrars that are looking for more information about our service can visit the website welcome-rde.denic-services.de. This website provides answers to the frequently asked questions, offers a lot of information to download and invites to register for the webinars that we are offering for on-boarding.

And not to forget, during all the selection process, ICANN was very much valuing the service quality and was insisting in the expectation to get the same kind of service level for all new registrars that the existing customers are appreciating. We have therefore agreed to double our Data Escrow customer service team which is a huge invest in addition to all the IT development that we have made before. Hence, from October onwards, we will have one customer service teams for all registrars already on-boarded and a second team trained and focused on on-boarding of registrars joining us.

Interview conducted by Nameshield on 18-07-2023.

Image source : Bruno via Pixabay

ICANN77: Concrete progress and the search for a future leader

ICANN77: Concrete progress and the search for a future leader

Last month, the 77th Summit of ICANN, the Internet’s regulatory body, was held in Washington DC. This second summit of 2023 was once again rich in meetings and exchanges, with 90 sessions held over four days.

Here is a look back at the highlights of this event.

Successful outcomes

While ICANN summits have often left a mixed impression due to the multitude of subjects debated and processes made more cumbersome by the consensual approach sought by the organisation, we can welcome the fact that ICANN77 was marked by the successful conclusion of several of them, starting with the Registration Data Consensus Policy.

In May 2018 ICANN hastily applied a Temporary Specification to all stakeholders with a package of measures directly linked to the GDPR that the European Union had just applied. These measures included the masking of personal data in generic domain name registration databases. This set of obligations was intended to be renewable for one year and was to be replaced by a permanent framework. The body responsible for generic name policies, the GNSO, therefore quickly convened a process for developing new policies, a PDP, which was divided into several workstreams. Phase 1 of the PDP concerned the long-term binding framework they were looking for. The result was the Registration Data Consensus Policy, which has now been finalised. This work has been extended because the subject of personal data on domain names overlaps with many other texts (21 policies in all) which have also been revised. While stakeholders will have at least 18 months to apply the new policy, aspects relating to the collection, processing and storage of personal data linked to domain names will be altered.

Phase 2 involves the creation of a standardised system for accessing hidden personal data on domain name contacts for legitimate purposes, such as investigations into cybercrime. This resulted in the creation of a prototype that will be deployed this Fall. Over the next two years, this prototype should enable the organisation to validate whether or not it should develop a permanent global tool. It is therefore a reasonable step, because it is prudent. It would have been risky to develop a particularly expensive global system whose use was uncertain. But this issue is also directly linked to the accuracy of the data. What is the point of requesting access to masked contact data if it is unreliable?

On this subject, ICANN has launched a project in 2021 on the accuracy of registration data. But ICANN came up against the fact that in order to assess the accuracy of the data, it needed a legal basis for accessing the data. This forced the body to put this project on hold last year, when negotiations began to create a Data Protection Agreement between ICANN and the stakeholders.

Two contractual amendments in 2023

On the contractual side, it should be noted that the contracts linking ICANN with the registry operators on the one hand and the registrars on the other are in the process – and this is unprecedented – of being amended twice in the same year. The first revision will come into force next month to organise the transition between the Whois protocol and the RDAP protocol. The second revision, which is about to be put to the stakeholders for a vote, aims to step up the fight against DNS abuse. As far as DNS abuse is concerned, it should be remembered that this subject has long been a staple of ICANN summits, in the sense that it has been debated for several years without ever coming to a conclusion due to a lack of consensus. The need to step up action against these attacks has therefore never been so close to being written into the contracts.

ICANN is looking for its future leader

In another unprecedented development, on 21 December last year, ICANN announced the resignation of Goran Marby, its President. Sally Costerton took on the responsibility and was rapidly appointed Interim President of the organisation. This experienced leader, who already has around ten years’ experience in the organisation, was logically closely watched at ICANN76, but was also well received by the community. She took ownership of the issues very quickly and was very proactive in pushing them forward. ICANN77 was an opportunity to propose a session called CEO Search Committee. The profile of the future president was drawn up, along with his or her eight responsibilities: management of the IANA function, development of new DNS system policies, the program for new generic extensions, strategic management, management of the governance body, commitment and exchanges within the community, management of responsibility and, of course, the role of representative of the body. The perspective given for the appointment of this future face of ICANN is the second quarter of 2024.

The next round of new generic extensions at the centre of attention

As is often the case at ICANN summits, the subject of the next round of new generic TLDs was on the menu for most of the discussions. The fact that the previous application window dates back to the beginning of 2012 is obviously no coincidence. At her first summit as President of ICANN, Sally Costerton made good progress on this issue, with ICANN76 concluding with the ICANN Board adopting 98 of the 136 recommendations arising from the process of developing new policies for the next round. 38 recommendations remain to be clarified, and this work is currently underway, with completion scheduled for the second half of this year.

At the same time, implementation of the other recommendations and revision of the Applicant Guide Book have begun. However, two other subjects complete the picture: the possibility of creating closed generic TLDs, a sort of model similar to brand TLDs but which would be made possible on generic terms, and the revision of policies for internationalised TLDs and domain names, i.e. in native languages. The first subject should soon be put into orbit via a process of development of new policies planned over nearly two years. As for the second, its policy development process could last until November 2025. The organisation’s intention is to bring these two issues to a successful conclusion before the next round.

At the time of the 2012 round of new generic extensions, internationalised extensions and domain names were already being strongly promoted as a vector for the success of this innovative process. However, this was without taking into account universal acceptance, which was still in its infancy and which has fortunately made considerable progress since then. The RDAP protocol for registration data was also already considered as an alternative to Whois to be implemented with the new generic TLD program. However, RDAP is only set to replace Whois after a transition period of 18 months. As for closed generic extensions, they were also considered in 2012 but abandoned due to a lack of consensus. They could finally see the light of day under terms to be defined during the next round. As for abuse of the DNS, another subject that has been debated for years, it is also on the point of leading to additional obligations that will affect registries and registrars alike.

If Nameshield is already offering you solutions to help you deal with infringements of your online assets and your gTLD projects, it should be noted that the obligations incumbent on companies that manage domain names are constantly increasing, but also that with ICANN the issues are almost always resolved in the end.

See you in Hamburg in October for ICANN78.

Image source : ICANN’s website

Phishing, slamming and other fraudulent e-mails: stay alert during the summer holidays!

Phishing, slamming and other fraudulent e-mails: stay alert during the summer holidays!

Every year, the summer holidays announce the upsurge of fraudulent e-mails mass campaigns. Indeed, cybercriminals try to profit from these periods when the vigilance is sometimes lowering, to launch phishing e-mails.

What are phishing and slamming?

Phishing is used by cybercriminals to obtain personal information in order to commit an identity theft.

In the world of phishing, slamming is a well-known variant that consists in encouraging domain names owners to renew their annuity with another registrar, by arguing the emergency and criticality of the concerned name’s loss. Concretely, this is an e-mail pushing its recipient to contract an unsolicited service and to proceed to the payment of this latter without delay.

Thus, the slamming can take the form of a fraudulent renewal bill, generally associated with intimidating terms like “Expiration notice”. Under the pressure of such e-mail, in general well built, it happens that the recipient then proceeds to the payment and is debited of an important amount for the so-called renewal.

In the same way, the slamming e-mail indicates that a “customer” of the sender posing as a fake registrar, wants to register domain names identical or similar to your brand. Then the fraudster proposes to register them for you in order to protect you from these troublesome registrations, of course, in exchange for an urgent payment.

Another kind of attack, the suspicious e-mail attachment!

Be careful of fraudulent e-mails with infectious attachments: a single entry point is enough to destroy a network!

The aim of a trap and thus malicious attachment is to pose as a legitimate file (PDF, Word document, JPG image…), while hosting and hiding a malicious code: this is what we generally call Trojans.

Some simple rules to protect against them

  • Always stay alert when someone asks you your personal data;
  • Do not ever open an attachment from an unknown sender, or from one who is not entirely trustworthy;
  • Check the links by hovering the cursor over them (without clicking) to ensure that they link to trustworthy websites;
  • Never reply under the pressure of this kind of solicitation and of course do not proceed to any payment;
  • If there is any doubt, do not reply to the e-mail and contact the sender through another method who will confirm whether it really is a fraud attempt or not.

Find on the Nameshield’s website a wallpaper to download to help you think about it more often.

.MY : Relaxation of registration rules for .MY domain names

.MY domain names

Due to the strict allocation criteria, connecting a .MY domain name for a company not located in Malaysia was difficult.

MYNIC, the Malaysian registry, wanted to make significant changes for 2023 in order to globalize its .MY domain names.

The registry has therefore decided to remove local presence restrictions on .MY.

This change means that anyone can register a .MY domain name on a “first-come, first-served” basis.

It means that it’s now possible to register a .MY domain name in the name of a European company and no priority phase has been planned.

Please note that it does not apply to the .COM.MY extension, which stays limited to Malaysian entities.

Do not hesitate to contact our teams to secure your .MY domain.

Image source : Pexels via Pixabay

The .COUNTRY registry increases its prices as of September 27, 2023

The .COUNTRY registry increases its prices as of September 27, 2023

The .COUNTRY registry will significantly increase the price for new registrations under this extension from September 27, 2023, 16:00:00 UTC.

All registrations, transfers and renewals of a .COUNTRY domain name registered after September 27, 2023 will be subject to a price increase of 100 times the current price.

This very significant price increase, which has not been explained by the registry, will only apply to domain names registered after this date.

Domain names registered before September 27 can still be renewed at the current price, and will not be affected by the price change.

To protect your brands without being impacted by this price increase, we invite you to register your .COUNTRY domain names as of now.

The Nameshield team is at your disposal for any questions.

Image source : internetnaming.co

ICANN76, Sally Costerton, the new interim president of ICANN, makes her mark

Candidate in March 2020 and then in March 2021, the city of Cancun finally had to wait until March 2023 and the end of the COVID pandemic to see a new edition of an ICANN summit in person. 2023, a very important year for the organisation. It will indeed celebrate its 25 years of existence while it is going through a risky period with an interim presidency after the resignation of its former President on 22 December 2022.

ICANN76, Sally Costerton, the new interim president of ICANN, makes her mark

Two women at the head of ICANN

Sally Costerton from the UK, who has been Vice President of Global Stakeholder Engagement (GSE) in charge of stakeholder engagement and awareness of ICANN and its mission worldwide since 2012, has been appointed interim Chief Executive Officer of ICANN following the departure of Goran Marby at the end of 2022. She is supported by Tripti Sinha who serves as ICANN’s Board Chair. Tripti is also Associate Vice President and Chief Technology Officer at the University of Maryland, in the Information Technology Division. This is the first time ICANN has had two women leaders. However, the situation echoes the creation of ICANN. As it was recalled at the opening ceremony, in 1998, when the US government gave ICANN the task of managing the DNS addressing system, a woman also held the position of Chair of the Board. This was Esther Dyson.

While leadership interims are rare at ICANN, this situation led to the organisation of a special session called “The Future of ICANN and the Next President and CEO”. A session where participants would have expected to interact with the new Board. This was not the case, as this session was like a kind of open mic without a direct interlocutor to express expectations towards the new Management of the organisation.

An interim presidency for a governance organisation also means a risky period, especially as there is no shortage of issues to address and the geopolitical context is tending towards increased fragmentation. However, although we do not know how long the interim presidency will last, Sally Costerton quickly made her mark at the start of the summit, when she declared, among other things, “I do not know everything, but I can rely on experts“. These words were reassuring and showed a pragmatic approach.

Transparency tested by experience

ICANN is a well-established organisation, as it has been holding summits for 25 years. The trend in recent years has been for the Supporting Organisations (SOs) and Advisory Committees (ACs) that make up the organisation to move towards greater transparency by opening up almost all their sessions to the participants. The most significant transformation has been in the GAC, the body representing governments, whose sessions were closed for many years before being fully open to all participants. This is an opportunity to salute the work of Manal Ismail, who after nearly six years at the head of the GAC is leaving her place to the Paraguayan Nicolas Caballero. A global tendency, therefore, of a nature to generate confidence, a key value to respond to the more and more numerous detractors of the ICANN governance mode.

But this tendency was reversed during this summit because many sessions were closed, “Closed sessions” to which even some affiliated participants could not have access neither in face-to-face nor in remote. Some of the participants were very upset and did not fail to point this out during the traditional Public Forum which usually closes the week of meetings.

Progress at a forced march?

The consensual approach, typical of ICANN, is both a strength for federating players around new obligations that are adopted, but also a weakness because it considerably slows down the progress of important work.

A striking example is the DNS abuse. Malicious use is indeed a real problem given the damage suffered by the affected Internet users. The GAC did not fail to recall this once again during a session where external experts were invited, such as a representative of the Federal Bureau of Investigation, the FBI. The latter indicated that in the United States, in 2022, more than 800,000 domain names were the subject of complaints causing losses of more than 10 billion US dollars. While the topic of DNS abuse has been a recurring theme at every ICANN summit over the years, it is clear that the consensus has shown its limits. Stakeholders in the GNSO, the generic name policy body, have never been able to agree on a way forward, whether it be a Policy Development Process or contract negotiations to revise stakeholder contracts with ICANN. After recent consultations with stakeholders, the GNSO finally decided on the second option, and the least we can say is that at ICANN76, the will was to reach a result quickly. An amendment to the registry and registrar contracts is being drafted and is expected to be presented in June and voted on by the parties concerned in October.  

The GNSO intends to build on the momentum of another contract amendment being voted on by stakeholders: an “RDAP” amendment. RDAP is an alternative protocol to Whois that provides access to domain names registration data. The outcome of the votes and thus the adoption of these contract revisions remained uncertain at the end of the ICANN summit as different thresholds of participation and favourable votes must be reached.

Partial adoption of recommendations for future rounds of new gTLDs

Another issue that some would like to see move forward more quickly is that of future rounds of new generic extensions. Indeed, the last window for applications for generic extensions dates back to January 2012. Since then, a policy development process has been conducted since 2015 to define a set of recommendations for the holding of new application windows. The Final report of this process was submitted to the ICANN Board in February 2021. In the autumn of 2021, ICANN surprised the community by announcing a scoping phase, an ODP (Operational Design Phase), which ultimately lasted until the beginning of this year. The board had not yet decided on the Final report of recommendations, a prerequisite to be able to start the implementation work of the recommendations. So the new interim president of ICANN was also very much expected on this subject.

And she quickly warned that the time was also for action on this subject: “You will see that things will be clarified” (editor’s note: on the next series of generic extensions), she declared during a session during the week. At the end of the week, at a Board meeting, 98 recommendations from the policy development process were adopted, with a further 38 put on hold as requiring further information. An implementation plan is also expected with a deadline set to 1st of August with a focus on internationalized domain names and extensions that ICANN organisation wants to focus on in future rounds and the need to clarify whether closed generic extensions will be offered.

Comments from NAMESHIELD

We can regret a return to a certain opacity in the decision making during ICANN76 where no less than 25 closed sessions were held. Nevertheless, this is perhaps where the progress made on subjects that were not progressing well came from, such as DNS abuse, a very important subject for NAMESHIELD, which offers several solutions to defend your online assets, and the holding of a forthcoming series of new generic extensions, where NAMESHIELD experts can also accompany you.

The other question was how the new interim ICANN President Sally Costerton, would handle her new role in a risky period for ICANN whose model is also increasingly challenged by States, international organisations and even technological alternatives. On this point, the new president appeared to be proactive, joining words to deeds, as on the subject of further series of new generic extensions. Sally Costerton seems to have already started to trace her way towards a full term CEO role for the organisation.

Image source : ICANN’s website

Afnic Registrar Day is back

Afnic Registrar Day

On January 10, the new edition of Registrar Day was held, organized by AFNIC, the registry of the .FR extension, this event is mainly intended for registrars.

While the event was usually held in December, this new edition, which was both accessible in person and remotely, and which took place after the pandemic period, was held at the beginning of this year, a way to place ourselves “in a new dynamic,” according to Pierre Bonis, AFNIC’s Director General.

The Registrar Day was an opportunity to review the highlights of the year 2022 for the organization, the most notable being the deployment of a new registry system on October 1 and the renewal by the French government of the .FR management concession for a new 5-year period. This renewal is accompanied by the implementation of new commitments such as access to registration data for authorized authorities or a strengthening of the fight against domain abuse.

In terms of figures, it should be noted that in 2022, .FR passed the 4 million mark in volume of domain names, a faster growth than the median rate of 2.0% recorded by the Council of European National Top-Level Domain Registries (CENTR) for the year 2022 at the level of European ccTLDs. It is worth noting that .FR ranks third in terms of volume among the ccTLDs of the European Union, behind .DE (Germany) with some 17 million domains and .NL (Netherlands) with more than 6 million domains, and is tied for 7th place with .AU (Australia) at the global level among the 308 ccTLDs delegated to the root 1  

1 Source Verisign

Image source : Afnic’s website