ietf-asrg
[Top] [All Lists]

Re: [Asrg] Assume perfect knowledge by domain registry provisioners, so what?

2003-05-09 04:21:23
                           ... theoritically speaking if this rule is 
enforced then the registrars will care if the domain has valid info. 

An appeal to a operational business interest is what I'm looking for,
though I'm willing to entertain candidate claims of marketing problem
or marketing opportunity, not an appeal to regulatory enforcement.

If the data that is provided a gTLD registrar, or to ccTLD registrar who
operates on a cost-recovery plus margin business model, by a registrant,
is sufficient for successful billing, the data is "registrar-sufficient".
It is not "intellectual-property-constituency-sufficient". For reasons of
inter-registrar, even inter-registry competition, whois data base mining
is _perceived_ to be both a business issue (unfair competition), and in
some way related to spam -- in both senarios contact data is harvested.
A paper by Ari [1] summarizing work done by CDT invalidates the primacy of
the second claim.

To summarize:
        o spammers do not use their real info when registering domains,
          they steal from registrars, and possibly from registries.
        o spammers are not restricted to registrars and registries which
          are in whole or in part under a regulatory regime in which ICANN
          participates.
        o I'm not going to comment on whether the .com and .net registry
          operator, and former .org registry operator, and operator of a
          set of cctld registries, the 40% market-share registrar for the
          com/net/org set of registries, or a vendor of certs, is acting
          in good-faith, or in bad-faith -- only that it is an actor.

Everything in your note ultimately is independent of the knowledge that
a mesh of communicating registry-provisioning entities could make shared
data to registrars and registries which is contemporanious to detection,
by any means, of a new emitter. I must have posed the problem poorly.

I don't consider whois:43 to be any part of the solution-space. I write
that as the (former) co-chair of the whois-fix BoF (IETF), and as one of
many active in removing or modifying the ICANN bulk transfer requirement
for registrars, and the author of a draft [2] proposing that the status
of rfc954 be changed from "standard" to "historic". The IESG view on the
issue can be disscerned in the exchanges between its members and myself
in the archives of the PROVREG WG, to be brief, their position is that
a mechanism for registrant "opt-out" of publication via 954 is manditory
to implement, and optional to deploy.

I promise not to comment on 954 again.

Eric

[1] http://www.cdt.org/speech/spam/030319spamreport.pdf
[2] http://www.ietf.org/internet-drafts/draft-brunner-rfc954-historic-00.txt
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg



<Prev in Thread] Current Thread [Next in Thread>