Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Networking

    Last Call for Whois Comments

    Written by

    Larry Seltzer
    Published January 11, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Who would have imagined that so much business and so much abuse would center around Internet domain names? Certainly not the designers of the system, including those of the Whois service, which reports on ownership and some other data on domain names. But an effort to reform the process is underway, and you have just a few days left to get in your opinion.

      Whois, like so much else of the Internet, was designed in an era of hippie trust amounting to naiveté. Of course it would have been better and, like, beautiful, man, if we could just trust users with ownership and contact information for domain names.

      But instead, the administration of the Domain Name System has turned into a disaster for everyone except those who abuse it, and much of the trouble stems directly from the free availability of this information. I suspect that one of the earliest sources for spam address harvesting was Whois, and it also provides the foundation for most examples of domain name theft.

      /zimages/1/28571.gifLarry Seltzer thinks theres more evidence that the domain registration system is failing to serve the publics interests, and its going to get even worse. Click here to read more.

      And then theres the general issue of privacy. Is it right that, in order to acquire and use a domain name, a user should have to disclose his or her address, phone number and e-mail address? In fact, Internet rules, promulgated by those great folks at ICANN (Internet Corporation for Assigned Names and Numbers), require that Whois data for a domain be accurate and up to date.

      There are very good reasons for keeping that information accurate and up-to-date: This is the contact information that will be used if an attempt is made to transfer your domain to a different registrar, and it may be up to you to deny the request. Other attempts to contact you, for reasons legitimate or otherwise, may go to these contact points.

      Faced with the abuse that comes from addresses being freely available, including spam and junk mail through the postal system, some people give false contact information. This is a bad idea. Even just putting a “nospam-remove” in your name could cause problems you might regret.

      So, some time ago ICANN formed a Whois Privacy Task Force. Actually, there seems to have been more than one Whois Task Force, and the discussions go back to 2003. But there is a Preliminary Task Force Report on Whois Services, Nov. 22, 2006, and the public comment period ends on Monday, Jan. 15.

      The first big “uh-oh” comes from the conclusion, up top, that the task force was, on the one hand, unable to agree on the purpose of Whois records or what data should be published, and on the other did agree that the current system is inscrutable and that any changes to it will be problematic. In other words, whatever we do will impinge on someones interests.

      Next page: The case of OPoC vs. Special Circumstances.

      The Case of OpOc


      vs. Special Circumstances”>

      There are two main proposals being considered and a number of more detailed questions. The two new models are called OPoC (the Operational Point of Contact) and the Special Circumstances proposal.

      OPoC, which I discussed in a recent column, is backed by many (self-styled, perhaps) privacy advocates, and is similar to GoDaddys DomainsByProxy model: The contact information is no longer that of the actual domain owner, but some third party with a code that allows them to contact the actual owner. Crucially, OPoC, as the ICANN report says, “does not include a mechanism for access to Whois data by, for example, law enforcement agencies or intellectual property rights holders.”

      /zimages/1/28571.gifSomeone is spying on Whois requests and snatching the domains. How does it work? Click here to read more.

      This limitation has led many to support the alternative Special Circumstances model, also known as the Netherlands Model, because the rules are similar to those governing the .nl top-level domain: “It allows individuals who demonstrate the existence of special circumstances to substitute contact details of the registrar for the data that would otherwise appear in published Whois.” In other words, it allows some people to use the OPoC model if they qualify.

      So who qualifies? According to the ICANN report:

      The proposal envisages that full contact data of individuals would be held back from publication in the Whois only when this “would jeopardize a concrete and real interest in their personal safety or security that cannot be protected other than by suppressing that public access.” This would seem to indicate that the vast majority of contact information would be published in the Whois, and that means of access to unpublished data would rarely be required.
      The classic example is a Web site for a battered womens shelter.

      Special Circumstances is backed most famously by intellectual property holders and their attorneys, and law enforcement. MarkMonitor, a corporate identity management and protection services company and a domain registrar itself, is organizing a campaign in support of Special Circumstances. Its got an impressive list of supporters there, and if you agree you can join the endorsement.

      I really am sympathetic to the interests of intellectual property owners, but Special Circumstances is a pretty meager concession to the privacy and abuse problems. Sure, I sympathize with battered womens shelters, but what about the more general problems of abuse, spamming and domain theft, for example? These didnt show up on the radar of the Special Circumstances people.

      I wish I could come up with a proposal that could satisfy both parties, and I dont want to look at it too much from the point of view of my own private interests. The best I can come up with is that I can understand the interests of both sides, but I think its best to support OPoC, and, once thats in place, see how to facilitate access to registrant information for law enforcement and legitimate legal mechanisms. At least theres a chance that could be accomplished. If we adopt Special Circumstances then the interests of most of the public are shoved aside.

      But enough about me, what do you think? Tell ICANN yourself by e-mailing it on this matter: whois-comments@icann.org

      Security Center Editor Larry Seltzer has worked in and written about the computer industry since 1983. He can be reached at larryseltzer@ziffdavis.com.

      Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at Ryan Naraines eWEEK Security Watch blog.

      Larry Seltzer
      Larry Seltzer
      Larry Seltzer has been writing software for and English about computers ever since—,much to his own amazement— He was one of the authors of NPL and NPL-R, fourth-generation languages for microcomputers by the now-defunct DeskTop Software Corporation. (Larry is sad to find absolutely no hits on any of these +products on Google.) His work at Desktop Software included programming the UCSD p-System, a virtual machine-based operating system with portable binaries that pre-dated Java by more than 10 years.For several years, he wrote corporate software for Mathematica Policy Research (they're still in business!) and Chase Econometrics (not so lucky) before being forcibly thrown into the consulting market. He bummed around the Philadelphia consulting and contract-programming scenes for a year or two before taking a job at NSTL (National Software Testing Labs) developing product tests and managing contract testing for the computer industry, governments and publication.In 1991 Larry moved to Massachusetts to become Technical Director of PC Week Labs (now eWeek Labs). He moved within Ziff Davis to New York in 1994 to run testing at Windows Sources. In 1995, he became Technical Director for Internet product testing at PC Magazine and stayed there till 1998.Since then, he has been writing for numerous other publications, including Fortune Small Business, Windows 2000 Magazine (now Windows and .NET Magazine), ZDNet and Sam Whitmore's Media Survey.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×