Feeds

Of ICANN and the Registerfly meltdown

What needs to be done

Beginner's guide to SSL certificates

Comment The scorn heaped upon ICANN recently for its laissez faire attitude toward customer allegations of fraud by its accredited registrar Registerfly - a scandal in which ICANN spent the better part of a year repeatedly referring customers back to Registerfly, even in the face of overwhelming evidence of misconduct - has forced ICANN to acknowledge that it is responsible for holding its accredited registrars to certain ethical standards. Well, it's a start.

For those, however, whose domains were lost through either neglect or malfeasance on the part of Registerfly, and whose domains are now occupied by cybersquatters, the loss of a business or personal website formerly hosted by Registerfly still burns.

Although ICANN recently issued an ultimatum to Registerfly, threatening to pull its accreditation unless it resolved its myriad customer service issues within two weeks time, the fact remains that pulling the accreditation of a negligent or possibly even criminal registrar is a merely a prophylactic measure - it may prevent future harm, but does nothing to resolve the property rights of those whose internet based businesses have vanished into cyberspace.

The fact is, Registerfly is not alone, and ICANN needs to develop some kind procedural safeguards to ensure that disputed domains are not inadvertantly auctioned off to the first bidder before this happens again.

Although ICANN rightly claims that allegations of monetary damages due to fraud or negligence need to be addressed by local authorities, the integrity of the domain system itself needs to be protected by ICANN - that, after all, is why ICANN takes a cut of every domain registration fee.

Whether or not local or federal authorities choose to prosecute Registerfly - and the rumors flying indicate that both the FBI and the Secret Service are involved now - jilted customers cannot expect the FBI, for example, just to hand over the control of a domain name that might now be owned by bona fide purchaser on the other side of the world. It's not like stolen silverware or jewelry - the only way for the authorities to return control of the domain would be to get a court order against, um... that group, the one that controls domain registration...oh yeah, ICANN.

At the very minimum, ICANN needs to be proactive here and develop a system for holding disputed domains in trust until the rightful owner can be determined. Even better would be a formal dispute resolution system with investigative power to follow up on serious allegations and nip them in the bud. Mr. Zupke, ICANN's go between with the accredited registrars, cannot police cyberspace alone.

ICANN performs a function in cyberspace somewhat analogous to the hall of records in a local community, organizing and documenting property rights. If ICANN feels that enforcing certain ethical standards on its partners runs counter to its bureaucratic instincts, it could still subcontract out such enforcement to a third party security group, much as it subcontracts out domain registration to groups like Registerfly.

The Registerfly fiasco has laid clear for all to see the inadequacies of the current registrar accreditation system, and the need for reform. There's no time like the present. ®

Burke Hansen, attorney at large, heads a San Francisco law office

Internet Security Threat Report 2014

More from The Register

next story
I'll be back (and forward): Hollywood's time travel tribulations
Quick, call the Time Cops to sort out this paradox!
Musicians sue UK.gov over 'zero pay' copyright fix
Everyone else in Europe compensates us - why can't you?
Megaupload overlord Kim Dotcom: The US HAS RADICALISED ME!
Now my lawyers have bailed 'cos I'm 'OFFICIALLY' BROKE
MI6 oversight report on Lee Rigby murder: US web giants offer 'safe haven for TERRORISM'
PM urged to 'prioritise issue' after Facebook hindsight find
BT said to have pulled patent-infringing boxes from DSL network
Take your license demand and stick it in your ASSIA
Right to be forgotten should apply to Google.com too: EU
And hey - no need to tell the website you've de-listed. That'll make it easier ...
prev story

Whitepapers

Seattle children’s accelerates Citrix login times by 500% with cross-tier insight
Seattle Children’s is a leading research hospital with a large and growing Citrix XenDesktop deployment. See how they used ExtraHop to accelerate launch times.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.