Home / Blogs

ICANN Workshop Displays Diverging Perspectives on WHOIS

Thomas Roessler

At a workshop held in late June in Montreal (Canada)—Karl Auerbach had submitted some live coverage to CircleID --, the Internet Corporation for Assigned Names and Numbers (ICANN) had an in-depth look at various aspects of the Internet's WHOIS databases. These databases associate social information (like holders' names and contact information) with network identifiers, such as IP addresses and domain names. Current policy for these databases—in particular in the generic top level domain area—is part of ICANN's contracts with domain name retailers ("registrars") and database operators ("registries"), and permits for use of the data by arbitrary parties for arbitrary purposes.

The week before the workshop, the EU's article 29 working party had issued an opinion (pdf), focused on domain name WHOIS and individual registrants' data. The working party identifies the WHOIS databases' original purpose—finding contact points to solve operative network problems—as legitimate, but raises concerns about other purposes for which the database is being used today, e.g. private policing of copyrights. Concerning extended search services which would, e.g., permit to search for all domain names registered by a particular individual, the working party cites an earlier opinion which notes that "the processing of personal data in reverse directories or multi-criteria searching services without unambiguous and informed consent by the individual is unfair and unlawful." The working party supports the WHOIS consensus policies which ICANN's board had adopted in March.

In Montreal, this position was represented by the EU Commission's Diana Alonso-Blas, who also said that the working party would be pleased to be involved with further discussion of the topic.

Others at the workshop gave insights into current WHOIS practice. Bruce Tonkin, CTO with Australian registrar Melbourne IT, and chairman of the GNSO Council, pointed to frauds and abuses in which WHOIS data give perpetrators information about the contractual relationships between registrars and domain name holders, and thereby make it easier for fraudsters to impersonate registrars. Statistics alone demonstrate that WHOIS isn't just used for the occasional queries it was intended for: On a normal day, there are about 2 million queries from less than 140,000 source addresses.

Data users were represented by (among quite a few others) Jane Mutimear (Bird & Bird), the chair of the GNSO's "Intellectual Property and Anticounterfeiting Interests Constituency”. She emphasized the importance of private policing of intellectual property rights and the contribution of WHOIS to these activities, and called for continued public access and the introduction of extended search services. Ms. Mutimear also elaborated on the use of WHOIS as a tool for managing domain name portfolios.

Things were wrapped up on two panels. Registrars acknowledged that they were in an uncomfortable situation, having contracts with ICANN which are apparently in conflict with applicable law. There was some hope that revising WHOIS policies could help, for instance by making different sets of data available to different tiers of data users. Intellectual Property and Law Enforcement representatives on the panels aggressively advocated continued easy and public access to the data, though. Safeguards for data subjects' rights were by most of these panelists considered as nuisances which would hamper effective law enforcement in cyberspace. One observer was lead to diagnose widespread "Internet exceptionalism” among panelists.

By Thomas Roessler, Mathematician. Visit the blog maintained by Thomas Roessler here.

Related topics: DNS, Domain Names, ICANN, Privacy, Whois

Get a weekly summary of postings to CircleID:

 Master Feed (more feeds)      Twitter      Mobile
Bookmark / Email This Post

Comments

To post comments, please login or create an account.

Related Blogs

Domain Registrars & Registries: Don't Say You Weren't Warned

EoWhy?

Perspectives on a DNS-CERT

"Thin Brand Line" Breaks as Canon Announces Plans for .CANON

EI, EI - NO!

Related News

Other Topics

Access Providers Broadband Censorship Cloud Computing Cyberattack Cybercrime Cybersquatting Data Center DNS DNSSEC Domain Names Domain Registries Email Enum ICANN Internet Governance Internet Protocol IP Addressing IPTV IPv6 Law Malware Mobile Multilinguism Net Neutrality P2P Policy & Regulation Privacy Regional Registries Security Spam Telecom Top-Level Domains VoIP Web White Space Whois Wireless



Industry Updates – Sponsored Posts

.ORG, The Public Interest Registry Celebrates Its 25th Year With 8 Million Registrations

MarkMonitor Year in Review Report: How Escalating Online Brand Abuse is Used to Monetize Web Traffic

.ORG: Introducing Fully Internationalized Domain Names

.ORG to Fully Deploy DNSSEC in June

The GLOBE Program Chooses Dyn Inc.'s Dynect Platform to Deploy DNSSEC per Federal OMB Mandate

SPECIAL: Updates from the ICANN Meetings in Nairobi

.ORG Registrations in 2009 Grew 8.4 Percent Over Previous Year

MarkMonitor Sets New Standard in Brand Protection with Site Staydown Service

Announcement: dotMobi Ownership

Afilias Limited Acquires .Mobi Domain Registry, Expands Market Leadership

ICANN and Cybersecurity: Hot Topics at The First Ever .ORG Forum

Using .ORG Directory to Find Haiti Relief Organizations

Neustar Releases UltraDNS Report Center

Afilias Releases .INFO Domain 2009 Annual Report

Expressions of Interest a Requirement for New gTLDs?

Neustar Implements DNS Security Extensions in the .US Registry

Neustar Launches Initiative to Enhance DNS With Faster, More Secure Updates

Registry Stakeholder Group Comments on Latest ICANN Policies

Open Phishing Season

dotMobi Is Now a Member of The LACTLD