Maybe you saw the stories recently about comments that were made at a recent World Economic Forum debate on cyberwarfare. As one of them notes, Hamadoun Toure, Secretary General of the International Telecommunications Union, proposed a treaty in which countries would pledge not to attack each other without having been attacked. This post isn't about Mr. Toure's proposal. It's about a comment the story attributes to Craig Mundie, Chief Research and Strategy Officer for Microsoft. According to The Raw Story, Mundie "called for a `driver's license' for internet users." more»
The 2010 Domain Pulse, hosted by SWITCH (the .CH registry) was held in the snowy Swiss city of Luzern. Domain Name Security (DNS) was of particular importance in this year's meeting with DNSSEC being implemented in the root zone in 2010 by ICANN, and by many registries in the next few years. ICANN plan to have all root servers signed with DNSSEC by mid-2010 Kim Davies, Manager, Root Zone Services at ICANN told the meeting, starting with the L root server, then A root server with the last being the J root server as all are gradually signed. more»
Again on the subject of new Top-Level Domains (TLDs) ... One of the "issues" that concerned a number of people is the concept of "vertical separation". The basic idea is that domain name registries and registrars should be kept separate. While that is a wonderful Utopian ideal, the reality is that in the real world companies own other companies, people trade in stocks and shares etc., etc. So it's far from being a simple "cut and dried" situation. more»
The Australian has a good article describing the efforts some of their ISPs are making in an attempt to clean up their act: the government is encouraging ISPs to detect computers on their network that are infected and part of botnets, and to communicate to the customer that their system is compromised... Unless the customer feels a little bit of pain they will not change their ways. more»
While I was giving my .music presentation at ICANN Studenkreis in Barcelona, Spain last week, it dawned upon me. There was not one single ICANN staff member sitting in the room taking notes on any of the presentations given by TLD applicants. I was convinced that it would be beneficial to ICANN staff to observe our presentations and perhaps receive useful feedback from TLD applicants that could be used to better draft the Expressions of Interest recommendation. more»
Before, during and after his inaugural speech (January 2009) President Obama spoke of the national benefits of broadband, and the changes which have been set in motion in the US telecoms market that were unheard of even a year ago. During the previous administration the incumbent telcos and cable companies had been given more freedom. As a consequence, innovation and competition dwindled and the US was no longer a leader in telecoms... However, since that time, the White House has lost some of its initial leadership. more»
There have been a number of reports recently about customer lists leaking out through Email Service Providers (ESPs). In one case, the ESP attributed the leak to an outside hack. In other cases, the ESPs and companies involved have kept the information very quiet and not told anyone that data was leaked. People do notice, though, when they use single use addresses or tagged addresses and know to whom each address was submitted. Data security is not something that can be glossed over and ignored. more»
In 2008 KnujOn published a report indicating that 70 ICANN accredited Registrars had no publicly disclosed business location. The fundamental problem was one of community trust and consumer faith. Registrars extend their legitimacy to their domain customers who then transact and communicate with the public. more»
I have deferred blogging on the Google/China imbroglio for a few reasons. First, heavyweights such as Jonathan Zittrain have tracked International online censorship and online security issues more closely than I have. Second, after Google's provocative blog post, I wanted to see the facts develop rather than rely solely on Google's assertions. The spin doctors are now moving in, so the useful development of the factual record will be slowing down. more»
My main argument is about the policy of handling vulnerabilities for 6 months without patching (such as the Google attacks 0day apparently was) and the policy of waiting a whole month before patching this very same vulnerability when it first became an in-the-wild 0day exploit (it has now been patched, ahead of schedule). Microsoft is the main proponent of responsible disclosure, and has shown it is a responsible vendor... I simply call on it to stay responsible and amend its faulty and dangerous policies. more»