Policy & Regulation

Policy & Regulation / Featured Blogs

Nothing to See Here

Three parallel events in US communications policy today, all reported on widely - but with a common thread. ... Law enforcement and national security officials want to make sure that they have the same ability to execute warrants and surveillance orders online that they had in the switched-telephone-circuit age -- which will mean substantial government design mandates for new software, hardware, and communications facilities. more

Policy Failure Enables Mass Malware: Part I (Rx-Partners/VIPMEDS)

This is the first in a series of releases that tie extensive code injection campaigns directly to policy failures within the Internet architecture. In this report we detail a PHP injection found on dozens of university and non-profit websites which redirected visitor's browsers to illicit pharmacies controlled by the VIPMEDS/Rx-Partners affiliate network. This is not a unique problem, however the pharmacy shop sites in question: HEALTHCUBE[DOT]US and GETPILLS[DOT]US should not even exist under the .US Nexus Policy. more

How I Think CIRA Should Evolve: Towards CIRA 2.0

There's been some good discussion here about possible policy changes which Canadian Internet Registration Authority (CIRA) could consider. But there's more to the CIRA Board election which is underway than simply arguing about whether a PO Box satisfies a "presence" requirement. CIRA's done pretty well over the past decade, but it's not perfect. As a candidate for re-election to the CIRA Board (and currently Vice-Chair) here are some of my own personal thoughts regarding ways in which CIRA might improve. I call this (unoriginally, I know) CIRA 2.0. more

New TLD Vertical Integration, Market Forces and the Path of Least Compliance

The ICANN Board will soon make many decisions, one of which is to decide whether to continue or reverse ICANN's longstanding policy of vertical separation of registries and registrars. Since new Top-Level Domains (TLDs) are supposed to benefit registrants with lower prices, choice and what we trust will be a decision for 'market-differentiated' competition, the Board will no doubt consider market forces as well as compliance and enforcement issues in choosing the path that can maximize these goals. more

Outages Never Sleep!

Not matter how much robustness and redundancy you build around your multi-tiered infrastructure you are bound to suffer outage(s). I'm not implying the failure of a single server, but a complex outage that's usually external to the operation of the infrastructure. What matters is how you communicate outage notification when things do go awry. I think the words that I'm searching for are transparency and openness. more

Precrime Regulation of Internet Innovation

In the sci-fi movie Minority Report, a 'precrime' police unit relies on the visions of psychics to predict future crimes, then arrests the potential perpetrators before they do anything wrong. In the world of Internet governance, the future is now, as regulators want online services to predict and prevent safety threats before they actually occur. more

IP Address Distribution Doesn’t Fit in the Registry/Registrar Model

At the IGF2010 in Vilnius, two folk are floating a trial balloon about separating the allocation function from the registry services function. Currently, these functions are seen as indivisible by the Internet addressing community. In other words, one gets an allocation or assignment from a RIR and the RIR adds the assignment to their database... The question being asked is "Is it time for a split between allocation and services for Internet number resources as was the case for domain name resources?" My answer is no more

Transmissions from the Past: Radio and Email on Mobile Devices

Apparently, along with trying to change who gets paid when the music gets played, the National Association of Broadcasters is lobbying Congress to require FM radio receivers to be built into phones and other mobile devices. I'm sure this is in part a reaction to the rise of streaming music apps like Pandora and the Public Radio Player, but they want FM receivers in not-so-smart phones too. more

Competition to Regional Internet Registries (RIR) for Post-Allocation Services?

Is it time for a split between allocation and services for Internet number resources as was the case for domain name resources? Back in 1996, Network Solutions had essentially four different government granted monopolies... In 1997, Network Solutions "spun" off the 3rd and 4th monopoly into a non-stock corporation known as American Registry for Internet Numbers (ARIN) which has continued the monopoly for its region after spinning off several other Regional Internet Registers (RIR) which are in themselves monopolies. more

Why I Support Canadian Presence Requirements for .CA Domain Names

It nearly goes without saying that if ".CA" means and should continue to mean, "Canada", the registration of a .CA domain name ought to involve some tie to Canada. As Canadian Internet Registration Authority ("CIRA") CEO, Byron Holland, aptly put it, "The fundamental requirement of having a Canadian presence in order to get a dot-ca domain name make sense...because it is a country code and there is an assumption that there is some "Canadian-ness". And that is why, in a nutshell, I support a Canadian 'presence requirement' for the registration of .CA domain names. Nevertheless, the question of what constitutes an appropriate 'presence requirement' is an interesting issue... more