  Heidi Ullrich:All ALAC statements, including on the topic of WHOIS, are available here:
  Matt Ashtiani:Affirmation of Commitments -
  Heidi Ullrich:WHOIS Expert Working Group:
  Gisella Gruber-White:REMINDER - Please speak at a reasonable pace for the interpreters
  Matt Ashtiani:SSAC054 -
  Heidi Ullrich:SSAC 51 -
  Matt Ashtiani:SSAC 55 -
  Garth Bruen:Back, browser crash
  Holly Raiche:What about the DNRD model in the agenda?
  Gisella Gruber-White:Evan Leibovitch is our next speaker
  Garth Bruen 2:Per Avri, not all registrants are created equal. If we are going to apply protections to endangered folks (and I agree we should somehow) we must also acknowledge that commercial entities with industry regulations on disclosure do NOT have a choice masking or lying in WHOIS records.
  Avri has a great model as well.  lots of good models out there.
  Jordi Iparraguirre ( .cat we managed to negotiate a change in contrat to provide privacy in our whois. System similar to .fr but .cat is a gTLD
  Garth Bruen 2:"Accurate-ish"
  Jordi Iparraguirre ( data for personal websotes (no bisiness) are public. For private uses or individuals, they may opt-out and hide private data. Law enforcement , registrars, icann, ... have acces to full whois data
  Garth Bruen 2:@Jordi, not true. ICANN for one does not have access to all the WHOIS data
  Garth Bruen 2:Recent breach notices have shown WHOIS data being wholy controlled by a reseller
  Rudi Vansnick:@Jordi : WHOIS data is not public if registration is private !
  Don Blumenthal - Public Interest Registry:Define "private." Is something "private" if it can be reached by law enforcement subpoena?
  Jordi Iparraguirre ( is a process to ask for full access if youmare really legitimate
  Garth Bruen 2:And Law Enforcement only has access through due process(as expected) it's not automatic
  Jordi Iparraguirre ( u use port 43 or web, data of who has opt put won't be shown.
  Michele Neylon:Alan - each registry has a contract with ICANN which is different, so they have an "option" - ask the guys in .cat - and they'll tell you how much pain they had
  Rudi Vansnick:for instance in .be : you can define you don't want to make your identity public, of course LEA will always have access
  Michele Neylon:Rudi - same for .eu and other ccTLDs
  Garth Bruen 2:But then who decides who is "legitimate" and can get access
  Luc Seufer:@Rudi local LEA i.e. those having jurisdiction
  Garth Bruen 2:This assumption that law enforcement should have speedy access in ALL cases violates the purposes of hiding registrant identifications in the cases layed out by Avri.
  Garth Bruen 2:You have people who, for good reasons, are hidding from their governments. Openning the records automatically for "Law Enforcement" would include every thuggish "police force"
  Luc Seufer:not all cases, those for which LEA have a court order to gain access to the details
  Michele Neylon:Garth - local LEA only.
  Michele Neylon:Local to the registrar or registry
  Michele Neylon:(depending on who holds the data obviously)
  Rudi Vansnick:@Luc : correct local LEA
  Garth Bruen 2:@Michele, I;m talking about that too!
  Michele Neylon:I won't act on a notice from a non-Irish LEA
  Rudi Vansnick:one LEA can ask to another to have access
  Michele Neylon:Rudi - yes
  Don Blumenthal - Public Interest Registry:Rudi, cross border requests generally involved a lot of red tape.
  Luc Seufer:if  there is a cooperation treaty between the crountries of those 2 LEAs
  Evan Leibovitch:It would surprise me if bad actors were not jurisdiction-shopping for domains, as is already done for incorporation and banking
  Avri Doria:I think we do have problems with the Thug countries of  Autocracy 1 and perhaps even Nice Thugs of Autocracy 2.0.  This problem is larger than anything ICANN can deal with.  Adhering to a Rule of Law standard of due process for Reveal works in the non autocratic places.
  Evan Leibovitch:Of course,  no matter what ICANN does, ccTLDs on their own may choose to enable -- or even encourage -- contact obfuscation in order to increase sales.
  Michele Neylon:Evan - most ccTLDs aren't commericial entities
  Luc Seufer:@Evan what do you mean?
  Garth Bruen 2:@Michele, some are completely. How do you fell about a ccTLD which has been wholy sold to foreign company?
  Lutz Donnerhacke:Luc: Evan is pointing out, that most ccTLDs are free to choose there own rules.
  Don Blumenthal - Public Interest Registry:Non-public whois in ccTLDs is a long-standing problem for LE. .nu was a porn domain haven when I was working cases.
  Luc Seufer:The .FR Registry did not choose to hide individual details in the whois. It was a binding recommendation from the French DPA. Not a commercial choice from the Registry
  Holly Raiche:@Evan - in Australia, most of the names ARE commerial - using
  Evan Leibovitch:@Michele ... it doesn't take many. It may take only one, in fact. But we already know of a number of ccTLDs that act as gTLDs even though they hide behind the ccTLD sovereignty rationale
  Garth Bruen 2:@Don, .nu run from Massachuettes in the U.S.! Where's the sovereignty?
  Evan Leibovitch:@Luc. I mean that a ccTLD may choose to ignore reasonable practice imposed (and supposedly enforced) upon gTLDs by ICANN
  Evan Leibovitch:It is good that many follow -- and in some cases exceed -- ICANN standards.
  Holly Raiche:@Evan - Oz certainly exceeds what is done in the gTLD space
  Don Blumenthal - Public Interest Registry:Garth, good question on jurisdiction. I raised that at the time but I don't know that anyone has formally made the legal argument that jurisdiction attaches where a registry is administered. I think that .nu was managed by a Seattle company at the ime.
  Evan Leibovitch:From the At-Large PoV, end-users don't have any idea what jurisdictions are in play for most TLDs.
  Volker Greimann:should 99% of registrants suffer the loss of privacy and freedom due to the acts of 1% of miscreants?
  Evan Leibovitch:Look at the sales pages for .co ... look how far you need to go for any reference to Colombia
  Don Blumenthal - Public Interest Registry:But some have vested interests, good or gad, in knowing.
  Don Blumenthal - Public Interest Registry:Good or bad (obviously)
  Evan Leibovitch:@Volker -- you have to demonstrate a loss of freedom. I don't accept it as an article of faith
  Volker Greimann:registrars are victims of bad registrants as well
  Garth Bruen 2:@Volker it is clearly a problem if the "1%'ers" are 90% of a portfolio
  Volker Greimann:I can only speak from our perspective and for us it is 1%. Not 90% of any portfolio.
  Volker Greimann:in our customer base at least
  Garth Bruen 2:Ha, I can show you some with 90%, be careful what you wish for
  Jim Galvin:DNRD stands for Domain Name Registration Data
  Jim Galvin:It is from SAC 054
  Volker Greimann:please do. We have no interest in illegal activity under our accreditation.
  Avri Doria:i use the term 'giggle test'  if the claim makes you laugh then maybe it is not legitimate.
  Avri Doria:Does a msipelling make Whois data inaccurate?  How much of a mispelling?
  Garth Bruen 2:@Michele, specifically in terms of 3.7.8. Where does it say the Registrar must/shall correct inaccuracy?
  Avri Doria:If you can still reach someone through email, but their phone has been detached for non payment, is the data inaccurale.
  Garth Bruen 2:Of course, you take notices from compliance seriously, but those notices are not about 3.7.8
  Luc Seufer:more importantly reachable doesn't meanthe registrant is forced to reply to you ethier via email or to pick up the phone
  Avri Doria:must someone have a phone to register a domain name?  does the absence of a phone make a difference?  How about if I use my skype contact number?
  Alan Greenberg:@Michele, issue is not with honorable registrrs, but those who might be less so.
  Michele Neylon:Avri - one of the questions we've been asking ICANN in the RAA negotations I think
  Garth Bruen 2:The enforcement is only to your investigation. You are speaking from your responsibility as businessman, I'm talking about the enforceability of the contract in a registrar's failure to correct or delete.
  Holly Raiche:@avri - the Final Report did distinguish between totally accurate, accurate where the registrant can be reached and totally inaccurate where the registrant cannot be reached
  Avri Doria:Holly, so we only care about totally inaccurate?
  Garth Bruen 2:@Michele, the way you have described the situation is excatly as the situation is. The enforcement of WHOIS inaccuracy is at your discretion. While you may do a good job, the fact I'm speaking to is that ICANN has no contractual hold over registrars to correct or delete.
  Michele Neylon:@Fatima algunos de nosotros entienden
  Michele Neylon:Garth - if you worked with registrars you'd get less pushback
  Michele Neylon:arguing with me over a single clause doesn't help your cause
  Luc Seufer:The number of inaccuracy notices we received in the past  from "complainants" who in fact turned out to be prospective buyers of domain names irritated that the registrant did not reply to their buying inquiries.. So it is good to put some common sense when treating those
  Michele Neylon:nor does it make it easy for me to push for certain things in industry
  Michele Neylon:Luc - I hear Google get a LOT of those
  Holly Raiche:The  Issues Report on Whois said that a proxy service was, in fact just acting as an agent.  A privacy service should be accredited as such - which was in the Final Report
  Michele Neylon:or rather their registrar does
  Garth Bruen 2:@Michele, you've told me I'm wrong but not how. Anything else is ad homimem
  Evan Leibovitch:+1 for the  cage match between Garth and Michele?
  Evan Leibovitch:It doesn't take a lawyer to determine if something exists in the RAA.
  Evan Leibovitch:especially an authority to act
  Volker Greimann:a lot of these issues will become non-issues under the new RAA anyway
  Avri Doria:Evan, often it does take a lawyer, or even a court, to decide if an obligation exists in a contract.
  Michele Neylon:Volker - yes
  Garth Bruen 2:@Michele, you answered my question. Thank you.
  Matt Ashtiani:At-Large Whois Registrant Identification Study, Draft Report Workspace -
  Holly Raiche:The problem is to determine what is practicable and reasonable - and we need to talk with each other to come up with a workable answer
  Garth Bruen 2:@Michele, you're not a lawyer, but I'm sure you would have your lawyer read any breach notice relating to 3.7.8 and he/she would advise you to sue ICANN, and they would be right.
  Avri Doria:I think the directory services work is essential for giving us the ability to develop reaosnable policies.
  Heidi Ullrich:All previous ALAC statements have been posted on the agenda page:
  Avri Doria:we can talk all we want, but until we have new tools that allows levels of access and reveal, we are just all pounding our heads into the wall.
  Garth Bruen 2:@Michele, my point was made in your answer. If a registrar had tens of thousands of ignored inaccuracies, they would have to dig up a different reason to breach them.
  Heidi Ullrich:Announcement of Expert WG:
  Matt Ashtiani:At-Large Expert gTLD Directory Services Working Group Workspace -
  Michele Neylon:FYI - as a member of the EWG - we have our first call tomorrow
  Michele Neylon:and our first meeting next week
  Michele Neylon:can't really say a whole lot until after we've had our first meeting etc
  Garth Bruen 2:@Michele, this is less of an argument between us than you think.
  Heidi Ullrich:There will be an At-Large WHOIS WG Meeting during the ICANN Meeting in Beijing - Wednesday, 10 April - 15:00-16:00.
  Avri Doria:I beleive it is NEVER too late to get involved in a PDPD
  Avri Doria:i mean a PDP
  Avri Doria:until it publishes its FINAL Report, perhaps.
  Alan Greenberg:QUite correct Avri. Even after final report there is always a comment period...
  • No labels