EU Privacy Watchdog To ICANN: Law Enforcement WHOIS Demands "Unlawful" 81
First time accepted submitter benyacrick writes "WHOIS was invented as an address book for sysadmins. These days, it's more likely to be used by Law Enforcement to identify a perpetrator or victim of an online crime. With ICANN's own study showing that 29% of WHOIS data is junk, it's no surprise that Law Enforcement have been lobbying ICANN hard to improve WHOIS accuracy. The EU's privacy watchdog, the Article 29 Data Protection Working Party, has stepped into the fray with a letter claiming that two of Law Enforcement's twelve asks are "unlawful" (PDF). The problem proposals are data retention — where registrant details will be kept for up to two years after a domain has expired — and re-verification, where a registrant's phone number and e-mail will be checked annually and published in the WHOIS database. The community consultation takes place at ICANN 45 in Toronto on October 15th."
Who's job is it? (Score:5, Interesting)
Re: (Score:1)
Dear cavreader,
Kindly fuck off.
Sincerely,
500 million EU citizens.
Re: (Score:1)
Thank You. I'll be sure to remember this sentiment the next time your population starts anther culling period. Maybe you will be less a problem when the population gets whittled down to 10 million or so, especially when you end up having to rebuild your stagnant society with US money and US military protection.
Re: (Score:2, Informative)
"The EU is behind more positive changes in IT"
Name one mainstream application platform, development environment, or key technology that isn't built upon technology originally developed in the US or blatantly stolen by countries like China. IBM, MS, Apple, Xerox, Dell, HP, Google, Facebook, Twitter, Oracle, Red Hat, and CISCO are just a few examples of the global IT contributions developed in the US. And while the Internet has grown due to contributions from both inside the US and outside the US the fact
Re: (Score:2)
"The EU is behind more positive changes in IT"
Name one mainstream application platform, development environment, or key technology
I'll name three, off the top of my head:
1. The World Wide Web
2. Linux
3. The ARM CPU
Mod -1 Spam (Score:1)
Mod -1 Spam
Working phone number in whois (Score:5, Insightful)
Re:Working phone number in whois (Score:4, Informative)
you could always get a Google Voice number and not forward it anywhere (or set it to perma-do-not-disturb) - you'd still be able to browse through voicemails if necessary through an email interface
Re:Working phone number in whois (Score:5, Insightful)
That would be a work-around, but it's more reasonable to recognize that it's not reasonable to force someone to publish their phone number to every pointy-headed moron in the world that thinks I owe them my time so they can make a sales pitch in my home.
If 'Law Enforcement' would care to actually pursue said morons when they violate the do not call list or commit various frauds AND they would care to narrow the exceptions to the DNC list, people might not be so resistant to give a real phone number.
It's not like whois is the only hope to track down a domain owner. IF they have a sufficient reason to track them down they can follow the IP address to a provider and present a warrant for the account information OR they can present the warrant to the domain registrar. If they don't have good enough reason to get a warrant, they shouldn't be pursuing it in the first place.
Re: (Score:2)
It's not like whois is the only hope to track down a domain owner. IF they have a sufficient reason to track them down they can follow the IP address to a provider and present a warrant for the account information OR they can present the warrant to the domain registrar. If they don't have good enough reason to get a warrant, they shouldn't be pursuing it in the first place.
Why is your comment not +5 Insightful yet? All this will do is increase business to "Protected Listings" in whois. Oh, wait... I forgot who government works for.
Re:Working phone number in whois (Score:4, Informative)
Yes, damn that government! Except the ones pushing for the more "accurate" WHOIS data is ICANN, a private organization, and the one pushing back is a governmental organization (created by the EU). But don't let facts get in the way of your anti-government diatribe.
Re: (Score:2)
Re: (Score:2)
Give 'em a number they can't call for free. That usually does the trick.
(I don't know how it works where you live but around here cellphones always cost money to call)
Re: (Score:3)
Unfortunately, here you get charged for receiving or making a call on a cellphone.
Re: (Score:3)
Close, The U.S.
Re:Working phone number in whois (Score:5, Funny)
you could always get a Google Voice number and not forward it anywhere (or set it to perma-do-not-disturb) - you'd still be able to browse through voicemails if necessary through an email interface
Bonus points for wasting their time as well as their call charges. Make your answering machine give a lengthy message, such as:
"You have reached the number that you dialed. Please check the number, and try your call again. Your call is important to you. Your patience and perseverance are valuable impediments to your business. Please don't hold. " Repeat that sequence as long as your message allows. A robo-caller will perhaps get confused by the pattern of pauses and statements, and might even bring a human on the line. An actual human will become grumpy and hang up in disgust.
Re: (Score:2, Funny)
You have reached an imaginary number. Please rotate your phone 90 degrees and try the number again."
That usually confuses any human on the line.
Re: (Score:2)
You have reached an imaginary number. Please rotate your phone 90 degrees and try the number again."
That usually confuses any human on the line.
Multiply your imaginary phone numbers by i if you are having trouble dialing.
Re:Working phone number in whois (Score:5, Interesting)
I have a few .uk domains. Because I am a non-trading individual, my details other than my name are not available to the public, but law enforcement can apply to the courts to get the details if my domain names are being used for illegal purposes. That seems to me to be a good balance between allowing law enforcement to shut down websites used to sell fake concert tickets, distribute malware and so on; and catch those responsible while ensuring I don't get continually harrassed by "The Domain Registry of Europe" and similar outfits that law enforcement ought to be going after.
Re: (Score:3)
...but law enforcement can apply to the courts to get the details if my domain names are being used for illegal purposes. That seems to me to be a good balance..."
Yes, but who defines "illegal purposes" and who vets the alleged "illegal purposes" to determine the validity of the request?
"Law Enforcement" is well known to have, shall we say, "unique" ideas about the definition of "illegal purposes". Not only that, "L.E." is also well know to flat-out LIE.
Re: (Score:2)
Yes, but who defines "illegal purposes"
The legislature, acting in their constitutionally provided role as representatives of the people. To be confirmed or vetoed by the president, according to his constitutionally provided role.
who vets the alleged "illegal purposes" to determine the validity of the request?
Judges do, as part of their role in the judicial system. Really, I thought that you would understand this.
Re:Working phone number in whois (Score:4)
The whole point is that law enforcement wants to do an end run around the judge by enforcing the accuracy of the published data and to hell with everyone else.
Re: (Score:2)
Because I am a non-trading individual, my details other than my name are not available to the public, but law enforcement can apply to the courts to get the details if my domain names are being used for illegal purposes. That seems to me to be a good balance
Re:Working phone number in whois (Score:4, Insightful)
A side point is that law enforcement loves for corporations to have have lots of information on individuals that is legally mandated to be correct so they can 'ask' for it without a warrant from a judge. That seems to be their angle here.
Re: (Score:2)
Judges do, as part of their role in the judicial system. Really, I thought that you would understand this.
Here in the USA, judges tend to rubber-stamp warrants, and then there is the Patriot Act, Mr. Snarky. As you say, "Really, I thought that you would understand this."
Re: (Score:2)
Re: (Score:2)
To be fair, he said he was using .uk domains and talking about Europe laws which is what this story is about (EU directive).
I'm sure the names can be changed and so on to make it fit, but there will be some differences because not every country has the same rights protected from government as the ''US" does.
Re:Working phone number in whois (Score:5, Informative)
Exactly. This seems like a good idea, and a balance between the .US TLD policy (all information is public) and the .SE TLD policy (no information other than a unique ID string is available to the public with no contact information -- not even an email is available).
I rather like the implementation of whois privacy used by Gandi.net (a French registrar who handles registration for a bunch of TLDs): for domains that are private-by-default (.SE, .uk for individuals, etc.) then they use the registry for privacy and include no information in whois. For domains where whois privacy is available (.com/net/org, etc.) they include the registrant's full name (so it's clear that they are the ones who legally own the domain) and then provide the Gandi postal address where all mail is presumably shredded. They also provide a unique, randomly-generated email address to protect against spam: if you get spam to that address you can simply push a button and a new, random address is created. Legitimate mail is forwarded on to the contact while spam is filtered out.
Gandi offers these privacy services to individuals only: companies and organizations are assumed to be less in need of privacy protecting services and must include their regular contact information.
I have no problem with law enforcement being able to get the details with a warrant issued by a relevant court, but I think the time for having all personal contact information being made public in whois has passed. It used to be that the name and contact information corresponded to a technical contact at an organization responsible for that domain but now many domains are owned by private individuals and this assumption can no longer hold.
Of course, even with a warrant the whois information for suspected bad guys is unlikely to be of use: I doubt the bad guys put in accurate and correct whois information or pay using their personal credit cards (as opposed to anonymous prepaid cards).
Local Entity Still Required (Score:2)
This does not apply to all European countries, there are still European countries that require that you have a local corporation and registration number to apply for domains [under the national TLD]. I assume you're wrongly using EU as a synonym for all of Europe(?)
The EU only requires that you don't put barriers in place, in any form, that hinder inter-European trade. French and Italian TLDs require a European address, but nothing beyond that.
Europe > EEA > EU (Score:2)
Even within the EU's economic area (EEA), as per your original comment, includes countries that are not members of the EU itself. The same laws apply in the whole EEA-region.
http://en.wikipedia.org/wiki/File:Supranational_European_Bodies.png [wikipedia.org]
It is in fact amongst this group of countries you will the few registrars that [still] require a local entity. I see now that there are very few left...
NORID of Norway's requirements are as follows:
Main requirements .no, you need to:
To register a domain name within
- have
Re: (Score:2)
And what are you using those domains for eh? MFA sites maybe and your trying to hide ownership from the big G
Re:Working phone number in whois (Score:5, Interesting)
This spring, I registered an "ego" domain - My own name dot net, on a whim.
I paid for it with a credit card in my name. I gave a fake phone number, and a PO box for my address. I used a real email address (albeit one made specifically to catch the junk I expected by registering.
And three days later, GoDaddy locked my domain and reversed the charges, refusing to do business with me until I sent them a scan of my driver's license. WTF?
So, I told GoDaddy to go fuck themselves, and registered with a no-name, for less, with automatic free privacy protection (the WhoIs contacts go to them, rather than to me) and that doesn't give the least damn if I want to register as George Bush.
The real problem here involves laziness on the part of law enforcement, pure and simple - IP addresses don't mean LEOs can't track you down, it just means they actually need to come up with enough evidence to convince a judge to demand the ISP turn over the owner's info. It makes doing their job an actual job, rather than a five second query against WhoIs.
Stop expecting to rest of the world to do your work for you, guys. If you need to track me down, do so. But don't expect me to put up with nonstop telemarketers, not to mention the risk of some crazy actually showing up at my door because he doesn't like what I said about Rush Limbaugh, just to save you from having to do some legwork if someday I break the law.
Innocent until proven guilty. Read up on it sometime, eh?
Re: (Score:2)
The real problem here involves laziness on the part of law enforcement, pure and simple - IP addresses don't mean LEOs can't track you down, it just means they actually need to come up with enough evidence to convince a judge to demand the ISP turn over the owner's info. It makes doing their job an actual job, rather than a five second query against WhoIs.
IP addresses are useless as anyone doing fraud can easily move from cafe to cafe to maintain their site(s).
I could see having to get a warrant to get at the identification data kept by a registrar but in order to be useful this still requires the registrar to make sure of your identity when you sign up. I have no problem with this so long as the registrar then has to abide by the (in my case EU and thus actually existant and useful) data protection / sharing rules and has an opt out (or better an opt in) f
Re: (Score:2)
So you (and a million criminals) stay anonymous. Hey, how about dealing with the bastards running the robo-dialers, eh? Fix the problem, don't avoid it.
"Oh, we don't go down that road: too many robbers."
Riii-ight.
just attach a website to a phone number (Score:2)
you need to type in a PIN that is SMSed to the phone to register the website. filter out online only phone numbers. phone numbers can be traced to an owner, or "oh yeah, my boyfriend {XYZ} borrowed my phone that day" which is law enforcement due diligence when investigating crime
seems to be about as good a system as you can hope for
Re: (Score:3)
phone numbers can be traced to an owner
Not where I live (European country): you can get an anonymous prepaid SIM card easily - mobile operators often offer them as promotional gifts, too. And you can add money using cash on many small shops.
Re: (Score:2)
so then, there's just no hope for connecting a website to a real person
Re: (Score:1)
That.. is a good thing..Whatever it takes to get rid of the all too corruptible DNS. Nuke it from orbit, if need be.
Re: (Score:2)
do you have a superior solution?
Re: (Score:2)
+1 funny
"Law Enforcement?" (Score:2, Insightful)
I didn't RTFA, but who exactly is "Law Enforcement?" The capitalization makes it seem like it's the proper name of some organization.
Re: (Score:1)
..who exactly is "Law Enforcement?
Anybody with a gun and a badge to hide behind when they go rogue.
Re: (Score:3)
Re: (Score:2, Informative)
I didn't RTFA, but who exactly is "Law Enforcement?" The capitalization makes it seem like it's the proper name of some organization.
Reading the articles would not help, their description does not go beyond this:
ICANN and the Registrars have engaged in six additional negotiation sessions, including two all-day, in-person meetings held in Washington D.C. (one of which was attended by Governmental Advisory Committee members and law enforcement representatives).
"law enforcement representatives" without capitalization.
Read the truth about ICANN and the DNS (Score:1)
The rotten and corrupt Domain Name System [kimmoa.se].
"asks" (Score:2)
Also known as questions in plain English. Or in this instance, possibly requirements.
Re: (Score:1)
Indeed.
Ask #1: Use proper English
I can give up the on line aspect of the computer. (Score:1)
It might become like flying I was a regular, I no longer fly.
Some thing others want worse than I do.
Prices gets high on grocery items I don't buy them, the store wants them worse than I do.
Same with products and services cost to much in my time or money I find something else to do.
When it's Free to be Anonymous, (Score:2)
I'll give the correct information on my domains. Until then, ICANN can go fuck itself. I'm tired of receiving spam sent to the address I use on my WHOIS listings.
Re: (Score:1)
I just use a privacy feature that Network Solutions or other domains have. No spam here so far. Yes, it costs more, but it does work.
As for ICANN, people may bellyache about them, but they are a lot better than the alternative that the UN is trying to push. The UN's replacement would not be limited in actions by bad press unlike ICANN. It also means a website in the US gets shut down and thrown off the Internet because someone across the world considers it against their lese majeste laws, or that sites
Re: (Score:2)
Oh, I know they work, but I refuse to pay extra for something they should be requiring my registrar to supply for free. It's very simple--if they require me to supply real information, they need to also make it a requirement that I can hide that information from harvesters for no extra charge. Until that happens, I'll continue to use false information. I'm not saying that ICAN
Re: (Score:2)
that shit shouldn't cost a dime
Re: (Score:2)
As does Gandi and Hover (customer only, no other affiliation).
Re: (Score:2)
As does NameSilo.com. They've got some of the lower prices I've seen. You can use coupon code BUCKOFF to save a dollar on your first order with them.
Internet.bs has low prices also and always free whois privacy. They don't generally do coupons though.
Re: (Score:2)
Thanks, folks, I'll check them out.
All Of Which Is Trivially Defeated (Score:2)
They might hope that Whois would allow them to short-circuit the good old-fashioned policework method of following the money, but I'm a
Does "ask" have to become a noun? (Score:2)
two of Law Enforcement's twelve asks are "unlawful"
Can't you call them "requests" like a normal person?
WHOIS - and ICANN - is worthless anyways (Score:2)
The real question is who is the idiot who told law enforcement officers that there is meaningful data in the WHOIS databases anyways. I would bet that the ICANN assertion of 29% of it be
Just subterfuge (Score:1)
Welcome to another New World Order / Law Enforcement Policy. Make up your own mind; but those are my thoughts.
Comes down to the desire of anonymity vs contact (Score:1)