[HN Gopher] Proposed Renewal of the Registry Agreement for .NET
       ___________________________________________________________________
        
       Proposed Renewal of the Registry Agreement for .NET
        
       Author : thesuperbigfrog
       Score  : 52 points
       Date   : 2023-04-20 12:05 UTC (10 hours ago)
        
 (HTM) web link (www.icann.org)
 (TXT) w3m dump (www.icann.org)
        
       | ksec wrote:
       | Arh, ICANN and VeriSign. Both have deliberately stalled on .Web
        
       | kensai wrote:
       | I found the explanation of the various domain names the best:
       | https://www.name.com/domains/net
       | 
       | If you want to check any other domain name, just substitute the
       | "net" with your own name. https://www.name.com/domains/
        
       | Zecc wrote:
       | This is about the .net TLD and has nothing to do with .NET the
       | framework.
       | 
       | It doesn't take long to realize this, it's even outright obvious
       | considering ICANN is involved, but still... It seems weird to me
       | that they would write .NET and .COM rather than .net and .com
       | even if DNS is case-insensitive.
        
         | saghm wrote:
         | After over 20 years of ambiguity, I don't think I'd honestly
         | have the energy to worry about this if I were the person at
         | ICANN deciding the headlines; it could have easily been avoided
         | had the .NET framework just picked a less confusing name.
        
         | lolinder wrote:
         | Using all caps goes back to the very first RFCs, so they
         | probably stick to that for historical reasons even if the
         | modern convention is lowercase.
         | 
         | https://datatracker.ietf.org/doc/html/rfc920#page-2
        
           | mindslight wrote:
           | I think in the past, internet signals were much weaker so
           | EVERYONE HAD TO YELL to get their message through. Either
           | that or 1-bits were in short supply.
        
           | tenebrisalietum wrote:
           | NO, HERE IS THE REASON WHY:
           | 
           | - THE INTERNET STARTED IN THE 1960'S.
           | 
           | - THE FIRST VIDEO DISPLAY TERMINALS THAT CAME OUT IN THE 70'S
           | DIDN'T SUPPORT LOWERCASE, E.G. THE DEC VT05.
           | 
           | - PHYSICAL TELETYPES AT THE TIME ALSO WEREN'T GUARANTEED TO
           | SUPPORT LOWERCASE, LIKE THE DECWRITER LA05.
        
             | derefr wrote:
             | Fun fact: the earliest versions of the ASCII standard only
             | had encodings for uppercase letters.
             | (https://en.wikipedia.org/wiki/ASCII#History)
        
               | Xorakios wrote:
               | FORTRAN, COBOL and BASIC all used all caps in the 70s
               | when I started to learn programming. People thought I was
               | a nutcase for abandoning cursive in high school!
               | 
               | And don't get me started on punch card programming in
               | college in 1980 :)
        
               | eyegor wrote:
               | Despite ~60 years of updates, the fortran language still
               | isn't case sensitive.
        
               | Wowfunhappy wrote:
               | Why were people still using punchcards in the 80s?
        
               | tanseydavid wrote:
               | To make confetti out of the chads for parades. ;)
        
               | Xorakios wrote:
               | Alas, at Princeton University 1980 that was the only way
               | to submit programs. I was doing tech support for
               | professors as part of my work-study package and a couple
               | hours a week on a green-bar paper teletype sorta like
               | this was a huge benefit: https://www.howtogeek.com/wp-
               | content/uploads/2021/05/teletyp...
        
             | cesarb wrote:
             | Fun trick (I don't know if it still works): on the login
             | prompt of your Linux (or other Unix) machine, type your
             | username in all caps. This sets some strange termios(3)
             | modes, which convert all lowercase output to UPPERCASE and
             | all UPPERCASE input to lowercase. These modes are, AFAIK,
             | for compatibility with these uppercase-only terminals.
        
               | chrismorgan wrote:
               | Just tried it. Didn't work.
               | 
               | (I tried it on a regular Linux virtual terminal (as is my
               | normal way--I don't use a graphical login manager), with
               | my password in correct/inverted/upper/lower case, none
               | work. It's conceivable a pam module could make it work or
               | something like that. I'm not investigating.)
        
               | tracker1 wrote:
               | good luck with multi-case passwords...
        
               | codetrotter wrote:
               | Wait. You guys use passwords on your computers??
        
               | zdimension wrote:
               | You got any more info on that? I can't find anything
               | online that talks about this trick
        
       | thesuperbigfrog wrote:
       | Additions in section 2.14 of the changes / redline document
       | (https://itp.cdn.icann.org/en/files/registry-agreement/redlin...)
       | are concerning:
       | 
       | "Registrar further acknowledges and agrees that Verisign reserves
       | the right to deny, cancel, redirect or transfer any registration
       | or transaction, or place any domain name(s) on registry lock,
       | hold or similar status, as it deems necessary, in its unlimited
       | and sole discretion, for the purposes set forth in Section
       | 2.7(b)(ii) of this Agreement."
        
         | rasengan wrote:
         | This makes sense since they are leasing domain names to you and
         | not selling them to you.
         | 
         | You don't own your Domain on the ICANN internet - and yes, that
         | sucks.
        
           | thesuperbigfrog wrote:
           | >> You don't own your Domain on the ICANN internet - and yes,
           | that sucks.
           | 
           | True, but how should disputes be resolved?
           | 
           | Under this proposed change, if Verisign decides to cancel the
           | lease for your .net domain, what can you do about it?
        
         | noja wrote:
         | Do you know why?
        
         | thesuperbigfrog wrote:
         | Section 2.7b states:
         | 
         | "Registrar's registration agreement with each Registered Name
         | Holder, shall also include the following:
         | 
         | (i) a provision prohibiting the Registered Name Holder from
         | distributing malware, abusively operating botnets, phishing,
         | pharming, piracy, trademark or copyright infringement,
         | fraudulent or deceptive practices, counterfeiting or otherwise
         | engaging in activity contrary to applicable law and providing
         | (consistent with applicable law and any related procedures)
         | consequences for such activities, including suspension of the
         | registration of the Registered Name
         | 
         | (ii) a provision that requires the Registered Name Holder to
         | acknowledge and agree that Verisign reserves the right to deny,
         | cancel, redirect or transfer any registration or transaction,
         | or place any domain name(s) on registry lock, hold or similar
         | status, as it deems necessary, in its unlimited and sole
         | discretion:
         | 
         | (1) to comply with specifications adopted by any industry group
         | generally recognized as authoritative with respect to the
         | Internet (e.g., RFCs),
         | 
         | (2) to correct mistakes made by Verisign or any Registrar in
         | connection with a domain name registration,
         | 
         | (3) for the non-payment of fees to Verisign;
         | 
         | (4) to protect against imminent and substantial threats to the
         | security and stability of the Registry TLD, System, Verisign's
         | nameserver operations or the internet,
         | 
         | (5) to ensure compliance with applicable law, government rules
         | or regulations, or pursuant to any legal order or subpoena of
         | any government, administrative or governmental authority, or
         | court of competent jurisdiction, and/or
         | 
         | (6) to stop or prevent any violations of any terms and
         | conditions of this Agreement, the Operational Requirements, or
         | pursuant to Verisign's Registry Agreement with ICANN; and
         | 
         | (iii) a provision requiring the Registered Name Holder to
         | indemnify, defend and hold harmless Verisign and its
         | subcontractors, and its and their directors, officers,
         | employees, agents, and affiliates from and against any and all
         | claims, damages, liabilities, costs and expenses, including
         | reasonable legal fees and expenses arising out of or relating
         | to, for any reason whatsoever, the Registered Name Holder's
         | domain name registration. The registration agreement shall
         | further require that this indemnification obligation survive
         | the termination or expiration of the registration agreement."
         | 
         | So basically Verisign has full authority to do whatever it
         | wants regarding .net TLD domain names in order to prevent
         | crimes and bad behavior, comply with laws, correct errors (who
         | defines what is an error), and collect fees.
         | 
         | Many people are upset with these proposed changes because there
         | are no recourse procedures outlined for domain holders.
         | 
         | If you hold a .net domain which you paid for and have been
         | using for years and they decide that you are doing something
         | they do not like or someone else claims ownership rights for
         | your domain and convinces Verisign that they should have it,
         | your domain can be forcibly transferred from you.
         | 
         | If you disagree with what they do, too bad.
        
         | lolinder wrote:
         | Below are the purposes in 2.7(b)(ii). Note that the prior
         | agreement already included purposes 1-3, but 4-6 are new.
         | 
         | > (1) to comply with specifications adopted by any industry
         | group generally recognized as authoritative with respect to the
         | Internet (e.g., RFCs),
         | 
         | > (2) to correct mistakes made by Verisign or any Registrar in
         | connection with a domain name registration, or
         | 
         | > (3) for the non-payment of fees to Verisign; and,
         | 
         | > (4) to protect against imminent and substantial threats to
         | the security and stability of the Registry TLD, System,
         | Verisign's nameserver operations or the internet,
         | 
         | > (5) to ensure compliance with applicable law, government
         | rules or regulations, or pursuant to any legal order or
         | subpoena of any government, administrative or governmental
         | authority, or court of competent jurisdiction, and/or
         | 
         | > (6) to stop or prevent any violations of any terms and
         | conditions of this Agreement, the Operational Requirements, or
         | pursuant to Verisign's Registry Agreement with ICANN;
        
           | derefr wrote:
           | > (1) to comply with specifications adopted by any industry
           | group generally recognized as authoritative with respect to
           | the Internet (e.g., RFCs),
           | 
           | This clause is probably the original motivation for this
           | subsection (with 4, 5, and 6 being "obvious" corollaries of
           | it): the .net TLD is the (de-facto?) place where Autonomous
           | Systems expect to be able to register conventionally-named
           | zones (format AS\d+\\.NET), under which they then often
           | register DNS names for things like backbone Internet
           | switches.
           | 
           | Insofar as these ASes might be binding control-plane
           | components to network middleboxes through these DNS names
           | (unlikely, given the layer of the stack they operate on, but
           | you never know), a takeover of their AS\d+\\.NET domain-name
           | would enable a wide-ranging attack on Internet
           | infrastructure.
           | 
           | Additionally -- though much less likely -- you _might_ be
           | able to do some nefarious things just by squatting on an
           | AS\d+\\.NET domain name. If some engineer at the NOC is new
           | there, and worked for other AS NOCs who _did_ use AS\d+\\.NET
           | domain names to home equipment, but their new job doesn 't,
           | but they don't _know_ that yet, they might misconfigure a
           | system in a way that 'd be innocuous if the domain was
           | unregistered, but very bad if it was registered to an
           | attacker.
        
         | candiddevmike wrote:
         | Is this a requirement from the US government for Verisign?
        
       ___________________________________________________________________
       (page generated 2023-04-20 23:03 UTC)