...I forgot to add a link to the second SSAC report: https://par.icann.org/files/paris/SSACReportonDomainNameFrontRunning_24Jun08... Gabi -----Original Message----- From: Gabriella Schittek Sent: Saturday, August 16, 2008 5:11 PM To: 'Patricio Poblete' Cc: 'ccnso-council@icann.org' Subject: Clarification on question on front-running Hi Patricio, Whilst doing the minutes from the last council call I listened to the recording and I realised I misunderstood one of your questions regarding Domain Name Front Running. You asked "In the [domain name front running] briefing paper it is mentioned that front running also could be done by third parties through ISPs or by spy-ware. Is it really happening in that way, or is it just a possibility?". Then Chris asked me where I had that information from. The correct answer to this is that the information on the various methods derives from the first SSAC report which was published in October 2007 - see http://www.icann.org/en/committees/security/sac022.pdf, page 5 under the heading "Methods of Monitoring and Identifying Domain Names of Interest". However, the SSAC also writes in its report that "We include all the opportunities mentioned here; however, SSAC does not claim that any or all these methods are currently being used, or that this list is exhaustive, only that these represent plausible opportunities for gathering and monitoring domain names of interest to prospective registrants, and that these have been related to SSAC by parties who have anecdotal or partial information regarding a possible domain name front running incident." In the follow-up report, one of SSAC's conclusions is that (Page 8, finding 4): "Various acts of collecting names of interest from DNS, WHOIS, domain name availability checks, and other resources to preemptively register a domain name may appear to be unfair, improper and even criminal to registrants but these conclusions are not necessarily established facts." So, basically, yes, according to the SSAC report this is just a possibility, but there is no real proof it is happening. I hope this clarifies. Gabi
participants (1)
-
Gabriella Schittek