Well said, and spot on. +1!
Many (most?) of the new gTLD registry agreements require searchable whois and such functionality is restricted to authenticated users. The RDAP profile even mentions this in 2.1 ("Registries offering searchable Whois service (e.g., per exhibit A of their RA) MUST support RDAP search requests for domains and entities.") Yet - though your proposal is mentioned - the public comments page glosses over the need for authentication saying "ICANN notes that for the three gTLDs that have differentiated access in their registry agreements, there are, at least two models." Three gTLDs? No, anyone offering searchable whois is required to do so only to authenticated users.