News: 1592909172

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Facebook accused of trying to bypass GDPR, slurp domain owners' personal Whois info via an obscure process

(2020/06/23)


Facebook is accused of attempting to bypass Europe's hard-line privacy legislation and access personal data on domain name holders through an obscure policy process with the Whois registry.

Earlier this month, the CEO of domain registrar Namecheap Richard Kirkendall warned “Facebook is fighting for the blanket right to access your information,” and detailed efforts behind the scenes at DNS overseer ICANN to force through Facebook’s interpretation of privacy laws to slurp data on domain holders. Facebook ostensibly wants the info so it can track down and sue anyone who creates a domain or site that even vaguely sounds or looks like Facebook, including those masquerading as legit Facebook web properties to harvest people's login details.

ICANN is engaged in an effort to replace its outdated Whois database, which links domain names to their owners' contact info, with one compatible with Europe’s privacy-protection GDPR, a process that has been going on for nearly three years.

Progress has been slow going, in large part because commercial entities desperately want access to the full registration data of domains – which includes people’s home addresses, telephone numbers and email addresses – and have been trying to find ways around the privacy protections.

The first phase of the project was supposed to be in place by the end of February, and is still not done. The second phase had a deadline of this month and has already been extended in July. Over a year ago, the US government said its patience was [1]running out .

Kirkendall revealed in a [2]blog post that, in its latest effort to gain access to the mountain of Whois domain data, Facebook insisted it has a “legitimate interest” in the information. That term comes straight from GDPR legislation, though the social media giant has tried to reinterpret the expression outside of the context of GDPR to grant it constant access to private data.

Won't take no for an answer

While ICANN’s so-called expedited policy development process (EPDP) team tries to figure out how to grant access to such data, Facebook’s representative – who is a former member of ICANN’s policy team – has been pushing the wonks to grant Facebook a look-see, despite repeat refusals by the registries and registrars who argue that the Silicon Valley corporation has no right to the data and should use established legal avenues to obtain the information.

Haunted by Europe's GDPR, ICANN sharpens wooden stake to finally slay the Whois vampire [3]READ MORE

Access to full domain data through ICANN’s upcoming System for Standardized Access/Disclosure ( [4]SSAD ) approach will only be allowed for law enforcement and companies that provide domain resolution services on behalf of ICANN – so-called Uniform Domain-Name Dispute-Resolution ( [5]UDRP ) providers. However, commercial companies claim that their rights must also be considered, particularly around trademarks, and they should also be granted access.

Facebook has been particularly aggressive, filing tens of thousands of requests for data on domains that are often only tangentially related to its trademarks and insisting its rights are being infringed. When those requests have been rebuffed, Facebook has then sued the companies that people used to register the names, claiming trademark infringement and demanding $100,000 in compensation.

Namecheap’s Kirkendall is aware of this approach because his company is one of those being [6]sued [PDF] for infringement. Back in March, Facebook [7]lodged a lawsuit and wrote a blog post attacking the registrar for allowing people to register “deceptive” and “abusive” domain names.

But he insists that his company will not cave to strong-arm tactics: “Facebook recently started a campaign where it seeks to market itself as a company striving to protect internet users against cybercriminals,” he wrote.

“In fact, it used this claim when it sued Namecheap because Namecheap refused to hand over its customers’ personal information to Facebook just because Facebook demanded it. In doing so, it is attacking the fundamental right of privacy by attempting to set a dangerous precedent that could expose anyone’s information.”

Namecheap is just one of three registrars, so far, that have been sued by the mega corporations.

Deficient

Earlier this month Namecheap filed to have the case dismissed entirely and [8]mocked [PDF] Facebook’s “attempt to overcome the legal and factual deficiencies in their claims for cybersquatting, trademark infringement, and trademark dilution by relying upon non-existent allegations in the Complaint and misleading arguments.”

It’s not just Namecheap that is fed up with Facebook’s bullying tactics, either. Another [9]recent post by one of the world’s largest registrars, Tucows, gave “examples that are obvious to a layperson as non-infringing” in the context of efforts to streamline the system of asking for domain name data. Almost all of them came from Facebook.

“Instantmonogram.com; letsfacethebook.com – in each of these cases, the domain name contains the whole trademark separated by additional characters ('Insta[…]gram' or 'Face[…]book') but bears no relation to any infringement of it,” the Tucows post noted.

It gave a second category of obvious wrong requests from Facebook: “These do not contain the full trademark but only portions of it or portions of misspellings…” One of the examples? zharfambook.com

And then it has a whole section for “domains that use the full trademark [but] nevertheless evince an indication that the domain is or will be used to discuss grievances with the company in question.” Every one of them comes from Facebook: addictedtofacebook.org, banned-by-facebook.com, divestfacebook.com, facebooksucks.org, protestfacebook.org, saynotoinstagram.com.

The message to Facebook from both Namecheap and Tucows – and many others in the domain industry – is clear: back off, we’re not going to cave under pressure to hand over the personal details of millions of people.

Stubborn

But so far at least, the antisocial network – whose entire business is built on grabbing, storing and monetizing this kind of data – is determined to keep pushing its claims, even if it delays the creation of a new system for everyone else.

Its representative continues to claim that being a registered trademark holder is sufficient to be granted full access to the Whois database, and that all other routes are unduly burdensome.

“You don’t know who to sue until you’ve got the Whois information,” claimed Facebook rep Margie Millam at one such recent meeting. “So it’s backwards to say you have to have a lawsuit and you have to use your subpoena power under the lawsuit to get access to Whois.”

She went on: “If that’s what the contracted parties are saying, that’s a huge problem for us. This SSAD will never solve the problem… the reality is that there are contracted parties that routinely do not look at requests. All they say is, ‘Go get a subpoena,’ or, ‘File a UDRP.’ That’s not the answer that’s going to work for us.”

Kirkendall closed out his blog post by making it plain what he believes is behind Facebook constant efforts: “Does Facebook really care about protecting you from cybercrime or are their recent efforts their newest Trojan Horse to get personal data that Facebook doesn’t have a right to have? We think it is the latter. What do you think?”

A Facebook spokesperson was unable to comment by time of publication. ®

Sponsored: [10]Security Features of Connect for Anthos



[1] https://www.theregister.com/2019/04/08/ntia_icann_whois_hurry_up/

[2] https://www.namecheap.com/blog/the-secret-fight-for-your-personal-information/

[3] https://www.theregister.com/2019/10/23/icann_kills_whois/

[4] https://www.icann.org/news/blog/epdp-team-makes-key-progress-in-phase-2-work

[5] https://www.icann.org/resources/pages/help/dndr/udrp-en

[6] https://regmedia.co.uk/2020/06/22/facebook-namecheap.pdf

[7] https://www.theregister.com/2020/03/06/facebook_namecheap_ads/

[8] https://regmedia.co.uk/2020/06/22/namecheap-facebook.pdf

[9] https://opensrs.com/blog/2020/03/privacy-and-lawful-access-to-personal-data-at-tucows/

[10] https://go.theregister.com/tl/1956/-8474/security-features-of-connect-for-anthos?td=wptl1956

Outragous

Captain Hogwash

Sadly, if I were to try and explain this to the facebook users I know, they would collapse with boredom long before I finished explaining what a domain is.

What do you think it is about

b0llchit

Of course it is about private and personal data. There is only one reason why the asocial media exist and that is for monetizing your data. That is their livelihood. Anything else is a smokescreen to get more information. All those "free" services are there to entice you to give up more information.

Facebook is just one exampe of that business. The other "big" ones do the same thing. However, no one should forget, there are far more smaller players with equally or more aggressive methods to get your data. And then, the big ones are also in bed with those smaller ones. The only safe data is the data that has not been disclosed.

DavCrav

"“You don’t know who to sue until you’ve got the Whois information,” claimed Facebook rep Margie Millam at one such recent meeting. “So it’s backwards to say you have to have a lawsuit and you have to use your subpoena power under the lawsuit to get access to Whois.”"

Yeah, except that's bollocks. It's exactly the route copyright holders usually go. Name a John Doe, subpoena the ISP to obtain the name with some evidence of infringement, then launch a suit against the person.

"We don't know who to sue"

Chris G

Then it is fairly obvious they are not having an impact on Faecebarf.

Zuckerbarf and all those who support him should be renditioned to the bottom of a deep, dark hole on a remote airless planet.

Re: "We don't know who to sue"

[email protected]

This sort of thing is why alien life would never willingly contact humans - not content with polluting our own planet, we are now trying to export some of the worst excrement in existence...

Q: What do you call a WASP who doesn't work for his father, isn't a
lawyer, and believes in social causes?
A: A failure.