News: 1634301124

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

German Pirate Party member claims EU plans for a GDPR-compliant Whois v2 will lead to 'doxxing and death lists'

(2021/10/15)


The European Union has drawn the ire of privacy activists for proposals to put real names and contact details back into Whois lookups, as part of its Network and Information Systems (NIS) Directive.

The EU Commission's draft update to the NIS Directive has been slowly grinding through the bloc's bureaucracy, and this week German Pirate Party MEP Patrick Breyer [1]declared it "a big step towards abolishing anonymous publications and leaks on the internet."

Why? Because the draft directive's explanatory memorandum

[2]PDF

says domain registries will have to "establish policies and procedures for the collection and maintenance of accurate, verified and complete registration data, as well as for the prevention and correction of inaccurate registration data."

[3]

What won't be happening, however, is the free publication of names and contact details. Currently the draft text of article 23 states: "Member States shall ensure that the TLD registries and the entities providing domain name registration services for the TLD publish, without undue delay after the registration of a domain name, domain registration data which are not personal data. "

[4]

[5]

That italicised line seems to have passed by an awful lot of very shouty people.

Data, data, everywhere, nor any drop to scrape

Doxxing domain registrants is what used to happen until 2018, when the EU's General Data Protection Regulation came into force. Gathering and publishing personal data online without registrants' explicit consent to publication of it was in breach of GDPR and therefore the regs [6]caused the death of the creaky old protocol underpinning Whois .

Once a useful system back in the early days of the World Wide Web, Whois showed who owned a given web domain name, listing name, street address, postcode, and sometimes phone numbers too. In more recent years unscrupulous registrars stopped checking the accuracy of the information – and registrants became less keen on handing it over as marketers scraped the data. Systems protecting Whois from abuse [7]were sometimes pretty poor .

Now, however, the EU, having [8]spent considerable time and effort defending its position , wants to mandate a GDPR-compliant form of Whois – something the Pirate Party's Breyer described as licence to create "death lists" as well as carrying out "data theft and loss, stalking and identity theft, doxxing," and more. He appears not to have read draft article 23 of the updated NIS Directive.

[9]

Chad Anderson, a senior security researcher for threat intel firm DomainTools, told The Register : "For those that say this will be a hit to whistleblowers and activists: that's hogwash as they should all be using Tor and pre-built sites anyways to protect their anonymity... Leak sites will still exist and alternative registrars still exist. All of the problems for maintaining a private internet where activists can work have already been solved."

He added that the infosec industry has "found other ways of fingerprinting actors based on tactics, techniques, and procedures (TTPs)," saying:

For those that say this is a hit to privacy: this operates the same way it would if you were buying property anywhere else. Yes, it's digital property, but you should have to be responsible for that permissive SPF record allowing relay of malware spam in the same way you have to be responsive when there's a gas leak on physical property.

[10]Be careful what you inline: Defunct video-hosting domain used to inject smut flicks into news articles, more

[11]APNIC left a dump from its Whois SQL database in a public Google Cloud bucket

[12]You've got to be shipping me: KatherineRyan.co.uk suggests the comedian has diversified into freight forwarding

[13]ICANN begs Europe: Please fill in the blanks on this half-assed GDPR-compliant Whois we came up with

Bizarrely, given the history, ICANN itself appears to disagree with the EU's move to restore a partial status quo. In a feedback note [14]published on the EU Commission website during March 2021, ICANN's At-Large Advisory Committee said the draft NIS Directive's plans for TLD registries were unworkable.

"Some or all of the registration data may never be stored by (or even presented to) the registrar. It will be held by a privacy or proxy provider. A proxy provider will not pass on either the name of the real registrant or their contact information. A privacy provider protects only the contact data," wrote the org's Alan Greenberg.

Did you read it? Well, did you?

It appears that the current article 23 isn't causing much harm to those who actually did read it. The Internet Infrastructure Coalition, whose members include 123-Reg, GoDaddy and cPanel, as well as Amazon and Google, [15]said it was most worried about who would be making "justified requests" for Whois data rather than the concept of collecting the data.

Once rubberstamped into EU law, the directive isn't a directly effective legal text either; EU member states need to transpose it into their own laws to give it its legally enforceable effects.

So much for excitable people shouting about a new Whois leading to "death lists". As currently worded, all it means is a return to the pre-2018 Whois without publication of names and contact details – and that won't lead to some kind of WWW concentration camp. ®

Get our [16]Tech Resources



[1] https://www.patrick-breyer.de/en/cybersecurity-eu-to-ban-anonymous-websites/

[2] https://www.europarl.europa.eu/RegData/docs_autres_institutions/commission_europeenne/com/2020/0823/COM_COM(2020)0823_EN.pdf#page=11

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YWmlvEjoBJr5kK5vAX7F3AAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWmlvEjoBJr5kK5vAX7F3AAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWmlvEjoBJr5kK5vAX7F3AAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2019/10/23/icann_kills_whois/

[7] https://www.theregister.com/2016/10/21/comodoh_researchers_exploit_image_recognition_bug_to_steal_certs

[8] https://www.theregister.com/2018/06/15/icann_whois_gdpr/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWmlvEjoBJr5kK5vAX7F3AAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2021/07/22/vid_me_video_hijacking/

[11] https://www.theregister.com/2021/06/22/apnic_whois_data_exposed/

[12] https://www.theregister.com/2020/12/11/katherine_ryan_domain/

[13] https://www.theregister.com/2020/10/08/icann_whois_plans/

[14] https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/12475-Cybersecurity-review-of-EU-rules-on-the-security-of-network-and-information-systems/F2004732_en

[15] https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/12475-Cybersecurity-review-of-EU-rules-on-the-security-of-network-and-information-systems/F2004725_en

[16] https://whitepapers.theregister.com/



Checking at least some details?

Joe W

OK, I am not holding my breath, but wouldn't it be nice to be able to pinpoint nefarious activity on domains (registered to phish or scam, complete with copies of real homepages to deceive the mark) to persons? Having some way to get that information definitely would be helpful in some cases. Considering it should have been done that way before 2018 (gosh, that long ago?), but did not work as intended I feel disinclined to have that info accessible.

And let's not start looking at what "legimate interest" might mean... (other than a red flag for any reader)

Re: Checking at least some details?

Graham Cobb

Crims will have (throwaway) front organisations (many in corrupt countries) to do registration. Political campaigners in Belarus and other authoritarian countries will be arrested.

The rest of us will just be harassed.

WHOIS not alone

Mike 137

If the WHOIS database contravened the GDPR, does not the UK companies registry still do so? It lists all directors by name and role, which is fundamentally personal data. The difference is that the companies registry doesn't try to rely on consent as its lawful basis for processing. If ICANN had chosen an alternative lawful basis for transactions involving EEA registrants (e.g. contractual necessity or legitimate interest) the whole debacle could have been avoided.

A simple opt out mechanism for special cases would have then been sufficient.

Re: WHOIS not alone

Anonymous Coward

"UK companies registry"

I'm not very happy that they show my details to all and sundry who query my company including my full name and my wife's name, our dates of birth, address and even scans of our signatures. It's a free gift to identity thieves and scammers.

Re: WHOIS not alone

Graham Cobb

Companies are for commercial activities. They are not necessary to start, or even run, a political campaign.

"does not the UK companies registry still do so?"

LDS

You'll need to change the laws that require a company administrator to be easily identified for legal reasons.

"He appears not to have read draft article 23"

LDS

He wasn't able to find it using BitTorrent from a pirate site so he actually didn't read it probably. Again he's just worried his favourite source of pirated material will be identified and closed.

It's time to crackdown sites registered with fake data just to be used for illegal activities - ICANN doesn't like it because they know registrars will make far less money if crooks can't register websites by the sackful using stolen credit cards. They will probably move to use some dummies, but it will be more complex anyway.

I'm perfectly fine with domain registration being vetted and corresponding to real people - I had to do it anyway twenty years ago because here that was the rule, and that's why I asked to hide them as soon as GDPR made it possible - there were my name, address and telephone number. Acceptable back then, not acceptable any longer.

Of course as long as PII aren't published to dogs & pigs, and available only under very specific rules.

Re: "He appears not to have read draft article 23"

Graham Cobb

If crooks are using a sack of stolen credit cards they already have enough info to put in a false name and address. Either they already know the name and postcode (most online credit card transactions) or the provided name and postcode are not being validated. A (stolen) credit card which validates will be enough to convince any registrar that the provided name and address are valid.

Re: "He appears not to have read draft article 23"

LDS

Depends. If additional proof of identity are required that may not be enough. Here a credit card is not enough to prove your identity.

Re: "He appears not to have read draft article 23"

Graham Cobb

It will be enough to prove your identity to a domain registrar. They aren't the police or a bank. I really don't think anyone is proposing anti-money-laundering levels of proof to be required.

Re: "He appears not to have read draft article 23"

LDS

That depends on the rules and laws. There are many other services or goods you can't buy simply exhibiting a credit card - and even if they are not a bank or the police they can ask you a proof of identity.

rg287

Are there not two issues going on here?

Prior to 2018, public WHOIS reflected exactly the information that registrars gave them. This was not compliant with GDPR.

But because people were already sick of this, proxy registrars popped up and only submitted their own details as a Privacy service.

Article 23 does not merely provide a GDPR-compatible framework. It effectively bans proxy registrars and require the registrants details to be passed through to the registry - they just can't be published publicly.

This is indeed a significant change. Rather than simply regulating how registries store and publish data, they're now telling them how to conduct their business and stipulating data they must collect. It's a significant step up in regulating the domain industry and one which the article somewhat glosses over in it's scathing dismissal of the (admittedly rather clickbaity) cries from privacy advocates.

This statement:

As currently worded, all it means is a return to the pre-2018 Whois without publication of names and contact details – and that won't lead to some kind of WWW concentration camp.

Is not accurate. We're not going back to pre-2018. This is a new regime in which proxy registrars and "privacy services" are banned.

Now as JoeW says, this is not necessarily a bad thing and it would be nice to be able to pinpoint certain bad actors.

But realistically it means bad actors will just use TLDs outside the EU (such as such minor extensions like .com, .org or almost all gTLDs).

Zippy´s Sausage Factory

I'm in agreement with this, but as usual I'm thinking about where the process leads.

If the registrar has to collect and verify personal data, this concerns me. What then happens to that data? Who has access to it?

It seems to me that having that database there provides a handy means of being able to censor private citizens own domains, should they wish to. Said something bad about the government? Following a "justified request" to your domain name provider, here comes the local police, knocking on your door, as a "friendly" reminder to be politer in future...

And you know that if the EU starts doing it, it'll be cited as a precedent by other governments whose reminders won't be quite as "friendly".

And that's what worries me.

LDS

You mean just like registering a telephone number or asking for an internet connection and using to say/write something bad?

Domain registrations ends up to the official registrar for each TLD. That's where data are stored and should be protected. They collect user data just like telcos do...

Disgusted Of Tunbridge Wells

EU: The GDPR

EU: Now put all your information in plain text in a directory for anybody to look up

If you can't get your work done in the first 24 hours, work nights.