Yesterday we invited comment from a number of interested parties regarding a suggestion from F-Secure’s Mikko Hypponen that registrars should simply refuse to issue domain names that are obviously intended for phishing. In an open letter to registrars on his blog, Hypponen cited as an example directNIC’s selling a “Craig Smith” the domain name “signin-ebay-c.com,” which was then used as a phishing site.
We’ll hear later from directNIC CEO Sigmund Solares, with whom I had a discussion about the issue late yesterday. (Update: Here’s the Solares post.)
First up this morning, though, will be Dave Jevans, chairman of the Anti-Phishing Working Group:
Mr. Hypponen does bring up a good and valid point: Some registrars do not perform very much verification of domain registrations, and many do allow the trademarks of other companies to be registered.
The issue is a complex one.
Unfortunately, it is not possible for a registrar to know a-priori whether a site is going to be used for phishing or not. There are many “squatters” who may have every right to register domain names with other companies’ trademarks in them, per ICANN policy. They may have to relinquish those domains should a trademark infringement be shown by the brand holder, per ICANN policy.
However, if someone creates a site such as realbank-sucks.com, and uses it as a parody site or to complain about realbank’s services, that is fully within their legal rights to do so (at least in the U.S). Therefore, how can a domain name registrar, who may register tens of thousands of domains per day, make such a determination?
Vetting every site to a higher level will cost money. The price of domain names will rise. There are those in the free-speech community who are of the opinion that this is a bad thing, as it will prevent individuals and small businesses from registering domain names.
The concept of high assurance certificates has been proposed, and is being adopted in the new Web browsers, to help distinguish sites that have gone through a more extensive validation of the credentials of the registrant.
ICANN has recently been proposing expanded capabilities for anonymous or private registration of domain names. APWG is part of a group of companies investigating this proposal. In general, we believe that law enforcement and certain aggrieved parties (i.e. brands being phished) should be able to access the data of registrants.
As you can see, it’s a complex issue. Mikko Hypponen’s example is a great one of how a domain registrar allowed a phishing site to be registered. This should be prevented. However, there are myriad issues on all sides that make this is thorny problem and not easy to solve. Please also note that there are now hundreds of registrars in all parts of the world, and not all of them have the same vetting abilities or policies.
Dave Jevans
Chairman, APWG




