[00:00.000 --> 00:01.440] Top-level domain program. [00:03.020 --> 00:04.100] Thank you very much. [00:04.280 --> 00:04.980] It's good to be here. [00:06.880 --> 00:25.280] Just as an aside, if anybody's looking to do anything really interesting, there is a basically Grand Canyon-sized pothole on 34th and 10th that I decided to ride my bike into, which is part of the reason why I'll be limping around, shifting a lot up here. [00:25.600 --> 00:29.520] It was not a fun, pleasant, not a fun way to spend my Friday evening. [00:30.640 --> 00:33.000] So, in any event, my name is Alex Urbelis. [00:33.100 --> 00:35.220] We're going to talk about ICANN's new GTLD program. [00:36.440 --> 00:40.020] I am a technology lawyer with Steptoe and Johnson. [00:41.080 --> 00:48.720] I've been involved with 2600 since I was probably about 15 years old, so going on 19 years now. [00:49.240 --> 01:08.540] I used to contribute pretty regularly with Emanuel on Off the Hook, and I've worked with a team of lawyers in my office who were basically responsible for a little bit over 10 percent of all of the new GTLD applications submitted to ICANN this year, and generally handle a lot of matters of Internet governance policy. [01:09.400 --> 01:13.820] Prior to private practice, my background was, you know, a little bit all over the place. [01:13.920 --> 01:27.260] I worked a bit in the Department of Defense, was a graduate fellow in the Office of General Counsel at CIA, did some federally funded cybersecurity and counterterrorism research, and prior to that, did IT at a software company. [01:28.540 --> 01:36.180] Participate in things like the International Association of Privacy Professionals, Privacy Research Group at NYU, the Internet Society, and, of course, 2600. [01:37.360 --> 01:38.980] So, yeah, why not, right? [01:39.480 --> 01:41.080] So, quick overview of the presentation. [01:41.700 --> 02:01.780] I think we're going to step through what's going on with the new GTLD program, the status of it, some of the security issues that arose in April of 2012, and then talk about the expansion of the root zone, and how this expansion of the Internet, how new GTLDs may affect our current form of Internet governance, [02:01.940 --> 02:10.560] as well as some of the tension that's playing out right now between nations and private industry with respect to who controls the Internet. [02:11.540 --> 02:19.580] So, I know this one can hopefully just breeze right through this, because I'm sure many of you are very familiar with what ICANN is. [02:19.720 --> 02:22.020] But for those of you who aren't, let's just breeze through this. [02:22.280 --> 02:26.320] So, it stands for the Internet Corporation for Assigned Names and Numbers was formed in 1998. [02:26.800 --> 02:32.700] And basically, their mission is to keep the Internet stable and secure, and as well as to promote competition. [02:32.880 --> 02:35.840] And I think that function will come up a little bit later, as well. [02:36.540 --> 02:44.520] So, basically, what they do is they set global administrative policies, and they're responsible for universal resolvability of all domain names. [02:44.700 --> 02:56.420] And they do this by maintaining contracts with their Internet registries, run accreditation systems for registrars, and have a compliance department that seems willfully inadequate for what's ahead. [02:58.460 --> 03:09.020] Then, basically, just to get our term straight, a registry is basically the database of domains that belong to a particular top-level domain. [03:09.160 --> 03:13.900] The registrar is that which sells the domains, and the registrant is that person who's buying the domain. [03:14.560 --> 03:16.720] I think we can almost breeze through this. [03:16.920 --> 03:23.240] So, to give you a quick look at what we're really talking about here, the first are top-level is the spot to the right of the dot. [03:23.520 --> 03:25.880] Here, with this address, the dot org. [03:26.040 --> 03:31.940] The second level domain would be the ICANN, and the third level is the meetings aspect of it. [03:32.000 --> 03:39.720] Now, what's historic about ICANN's new GTLD program is that this is the first time ever that the space to the right of the dot can be customizable. [03:42.840 --> 03:46.100] individual entities, persons weren't allowed to apply. [03:46.200 --> 03:49.340] You had to apply through some kind of business organization or entity. [03:50.080 --> 03:52.220] So, you could own to the right of the dot now. [03:52.360 --> 04:00.700] You could have your brand, you could have your company name, you could have a generic name, and then you could basically regulate to the left of the dot your second-level domains. [04:01.580 --> 04:05.380] But the second-level domain space is still very, very highly regulated by ICANN. [04:05.500 --> 04:09.640] What's kind of the Wild West right now is the third level, the meetings dot space. [04:09.640 --> 04:23.760] And I think that we're going to see ICANN trying to reign that under control over the next couple of years, as well, because that may prove to be a very fertile source for cyber squatting and counterfeiting, as it has been already. [04:25.100 --> 04:29.060] So, these two, you know, we already really stepped through what these GTLDs are. [04:29.220 --> 04:37.560] There's currently 22 in operation, without counting the country code top-level domains, like .jp for Japan or .de for Germany. [04:38.240 --> 04:45.820] And this application process is already underway for people to purchase their own top-level domains to the right. [04:46.160 --> 04:57.800] And one of the other interesting aspects of this is, so you'll start to see, once these are delegated and entered into the root, you're going to start seeing IDNs, or internationalized domain names, so .whatever can be in Arabic, it can be in Cyrillic, [04:57.860 --> 04:58.540] it can be in Russian. [04:59.040 --> 05:07.040] This is already possible at the second level, and some top-level domains, but you're going to start to see a lot in the third level. [05:08.680 --> 05:18.340] So, just to give you a quick recap on this, applying for and buying a top-level domain is not like going to GoDaddy and trying to register a second-level domain. [05:18.740 --> 05:22.500] Every single application cost $185,000 to submit. [05:22.940 --> 05:24.960] All that money went to ICANN. [05:26.160 --> 05:29.000] The period was only open for about three months. [05:29.240 --> 05:30.420] It was years in the making. [05:30.640 --> 05:32.920] The application window opened on January 12th. [05:33.540 --> 05:36.920] You had to submit answers through this TAS system. [05:37.320 --> 05:41.580] It was called the New GTLD Application System, which ran through Citrix. [05:42.380 --> 05:46.520] It was kind of a silly system, and we'll get to a security glitch with that in a second. [05:46.780 --> 05:50.000] But basically, you had to submit answers to 50 questions. [05:50.900 --> 06:04.680] And these dealt with your technical capability to run a registry, your financial wherewithal to run the registry, information about the applicant entity, and generally, information about what kind of rights protection mechanisms you're going to have in place, [06:05.200 --> 06:14.700] how you're going to participate in things like the trademark clearinghouse, how you're going to ensure register on privacy and mitigate abuse within the top-level domain. [06:14.700 --> 06:18.880] So, this was supposed to be open for a period of three months. [06:19.040 --> 06:20.680] It was supposed to close April 13th. [06:21.040 --> 06:25.480] But then there was a glitch with the application system on April 12th. [06:26.440 --> 06:28.180] It was pretty bad, actually. [06:28.560 --> 06:33.980] People had a lot of difficulty getting into the system, and it pretty much shut down until May 30th. [06:34.180 --> 06:41.580] But at the end of May 30th, it turns out that 1,930 applications for top-level domains were submitted. [06:42.140 --> 06:44.820] This is a lot more than what ICANN had anticipated. [06:45.200 --> 06:54.140] And because of that, they planned to use this batching system to review the applications and then have them delegated into the route before they go live. [06:54.540 --> 06:57.280] So, of course, everybody wanted to have their applications go first. [06:57.520 --> 07:03.040] They came up with this digital archery system, which was akin to essentially a carnival game. [07:03.040 --> 07:12.620] Well, I'm not sure if anybody had followed this, but it was really a very bizarre proposal where, let's say I have an application in, and I want to be in the first batch. [07:13.040 --> 07:14.920] So, I select a time. [07:15.260 --> 07:22.860] I'm going to select 12.01 and one second on July 16th to basically hit a button. [07:23.140 --> 07:24.980] And you would log into the system. [07:25.120 --> 07:32.880] And the closer you were to actually hitting the button at that exact time, that actually determined what batch of applications you were going to be in. [07:32.880 --> 07:39.940] So, when I say carnival game, it really was like a carnival game with $185,000 initial investment into it. [07:40.080 --> 07:40.600] I mean, it's... [07:40.600 --> 07:41.920] It was a little silly. [07:42.160 --> 07:42.680] It was a little silly. [07:43.780 --> 07:47.780] ICANN just recently, over the last couple of weeks, concluded its meeting in Prague. [07:48.380 --> 07:51.220] And during that meeting, they dispensed with digital archery entirely. [07:51.520 --> 07:53.640] And nobody has any idea what they're going to replace it with. [07:53.840 --> 07:58.480] So, batching is still a big consideration in how they're going to handle this number of applications. [07:58.480 --> 08:00.800] So, the program is subject to change. [08:00.940 --> 08:03.800] It's a bit in flux right now, as I say here. [08:04.620 --> 08:12.320] So, initial evaluation of these applications was actually set to occur three days ago, and I think it did occur on time. [08:12.760 --> 08:19.280] And on June 13th, that was a very important day because that was when all the non-confidential portions of the applications were revealed. [08:19.280 --> 08:24.200] That's when you could see the 1,930 applications of applied-for strings. [08:24.460 --> 08:28.720] It also kicked off this public comment period and the GAC early warning. [08:29.020 --> 08:32.460] The GAC is the Governmental Advisory Committee. [08:32.520 --> 08:34.480] We're going to get into them in just a little bit. [08:34.660 --> 08:43.100] So, the public comment period is running right now, and it closes on, I think it's midnight UTC, August 12th. [08:43.100 --> 08:49.540] So, basically, any one of us can submit any comments on any new GTLD applications right now. [08:50.080 --> 08:51.520] There's no standing requirements. [08:52.220 --> 09:02.800] And we're starting to see, you know, the usual, there's, you know, a little bit of lunacy in some of the public comments that are being submitted, but I think what you're going to see is there's going to be a lot of infight between applicants, and I think public comments, [09:02.840 --> 09:12.920] which can spur somebody called the independent objector, who can raise a formal objection later, those could be instrumental in deterring your competitors' applications from going forward. [09:13.140 --> 09:21.880] So, I think we're going to see a lot of big corporations and a lot of people interested in deterring other strings from being delegated to use these public comment processes. [09:22.180 --> 09:27.660] But there's really no incentive to do it until literally the last day, because why give your opponent the opportunity to respond? [09:28.280 --> 09:34.180] So, I think come August 10th and 11th, we're going to start to see the public comment period really kick up. [09:35.660 --> 09:46.000] To give you a little bit of a breakdown, like we said, 1,930 applications, 1,409 applied for strings through 1,155 entities. [09:46.460 --> 09:52.960] And to break this down further, about 53% of these were dot generic terms, like dot music, dot art, dot app. [09:53.200 --> 09:55.660] Dot app is actually the most highly contested. [09:55.800 --> 09:58.620] And then 34% of these are dot brands. [09:59.580 --> 10:02.040] Yahoo, Google, dot McDonald's. [10:03.220 --> 10:07.020] And those, you're not going to be able to register in the second level. [10:07.160 --> 10:09.520] Those are going to be what's known as a closed registry. [10:09.860 --> 10:14.880] But for the dot generics, their business model is essentially going to be selling top-level domains. [10:15.220 --> 10:23.580] Then you have community applications, which, let's say you have, like there is for dot insurance, several different applicants applying for dot insurance right now. [10:24.780 --> 10:29.720] If you represent the insurance community, you can knock out the other applicants. [10:30.020 --> 10:35.740] So their investment can be just basically flushed down the toilet if you can meet these community priority criteria. [10:36.860 --> 10:41.280] And dot insurance is one application that's undergoing that right now. [10:41.520 --> 10:43.620] And then 3% were geographic names. [10:44.080 --> 10:47.100] Things like dot NYC, dot Dubai, dot London. [10:47.800 --> 10:56.180] You didn't really see too much participation from developing nations, despite the fact that ICANN was really pushing this and offered some financial assistance. [10:56.660 --> 11:01.560] You saw almost nothing coming from Africa, with the exception of South Africa. [11:02.140 --> 11:05.680] Most of the applications came from North America and Europe. [11:06.940 --> 11:16.760] And if you multiply 19, 30 times 185,000, you figure out that ICANN now has $357 million sitting in its bank accounts. [11:17.940 --> 11:23.740] And really only a little more than half of that is accounted for in terms of expenses. [11:23.960 --> 11:29.060] So there's supposed to be an excess of $160 million coming from this program. [11:29.600 --> 11:34.280] It's a lot of money for a not-for-profit corporation to take in in just a few days. [11:37.620 --> 11:43.360] We also see, though, that there weren't any applications for things like .hack, .freak. [11:44.020 --> 11:45.660] We didn't see .2600. [11:46.540 --> 11:52.740] Some of the more interesting strings, I think, were like .wtf and .sucks, which actually had three applications. [11:54.400 --> 11:56.060] So they're going to go into string contention. [11:56.160 --> 11:57.780] And I think that could be very interesting. [11:58.860 --> 12:06.160] But what troubled me, and I think maybe we can change this over the next couple of years, I mean, it's a gigantic investment, and nobody knew how this was going to pan out. [12:06.240 --> 12:21.180] But I think we should maybe get together some hackerspaces, get together some resources, and maybe we should put in an application for .hack or .freak, because that would ensure that, as I talk about later on, our voices continue to be heard in ICANN's major stakeholder groups, [12:21.560 --> 12:27.340] one of which the largest and arguably most powerful will probably come to be the registry stakeholders group. [12:27.340 --> 12:31.140] And if anybody can run an Internet registry, I think it would be people like us. [12:31.520 --> 12:33.440] So let's think about that in the future. [12:35.980 --> 12:36.840] Sure, I can stop. [12:36.940 --> 12:37.220] Absolutely. [12:37.820 --> 12:41.160] Wait, please stand up the microphone if you were to ask questions, because we have it on record. [12:42.520 --> 12:47.460] So what do they spend the $200 million on that, like, goes into expenses for? [12:47.700 --> 12:51.160] Well, the actual review process takes a long time. [12:51.160 --> 12:59.580] Reviewing these applications, these applications is anywhere from, you know, 60 or 70 pages to, you know, 250 pages of very tense. [12:59.760 --> 13:04.560] And, you know, about 100 of those is generally technical data that relates to back-end registry services. [13:04.800 --> 13:16.980] So valuing the applications, researching the applicants, dealing with the dispute resolution service providers, handling string contention, all of that's going to be, all of that is really accounted for. [13:17.120 --> 13:20.440] Plus, you know, I think ICANN did budget a bit for legal fees. [13:20.440 --> 13:24.800] There's no question that they're going to be facing, I think, some suits. [13:25.960 --> 13:34.740] But I think a lot of the budget, and this has come out in the ICANN PROG meeting, it seems like they over-budgeted for quite a bit of this. [13:34.880 --> 13:38.760] So I think $160 million in excess is probably a conservative figure. [13:38.940 --> 13:40.320] There may be a lot more in excess. [13:41.380 --> 13:45.680] So to go into the GAC here, the GAC is the Governmental Advisory Committee. [13:45.780 --> 13:48.500] They're a big constituent of ICANN. [13:48.580 --> 13:49.440] They're very, very powerful. [13:49.440 --> 13:51.360] So they have this early warning period. [13:51.480 --> 13:57.780] Now, if the GAC has any problem with your application, they can submit something called an early warning. [13:58.640 --> 14:01.500] And that's a major impediment for your application going forward. [14:01.660 --> 14:09.220] And any member, any GAC representative, of which there are, I believe, 116 right now, can submit an early warning. [14:09.220 --> 14:18.280] Most of these are going to relate to highly regulated industries like insurance or banking, financial services, that kind of thing. [14:19.220 --> 14:23.460] That's where I think we'll see a lot of the GAC interactions coming in. [14:26.100 --> 14:30.640] Now, we're going to also see applicants using the GAC offensively. [14:30.640 --> 14:40.780] You know, using the relationships with the GAC basically to bring up information or concerns about other applications that they wouldn't otherwise have reviewed themselves. [14:41.140 --> 14:49.200] So getting the GAC on your side is going to be basically a feather in your hat when it comes to getting your application moving forward. [14:50.360 --> 14:55.100] So the advice can take three forms, consensus, non-consensus, and remediation. [14:55.560 --> 14:58.120] Consensus advice, that's the worst kind that you could have. [14:58.120 --> 15:00.520] Your application probably is not going to be approved. [15:01.140 --> 15:11.020] Non-consensus advice is, you know, it's basically, it's going to be problematic for you because you can't change your application. [15:11.540 --> 15:17.020] And remediation advice could be very difficult, too, for the same reason, that you can't modify your application afterwards. [15:17.480 --> 15:27.700] But consensus advice is almost a little bit misleading because GAC consensus is reached by somebody making a proposal for something and nobody else piping up about it. [15:27.700 --> 15:32.740] So it's basically consensus by a failure for anybody to object. [15:33.380 --> 15:37.240] So consensus advice is reached much more easily than the name implies. [15:38.060 --> 15:41.980] And then you also have... this is where lawyers get involved. [15:42.120 --> 15:43.820] You have things like formal objections. [15:44.040 --> 15:44.880] You have legal rights objections. [15:45.120 --> 15:51.340] So let's say I have a right to a trademark and somebody applies for my trademark. [15:51.880 --> 15:55.800] I can voice a legal rights objection even though I'm not a new GTLD applicant. [15:56.160 --> 16:03.220] And if that other person doesn't have any legal rights to that particular string, then their application is going to be knocked out. [16:03.440 --> 16:11.240] But the interesting thing, though, is if the GTLD applicant does have legal rights to the string, then I can't let that go forward. [16:11.240 --> 16:18.000] And it doesn't matter really how tenuous the legal rights are so long as you have some form of right to it. [16:18.720 --> 16:22.000] And this is generally because property law really encourages use. [16:22.100 --> 16:23.920] And I think ICANN is really building on that. [16:24.520 --> 16:25.640] And then string confusion. [16:25.640 --> 16:37.860] If you think that there is some threat that another application has because the strings are so nearly identical or very similar to each other, you can go into string confusion with them. [16:38.100 --> 16:42.620] And ultimately, that could result in an auction and even more money for ICANN. [16:43.040 --> 16:44.440] And then the limited public interest objection. [16:44.440 --> 16:53.980] This isn't really going to be used, I think, at all, which is if a TLD is contrary to general principles of international law for morality and public order. [16:53.980 --> 16:55.780] So that's a tall burden. [16:56.000 --> 16:57.240] And then the community objection. [16:57.400 --> 17:03.180] We may see some communities piping up through the community objection, though, for certain applications. [17:03.780 --> 17:05.280] But that remains to be seen. [17:05.980 --> 17:08.800] And then, as we just mentioned, the string contention process. [17:09.120 --> 17:21.500] If there are more than one applicant, let's say, for .art or .app, and they all pass through initial evaluation and they're all qualified to run a registry, what happens, essentially, is ICANN will let that go to an auction. [17:21.500 --> 17:23.700] And the TLD goes to the highest bidder. [17:23.860 --> 17:25.420] And all the money goes to ICANN. [17:26.660 --> 17:27.500] Not surprisingly. [17:27.640 --> 17:28.760] That's a running theme, isn't it? [17:30.340 --> 17:33.180] It's that will also delay your application. [17:33.420 --> 17:39.020] If you get stuck in a string contention set, of which there are many, you're looking at two and a half to six months. [17:39.080 --> 17:42.760] I think more likely six months before your application could be delegated. [17:42.760 --> 17:45.980] So, here we are, another breakdown again. [17:48.140 --> 17:49.900] 116 internationalized domain names. [17:50.460 --> 17:53.400] And the batching proposal is really still up in the air. [17:53.500 --> 17:56.020] Nobody knows how ICANN is going to handle this many applicants. [17:59.000 --> 18:01.620] There is a potential to get some money back. [18:01.900 --> 18:07.720] If you withdraw your application after the GAC issues an early warning, you can get 80% back. [18:08.060 --> 18:09.120] So, not too bad. [18:10.700 --> 18:15.000] And then, basically, the farther down you go in the process, the less money you're going to get back. [18:15.200 --> 18:27.200] But $185,000 for the application itself seems like a lot of money, but I think the real cost comes in in putting together these applications and the contracts that you have to sign. [18:27.200 --> 18:31.540] So, there's a lot of outside costs that go into this. [18:32.320 --> 18:34.560] Lawyer's fees are one of them, of course. [18:35.740 --> 18:38.580] And then, the security glitch that happened in April. [18:38.800 --> 18:44.360] This was really bizarre because on April 12th, the system was really grinding to a halt. [18:44.680 --> 18:48.140] Nobody could really get in and make any material change their applications. [18:48.440 --> 18:51.540] Then, at around 10 PM, the whole thing just went down. [18:52.020 --> 18:59.280] Everybody went home and woke up the next morning and found out that the system was going to be taken off for about eight days. [18:59.820 --> 19:06.320] You know, and this was really disheartening for me because I had been working, you know, about 16 hours a day for, you know, three weeks on this. [19:06.640 --> 19:17.660] And it was like watching, you know, the finish line of a marathon just be picked up and moved eight miles away from you, you know, by some supernatural, you know, non-governmental organization hand. [19:17.720 --> 19:18.420] It was really disheartening. [19:19.220 --> 19:21.200] We just wanted this application period to be over. [19:21.200 --> 19:30.620] So this eight-day period actually biblically turned into 40 days and 40 nights of downtime, during which nobody really knew what happened. [19:31.000 --> 19:34.400] And ICANN was investigating what happened with the security glitch. [19:34.520 --> 19:37.980] And what it really was was it wasn't really a big deal. [19:37.980 --> 19:51.840] But if a deletion process was interrupted through the Citrix TAS connection, certain applicants were able to see the file names associated with other applications. [19:52.280 --> 19:59.780] And they could have been revealing of what string another applicant was applying for, you know, like for Ford or something, for instance. [19:59.960 --> 20:05.300] You know, it could have been Ford GTLD application attachment 31-33 or something. [20:05.300 --> 20:11.360] So there were some concerns about the confidentiality of applications being breached there. [20:12.140 --> 20:15.240] But ICANN did confirm this, you know, this wasn't the result of an attack. [20:15.440 --> 20:16.320] There was no data loss. [20:16.420 --> 20:17.120] There was no corruption. [20:17.380 --> 20:21.260] They contacted all of the applicants whose file names were compromised. [20:21.660 --> 20:24.260] They poured over the log files, I think very thoroughly. [20:25.240 --> 20:29.260] But more importantly, this kind of made ICANN look really silly. [20:30.240 --> 20:37.240] The corporation that is in charge of the security and stability of the Internet couldn't even maintain its own application system. [20:37.600 --> 20:40.960] So there was a lot of doubting, I think, that came along with that. [20:41.120 --> 20:43.120] But things have gotten back on track. [20:44.560 --> 20:54.480] And now some of the issues that we're facing here are, you know, is this expansion going to be at all problematic to the root zone of the Internet? [20:55.540 --> 20:58.600] You know, are there more security issues coming down the pipe here? [20:58.960 --> 21:05.260] So ICANN has said basically that, you know, we're not going to add more than 1,000 new GTLDs to the root. [21:05.400 --> 21:10.520] We're not going to allow 1,000 GTLDs to go live in the year. [21:10.960 --> 21:14.200] But this will undoubtedly change the landscape of the Internet. [21:14.360 --> 21:17.160] It's going to change the way the Internet looks irrevocably. [21:18.300 --> 21:26.820] And for years now, they've been debating whether or not this expansion of the root zone could actually cause some kind of security and stability concern. [21:27.100 --> 21:28.800] So let's back up a quick second. [21:28.880 --> 21:34.000] I'm sure a lot of you know what the DNS root is, but maybe some of us don't, and we'll step through it pretty quickly. [21:34.100 --> 21:36.800] So it's basically, it's the top-level DNS zone in a namespace. [21:37.940 --> 21:45.120] The DNS root zone is really the key component of the system that every application that uses the Internet uses. [21:45.320 --> 21:49.600] And essentially what it is, is a big list of authoritative servers that make the Internet run. [21:50.700 --> 21:52.300] And everybody uses it. [21:52.840 --> 21:56.380] So, who runs this gigantic list? [21:56.480 --> 21:57.300] Who manages this? [21:57.480 --> 21:59.300] There's really four major players. [22:00.560 --> 22:02.200] You have the NTIA. [22:02.360 --> 22:08.280] And you'll see there's a lot of U.S. government involvement in that, that will become relevant later in terms of Internet governance. [22:08.500 --> 22:12.200] So you have the NTIA, the National Telecommunications and Information Administration. [22:13.280 --> 22:16.740] They operate as an agency under the Department of Commerce. [22:16.940 --> 22:19.820] And they really have the ultimate authority over the root and always have. [22:20.740 --> 22:32.300] IANA, the Internet Assigned Numbers Authority, manages the zone file and interacts with the NTIA on basically changes that are proposed to be made to the root. [22:32.880 --> 22:36.340] And IANA has historically always been associated with ICANN as well. [22:36.340 --> 22:40.760] And just a few weeks ago, there was a... [22:41.220 --> 22:46.760] Well, the Department of Commerce re-handed over the contract for the IANA function to ICANN. [22:46.940 --> 22:50.760] And then VeriSign, which operates as a root zone maintainer. [22:51.360 --> 22:55.800] And then dispersed throughout the world, you have 12 different root server operators. [22:56.520 --> 22:59.200] And, you know, notably, again, you see a lot of U.S. involvement here. [22:59.300 --> 23:07.740] You see VeriSign, NASA, the U.S. Army, Department of Defense, and I believe... Well, ICANN, of course, and the University of Maryland. [23:08.380 --> 23:09.720] Was there a question in the back? [23:11.140 --> 23:11.920] Oh, no? [23:12.080 --> 23:12.240] Okay. [23:12.600 --> 23:12.940] Certainly. [23:14.460 --> 23:18.840] This is the dispersion of root servers from rootservers.org. [23:19.000 --> 23:26.020] And you'll see, you know, they're really clustered mainly around Europe and North America, quite a few in South America. [23:28.280 --> 23:34.900] Siberia just doesn't really... You know, they just don't register on the map over there in terms of root servers, but, you know, maybe in a few years down the road. [23:36.060 --> 23:41.040] Also, Australia has... There's a lot of... The L root servers are run by ICANN down there. [23:41.640 --> 23:48.760] And Australia has actually become, through several different private organizations, I think quite a major player in the ICANN world. [23:49.500 --> 23:53.180] So, the benefits of diversity of having these root servers all over the world are essentially... [23:53.180 --> 23:57.320] Well, they're not going to be too easy to take down in a DDoS attack. [23:57.320 --> 24:01.120] And they run all different types of software and all different types of platforms. [24:01.340 --> 24:08.080] So, one security bug is not going to take down the root servers that were geographically dispersed. [24:09.760 --> 24:13.280] We've seen some prior expansions of the root zone, but nothing this dramatic. [24:14.060 --> 24:18.240] Every time a new top-level domain is added, the root zone changes a little bit. [24:18.240 --> 24:22.420] And test internationalized domain names were added in 2007. [24:22.420 --> 24:30.660] And in 2010, you saw IDNs for Egypt, Saudi Arabia, and the United Arab Emirates going live. [24:31.780 --> 24:39.540] Also, with IPv6 deployment, we're seeing more and more data being put into the root zone, and DNSSEC, which is used to sign the root zone file. [24:40.140 --> 24:42.760] And so far, you know, this is just added text. [24:42.880 --> 24:46.420] Nothing has caused a major impact on the root. [24:48.240 --> 24:52.300] Nonetheless, one of ICANN's committees, the root... well, a study team, I guess. [24:52.380 --> 24:57.660] The root scaling study team stated a few years ago, well, you know, it could absorb... [24:57.660 --> 25:05.900] The root should or could absorb a small number of annualized TLDs together with introducing DNSSEC into the root. [25:06.760 --> 25:19.980] And a lot of this stemmed around concerns from IDNs, but it's difficult to square this hesitation of adding things to the root with ICANN's full steam ahead mentality of adding 1,000 to them. [25:22.920 --> 25:24.960] So, back to the main issue, really. [25:25.180 --> 25:31.780] I mean, does altering the size of the root have an effect, an adverse effect on security and stability? [25:33.920 --> 25:38.540] It's the aggregate effect, really, that is what the dramatic change to the root will be. [25:38.720 --> 25:45.060] Adding all the IPv6, DNSSEC, IDNs, plus arguably 1,000 TLDs a year into the root. [25:47.240 --> 25:53.480] This could impact the root servers... well, this could impact the root servers really in two different ways. [25:54.240 --> 25:55.960] ICANN has identified two issues. [25:56.340 --> 25:59.840] Root server operations and an impact on provisioning. [25:59.840 --> 26:03.680] So, the root server operations are really your ability to respond to queries. [26:04.380 --> 26:09.640] And provisioning pertains to the ability to receive and distribute new root zone files. [26:10.420 --> 26:14.340] And ICANN says, no, there's really... you know, we haven't seen any problems with this whatsoever. [26:15.520 --> 26:22.300] They actually came out with a recent study, which is, I think, very definitive in June 2012, just last month. [26:22.820 --> 26:27.460] But the risk to root servers really is, are they going to lose their ability to respond to queries? [26:27.800 --> 26:33.880] And if the root servers can't respond to DNS queries, well, that's going to cause resolution to ultimately fail. [26:34.200 --> 26:41.220] And it would be a slow process because a lot of people have this information cached, but that cache really only lasts for about 48 hours. [26:41.220 --> 26:50.680] So ICANN's analysis was, well, you know, performance of the root servers has nothing to do with how many records are in top-level... [26:50.680 --> 26:52.500] I'm sorry, are in the root zone itself. [26:52.820 --> 26:59.800] It's predicated on the number of queries a root zone server has to respond to. [26:59.800 --> 27:04.760] And the total number of Internet users is what determines the number of queries. [27:05.120 --> 27:11.920] So an increase in number of TLDs does not necessarily equate to an increase in the number of Internet users. [27:12.300 --> 27:19.040] Furthermore, the rate of change into the root would be very slow because we're not going to just delegate everything right at once. [27:20.780 --> 27:22.500] We're going to do 1,000 a year. [27:22.500 --> 27:27.480] Plus, we have all this system diversity and operator coordination, and so everything should be fine. [27:27.480 --> 27:29.560] We can handle 1,000 new TLDs. [27:29.620 --> 27:30.820] That's what ICANN said. [27:30.960 --> 27:37.180] But, you know, I think that there are some major issues that have not yet been resolved because... [27:37.180 --> 27:38.040] All right. [27:38.160 --> 27:39.620] So first, let's talk about query rates. [27:39.800 --> 27:42.600] Well, what about Internet users? [27:42.700 --> 27:44.340] What about adding Internet exchange points? [27:44.500 --> 27:50.820] I mean, this has been a major project for the Internet Society and ICANN as well in terms of global connectivity. [27:51.240 --> 27:57.460] So if we add more connectivity to developing nations and if we add more local content, that's one of the major problems with this. [27:57.480 --> 28:01.940] developing nations is even if they have connectivity, they're not necessarily going to have local content. [28:02.120 --> 28:10.340] But, you know, these internationalized domain names could perhaps maybe fix that or give an incentive for people to develop local content for areas like Botswana. [28:10.500 --> 28:15.840] So we're going to possibly see TLDs having an effect on queries. [28:16.160 --> 28:22.180] And if Internet exchange points are added throughout the world, then we're definitely going to see an increase in connectivity. [28:22.180 --> 28:27.900] And whether or not the root servers can respond to that increase, I haven't seen data on that. [28:28.380 --> 28:36.680] Also, we talked about the carnival game with digital archery and the batching proposals for ICANN. [28:36.740 --> 28:42.340] But we don't really know, and ICANN hasn't come out and said yet, how many they're going to implement at a time. [28:42.580 --> 28:47.580] They would like it to be a kind of steady and slow process, but we just don't know. [28:47.580 --> 28:59.600] I mean, here you have the situation where ICANN's policy recommendations could really have a technical impact on the way in which this is implemented in root servers. [29:00.500 --> 29:10.600] And then, also, think about if you have... if you do add a whole bunch of new root servers at the same... I'm sorry, new TLDs into the root at the same time, none of that information is going to be cached. [29:10.600 --> 29:19.540] So, if you have 1,000 new TLDs just going live, then the root servers, the day in which they go live, are going to have to respond to a hell of a lot more queries than they're used to. [29:20.080 --> 29:21.660] And can we accommodate this? [29:21.820 --> 29:24.720] We haven't seen... at least I haven't seen anything on that. [29:24.720 --> 29:35.460] And the system diversity factor... well, that really only relates to combating something like a DDoS attack and security glitches that are, you know, inherent to software. [29:35.860 --> 29:39.740] But what if misinformation was propagated in a root zone file? [29:39.840 --> 29:42.380] Then that's going to affect the Internet generally. [29:43.400 --> 29:47.540] And so, the system diversity factor, I think, doesn't even come into play at that point. [29:49.100 --> 29:54.880] And then, the provisioning aspect of accepting, verifying, and implementing changes to the root. [29:55.680 --> 29:58.620] This also pertains to distributing the updated zone files. [30:00.160 --> 30:10.360] So, basically, the way in which this will work is you have the... you have ICANN through the IANA function getting some kind of change request. [30:10.800 --> 30:17.580] IANA would then go over to the NTIA, and the NTIA would say, yes, okay, you can make that change request. [30:17.880 --> 30:21.100] They then communicate with VeriSign as the root zone maintainer. [30:21.580 --> 30:30.160] They make the change to the actual root zone file, sign it with DNSSEC, and then send it out to all the RSOs, to all the root server operators. [30:30.160 --> 30:40.940] And then, they have to distribute that, disseminate it internally, to make sure all their servers are up to date, and have the most readily available root server information for DNS lookups. [30:42.120 --> 30:47.200] And so, the issue really is, is adding a thousand new TLDs going to change this process? [30:47.340 --> 30:48.900] It's going to cause some kind of breakdown. [30:49.760 --> 30:52.560] And ICANN came back and said, no, no, no, no. [30:52.640 --> 30:54.580] There's no threat to stability here. [30:55.460 --> 31:00.280] We can handle this because, you know, we have the ability to scale our operations. [31:03.140 --> 31:08.640] Bizarrely, they also said that the evaluation of new TLD applications was really the largest task. [31:08.840 --> 31:10.000] And that's already underway. [31:10.320 --> 31:15.140] But that has absolutely nothing to do with root server operations, in my opinion. [31:15.460 --> 31:24.800] I mean, unless maybe what they were considering was, well, we want to prevent inadequate registries from having access to the root whatsoever. [31:25.760 --> 31:30.420] But the new TLD application evaluations really just doesn't seem relevant to me. [31:30.620 --> 31:34.460] And then, the propagation of zone files occurs, right now, twice a day. [31:35.380 --> 31:37.960] And ICANN believes that that number is not going to change. [31:38.320 --> 31:43.440] And so, really, in terms of distribution, they said, no, this really shouldn't be too much of a problem. [31:43.960 --> 31:53.240] So, also, that dissemination from the root zone maintainer, VeriSign, to the operators, all throughout the world, is a pretty well-established process. [31:54.800 --> 31:57.420] But there's other issues that haven't been addressed. [31:57.900 --> 32:12.460] For instance, the IANA staff, when they get the first request to delegate a new TLD, they're going to be required to submit a report to the NTIA before any new TLD gets delegated. [32:12.560 --> 32:15.500] Now, how are they going to handle a thousand reports? [32:15.720 --> 32:17.960] I mean, what even goes into these reports? [32:18.220 --> 32:19.620] Do they have the staffing to do this? [32:19.620 --> 32:20.880] Is this going to cause a backlog? [32:23.160 --> 32:35.160] And more importantly, I think, in terms of governance issues, are they going to be making any policy decisions about what can and what can't go into a TLD, into the root zone? [32:35.240 --> 32:43.720] For instance, I mean, .wtf, if mission and purpose, if people at IANA don't necessarily agree with that, or .sucks, they don't think that the Internet would benefit from that. [32:43.720 --> 32:56.080] Or if .hack or .freak they would consider, you know, to be anathema to ICANN's principles or the IANA function, do they have the right to stop that? [32:56.200 --> 32:58.200] That would be a really big problem. [32:59.180 --> 33:01.420] And then change requests also. [33:02.080 --> 33:13.620] ICANN is also assuming that change requests are going to come in, changes to the root zone from registries and TLD operators, usually only, on average, one per year. [33:13.840 --> 33:15.860] You know, so it's not too burdensome. [33:15.860 --> 33:20.860] But I think, you know, ICANN isn't used to working with major corporate clients. [33:20.980 --> 33:32.160] And when 34% of the applicants were .brand applications, I think they may see a major change in the type of accountability that is expected of them. [33:32.700 --> 33:37.460] Having dealt with lots and lots of corporate clients, they can be very demanding people. [33:37.460 --> 33:39.760] They expect your time and they expect a quick turnaround. [33:40.980 --> 33:48.180] Does ICANN have the capacity to basically serve the world's corporations in terms of root zone requests? [33:48.320 --> 33:52.280] And does this change the amount of times that the root zone file has to be propagated? [33:53.860 --> 34:03.440] And I think even more importantly, ICANN's security assessments related primarily to stability. [34:03.440 --> 34:08.100] The stability of the provisioning system and the stability of the root server operations. [34:08.360 --> 34:12.960] But not necessarily about security in the way in which people like you and I would think about this. [34:14.760 --> 34:17.200] You know, we have to think about the system as a whole. [34:17.380 --> 34:23.900] And the real fundamental question here is, can the DNS system be compromised by insecurities in the provisioning system? [34:24.240 --> 34:28.340] So, like we mentioned before, this involves IANA communicating to the U.S. [34:28.480 --> 34:30.400] Department of Commerce via the NTIA. [34:30.400 --> 34:35.440] The Department of Commerce communicating with VeriSign, VeriSign then communicating with the root server operators. [34:36.160 --> 34:42.220] And interjected into the mix of this are, per year, 1,000 new top-level domain operators. [34:42.560 --> 34:46.480] Now, can any of these communications between any of these parties be compromised? [34:46.480 --> 34:47.500] Can they be altered? [34:47.640 --> 34:48.480] Can they be spoofed? [34:49.180 --> 35:01.220] We need more details, I think, about this process to really make a serious assessment of whether this amount of change to the root zone could have a negative impact on the functioning of the domain name system. [35:02.440 --> 35:08.100] So, we also saw another somewhat troubling innovation in 2011. [35:08.560 --> 35:14.180] So, ICANN has been using an automated system for changes to the root zone, for routine changes. [35:14.420 --> 35:17.880] This thing, this EIANA change request tool, it's web-based. [35:18.140 --> 35:20.740] TLD operators get a username and password. [35:20.740 --> 35:28.300] They log into this thing, they make a change request, and then IANA brings it to NTIA, and we go down the process again. [35:29.840 --> 35:36.520] But what I don't understand is, you know, so are all TLD operators now going to have access to this EIANA change request? [35:36.760 --> 35:38.240] And that's going to be a big problem. [35:38.440 --> 35:44.260] I mean, if you're giving out 1,000 usernames and passwords to this thing per year, it's going to be compromised. [35:44.260 --> 35:51.680] You know, corporate America hasn't had the greatest track record when it comes to securing usernames and passwords. [35:53.520 --> 35:55.860] But none of us do, I guess, really. [35:57.360 --> 36:11.340] So, the other issue, too, is if this EIANA system becomes unavailable, then they're going to go back to this kind of normal process of, you know, somebody getting on the phone and via phone and fax and email making a change request. [36:11.340 --> 36:18.640] I mean, there's a gigantic potential for social engineering root zone changes, if we really saw that. [36:18.760 --> 36:24.220] I mean, maybe that's what we'll do in two years with Emmanuel on the panel. [36:26.120 --> 36:28.480] I'm not advocating that, but... [36:29.900 --> 36:32.620] So, let's go back to conclusions here for a second. [36:32.820 --> 36:37.880] I think that in terms of operations and provisioning, ICANN was probably right. [36:38.360 --> 36:44.280] I don't think there is going to be a major adverse effect to the domain name system in that sense. [36:44.820 --> 37:00.320] There probably is the capacity to handle these changes, but what we don't know is, you know, how greater extent of Internet connectivity and Internet exchange points being added throughout the world, how those servers could respond to additional queries. [37:00.500 --> 37:01.520] You know, we're not sure about that. [37:01.520 --> 37:04.800] We need more information about how these TLDs are going to be delegated. [37:05.380 --> 37:20.340] We need more information about these change requests and how they're going to handle changes from corporate clients, and about how the communicative process between these three or four different agencies and players in the root zone are actually going to be secured. [37:21.340 --> 37:31.820] So, this is probably more a function of ICANN's committee structure than anything else, because, you know, there are committees on basically everything at ICANN, and they have a very, very narrow focus. [37:32.260 --> 37:45.880] At this point, it seems like their real focus was stability, and I think that it would be up to people like us, maybe even through the public comment process, to make sure that ICANN really has a handle on the security within the process as well. [37:47.860 --> 37:53.860] And this is going to have a major effect on how the Internet is governed. [37:55.720 --> 37:58.280] And when we talk about Internet governance, what are we really talking about? [37:58.340 --> 38:05.360] We're talking about the coordination of the technical infrastructure and the policy that defines the way in which that infrastructure works and interacts. [38:05.760 --> 38:16.760] And so, with 1,930 different applications, you know, the Internet's definitely going to look a lot different, but you also have a lot more money at stake and a lot more players. [38:17.000 --> 38:21.160] And what we have right now through ICANN is this multi-stakeholder process. [38:21.420 --> 38:28.140] And, I mean, by definition, the more stakeholders you add to a multi-stakeholder process, the more change is going to be effected. [38:28.680 --> 38:32.120] So, really, I mean, who are the stakeholders right now? [38:33.200 --> 38:38.420] You know, ICANN is full of acronyms, GNSO, GAC, CCNSO. [38:38.420 --> 38:39.740] I mean, they're all over the place. [38:39.960 --> 38:43.500] The, you know, SSAC, absolutely. [38:44.600 --> 38:45.360] They're all over. [38:45.440 --> 38:45.860] They're all over. [38:46.020 --> 38:53.300] So, but the people that have historically been most active in ICANN are people who, you know, whose bottom line it affects. [38:53.580 --> 38:59.820] So, you have the registries, you have the registrars, you have the brands, and Internet-based businesses, search engines. [39:00.000 --> 39:04.000] You know, those are the guys that have been and are the major players in ICANNs. [39:04.000 --> 39:09.720] And these are the players that they have the means to send people to the ICANN meetings that occur throughout the world. [39:09.840 --> 39:16.000] They have the means to follow the somewhat slow-moving policy development process that ICANN has concocted. [39:16.580 --> 39:20.760] They have the means to submit comments and really participate in the process. [39:21.100 --> 39:24.840] So, their interest is always accounted for when there's shifts in Internet policy. [39:26.240 --> 39:30.900] And what's very significant in terms of the perspective of the rest of the world is that, well, this is really... [39:31.340 --> 39:34.440] the interests that are accounted for are the interests of the private sector. [39:35.420 --> 39:37.580] And maybe there's good reason for this, perhaps. [39:37.820 --> 39:41.840] You know, because Internet innovation and economic growth, well, they've always really gone hand-in-hand. [39:42.120 --> 39:47.120] And as we noted earlier, one of ICANN's core objectives is to promote competition. [39:47.500 --> 39:57.260] So, it should come as really no surprise that the rest of the world has seen ICANN as really a tool for business and the U.S. [39:57.400 --> 39:57.600] government. [39:58.320 --> 40:00.580] So, these changing stakeholders, who are they going to be? [40:00.640 --> 40:01.840] They're going to be these new registries. [40:02.020 --> 40:08.700] They're going to be, basically, the thousands of new registry operators who own little bits of the Internet. [40:10.480 --> 40:12.200] And these are dot brands. [40:12.400 --> 40:13.480] They're going to be, you know, industries. [40:13.700 --> 40:14.500] They're going to be communities. [40:14.500 --> 40:23.820] And we also saw applications from a very large... for a large number of just dot generic terms of people trying to snatch up Internet real estate. [40:24.480 --> 40:28.900] So, there's this corporation called Donuts, Inc., which kind of came out of nowhere. [40:29.400 --> 40:32.520] They filed 307 GTLD applications. [40:32.720 --> 40:34.760] That's a $56.8 million investment. [40:35.440 --> 40:38.960] Next on the line was Google, who filed 101 applications. [40:40.200 --> 40:41.980] That's $18.7 million. [40:42.420 --> 40:44.200] And top-level domain holdings filed 92. [40:44.600 --> 40:50.600] Then you have other smaller investors, you know, people who have applied for 10, 15, 60, below that. [40:50.700 --> 40:52.300] And a lot of these are generic terms. [40:52.680 --> 40:55.260] That could be very, very valuable Internet real estate. [40:55.660 --> 41:01.860] So, who stands to really become very powerful is this registry stakeholders group within ICANN itself. [41:02.040 --> 41:02.840] It's known as RISIG. [41:02.840 --> 41:07.840] And they are set to become arguably the most influential stakeholder in the process. [41:08.900 --> 41:16.280] So, this is a little bit troubling because I think ICANN has been getting better at accounting for other people's voices. [41:16.700 --> 41:20.440] You see more interaction with academia, governments, private industry. [41:20.700 --> 41:24.060] You saw them really trying to reach out to developing nations during the new GTLD process. [41:24.840 --> 41:27.200] Standards affecting bodies like the IETF. [41:27.200 --> 41:34.800] You know, they're all in there, but this overbalance of registries could really affect the way in which policy is made. [41:34.980 --> 41:39.520] I mean, essentially, it could drown out the voices of other stakeholders in the process. [41:40.360 --> 41:45.820] And it could shift some of ICANN's initiatives into more kind of self-interested type of endeavors. [41:46.740 --> 41:48.120] And you have to really think about it. [41:48.180 --> 41:50.820] I mean, most of the applications came from the U.S. [41:50.880 --> 41:51.340] and the EU. [41:52.340 --> 42:01.140] And in terms of connectivity and the global reach of the Internet, you know, the developing nations are just not really represented in this process right now. [42:03.420 --> 42:10.700] So, some further concerns are that, you know, Internet policy and free expression, well, these have always been inextricably linked. [42:11.060 --> 42:26.780] And for this multi-stakeholder process to endure for it to be meaningful and systematic and for it to still have some teeth, we really have to give a lot more consideration to how developing nations and how really the most important constituents, Internet users, [42:27.440 --> 42:29.500] are going to be accounted for in this process. [42:30.480 --> 42:40.100] And I think we really do need to continue to think through all of the implications of Internet policy and governance on things like free expression and innovation. [42:41.500 --> 42:51.580] And really, people like us, I think, have almost an obligation to become more involved with ICANN as constituents, maybe even as a constituent organization. [42:54.120 --> 42:58.560] So, we've talked about private industry and their involvement with ICANN. [42:58.600 --> 43:07.640] And now what we see also is another battle on the Internet governance front of stakeholders, these private industry, essentially, versus nations. [43:08.520 --> 43:22.580] I'm not sure if anybody has been following a lot of this debate, but the International Telecommunications Union, which is really a branch of the UN, has been doing a lot of posturing in terms of trying to take over some Internet governance functions. [43:22.740 --> 43:27.360] And we've already started to see some pushback from private industry about this. [43:28.040 --> 43:36.840] For instance, on May 24th, Vince Cerf, who was one of the, you know, the grandfathers of the Internet in terms of developing the TCP/IP protocol. [43:36.840 --> 43:39.300] He's Google's chief Internet evangelist right now. [43:40.040 --> 43:44.840] And really just a fantastic, fantastically bright and articulate man. [43:45.220 --> 43:50.220] Wrote an op-ed in the New York Times on May 24th call about keeping the Internet open. [43:51.180 --> 43:59.360] And this makes it very clear that private industry sees the multi-stakeholder model as valuable to them because their voice is heard there. [43:59.360 --> 44:02.200] It affects their bottom line. [44:04.140 --> 44:13.740] And traditional regulatory functions over the Internet would really, you know, could be stultifying or stifling in terms of what they can do and what they can roll out. [44:14.060 --> 44:19.700] So the multi-stakeholder model, which they're a gigantic part right now, you know, they want to keep it that way. [44:21.440 --> 44:30.680] And there are a lot of, you know, free speech and innovation and collaboration implications of this. [44:30.780 --> 44:36.500] And that's what private industry is really... those are the arguments that they're bringing out to the forefront. [44:36.680 --> 44:38.540] And they definitely make sense and they're cogent. [44:38.700 --> 44:43.280] But we also have to remember that there's other interests of private industry at stake. [44:43.280 --> 44:46.920] I mean, you saw this, again, in the SOPA-PEPA debate. [44:47.080 --> 44:52.520] And, you know, you have these powerful Internet companies basically standing off against the old guard. [44:52.760 --> 45:05.960] And here, what we have are, you know, these powerful Internet companies, these powerful giants of industry, basically facing off against any kind of regulatory interjection in the Internet governance process. [45:06.300 --> 45:08.780] And that's, you know, it's very telling. [45:08.780 --> 45:15.360] And I think it's something that we're going to continue to see so long as Internet governance is an area that's not really very, very well-defined. [45:15.620 --> 45:17.280] And it continues to be a gray area. [45:18.180 --> 45:30.080] So, a little background on the ITU, which is somewhat interesting, was actually established way back in the 19th century, in 1865, to facilitate amendments to something called the International Telegraph Convention. [45:30.400 --> 45:33.400] In 1947, it became a specialized agency of the UN. [45:33.400 --> 45:42.360] And since 2003, they've been posturing to get their hands involved in Internet governance through something called the World Summit on the Information Society. [45:42.620 --> 45:46.520] The first meeting was in Geneva in 2003, and then Tunis in 2005. [45:48.160 --> 45:57.100] The interesting thing, though, is that, you know, all of these negotiations with the ITU, the only people allowed into the process are nation states. [45:57.380 --> 45:58.580] There's no other stakeholders. [45:58.580 --> 46:05.040] There is some form of private membership into the organization, but it is incredibly expensive. [46:05.040 --> 46:08.520] I think in between $10,000 and $15,000 for a membership. [46:08.740 --> 46:13.780] And, you know, not every company and not every person can afford that kind of fee. [46:14.460 --> 46:20.080] So there's 193 states, and everybody gets a vote, and it's a majority that carries a vote. [46:20.220 --> 46:28.280] So what's scary about that is you have nations like Syria and China, and their vote counts just as much as the United States, as the UK. [46:29.460 --> 46:35.660] Right now, I think there are 40 countries that are actively censoring the Internet, and that's growing all the time. [46:37.400 --> 46:43.120] So nations, you know, having nations have some... [46:43.120 --> 46:48.140] Well, allowing nations to have some input into the Internet governance function is scary to a lot of people. [46:48.580 --> 46:50.860] And this is what private industry is really bringing out. [46:50.860 --> 46:59.140] So what's happening right now is that everyone is gearing up for a meeting in Dubai in December. [46:59.400 --> 47:03.080] And this is the World Conference on International Telecommunications Regulations. [47:03.320 --> 47:08.080] And what's going to happen there is they're going to amend these international telecommunications regulations. [47:08.280 --> 47:09.920] They haven't been amended since 1988. [47:09.920 --> 47:20.440] And really what they pertain to are kind of interoperability of international telecommunications equipment, radio frequencies, facilities, that kind of thing. [47:20.960 --> 47:36.180] But what, you know, in the way in which the ITU could become much more involved in Internet governance is if these are expanded into the scope of peering arrangements of the regulation of new technologies, data security and privacy requirements, international standards for such things, [47:36.180 --> 47:45.300] and the protection of children, which as we all know historically has been a kind of underrepresented and over-censored constituent of the Internet. [47:46.120 --> 47:48.360] And so there's a potential for a lot of censorship. [47:48.800 --> 47:51.740] And there's a potential for dramatic changes in terms of policy. [47:51.940 --> 47:57.560] And I don't think that can really be underestimated because all of these have been proposals by member states. [47:57.560 --> 48:09.760] So industry sees this, well, you know, they don't want to have these nation states interject, essentially, politics of diplomacy and compromise into the Internet governance process. [48:10.020 --> 48:11.800] They like the multi-stakeholder model. [48:12.300 --> 48:33.880] I think it was said best in an Internet protocol journal article from a few years ago where somebody kind of classifying various criticism that had been hurled at the ITU said it was accused of, you know, imposing anachronistic, inappropriate regulatory measures that stultify any form of innovation and progress in telecommunications. [48:34.060 --> 48:36.680] I think quite well put, but maybe a bit heavy-handed. [48:38.780 --> 48:43.120] And nations, other nations around the world, they see ICANN with a lot of skepticism. [48:43.120 --> 48:47.520] So they want to have their voice heard, and they think their voice is going to be better heard through something like the ITU. [48:47.520 --> 48:52.660] Because ICANN, it's a California not-for-profit corporation with direct ties to the U.S. [48:53.000 --> 48:53.980] Department of Commerce and U.S. Industry. [48:54.660 --> 49:05.340] And they see this, that ICANN has been basically positioned to maintain the U.S.'s advantageous position with regard to economic growth. [49:06.180 --> 49:12.320] And that they have, for a while, shunned the involvement of other nations or turned a blind eye to developing nations. [49:12.440 --> 49:13.460] And that's been a bit of a problem. [49:14.180 --> 49:16.700] So I think it really depends on your perspective here. [49:16.700 --> 49:29.900] So if you see the Internet as something like a public utility, something that the public has come to rely on, then it actually kind of makes sense that the ITU should be able to have some kind of regulatory function. [49:30.060 --> 49:39.320] But the ironic point of that is, or the ironic consequence of that is, that also presents the greatest potential for censorship. [49:40.260 --> 49:54.080] And if you see this as the Internet as a kind of decentralized force with economic power, then the multi-stakeholder model and ICANN's inclusion of private industry as the major stakeholders actually begins to make sense as well. [49:54.920 --> 50:11.780] So I think what we can take away from this is that there's going to be a great deal riding on matters of Internet governance that we're going to see, no matter what, some major changes to this multi-stakeholder model of governance where new TLD registries are going to have a very, [50:11.840 --> 50:16.840] very powerful voice in the registry stakeholders group and become more and more active throughout ICANN. [50:17.760 --> 50:25.320] And we have to ensure that normal Internet users' rights are just not pushed to the wayside. [50:26.020 --> 50:29.760] And you're also going to see, well, maybe after December, we'll see what happens. [50:30.160 --> 50:33.440] The ITU may have its hand in Internet governance functions. [50:33.520 --> 50:34.200] We just don't know. [50:34.320 --> 50:37.040] What we do know is industry is not going to let this happen without a fight. [50:38.660 --> 50:41.740] And I think it behooves all of us to follow this very closely. [50:43.740 --> 50:49.060] The multi-stakeholder model, however, in my opinion, it's actually served us pretty well so far. [50:49.380 --> 50:58.760] But I think, you know, what really matters is, you know, whether the ITU gains some governance power or not, we're stakeholders here. [50:58.800 --> 51:01.240] And I think we need to make our voice known. [51:01.380 --> 51:06.960] We need to continue to have, I think, a major impact on the way in which the Internet is governed and it's grown. [51:06.960 --> 51:10.160] And we should all have a part of the process. [51:10.500 --> 51:17.000] And I think we should really give a lot of thought to starting, you know, a hacker-based Internet registry. [51:17.980 --> 51:19.020] And that's it for me. [51:20.620 --> 51:21.860] So I'll take questions. [51:23.800 --> 51:25.380] And as I mentioned, thank you very much. [51:25.860 --> 51:29.020] As I mentioned, I'm an attorney here in New York with Steptail & Johnson. [51:29.420 --> 51:34.820] Anybody with any follow-up questions that aren't mentioned today, you know, can feel free to reach out to me directly. [51:36.380 --> 51:39.280] I live in the West Village and I work in Midtown, so I'm always around. [51:39.500 --> 51:40.380] Are you taking questions? [51:40.520 --> 51:40.960] Absolutely. [51:41.420 --> 51:42.800] We've got about three minutes. [51:43.080 --> 51:43.320] Okay. [51:43.720 --> 51:54.760] One of the underrepresented groups in ICANN seems to be the registrants themselves, who one would think perhaps they should benefit from this great expansion in the TLD space. [51:55.480 --> 51:59.760] And another interesting group is the CCTLDs, which are out of the process completely. [52:00.280 --> 52:15.520] So, you know, any sort of risk to the domain name system as a whole is often not in the GTLDs, the .coms and .mills and .nets, which are regulated by ICANN, but in the .cn and .ie and those. [52:15.520 --> 52:16.020] Yeah. [52:16.140 --> 52:18.560] So, I would appreciate your comments on that. [52:19.060 --> 52:26.280] Another question is whether what the ITU is really seeking is replacing the NTIA to sign the route. [52:26.600 --> 52:26.920] Yeah. [52:26.960 --> 52:36.320] Because the NTIA has been political in its choice of delaying to sign certain route updates like North Korea and Palestine, as my understanding. [52:36.320 --> 52:36.920] Absolutely. [52:37.320 --> 52:39.940] To go to your first question, I think I just agree with you. [52:40.080 --> 52:43.000] Registrants do need to have a greater voice. [52:43.260 --> 52:43.720] Absolutely. [52:44.340 --> 52:49.640] With regard to the CCTLD operators, the country code top-level domain operators, it's interesting. [52:49.880 --> 52:57.160] They're not really a part of the process, but they do have the right to object to other domain names being delegated. [52:57.160 --> 53:07.740] If they believe, you know, a GTLD application is confusingly similar to their own extension, they have the right to object to that and essentially knock out the application from the process. [53:08.300 --> 53:15.860] So, the extent to which they are going to become major players in the GTLD application process is yet to be seen. [53:16.060 --> 53:20.400] We'll probably see them stepping up to the plate in January at the end of the objection period. [53:21.060 --> 53:28.240] And with regard to the ITU replacing the NTIA, you're probably absolutely right about that. [53:28.760 --> 53:28.840] Yeah. [53:30.180 --> 53:31.040] Next question. [53:31.240 --> 53:31.640] Yes. [53:31.640 --> 53:38.060] So, my former employer had about 17,000 mostly parked domains to protect their trademark portfolio. [53:39.120 --> 53:54.260] And the expansion of the GTLDs feels to me from that perspective to be a nice organized shakedown on similar trademark holders to get them to register yet more of these domains in 100 or 1,000 additional namespaces. [53:54.980 --> 54:06.680] And the fact that ICANN is largely sort of feels like a cabal of registries or registrars, I'm sorry, sort of makes this sort of one take a fairly cynical view of the whole process. [54:06.960 --> 54:07.100] Yes. [54:07.220 --> 54:10.760] What's your take on ICANN as the sort of shakedown operator? [54:11.360 --> 54:21.700] It's been a major criticism of the program is that all these defensive registrations are going to have to essentially be multiplied times the number of dot generic TLDs there are in existence. [54:21.980 --> 54:28.660] And that's going to cause, you know, major brands to spend a hell of a lot more money than they would otherwise have. [54:28.780 --> 54:35.000] But to combat that perception, they've developed certain rights protection mechanisms that are inherent to the process now. [54:35.000 --> 54:45.900] ICANN is in the process of developing something called the trademark clearinghouse by which individual, any trademark owner can submit their mark to the trademark clearinghouse. [54:46.220 --> 54:53.100] And if you are going to register a domain within the TLD, you're going to get a notice if there's a direct hit that's a match with that particular string. [54:53.380 --> 55:12.040] So then the, if you go forward with it, the owner of the trademark would then get a notice that said, so-and-so registered this domain, and then they could go forward with some kind of UDRP or URS process by which they either disable the domain or transfer it back to them if they believe that they have to. [55:12.260 --> 55:17.320] But it doesn't negate the effect that they do still have to register these defensive registrations. [55:17.520 --> 55:25.400] And that's really more of a function of the history of trademark law and the obligations for trademark holders to enforce their rights. [55:25.820 --> 55:27.820] But we're seeing that shift as well. [55:27.820 --> 55:35.640] So I think when there's a shift in the law in which that creates this obligation, then the defensive registrations will probably decrease as well. [55:36.720 --> 55:38.280] And I think, I think we'll run out. [55:38.380 --> 55:40.500] I'm so sorry, but I'm happy to take questions afterwards. [55:40.960 --> 55:42.020] Thanks, everyone, for listening.