CircleIDLatest posts on CircleID2015-08-07T07:59:00-08:00tag:circleid.com,2002:master-feedhttp://www.circleid.com/images/logo_rss.gifhttp://www.circleid.com/images/logo_rss_icon.gifSubscribe with My Yahoo!Subscribe with NewsGatorSubscribe with My AOLSubscribe with BloglinesSubscribe with NetvibesSubscribe with GoogleSubscribe with PageflakesGlobal IPv6 Summit to Be Held on September 7th 2015tag:circleid.com,2015:blogs/1.90832015-08-07T07:59:00-08:00Xudong Zhang<p><span style="font-size:85%;color:#666666;padding:0 0 2px 7px;margin:0 0 10px 10px;border-left:1px solid #ddd;width:209px;float:right;line-height:1.4em;"><a href="http://www.conference.cn/ipv6/2015/En/" target="_blank"><img src="http://www.circleid.com/images/uploads/9083.gif" border="0" width="209" height="189" style="display:block;margin-bottom:13px;" /></a><strong>Global IPv6 & Next Generation Inter net Summit 2015</strong> – The summit is jointly held by IPv6 Forum and BII, with great support from IAB, ICANN, APNIC, IETF, IEEE, 5G World Alliance, ETSI and ONF, etc. The summit will have discussions on the IPv6 relevant technologies and applications in this era of exhausting IP address and rapid growth of Internet application. (<a href="http://www.conference.cn/ipv6/2015/En/" target="_blank">Click to Learn More</a>)</span>September 7th 2015 will see the Global IPv6 Next Generation Internet Summit 2015 (hereinafter referred to as IPv6 Summit) held in the Presidential Hotel Beijing. The conference will be co-hosted by the IPv6 Forum and BII Group, under the theme of "<em>IPv6 approaching, are you ready?</em>," which will be well attended by top-notch industrial experts both at home and abroad, hundreds of representatives from carriers across the globe, representatives of well-known vendors in the industry, experts from academic agencies, enterprise users, and many influential news outlets, who will discuss the mainstream plans and technical foci of large-scale IPv6 deployment, influence and challenges brought by IPv6 development on network security, Global Internet of Things boosted by IPv6, and other burning issues.
</p>
<p>
With the industrial consensus that IPv4 addresses are running out and IPv6 is the dominant trend, it seems that IPv6 is really approaching us. On one hand, many countries have run out of the IPv4 addresses, and hiking efforts committed by all governments to promoting next generation internet are now being made. China, for example, over recent years, has enacted Opinions on 12th Five-Year-Plan of Next Generation Internet, Opinions on Fully Implementing the Deployment of IPv6 in LTE Networks, etc. to fully boost the development of next generation internet. On the other hand, as the technology of transition from IPv4 to IPv6 is now maturing, the industrial demand has been enhanced, and the investment by carriers, vendors, etc. worldwide into IPv6 has been riding on an upward wave. Fuelled by various factors, the users of IPv6 are expanding in multiples, among which, more than 40% internet users in Belgium access internet by IPv6, and the penetration in the U.S., Germany, Peru, etc. are also increasing dramatically. It is worth mentioning that Mr. Fu Chengpeng, chief scientist with China Unicom points that IPv4 interest structure has been cast, and that it is hard to hike the speed while cut the price, which is easily possible with IPv6. It can be said that the government, carriers, vendors, and even internet users, through years of development and deployment, is ready for embracing the IPv6 era.
</p>
<p>
<strong>Supported by authoritative agencies, the summit is expecting industrial gurus in Beijing</strong>
</p>
<p>
It is learnt that the summit has received the support from IAB, ICANN, APNIC, IETF, IEEE, 5G World Alliance, ETSI, ONF, and many other authoritative agencies and organizations. At that time, Mr. Vint Cerf, Father of Internet, Mr. Latif Ladid, chair of Global IPv6 Summit, Jari Arkko, president of IETF, Andrew Sullivan, president of IAB, Ms. Zhao Huiling, director of China Cloud Computing Center, Mr. Duan Xiaodong, director of institute of network at China Mobile Institute, and Tang Xiongyan, Chief scientist with China Unicom Network Technology Institute, et al. will attend the summit and share their insights with the audience present.
</p>
<p>
<strong>Established brand through 15 consecutive sessions, significantly boosting the industry</strong>
</p>
<p>
This year marks the 15th session of the summit, which, based on the previous 14 sessions, has become the flagship conference of IPv6 next generation internet both at home and abroad, well attended by the top-notch internet experts, carriers, VIPs, and enterprises, who on the conference demonstrate their IPv6 solutions and successful applications and establish the most professional and comprehensive platform. It can said that IPv6 summit witnesses and propels the transition of IPv6 from the sprouting concept to the fruiting industry, recording their insights into the industry, and seeding the influence all over the world.
</p>
<p>
The news has it that during the IPv6 summit in 2014, the stocks of China's next generation internet waxed by 1.29%, and that the shares of some relevant enterprises swelled by over 8%. It is on the horizon that the summit will no doubt, galvanized by its great brand influence, bring more highlights to the next generation internet to lend a favour hand in ushering in the IPv6 era.
</p>
<p>
<strong>In-depth integration with the industry, with on-site ShowCase</strong>
</p>
<p>
According to the commission of the summit, in order to demonstrate in a full dimension the IPv6 progress to the audience, and establish a platform for industrial, academic, and research exchanges, the summit will also hold IPv6 ShowCase events, which extended invitations to the vendors that have been approved by IPv6 ready tests, for demonstrating the product, service, IPv6 and other diversified solutions. At the same time, there will be IPv6 ready real-time tests, SDN/IPv6 integration test, IPv6 Enabled quests, and IPv6 Education on-site consultancy at the venue of the summit. Whether you are the attending vendor or the audience, this is a premium opportunity for you to keep abreast of IPv6 technical status quo and the trending development, understand the current industry and find your partners.
</p>
<p>
<strong>Free admission — No charge for the audience to attend the summit</strong>
</p>
<p>
With the aim to drive IPv6 industry, the IPv6 summit will provide free tickets to all the audience that apply for the admission. No matter who you are, carriers, governments, enterprise users, hardware/software suppliers, chip manufacturers, end device suppliers, dot-coms, research institutes, universities, colleges, or investment agencies, welcome to our summit, and you will enjoy a premium industrial festival.
</p>
<p>
Refer to <a href="http://www.conference.cn/ipv6/2015/en">http://www.conference.cn/ipv6/2015/en</a> for more summit-related information.
</p><p><em>Written by <a href="http://www.circleid.com/members/7656/">Xudong Zhang</a></em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/ipv6">IPv6</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=rgVisewmfZg:cqSrP1B4ZlI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=rgVisewmfZg:cqSrP1B4ZlI:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=rgVisewmfZg:cqSrP1B4ZlI:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=rgVisewmfZg:cqSrP1B4ZlI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=rgVisewmfZg:cqSrP1B4ZlI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=rgVisewmfZg:cqSrP1B4ZlI:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=rgVisewmfZg:cqSrP1B4ZlI:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=rgVisewmfZg:cqSrP1B4ZlI:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=rgVisewmfZg:cqSrP1B4ZlI:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>ICANN Website Breached, Passwords Obtained by an Unauthorized Persontag:circleid.com,2015:news/6.90822015-08-06T13:14:00-08:00CircleID Reporter<p>Usernames/email addresses and encrypted passwords for profile accounts created on the ICANN.org public website have been obtained by an unauthorized person, the Internet Corporation for Assigned Names and Numbers announced Wednesday night. <a href="https://www.icann.org/news/announcement-2015-08-05-en">According to ICANN</a>, there is no evidence that any internal ICANN systems were accessed without authorization. "While investigations are ongoing, the encrypted passwords appear to have been obtained as a result of unauthorized access to an external service provider."
</p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/cyberattack">Cyberattack</a>, <a href="http://www.circleid.com/topics/icann">ICANN</a>, <a href="http://www.circleid.com/topics/security">Security</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=z3LBQiHFz4A:XkiKHT-22co:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=z3LBQiHFz4A:XkiKHT-22co:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=z3LBQiHFz4A:XkiKHT-22co:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=z3LBQiHFz4A:XkiKHT-22co:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=z3LBQiHFz4A:XkiKHT-22co:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=z3LBQiHFz4A:XkiKHT-22co:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=z3LBQiHFz4A:XkiKHT-22co:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=z3LBQiHFz4A:XkiKHT-22co:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=z3LBQiHFz4A:XkiKHT-22co:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>The Internet of Things: When Sci-Fi Becomes Realitytag:circleid.com,2015:blogs/1.90812015-08-06T11:28:00-08:00Ram Mohan<p><em>Chapter 15 – The Day of Reckoning
</p>
<p>
First it was the fridge — it didn't feel as cold. Then the oven was taking a long time to heat up. Then the air conditioning, the washer, the dryer… even the microwave — they all seemed a little off. Not much — but a proud and dedicated homeowner like myself could definitely feel it. Then my phone rang. It was John, my neighbor.
</p>
<p>
"Hey what's up?" I was talking to John but really staring at the holiday-themed, half-heated up microwave dinner box.
</p>
<p>
"Need a favor, neighbor. Our dryer is acting up. Can we come over and use yours..." John was still talking when the news alert popped up on the screen of my cell: WORLD'S LARGEST ECOMMERCE SITE GRINDS TO A HALT ON THE BUSIEST DAY OF ONLINE SHOPPING...</em>
</p>
<p>
<span style="display:block;text-align:center;">* * *</span>
</p>
<p>
In my <a href="http://www.circleid.com/posts/20150602_internet_of_things_solving_security_challenges/">last blog post</a> I shared some of the general security challenges that come with the Internet of Things (IoT). In this post, I will focus on one particular security risk: distributed denial of service (DDoS) attacks.
</p>
<p>
Even before the age of IoT, DDoS attacks have been turning multitudes of computers into botnets, attacking a single target and causing denial of services for the target's users. By "multitudes" we can be talking about thousands or even millions of victim devices. Now add IoT into the equation and we could be looking at billions of devices pressed into attack! The scale and the damage would be unprecedented and massive. Such attacks could bring some of the largest systems down (in my little piece of fiction above, an Amazon-like company). If it sounds like science fiction, it won't be for long. What will it take for DDoS attacks that use IoT devices to cross that line from fiction to reality and how we can prevent such disaster from happening?
</p>
<p>
<strong>DDoS Attacks – Growing and Evolving with IoT</strong>
</p>
<p>
DDoS attacks are getting worse: as reported by Akamai<sup>1</sup>, the number of DDoS attacks in Q1 2015 have more than doubled the same period last year. That's hardly a surprise as the most common software architecture, and its vulnerability, has remained unchanged for many years: the client-server model. Connected on the same network, clients (such as company computers) initiate a service request and servers (the company servers) provide the service. A company computer may request data or a software update, and the company's servers will provide the requested resource or service in response. If malware takes over, for instance, the compromised machines become a "zombie army." Since many company computers are always connected to the company's network, they can turn against the company's servers and initiate a DDoS attack.
</p>
<p>
The Akamai report calls out one important IoT-related issue: Simple Service Discovery Protocol (SSDP) attacks. SSDP are network protocols that bypass server-based configuration mechanisms and enable devices on the same network to discover and communicate with one another. They are intended for use with simple devices at home or in smaller offices — an important enabler scaling and making IoT readily available to the masses. SSDP attacks in Q1 2015 made up more than 20% of the attack vectors — something that wasn't even tracked a year ago. So that little wireless activities tracker you wear on your wrist (Fitbit, Apple Watch, and many others) which you love as it syncs up your health data on your cell phone and your company tablet? With a little bit of malware, it can turn into the zombie device that you fear: it can attack any server without your noticing until it's too late!
</p>
<p>
While the SSDP attacks reported have not turned fridges, coffee machines, microwaves, or dryers in our homes into zombie armies yet, their growth provides a great opportunity for abuse.
</p>
<p>
<strong>What You Can Do To Put off the day of reckoning</strong>
</p>
<p>
Let's face it: DDoS attacks will only get worse with IoT opening up even more opportunities for attacks. Without any breakthrough in security measures, players in the IoT ecosystem have to consciously and meticulously put some hard work (in fact a LOT of it!) into fighting this DDoS war.
</p>
<p>
<strong>1. Network engineers and administrators of large networks: Redefine your security strategy.</strong>
</p>
<ul><li><em>Understand the complexity:</em> With IoT, we are no longer talking about the operating systems of smart phones or tablets. Instead, we are looking at a quickly and ever-expanding list of "things" from clothing to watches to drones to cameras to sensors — the sky is the limit! These devices are made by different manufacturers, often operate on different protocols and connection methodologies, and have their own vulnerabilities. There is no single firewall — or a single solution — that will keep all things in IoT secure. There is not even a common management model for these devices. That's a paradigm shift for many network administrators.</li>
<li><em>Separate the networks:</em> Mitigate risks by putting IoT and company-issued IT devices on separate networks. So if one network is compromised, the other — with the company's most sensitive data — can stay intact.</li>
<li><em>Actively monitor:</em> You need to be able to understand your network traffic and detect intrusions quickly. Since attacks are almost "expected" these days, your ability to identify problems in real time is one of your strongest security strategies. However, IoT devices are unannounced and are provided access to secured corporate devices by the end-user without corporate technologies teams' knowledge or consent. These represent significant new intrusion points for those with malicious intent and you need to actively monitor/look out for such intrusions.</li>
<li><em>Exert influence early on in the decision-making process:</em> IoT is happening and the benefits are phenomenal. Your organization's leadership team will WANT to capitalize on the new business opportunities IoT brings along. You need to become and be known internally as an IoT expert, so management will want your opinion and guidance on IoT-related strategies. You don't want to be in a position where you have to implement an IoT plan full of security holes, or worse, one that has insufficient consideration for security.</li></ul>
<p>
<strong>2. Software designers: Put security in the forefront of your design process</strong>
</p>
<ul><li><em>Take IoT security seriously:</em> IoT devices are typically the weakest link when it comes to a network's security. The household electronics in my Sci-Fi opening are unlikely to support cryptology or other complex device architecture. They are the perfect botnet hosts and when they attack, their attacks will come from legitimate networks making it even harder for their target to detect. I believe the same security mechanisms built into expensive, high-performing computers should be extended to inexpensive, simple IoT devices.</li>
<li><em>Approach IoT security creatively:</em> When it comes to incorporating DDoS defensive mechanisms into IoT design and architecture, think out-of-the-box — literally! Today, many IoT devices don't even have the ability to receive firmware or software updates. For those that do, users typically have to allow such updates. In the future, however, this will likely evolve into automatic updates. Now that's a double-edged sword: there are security risks involved with auto-updates obviously, but manufacturers can also push patches automatically. Security can become an out-of-the-box solution then.</li></ul>
<p>
My Sci-Fi story is still being written, as is the story of IoT. Let's work together and give it a happy ending.
</p>
<p>
<span class="footNotes"><sup>1</sup> Akamai State of the Internet [Security] Report, May 2015</span>
</p><p><em>Written by <a href="http://www.circleid.com/members/1080/">Ram Mohan</a>, Executive Vice President & CTO, Afilias</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/ddos">DDoS</a>, <a href="http://www.circleid.com/topics/security">Security</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=zeOUfOojq18:bBEJIwjYIXo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=zeOUfOojq18:bBEJIwjYIXo:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=zeOUfOojq18:bBEJIwjYIXo:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=zeOUfOojq18:bBEJIwjYIXo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=zeOUfOojq18:bBEJIwjYIXo:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=zeOUfOojq18:bBEJIwjYIXo:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=zeOUfOojq18:bBEJIwjYIXo:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=zeOUfOojq18:bBEJIwjYIXo:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=zeOUfOojq18:bBEJIwjYIXo:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Tips for Managing Your Company's Shadow IT Issuestag:circleid.com,2015:blogs/1.90792015-08-06T10:26:00-08:00John Grady<p><strong>Shadow Dance: Managing the IT You Can't See</strong>
</p>
<p>
Shadow IT — the use of unsanctioned software and services by employees — is a problem. It's a big one. <a href="http://www.forbes.com/sites/joemckendrick/2015/01/20/is-shadow-it-a-runaway-train-or-an-innovation-engine/">According to Forbes</a>, 72 percent of executives don't know how many "shadow" apps are being used on their network. Beyond overloading network resources and impacting data compliance, there is also the real threat of security breaches from unapproved apps. Managing IT you can't see is no easy task, but fortunately it's not impossible. Here are five tips to help bring light to the shadows.
</p>
<p>
<strong>Discover</strong>
</p>
<p>
The first step in managing shadow IT? Identifying use. <a href="http://www.cio.com/article/2380960/byod/6-tips-to-help-cios-manage-shadow-it.html">According to CIO</a>, this demands constant network monitoring — how many services and devices are in use at any given time, and are they approved? Continuous scanning gives IT admins the heads up if a new device comes online or a new service is deployed, allowing them to zero in on suspect applications and employees willing to circumvent IT policies.
</p>
<p>
<strong>Defend</strong>
</p>
<p>
Of course, some shadow IT applications will slip through the cracks, potentially leaving corporate networks vulnerable. Information Age points to the need for an effective, automatic defense such as next-generation firewalls that are designed to recognize "thousands of unique applications, including those delivered over a SaaS-based model." These firewalls also permit granular access control, allowing admins to permit or deny use based on need, role or risk assessment. In addition, they facilitate the development of a collaborative rather than combative IT culture by allowing users to continue using apps verified as low-risk.
</p>
<p>
<strong>Destroy</strong>
</p>
<p>
Shadow IT is here to stay — cut off access to one cloud service and five more will take its place as employees look for the shortest path between technology and business objectives. While it's impossible to destroy shadow IT outright, there are other areas in your enterprise that could benefit from some creative restructuring. <a href="http://www.itbusinessedge.com/slideshows/five-tips-for-overcoming-shadow-it-in-the-enterprise-07.html">As noted by IT Business Edge</a>, key components of uncontrolled shadow IT proliferation are the departmental silos that naturally spring up around technology. By tearing down these walls and ensuring that all users are on the same playing field, you reap the benefit of much-improved IT sightlines.
</p>
<p>
<strong>Develop</strong>
</p>
<p>
Of course, all of these steps result in only a temporary fix if IT admins don't take the time to develop companywide access and use policies that specifically address shadow IT. It starts with an evaluation of risk — what's the potential impact of a breach, or the backlash of cutting off all users from non-approved apps? No matter the ultimate decision, it's important to create an IT policy that is clear about expectations and consequences, and is uniformly enforced across the enterprise — regardless of role, title or department, everyone must be bound by the same rules.
</p>
<p>
<strong>Discuss</strong>
</p>
<p>
The final piece of the shadow IT puzzle? Thinking long term. <a href="http://www.technewsworld.com/story/82154.html">Tech News World discusses shadow IT</a> in the light of Sei Weng's "The Lost Horse" — a Chinese proverb that speaks to the unpredictability of fortune. When Sei Weng's horse goes missing, his neighbors commiserate — but he argues the event could actually be good fortune, and sure enough the horse returns with a powerful stallion in tow. They congratulate him, but Sei Weng notes that not everything is at it appears; the new horse later throws his son and the result is a broken leg. For IT, the lesson here is taking the time to dive headlong into shadow IT and see how it's really impacting your business. Seemingly innocuous apps could be doing major damage or exposing sensitive files, while large-scale file storage apps might actually provide long-term value.
</p>
<p>
Want a better look at shadow IT? Discover what's happening and defend your network, destroy silos and then develop a companywide policy in discussion with employees.
</p><p><em>Written by <a href="http://www.circleid.com/members/7261/">John Grady</a>, Senior Manager of Product Marketing</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/cloud_computing">Cloud Computing</a>, <a href="http://www.circleid.com/topics/security">Security</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=mMqg7q3oO7s:drRnovVPsFY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=mMqg7q3oO7s:drRnovVPsFY:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=mMqg7q3oO7s:drRnovVPsFY:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=mMqg7q3oO7s:drRnovVPsFY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=mMqg7q3oO7s:drRnovVPsFY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=mMqg7q3oO7s:drRnovVPsFY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=mMqg7q3oO7s:drRnovVPsFY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=mMqg7q3oO7s:drRnovVPsFY:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=mMqg7q3oO7s:drRnovVPsFY:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Are Botnets Really the Spam Problem?tag:circleid.com,2015:blogs/1.90782015-08-05T09:54:00-08:00Laura Atkins<p>Over the last few years I've been hearing some people claim that botnets are the real spam problem and that if you can find a sender then they're not a problem. Much of this is said in the context of hating on Canada for passing a law that requires senders actually get permission before sending email.
</p>
<p>
Botnets are a problem online. They're a problem in a lot of ways. They can be used for denial of service attacks. They can be used to mine bitcoins. They can be used to host viruses. They can be used to send spam. They are a problem and a lot of people spend a lot of time and money trying to take down botnets.
</p>
<p>
For the typical end user, though, botnets are a minor contributor to spam in the inbox. Major ISPs, throughout the world, have worked together to address botnets and minimize the spam traffic from them. Those actions have been effective and many users never see botnet spam in their inbox, either because it's blocked during send or blocked during receipt.
</p>
<p>
Most of the spam end users have to deal with is coming from people who nominally follow CAN SPAM. They have a real address at the bottom of the email. They're using real ISPs or ESPs. They have unsubscribe links. Probably some of the mail is going to opt-in recipients. This mail is tricky, and expensive, to block, so a lot more of it gets through.
</p>
<p>
Much of this mail is sent by companies using real ISP connections. <a href="https://krebsonsecurity.com/">Brian Krebs</a>, who I've <a href="https://wordtothewise.com/?s=krebs">mentioned before</a>, wrote an article about one hosting company who previously supported a number of legal spammers. This hosting company was making $150,000 a month by letting customers send CAN SPAM legal mail. But the mail was unwanted enough that AOL blocked all of the network IP space — not just the spammer space, but all the IP space.
</p>
<p>
It's an easy decision to block botnet sources. The amount of real mail coming from botnet space is zero. It's a much bigger and more difficult decision to block legitimate sources of emails because there's so much garbage coming from nearby IPs. What AOL did is a last resort when it's clear the ISP isn't going to stop spam coming out from their space.
</p>
<p>
Botnets are a problem. But quasi legitimate spammers are a bigger problem for filter admins and end users. Quasi legitimate spammers tend to hide behind ISPs and innocent customers. Some send off shared pools at ESPs and hide their traffic in the midst of wanted mail. They're a bigger problem because the mail is harder to filter. They are bigger problems because a small portion of their recipients actually do want their mail. They're bigger problems because some ISPs take their money and look the other way.
</p>
<p>
Botnets are easy to block, which makes them a solved problem. Spam from fixed IPs is harder to deal with and a bigger problem for endusers and filters.
</p>
<p>
<em>This post originally published on <a href="https://wordtothewise.com">Word to the Wise</a>.</em>
</p><p><em>Written by <a href="http://www.circleid.com/members/4297/">Laura Atkins</a>, Founding partner of anti-spam consultancy & software firm Word to the Wise</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/cyberattack">Cyberattack</a>, <a href="http://www.circleid.com/topics/security">Security</a>, <a href="http://www.circleid.com/topics/spam">Spam</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=sLA7bK-kyjk:4wN6rbFOq9o:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=sLA7bK-kyjk:4wN6rbFOq9o:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=sLA7bK-kyjk:4wN6rbFOq9o:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=sLA7bK-kyjk:4wN6rbFOq9o:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=sLA7bK-kyjk:4wN6rbFOq9o:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=sLA7bK-kyjk:4wN6rbFOq9o:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=sLA7bK-kyjk:4wN6rbFOq9o:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=sLA7bK-kyjk:4wN6rbFOq9o:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=sLA7bK-kyjk:4wN6rbFOq9o:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>The IANA Stewardship Transition - Now Is the Time to Share Your Viewstag:circleid.com,2015:blogs/1.90772015-08-05T09:26:00-08:00Konstantinos Komaitis<p>The <a href="http://www.internetsociety.org/ianaxfer">IANA Stewardship Transition</a> process may have started more than a year ago, but last week it reached its pinnacle <a href="https://www.ianacg.org/icg-files/documents/IANA-stewardship-transition-proposal-EN.pdf">with the publication</a> of the compiled Proposal to Transition the Stewardship of the Internet Assigned Numbers Authority (IANA) Functions from the US Commerce Department's National Telecommunications and Information Administration (NTIA) to the Global Multistakeholder Community" by the IANA Coordination Group (ICG).
</p>
<p>
Now, it is time for all of us to tune in and share our views on this very important proposal.
</p>
<p>
This is an historical moment which we can all be part of. I would like to encourage everyone to read and reflect on the ICG proposal, participate at the webinars and submit their comments to the ICG's process. The Internet has consistently been shaped and evolved through bottom-up and inclusive processes. The IANA Transition process is no exception and everyone is invited.
</p>
<p>
In this context, the ICG is now inviting the global Internet community to review, reflect and deliberate on the proposal and asks all interested parties to <a href="https://www.ianacg.org/calls-for-input/combined-proposal-public-comment-period/#instructionssubmitcomment">submit their comments</a> by the 8th September 2015 at 23:59 UTC.
</p>
<p>
As part of this call for public comment and continuing its role as an additional source of information and knowledge on all things IANA, <a href="https://www.ianacg.org/iana-stewardship-transition-coordination-group-icg-to-host-webinars-in-conjunction-with-call-for-public-comment/">the ICG will be hosting two webinar</a>s with the aim to help the public understand the proposal, the purpose of the ICG's public comment period and how to provide public comments. The topics that will be covered include:
</p>
<ul><li>What are the IANA functions?</li>
<li>What is the IANA stewardship transition?</li>
<li>What is being proposed for the transition of the IANA stewardship?</li>
<li>Why is the ICG seeking public comments?</li>
<li>What should commenters focus on?</li></ul>
<p>
At the same time, in parallel to the ICG's proposal, the Cross-Community Working Group (CCWG) on Accountability has just released its <a href="https://www.icann.org/public-comments/ccwg-accountability-2015-08-03-en">second draft for public comment</a>. For the past months, members of the CCWG-Accountability have been working on enhancements to ICANN's accountability framework that have been identified as essential to happen or be committed to before the IANA Stewardship Transition takes place. This is just as an important process as the ICG one and it significant that the community pays similar attention to these recommendations.
</p>
<p>
Finally, last week, the Internet Society released a <a href="https://www.internetsociety.org/sites/default/files/IANA-Transition-Perspectives-20150728-en.pdf">policy paper</a> entitled: "Perspectives on the IANA Stewardship Transition Principles". The paper is a contribution to the ongoing discussions regarding <a href="https://www.internetsociety.org/ianaxfer">the IANA transition process</a>. Like all other interested parties, the Internet Society is contributing to this process. As we have previously stated "<a href="http://www.internetsociety.org/news/internet-society-board-trustees-encourages-continued-trust-multistakeholder-process-iana">a successful transition [can help] reinforce the value of the collaborative, multistakeholder model</a>”.
</p>
<p>
What is currently taking place should be considered a milestone in the administration and management of the Internet. In one of my previous blog posts, I have said that this transition has always been in the cards — since 1998 to be precise. We have come a long way. We now have a final proposal and a global Internet community that is more mature, more diverse and more committed than ever before.
</p>
<p>
In this spirit, we should continue to show our support and help shape the future of the Internet.
</p>
<p>
P.S. The NTIA's Larry Strickling has also published an article asking for comments: <a href="http://www.ntia.doc.gov/blog/2015/let-your-voice-be-heard-iana-transition">Let Your Voice be Heard on IANA Transition.</a>
</p><p><em>Written by <a href="http://www.circleid.com/members/949/">Konstantinos Komaitis</a>, Policy Advisor for the Internet Society</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/dns">DNS</a>, <a href="http://www.circleid.com/topics/domain_names">Domain Names</a>, <a href="http://www.circleid.com/topics/icann">ICANN</a>, <a href="http://www.circleid.com/topics/internet_governance">Internet Governance</a>, <a href="http://www.circleid.com/topics/top_level_domains">Top-Level Domains</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=YOcvN65tGLc:u6uGCTKMmWg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=YOcvN65tGLc:u6uGCTKMmWg:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=YOcvN65tGLc:u6uGCTKMmWg:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=YOcvN65tGLc:u6uGCTKMmWg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=YOcvN65tGLc:u6uGCTKMmWg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=YOcvN65tGLc:u6uGCTKMmWg:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=YOcvN65tGLc:u6uGCTKMmWg:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=YOcvN65tGLc:u6uGCTKMmWg:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=YOcvN65tGLc:u6uGCTKMmWg:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>ICANN Wins a Very Weak TLD Lawsuittag:circleid.com,2015:blogs/1.90762015-08-04T09:51:00-08:00John Levine<p>Back in the 1990s as the Internet was starting to become visible to the world, several people had the bright idea of setting up their own top level domains and selling names in competition with what was then the monopoly registrar Network Solutions (NSI). For these new TLDs to be usable, either the TLD operators had to persuade people to use their root servers rather than the IANA servers, or else get their TLDs into the IANA root.
</p>
<p>
Attempts to get people to use other roots never were very successful, particularly after Eugene Kashpureff, the operator of alternate root AlterNIC made an ill-advised attempt to use DNS cache poisoning to <a href="https://en.wikipedia.org/wiki/AlterNIC#Hijacking_of_InterNIC.27s_website">hijack web traffic from the InterNIC website</a> and pled guilty to wire fraud.
</p>
<p>
Some of the alternate root TLDs are still around, with operators who are under the impression that they have a right to have their TLDs in the IANA root. One of them is name.space.
</p>
<p>
In 1997, around the time the government was figuring out how to move the Internet out from its direct oversight, name.space asked NSI to add their TLDs to the root, and NSI not surprisingly said no. Name.space then sued NSI for anti-trust, and subsequently added the National Science Foundation (NSI's contractor) as a defendant on First Amendment grounds. Name.space lost in court, appealed, and <a href="http://law.justia.com/cases/federal/appellate-courts/F3/202/573/592580/">lost on appeal.</a> The courts found that NSI was acting under a government contract, and anti-trust law doesn't apply to the government itself, and that (oversimplifying a little) domain names are like phone numbers, not speech that gets First Amendment protection.
</p>
<p>
Shortly after that, name.space who was nothing if not persistent, applied to have 118 of its TLDs included in ICANN's 2000 round of TLD expansion, paying $50,000. ICANN never really defined its procedures to approve or deny applications, trickled out 12 new domains between 2001-2006, and never finally said yes or no to the rest of them, other than the contentious .XXX finally approved in 2011. Name.space was not the only applicant left hanging in that round.
</p>
<p>
In the current round, ICANN implicitly said that the 2000 round was over and as a consolation prize offered a one-time discount from the new $185,000 price to each prior applicant. ICANN got almost 2000 applications at $185K each, but not from name.space who said (no doubt truthfully) that they couldn't afford 118 x $185K to reapply. So in 2012, they sued instead.
</p>
<p>
The <a href="http://name.space.xs2.net/law/2012-10-10+name.space+v+icann.pdf">complaint that started the suit</a> is a 35 page rant accusing ICANN of an anti-competitive conspiracy with Verisign, Afilias and others to monopolize the domain market, infringing name.soace's trademarks in their TLDs, and various other charges.
</p>
<p>
They <a href="https://www.icann.org/en/system/files/files/order-granting-icann-motion-to-dismiss-04mar13-en.pdf">lost in district court</a> again, and last week, they <a href="https://www.icann.org/en/system/files/files/namespace-ninth-circuit-affirming-dismissal-31jul15-en.pdf">lost again on appeal</a>. The grounds were somewhat different from last time. The courts held that you need more than a failed business plan to prove an anti-competitive conspiracy. ICANN had plausible business reasons for the higher prices (such as anticipating that disgruntled parties would sue them), and they of course they got plenty of applications from other people. The courts similarly dismiss a claim for intentional interference with name.space's contracts since there is no evidence that ICANN intended to do so. Indeed, there is no evidence I can see that they were paying any attention to name.space at all.
</p>
<p>
For the trademarks, when the district court ruled in 2013, none of the TLDs in the current round were active yet, the trademark issue was not "ripe" for decision, so at that time name.space had no trademark claims to decide. By the time the appeals court ruled last week, dozens of the disputed names, from .ACADEMY to .SUCKS, were active, but appeals don't revisit the facts of the case, only whether the original court applied the law correctly. So the appeals court agreed that the trademark issue wasn't ripe in 2013 and that was that.
</p>
<p>
In principle, name.space could refile a trademark claim, but it's extremely unlikely they could win. The complaint acknowledges that the US Patent and Trademark Office has not allowed TLDs as trademarks and has a couple of pages of hand waving about why this time is different, but I don't find it persuasive and I doubt a court would either.
</p>
<p>
Some press reports are spinning this as a big victory for ICANN, which it is not. This case was fatally weak when it was filed, and it's no surprise it turned out as it did.
</p>
<p>
One last thing I don't understand is who's paying for the suit. Name.space's lawyers are Morrison Foerster, a large firm whose work does not come cheap. I see a page at rally.org where name.space is trying to raise legal funds with little success, a total of about $2000 so far, which wouldn't pay for the first page of the complaint. The suit asks for damages which would pay the lawyers if they won, but with such a weak case I'd be surprised if anyone would take it on contingency.
</p><p><em>Written by <a href="http://www.circleid.com/members/1015/">John Levine</a>, Author, Consultant & Speaker</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/domain_names">Domain Names</a>, <a href="http://www.circleid.com/topics/icann">ICANN</a>, <a href="http://www.circleid.com/topics/law">Law</a>, <a href="http://www.circleid.com/topics/top_level_domains">Top-Level Domains</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=Ulkml5FLF_s:JVZ7pM9Kq8g:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=Ulkml5FLF_s:JVZ7pM9Kq8g:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=Ulkml5FLF_s:JVZ7pM9Kq8g:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=Ulkml5FLF_s:JVZ7pM9Kq8g:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=Ulkml5FLF_s:JVZ7pM9Kq8g:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=Ulkml5FLF_s:JVZ7pM9Kq8g:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=Ulkml5FLF_s:JVZ7pM9Kq8g:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=Ulkml5FLF_s:JVZ7pM9Kq8g:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=Ulkml5FLF_s:JVZ7pM9Kq8g:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>ICG Seeking Public Feedback on Key Internet Governance Proposaltag:circleid.com,2015:news/6.90752015-08-04T09:15:00-08:00CircleID Reporter<p>The IANA Stewardship Transition Coordination Group (ICG) <a href="https://www.ianacg.org/news-release-icg-seeking-public-input-on-key-internet-governance/">on Friday released for public comment</a> the proposal for the transition of the stewardship of the Internet Assigned Numbers Authority (IANA) functions from the U. S. Department of Commerce's National Telecommunications and Information Administration (NTIA) to the global multistakeholder community. The ICG is encouraging the public to review <a href="https://www.ianacg.org/icg-files/documents/IANA-stewardship-transition-proposal-EN.pdf">the proposal</a> and share their reactions and comments during the public comment period here.
</p>
<p>
"The dedication that the Internet community has exhibited to the IANA stewardship transition is nothing short of remarkable," said Alissa Cooper, Chair of the ICG and member of the Internet Engineering Task Force (IETF) community. "The public comment period presents an opportunity for the public to assess the transition proposal in its entirety and for the ICG to build a public record demonstrating how the proposal meets the expectations set out by the U.S. Government."
</p>
<p>
Following the opening of the 40-day public comment period, the ICG will host two briefing webinars open to the public on <em>Thursday 6 August</em>, <em>19:00-20:30 UTC</em> and <em>Friday 7 August</em>, <em>11:00-12:30 UTC</em>.
</p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/icann">ICANN</a>, <a href="http://www.circleid.com/topics/internet_governance">Internet Governance</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=VBBVM4spXfY:XlBE4U7nIes:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=VBBVM4spXfY:XlBE4U7nIes:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=VBBVM4spXfY:XlBE4U7nIes:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=VBBVM4spXfY:XlBE4U7nIes:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=VBBVM4spXfY:XlBE4U7nIes:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=VBBVM4spXfY:XlBE4U7nIes:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=VBBVM4spXfY:XlBE4U7nIes:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=VBBVM4spXfY:XlBE4U7nIes:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=VBBVM4spXfY:XlBE4U7nIes:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>From Toad to Princess - New TLDs Are No Magical Wand in the Kingdom of Search Enginestag:circleid.com,2015:blogs/1.90742015-08-04T08:58:00-08:00Hans Seeuws<p><em>Co-authored by David Hallam, Business Development Director NCC Group and Hans Seeuws, Managing Director OpenRegistry.</em>
</p>
<p>
Google has posted details on <a href="http://googlewebmastercentral.blogspot.fr/2015/07/googles-handling-of-new-top-level.html">Ranking of new gTLDs</a> (new gTLDs) in search. John Mueller, Webmaster Trends Analyst, said that new gTLD's will be treated the same as other gTLD's such as .com. He stated: <em>"Overall, our systems treat new gTLDs like other gTLDs (like .com & .org). Keywords in a TLD do not give any advantage or disadvantage in search."</em> The ambiguous use of the word "overall" in the statement, may leave some doubt as to whether the 600 .brands — new domain extensions operated by brand owners — are included or excluded in any VIP search ranking treatment. One could speculate that the vague wording is perhaps driven by commercial reasons. If Google had announced that all domains within a .brand domain extension would be valued higher, why would those same brands then bother to register their names in any of Google's new domain extensions such as .home or .site?
</p>
<p>
Google's comment on new domain name ranking wasn't the first of its kind. The message became somewhat of a mantra each time an SEO study around new Internet extensions claimed to have discovered a domain ending that brings specific search benefits.
</p>
<ul><li>German search engine optimisation specialist Searchmetrics found what appeared to be a 1.18 position improvement in .berlin domains when web users were searching for information while physically located in Berlin. Search engines often use your IP address to deliver better results.</li>
<li>Total Websites took screenshots that appeared to show how a domain ending in ".company" would do better than an equivalent dot-com domain if someone used the term "company" in their search. It found the same pattern across other new domain extensions as well.</li></ul>
<p>
A domain extension — whether or not it contains a keyword — is only one part of the entire URL. It's no magical wand that will transform any toad into a high ranking Google princess. Far more relevant is that .brands can utilise their seizable investment to create a domain naming strategy that aligns with consumer search behavior. Combined with proven SEO methods, this can pave the way to 'click through rate' heaven.
</p>
<p>
<strong>The Only Way for .brands Is Up</strong>
</p>
<p>
Having full control over every character between the two dots unleashes a powerful weapon with several ways for .brands to attract attention.
</p>
<ol><li>The presence of search terms in the domain name leads to higher organic rankings or a better ad quality score in pay-per-click ad ranking algorithms. <a href="http://www.memorabledomains.co.uk/ppc-generic-domains.html">Studies</a> show that using the ideal generic name produced 45 per cent more clicks on an ad. Don't make a term like 'home', 'domains', or 'nic' your online operating basis, but look for keywords that match closely with what your customers are searching for.</li>
<li>Shorter snappy titles get read first — myproduct.brand instead of brand.com/myproduct</li>
<li>We tend to give more attention to words at the end of a sentence or line. .brands will shift the consumer's attention away from a generic .com towards a meaningful and relevant brand.</li>
<li>Last but not least: keywords in a search show up in bold in the URL. How's that for an online neon sign?</li></ol>
<p>
<em>"The fundamental way to increase your rank is to increase your relevance,"</em> Google CEO <a href="http://adage.com/article/media/google-s-schmidt-internet-cesspool-brands/131569/">Eric Schmidt quote</a>. Billions of Internet users each day decide what is relevant and what is not, by clicking. The more that new .brand domain extensions start actively using their extension AND host content rich sites, the more Internet users will prefer URLs that they know and trust, and click on them. The more visitors, the better the click rate, one of the search metrics that factor in determining a search engine rank.
</p>
<p>
<strong>Things to Consider when Launching Your .brand</strong>
</p>
<ul><li>Consistency in domain naming - If you type in www.example.brand, but then your type in just example.brand and the "www" does not redirect to www.example.brand, that means the search engines are seeing two different sites. This isn't effective for your overall SEO efforts as it will dilute your inbound links, as external sites will be linking to www.example.com and example.com.</li>
<li>Bad redirects -Shifting from a .com to a new .brand domain extension requires the right precautionary measures to avoid the risk of causing search engine issues. Set up the redirects on a page-to-page basis such that sub-folders and deep content pages are redirected to corresponding sub-folders and deep content pages on the new domain. SEO specialists should avoid redirecting all pages from one domain to the homepage of another domain.</li>
<li>Duplicate content - If you decide to build your new domain extension AND keep the .com alive at the same time, there needs to be sufficiently different content on each website to avoid a duplicate content penalty.</li>
<li>Frivolous forwarding - Registering domain names and redirecting them to another site has long been a practice employed for SEO reason. Though this has been effective in the past, Google largely devalues URLs that simply forward.</li></ul>
<p>
<strong>One More Thing… </strong>
</p>
<p>
Google is trying to find the most relevant search results, not the sites that best game the system. And relevance and brands are closely linked according to Schmidt, back in 2008 he said: <em>"The Internet is fast becoming a cesspool where false information thrives. Brands are the solution, not the problem. Brands are how you sort out the cesspool."</em> Not a single brand has paid the $185,000 ICANN application fee to game the search engine system. What better way for a brand to be considered relevant online than to create its own gated community and put a lid on that cesspool?
</p><p><em>Written by <a href="http://www.circleid.com/members/7653/">Hans Seeuws</a>, Managing Director at OpenRegistry</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/top_level_domains">Top-Level Domains</a>, <a href="http://www.circleid.com/topics/web">Web</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=7nWC3MvbyBQ:ofBiRKTSLyY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7nWC3MvbyBQ:ofBiRKTSLyY:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=7nWC3MvbyBQ:ofBiRKTSLyY:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7nWC3MvbyBQ:ofBiRKTSLyY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=7nWC3MvbyBQ:ofBiRKTSLyY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7nWC3MvbyBQ:ofBiRKTSLyY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7nWC3MvbyBQ:ofBiRKTSLyY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=7nWC3MvbyBQ:ofBiRKTSLyY:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7nWC3MvbyBQ:ofBiRKTSLyY:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Group Working on Securing Email Using DNStag:circleid.com,2015:news/6.90732015-08-03T21:09:00-08:00CircleID Reporter<p>A group of researchers from the US government and dot-com operator VeriSign are working on a new system for secure email: using domain names. Highlighting the problems and security holes associated with current mail systems, the team from the National Institute of Standards and Technology (NIST), a subset of the US Department of Commerce, argues that by using a new set of security protocols built around the domain name system, it is possible to provide a much higher level of security in electronic messages.
</p><p><strong>Read full story:</strong> <a href="http://www.theregister.co.uk/2015/08/03/nextgen_secure_email/">The Register</a></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/dns">DNS</a>, <a href="http://www.circleid.com/topics/email">Email</a>, <a href="http://www.circleid.com/topics/security">Security</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=5lw9mOxhQ30:H0C6gxskJgs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=5lw9mOxhQ30:H0C6gxskJgs:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=5lw9mOxhQ30:H0C6gxskJgs:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=5lw9mOxhQ30:H0C6gxskJgs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=5lw9mOxhQ30:H0C6gxskJgs:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=5lw9mOxhQ30:H0C6gxskJgs:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=5lw9mOxhQ30:H0C6gxskJgs:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=5lw9mOxhQ30:H0C6gxskJgs:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=5lw9mOxhQ30:H0C6gxskJgs:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Air Pollution in China Causing Higher Data Center Equipment Failure Ratestag:circleid.com,2015:news/6.90722015-08-03T11:47:00-08:00CircleID Reporter<p>China's notoriously high air pollution levels are a well-documented public-health issue. But pollution also has other less talked about effects. One of them is on the <a href="http://www.datacenterknowledge.com/archives/2015/08/03/china-data-center-operators-struggle-with-pollution/">efficiency of data centers</a> in the country. Pulling outside air into a data center to cool equipment to reduce energy used by mechanical cooling systems has been one of the most effective ways to increase the facility's energy efficiency.
</p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/data_center">Data Center</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=7wfMo-8uq_I:73JwFs3IuUY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7wfMo-8uq_I:73JwFs3IuUY:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=7wfMo-8uq_I:73JwFs3IuUY:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7wfMo-8uq_I:73JwFs3IuUY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=7wfMo-8uq_I:73JwFs3IuUY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7wfMo-8uq_I:73JwFs3IuUY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7wfMo-8uq_I:73JwFs3IuUY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=7wfMo-8uq_I:73JwFs3IuUY:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7wfMo-8uq_I:73JwFs3IuUY:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Neustar Acquires Bombora Technologies, the Holding Group for Ari Registry Services and AusRegistrytag:circleid.com,2015:news/6.90702015-07-31T10:36:00-08:00CircleID Reporter<p>Neustar <a href="http://www.businesswire.com/news/home/20150730006640/en/Neustar-Acquires-Leading-Domain-Registry-Provider-Bombora#.VbuyIWRVhBc">announces that it has acquired Bombora Technologies Pty Ltd (Bombora)</a>, based in Australia, for AUD $118.5 million, or approximately USD $86.9 million. Bombora and its subsidiaries, which include ARI Registry Services, provide registry services for a number of top-level domains (TLDs) including .au, .melbourne, .sydney, and over 100 new TLDs, including several in the Fortune 500.
</p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/registry_services">Registry Services</a>, <a href="http://www.circleid.com/topics/top_level_domains">Top-Level Domains</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=mKBfLd0ivbA:1T5g3yyqEIc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=mKBfLd0ivbA:1T5g3yyqEIc:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=mKBfLd0ivbA:1T5g3yyqEIc:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=mKBfLd0ivbA:1T5g3yyqEIc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=mKBfLd0ivbA:1T5g3yyqEIc:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=mKBfLd0ivbA:1T5g3yyqEIc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=mKBfLd0ivbA:1T5g3yyqEIc:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=mKBfLd0ivbA:1T5g3yyqEIc:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=mKBfLd0ivbA:1T5g3yyqEIc:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Call for Participation - DNSSEC Workshop at ICANN 54 in Dublin, Irelandtag:circleid.com,2015:blogs/1.90692015-07-31T10:05:00-08:00Dan York<p>Would you like to present an idea you have related to <a href="https://www.internetsociety.org/deploy360/dnssec/">DNSSEC</a> or <a href="https://www.internetsociety.org/deploy360/resources/dane/">DANE</a> to a gathering of people within the DNSSEC community? Do you have an idea for a new tool or service? Have you recently implemented DNSSEC or DANE and want to share your story?
</p>
<p>
If so — and if you will be attending <a href="https://meetings.icann.org/en/dublin54">ICANN 54 in Dublin</a> on October 21 — please send a brief 1-2 sentence proposal to: <a href="mailto:dnssec-dublin@isoc.org">dnssec-dublin@isoc.org</a>
</p>
<p>
The deadline is <strong>Monday, August 17</strong>, so please send your proposal soon!
</p>
<p>
We are open to proposals on a wide range of topics — the full Call for Participation is included below with suggestions to help, but we are also open to proposals on pretty much any topic related to DNSSEC / DANE / DNS security.
</p>
<p>
<span style="display:block;text-align:center;">* * *</span>
</p>
<p>
<span style="display:block;text-align:center;"><strong>Call For Participation</strong></span>
</p>
<p>
The DNSSEC Deployment Initiative and the Internet Society Deploy360 Programme, in cooperation with the ICANN Security and Stability Advisory Committee (SSAC), are planning a DNSSEC Workshop at the ICANN 54 meeting on 21 October in Dublin, Ireland. The DNSSEC Workshop has been a part of ICANN meetings for several years and has provided a forum for both experienced and new people to meet, present and discuss current and future DNSSEC deployments. For reference, the most recent session was held at the ICANN meeting in Buenos Aires, Argentina on 24 June 2015. The presentations and transcripts are available at: <a href="https://buenosaires53.icann.org/en/schedule/wed-dnssec">https://buenosaires53.icann.org/en/schedule/wed-dnssec</a>.
</p>
<p>
At ICANN 54 we are particularly interested in live demonstrations of uses of DNSSEC or DANE. Examples might include:
</p>
<ul><li>Email clients and servers using DNSSEC, OPENPGPKEY, or S/MIME for secure email.</li>
<li>Tools for automating the generation of DNSSEC/DANE records.</li>
<li>Services for monitoring or managing DNSSEC signing or validation.</li>
<li>Tools or services for using DNSSEC/DANE along with other existing protocols and services such as SSH, XMPP, SMTP, S/MIME or PGP/GPG.</li>
<li>Innovative uses of APIs to do something new and different using DNSSEC/DANE.</li>
<li>S/MIME and Microsoft Outlook integration with active directory.</li></ul>
<p>
Our interest is to provide current examples of the state of development and to show real-world examples of how DNSSEC and DANE related innovation can be used to increase the overall security of the Internet.
</p>
<p>
We are open to presentations and demonstrations related to any topic associated with DNSSEC and DANE. Examples of the types of topics we are seeking include:
</p>
<p>
<strong>1. DNSSEC activities in Europe</strong>
</p>
<p>
For this panel we are seeking participation from those who have been involved in DNSSEC deployment in Europe and also from those who have not deployed DNSSEC but who have a keen interest in the challenges and benefits of deployment. In particular, we will consider the following questions: Are you interested in reporting on DNSSEC validation of your ISPs? What can DNSSEC do for you? What doesn't it do? What are the internal tradeoffs to implementing DNSSEC? What did you learn in your deployment of DNSSEC? We are interested in presentations from both people involved with the signing of domains and people involved with the deployment of DNSSEC-validating DNS resolvers.
</p>
<p>
<strong>2. Potential impacts of Root Key Rollover</strong>
</p>
<p>
Given many concerns about the need to do a Root Key Rollover, we would like to bring together a panel of people who can talk about what the potential impacts may be to ISPs, equipment providers and end users, and also what can be done to potentially mitigate those issues. In particular, we are seeking participation from vendors, ISPs, and the community that will be affected by distribution of new root keys. We would like to be able to offer suggestions out of this panel to the wider technical community. If you have a specific concern about the Root Key Rollover, or believe you have a method or solution to help address impacts, we would like to hear from you.
</p>
<p>
<strong>3. Implementing DNSSEC validation at Internet Service Providers (ISPs)</strong>
</p>
<p>
Internet Service Providers (ISPs) play a critical role by enabling DNSSEC validation for the caching DNS resolvers used by their customers. We have now seen massive rollouts of DNSSEC validation within large North American ISPs and at ISPs around the world. We are interested in presentations on topics such as:
</p>
<ul><li>Can you describe your experiences with negative Trust Anchors and operational realities?</li>
<li>What does an ISP need to do to prepare its network for implementing DNSSEC validation?</li>
<li>How does an ISP need to prepare its support staff and technical staff for the rollout of DNSSEC validation?</li>
<li>What measurements are available about the degree of DNSSEC validation currently deployed?</li>
<li>What tools are available to help an ISP deploy DNSSEC validation?</li>
<li>What are the practical server-sizing impacts of enabling DNSSEC validation on ISP DNS Resolvers (ex. cost, memory, CPU, bandwidth, technical support, etc.)?</li></ul>
<p>
<strong>4. The operational realities of running DNSSEC</strong>
</p>
<p>
Now that DNSSEC has become an operational norm for many registries, registrars, and ISPs, what have we learned about how we manage DNSSEC? What is the best practice around key rollovers? How often do you review your disaster recovery procedures? Is there operational familiarity within your customer support teams? What operational statistics have we gathered about DNSSEC? Are there experiences being documented in the form of best practices, or something similar, for transfer of signed zones?
</p>
<p>
<strong>5. DANE and DNSSEC application automation</strong>
</p>
<p>
For DNSSEC to reach massive deployment levels it is clear that a higher level of automation is required than is currently available. There also is strong interest for DANE usage within web transactions as well as for securing email and Voice-over-IP (VoIP). We are seeking presentations on topics such as:
</p>
<ul><li>What tools, systems and services are available to help automate DNSSEC key management?</li>
<li>Can you provide an analysis of current tools/services and identify gaps?</li>
<li>Where are the best opportunities for automation within DNSSEC signing and validation processes?</li>
<li>What are the costs and benefits of different approaches to automation?</li>
<li>What are some of the new and innovative uses of DANE and other DNSSEC applications in new areas or industries?</li>
<li>What tools and services are now available that can support DANE usage?</li>
<li>How soon could DANE and other DNSSEC applications become a deployable reality?</li>
<li>How can the industry use DANE and other DNSSEC applications as a mechanism for creating a more secure Internet?</li></ul>
<p>
We would be particularly interested in any live demonstrations of DNSSEC / DANE application automation and services. For example, a demonstration of the actual process of setting up a site with a certificate stored in a TLSA record that correctly validates would be welcome. Demonstrations of new tools that make the setup of DNSSEC or DANE more automated would also be welcome.
</p>
<p>
<strong>6. When unexpected DNSSEC events occur</strong>
</p>
<p>
What have we learned from some of the operational outages that we have seen over the past 18 months? Are there lessons that we can pass on to those just about to implement DNSSEC? How do you manage dissemination of information about the outage? What have you learned about communications planning? Do you have a route to ISPs and registrars? How do you liaise with your CERT community?
</p>
<p>
<strong>7. DNSSEC and DANE in the enterprise</strong>
</p>
<p>
Enterprises can play a critical role in both providing DNSSEC validation to their internal networks and also through signing of the domains owned by the enterprise. We are seeking presentations from enterprises that have implemented DNSSEC on validation and/or signing processes and can address questions such as:
</p>
<ul><li>What are the benefits to enterprises of rolling out DNSSEC validation? And how do they do so?</li>
<li>What are the challenges to deployment for these organizations and how could DANE and other DNSSEC applications address those challenges?</li>
<li>How should an enterprise best prepare its IT staff and network to implement DNSSEC?</li>
<li>What tools and systems are available to assist enterprises in the deployment of DNSSEC?</li>
<li>How can the DANE protocol be used within an enterprise to bring a higher level of security to transactions using SSL/TLS certificates?</li></ul>
<p>
<strong>8. Hardware Security Modules (HSMs) use cases and innovation</strong>
</p>
<p>
We are interested in demonstrations of HSMs, presentations of HSM-related innovations and real world use cases of HSMs and key management.
</p>
<p>
In addition, we welcome suggestions for additional topics.
</p>
<p>
If you are interested in participating, please send a brief (1-2 sentence) description of your proposed presentation to <a href="mailto:dnssec-dublin@isoc.org">dnssec-dublin@isoc.org</a> by <strong>Monday, 17 August 2015</strong>
</p>
<p>
We hope that you can join us.
</p>
<p>
On behalf of the DNSSEC Workshop Program Committee:
</p>
<p>
Mark Elkins, DNS/ZACR
<br />
Cath Goulding, Nominet UK
<br />
Julie Hedlund, ICANN
<br />
Jean Robert Hountomey, AfricaCERT
<br />
Jacques Latour, .CA
<br />
Xiaodong Lee, CNNIC
<br />
Luciano Minuchin, NIC.AR
<br />
Russ Mundy, Parsons
<br />
Ondřej Surý, CZ.NIC
<br />
Yoshiro Yoneya, JPRS
<br />
Dan York, Internet Society
</p><p><em>Written by <a href="http://www.circleid.com/members/2673/">Dan York</a>, Author and Speaker on Internet technologies</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/dns">DNS</a>, <a href="http://www.circleid.com/topics/dnssec">DNS Security</a>, <a href="http://www.circleid.com/topics/icann">ICANN</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=_6iWaMQSGTI:WOOa7B3looM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=_6iWaMQSGTI:WOOa7B3looM:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=_6iWaMQSGTI:WOOa7B3looM:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=_6iWaMQSGTI:WOOa7B3looM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=_6iWaMQSGTI:WOOa7B3looM:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=_6iWaMQSGTI:WOOa7B3looM:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=_6iWaMQSGTI:WOOa7B3looM:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=_6iWaMQSGTI:WOOa7B3looM:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=_6iWaMQSGTI:WOOa7B3looM:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Internet Society's Contribution to the WSIS+10 Written Consultationtag:circleid.com,2015:blogs/1.90682015-07-31T09:19:00-08:00Constance Bommelaer<p>Today we at the Internet Society submitted our contribution to the United Nations General Assembly's 10-year review of the World Summit on the Information Society <a href="https://www.internetsociety.org/wsis">(WSIS+10)</a> that will take place in New York in December. The goal of this meeting is to set the agenda for the UN - and through that the agendas of nations around the world — with regard to the future of the "Information Society".
</p>
<p>
As one of the organizations involved in the WSIS since its inception, the Internet Society is following the WSIS+10 process closely and participating to the greatest extent possible. In particular, the Internet Society is gathering information and sharing it with its network of 75,000 members, 110 Chapters all over the world and 145 Organization members.
</p>
<blockquote><p>» <strong><a href="https://www.internetsociety.org/doc/internet-society-written-submission-wsis10-non-paper">Read the Internet Society's written contribution to WSIS+10</a></strong><sup>1</sup></p></blockquote>
<p>
2015 is a historic year in UN history. Over the past months, critical negotiations have been converging towards two landmark events: the UN Summit for the adoption of the post-2015 development agenda to be held this September in New York, and the UN General Assembly High-Level Meeting in December on the overall review of the outcomes of <a href="https://www.internetsociety.org/wsis">the WSIS</a>, during which the Assembly will also decide on the future of the <a href="https://www.internetsociety.org/igf">Internet Governance Forum (IGF)</a>.
</p>
<p>
In this broad context, the international community has today <strong>an unprecedented opportunity to seize</strong>. By underscoring <a href="https://www.internetsociety.org/internet-invariants-what-really-matters">the principles that have led to the success of the Internet</a> over the past decade, stakeholders can lay the foundations of tomorrow's Information Society where the Internet can play an even stronger role in supporting economic growth and social progress in all parts of the world.
</p>
<p>
Specifically, <strong>the international community needs to reaffirm the value of a distributed model of governance</strong> where each stakeholder group has its own role and responsibility in the evolution of the Internet — while all converge towards a common goal of enabling an Internet of opportunity for all.
</p>
<p>
WSIS+10 is not only an opportunity to celebrate the progress made over the past years in developing Internet infrastructure and supporting human empowerment, it is also a chance to tackle remaining challenges to bring the Internet to its full development potential. Furthermore, <strong>WSIS+10 can become a historical milestone to build a collective vision for the future of the Information Society</strong>, based on three pillars:
</p>
<ol><li>Collaborative networks for human empowerment and Sustainable Development;</li>
<li>Collaborative security for trustworthy environments; and</li>
<li>Collaborative governance where open frameworks lead to successful discussions.</li></ol>
<p>
<a href="https://www.internetsociety.org/doc/internet-society-written-submission-wsis10-non-paper">In our contribution</a>, we set out this positive vision for the WSIS+10 Review that reflects the progress made since 2005; the challenges still before us to build a truly global Information Society; and the benefits of an open and inclusive dialogue both during and leading up to the High Level WSIS+10 event.
</p>
<p>
We look forward to continuing to participate in the WSIS+10 review and thank the UN General Assembly for opening up the process to more than just governments. <a href="http://www.openwsis2015.org/">Along with over 125 other organizations and individuals</a>, we continue to believe that the best outcome will be achieved through involving all the many different stakeholders who exist in our connected world.
</p>
<p>
<span class="footNotes"><sup>1</sup> NOTE about UN terminology and process: As you will see in the title of our contribution, the UN is assembling a document they call a "Non-Paper" that will be published in August and will serve as the input into the UNGA High-Level Meeting in December. You can <a href="http://unpan3.un.org/wsis10/nonpapersubmissions">view the full list of written submissions to this "Non-Paper"</a> on the UN website and also <a href="http://unpan3.un.org/wsis10/preparatoryprocess">view the steps of the preparatory process</a> for the WSIS+10 Review.</span>
</p>
<p>
<em>This post originally appeared on <a href="https://www.internetsociety.org/blog/public-policy/2015/07/internet-society-isoc-contribution-wsis10-written-consultation">the Internet Society's blog.</a></em>
</p><p><em>Written by <a href="http://www.circleid.com/members/7554/">Constance Bommelaer</a>, Senior Director, Global Internet Policy, Internet Society</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/internet_governance">Internet Governance</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=yF6dCZwcQbo:MgLHjvKd1_4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=yF6dCZwcQbo:MgLHjvKd1_4:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=yF6dCZwcQbo:MgLHjvKd1_4:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=yF6dCZwcQbo:MgLHjvKd1_4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=yF6dCZwcQbo:MgLHjvKd1_4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=yF6dCZwcQbo:MgLHjvKd1_4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=yF6dCZwcQbo:MgLHjvKd1_4:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=yF6dCZwcQbo:MgLHjvKd1_4:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=yF6dCZwcQbo:MgLHjvKd1_4:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>How to Move Cybersecurity Forward in a More Positive Waytag:circleid.com,2015:blogs/1.90652015-07-29T09:49:00-08:00Paul Budde<p>In 2013 I wrote a blog <a href="http://www.circleid.com/posts/20111125_telecoms_as_a_spying_tool/">Telecoms as a spying tool</a>, in which I mentioned that those who use the internet to spy indiscriminately will have to face the reality that such activities will only start a cat-and-mouse game — the technology will always be able to stay one step ahead of those who are using the internet for criminal purposes.
</p>
<p>
Since that time some very significant developments have taken place that have confirmed our prediction.
</p>
<p>
When I wrote that article encryption technologies had already been around for some time, but they were not being used by the majority of internet users. Some websites, particularly those from financial institutions and at least some of the government sites, used encryption technologies, but even at a business level security still had rather low priority. Data breaches that are still hitting the news, show that this continues to be a problem for many of the organisations and people using the internet.
</p>
<p>
Beyond that, encryption was being used by those who wanted to avoid detection, such as criminals and terrorists. However, in reality people who carry out illegal activities often make simple mistakes, and so in many cases those offenders were eventually caught, with or without the assistance of technology. This is still the case — mass surveillance usually contributes little or nothing to the capture of criminals or terrorists. More targeted approaches that have been used over the years, including the use of technology, have delivered far better results.
</p>
<p>
Obviously most people were fully aware that the police and security agencies were using technology to try and catch those criminals and there was little or no outcry about it, as people obviously understood the benefits of having vigilant security services. They trusted that those agencies would use the appropriate warrants to conduct their investigations, or that secret actions were at least overseen by their national parliaments.
</p>
<p>
However, the revelations of Edward Snowden showed that these tools were not only used to catch criminals. They were also used for mass surveillance purposes, and this revelation shocked the entire world. It became clear that very personal information from friendly government leaders was spied upon, and also that computers from companies such as Google were hacked into in order to obtain information on people without any warrant attached.
</p>
<p>
This immediately brought about a chain reaction (as in the cat-and-mouse example). Internet companies do have a legal obligation to protect the integrity of their ICT infrastructure, the security of their data and the privacy of their customers; and so this was a clear wake-up call for them to massively step up their security. If NSA can tap into these networks and services, others with criminal intentions will also find ways to do so. So encryption technologies were used, this time to introduce a far more general level of protection both at national government levels and in relation to consumer-based services from Google, Facebook and others. Furthermore massive amounts of money were pumped into this market to create even better encryption solutions.
</p>
<p>
With this explosion in encryption, consumer devices, having data in them, are now also being encrypted. The reality is that encryption is rapidly becoming the norm.
</p>
<p>
In this cat-and-mouse game law enforcement agencies are complaining that the techniques they used before are not working as well as they did in the past — in fact, for them it is only getting worse. We are already hearing political murmurings, in the UK and Australia for example, that encryption technologies should be banned. This is a clear indication that those politicians have very little idea about technological developments — that they are largely unaware that encryption has already become a very critical part of internet services. Banning encryption is not only counter-productive in an economic sense; it is also too late, since large amounts of information have already been encrypted over the last two years.
</p>
<p>
The encryption explosion has other impacts too. The cellular networks that used to use deep packet inspection (DPI) to do traffic management are now unable to manage traffic in the same way. Microwave links that use compression to increase capacity are no longer able to carry the same amount of traffic. Content filters and firewalls that used to be used to control access to information are unable to perform these functions anymore without explicit intervention by the client to load compromised security certificates, etc.
</p>
<p>
However these technical issues will no doubt be resolved over time.
</p>
<p>
Nevertheless the whole spying affair has totally backfired on those spy agencies that used these tools in 'illegal' ways, and as a consequence the whole web is going dark. It is predicted that by the end of the year the majority of US internet will be encrypted, and even email traffic is now being encrypted on a broad basis.
</p>
<p>
So within a few short years the internet world has changed. So what needs to be done in order to assist police and security agencies in doing their job? Law enforcement agencies still of course have the ability to investigate websites and to get content with warrants. But the reality is that this is becoming a much harder task and will take many more resources than it used to. Governments are trying to insist on access to key materials to allow them to decrypt data in flight as they did before. But this is a very hard thing to enforce without creating holes in the internet and the networking economy that can be exploited by others as well. The internet has become far too important in an economic sense to allow for undermining the communication security of everyone simply in order to enhance the ability to intercept traffic. And it is also Snowden that reminded us that the government can't keep secrets that well either.
</p>
<p>
There is no good solution here, only tradeoffs. The risk to security by trying to embed holes for law enforcement is unwise and unworkable. This is an international problem and needs international cooperation — and how will it be possible to get all of the countries to play along? If the certification authorities are deliberately compromised in the cat-and-mouse game new ones will simply spring up that will create an alternate system, maybe run by companies in countries that are less democratic and have even less oversight.
</p>
<p>
On the other side, technology companies have developed tools to detect network compromises, and it will be more difficult (but of course not impossible) for criminals and terrorists to exploit these holes than it used to be.
</p>
<p>
Totally predictable within a complex, dynamic technological environment, the natural result of government overreach in this spying affair, is the encryption explosion — especially as it has become clear that adequate supervision is not being applied. The draconian political reaction that we see in the 'Five Eyes' countries clearly shows that some of these lessons have not been internalised by policymakers. In other less democratic countries this might also be the case but we obviously hear very little about that from them.
</p>
<p>
Technology usually doesn't operate with the degrees of freedom that policymakers want, and engineers are almost always faster than policymakers in adapting to new rules and laws. It's a losing battle to try and contain that technology.
</p>
<p>
What this means is that there is a need for governments to be more open and transparent, and to work with the industry in a legitimate way to address some of the problems we all face (terrorism, cybercrime, child pornography, and so on). Governments who are simply playing the cat-and-mouse game are not likely to achieve outcomes that benefit both their people and the institutions that are needed to keep us safe.
</p><p><em>Written by <a href="http://www.circleid.com/members/3749/">Paul Budde</a>, Managing Director of Paul Budde Communication</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/policy_regulation">Policy & Regulation</a>, <a href="http://www.circleid.com/topics/privacy">Privacy</a>, <a href="http://www.circleid.com/topics/security">Security</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=lAdHwuEqdnY:z5CxU3y8Uz8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=lAdHwuEqdnY:z5CxU3y8Uz8:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=lAdHwuEqdnY:z5CxU3y8Uz8:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=lAdHwuEqdnY:z5CxU3y8Uz8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=lAdHwuEqdnY:z5CxU3y8Uz8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=lAdHwuEqdnY:z5CxU3y8Uz8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=lAdHwuEqdnY:z5CxU3y8Uz8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=lAdHwuEqdnY:z5CxU3y8Uz8:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=lAdHwuEqdnY:z5CxU3y8Uz8:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Out of .Africa - Process Failures Don't Change the Factstag:circleid.com,2015:blogs/1.90632015-07-28T20:28:00-08:00Sophia Bekele<p><strong><em>Posted here on behalf of DotConnectAfrica Trust as rejoinder and reply to Andrew Mark's recent article.</em></strong>
</p>
<p>
The attention of DotConnectAfrica Trust has been drawn to a recent Blog article by Mr. Andrew Mark that was published in CircleID (<em>see</em> <a href="http://www.circleid.com/posts/20150724_out_of_dot_africa_process_failures_dont_change_the_facts/">Out of .Africa - Process Failures Don't Change the Facts</a>).
</p>
<p>
In his article, Mr. Mark tried to re-frame the ongoing discussions and commentary about DCA Trust's recent IRP victory against ICANN as one about <em>"requisite support for geographic string"</em> to assist him reach the biased conclusion that ZACR's bid has the required support to run .Africa whilst DCA Trust's bid does not.
</p>
<p>
In the same tendentious Blog posting, Mr. Mark agrees that the process was indeed flawed and replete with procedural errors; that DCA may have been treated unfairly; the ICANN GAC may have 'over-reached' or been vague in its advice to the Board — but still went on to argue that the Geographic Panel should have disqualified DCA long ago.
</p>
<p>
Before addressing Mr. Mack's presumptuous <em>'enlightened self-interest'</em> in .Africa, we would like to begin by exposing some of the outright fallacies and illogicalities in Andrew Mark's Blog article.
</p>
<p>
<strong>1. The first is the assertion that "the ZACR bid had Letters of Support from literally dozens of African countries"</strong>
</p>
<p>
Nothing could be farther from the truth. ZACR never received any letters of support from any African country government in support of its bid. Any such claims that ZACR had dozens of letters of support are indeed specious.
</p>
<p>
What DotConnectAfrica Trust established long ago is that the African countries through their ccTLD operators and ICT Ministries had provided letters in support of the "African Union Commission's position" on .Africa — which was to request ICANN to approve the inclusion of .Africa in the Top-Level Reserved Names List — so as to enable the AUC benefit from a special legislative protection that would allow the AUC to delegate .Africa to a structure that the AUC would identify and select (appoint) outside the ICANN new gTLD program. This request was submitted as part of the 'African Agenda' to ICANN in October 2011 during the ICANN International Meeting in Dakar, Senegal. DCA Trust had <a href="http://archive.constantcontact.com/fs053/1102516344150/archive/1108602153904.html">successfully campaigned publicly</a> to oppose the request that was made for the reservation of the .Africa name, which caused ICANN to reject the AUC request; but advised AUC instead to use the Community Objection route and or GAC Policy Advice to influence the delegation outcome of .Africa (<em>please see</em> <a href="https://www.icann.org/en/system/files/correspondence/crocker-to-ibrahim-08mar12-en.pdf">letter by Crocker of ICANN to Ibrahim of the AUC, 8th March 2012</a>).
</p>
<p>
Some of the African countries had actually provided such letters that were written to support the <em>"AUC position"</em>, which ZACR then fraudulently appropriated as its own letters of endorsement for .Africa. There is a big difference between letters that are written to support the AUC's request to have the .Africa name reserved, and letters that would have been ordinarily written by African countries to ICANN to specifically endorse ZACR's application for .Africa. The letter written by Namibia is a good example of such letters that had been written in support of the AUC's position on .Africa. These countries never endorsed ZACR. Providing support — whether valid or not - for the .Africa name to be reserved outside ICANN new gTLD policy guidelines is not an endorsement for a geographic name string as stipulated under the new gTLD Program. Therefore, Mr. Andrew Mack did not tell the truth when he wrote that ZACR received letters of support from literally dozens of African countries.
</p>
<p>
DCA Trust had discovered this falsehood that was being regularly peddled since early 2012 which caused DCA Trust to bring the issue to the attention of ICANN by <a href="http://tandaabiashara.com/more-irregularities-and-misrepresentations-of-africa-endorsements-from-african-governments-noisiest-battle-of-all-gtlds/">highlighting the Namibian letter as a good illustration</a>.
</p>
<p>
Notwithstanding, it was also established during the DCA vs. ICANN IRP that ZACR lacked any letters of endorsement. This explains why ICANN staff were implicated in helping to 'ghost-write' another letter of endorsement for the AUC which was later re-submitted to ICANN to enable ZACR's application to 'pass' the Geographic Names Panel evaluation. It is already <a href="http://www.theregister.co.uk/2015/07/24/icann_dot_africa/?page=1">common knowledge</a> that the details of such irregularities were redacted from the Final IRP Declaration by ICANN staff.
</p>
<p>
It is therefore quite disingenuous of Mr. Andrew Mack to make the 'tongue-in-cheek' remark that "I've heard a lot of discussion of the .africa controversy of late — from conspiracy theories to questions about staff competence".
</p>
<p>
If ZACR actually had 'dozens of letters of support' as Mr. Andrew Mack has falsely claimed, then this issue of 'ghost-writing' of a letter of endorsement by ICANN staff for the AUC apparently for the benefit of ZACR would not have arisen during the DCA vs. ICANN IRP.
</p>
<p>
<strong>2. As an individual, Mr. Andrew Mack seems ethically challenged...</strong>
</p>
<p>
In his write-up, Mr. Mack agrees that DCA Trust was treated unfairly, yet advanced the view that DCA Trust should have been disqualified long ago by the Geographic Names Panel. Andrew Mack is probably not aware that unfair and discriminatory treatment needs to be thoroughly redressed for the interest of justice, equity and fairness.
</p>
<p>
Since something should be done regarding this abysmal level of ignorance and short-coming, Mr. Andrew Mack should perhaps be sentenced to undergo a 6-month course in 'Ethics' and another 3-month course in 'Critical Reasoning' in order to help complete his education.
</p>
<p>
<strong>3. Mr. Andrew Mack is deeply confused regarding what the DCA vs. ICANN IRP was about</strong>
</p>
<p>
It is quite obvious that Mr. Andrew Mack does not logically understand that if a process was flawed and irregular, the outcome would be absolutely dubious, will not stand to scrutiny, and cannot be vouched for. Nevertheless, amidst all these short-comings and irregularities, Mr. Andrew Mack still advances the notion that "we should move on" by sweeping all these wrongdoings under the carpet. Where is Accountability? Where is Transparency? Where is Probity?
</p>
<p>
We find it rather troubling that at a time that the Global Internet Community remains seriously concerned and challenged about ICANN's accountability improvements; and as such concerns have also become inextricably tied to the process of transitioning the IANA technical functions to the Global Multi-stakeholder Community; that wholesale accountability problems that have been uncovered by the DCA vs. ICANN IRP are now being made to look inconsequential by an ethically-challenged 'self-styled pundit'.
</p>
<p>
Apparent contradictions notwithstanding, we think that Andrew Mack was intellectually dishonest in his analysis. On one hand Andrew Mack thinks that 'ICANN needs more accountability', but his established bias against DCA Trust also makes him to think that 'ICANN's policy should be followed'. At what stage did Andrew Mack forget that DCA's decision to invoke an IRP under ICANN's accountability mechanism was because ICANN failed to follow its set policy as stated in the new gTLD Guidebook; and the principles enshrined in ICANN's Bylaws and Articles of Incorporation?
</p>
<p>
Again, Andrew Mack also posited that the biggest procedural error lies in "ICANN's simple inability to follow its own policy", and forgot that it was for this very reason, amongst others, that caused ICANN to lose the DCA vs. ICANN IRP, when the Panel ruled that ICANN broke its Bylaws and Articles of Incorporation, thereby making DotConnectAfrica Trust the prevailing party.
</p>
<p>
With these types of half-baked opinions, one wonders what type of advice Andrew Mack gives to his clients as the 'principal' of AMGlobal Consulting, a company that works "extensively in Africa".
</p>
<p>
<strong>4. Conclusion</strong>
</p>
<p>
DCA Trust believes that the only end to this controversy is not to "move on" as Andrew Mack has counseled so naively, but for further investigations to be conducted to identify the real culprits who were complicit in this fiasco, and for such individuals to be held accountable. We think that wrong-doing must be punished, and there should be severe penalties for ICANN as the guilty party in the recently decided IRP.
</p>
<p>
Moreover, it is also our firm belief that ZACR — as the apparent beneficiary of ICANN's wrong-doing — should be removed completely from the new gTLD Program. ICANN could not have legitimately delegated the .Africa new gTLD string to ZACR at the same time that ICANN was busy breaking its own Bylaws and Articles of Incorporation. The delegation of .Africa to ZACR under a putative new gTLD Registry Agreement that was signed between ICANN and ZACR at a time that ICANN was committing many violations remains legally problematic.
</p>
<p>
On a day that President Barack Obama told a gathering at the African Union Commission headquarters in Addis Ababa, Ethiopia that Africa should put an end to "the cancer of corruption", is it not poetic justice of some sort that .Africa, a new gTLD string that Is associated with the continent that is frequently criticized for poor governance and corruption, is now being used as a test case for demonstrating ICANN's accountability failures?
</p>
<p>
DCA Trust has always maintained that it is acting based on strong moral convictions, and that truth and justice will ultimately prevail whilst its detractors will encounter failure at their sentinel. These predications have all come to pass, and this possibly explains the level of frustration that Mr. Andrew Mack and his cohort are now feeling in the matter of .Africa new gTLD.
</p>
<p>
Andrew Mack tried to suggest <a href="http://www.circleid.com/posts/20121024_icann_africa_strategy_is_not_the_same_as_the_african_agenda/">in a 2012 posting</a> that the DotAfrica application somehow has something to do with the ICANN Africa Strategy. In his article he stated inter alia: "You could also see it in the tremendous enthusiasm for the AUC-endorsed dotAfrica (.africa) application, which has become a real a (sic) focal point of an emerging "African Agenda".
</p>
<p>
To Andrew Mack's chagrin, the African Agenda was never accepted by ICANN, and the same excessive amounts of political and vested group pressures that had been put on ICANN to present the .Africa new gTLD name string as a 'commitment gift' to the African Internet community is what ultimately led to ICANN's accountability failures regarding .Africa.
</p>
<p>
Andrew Mack's advocacy on behalf of ZACR can now be dismissed as partisan posturing by another one of those bogus pretenders who claim to 'know Africa' very well: "I spoke at the DNS Africa event in Nairobi; I can confirm that there is interest in .Africa, blah blah blah...!"
</p><p><em>Written by <a href="http://www.circleid.com/members/5906/">Sophia Bekele</a>, CEO of DotConnectAfrica</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/icann">ICANN</a>, <a href="http://www.circleid.com/topics/internet_governance">Internet Governance</a>, <a href="http://www.circleid.com/topics/policy_regulation">Policy & Regulation</a>, <a href="http://www.circleid.com/topics/top_level_domains">Top-Level Domains</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=HTW7iegONkY:GOZqq1otYdI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=HTW7iegONkY:GOZqq1otYdI:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=HTW7iegONkY:GOZqq1otYdI:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=HTW7iegONkY:GOZqq1otYdI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=HTW7iegONkY:GOZqq1otYdI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=HTW7iegONkY:GOZqq1otYdI:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=HTW7iegONkY:GOZqq1otYdI:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=HTW7iegONkY:GOZqq1otYdI:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=HTW7iegONkY:GOZqq1otYdI:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Navigating the .brand Delegation Processtag:circleid.com,2015:blogs/1.90642015-07-28T20:03:00-08:00Corey Grant<p><em>This is the second post in a series from Corey Grant, Senior Industry Consultant at ARI Registry Services, about how .brand TLDs can get started and make the most of their TLDs.</em>
</p>
<p>
Today marks a major milestone for .brand Top-Level Domain applicants, as we pass the deadline set by ICANN for them to sign their Registry Agreement (RA).
</p>
<p>
For those who have knuckled down over the last few weeks and months to meet this deadline, congratulations — for many, this was no mean feat and the effort should be acknowledged.
</p>
<p>
At the same time, organisations that have reached this point need to remember that putting pen to paper is the first step of many; in order to get your TLD to a stage where it can be used, there is a process that now begins that can be complex, at best.
</p>
<p>
So what's involved in getting a TLD delegated — and how long will it reasonably be before brands can start using their new TLDs?
</p>
<p>
<strong>The path from RA signing to delegation</strong>
</p>
<p>
At ARI, we were the first Registry to navigate the complex path to TLD delegation, when we launched شبكة. ('web' in Arabic and pronounced "dot shabaka") in October 2013 as the world's first new TLD.
</p>
<p>
In many respects, we were helping write the delegation process for all applicants as شبكة. traversed the process. In fact, our progress was recorded through a journal on <a href="http://domainincite.com/14044-dotshabaka-diary-day-1">Domain Incite</a> which allowed other TLD applicants to learn from our experiences.
</p>
<p>
Since then we've spent almost two years gaining more experience and partnering with other Registry Operators to help them through the delegation process. Based on our experiences as a Registry Services Provider over the last few years, we've drawn up a timeline of the typical delegation process as a guide, which you can view below.
</p>
<p>
No matter what your plans are for your .brand TLD, it makes sense to move through the delegation process as efficiently as possible. That way you will have the ability to use your TLD, whether you currently plan to or not. Plans change, and I've seen clients have commercial opportunities to use the TLD at short notice, but were unable to because they did not prioritise moving through stages of the delegation process.
</p>
<p>
In the table below, the 'typical timeframe' we've estimated is based on our own client experiences. The process can sound complicated, but your Registry Services Provider should assist you in moving through these requirements and be able to execute steps such as pre-delegation testing and delegation on your behalf.
</p>
<p>
Also bear in mind that ICANN will now have a significant workload to manage, with approximately 170 .brand TLDs likely to begin the delegation process following today's deadline. Given this, there is the possibility of a backlog being created that could cause further delays for some applicants.
</p>
<p>
Delegation is only one part of the process. Running parallel to the delegation timeline is another, arguably more daunting timeline for the commercial steps that must be considered to get a TLD ready for operation.
</p>
<p>
While time pressure means the delegation process is the most urgent step right now, once this is set in motion it should proceed with little effort required. For .brand TLD owners, the bigger focus should be on beginning the commercial steps to launching and using your .brand TLD such as stakeholder engagement and developing an implementation plan — elements of which I'll examine further in the coming weeks.
</p>
<p>
<a href="http://www.circleid.com/images/uploads/9064.jpg"><img src="http://www.circleid.com/images/uploads/9064.jpg" border="0" style="display:block;width:644px;padding-bottom:20px;" /></a>
</p><p><em>Written by <a href="http://www.circleid.com/members/7569/">Corey Grant</a>, Senior Industry Consultant at ARI Registry Services</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/icann">ICANN</a>, <a href="http://www.circleid.com/topics/top_level_domains">Top-Level Domains</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=AAt1wkFlNq0:tS-URNO6GvY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=AAt1wkFlNq0:tS-URNO6GvY:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=AAt1wkFlNq0:tS-URNO6GvY:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=AAt1wkFlNq0:tS-URNO6GvY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=AAt1wkFlNq0:tS-URNO6GvY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=AAt1wkFlNq0:tS-URNO6GvY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=AAt1wkFlNq0:tS-URNO6GvY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=AAt1wkFlNq0:tS-URNO6GvY:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=AAt1wkFlNq0:tS-URNO6GvY:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>5th ITAC OECD Newsletter: Internet Governance, WSIS+10, IoT, Cybersecurity, Trust, Standards…tag:circleid.com,2015:blogs/1.90622015-07-28T18:56:00-08:00Dan York<p>Today the <a href="http://www.internetac.org/">Internet Technical Advisory Committee (ITAC)</a> to the OECD published the fifth edition of its newsletter at:
</p>
<p>
<a href="http://www.internetac.org/archives/category/newsletter">http://www.internetac.org/archives/category/newsletter</a>
</p>
<p>
The <a href="http://www.internetac.org/">ITAC</a> was created in 2009 following the OECD's Seoul Ministerial with the objective to provide Internet technical and policy expertise to the work of the OECD on Internet-related issues. This informal group is coordinated by the Internet Society and currently counts 28 members active in domains such as open Internet/Web standards development, interconnection, IP addressing, security or privacy.
</p>
<p>
The goal of the ITAC newsletter is to provide concrete illustrations and practices of the evolving multistakeholder model of Internet policy development, and to create opportunities for new partnerships. The publication of this fifth newsletter was coordinated by my colleagues Constance Bommelaer and Nicolas Siedler and includes these articles:
</p>
<ul><li><strong>Editorial: On the road to Mexico 2016 </strong>(from Internet Society)</li>
<li><strong>Interview of Ambassador Dionisio Pérez-Jácome Frisione, Mexico's Permanent Representative to the OECD</strong></li>
<li><strong>New Internet (and IoT) Era and the Protection of Economic and Social Activities</strong> (from IEEE)</li>
<li><strong>Consent as a critical component for Trust in the Growth of the Digital Economy</strong> (from Kantara Initiative)</li>
<li><strong>Investigating Whether Internet Paths Stay Within Borders</strong> (from RIPE NCC)</li>
<li><strong>United we stand: Protecting against cyber threats with standards for sharing</strong> (from OASIS)</li></ul>
<p>
ITAC provides an avenue for new technical insights to contribute to the work of the OECD. ITAC is open to any Internet technical and research organization that meets the membership criteria listed in the Committee's Charter.
</p>
<p>
ITAC encourages Policymakers, members of Civil Society and Businesses to submit queries regarding any of the ITAC work to Questions@internetac.org
</p>
<p>
If your organization is interested in joining ITAC and contributing with technically-informed advice to the OECD's development of Internet-related policies, you can visit the website, <a href="http://www.internetac.org">http://www.internetac.org</a>, to read the "Criteria for Membership" in ITAC's Charter (Section III).
</p><p><em>Written by <a href="http://www.circleid.com/members/2673/">Dan York</a>, Author and Speaker on Internet technologies</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/internet_governance">Internet Governance</a>, <a href="http://www.circleid.com/topics/policy_regulation">Policy & Regulation</a>, <a href="http://www.circleid.com/topics/security">Security</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=Y-UE3a2pAc8:x7v9Qr9oa9Q:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=Y-UE3a2pAc8:x7v9Qr9oa9Q:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=Y-UE3a2pAc8:x7v9Qr9oa9Q:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=Y-UE3a2pAc8:x7v9Qr9oa9Q:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=Y-UE3a2pAc8:x7v9Qr9oa9Q:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=Y-UE3a2pAc8:x7v9Qr9oa9Q:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=Y-UE3a2pAc8:x7v9Qr9oa9Q:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=Y-UE3a2pAc8:x7v9Qr9oa9Q:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=Y-UE3a2pAc8:x7v9Qr9oa9Q:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Should You Whitelist Your Vulnerability Scanning Service Provider?tag:circleid.com,2015:blogs/1.90612015-07-28T12:34:00-08:00Gunter Ollmann<p>Unlike consultant-led penetration testing, periodic or continual vulnerability scanning programs have to operate harmoniously with a corporation's perimeter defenses.
</p>
<p>
Firewalls, intrusion prevention systems, web proxies, dynamic malware analysis systems, and even content delivery networks, are deployed to protect against the continuous probes and exploit attempts of remote adversaries — yet they need to ignore (or at least not escalate) similar probes and tests being launched by the managed security service providers an organization has employed to identify and alert upon any new vulnerabilities within the infrastructure or applications that are to be protected.
</p>
<p>
Just the other week I was asked by a prospect whether they should whitelist the IP addresses of the systems tasked with continually scanning their Internet accessible servers and web applications, or should they let those scanners be subject to the same defenses and blocking as any other "attacks"?
</p>
<p>
The simple answer is "Yes — whitelist the source IP addresses and let those scanners uncover all the infrastructure and application flaws they can". The more verbose answer to the question requires a greater understanding of how both vulnerability scanners and perimeter defenses are developed and what they're really capable of bringing to the table.
</p>
<p>
<strong>What is the purpose of continual vulnerability scanning?</strong>
</p>
<p>
The primary purpose of continual vulnerability scanning is to quickly identify and alert on any new vulnerabilities uncovered in Internet accessible systems. The scanning isn't meant to replicate how an attacker would uncover or exploit systems — that's what penetration tests are for (and why you should also conduct them regularly). Consequently, "defending" against your managed security service providers scans — while it may be pleasant to have reports or management portals with no findings and a clear status — is not only a poor security choice, but most likely to be money down the drain.
</p>
<p>
Arguably the most important perimeter defense system in common use today are intrusion prevention systems (IPS). Firewalls or any of the "next generation" prefixed versions of firewalls are a close second — but I'd happily argue that current generation IPS encapsulate all the security capabilities of firewalls already. As such, let me use IPS as an example of how scanning and perimeter defenses operate in a contradictory yet harmonious way… from the perspective of someone who spent several years being responsible for the R&D of both IPS and vulnerability scanning technologies at multiple companies.
</p>
<p>
Every IPS sales person and vendor will tell you that their IPS appliance, software, or cloud service, is designed to stop all attacks. "All" is clearly an optimistic statement, yet IPS technologies are pretty reliable at detecting vulnerability scanners, out-of-the-box commercial exploit products, and non-obfuscated exploit techniques. For specific classes of threats or well documented networking protocols, IPS can and do often offer basic zero-day exploit detection on occasion (which will be clearly documented and time-lined in any PowerPoint presentation the vendor sales team can hope to get in front of you). In many cases you'll also hear the term "virtual patch" being used; i.e. the vendor has a detection signature or algorithm that will block "all" exploit vectors for a particular vulnerability, giving the organization time to roll out the real software patch to all physical servers.
</p>
<p>
<strong>If that's how IPS are supposed to work, what's the contradictory story?</strong>
</p>
<p>
IPS are designed to protect network-based attacks, vulnerability scanners are designed to identify vulnerabilities, and scanning vendors have gone out of their way to ensure that the methods they use to reliably detect a vulnerability does not contain exploit material or leave a targeted system or service in an unusable state. Therefore, by that very definition, the scans launched by a vulnerability scanner are neither exploits nor attacks, and any IPS raising an attack alert must be a false positive.
</p>
<p>
From an IPS vendor's perspective, they're damned if they do and damned if they don't. At some point in time every organization with a deployed IPS will run a vulnerability scanner against the systems it's supposed to protect. If the scanner finds any vulnerabilities, the organization will chastise the vendor for not "protecting" against the scan — whether or not they successfully argue the difference between a vulnerability test and an exploitation of a vulnerability. As such, every commercial IPS vendor buys every other commercial vulnerability scanner and runs them repeatedly against their IPS products — adding new signatures or alerts for pretty-much every test those scanners can run. If you have deployed IPS systems to protect your organization and a vulnerability scanner has identified vulnerabilities in the infrastructure it's supposed to be protecting, then there's a highly probably your fault (i.e. someone has misconfigured your IPS or hasn't turned on the relevant alerting functions).
</p>
<p>
In that context, if you've subscribed to a continual vulnerability scanning service and have deployed appropriate perimeter defenses, the vulnerability scanners should not find any vulnerabilities. Unfortunately, not finding vulnerabilities is not nearly the same as not having exploitable vulnerabilities.
</p>
<p>
<strong>Traditional perimeter defenses</strong>
</p>
<p>
Traditional perimeter defenses are good at finding the "known knowns", yet struggle or fail with "unknown knowns" and customized exploits. While an IPS may be good enough to detect and block a vulnerability scanners test of a "protected" vulnerability, too often it will not prevail and instead be circumvented with a customized or non-generic versions of an exploit; which incidentally is getting easier and easier for attackers to do
</p>
<p>
Finally, this leads me to the "harmonious" part of the story…
</p>
<p>
By whitelisting the source IP addresses of the managed security services continually scanning web applications and infrastructure, an organization can observe the true state of their Internet accessible services and work on mitigating the underlying threat — while employing IPS and other perimeter defenses to buffer in-bound attacks and enumerating the source of real attackers.
</p>
<p>
If that symbiotic harmonization between IPS and vulnerability scanning isn't enough, then I'll leave you with one last reason why blocking legitimate vulnerability scanning is unlikely to be in your organizations best interest — HTTPS. In almost all cases encrypted network traffic will pass uninspected by an organizations perimeter defenses. If your web application provides services over HTTPS any attacks against the application over HTTPS will be undetectable by your network-based (and likely host-based) IPS. So, let those vulnerability scanners do their work for you and identify the vulnerabilities you need to fix.
</p><p><em>Written by <a href="http://www.circleid.com/members/5583/">Gunter Ollmann</a>, CTO at NCC Group Domain Services</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/cyberattack">Cyberattack</a>, <a href="http://www.circleid.com/topics/malware">Malware</a>, <a href="http://www.circleid.com/topics/security">Security</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=7xpWY5E2oC8:GVBDZ5cfCeM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7xpWY5E2oC8:GVBDZ5cfCeM:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=7xpWY5E2oC8:GVBDZ5cfCeM:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7xpWY5E2oC8:GVBDZ5cfCeM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=7xpWY5E2oC8:GVBDZ5cfCeM:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7xpWY5E2oC8:GVBDZ5cfCeM:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7xpWY5E2oC8:GVBDZ5cfCeM:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=7xpWY5E2oC8:GVBDZ5cfCeM:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=7xpWY5E2oC8:GVBDZ5cfCeM:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>Independent Show 2015: Out-of-the-Box Lessons in the Digital Agetag:circleid.com,2015:blogs/1.90602015-07-28T11:54:00-08:00Ladi Astrab<p>This year's Independent Show summer conference was held in Boston, a place where the accents are strong and you hear great quotes like:
</p>
<p>
<em>"Hey Norm, how is the world treating you?"</em>
</p>
<p>
<em>"Like a baby treats a diaper. Now start pouring."</em>
</p>
<p>
Boston is one of my favorite cities on the East Coast. Intercity transport is made easy by having both a subway and a Hubway, and of course cabbies are everywhere and are always strong on conversation.
</p>
<p>
If I had to sum up this year's conference with one phrase, it would have to be: <em>out-of-the-box thinking</em>.
</p>
<p>
The keynote speech was given by Professor Bharat Anand of the Harvard School of Business, whose expertise is in the areas of digital strategy, corporate strategy, and media strategy — in other words, digital marketing. The title was "Lessons from the Digital Transformation of Media". Professor Anand believes that MSOs need to move from a product-centric to a consumer-centric way of thinking. The state of TV in 2015, as well as increasing competition from both broadcast and consumption, is interestingly enough at the same state it was in back in 1986. He states that the winning strategy is to answer two fundamental questions: "Where do you play?", and "How do you win?"
</p>
<p>
Anand urged the audience to think about products and services in terms of substitutes and complements. Substitute products are anything with the availability of a substitute that decreases the value of the product. Complement products are anything with the availability of a complement that increases value of the product. A customer will value your product more if s/he has the complementary product, rather than having just your product alone. If the price decreases with the complement, that will make your product more attractive.
</p>
<p>
It's important not to look at the obvious, but think of the opportunity. For example, you would think that a substitute to power tools would be a handyman or duct tape, but actually, it is a dress tie. On Father's Day, these two objects (power tools and shirt ties) are in direct competition as substitutes, but if you combine socks with the shirt tie, then you have a complement and possibly a more compelling reason to choose one over the other. Other examples of complements are: hot dogs and ketchup, cars and roads, tires and restaurant guides, hardware and software, and 'Piracy' and Silicon Valley.
</p>
<p>
Another point that Professor Anand emphasized was user connections as strategy, which is very persuasive in digital markets. It has the power to overwhelm product quality with small changes that have huge impacts on a business. It is noted that user connection is under business control, and requires an understanding of user behaviors.
</p>
<p>
Tying it all together as I sat watching and listening, I thought about a very interesting presentation from Sony Playstation and their product VUE, which provides TV content via Sony Playstation 4. Here is a thought from a complement perspective: MSOs can bundle the PS4 with an Internet and VUE package to target gamers. Sony Playstation folks mentioned that MSOs could be used as distribution points for the Sony Playstation 4/VUE. This would increase an MSO's subscriber base, as well as its points of transport to make customers more sticky.
</p>
<p>
This brings me to the final point from the presentation: network effects are persuasive, or in other words, bring a "mob mentality" or the "Jones effect". If the Smith family has the Gamer's Package, the Jones family will want it too.
</p>
<p>
I must say, leaving that presentation made me feel smarter.
</p>
<p>
I also attended a very enlightening presentation given by well-known Wall Street analyst Craig Moffett, titled <em>Cable: Next 10 Years</em>. Moffett started his presentation by looking at cable over the last 10 years with three tenets:
</p>
<ol><li>Telcos have not overbuilt cable with fiber on a large scale, and cable is still the dominate terrestrial infrastructure</li>
<li>Wireless is not an economically viable substitute to wired broadband</li>
<li>Usage-based pricing and the notion of transport charges have swept the industry</li></ol>
<p>
Next on Moffett's agenda were the next 10 years. Cord-cutting is finally accelerating, and growth is down for pay-TV. Moffett says new conditions are coming in the future:
</p>
<ol><li>Live TV watching rates will continue to drop</li>
<li>Cable share gain will be moderated as satellite share gain is halted</li>
<li>Broadband will approach saturation, with the only segments left outside being the over-65-year-olds or computer illiterate</li></ol>
<p>
Broadband pricing is the last lever to pull, but the pricing power risk is attracting regulatory attention. Now, regulation is the central issue and is like threading a needle, as many important questions are left unanswered:
</p>
<ol><li>How fast will bundles unwind?</li>
<li>Do commercial prospects offer enough growth to reduce the needs of price hikes?</li>
<li>Where will wireless fit in?</li>
<li>How much consolidation will be allowed? And with whom?</li>
<li>If home automation/security is a viable business, will it be a profitable business in terms of software or hardware?</li></ol>
<p>
Some businesses may not be big enough to move the needle.
</p>
<p>
In conclusion, I came out of this conference feeling a little smarter and will be adding some of these new thought processes into my own strategies. The experts all seem to agree that the cable space is still a good place to invest in.
</p><p><em>Written by <a href="http://www.circleid.com/members/7647/">Ladi Astrab</a>, Pre-Sales Director at Incognito Software Systems</em></p><p><strong>Follow CircleID on <a href="http://twitter.com/circleid">Twitter</a></strong></p><p><strong>More under:</strong> <a href="http://www.circleid.com/topics/broadband">Broadband</a>, <a href="http://www.circleid.com/topics/telecom">Telecom</a></p><div class="feedflare">
<a href="http://feeds.circleid.com/~ff/cid_master?a=yKR-0qCxtQc:CJTGgD-R86s:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=yKR-0qCxtQc:CJTGgD-R86s:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/cid_master?i=yKR-0qCxtQc:CJTGgD-R86s:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=yKR-0qCxtQc:CJTGgD-R86s:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/cid_master?i=yKR-0qCxtQc:CJTGgD-R86s:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=yKR-0qCxtQc:CJTGgD-R86s:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=yKR-0qCxtQc:CJTGgD-R86s:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/cid_master?i=yKR-0qCxtQc:CJTGgD-R86s:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.circleid.com/~ff/cid_master?a=yKR-0qCxtQc:CJTGgD-R86s:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"></img></a>
</div>