3 ms·
Another example is the case of US ICE seizing domains quite dubiously. This brings me to another example of how the seizure of domains for law enforcement purpo
by dijhrykl 9y ago
Another example is the case of US ICE seizing domains quite dubiously. This brings me to another example of how the seizure of domains for law enforcement purposes related only to services provided by hosts referenced by the zone files served by nameservers referenced by those domains is almost necessarily disproportionate: when one seizes a domain one assumes control of all records served by it, including MX records. As such, when one seizes a domain, one takes control not just of any websites served via it, but any email service for it as well. (For this reason in particular, thinking of domain names as fundamentally website-centric is hazardous to the future political integrity of the domain name system. Domain names are not websites.) As such when ICE seizes a domain, they also are implicitly assuming the right to redirect all incoming email to that domain to them (not even intercept but forward, e.g. with a warrant, but redirect outright). In fact, I'm not sure if this would even be illegal; if you've obtained a domain legally, you can configure it as you wish.
If someone claims a domain of mine, example.com, has a website facilitating illegal activity, and has it seized by some jurisdiction's law, what if my principal email address is @example.com? Now I am deprived of the ability to engage in correspondance so as to ascertain the grounds for such seizure and contest it. The intention was to disable the website, yet email service and potentially an arbitrary number of other services are also disrupted. Again, I reiterate that there is no way of reliably ascertaining an upper bound to the operational impact of a domain seizure, and as such it is hard to see that domain seizures can ever be reliably ascertained to be proportionate as a law enforcement measure in advance.
The idea of domain seizures as a law enforcement method is a really, really bad idea. It makes about as much sense, and is as about as proportionate, as the postal service revoking the address of someone who commits mail fraud; their house number is literally erased from databases, and mailmen return mail sent to that house number as undeliverable. Nobody would claim this is a sane way of dealing with abuse of the postal service.
And of course, nothing in this should seem like it makes law enforcement impractical. If a service is illegal, go after the people, the company, the servers; going after the domain always has the potential to cause extreme collateral damage, and the degree of damage which may be caused cannot be ascertained in advance. Even more worryingly, to the extent that we've seen seizures so far, it seems like something mostly done because it is easy, not because it is right; a cheap, usually due-process-free way of smiting websites deemed improper when persuing the persons or machines involved would be more effort. This reduces the trustworthiness and reliability of the domain name system, and its ability to serve an apolitical role for entities of all countries worldwide. This is a disaster for the law abiding just as much as it is for the lawless.
If this company is serious about the robustness of domain names, it needs to stop perpetuating an idea of the registrar (or pretend registrar) as a publisher, as a legally responsible entity for the services dereferencable via domain names, particularly since such a model of liability is, mercifully, not yet one that has appears to have become reality. To do so simply accelerates the undesirable.