36 ms·
WHOIS blackout period likely starting in May
- deleted 8y ago[deleted]
- becauseiam 8y agoThe WHOIS blackout has already started, I recently registered a domain with a non-European ccTLD, but with Gandi for the registrar. The WHOIS reads: Administrative Contact: Not displayed due to GDPR
- Semaphor 8y agoMy .me domain displays (and always has displayed IIRC) nothing but my full name (not that interesting as the domain is my name). Everything else are the contact details from Gandi.
- __david__ 8y agoMust be a Gandi thing. My .io domain from Gandi only shows my name but a .me domain from another registrar still shows home address, phone number, etc.…
- kbar13 8y agodomain registration data is in a weird place for the modern internet. I can see the value of having a real registry when it was first developed, but now it seems like a pretty easy way for people to shoot themselves in the foot with regards to privacy. Also, some registrars charge a premium for WHOIS privacy. It should not cost extra to have your legal name and address to be hidden from the entirety of the internet.
- mort96 8y agoDo any registrars not charge a premium for Whois privacy? I know Hover doesn't have a separate Whois privacy entry price, but the base price at Hover seems to be about the price of a domain + Whois privacy at other registrars.
- BlueGh0st 8y agoGoogle domains offers it for free and as standard.
- asaph 8y agoI wouldn't say free. I would say it's included in the $12/year price of .com registration. I suspect that price is competitive with registrars that have a base price that doesn't include WHOIS privacy and sell privacy as an add-on, though I haven't shopped around in a while. All my domains are registered with Google Domains.
- hamandcheese 8y agoGandi.net doesn't charge extra and also has reasonable prices.
- us0r 8y agoi get it free from moniker
- PatientJ 8y agoiwantmyname.com doesn't charge for whois privacy
- wilg 8y agoIt's included on Hover as well.
- mort96 8y agoThat's what I meant with "I know Hover doesn't have a separate Whois privacy entry price, but the base price at Hover seems to be about the price of a domain + Whois privacy at other registrars".
- bks 8y agoI shifted my entire domain portfolio from Bulkregister.com to Uniregistry for this issue. Bulk charges $3 per domain per year and I saved thousands a year moving to Uniregisry.
- cm2187 8y agoAnd some jokers like OVH do not charge anything for privacy but fuck it up. I got recently hundreds of emails and a dozen phone calls from various spammers as a result of registering some domain names with them despite chosing the privacy options. The publication of personal information on whois cannot stop soon enough.
- dx034 8y agoYep, they only replace owner but not contact details for admin or tech. That way your details are as public as without their "service".
- jdietrich 8y agoWHOIS privacy isn't even an option for some tlds. Nominet require the registrant's legal name and postal address and only offer a discretionary opt-out for non-commercial websites. https://registrars.nominet.uk/namespace/uk/management/data-quality/whois-opt-out https://registrars.nominet.uk/namespace/uk/management/data-q...
- jedberg 8y agoWhen you buy a house, your name and the purchase price are public information. Any one at any time can look up who owns a house, how much they paid for it, and how much they pay in property tax every year. I get a ton of spam because of this. However, I'd rather have this system than one in which all the owners are secret. I've had to look up owner information before to contact owners of various properties, and having that hidden would have made that task impossible. You can hide the ownership information of a house, if you pay extra money, by hiring a lawyer to create an entity and put the entity on the property, but then the lawyer has to put their address, and forward any requests on to you, just like the whois privacy folks. I think it is a good thing that every domain has valid contact info.
- dictum 8y ago> However, I'd rather have this system than one in which all the owners are secret. I don't mean to be cynical, but isn't this system also the one in which some people simply register their houses under a shell company?
- jedberg 8y agoYes, but at least the shell company forwards on the messages. And most people don't do it because it's a hassle.
- woolvalley 8y agoAnd you lose a 250-500k capital gains exemption if you sell the house and it's not owned & lived in by you directly AFAIK The issue with this system is it also lets people look up where you live by name alone, which can be bad if you want to own your house and have a stalker problem. The map works 2 ways.
- toomuchtodo 8y agoNot true with a revocable trust, which costs under $1000 to establish and provides all the same benefits of owning the real estate directly without disclosing ownership. Disclaimer: Applies primarily to IL and FL, not an attorney, nor your attorney.
- phit_ 8y agothank god, tired of paying extra for "whois privacy" that various registers offer running a hobby project should not require you to share your private contact details with the world
- robalfonso 8y agoPrivacy still has a place, this would not keep someone from knowing what corporation owns a domain - and will not keep the government or other interested parties from finding that out. Privacy services still act as an impediment to keep ownership private far better than this will.
- throwaway2048 8y agoIt however brings to a dead stop the push they have been making to make whois privacy a violation of the TOS of registering a domain.
- appdrag 8y agoA lot of registrars include privacy for free.
- gwbas1c 8y agoI've gotten so much telemarketing from my whois. Quite frankly, it's ridiculous. I'm glad that the EU twisted ICANN's arm off and beat them into submission. I think ICANN is going to quickly realize that they will need to take an active role in brokering communication with domain holders; this way they will have to act as gatekeepers against spam.
- Ologn 8y agoHear hear. I run a few small web sites, and in the past few years have gotten zero calls from devops types calling about a problem, and dozens, if not hundreds, of telemarketing calls, to a number that is only listed on my whois data.
- lamlam 8y ago
- robalfonso 8y agoIn the short term WHOIS is going to be limited to just the registrant organization, state, country and a masked email address (Admin and Technical fields will be removed save email). This is short term to come into compliance with GDPR. Long term ICANN intends to create a privileged group (other registrars, law enforcement, etc) Who will be able to get to the full whois data. So a sort of tiered system. Expect this to take a minimum of a year. The ICANN multi stake holder model means nothing happens fast.
- bhhaskin 8y agoJust another way ICANN can make money. You can bet your bottom they will sell the premium access.
- forapurpose 8y ago> Long term ICANN intends to create a privileged group (other registrars, law enforcement, etc) Who will be able to get to the full whois data. To a substantial degree it's privacy for the powerful and transparency for the weak. It should be the reverse: The powerful and government institutions should be transparent, and citizens should have their privacy.
- gred 8y ago> The powerful and government institutions should be transparent, and citizens should have their privacy. Hear, hear! The most frustrating part of the Clinton email fiasco to me was the contrast between the rule bending going on at the highest levels in the name of privacy, and the pervasive monitoring that the rest of us are subjected to.
- slrz 8y ago> Long term ICANN intends to create a privileged group (other registrars, law enforcement, etc) And trademark owners, of course. So that the Three Letter Corporation (TLC) can continue sending lawyers to wrestle away control over the domain of Theodore L. Clark's personal homepage initially set up in 1995 (and enthusiastically maintained since). Because chaos and mayhem would result if there's even a single ccTLD where the "tlc" label is not assigned to the same one entity that just redirects it to their .com anyway.
- atesti 8y agoDoes this also apply to RIPE for the whois of an IP address?
- phicoh 8y agoThere is a RIPE meeting this week. Tomorrow (Wednesday) there will be an update regarding GDRP in the database working group: https://ripe76.ripe.net/programme/meeting-plan/db-wg/ https://ripe76.ripe.net/programme/meeting-plan/db-wg/
- CNJ7654 8y agoDo people actually give their real info on the WHOIS lookup? I've always given pseudonyms like Steven Stromboli or Paul Penne and fake addresses
- lima 8y agoI work for a popular hosting company and WHOIS data is causing constants issues - mostly for non-technical customers, but on one occasion, I accidentally used my work mail address during testing. The WHOIS database for, say, the .net zone is extensively mined by spammers and telemarketers. I received a torrent of marketing mails for months even though I immediately changed it to a noreply mail address. We receive numerous complaints from customers who ignored our warnings.
- NoSalt 8y agoI'm good with this. I don't like the fact that some yahoo can look me up and come after me just because he might not like what is on my website.
- 7ewis 8y agoNoticed this the other day, my own domain is already blacked out. I used to put fake info there anyway, I don't want my domain linked to my home address, or provide an easy way for spammers to get my email.
- jiveturkey 8y agogood. -grumpycat
- walrus01 8y agothere is another type of whois that people don't ordinarily interact with, but is essential for the correct operation of the internet... ARIN, RIPE, APNIC and AFRINIC run whois databases for IP space. Network operators use them to find who controls chunks of v4 space (ranging from the globally-minimum-announceable /24 to /12). ISPs can use tools like SWIP to point the whois for a block of space in use by a customer to that customer's whois info. I sincerely hope that this doesn't become more difficult to use, because it will make basic network diagnostics at a WAN scale much more annoying. The good news is that the typical ISP-level info in IP space whois databases doesn't fall under the GPDR, since most are role accounts (abuse@ispname.com , noc@ispname.com, etc). Also generic phone numbers for NOC and network engineering groups. However, a lot of ISPs do currently have individual persons listed as points of contact in their whois entries.
- chx 8y agoMy quick and dirty three step scam website detecting process https://travel.stackexchange.com/a/84026/4188 https://travel.stackexchange.com/a/84026/4188 obviously includes whois but -- I think I will make do without. It's only a little harder, to be frank.
- oliwarner 8y agoI don't understand the problem. When buying a domain you do so in ICANN's jurisdiction, under their terms. Actively and voluntarily forfeiting your right to privacy should trump statutory privacy. And if that isn't enough, ICANN can fix this without compromise. One mass email. "Respond expressly allowing us to publish your PII, or lose your domain."
- tcd 8y agoYeah, that's not how the law works, sorry about that. Every human has rights that cannot simply be waived because a website says so. Everyone has a right to privacy, and that's what the GDPR is about ensuring for EU subjects. Your thinking is extinct and I strongly suggest changing it, or fading away like everyone else who feels the same way.
- mynameisvlad 8y ago> Everyone has a right to privacy This is far from an absolute. Each country more or less dictates the rights of their people, and many countries do not directly provide this right. As an example, the Indian supreme court only declared it a right last year, and most articles talking about it only list a very select few other countries as ones that provide this right.
- Dravidian 8y agoIndian government mandates original information to be filled in RABT else the domain registrar can cancel your account. And since GST, if you register a domain you are supposedly a business owner and need to provide a GST number mandatorily. Check these out with Net4. Indian govt sucks big time when it comes to privacy.
- obscura 8y agoAnd even where it is a right, it's not an absolute right - it has to be balanced with other rights and may be limited by laws.
- dragonwriter 8y ago
- techsin101 8y agowhois guard is a joke so i welcome this
- clay_the_ripper 8y agoI really wish WHOIS would go away forever. There is absolutely no point to it. If you don’t pay to get your name private, you get SPAMMED to such an incredible degree, it’s absolutely awful. Literally 10+ calls a day, emails voicemails. So you have to buy the “privacy protection” thing, which defeats the whole purpose anyway. All WHOIS does is create an industry of people selling privacy to WHOIS. This whole narrative about “journalism” and it being used for research sounds like nonsense to me. Something tells me these people have a vested financial interest in this. Would love to hear an alternate point of view on this.
- ryan-c 8y agoI've actually found that rotating the email address I have listed in whois quarterly addresses the spam problem pretty well. Phone number goes to my Google Voice account which is set up to send everything directly to voicemail.
- x0x 8y agoI agree WHOIS is completely useless! Anyone can fake this info anyway and anyone using there real info can be SWATTED (https://en.wikipedia.org/wiki/Swatting https://en.wikipedia.org/wiki/Swatting)
- daurnimator 8y agoOnly if you use your home address. Most people use a PO Box or other forwarding. (or in the case of a business: physical office presence, which is usually published on the website itself)
- snuxoll 8y agoAnyone who has my name can find my address, voter registration records are easily searched online in many states. I only bother with WHOIS protections (which Gandi includes at no additional charge) to avoid spam, very few people can claim they are truly safe from swatting.
- slrz 8y agoChoose a registrar that doesn't charge you extra? Your name stays in, of course, but your (electronic and snail) mail addresses and phone number can be replaced by registrar-managed ones where they forward you incoming stuff and (mostly) keep the spam. It's a pretty common thing with European providers, I think.
- MR4D 8y agoThis is stupid. What happens next - do patents and copyrights have owner’s right to be forgotten? If so, then who do you sue for stealing your copyright? The intent is good - let me be clear about that. But the implementation is having second order affects that are going to f* with things in a big way because it wasn’t thought through as thoroughly as it should have been. * * Key thought here is that it might be extremely difficult to think through all the second order effects, which suggests to me that a better phase in process should have been implemented. EDIT - Not sure why this is being voted down. If i’m Not clear here, then please see my follow-on comment for (hopefully) a more clear view of my position. I’m not saying Whois is stupid - I’m saying GDPR is (due to the lack of thinking around second-order effects).
- f2n 8y agoI don't understand how any of those are remotely related to whois being removed. It's not like it represented anyone that could feasibly be sued before, just a whoisguard service, usually
- MR4D 8y agoIn the US, we have different sites where you can look up patent information. In fact, IBM and Microsoft run this one, which is a global database. Article: https://www.zdnet.com/article/microsoft-ibm-arm-back-open-patent-database/ https://www.zdnet.com/article/microsoft-ibm-arm-back-open-pa... Site: http://oropo.net/ http://oropo.net/ So my question, is if Whois had to take their site offline due to GDPR, then will things like this go offline? My concern is that GDPR will have a chilling effect not just on free speech, but on open information of many kinds. PS - for reference, here is a good overview of the issues that an open patent database helps solve: http://oropo.net/oropo_report_20150615.pdf http://oropo.net/oropo_report_20150615.pdf
- zaarn 8y agoWHOIS will not be permanently offline, it will be temporarily offline while the ICANN and others work out how to give access to people who have legitimate interest in the data, ie people looking for a legal contact, sysadmins looking to notify someone, registrars themselves, etc. I don't think the US patent database will go offline, the EU one might hide personal information like name and address unless you request access under legitimate interest.
- mirimir 8y agoSo will firms like https://www.domaintools.com/ https://www.domaintools.com/ need to redact their whois history data? They're in Seattle, for whatever that's worth.
- pferde 8y agoI'm just wondering why ICANN is "scrambling to get it GDPR-compliant" just now, at the eleventh hour. They had just as much time as rest of the world to do it sooner, without any interim modes, and without any rush and all the problems that can come from hastiness.
- kijeda 8y agoA big factor is that ICANN is comprised of multiple stakeholder communities of competing interests that have to come up with consensus to make new policies. Refining the model of what is published in the WHOIS has been the subject of working groups in ICANN for over 10 years, but consensus was never reached because you had a huge spread of opinions that never converged. Privacy advocates argued for no WHOIS, whereas interests from law enforcement, security research and intellectual property arguing for full disclosure.
- holstvoogd 8y agoICANN is scrambling to be compliant they write... We've all had 2 years notice since the GPDR has been adopted! And if you 'didnt know', you have bigger organizational problems. I understand it is a lot of annoying work, but adtech and data brokers (etc etc) have been gutting privacy and the internet for long enough. We've let it come this far, now we get regulated. (disclaimer: I only started working on compliance this year, do as I say, not as I do ;))
- guitarbill 8y agoIt's worse than that. Article 29 Working Party (WP29) - which deals with data protection has said since 2003 (well over a decade!) that Whois is not compatible with EU law [0]. They just didn't have a way to enforce it before GDPR. But ICANN are delusional idiots, maybe because they get so much money from US intellectual property interests. They did nothing, and then seemed to think that they could get a moratorium on enforcement. But even their own Non-Commercial Stakeholders Group basically told them to get lost [1]. It's a fascinating story of just how terrible ICANN is. As always, the Register has a great write-up [2]. One thing it clear, they deserve it. I do feel bad for registrars though, and hope they had more sense than ICANN and developed a plan B. [0] http://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2003/wp76_en.pdf http://ec.europa.eu/justice/article-29/documentation/opinion... [1] https://www.icann.org/en/system/files/files/gdpr-comments-ncsg-article-29-wp-whois-23apr18-en.pdf https://www.icann.org/en/system/files/files/gdpr-comments-nc... [2] https://www.theregister.co.uk/2018/04/25/icann_whois_gdpr/ https://www.theregister.co.uk/2018/04/25/icann_whois_gdpr/
- petercooper 8y agoWe've all had 2 years notice since the GPDR has been adopted! Have we really? The first it cropped up on my radar was late 2017 and I'm in a business that adheres very strictly to EU DP best practices (so was already mostly GDPR compliant). I'm not sure whose job it was to promote awareness of this but Britain's data protection agency certainly didn't do a good job of it given they've had my email address for years(!)
- alerighi 8y agoHaving a public register that tells you who owns a particular domain or IP address could be useful for a lot of things. Sure, they could take away a lot of fields that are not necessary and might be a privacy problem, like address and phone number, today it's useless, and maybe instead add a GPG public key, so much useful, and keep name and email address. But don't remove it, it's a useful thing I use a lot, most of the times for security purpose, you see a suspicious IP address or domain while observing a packet capture, WHOIS tells you who owns it, you find in a log an IP address that tries to bruteforce into your server, WHOIS tells you who it is and gives you an address to contact and ask explanations, you need to find a person to contact if you have a problem with a website, contact the email address in the WHOIS record of the domain, you are sure that you are contacting the right person, even if the site gets hacked in the worst way the WHOIS record can't change.
- antthewho 8y agoForget hacking! you wanna unhack my constantly blacked and hacked phone line make sure you get a 9/11 movie star to call once you have my IP 146.200.117.18. and telephone number 44(0)1491573890. British mafia think they own a brain they have no idea, i am nice guy family man and they have been blocking my bank account and telephone for 15 years only findout now. so if you know anyone we would appreciate your strength and connections and friendlyness. Lets hope some of you are nice guys
- lumberingjack 8y agoBack in 2002 teenager me used WHOIS to lookup my ISP's (adelphia) phone number. Some guy picked up the phone in their server room no shit. He answers the phone like it's a internal only line "server room Jim here how can I help?" Me: "ya um I have a problem with my SMTP port can you help out?" Net Admin "How did you get this number! but ya I can help kid"