3 ms·
Rob, as I understand it, the RRSG was pretty vehemently against this every step of the way. The RRSG has since repeatedly asked ICANN and LEA for some data rega
by StuntPope 11y ago
Rob, as I understand it, the RRSG was pretty vehemently against this every step of the way. The RRSG has since repeatedly asked ICANN and LEA for some data regarding the efficacy of WAP and none has been forthcoming (although there is now, finally a review of WAP in progress).
To date there has not been one single documented instance of the WAP fulfilling one objective of LEA or preventing a single instance of cybercrime since it's inception.
It is patently ridiculous in implementation given that it does nothing to prevent blatantly fake whois data (see the screen grab from my example where I successfully verified "Some Guy" as the domain registrant).
It's just a half-assed flawed implementation of a horribly flawed policy that only accomplishes two things:
1) throwing registrants under a bus, especially since the ones most likely to burned by this are technically less sophisticated rule followers and
2) utterly screwing registrars, since we end up holding the bag when these domains go offline.
- robalfonso 11y agoTotally agree, it's pretty useless right now especially since the option of what to verify is pretty loose, though the 2013 raa does specify there can be some new fields introduced. Now on the customer side we did a implementation like yours and almost launched it, BUT we thought better and came up with a less onerous system that still complied with the raa, there has been very little heart burn on our end with regards to customers or implementation, if you want to talk about it message me. For us this has been a big deal and we are a top 50 registrar