9898

A new way to game the new gTLD program

时间: 2024-05-14 21:53:29   点击数: 537   来源: 耐思智慧

A new way to game the new gTLD program

It may not help you win a gTLD, but a new method for screwing over your enemies in ICANN’s new gTLD program has emerged.



As I reported earlier today, it seems quite likely that ICANN is going to add a new step in the <strong>new gTLD</strong> evaluation process for the next round — testing each applied-for string in the live DNS to see if it causes significant name collision problems, breaking commonly deployed software or leading to data leaks.


The proposed new Technical Review Team would make this assessment based in part on how much query traffic non-existent TLDs receive at various places in the DNS, including the ICANN-managed root. A string with millions of daily queries would be flagged for further review and potentially banned.


The Name Collision Analysis Project Discussion Group, which came up with the new name collisions recommendations, reckons this fact could be used against new gTLD applicants as a form of sabotage, as it might be quite difficult for ICANN to figure out whether the traffic is organic or simulated.


The group wrote in its final report (pdf):


In the 2012 round, the issue of name collisions included an assumption that the existence of any name collision was accidental (e.g., individuals and organizations that made a mistake in configuration). In future rounds, there is a concern on the part of the NCAP DG that name collisions will become purposeful (e.g., individuals and organizations will simulate traffic with an intention to confuse or disrupt the delegation process)…


Determining whether a name collision is accidental or purposeful will be a best-effort determination given the limits of current technologies.


We’re basically talking about a form of denial of service attack, where the DNS is flooded with bogus traffic with the intention of breaking not a server or a router but a new gTLD application filed by a company you don’t like.


It probably wouldn’t even be that difficult or expensive to carry out. A string needs fewer than 10 million queries a day to make it into the top 25 non-existent TLDs to receive traffic.


It would make no sense if the attacker was also applying for the same gTLD — because it’s the string, not the applicant, that gets banned — but if you’re Pepsi and you want to scupper Coca-Cola’s chances of getting .coke, there’s arguably a rationale to launch such an attack.


The NCAP DG noted that such actions “may also impact the timing and quantity of legal objections issued against proposed allocations, how the coordination of the next gTLD round is designed, and contention sets and auctions.”


“Name collisions are now a well-defined and known area of concern for TLD applicants when compared to the 2012 round, which suggests that individuals and organizations looking to ‘game’ the system are potentially more prepared to do so,” the report states.


I’d argue that the potential downside of carrying out such an attack, and getting found out, would be huge. Even if it turns out not to be a criminal act, you’d probably find yourself in court, with all the associated financial and brand damage that would cause, regardless.



Source from Domain Incite




<span style="font-size:14px;font-family:Verdana;">NiceNIC.NET</span> is an ICANN, gTLDs, ccTLD, new gTLDs Accredited <strong><span style="font-family:Verdana;font-size:14px;">Domain Registrar</span></strong>Hosting & Server Provider, founded in 2006.

 

Customers are happy with NiceNIC service!
1. PAY & RELAX with Convenience and Privacy
2. Bitcoin, USDT, ETH and other Cryptocurrency
3. Largest Selection Domain Portfolio Lowest at $2.99
4. Latest Security Solutions - SSL Certificates Lowest at $8.99
5. ICANN and gTLD & ccTLD Registries ACCREDITED REGISTRAR




上一篇:.home, .mail and .corp could get unbanned 下一篇:Unstoppable to apply for Women in Tech gTLD

旗下网站:耐思智慧 - 淘域网 - 我的400电话 - 中文域名:耐思尼克.cn 耐思尼克.top

耐思智慧 © 版权所有 Copyright © 2000-2025 IISP.COM,Inc. All rights reserved

备案号码: 粤ICP备09063828号  公安备案号: 公安备案 粤公网安备 44049002000123号  域名注册服务机构许可:粤D3.1-20240003 CN域名代理自深圳万维网

声明:本网站中所使用到的其他各种版权内容,包括但不限于文章、图片、视频、音频、字体等内容版权归原作者所有,如权利所有人发现,请及时告知,以便我们删除版权内容

本站程序界面、源代码受相关法律保护, 未经授权, 严禁使用; 耐思智慧 © 为我公司注册商标, 未经授权, 严禁使用

法律顾问:珠海知名律师 广东笃行律师事务所 夏天风 律师