December 7, 2005 5:15 PM PST

ICANN told to clamp down on dodgy domain names

More than 8 percent of all Internet domain names are registered with false or incomplete information, according to a U.S. government study into the prevalence of phony Web sites.

The study, released Wednesday by the U.S. General Accountability Office, showed that 2.31 million domain names, or 5.14 percent of all domain registrations, have been registered with information "obviously and intentionally false" (such as a (999) 999-9999 telephone number, the report says). The GAO also found that 1.6 million, or 3.6 percent, contained incomplete data in one or more of the required fields.

The report drew a response from Rep. Lamar Smith, chairman of the Subcommittee on Courts, the Internet and Intellectual Property.

"Vendors unwilling to identify themselves publicly are more than likely fraudulent," Smith, a Republican from Texas, said in a statement released Wednesday.

Smith concluded that the Internet Corporation for Assigned Names and Numbers (ICANN), the standards body for Internet domain names, is failing to "weed out such fraudulent identifications."

The rise of phishing scams has prompted Congress to investigate. In such fraud schemes, Internet thieves lure consumers to counterfeit Web sites to dupe them out of vital information such as credit card numbers and passwords. Roughly one in four U.S. Internet users have been targets of phishing attacks, according to a study conducted by Time Warner.

Contact information for operators of Web sites is publicly available through the Whois Internet service. Data from Whois could help law enforcement officials track down Internet criminals--provided it's accurate.

The GAO said that ICANN is now requiring registrars to investigate and correct any reported inaccuracies in contact information. The Internet group continues to assess the operation of the registration process and look for ways to improve accuracy, according to the agency's report.

Attempts to reach an ICANN representative were not successful.

This is not the first time ICANN has been called on to monitor the accuracy of its registrations more closely. A study three years ago found that ICANN policies encouraged but did not require registration organizations, such as VeriSign or Go Daddy, to verify information from people who have submitted false information. It recommended that ICANN change those policies.

See more CNET content tagged:
Internet domain name, Whois, domain name, registration, phishing

Add a Comment (Log in or register) 14 comments
Invalid phone numbers
by tjonz December 7, 2005 6:27 PM PST
It's worth noting that *some* of the invalid data cited in the GAO report was added to domain records by the registrars. For example, time was that domain contacts were not required to publish a telephone number; when ICANN decided to require this information, Verisign/NetSol (for one) inserted "999-999-9999" into all records that did not already include a phone number.
Reply to this comment
Domain owners do not deserve any privacy!
by sysadmin999 December 7, 2005 7:13 PM PST
Security is a priority on the web, unless you are a domain owner, in that case - according to ICANN rules, you should be fair game for every spammer and con artist out there.

As a sysadmin I cannot begin to tell you the number of security issues I have to deal with almost daily. Viruses, phishing, pharming, spam and even snail mail rip-off artists all attempting to con my clients. Every new domain I put up gets spammed with the first couple of days and the automated break in attempts begin shortly after that.

Knowing all these threats exist, how can ICANN insist domain owners publish their full, personal details online for all to see?

I belive domain registration information needs to be better protected and managed if ICANN wants to have any hope of compliance.

If ICANN truly feels all domain owners should comply with their out of date ARPANET rules then I suggest they should lead the compliance drive by publishing the full names, home addresses and home phone numbers of all the ICANN staff, including the board.
Reply to this comment View all 2 replies
Good luck with that.
by katamari December 7, 2005 7:15 PM PST
I'll be the first to blatently admit that I do not list legitimate contact methods (except for my Email address) for any of my domains. Yes, this violates ICANN specifications... so the question is, why do I do it?

Simple: to avoid spam. What kinds-of spam you ask? All forms.

There are shady registrars out there -- some of which who have been taken to court in Europe for their shady dealings -- who peruse the WHOIS database (despite it being against the law) and begin sending unsolicited snail mail to any of the contacts listed.

One such company, who still does this even today, is the "Domain Registry of America" (DROA). You can visit their site here: http://www.droa.com/

Look on Google and Usenet for references to this company. All you'll find are complaints about how they send you spam, send you false "invoices" when a domain you own (NOT WITH THEM!) is about to expire, yadda yadda. In one case, I even received a telephone call from some random registrar (it was an automated message, yapping about one of my domain names -- maybe it was the DROA, I don't know. They didn't provide their company name!).

But as I said, I do keep a legitimate Email address in my contact records. This is necessary in case my own registrar has issues and needs to contact me, or if someone has concerns. Of course, the amount of Email-based spam I get to this address is through the roof (so much for the "DON'T USE THIS DATABASE FOR UNSOLCITED EMAIL" warning WHOIS outputs...).

ICANN, if you want people to put legitimate information in their records, then you need to stop jerking off and do something about outfits like the DROA and many others. Until then, good luck getting myself and many others to put accurate snail mail or telephone contact information in our records...
Reply to this comment
What about anonymous registrars?
by MahRain December 8, 2005 2:17 AM PST
There are some organizations who register domain names on their own name, and link the content of another person. These are specially designed constructions to conceil the identity of the domain owners.

Any way they could force them?
Reply to this comment
Terrible idea
by December 8, 2005 6:39 AM PST
Previous comments are spot on.

ICANN are promoting combine harvesting of email addresses & private information.

I would be happy to provide such information if it wasnt going to published to every tom, dick and spammer harry.
Reply to this comment
I'm 50/50 on this WHAT IF.....
by inachu December 8, 2005 8:39 AM PST
What if its a girl hosting her Geocities website and
She posts pictures of herself and family and dog and
shows pictures of her new house and car sicne they won the million dollar lotto.

Then anyone can drive by their house and ask if they can have some money since they are so rich.
Or people would google them and then call them at all hours of teh night and pedos would be driving by and looking and using the registers email and add it to their instant messenger to hook up with them later online.....

ONLY THE NAME, CITY, STATE should be shown and
If you want to contact the domain owner then have it work like craigslist for permission and it will be the persons discretion if they want to talk or email with whomever.

If you are with a GOVT agency then network solutions or go daddy should have a form like MSN passport that lets you log in as the feds so you can bypass and see the domain info instantly.

This is soooooooo easy to do! Why hasn't anyone fixed it?!?!?!
Reply to this comment View reply
Spam Domains
by rob8888 December 8, 2005 8:45 AM PST
Yes, the false information is a way that spammers hide their identity. The good news is that ICANN works with registrars and if they can't get in touch with the domain owner to have the false, incorrect information corrected, the domain will be taken offline.
Here is an article about it:
http://www.alovelinksplus.com/info/blacklist/how-to-combat-spam.htm
I have had success in having more than a dozen domains taken offline that I received SPAM from.
Reply to this comment
No anonymity for business domains
by Mark Donovan December 8, 2005 9:53 AM PST
There may be a disconnect between personal domain registrations and business domains. While individuals may expect a level of confidentiality, anyone doing business using domain registrations has no right to anonymity.

Outside the Internet, business identities are public record. Here in the U.S. business registrations to state government are public information. The corporation commissions in many states make these records searchable on the Internet. U.S. corporations that are publicly owned must file information to the Security and Exchange Commission (SEC). See the SEC web site for the type of information that's public. Search for Ticker Symbol AAPL, for example.

http://www.sec.gov/edgar/searchedgar/companysearch.html

Moreover, it's unacceptable for a business, whether privately or publicly owned, to transact business anonymously. Revealing one's correct, verifiable contact information is the price of doing business with the public. Every business domain registration must be accurate and verifiable. Dealing with the possibilities of unwanted solicitations, fraudulent transactions, etc. is common to both offline and online business and can't be solved by allowing Internet anonymity.
Reply to this comment
You mean like...
by katamari December 8, 2005 12:25 PM PST
...registrars such as Domains By Proxy (www.domainsbyproxy.com)?

There's no way to enforce this with them either. Sure, they claim to comply with law enforcement, but then again, it doesn't matter if you agree to comply or not -- you WILL comply with a subpoena. :-)

Companies like Domains By Proxy that exist solely *because* of the problems associated with putting up real information in one's WHOIS records. They admit this freely on their site. I'm disgruntled that someone's in the business of *making money* off of people's desire for privacy (it runs along the same lines as spam, in my opinion).

Proxy registrars should be shut down + taken offline. I'm amazed ICANN lets them stay around. You can't find any information about who owns their companies, either. I don't trust them simply because they don't disclose on their own site who calls the shots, where the money goes, who runs the place, yadda yadda. For all I know it's some IRC packet kid running a "business" out of his bedroom, collecting thousands upon thousands of credit cards which will eventually be sold to the highest bidder.

Wouldn't be the first time...
Reply to this comment
But what about...
by aabcdefghij987654321 December 9, 2005 6:50 AM PST
the person who is living under a repressive government that has registered a domain name and has posted information their government has deemed to be seditious?

This article and all the comments so far have only looked at one half of the story. It should be remembered that there may be good reasons to allow people to hide their identity even from governments as well.

The question then is how to set a balance between the need to shut down sites which prey upon people vs how to protect people against bad government.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
Aligning CIO & CEO visions
What CIOs need to know

It's a simple truth. The closer you and your CEO see things, the greater your chance for success. Our exclusive report can help you get there—and help your business grow. To get the report, featuring the views of 765 CEOs on innovation. click here

Click Here!
What CEOs think: Innovation Insights for CIOs

Learn How CIOs can deliver strategic success for their enterprises

The New CIO: Beyond Technology

Learn how CIOs become heroes

Podcast: Chris Gorog of Napster

Learn about the impact of technology in strategy execution

The future of the Enterprise

Read more about tomorrow's organization

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' photos

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Outside the Lines

    EIC Squared: Chrome, iPods, and a Dell-Salesforce union

    On this week's EIC Squared podcast CNET's Dan Farber and ZDNet's Larry Dignan discuss Google's latest rocket launch--the Chrome browser--as well as Apple's iPod event next week and a Dell-Salesforce.com union.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • Webware

    Mozilla releases second Firefox 3.1 alpha

    Added features include support for a new video tag element introduced with the HTML 5 standard, along with some speed enhancements.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crave

    This week in Crave-land

    The Xbox 360 finally gets a price cut, and the game world gets ready for the arrival of Spore.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.