[00:00.630 --> 00:04.470] This next panel is fucking up the internet at ICANN. [00:06.740 --> 00:08.330] With ICANN. [00:08.330 --> 00:08.830] Hi, Aber. [00:09.020 --> 00:10.420] Through ICANN. [00:11.140 --> 00:13.000] I have to really get on top of that mic and stuff. [00:13.260 --> 00:13.880] Yeah, okay. [00:14.640 --> 00:15.400] Maybe I can. [00:17.310 --> 00:24.780] Yeah, maybe I should have called this how global control on the internet works, but I thought I'd make it a little bit more obvious. [00:25.020 --> 00:26.260] So, I'm Andy Muller-McGoon. [00:26.480 --> 00:29.740] By nature, I'm a spokesman of Chaos Computer Club. [00:29.740 --> 00:34.840] I've been attending most of these 2600 conferences here as well. [00:35.040 --> 00:41.980] So, normally, I'm involved as a speaker of an organization that promotes freedom of information and free flow of information. [00:42.640 --> 00:47.680] Since the year 2000, by some strange story, I became director of ICANN. [00:47.780 --> 01:01.460] ICANN seems to be a corporation for control of information instead of freedom of information, which, of course, does not mean freedom of speech at all times in all rooms. [01:02.060 --> 01:02.800] Thank you. [01:04.100 --> 01:04.650] Okay. [01:05.670 --> 01:10.810] So, some of you might not be familiar with what ICANN exactly does. [01:10.960 --> 01:19.240] I will try to give you a short technical introduction also to explain why it has such an impact on the internet. [01:19.240 --> 01:39.760] The internet is being most of the times described as a very decentralized infrastructure, in the meaning of it's a bunch of computers talking to each other on the base of protocols like TCP IP, on the basement of IP addresses, which are distributed, so every computer has one, [01:39.860 --> 01:41.720] through the RIRs. [01:41.720 --> 01:49.650] Anyhow, there's some routing protocols so that the communication services on the base of IP numbers find their way to the hosts. [01:50.660 --> 01:53.740] But then there is, of course, communication services. [01:54.220 --> 01:58.510] And until we come to the communication services, we can say, yes, it's true. [01:58.620 --> 01:59.580] It's very decent, surely. [01:59.800 --> 02:03.210] It takes place without a central control or anything. [02:03.210 --> 02:15.220] But there's one problem with this, and that is that human being used to use communication services more likely by using the domain name system done on the base of IP addresses. [02:15.440 --> 02:24.930] So, of course, you can send me an email at Andy at 195.21.6.65, but it might be more easy if I say Andy at CCC.de. [02:25.720 --> 02:43.610] So, the DNS system, the domain name system, mapping these domain names to the IP numbers of the specific hosts for the specific services is different than the rest of the Internet because it's a centrally-based, hierarchic, and so-called distributed database system. [02:43.860 --> 03:04.080] So, at the other side of the net, if you send me an email at Andy at CCC.de, there's a so-called resolver looking from the top, excuse me, from the last digits of that email address, for example, what is .de at CCC.de. [03:04.220 --> 03:24.280] DE is an ISO 3166-2 code for Germany, and that means it is through the so-called root zone file, leading you to a database called a country code, top-level domain registry, which contains the record of CCC. [03:24.620 --> 03:31.390] So, CCC.de is German database, of course, the CCC.de, where it leads to. [03:31.640 --> 03:51.980] But the information where the top-level domains, registries, or databases are, is located in one central file called the root zone file, and that file is being distributed over the whole planet, more or less, through all internet service providers, by 13 computers called the root name servers. [03:53.580 --> 04:09.700] This internet domain name system, root servers, it's 13 computers, and normally what is happening is that there is one central place, the root name server A, where this file is being administrated. [04:09.700 --> 04:33.040] So, for example, if the German registry running .TE might have to change one of their IP numbers of their name servers, they just send this information to some place, I'll explain very soon, and then they change it here in the root name server A, and then this information gets distributed to the other servers. [04:33.040 --> 04:42.400] So, 13 servers we have in common, 10 of them are located in the United States, which means they are in the jurisdiction also of United States. [04:42.680 --> 04:46.920] It's only 8 of these 10 that are located in U.S. [04:47.080 --> 04:52.600] government facilities, such as universities, or Department of Defense places, or whatever. [04:53.840 --> 05:04.120] We have some outside, and normally if we say Mr. Bin Laden drops a little bigger airplane to this area here, and this all disappears. [05:04.660 --> 05:11.880] So, normally, and in theory, it is possible to administrate this file at, let's say, Stockholm or some other place. [05:12.480 --> 05:26.940] I can have a conference on security issues more attached in November of last year after September 11th, and someone mentioned, by the way, that they never tested if this would work, in the meaning of never change a running system. [05:26.940 --> 05:34.960] And no one right now has ever tested if the distribution of the file could also take place from somewhere else in server A. [05:35.240 --> 05:38.560] So, it's a little bit different between theory and practice here. [05:39.620 --> 05:57.980] Anyhow, the distribution of this file of curves has great impact, because, let's say, the United States, holding this function here, might get into a struggle with a very unlikely case, let's say, Iraq. [05:58.260 --> 05:59.620] They would, of course, not do so. [06:00.320 --> 06:08.580] But, let's assume they would get into trouble with Iraq and declare war on Iraq, where United States government normally doesn't declare war, just makes war. [06:08.700 --> 06:10.160] But, okay, that's another issue. [06:10.680 --> 06:13.040] Let's say, in theory, they would declare war. [06:14.140 --> 06:30.400] They could, of course, change the content of the root zone file, mapping the domain name system to the registry of the Iraqi government, holding the .aq or iq records. [06:31.200 --> 06:34.340] They could, let's say, delete this entry simple. [06:34.540 --> 06:39.920] Then Iraq wouldn't be any more there on the internet within, let's say, a few days. [06:39.920 --> 06:46.420] Of course, the IP connections on all communication service on the base of IP addresses would still work. [06:46.620 --> 06:52.800] But the human beings using email services and web addresses and so on, that wouldn't go through anymore. [06:53.500 --> 06:59.240] So, I'll come to some examples of what happened already in this area. [07:00.640 --> 07:06.720] I just wanted to give this as a short introduction, so what this is all about in the domain name system. [07:06.720 --> 07:18.320] In the old days of the internet, there was an institution called IANA where this was more or less nothing else than one person, and that is Jon Postel. [07:18.800 --> 07:23.180] Jon Postel was the guy who administrated this file. [07:23.340 --> 07:30.100] So, IANA is Internet Assigned Numbers Authority, which means he did not only attach protocol numbers. [07:30.100 --> 07:41.540] So, of course, if someone, let's say, was so far going to introduce beaming into the TCP IP protocol, so we'd say we could have a molecular transformation over TCP IP. [07:41.860 --> 07:43.860] If that is a good idea, it's another question. [07:44.000 --> 07:51.560] But let's say someone would involve such a protocol, then of course it would need a port number for the TCP IP protocol. [07:51.740 --> 08:08.920] And someone has to do that, and it has to be sure that it doesn't mess up with some other protocol numbers, so that you get introduced, get put part in your molecules on the one head of the planet, and then get mixed up in an FTP server somewhere else. [08:10.060 --> 08:14.560] So, in the old days, this was an easy one-man job, more or less. [08:14.820 --> 08:28.920] And the creation of top-level domains like the German dot DE was going this way, that someone in Germany found out that there would be the possibility of setting up a registry for this dot DE ISO 3166 code. [08:29.120 --> 08:39.340] And he called up Jon Postel, said, I'm located here in a place called Germany, that's Europe, and we'd like to set up a registry for, you know, this unused dot DE top-level domain. [08:39.540 --> 08:45.780] And he just... Jon Postel maybe was never in Germany, but he just looked at his map, said, oh yes, right, it exists. [08:45.980 --> 08:47.200] There is something like Germany. [08:47.540 --> 08:49.940] And so why don't you just give me your IP number? [08:49.940 --> 08:57.380] And he put that IP number in the file called host.txt, and that was the creation of the German top-level domain. [08:57.500 --> 08:58.460] That was the whole story. [08:58.600 --> 09:00.040] That was all the bureaucratic act. [09:00.180 --> 09:01.160] That was it. [09:02.180 --> 09:22.900] But Jon Postel, of course, had not the appearance, as you might see, to be seen as a trustful partner of many governments, making starting research at the beginning of the 90s and in the middle of the 90s, and seeing that the internet would not only become major infrastructure for social and cultural activity, [09:23.180 --> 09:26.100] but also for economic and political activity. [09:26.780 --> 09:49.380] So originally, there was an idea of going to the United Nations and creating a United Nations treaty organization who would, let's say, on the basement of membership of all countries of this wonderful planet, create a more or less bureaucratic institution that would administrate not only this file, [09:49.600 --> 10:02.840] but would make the decisions about who is allowed to run the registry, who is under what circumstances allowed to have a second-level domain in the registry, because, of course, we don't have only the country called top-level domains. [10:02.960 --> 10:06.160] We have the generic ones, like com.org.net in the old days. [10:06.280 --> 10:07.980] Now we have InfoBiz and so on. [10:08.220 --> 10:11.020] And it's, of course, a vital question. [10:11.020 --> 10:13.260] Who is allowed to run such a thing? [10:13.420 --> 10:14.620] Where is it located? [10:14.840 --> 10:16.280] Who gets access to it? [10:16.540 --> 10:21.780] Is trademark applied to the people who use these namespaces and so on? [10:24.100 --> 10:30.580] What happened is that the United States government, let's say, didn't really like this idea of the United Nations. [10:31.440 --> 10:33.420] There's two reasons for this. [10:33.640 --> 10:34.700] The one is the official one. [10:34.800 --> 10:36.820] The other is the real one, I guess. [10:37.140 --> 10:46.420] The official reason was, oh, United Nations would be so bureaucratic and that doesn't fit with the speed of the Internet running. [10:46.840 --> 10:49.420] So United Nations, that would be not good. [10:49.640 --> 10:54.980] And it would be much better if this is done by a private entity, let's say, a California company. [10:55.600 --> 11:07.720] The true reason, of course, was that in the United Nations, the United States government obviously doesn't have that majority like they have in other so-called international or global institutions. [11:08.460 --> 11:32.500] Anyhow, what happened is they created on the base of a white paper of the Department of Commerce, a memorandum of understanding of the functions, a contract over the IANA functions because John Postel did his work at the University of California, but he got the funding from the Department of Defense for some years already. [11:32.500 --> 11:48.420] So they did create ICANN as a company under California law, and to satisfy the other governments who also wanted to, of course, be part of this policy-making game, they created the so-called governmental advisory committee. [11:48.740 --> 11:54.120] The governmental advisory committee is not really inside the structure of ICANN. [11:54.120 --> 11:57.140] It's just a governmental represents meeting. [11:57.580 --> 12:01.760] And when I came to the ICANN board, it was still a little simple. [12:01.980 --> 12:12.900] We got a briefing before we went to the so-called session governmental advisory committee to the board, and they told us, oh, if you go into that room, don't mess up the situation. [12:12.900 --> 12:14.560] Be friendly to that guys. [12:15.060 --> 12:16.940] Just, you know, listen to them. [12:17.180 --> 12:18.880] Always say, mm-hmm, mm-hmm. [12:19.100 --> 12:25.420] And if you really want to mess it up and ask questions, just say, I'm just having a question for clarification. [12:26.140 --> 12:31.100] So, because at the end of the day, we could go out of that room and ignore what they said. [12:31.100 --> 12:32.460] It's an advisory committee. [12:32.780 --> 12:35.860] You can listen to the advice, or you can tell them to fuck themselves. [12:36.560 --> 12:43.280] Of course, it's not a good idea to tell governmental representatives to fuck themselves. [12:43.540 --> 12:44.940] That's the other side of the game. [12:45.160 --> 12:49.200] So, it's better that you behave like, oh, yes, it's very important what you said. [12:49.340 --> 12:52.400] Mm-hmm, oh, yes, are we gonna take this into consideration? [12:52.400 --> 12:53.440] Of course, yes. [12:54.040 --> 12:54.660] Blah, blah. [12:54.920 --> 12:58.800] But it still means you have the freedom of do whatever you want. [13:00.760 --> 13:05.040] This... I'll come later to this special situation. [13:05.040 --> 13:19.340] The United States government has, because the contracts, the memorandum of understanding over the IANA functions, and the contract also about this, does, of course, mean I can act on behalf of the United States government. [13:19.800 --> 13:30.660] And if a redelegation, for example, takes place, or if I can decide about the creation of a top-level domain, they do this only with the approval of the DOC. [13:30.660 --> 13:40.060] That means every single decision has to be approved by the United States government, Department of Commerce, National Telecommunication and Information Agency. [13:42.280 --> 13:45.180] And sometimes we get that approval, sometimes not. [13:47.060 --> 13:48.980] I'll come to some examples soon. [13:49.610 --> 13:55.580] The structure of ICANN, this is the old structure still, as in place today, is quite simple. [13:55.920 --> 14:00.600] We have three different, let's say, more or less technical policy areas. [14:00.780 --> 14:03.180] The one is domain name supporting organization. [14:03.480 --> 14:06.000] That's, of course, where the most struggle takes place. [14:06.180 --> 14:09.940] The address supporting organization, that's mainly the RIRs. [14:09.940 --> 14:17.360] So the regional internet registries, which give out the IP numbers to internet service providers and so on. [14:17.780 --> 14:21.320] This is, let's say, working without much discussion. [14:21.680 --> 14:29.240] And then we have the protocol supporting organization, which is more or less very questionable if this is within ICANN. [14:29.240 --> 14:39.580] Because if you look at institutions like Etsy or ITU or the World Wide Web Consortium, they, of course, in the ITF, they, of course, don't take place on orders of ICANN. [14:39.920 --> 14:53.460] The only thing they have to do with ICANN is if they create a protocol, this has to be, let's say, approved maybe by the IANA and sent out as an information to the people who use the IANA functions. [14:53.460 --> 15:05.740] But if you listen to people like John Klastin, who has been working a lot on creating protocols, when he goes to ICANN meetings, he used to say, oh, it's so good that ICANN doesn't work. [15:05.960 --> 15:15.100] Because let's think about what would happen if ICANN would give orders to people developing protocols and telling them what to do and what not to do. [15:15.180 --> 15:17.420] This would be even more problematic. [15:18.420 --> 15:26.340] Anyhow, when John Postel, let's say, did this as a one-man show, he already made one thing wrong. [15:26.340 --> 15:29.120] And I think that we will have to pay a lot for that. [15:29.320 --> 15:37.220] And that is leaving the mission of technical administrative handling of things to some other area. [15:37.320 --> 15:38.600] It's mentioned here. [15:39.100 --> 15:41.520] It's called the intellectual property area. [15:41.520 --> 15:58.500] It means we have a few representatives from lawyers, from the MPAA, from all these nice people claiming interest on trademarks, on all kinds of intellectual property ideas. [15:58.500 --> 16:11.340] And to give you an idea of what's happening here, in Montevideo, last year we had a September meeting of about, I counted the statistical list, we had about 450 attendees all in all. [16:11.800 --> 16:15.620] We had about 320 intellectual property people there. [16:16.020 --> 16:19.780] And we had about 100 governmental representatives. [16:20.060 --> 16:23.740] And yes, there were some people who know about technical details as well. [16:23.740 --> 16:26.000] But it has not been the majority. [16:26.340 --> 16:30.080] So, of course, these people are well organized. [16:30.460 --> 16:34.020] They are able to come to meetings all over the planet. [16:34.360 --> 16:35.800] They have legal advice. [16:36.020 --> 16:37.300] They have technical advice. [16:37.440 --> 16:38.660] Of course, they buy it just. [16:39.220 --> 16:40.900] So, this is a little bit of a problem. [16:42.920 --> 16:49.740] The original idea of ICANN was to have a balance of interest between users and stakeholders, so-called stakeholders. [16:49.740 --> 16:56.240] So, the idea was to have half of the board selected by the so-called supporting organization, three of them each. [16:56.540 --> 17:00.460] And the other half, nine board seats, elected by the internet users. [17:00.640 --> 17:04.750] So, to have a balance of interest between users and the people running the infrastructure. [17:05.700 --> 17:18.360] The creation of ICANN in 1998, which also, more or less, at the same time Jon Postel preferred to die, whatever conspiracy that leads us to. [17:18.600 --> 17:26.950] So, he did not even stay alive one day where ICANN was officially registered as a California company. [17:26.950 --> 17:33.580] So, anyhow, the first board was selected by the Department of Commerce, by the United States government. [17:34.290 --> 17:38.880] Of course, with some suggestions Jon Postel made before he died. [17:40.190 --> 17:46.800] And since the year 2000, ICANN did not really act with any kind of legitimation from the user's side. [17:47.030 --> 17:50.750] So, there was much more criticism and criticism coming up and together. [17:50.750 --> 17:56.360] And then they decided in the year 2000 to have at least a little bit of simulation of legitimation. [17:57.060 --> 18:00.540] And decided to make some votes or elections. [18:01.080 --> 18:06.910] And, but of course, not too dangerous, not too much democratic people in there. [18:07.300 --> 18:13.530] So, they only allowed the selection or election of five of these 19 people. [18:13.800 --> 18:17.730] And I could tell you now a long story, but anyhow, I'm one of them. [18:17.730 --> 18:22.840] And I am here allowed to represent all European internet users. [18:23.060 --> 18:25.820] Which is a pretty tough job and it's unpaid as well. [18:26.530 --> 18:27.380] But, okay. [18:30.890 --> 18:37.620] The mission of ICANN is very much attached to one word and that's stability. [18:38.230 --> 18:43.210] Vint Cerf is one of the father of the internet or whatever, likes this word a lot. [18:43.410 --> 18:45.100] But he rarely defines it. [18:45.100 --> 18:52.060] It's not sure if he means technical stability, political stability, stability for economic use of the internet. [18:52.410 --> 18:53.880] Or whatever that shall be. [18:54.950 --> 19:01.800] When Stuart Lin took over as CEO of this company in the year 2001. [19:04.410 --> 19:12.010] He introduced something which I guess Paul Guerin from Namespace will explain you as being the pure evil of ICANN. [19:12.030 --> 19:13.140] And I would agree to that. [19:13.360 --> 19:15.060] That's the so-called ICP3. [19:15.300 --> 19:20.300] It's a policy saying, don't have any god next to me. [19:21.040 --> 19:33.010] So it says that for the use of stability of the internet, no one shall run a domain name system, a namespace, next to ICANN. [19:33.670 --> 19:36.600] Which means email could go the wrong way. [19:36.910 --> 19:42.470] You could come to a website that's not the website of the people you wanted to go to. [19:43.260 --> 19:51.080] And then the long exploration comes, of course, you know, the land of the evening will go under and we will all die and blah, blah, blah. [19:52.010 --> 19:58.030] So this is, yeah, also I guess the word unique authoritative root for DNS. [19:58.230 --> 19:59.860] Of course there is some truth in it. [19:59.970 --> 20:08.600] That if we have a .com top level domain and if we have an entry in the .com top level domain, a second level domain, let's say 2600.com. [20:08.620 --> 20:12.100] Of course we want to come to the 2600 side and not somewhere else. [20:12.600 --> 20:19.230] But this, I guess, is not a reason to say we shouldn't have Coca-Cola.sucks domain. [20:19.230 --> 20:29.990] Because the creation of top level domains where the registries would explicitly have a policy to not give the trademark owners their name. [20:30.300 --> 20:38.430] But give it to people who, let's say, want to report about consequences for the environment, for treating of human beings or whatever. [20:38.970 --> 20:44.790] This is all kinds of ideas that would, that will not likely take place into ICANN. [20:44.790 --> 20:56.490] Because we have this majority of nice intellectual property people telling us that it is simply not possible to give a domain name to someone who is not the owner of the trademark. [21:02.350 --> 21:10.190] So, I'll spend a few minutes to explain you what ICANN did already and what's the, yeah, reality of this. [21:10.790 --> 21:17.810] We have, maybe the most important thing ICANN did so far was introduction to the so-called UDRP. [21:17.810 --> 21:45.150] The UDRP is meant to be a universal policy or, yeah, domain name dispute resolution policy and is declared to be something which makes it more easy, more effective and less costful for trademark holders and people who have domain names and might be getting into contact with the owner of a trademark to solve this problem. [21:45.150 --> 21:49.450] So, of course, the official language for this is called cyber-squatting. [21:50.970 --> 21:56.910] There might be different views on this because you have to mention that on this planet we don't have one trademark system. [21:57.070 --> 22:00.650] We have almost so many trademark systems as we have governments and jurisdictions. [22:00.650 --> 22:19.390] And if you, let's say, as an American citizen create a top-level domain whatever.com and it does not violate any American copyright trademark, that doesn't mean that not at the other side of the planet someone might have this as a trademark for something. [22:19.390 --> 22:26.410] And at the end of the day, the UDRP will mean you will need a lot of money for lawyers or you will use the domain name. [22:27.110 --> 22:38.490] And so this is, let's say, this could be an own three hours or three days panel to discuss the UDRP and its details. [22:38.490 --> 22:44.030] It's, of course, created with very much support of WIPO, the World Intellectual Poverty Organization. [22:44.950 --> 22:52.310] Which, by the way, is one of the so-called fair treaty panels of the UDRP to decide about the things. [22:52.470 --> 22:54.110] So that's also very nice. [22:55.970 --> 22:59.150] We have some other impacts of this. [22:59.230 --> 23:02.110] Excuse me, this is a German example. [23:02.890 --> 23:08.330] For example, Greenpeace in Germany had the domain name oilofelf.de. [23:09.170 --> 23:23.010] So they reported about the environmental problems the oil company Elf creates by getting oil into African, out of African countries in special ways and so on. [23:23.430 --> 23:37.430] And there was a decision saying that, or the oil company said that it should not be, that it is not possible to use their trademarked name within a domain name to report about them. [23:37.610 --> 23:40.570] So the German court gave Greenpeace right. [23:40.830 --> 23:48.530] But we just had a similar decision in France these days from, I guess it was Exxon or Shell or something like that, where Greenpeace lost. [23:48.770 --> 23:56.650] So this is the direct impact of applying trademark ideas to the domain name system. [23:57.890 --> 24:05.610] We have other, I already explained to you about this situation that we might face if we come to a war or something like that. [24:05.850 --> 24:10.570] But we already have discussions that raise the question of jurisdiction of databases. [24:11.090 --> 24:21.570] For example, when the presidential election here in the United States took place and it was this kind of strange situation that no one knew who was the elected president. [24:21.570 --> 24:30.170] And there was a growing importance for a few hundred people who were electing, taking place at this election by letter voting. [24:30.610 --> 24:43.950] There was an Austrian based artist group who thought this is a great chance to be able to offer these 200, 300 people who vote by letter and would still be able to give their votes. [24:43.950 --> 24:50.430] So to make an important decision here about the outcome of the elections, to put that vote to an auction. [24:50.730 --> 24:53.110] So they thought this is a great fund. [24:53.390 --> 24:56.210] And they set up a domain called voteauction.com. [24:56.470 --> 25:01.630] So offering these people to just, you know, offer their vote to the highest bid. [25:02.710 --> 25:11.290] What happened is that there was a court decision in Minnesota because the court in Minnesota did not think this is very funny. [25:11.290 --> 25:13.550] And they closed the domain name. [25:13.810 --> 25:18.610] They didn't even inform the people in Austria and Vienna about this. [25:18.810 --> 25:21.510] They just found out their domain name doesn't work anymore. [25:21.970 --> 25:25.890] And I just give you this here as an example where we could say, wait a moment. [25:26.070 --> 25:31.750] This is United States Minnesota law being applied to Vienna, Austria, Europe. [25:32.490 --> 25:35.510] And this is, of course, just one example. [25:37.870 --> 25:42.190] There's also, but I guess I will make this a little short. [25:42.370 --> 25:48.230] There's, of course, a long discussion with an icon to how to get rid of this user-elected directors. [25:49.430 --> 25:57.550] There was a so-called clean sheet study given to some people called the At-Large Study Committee. [25:57.550 --> 25:59.510] That was Esther Dyson. [25:59.930 --> 26:02.930] She's the former head of ICANN. [26:03.030 --> 26:05.170] Then we have someone called Karl Bildt. [26:05.230 --> 26:11.330] He's former parliamentarian secretary of Sweden and other people. [26:11.570 --> 26:19.110] And they wrote some ideas on how to simulate or, let's say, bring up the legitimation of the ICANN board. [26:20.510 --> 26:33.310] Anyhow, when they represented, or when they did fulfill their mission and presented in March of this year, their paper saying, this is the way we could act. [26:33.470 --> 26:41.350] A few weeks before, Stuart Lin, the CEO of ICANN, already said, this is all a bunch of problems and it won't work out. [26:41.350 --> 26:49.630] And represented a whole restructuring thing for ICANN without user-elected and without any balance of interest ideas. [26:50.630 --> 26:55.230] Officially, we could say this was only his private opinion. [26:55.230 --> 26:57.910] It was not a directly official paper. [26:57.910 --> 27:14.150] But it led to a huge discussion where, at the end of the day, the ICANN's at large study committee paper was just taken and said, yes, we'll notice it and we'll come to it later. [27:14.750 --> 27:18.770] But right now, we're going to create an evolution reform committee. [27:18.770 --> 27:38.070] So what happened right now is that many people are unsatisfied with the ICANN not only from the user community, many people are unsatisfied with it being not very effective and not very fast by, for example, the creation of more generic top-level domains for more competition. [27:39.490 --> 27:55.330] And also, Karl Auerbach, who was elected from the American citizens to be user representative, he started, let's say, a little bit different fight, because he asked for access to financial records of ICANN's to find out what kind of lawyers would get, [27:55.490 --> 27:57.450] what kind of amount of money and so on. [27:58.290 --> 28:04.690] This access he did not get without the condition that he would have to sign a non-disclosure agreement. [28:04.970 --> 28:11.310] So this means, yes, he would get access to the record, but he would not be able to tell anyone what's in the records. [28:11.310 --> 28:21.210] And so he got some funding from the Electronic Frontier Foundation to fight this procedure Stuart Lynn has made. [28:21.890 --> 28:43.230] This might be an interesting story, but at the end of the day, for me it's very sad, because it means that Karl does not really attempt his position as ICANN director at the time, because his lawyer told him to not do so, because if he would get in direct contact with the people he just accuses, [28:43.430 --> 28:47.030] then this would limit his chances to win this lawsuit. [28:47.450 --> 28:52.010] If this is helpful, everyone has to decide on himself. [28:52.770 --> 29:11.310] But the problem is a little bit that by ICANN on the one hand side saying this user-elected thing, wait a moment, we first have to fix other problems, then going to so-called Evolution and Reform Committee, there is the question of how we will handle this institution. [29:11.610 --> 29:28.370] Because many American NGOs decided that their level of going to ICANN and trying to get the attention for, for example, privacy concerns, for concerns of freedom of speech versus intellectual property and so on, that they didn't want to go to ICANN anymore, [29:28.410 --> 29:30.790] because the board wouldn't listen to them. [29:31.050 --> 29:41.530] So they went to United States Department of Commerce, they went to Senate hearings and so on, and tried to get, and they did get the attention of U.S. Senate members. [29:43.110 --> 29:49.450] And this divorces the ICANN critics right now in a, I think, very dangerous situation. [29:49.450 --> 30:02.750] Because some of you here being American citizens, I might understand that if you say ICANN is a bunch of shit, and I go to my Senate member and he listens more to me, I might be understanding that from your position. [30:03.010 --> 30:17.670] But for me, as a European Internet user, I have problems with this because, tell me one single history, example from history whereby involvement of the United States Government and global policy making anything improved. [30:17.970 --> 30:20.510] I'm sorry to say, I don't know such an example. [30:20.790 --> 30:30.150] And this brings me into the problem of that the ICANN critics scene and the NGOs divorce right now a little bit. [30:30.490 --> 30:32.990] And this does not make me any happy. [30:33.390 --> 30:37.750] Anyhow, so there is a few current problems and a few options. [30:37.750 --> 30:47.450] Of course, I have Paul Garen here who runs Namespace, which is a complete alternative system of the domain name system, more or less. [30:48.590 --> 30:51.610] That's, of course, a practical escape, maybe. [30:51.850 --> 31:02.350] But the question is, of course, how reasonable, how realistic is it that the majority of Internet users will be able to use any alternatives. [31:02.350 --> 31:17.030] This, of course, has to do with this ICP3 problem saying, don't have any go up next to me, which means the majority of Internet service providers will simply not provide any alternative domain name system to their Internet users. [31:18.470 --> 31:23.210] So, we have the question... I'll get to you very soon. [31:23.370 --> 31:24.510] This is my last slide. [31:24.510 --> 31:33.030] So, the question of NGO representation in decision-making bodies such as ICANN is emerging. [31:33.630 --> 31:41.650] Because ICANN, of course, said this user representation in ICANN, they didn't see the point. [31:41.790 --> 31:42.950] They didn't understand it. [31:43.070 --> 31:52.450] And I think it's very important to be able to address specific issues where users are affected by policy bodies like ICANN is. [31:53.090 --> 32:10.150] The funding of such NGOs, of course, is a critical matter because if you look in what ways the industrial people, the intellectual property people come to ICANN meetings, you know, just go there and invite hundreds of people to dinners and so on. [32:10.370 --> 32:14.470] Of course, the NGOs are not possible to act that way all the way. [32:15.650 --> 32:28.450] Okay, we have various questions in what the Internet and domain name systems might be mixed up if governmental involvement on the one hand side goes much higher. [32:28.610 --> 32:32.550] And on the other hand side, the governments in between have fights, of course, right now. [32:32.830 --> 32:36.170] We all know the international situation is not very relaxed. [32:36.170 --> 32:41.790] And it becomes to the situation that it's able to realize this at ICANN as well. [32:42.050 --> 32:48.490] Of course, the IP44 routing is a problem itself. [32:48.970 --> 33:01.130] Most of you might know that if we have a serious threat of some countries or some, let's say, lines or some specific routers are not being on the net anymore, we will have problems. [33:01.330 --> 33:30.670] The NATO already announced to some technical European ISP colleagues of mine, that all specific routers must be AP46 capable, cause of the possibility of the explicit routing facilities you have in IP46, because this handmade routing tables in IP44 might not be work if we become in a situation where some lines are no more there. [33:32.410 --> 33:36.990] So, of course, we don't have only ICANN problems in the domain name system. [33:37.290 --> 33:50.070] We have also problems of, for example, the German government coming on the idea of spoofing DNS addresses, so banning access to content which is illegal in Germany, but it's legal in the United States. [33:50.070 --> 34:03.170] So, also, to say something nice about the United States, you still have your first amendment, and this means you're able to provide your, like, tryptome-like information on some stuff that cannot be distributed in countries like Germany. [34:03.170 --> 34:09.990] So, they start to use and political abuse the domain name system for restricting access to content. [34:10.950 --> 34:13.430] Okay, I'll get to Paul now. [34:14.170 --> 34:23.990] So, he's able to say something about the alternate route situation, and also we have some people in the audience who know the ICANN game a little bit and might like to comment that. [34:24.290 --> 34:42.330] Of course, the obvious last question is, or what I would like to say here is, that I guess this impact of free flow of information still needs to be explained a lot to governments, because if you look at things like the Cybercrime Treaty, it's a lot a law that... [34:42.330 --> 34:47.470] It's a collection of all kinds of problems free flow of information affects. [34:47.710 --> 34:49.670] For example, intellectual property. [34:49.870 --> 34:57.470] Of course, any intellectual property concepts based on control is bullshit now, because we have a technical reality of free flow of information. [34:57.630 --> 35:07.430] Then we have hate speech paragraphs in there, which is, of course, bullshit, because we don't have the situation where every country can have different sensitiveness on content. [35:07.430 --> 35:17.490] Then we have forbidding of distribution of computer viruses, which is, of course, completely bullshit in an environment of free flow of information. [35:17.650 --> 35:25.830] And also, we as KS Computer Club, we really looked, but we didn't found a single computer virus which cares about laws in its distribution mechanisms. [35:26.430 --> 35:29.350] And so stuff like this is still... [35:29.350 --> 35:40.250] And this is one of the problems you can really feel at ICANN, that it is money, many governments, governmental people there, who simply don't understand the issue. [35:40.530 --> 35:46.190] And sometimes the harm they do, they don't do by really wanting to do harm. [35:46.290 --> 35:48.130] They simply don't see the alternatives. [35:48.390 --> 35:53.450] And I think it's also the hacker scene's role should be to explain these alternatives much better. [35:53.630 --> 35:53.770] Okay. [36:03.050 --> 36:05.250] That's the ICANN conspiracy mind control. [36:05.250 --> 36:06.590] Hey, hi, everybody. [36:06.710 --> 36:09.450] I'm Paul Guerin, the founder of Namespace and Free the Media. [36:09.910 --> 36:12.250] And I just want to clarify something. [36:12.510 --> 36:19.250] There's been a lot of mischaracterization and misinterpretation of what the Namespace project has been about from its inception. [36:19.530 --> 36:24.530] And first of all, I want to say very clearly that Namespace is not... [36:24.530 --> 36:30.090] never was intended to be, and hopefully will never have to become, an alternate route. [36:30.790 --> 36:36.610] What Namespace has always been about from its first day is about public access and free expression. [36:37.890 --> 36:45.550] The question of alternate route is a difficult one because that basically would cause a split in the Internet. [36:45.550 --> 36:52.930] And in 1996, 97, I had a discussion with Rop Gonggrijp in Amsterdam over dinner. [36:53.730 --> 37:02.710] And we agreed that the danger that lay ahead in creating new domains would be a split in the net. [37:02.870 --> 37:06.350] And he talked about the old days of IRC when there used to be... [37:06.350 --> 37:11.650] You get on an IRC server and you're basically in touch with everybody else on IRC until that split. [37:11.650 --> 37:13.430] We agreed that was a bad thing. [37:13.890 --> 37:22.050] So the whole purpose of Namespace project, of creating new top-level domains, was about, first of all, network autonomy and sustainability. [37:22.290 --> 37:30.850] That is, that artists and hackers and people who are not part of the commercial mainstream can have a sustainable economic basis in order to build their own networks. [37:31.470 --> 37:35.930] So when I looked at this, and this was the part of a discussion that came out of the... [37:35.930 --> 37:40.990] kind of an international art, media art scene that was focused in Amsterdam. [37:40.990 --> 37:52.130] There was a group of conferences called The Next Five Minutes, of which I was an early participant and, you know, long-time member of, where we talked about these issues. [37:52.190 --> 37:59.330] And I looked at the scenarios down the road and I saw these threats to the disappearance of public access on the net. [37:59.330 --> 38:16.890] And in 1995, I wrote an essay, short essay, called The Disappearance of Public Space on the Net, where I basically predicted, quite accurately, the Disneyfication of cyberspace, where we are today, basically, where we are transformed from being producers and participants to consumers. [38:17.110 --> 38:19.230] And that's the direction that the net is going. [38:19.230 --> 38:41.730] So when I looked at this strategy, and, you know, not wanting to do something that was, you know, ineffective or not going to make a difference in the long run, I realized after assessing the structure and basically what it would take to effectively get new domains published in the legacy root zone, [38:41.790 --> 38:47.210] as we know it today, it turned out, in our assessment, to be a corporate matter. [38:47.670 --> 38:58.390] Because, in fact, the company, excuse me, who was in charge of controlling the contents of the root zone file was Network Solutions Incorporated. [38:58.730 --> 39:16.090] And when further explored, although it was Jon Postel who gave instructions to add top-level domains to the root, it was Network Solutions who actually made the edit to the root zone file, which, by the way, is a flat text file. [39:16.170 --> 39:17.250] Would you have a copy of that? [39:17.370 --> 39:20.410] Could you put that up on screen so people see what the root zone file looks like? [39:20.610 --> 39:29.850] Because, actually, there's a lot of chaos and noise and smoke and mirrors around this issue, but it really comes down to a simple text edit. [39:30.290 --> 39:38.070] As Andy noted earlier in his scenario, what if we were at war and we wanted Iraq or China or somebody to disappear from the Internet? [39:38.070 --> 39:45.350] Well, all that would require would be that their top-level domain glue, so to speak, would be deleted from that text file. [39:45.670 --> 39:51.750] And in basically no time at all, people wouldn't be able to access .IQ or .CN, for example. [39:51.990 --> 39:55.550] So, when I saw this happening... [39:55.550 --> 40:02.450] And, by the way, Namespace was actually activated in the summer of 1996, so there was nothing called ICAN at the time. [40:02.450 --> 40:08.070] It was IANA, Jon Postel in California, Network Solutions, who had the contract. [40:08.490 --> 40:12.790] So, Namespace started in 1997...1996, rather. [40:13.150 --> 40:20.330] And we seeded with about 30 proof-of-concept top-level domains that we initially published on our own. [40:20.410 --> 40:26.890] And it was just, you know, from the people who were involved in the early stages of the project, we felt that these were obvious choices. [40:27.070 --> 40:32.530] For example, .art, .music, .info, .sex, etc. [40:33.510 --> 40:42.410] And so, we set up machines that were running these top-level domain records with an amended root zone file. [40:42.530 --> 40:45.610] We had a copy of the legacy root zone, and we added these additional entries. [40:45.610 --> 40:55.810] So, when you would point to any of our resolvers, you would be able to type in, you know, joes.art, and you'd get somebody's page if it was registered under that domain. [40:56.570 --> 41:06.910] So, the question was, how could we get people, first of all, to understand this, which, you know, most people were still struggling to get on AOL and make that work. [41:07.690 --> 41:17.790] How could we get people to understand, first of all, the importance of the domain system, and also how easy it is to resolve, for example, what exists today, bush.sucks. [41:19.190 --> 41:34.310] So, we created a switcher application that would switch the local TCP settings in the DNS, and we freely distributed that along with instructions, how individual users could route around the exclusion of these top-level domains. [41:34.550 --> 41:42.430] But we saw, you know, it was never intended that our service was going to replace the existing, existing system. [41:42.530 --> 41:45.810] We were looking for a way to gain access. [41:46.450 --> 42:06.450] And going back to the corporate matter, as I said, what first came to my mind was, as a lot of people, you know, around 2600 seem to know very much about the phone system, that it was the deregulation of the phone system, the breakup of AT&T, that actually allowed the Internet to grow. [42:06.670 --> 42:07.790] So, what caused that? [42:07.790 --> 42:12.010] Well, in 1980s, there was a company around called MCI. [42:12.930 --> 42:13.810] Anybody heard of them? [42:14.570 --> 42:28.210] They weren't very big in those days, but they were attempting to provide alternative long-distance services, where you could just pick up, you know, your phone and dial an 11-digit code, and you would then be able to get to some cities. [42:28.510 --> 42:29.610] It wasn't full coverage. [42:29.610 --> 42:44.290] So, in 1978, I think it was, or 77, MCI challenged AT&T on the basis of antitrust, specifically for violations of the Sherman Act, which is denial of access to an essential facility. [42:44.590 --> 42:54.590] In the case of AT&T, who up until 1983 was the telephone company monopoly in America, and it was a government-sanctioned one at the time, too. [42:55.670 --> 43:04.490] It was ruled in 1983 that AT&T could not exclude MCI from patching into their local switch in order to route long-distance calls directly. [43:04.790 --> 43:07.450] So, now the rest we know is history. [43:07.770 --> 43:16.770] So, what Namespace's strategy was, then, was to take network solutions on a corporate battleground through the antitrust laws. [43:17.050 --> 43:22.690] And that was the basis for gaining access to the root zone. [43:22.850 --> 43:45.690] Now, when we first sent the letter, I signed a letter in March 11, 1997, announcing the fact that Namespace was in existence and that we were, at the time, publishing about 350 top-level domains that were suggested by a public survey that we were conducting on an ongoing basis where people could suggest new domains. [43:46.230 --> 43:48.470] So, we took thousands of emails from all over. [43:48.630 --> 43:50.270] People were pretty enthusiastic about it. [43:50.370 --> 44:00.410] And we asserted moderate editorial control, what we thought would make sense generically to serve the largest number of users, and we published those domains. [44:00.590 --> 44:07.050] So, I sent the letter of request on behalf of Namespace to Network Solutions, and they responded with a phone call. [44:07.190 --> 44:13.450] And I have the audio recording of that historical telephone call, which I would play, but we're really short on time. [44:13.590 --> 44:14.490] It runs about 10 minutes. [44:14.650 --> 44:17.690] But, what was established in that phone call is very telling. [44:17.970 --> 44:30.430] Because in 1997, and of course, our due diligence proved this before we were able to articulate our antitrust strategy, was that there was no articulated contractual chain of command. [44:31.070 --> 44:38.570] So, when we first called Network Solutions, basically, they said, well, it's not up to us to decide what top-level domains in. [44:38.570 --> 44:42.670] And we do what IANA tells us to do, what Jon Postel tells us to do. [44:42.830 --> 44:51.730] And when questioned further by our then-attorney, Michael Donovan, they said, well, do you have a contract with IANA? [44:51.910 --> 44:54.810] And their response was, we have a contract with IANA. [44:54.950 --> 44:57.250] No, we don't have a contract with IANA. [44:57.450 --> 45:14.190] And so, therefore, it was clear that the contract which did apply was the cooperative agreement between the National Science Foundation and Network Solutions, which, in fact, spelled out the discretionary power to allow Network Solutions to make changes to the address system, [45:14.210 --> 45:15.090] as they saw fit. [45:16.210 --> 45:17.930] So, what does that tell you? [45:18.090 --> 45:24.250] It tells you that the Network Solutions, okay, I got five minutes, could make this change. [45:24.250 --> 45:32.230] But they refused, and they deferred first to the NSF, who said that, you know, don't take any move on this now. [45:32.330 --> 45:54.810] And then it was then bumped up the tree to the NTIA, to the Commerce Department, who in 1998 took over the cooperative agreement from Network Solutions and amended it to put in writing Amendment 11, which states that the Department of Commerce has to issue a written directive to Network Solutions to add top-level domains. [45:56.670 --> 46:06.350] That rewriting of the contract created a situation, and at the same time that happened was around the creation of ICANN and the death of Jon Postel. [46:06.470 --> 46:12.410] All these incidents happened within maybe a two-week period of each other, September 1998. [46:13.670 --> 46:25.010] At that point, after much other spooky things that happened along the way, which I don't have time to talk about now, the condition had changed. [46:25.310 --> 46:33.530] And this gave the Court of Appeals the ability to find Network Solutions immune from the antitrust law. [46:34.690 --> 46:48.850] And it says here, although NSI's antitrust charges were immunized in the namespace case, the Court was careful not to extend the antitrust protection into the future and was clear to state that simply having a contract with the government does not, by default, [46:49.090 --> 46:50.110] confer immunity. [46:50.930 --> 47:00.590] Namespace is surely correct in arguing that the existence of a government contract does not automatically confer a federal agency absolute antitrust immunity onto a private contractor. [47:00.730 --> 47:13.010] However, the conduct being challenged by Namespace in this appeal was compelled by the explicit terms of NSI's agreement with the government agency and by the government's policies regarding proper administration of the DNS. [47:13.490 --> 47:18.670] So in other words, it was a policy decision and not a legal decision. [47:18.790 --> 47:21.210] And so the antitrust challenge still remains. [47:21.390 --> 47:25.570] However, I don't see that as the way to go. [47:25.670 --> 47:32.790] And I think ICANN, as I had seen from the beginning, is really mainly smoke and mirrors because where the power lies is the Department of Commerce. [47:32.790 --> 47:38.590] And in fact, I agree with the concept of the internationalization of the net and things like that. [47:38.730 --> 47:44.870] But one thing you could say our lawsuit accomplished is that we smoked them out because there was not an articulated chain of command. [47:45.630 --> 47:55.290] Namespace's argument was that the DNS and the root domain is a global commons and that there should be non-discriminatory and equal access as the antitrust laws apply. [47:55.570 --> 48:02.950] Now, when the government stepped in and asserted their authority, basically what they're doing is denying us our right to publish. [48:03.410 --> 48:04.530] And what does that sound like to you? [48:04.630 --> 48:06.710] Sounds like a First Amendment violation. [48:07.110 --> 48:10.890] So the strategy to go forward now is... [48:11.730 --> 48:13.790] I have an organization called Free the Media. [48:13.970 --> 48:19.650] Free the Media is transitioning to the nonprofit management of the top-level domains that Namespace has published. [48:20.070 --> 48:33.450] And for example, we are the publishers of .sucks and the policy that Andy discussed earlier where a trademark holder wouldn't be allowed to register Microsoft.sucks, for example, would be the case. [48:33.630 --> 48:35.730] So they're telling me to wrap up now. [48:36.050 --> 48:38.750] I wish I had about ten more minutes to go into this. [48:38.910 --> 48:41.150] But basically, you can come by. [48:41.290 --> 48:42.470] We're going to have a table here tomorrow. [48:43.550 --> 48:58.230] You can support our organization by joining Free the Media and by registering in some of the new domains and petitioning the Department of Commerce for access to Legacy Root so we can exercise our rights to free speech in public access. [48:58.410 --> 48:58.910] Thanks a lot. [48:59.030 --> 49:03.010] By the way, there's a new book out called Ruling the Root, MIT Press. [49:03.010 --> 49:06.270] This is by Professor Milton Mueller, Syracuse University. [49:06.270 --> 49:11.190] I suggest you read it because this does lay out some of the history. [49:11.370 --> 49:11.890] Thanks.