Time to Chime In on Domain Transfers

ICANN’s Proposed Domain Transfer Changes: Streamlining or Sacrificing Security?

Arrows pointing right and left with the words 'domain transfers' in white

The Internet Corporation for Assigned Names and Numbers (ICANN), the organization responsible for coordinating the internet’s domain name system (DNS), is currently seeking public feedback on a Working Group’s Initial Report concerning proposed changes to the domain transfer process. These proposed changes aim to modernize and streamline the process, but concerns have been raised about potential security implications.

The Initial Report outlines a series of modifications to the inter-registrar domain transfer process, with the most significant being the elimination of the Form of Authorization (FOA) step. This change has sparked debate within the domain name community, with some arguing that it will simplify transfers and others fearing it could increase the risk of fraudulent activity.

Understanding the Current Domain Transfer Process

To fully appreciate the potential impact of these proposed changes, it’s essential to understand how domain transfers currently work. The standard domain transfer process typically involves the following steps:

  1. Authorization Code Acquisition: The domain owner obtains an authorization code (also known as an EPP code or transfer code) from their existing registrar. This code serves as proof that the domain owner has authorized the transfer.
  2. Transfer Initiation: The domain owner provides the authorization code to the gaining registrar (the registrar they wish to transfer the domain to). The gaining registrar then verifies the code and initiates the transfer request.
  3. Form of Authorization (FOA): The losing registrar (the registrar the domain is currently with) sends a notification, known as the Form of Authorization, to the domain owner. This FOA informs the domain owner of the pending transfer and provides them with a period, typically up to five days, to cancel the request if it’s unauthorized.

The Proposed Changes: Eliminating the Form of Authorization

The proposed changes would eliminate step #3, the Form of Authorization, from the domain transfer process. Instead, a notification would be added to step #1. This means that when a domain owner requests an authorization code, their registrar would be required to notify them of the request. The idea behind this change is to speed up the transfer process and make it more efficient.

However, critics argue that this change could weaken domain security. The Form of Authorization currently provides a crucial opportunity for domain owners to identify and stop fraudulent transfer attempts. By eliminating this step, domain owners may not be aware of a fraudulent transfer until after it has already been completed.

The Security Concerns: A Potential Step Backwards?

The core concern revolves around the potential for increased fraudulent domain transfers. The FOA acts as a critical safety net, alerting domain owners to unauthorized transfer attempts and giving them time to intervene. Removing this step could leave domain owners vulnerable to malicious actors who may attempt to steal their domain names.

Consider a scenario where a cybercriminal gains access to a domain owner’s email account. They could then request an authorization code without the domain owner’s knowledge. Under the current system, the FOA would alert the domain owner to the pending transfer, allowing them to contact their registrar and stop it. However, under the proposed system, the domain owner might not receive any notification until the transfer is complete, potentially losing control of their domain.

While the proposed changes include a notification at the authorization code request stage, critics argue that this may not be sufficient. Even if the domain owner receives an email notification immediately after the authorization code is requested, the transfer could still be completed before they have a chance to react. This is because the transfer process can often be completed within minutes.

Potential Backdoor Security Measures: A New Burden for Domain Owners?

Another concern is that registrars might implement their own “backdoor” security measures to compensate for the removal of the FOA. This could involve delaying the issuance of authorization codes to allow domain owners more time to verify the request. While this might improve security, it could also create a new burden for domain owners, forcing them to wait longer to complete legitimate domain transfers.

Imagine a domain owner who wants to quickly transfer their domain to a new registrar to take advantage of a better price or service. Under the current system, they can obtain the authorization code and initiate the transfer process relatively quickly. However, if registrars implement delays in issuing authorization codes, the domain owner would have to wait before they can complete the transfer, potentially losing out on the opportunity.

The Importance of Transfer Rollback Procedures

ICANN’s Working Group is reportedly working on transfer rollback procedures in a later phase. These procedures would allow domain owners to reverse fraudulent transfers after they have been completed. However, critics argue that it doesn’t make sense to approve a less secure transfer system before these rollback procedures are fully developed and implemented.

It’s like building a house without a foundation. Approving a less secure transfer system without adequate rollback procedures could leave domain owners vulnerable to fraud and create a chaotic situation in the event of a successful attack. A more prudent approach would be to develop and implement robust rollback procedures before making any changes that could weaken domain security.

A Call for Feedback and Further Consideration

The proposed changes to the domain transfer process raise important questions about the balance between efficiency and security. While streamlining the transfer process is a laudable goal, it should not come at the expense of domain security.

ICANN’s decision to seek public feedback on this issue is commendable. It’s crucial for domain owners, registrars, and other stakeholders to carefully consider the potential implications of these changes and provide their input to ICANN. Only through open and transparent dialogue can we ensure that the domain transfer process is both efficient and secure.

My Submitted Comment to ICANN

To contribute to the ongoing discussion, I submitted the following comment to ICANN:

Thank you for your work modernizing domain transfers.

I’m concerned about the decision to remove the losing registrar’s Form of Authorization (FOA). With the FOA, a domain owner could be made aware of a fraudulent transfer and have time to contact the registrar to stop it. Under the proposed system, the domain registrant likely won’t learn of a transfer until after the transfer is complete.

While this will make transfers easier and in the words of the Initial Report instant, I’m concerned that it will result in fraudulent transfers.

It would be interesting to hear from registrars about how many times customers try to stop fraudulent transfers after receiving the FOA.

There is a backdoor security measure that registrars could undertake to reduce the chances of this happening: domain registrars could delay the time between people asking for Transfer Authorization Codes (TACs) and issuing them to customers. I fear that registrars will feel compelled to implement this backdoor security measure, which will ultimately burden domain registrants; they will have to request the code and then wait a long time for it to arrive before providing it to the gaining registrar. They would not be able to complete the domain transfer process in one sitting.

I understand the Working Group is working on transfer rollback procedures in a later phase. Approving a less secure transfer system prior to determining rollback features doesn’t make sense to me.

Conclusion: Proceed with Caution

ICANN’s proposed changes to the domain transfer process have the potential to significantly impact the domain name ecosystem. While streamlining the transfer process is a desirable goal, it’s crucial to carefully consider the potential security implications. Removing the Form of Authorization could increase the risk of fraudulent domain transfers, and registrars might implement their own security measures that could burden domain owners.

It’s essential for ICANN to proceed with caution and carefully evaluate the feedback received from the public. A more prudent approach would be to develop and implement robust transfer rollback procedures before making any changes that could weaken domain security. By prioritizing security and transparency, ICANN can ensure that the domain transfer process remains both efficient and secure for all stakeholders.