« Rogue B$ anyone?
Boooo! ICANN Flip-flops. »

ICANN de-accredits EstDomains!

October 29th, 2008

I have blogged on this in the past, and everyone in the security arena is also commenting on this presently. I am very pleased to see that EstDomains has been de-accredited by ICANN, the governing entity that coordinates the allocation and assignment of the three sets of unique identifiers for the Internet.

In short, they have pulled the plug on EstDomains ability to register websites.

The reason they invoked for the de-accreditation was that The CEO of EstDomains, Vladimir Tsastsin, has been convicted of credit card fraud, document forgery, and money laundering, and sentenced to 3 years of prison in Estonia. Apparently a criminal conviction violates a clause in the agreement that ICANN had with EstDomains, and allowed them to terminate the RAA (Registrar Accreditation Agreement).

This feels an awful lot like Al Capone being sent to jail for tax evasion, and not for the numerous other crimes he committed. That ICANN had to wait for something like this to take action, when EstDomains active participation in the cyber crime ecosystem has been the worst kept secret, for so long, clearly demonstrates that they intend to continue with their “we don’t police” approach to registrar accreditation.

Going to jail for tax evasion, as befell Al Capone, is still going to jail. Having your Registrar status revoked for having a criminal record, rather than for brazenly providing domain registrar services to the criminal element, is still having your registrar status revoked.

At least it is a step in the right direction. Mikko Hyppönen of F-secure has a very informative blog entry on exactly just how long this has been going on. http://www.f-secure.com/weblog/

And now, ICANN is looking for someone to take over the bulk of the sites that EstDomains managed.
http://www.icann.org/en/announcements/announcement-2-28oct08-en.htm

I don’t envy whoever gets this job, but I do have a few suggestions: Compare the approx 280,000 domains against all the major blacklists. Anyone on the list gets dropped. Examine the balance by parsing it through the Google safe browsing API, Drop whatever else turns up.

This may feel a little too much like “throwing away the baby with the bathwater” to some, but it beats the alternative of just pulling the plug on the whole lot. Besides, I suspect that the number of domains will be considerably smaller after that process…

Jean “TinFoilHatMan” Taggart

    This entry was posted on Wednesday, October 29th, 2008 at 11:53 am and is filed under Malware Trends. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.