Skip to content

Davey Winder

delivering award-winning technology journalism since 1991

  • home
  • about me
  • follow me on mastodon
  • privacy policy
  • Toggle search form
Stencils of the word private

ICANN struggles to make WHOIS GDPR compliant without increasing cyber-crime

Posted on April 6, 2018April 6, 2018 By Davey Winder

The General Data Protection Regulation (GDPR) could kibosh WHOIS requests and make the job of incident response much harder indeed

On 25 May the General Data Protection Regulation (GDPR) will come into effect, and could make the job of incident response a whole lot harder for security researchers. The Internet Corporation for Assigned Names and Numbers (ICANN) could find itself on the wrong end of fines up to four percent of global revenue unless it makes changes to the WHOIS system of querying domain name registrant databases. Currently, this type of registrant research is used as an investigative tool by security professionals when it comes to tackling everything from phishing scams to malware distribution sites. It’s often something of a first stop during an incident response, especially where a legitimate site has been compromised to distribute malware without the registered owners knowing.

While most domain name registrars already offer a privacy protection service that hides registrant name, address and telephone contact from the public-facing WHOIS search, this doesn’t appear to be enough to satisfy GDPR affirmative consent requirement. As a result, ICANN has proposed both redacting personal data from WHOIS and an accreditation process to verify the legitimacy of those (security professionals, law enforcement, journalists) who use it within their investigations.

Click here to read complete article

Analysis Tags:Cybercrime, GDPR, ICANN, incident response, WHOIS

Post navigation

Previous Post: Common-sense GoScanSSH author avoids infecting high-risk targets
Next Post: Reputation rebuilding on cybersecurity is key for the NHS

Related Articles

Forget Passwords, This New Tech Is Nearly Hacker-Proof, 1Password Says Analysis
Gmail Hackers Leave Vital Clues Behind—Check These 3 Things Now Analysis
No, 1Password Has Not Just Been Hacked—Your Passwords Are Safe Analysis
New Critical Security Warning For iPhone, iPad, Watch, Mac—Attacks Underway Analysis
New Emergency Chrome Security Update After Critical iOS 16.6.1 Release Analysis
New iPhone iOS 16 Bluetooth Hack Attack—How To Stop It Analysis

Categories

Post Archive

Tags

0day Analysis Android Apple Apps breach bug bounty Business Chrome crime Cybercrime Data Protection Encryption Enterprise Google Government Hackers Hacking Health healthcare industry iOS IoT iPhone Malware Microsoft News NHS Opinion passwords Phishing Privacy ransomware Research Russia Samsung threat intelligence Twitter Update Vulnerabilites vulnerabilities Vulnerability Windows Windows 10 zero-day

Copyright © 2025 Davey Winder .

×
Cookies
We serve cookies. If you think that's ok, just click "Accept all". You can also choose what kind of cookies you want by clicking "Settings". Read our cookie policy
Settings Refuse all Accept all
Cookies
Choose what kind of cookies to accept. Your choice will be saved for one year. Read our cookie policy
  • Necessary
    These cookies are not optional. They are needed for the website to function.
  • Statistics
    In order for us to improve the website's functionality and structure, based on how the website is used.
  • Experience
    In order for our website to perform as well as possible during your visit. If you refuse these cookies, some functionality will disappear from the website.
  • Marketing
    By sharing your interests and behavior as you visit our site, you increase the chance of seeing personalized content and offers.
Save Refuse all Accept all
GDPR Cookie Policy