ICANN

ICANN's Domain Shift Leaves 22,000 Users Facing Security Risks

ICANN's decision to drop third-level .name domains is a quiet shift with loud consequences. By letting Verisign phase out these registrations, roughly 22,000 users face a real risk: their released second-level domains…

4 min readInfoQ
ICANN's Domain Shift Leaves 22,000 Users Facing Security Risks

Twenty-two thousand people woke up one morning to discover that the web addresses they had built their identities around were being quietly retired. ICANN's approval of Verisign's plan to drop third-level .name registrations is not a technical footnote. It is a decision about who controls the architecture of trust online, and it deserves more scrutiny than a quiet regulatory handoff. Neil Fraser's disclosure matters because it exposes how easily a policy change can ripple into real-world consequences: released second-level domains can be squatted on, impersonated, and weaponized. This is not hypothetical. It is the raw material of phishing campaigns and credential theft.

What makes this story uncomfortable is that the logic behind the move is not irrational. Third-level .name domains, like `john.doe.name`, never achieved the cultural or commercial traction that their promoters imagined. Usage declined. Verisign, as the registry operator, saw a product with a shrinking user base and made a business decision. ICANN, the steward of the domain name system, signed off. On paper, this is efficient portfolio management. In practice, it treats 22,000 registrants as legacy baggage, people whose digital presence is being repurposed without their consent. The users pushing back with legal options are not being paranoid. They are asking a fair question: why should a registry's financial calculus override the stability of an address that people have used for years, sometimes decades, to receive email and host personal sites?

There is a broader lesson here that connects to how we handle data ownership and system changes in the AI era. When platforms alter their terms, deprecate APIs, or sunset features, the burden always falls on the individual. We saw this with the recent Gemini's Brief Hacks Highlight AI's Evolving Data Access Landscape, where the conversation was less about the hacks themselves and more about who gets to decide what "appropriate" access means. Similarly, the .name situation is not just about a domain suffix. It is about whether users have a meaningful voice when the infrastructure they depend on shifts beneath them. And while tools like Unlock Your Codebase: Explore AI-Powered Knowledge Graphs for Seamless Development promise to make data more navigable and portable, they do not solve the underlying power imbalance between the people who own the platform and the people who merely use it.

Our take is blunt: this is a preventable erosion of trust, and ICANN should not have waved it through without a clearer transition plan for the affected registrants. If you are one of the 22,000, your options are not just legal. You can migrate your identity to a second-level domain now, before the rug is pulled, and you should. But the deeper question is structural. If a registry can dissolve a namespace because it is unprofitable, what stops it from doing the same to other TLDs that fall out of fashion? The takeaway to quote: "A domain name is only as stable as the business case behind it." Watch how Verisign handles the transition period. If released domains start resolving to parked ads or, worse, lookalike pages, the legal challenges will not just be about .name. They will be about the fundamental promise of the domain name system itself.

From InfoQ

Neil Fraser's disclosure highlights a regulatory change affecting the .name top-level domain. Following ICANN's approval, Verisign will eliminate third-level registrations due to declining usage. This affects about 22,000 registrants and raises security concerns, as released second-level domains could be exploited. Affected users are considering legal options to challenge the decision.

Read the original at InfoQ