Re: New DNS vulnerability: political overreach
According to Tom Beecher via NANOG <nanog@lists.nanog.org>:
My concern, and this is where I think the law could stand improvement, is that the court co-opted a distant third party in its remedy for the dispute. They interfered with a contract between Verisign and one of its registrars, neither of which was a party to the lawsuit about Kick's behavior, neither of which was accused of any wrongdoing, and neither of which was more than tenuously operating within the court's geographical jurisdiction. That doesn't seem like something the law should allow, at least not of a state court.
I agree. But I don't think it's a case of the law needing improvement. This is a problem with the Texas state courts ruling on things that seem to be very clearly a federal question , which they have been doing with increasing regularity in the last decade or so.
That's the way courts work in the US. If someone files a case in a state court, the court will assume it has jurisdiction unless the defendant argues otherwise. That's why it's such a bad idea to default: the court's not going to make your argument for you. I have my concerns about Texas courts, but I believe in this kind of situation any state court would have done the same. R's, John -- Regards, John Levine, johnl@taugh.com, Primary Perpetrator of "The Internet for Dummies", Please consider the environment before reading this e-mail. https://jl.ly
That's the way courts work in the US. If someone files a case in a state court, the court will assume it has jurisdiction unless the defendant argues otherwise. That's why it's such a bad idea to default: the court's not going to make your argument for you.
Generally yes, but there are exceptions. There are certain claims that are exclusively in the federal jurisdiction , and state courts cannot hear them. There are also instances where if a state law says its courts do not have to hear a given matter, they cannot be forced to hear it on federal grounds, unless the federal statute expressly requires it. ( Douglas vs NY, NH & HR , 279 US 377 (1929 ) ) .Violent agreement with you that risking default in any case, even if it seems absurd, is a bad strategy. Getting back to the technical issue though, all these things do is reinforce the thought that if you are using a domain for commercial purposes , you probably want to strongly consider one managed by a non-US registrar if possible, as long as the legal environment is such that any state AG trying to make hay can just yeet you offline on a whim. On Mon, Jul 27, 2026 at 11:13 PM John R. Levine via NANOG < nanog@lists.nanog.org> wrote:
According to Tom Beecher via NANOG <nanog@lists.nanog.org>:
My concern, and this is where I think the law could stand improvement, is that the court co-opted a distant third party in its remedy for the dispute. They interfered with a contract between Verisign and one of its registrars, neither of which was a party to the lawsuit about Kick's behavior, neither of which was accused of any wrongdoing, and neither of which was more than tenuously operating within the court's geographical jurisdiction. That doesn't seem like something the law should allow, at least not of a state court.
I agree. But I don't think it's a case of the law needing improvement. This is a problem with the Texas state courts ruling on things that seem to be very clearly a federal question , which they have been doing with increasing regularity in the last decade or so.
That's the way courts work in the US. If someone files a case in a state court, the court will assume it has jurisdiction unless the defendant argues otherwise. That's why it's such a bad idea to default: the court's not going to make your argument for you.
I have my concerns about Texas courts, but I believe in this kind of situation any state court would have done the same.
R's, John -- Regards, John Levine, johnl@taugh.com, Primary Perpetrator of "The Internet for Dummies", Please consider the environment before reading this e-mail. https://jl.ly
_______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/4ZHEPJJC...
On Jul 28, 2026, at 9:32 PM, Tom Beecher via NANOG <nanog@lists.nanog.org> wrote:
Getting back to the technical issue though, all these things do is reinforce the thought that if you are using a domain for commercial purposes , you probably want to strongly consider one managed by a non-US registrar if possible,
Again, this was a takedown at the registry, i.e., Verisign, not the registrar. To avoid this sort of action, you’d have to use a top-level domain operated by a company outside of the US, e.g., a ccTLD not in US/PR/AS/GU/VI/MP/(UM) or one of the new gTLDs not operated by a company subject to US jurisdiction (I’m too lazy to look that up). Of course, going that route will probably result in your customers getting confused because you don’t have a .COM domain name and, of course, you’d be subject to the legal jurisdiction of the country the TLD is operated in. Regards, -drc
Again, this was a takedown at the registry, i.e., Verisign, not the registrar. To avoid this sort of action, you’d have to use a top-level domain operated by a company outside of the US, e.g., a ccTLD not in US/PR/AS/GU/VI/MP/(UM) or one of the new gTLDs not operated by a company subject to US jurisdiction (I’m too lazy to look that up). Of course, going that route will probably result in your customers getting confused because you don’t have a .COM domain name and, of course, you’d be subject to the legal jurisdiction of the country the TLD is operated in.
Yes, s/registrar/registry/ in my message. But beyond that, yes. This has been true since 2012 when the DOJ first started performing domain seizures. A non-US entity only had to really pay attention to US federal law; If you weren't doing anything with your domain that might run afoul there, you were pretty safe that your domain wouldn't be seized. ( Acknowledging here that the justifications for this action have been expanding since 2012, which is Not Great either. ) Now, if this Texas action sticks as precedent, any **alleged** violation of ANY US law ( federal / state / local / territorial) allows a court to issue an order to take your domain down if it's from a US registry. Which of course opens the door to non-US registries doing the same things (if they aren't already), and everything just gets more fragmented and stupid. I applaud all the legal professionals who fight to prevent this stupidity. Truly underappreciated. On Tue, Jul 28, 2026 at 11:57 AM David Conrad <drc@virtualized.org> wrote:
On Jul 28, 2026, at 9:32 PM, Tom Beecher via NANOG <nanog@lists.nanog.org> wrote:
Getting back to the technical issue though, all these things do is reinforce the thought that if you are using a domain for commercial purposes , you probably want to strongly consider one managed by a non-US registrar if possible,
Again, this was a takedown at the registry, i.e., Verisign, not the registrar. To avoid this sort of action, you’d have to use a top-level domain operated by a company outside of the US, e.g., a ccTLD not in US/PR/AS/GU/VI/MP/(UM) or one of the new gTLDs not operated by a company subject to US jurisdiction (I’m too lazy to look that up). Of course, going that route will probably result in your customers getting confused because you don’t have a .COM domain name and, of course, you’d be subject to the legal jurisdiction of the country the TLD is operated in.
Regards, -drc
On Tue, 28 Jul 2026, Tom Beecher wrote:
Now, if this Texas action sticks as precedent, any **alleged** violation of ANY US law ( federal / state / local / territorial) allows a court to issue an order to take your domain down if it's from a US registry. Which of course opens the door to non-US registries doing the same things (if they aren't already), and everything just gets more fragmented and stupid.
I applaud all the legal professionals who fight to prevent this stupidity. Truly underappreciated.
Once again, this takedown was a screwup due to the target not responding to the suit and the court accepting all the assertions in the complaint, because that's what courts do when a defendant doesn't reply. It's not a precedent in any meaningful sense other than "don't do that." R's, John
Once again, this takedown was a screwup due to the target not responding to the suit and the court accepting all the assertions in the complaint, because that's what courts do when a defendant doesn't reply. It's not a precedent in any meaningful sense other than "don't do that."
Respectfully disagree, but I don't see much benefit to debating this further. On Tue, Jul 28, 2026 at 1:44 PM John R. Levine <johnl@iecc.com> wrote:
On Tue, 28 Jul 2026, Tom Beecher wrote:
Now, if this Texas action sticks as precedent, any **alleged** violation of ANY US law ( federal / state / local / territorial) allows a court to issue an order to take your domain down if it's from a US registry. Which of course opens the door to non-US registries doing the same things (if they aren't already), and everything just gets more fragmented and stupid.
I applaud all the legal professionals who fight to prevent this stupidity. Truly underappreciated.
Once again, this takedown was a screwup due to the target not responding to the suit and the court accepting all the assertions in the complaint, because that's what courts do when a defendant doesn't reply. It's not a precedent in any meaningful sense other than "don't do that."
R's, John
On 28 July 2026 17:47:41 CEST, Tom Beecher via NANOG <nanog@lists.nanog.org> wrote:
That's the way courts work in the US. If someone files a case in a state court, the court will assume it has jurisdiction unless the defendant argues otherwise. That's why it's such a bad idea to default: the court's not going to make your argument for you.
Generally yes, but there are exceptions. There are certain claims that are exclusively in the federal jurisdiction , and state courts cannot hear them. There are also instances where if a state law says its courts do not have to hear a given matter, they cannot be forced to hear it on federal grounds, unless the federal statute expressly requires it. ( Douglas vs NY, NH & HR , 279 US 377 (1929 ) )
.Violent agreement with you that risking default in any case, even if it seems absurd, is a bad strategy.
Getting back to the technical issue though, all these things do is reinforce the thought that if you are using a domain for commercial purposes , you probably want to strongly consider one managed by a non-US registrar if possible, as long as the legal environment is such that any state AG trying to make hay can just yeet you offline on a whim.
On Mon, Jul 27, 2026 at 11:13 PM John R. Levine via NANOG < nanog@lists.nanog.org> wrote:
According to Tom Beecher via NANOG <nanog@lists.nanog.org>:
My concern, and this is where I think the law could stand improvement, is that the court co-opted a distant third party in its remedy for the dispute. They interfered with a contract between Verisign and one of its registrars, neither of which was a party to the lawsuit about Kick's behavior, neither of which was accused of any wrongdoing, and neither of which was more than tenuously operating within the court's geographical jurisdiction. That doesn't seem like something the law should allow, at least not of a state court.
I agree. But I don't think it's a case of the law needing improvement. This is a problem with the Texas state courts ruling on things that seem to be very clearly a federal question , which they have been doing with increasing regularity in the last decade or so.
That's the way courts work in the US. If someone files a case in a state court, the court will assume it has jurisdiction unless the defendant argues otherwise. That's why it's such a bad idea to default: the court's not going to make your argument for you.
I have my concerns about Texas courts, but I believe in this kind of situation any state court would have done the same.
R's, John -- Regards, John Levine, johnl@taugh.com, Primary Perpetrator of "The Internet for Dummies", Please consider the environment before reading this e-mail. https://jl.ly
_______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/4ZHEPJJC...
_______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/6DAHEFBA... Note: As I understand it, a non-US registry isn't sufficient - it must be under another country's ccTLD, as all gTLDs sign a contract with ICANN to enforce US law.
Many ccTLDs are also, unexpectedly, run by US entities or entities associated with the US, as we saw recently when a partially US-owned registry seized t.me from Telegram.
On Wed, Jul 29, 2026 at 3:03 AM Kevin Tillery via NANOG <nanog@lists.nanog.org> wrote:
Note: As I understand it, a non-US registry isn't sufficient - it must be under another country's ccTLD, as all gTLDs sign a contract with ICANN to enforce US law.
Hi Kevin, Not exactly. The contract between the TLD registry and ICANN operates under US law which means that a US court can order ICANN to make a technically feasible change to their relationship with any TLD registry. But the court can only order iCANN to do things that it is -possible- for ICANN to unilaterally do. Regards, Bill Herrin -- For hire. https://bill.herrin.us/resume/
participants (5)
-
David Conrad -
John R. Levine -
Kevin Tillery -
Tom Beecher -
William Herrin