New DNS vulnerability: political overreach
A Texas court has suspended the .com domain of a Dutch porn site which doesn't have any business presence in Texas, because it doesn't comply with Texas rules about porn (which are extremely onerous): https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxt... Clearly the US is not fit to manage top-level domains (other than .us of course) even though it ended up with them by historical accident. It worked for a while but now it's not working any more. Has anyone come up with any plan to solve this and make the DNS more neutral? As a first step I'd think about experimenting with a DNS resolver that would move all US TLDs to subdomains of .us. However that obviously would just break the current internet for whoever is using this resolver, at least due to widespread use of vhosts. Kevin
Can we keep politics and personal opinions separate and independent of the technical aspects of the issue at hand (if there are any)? Per the NANOG list info page: "Appropriate topics include: routing; broad-based engineering problems/issues/solutions; outages; performance measurement; evolving wide-area technologies; exchange points; traffic engineering; operational experience; ISP security; and trouble ticket systems." Is there an actual legit technical issue here that needs discussion or solving? ---- Andy Ringsmuth andy@andyring.com Love others, encourage others, help others.
On Jul 19, 2026, at 6:05 AM, Kevin Tillery via NANOG <nanog@lists.nanog.org> wrote:
A Texas court has suspended the .com domain of a Dutch porn site which doesn't have any business presence in Texas, because it doesn't comply with Texas rules about porn (which are extremely onerous):
https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxt...
Clearly the US is not fit to manage top-level domains (other than .us of course) even though it ended up with them by historical accident. It worked for a while but now it's not working any more. Has anyone come up with any plan to solve this and make the DNS more neutral?
As a first step I'd think about experimenting with a DNS resolver that would move all US TLDs to subdomains of .us. However that obviously would just break the current internet for whoever is using this resolver, at least due to widespread use of vhosts.
Kevin _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/55UTA3Q4...
Considering that this is the second time in less than a week that a company has had their domain taken off line at the Registrar level (https://techcrunch.com/2026/07/14/telegrams-shortlink-domain-is-back-online-...) I do think there is a legitmate technical concern here, though I'd argue it is far from new. It is a scenario that most companies don't account for, but depending on the type of business you are in, it is a very real concern and you should have a response plan in place. allan On Sunday, July 19th, 2026 at 9:08 AM, Andy Ringsmuth via NANOG <nanog@lists.nanog.org> wrote:
Can we keep politics and personal opinions separate and independent of the technical aspects of the issue at hand (if there are any)? Per the NANOG list info page:
"Appropriate topics include: routing; broad-based engineering problems/issues/solutions; outages; performance measurement; evolving wide-area technologies; exchange points; traffic engineering; operational experience; ISP security; and trouble ticket systems."
Is there an actual legit technical issue here that needs discussion or solving?
---- Andy Ringsmuth andy@andyring.com
Love others, encourage others, help others.
On Jul 19, 2026, at 6:05 AM, Kevin Tillery via NANOG <nanog@lists.nanog.org> wrote:
A Texas court has suspended the .com domain of a Dutch porn site which doesn't have any business presence in Texas, because it doesn't comply with Texas rules about porn (which are extremely onerous):
https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxt...
Clearly the US is not fit to manage top-level domains (other than .us of course) even though it ended up with them by historical accident. It worked for a while but now it's not working any more. Has anyone come up with any plan to solve this and make the DNS more neutral?
As a first step I'd think about experimenting with a DNS resolver that would move all US TLDs to subdomains of .us. However that obviously would just break the current internet for whoever is using this resolver, at least due to widespread use of vhosts.
Kevin _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/55UTA3Q4...
_______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/EJC2UZCJ...
Allan, I agree with Andy: this isn’t a technical concern. Frankly I feel like your title was a bait, causing people like me working on real dns security to read your post , although I believe unintentionally. It isn’t a technical issue since nobody said all companies must use the com tld. If there’s sufficient demand surely someone will set up an alternative tld out of the US jurisdiction . So… problem solved? No need in new technology? And sorry if I’m grumpy today, it has been one of these days…. Amir -- Amir Herzberg Comcast professor of Security Innovations, Computer Science and Engineering, University of Connecticut Homepage: https://sites.google.com/site/amirherzberg/home `Applied Introduction to Cryptography and Cybersecurity' textbook: https://www.worldscientific.com/pb-assets/wspc-site/catalogue-pdf/ComputerSc... <https://sites.google.com/site/amirherzberg/crypto-cyber-book> On Sun, Jul 19, 2026 at 9:37 AM Allan Liska via NANOG <nanog@lists.nanog.org> wrote:
Considering that this is the second time in less than a week that a company has had their domain taken off line at the Registrar level ( https://techcrunch.com/2026/07/14/telegrams-shortlink-domain-is-back-online-...) I do think there is a legitmate technical concern here, though I'd argue it is far from new.
It is a scenario that most companies don't account for, but depending on the type of business you are in, it is a very real concern and you should have a response plan in place.
allan On Sunday, July 19th, 2026 at 9:08 AM, Andy Ringsmuth via NANOG < nanog@lists.nanog.org> wrote:
Can we keep politics and personal opinions separate and independent of the technical aspects of the issue at hand (if there are any)? Per the NANOG list info page:
"Appropriate topics include: routing; broad-based engineering problems/issues/solutions; outages; performance measurement; evolving wide-area technologies; exchange points; traffic engineering; operational experience; ISP security; and trouble ticket systems."
Is there an actual legit technical issue here that needs discussion or solving?
---- Andy Ringsmuth andy@andyring.com
Love others, encourage others, help others.
On Jul 19, 2026, at 6:05 AM, Kevin Tillery via NANOG < nanog@lists.nanog.org> wrote:
A Texas court has suspended the .com domain of a Dutch porn site which doesn't have any business presence in Texas, because it doesn't comply with Texas rules about porn (which are extremely onerous):
https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxt...
Clearly the US is not fit to manage top-level domains (other than .us
of course) even though it ended up with them by historical accident. It worked for a while but now it's not working any more. Has anyone come up with any plan to solve this and make the DNS more neutral?
As a first step I'd think about experimenting with a DNS resolver that
would move all US TLDs to subdomains of .us. However that obviously would just break the current internet for whoever is using this resolver, at least due to widespread use of vhosts.
Kevin _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/55UTA3Q4...
_______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/EJC2UZCJ... _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/FARPULLL...
According to the press release, the domain was placed on registry lock by Verisign — it wasn’t done at the registrar. As Verisign is a US company, they probably assume it’s prudent to abide by court orders, so it shouldn’t be too much of a surprise. The Telegram case is a bit more interesting given DomainME (registry, not registrar) is, according to the TechCrunch article, Montenegro-based. This demonstrates that US OFAC sanctions have extra-territorial reach (or perhaps Montenegro has imposed the same sanctions that the US did?). Again, shouldn’t be too much of a surprise, but it often is. Regards, -drc
On Jul 19, 2026, at 6:37 AM, Allan Liska via NANOG <nanog@lists.nanog.org> wrote:
Considering that this is the second time in less than a week that a company has had their domain taken off line at the Registrar level (https://techcrunch.com/2026/07/14/telegrams-shortlink-domain-is-back-online-...) I do think there is a legitmate technical concern here, though I'd argue it is far from new.
It is a scenario that most companies don't account for, but depending on the type of business you are in, it is a very real concern and you should have a response plan in place.
allan On Sunday, July 19th, 2026 at 9:08 AM, Andy Ringsmuth via NANOG <nanog@lists.nanog.org> wrote:
Can we keep politics and personal opinions separate and independent of the technical aspects of the issue at hand (if there are any)? Per the NANOG list info page:
"Appropriate topics include: routing; broad-based engineering problems/issues/solutions; outages; performance measurement; evolving wide-area technologies; exchange points; traffic engineering; operational experience; ISP security; and trouble ticket systems."
Is there an actual legit technical issue here that needs discussion or solving?
---- Andy Ringsmuth andy@andyring.com
Love others, encourage others, help others.
On Jul 19, 2026, at 6:05 AM, Kevin Tillery via NANOG <nanog@lists.nanog.org> wrote:
A Texas court has suspended the .com domain of a Dutch porn site which doesn't have any business presence in Texas, because it doesn't comply with Texas rules about porn (which are extremely onerous):
https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxt...
Clearly the US is not fit to manage top-level domains (other than .us of course) even though it ended up with them by historical accident. It worked for a while but now it's not working any more. Has anyone come up with any plan to solve this and make the DNS more neutral?
As a first step I'd think about experimenting with a DNS resolver that would move all US TLDs to subdomains of .us. However that obviously would just break the current internet for whoever is using this resolver, at least due to widespread use of vhosts.
Kevin _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/55UTA3Q4...
_______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/EJC2UZCJ...
NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/FARPULLL...
On Sun, Jul 19, 2026 at 8:08 AM Andy Ringsmuth via NANOG <nanog@lists.nanog.org> wrote:
"Appropriate topics include: routing; broad-based engineering problems/issues/solutions; outages; performance measurement; evolving wide-area technologies; exchange points; traffic engineering; operational experience; ISP security; and trouble ticket systems."
The technical issue would be susceptibility of All database to tampering by any authorities who hold legal supremacy/jurisdiction over whichever person(s) or organizations are responsible for specific TLDs, or even the actual org responsible for that registry, for any reason, against the wishes of the domain holder. Even if the domain holder exists outside that jurisdiction or can legally operate under different rules. While this can be a serious technical issue; I don't believe there is anything network operators can do about it. You could consider distributed alternatives such as IPNS of the IPFS protocol a cryptographic-based name system, Tor hidden services, etc. Your best option might be to register your own domains under multiple ccTLDs while ensuring that there is no overlap amongst the registry operators or registrars between any of the chosen TLDs and domains.
Andy Ringsmuth -- -JA
This is indeed. Politics has an annoying tendency to cause technical problems, the current one being how to protect the DNS from political attack. There's nothing new about this - TLS became ubiquitous because of the Snowden leaks. Nobody said "get this TLS talk off my list because it's political" That's why I'm asking if there's something similar people can do to secure DNS? Probably not at the moment and certainly not easily? Although since it isn't about routing I'm not fully sure it's on-topic for NANOG and might be better suited for somewhere like IETF? Kevin On 19 July 2026 18:05:29 CEST, Jay Acuna via NANOG <nanog@lists.nanog.org> wrote:
On Sun, Jul 19, 2026 at 8:08 AM Andy Ringsmuth via NANOG <nanog@lists.nanog.org> wrote:
"Appropriate topics include: routing; broad-based engineering problems/issues/solutions; outages; performance measurement; evolving wide-area technologies; exchange points; traffic engineering; operational experience; ISP security; and trouble ticket systems."
The technical issue would be susceptibility of All database to tampering by any authorities who hold legal supremacy/jurisdiction over whichever person(s) or organizations are responsible for specific TLDs, or even the actual org responsible for that registry, for any reason, against the wishes of the domain holder.
Even if the domain holder exists outside that jurisdiction or can legally operate under different rules.
While this can be a serious technical issue; I don't believe there is anything network operators can do about it. You could consider distributed alternatives such as IPNS of the IPFS protocol a cryptographic-based name system, Tor hidden services, etc.
Your best option might be to register your own domains under multiple ccTLDs while ensuring that there is no overlap amongst the registry operators or registrars between any of the chosen TLDs and domains.
Andy Ringsmuth -- -JA
NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/LZL2ZERU...
Kevin, Please take this to ICANN. This is not a technical issue. If you are a business in anywhere in the world who knowingly ignores legal request for other parts of the world _AND_ ignore the “bottom up” community driven ICANN governance processes, then you are an idiot. www.icann.org <http://www.icann.org/> Barry
On Jul 20, 2026, at 01:01, Kevin Tillery via NANOG <nanog@lists.nanog.org> wrote:
This is indeed. Politics has an annoying tendency to cause technical problems, the current one being how to protect the DNS from political attack.
There's nothing new about this - TLS became ubiquitous because of the Snowden leaks. Nobody said "get this TLS talk off my list because it's political"
That's why I'm asking if there's something similar people can do to secure DNS? Probably not at the moment and certainly not easily?
Although since it isn't about routing I'm not fully sure it's on-topic for NANOG and might be better suited for somewhere like IETF?
Kevin
On 19 July 2026 18:05:29 CEST, Jay Acuna via NANOG <nanog@lists.nanog.org> wrote:
On Sun, Jul 19, 2026 at 8:08 AM Andy Ringsmuth via NANOG <nanog@lists.nanog.org> wrote:
"Appropriate topics include: routing; broad-based engineering problems/issues/solutions; outages; performance measurement; evolving wide-area technologies; exchange points; traffic engineering; operational experience; ISP security; and trouble ticket systems."
The technical issue would be susceptibility of All database to tampering by any authorities who hold legal supremacy/jurisdiction over whichever person(s) or organizations are responsible for specific TLDs, or even the actual org responsible for that registry, for any reason, against the wishes of the domain holder.
Even if the domain holder exists outside that jurisdiction or can legally operate under different rules.
While this can be a serious technical issue; I don't believe there is anything network operators can do about it. You could consider distributed alternatives such as IPNS of the IPFS protocol a cryptographic-based name system, Tor hidden services, etc.
Your best option might be to register your own domains under multiple ccTLDs while ensuring that there is no overlap amongst the registry operators or registrars between any of the chosen TLDs and domains.
Andy Ringsmuth -- -JA
NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/LZL2ZERU...
NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/VL4QKNMC...
From: Barry Greene <bgreene@senki.org>
Please take this to ICANN. This is not a technical issue. If you are a business in anywhere in the world who knowingly ignores legal request for other parts of the world _AND_ ignore the “bottom up” community driven ICANN governance processes, then you are an idiot.
just wow!
A Texas court has suspended the .com domain of a Dutch porn site which doesn't have any business presence in Texas, because it doesn't comply with Texas rules about porn (which are extremely onerous):
https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxt...
Clearly the US is not fit to manage top-level domains (other than .us of course) even though it ended up with them by historical accident. It worked for a while but now it's not working any more. Has anyone come up with any plan to solve this and make the DNS more neutral?
first, this is far from new. and it is both a technical and political problem. the dns is hierarchic, i.e. control is centralized. and centralization and hierarchy are foci for 'attacks'. but be patient, deleg is gonna solve everything :) com, net, org, etc. are going to be administered in some juristiction. all juristictions suck in one way or another, and the suckage varies over time. cf. the problems in italy and spain this last year+. or how long it took the courts in mauritius to realize they were being abused.
As a first step I'd think about experimenting with a DNS resolver that would move all US TLDs to subdomains of .us. However that obviously would just break the current internet for whoever is using this resolver, at least due to widespread use of vhosts.
i am afraid you will have to spell this out in more detail for me to make sense of it. i got lost even before you got to vhosts. but i am easily confused. randy
Clearly the US is not fit to manage top-level domains (other than .us of course) even though it ended up with them by historical accident. It worked for a while but now it's not working any more
The US Department of Justice decided that they could seize any .com domain back in 2012, and have done so with ever-increasing frequency since. Heck, they are flexing literally today by seizing 1,000 more that were streaming World Cup matches. It's news to me that a state court issued a ruling to seize something, but I'm sure it's happened before. The cat has long been out of the bag here. On Sun, Jul 19, 2026 at 7:06 AM Kevin Tillery via NANOG < nanog@lists.nanog.org> wrote:
A Texas court has suspended the .com domain of a Dutch porn site which doesn't have any business presence in Texas, because it doesn't comply with Texas rules about porn (which are extremely onerous):
https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxt...
Clearly the US is not fit to manage top-level domains (other than .us of course) even though it ended up with them by historical accident. It worked for a while but now it's not working any more. Has anyone come up with any plan to solve this and make the DNS more neutral?
As a first step I'd think about experimenting with a DNS resolver that would move all US TLDs to subdomains of .us. However that obviously would just break the current internet for whoever is using this resolver, at least due to widespread use of vhosts.
Kevin _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/55UTA3Q4...
participants (9)
-
Allan Liska -
Amir Herzberg -
Andy Ringsmuth -
Barry Greene -
David Conrad -
Jay Acuna -
Kevin Tillery -
Randy Bush -
Tom Beecher