ELSEIF
Your brief EB
309 stories from 172 feeds 995 clusters Refreshed 52 seconds ago next pull 11:15

SECURITY Signal 413

ICANN approves Verisign’s removal of 22,000 third-level .name domains risking identity theft

ICANN’s approval of Verisign’s request to drop third-level .name domain registrations exposes legacy users to potential identity theft by releasing second-level domains for public registration.

WHY IT MATTERS

This change disrupts long-standing digital identities tied to 22,000 domains, including email and IoT infrastructure. The release of second-level domains creates a security risk, as attackers could hijack accounts linked to abandoned addresses. Engineers must now assess mitigation strategies for affected systems.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Verisign will delete all third-level .name domains (e.g., first.last.name) following ICANN’s approval, affecting ~22,000 registrants.

02

Released second-level domains may be re-registered, enabling attackers to intercept communications or reset passwords tied to legacy addresses.

03

Critics argue the decision sets a precedent for registry actions that invalidate active, paid domains without defensive protections.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

ICANN’s approval of Verisign’s request to discontinue third-level .name domain registrations marks a significant shift in the management of the .name top-level domain (TLD). The change targets domains structured as first.last.name, which have been available since the TLD’s launch in 2001. Verisign cited declining usage and limited registrar support as justification for the move, but the operational impact extends beyond mere deprecation. Existing third-level domains will be deleted after a 90-day notice period, while second-level domains (e.g., example.name) remain unaffected. This selective removal creates a bifurcated landscape where legacy users face disruption, but newer registrants see no change.

The security implications of this decision are severe. Once third-level domains are deleted, their parent second-level domains may become available for public registration. For example, if a user previously held john.doe.name, the second-level domain doe.name could be re-registered by a malicious actor. This opens the door to identity theft, as attackers could configure DNS records to intercept emails, reset passwords, or hijack accounts tied to the now-orphaned addresses. The risk is not theoretical; technical communities have already flagged this as a potential ‘identity theft-as-a-service’ scenario, where automated tools could exploit abandoned domains at scale.

The decision has drawn criticism for its handling of legacy domains. Verisign’s filing claimed no security, stability, or resiliency concerns were identified by registrars, but this assertion has been widely contested. Engineers argue that Verisign could have mitigated the fallout by freezing existing delegations in a read-only state or permanently reserving the associated second-level domains. Instead, the move invalidates active, paid domains without offering defensive protections, setting a precedent that could erode trust in registry stewardship. Affected users are now exploring legal or administrative appeals to compel ICANN and Verisign to reconsider.

For engineers and operators, the change introduces immediate challenges. Systems relying on third-level .name domains, such as email servers, IoT devices, or long-running web services, will require migration or reconfiguration. The 90-day notice period provides a narrow window to update DNS records, notify users, and implement redirects or alternative authentication mechanisms. The broader concern is whether this decision signals a trend where registries prioritize operational convenience over the stability of legacy infrastructure. If so, it may prompt a reevaluation of how digital identities tied to niche TLDs are managed and protected.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
InfoQ Does ICANN Open the Door on Identity Theft by Dropping 3rd Level .name Domains Registrations? Open ↗