SECURITY Signal 413
ICANN approves Verisign’s removal of 22,000 third-level .name domains risking identity theft
ICANN’s approval of Verisign’s request to drop third-level .name domain registrations exposes legacy users to potential identity theft by releasing second-level domains for public registration.
This change disrupts long-standing digital identities tied to 22,000 domains, including email and IoT infrastructure. The release of second-level domains creates a security risk, as attackers could hijack accounts linked to abandoned addresses. Engineers must now assess mitigation strategies for affected systems.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Verisign will delete all third-level .name domains (e.g., first.last.name) following ICANN’s approval, affecting ~22,000 registrants.
Released second-level domains may be re-registered, enabling attackers to intercept communications or reset passwords tied to legacy addresses.
Critics argue the decision sets a precedent for registry actions that invalidate active, paid domains without defensive protections.
THE READ
What the cluster adds up to.
ICANN’s approval of Verisign’s request to discontinue third-level .name domain registrations marks a significant shift in the management of the .name top-level domain (TLD). The change targets domains structured as first.last.name, which have been available since the TLD’s launch in 2001. Verisign cited declining usage and limited registrar support as justification for the move, but the operational impact extends beyond mere deprecation. Existing third-level domains will be deleted after a 90-day notice period, while second-level domains (e.g., example.name) remain unaffected. This selective removal creates a bifurcated landscape where legacy users face disruption, but newer registrants see no change.
The security implications of this decision are severe. Once third-level domains are deleted, their parent second-level domains may become available for public registration. For example, if a user previously held john.doe.name, the second-level domain doe.name could be re-registered by a malicious actor. This opens the door to identity theft, as attackers could configure DNS records to intercept emails, reset passwords, or hijack accounts tied to the now-orphaned addresses. The risk is not theoretical; technical communities have already flagged this as a potential ‘identity theft-as-a-service’ scenario, where automated tools could exploit abandoned domains at scale.
The decision has drawn criticism for its handling of legacy domains. Verisign’s filing claimed no security, stability, or resiliency concerns were identified by registrars, but this assertion has been widely contested. Engineers argue that Verisign could have mitigated the fallout by freezing existing delegations in a read-only state or permanently reserving the associated second-level domains. Instead, the move invalidates active, paid domains without offering defensive protections, setting a precedent that could erode trust in registry stewardship. Affected users are now exploring legal or administrative appeals to compel ICANN and Verisign to reconsider.
For engineers and operators, the change introduces immediate challenges. Systems relying on third-level .name domains, such as email servers, IoT devices, or long-running web services, will require migration or reconfiguration. The 90-day notice period provides a narrow window to update DNS records, notify users, and implement redirects or alternative authentication mechanisms. The broader concern is whether this decision signals a trend where registries prioritize operational convenience over the stability of legacy infrastructure. If so, it may prompt a reevaluation of how digital identities tied to niche TLDs are managed and protected.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗