6 ms·
I feel like the title "Facebook sues Namecheap for registering phishing domains" is somewhat misleading. > We found that Namecheap’s proxy service, Whoisguard,
by caffeinewriter 7y ago
I feel like the title "Facebook sues Namecheap for registering phishing domains" is somewhat misleading.
> We found that Namecheap’s proxy service, Whoisguard, registered or used 45 domain names that impersonated Facebook and our services, such as instagrambusinesshelp.com, facebo0k-login.com and whatsappdownload.site. We sent notices to Whoisguard between October 2018 and February 2020, and despite their obligation to provide information about these infringing domain names, they declined to cooperate.
Specifically, they're suing Namecheap and their proxy service for not providing information about the true registrants of the allegedly infringing domains.
- CydeWeys 7y agoAnd to be clear, all Namecheap had to do to prevent this lawsuit was identify the owners of or delete the obviously-phishing and obviously-TM-infringing domain names. They didn't, so now Facebook is taking them to court over it.
- JoshTriplett 7y agoOr, alternatively, remove the domain names, since they're blatantly phishing domains. I think anonymous domain registration is an important property to preserve. Many people need such services for their safety. However, if you're going to serve as an anonymity shield for another party, you're taking on some of that party's liability, and in particular you need to take down malicious domains.
- throwaway3157 7y agoI know some attorneys are on HN, so question: does Namecheap/Whoisguard have a legal obligation to reveal that requested info?
- mmanfrin 7y agoFacebook listed 3 of the 45, including one that I'd argue does not at all violate TM or phish. In a post like this, they'd likely pick the most egregious examples, so your statement about how obvious this is is entirely baseless. Furthermore, I'm absolutely okay with Namecheap not honoring a demand for information without a subpoena. Those whoisguards protect me from spammers, scammers, and anyone who would want my information from a whois.
- tptacek 7y agoWhy do I care about the other examples if the egregious examples include obvious phishing sites?
- blackearl 7y agoIt sounds like Facebook asked, not a court. Just because you're a big company doesn't mean others need to bend to your will.
- sieabahlpark 7y agoWell what's the point of protecting the domain owner if anyone who comes by and asks can get that info?
- notRobot 7y agoAgreed 100%. I'm a huge fan of removing all PII from whois info. Get a subpoena if you want that data. Otherwise next thing you know they'll be demanding registrant info for "facebookisevil.com" because it "infringes on our trademarks!!!"
- rstupek 7y agoActually all PII information is already removed from whois info. I think it was a consequence of gdpr
- disiplus 7y agowhat value is there in whoisguard if anybody can strong arm you in giving the data away.
- ensignavenger 7y agoAccording to ICANN they cannot simply delete the domains- https://www.icann.org/resources/pages/help/dndr/udrp-en https://www.icann.org/resources/pages/help/dndr/udrp-en "Under the policy, most types of trademark-based domain-name disputes must be resolved by agreement, court action, or arbitration before a registrar will cancel, suspend, or transfer a domain name."
- caffeinewriter 7y agoHonestly, I'm glad they didn't. There's not much use in a whois privacy service if they'll give up the info just because a company says "this is infringing".
- StreamBright 7y agoThis pretty much depends on the details.
- xorcist 7y agoNamecheap is responsible for administrating domain ownership. They are not free to unilaterally change or remove ownership at will. That doesn't mean it's impossible to deregister infringing domains. It means that there is a process to follow, which is probably what we're seeing right now.
- shpongled 7y agoThen Namecheap is liable for determining what qualifies as phishing or TM infringement. This is not their responsibility.
- AlexandrB 7y agoHow is "instagrambusinesshelp.com" impersonating Facebook services? Is the argument here that using "Instagram" in a domain name inherently not allowed? Edit: Would "instagramsucks.com" or "facebooksucks.com" also be infringing?
- gibolt 7y agoInstagram has a business portal. When your site could easily be mistaken as an official company channel, that should not be allowed.
- AlexandrB 7y agoBut the language on Facebook's press release implies that the names themselves are misleading. They don't mention the content. I'm not disputing that the sites themselves are scammy/phishing, but what Facebook is saying here sounds like an overreach that amounts to "using Facebook trademarked names in a domain name is misleading and inherently untrustworthy".
- bavell 7y agoThis seems like a bad knee-jerk reaction, not a real solution. My company also has a business portal. Can I take down domains that are similar to it as well? Or is this power just reserved for MegaCorp Inc. who can afford large legal teams? At what point does a company become large enough to warrant "protection" of domains similar to their own? Who makes that decision and is there any dispute process? Etc, etc... So many questions and potential pitfalls surrounding this approach. I don't know if there's any better realistic "solution" than to let users ultimately be responsible for the domains they visit. Not much of a solution but I don't see any better options that are both realistic and helpful.
- Kalium 7y agoThere's an ICANN process that allows you to file exactly this sort of domain-specific takedown notice. https://www.icann.org/resources/pages/help/dndr/udrp-en https://www.icann.org/resources/pages/help/dndr/udrp-en The big drawback of the process it that it doesn't work well for phishing attacks, where taking down one domain is of limited value. It's designed more for things like nissan.com
- dang 7y agoWe've edited the title in an attempt to thread that needle. If someone can suggest a better—more accurate and neutral—title, we can change it again.
- bagacrap 7y ago"This week we filed a lawsuit in Arizona against Namecheap [...] for registering domain names that aim to deceive people by pretending to be affiliated with Facebook apps." The press release says "for registering domain names" so I think the original title was accurate. Previous similar court case where Verizon won a judgment against OnLineNic on the basis of trademark infringement: https://dockets.justia.com/docket/california/candce/3:2008cv02832/204081 https://dockets.justia.com/docket/california/candce/3:2008cv... So it doesn't seem like this suit is just about discovering the identities of the registrants.
- dang 7y agoHmm. Maybe we'll just cut it to the minimum viable title. (Title was "Facebook sues Namecheap for registering phishing domains", then "Facebook sues Namecheap for registrants of phishing domains".)
- EE84M3i 7y agoWell, their whois proxy services. Namecheap has other proxy services (email for sure, I think also some configurations like parking and redirection use an HTTP proxy), so not specifying whois proxy is pretty confusing.