Domain Registry Lock for .ZA being explored

Jamie McKane

MyBroadband Journalist
Joined
Mar 2, 2016
Messages
7,000
Reaction score
1,008
“The ZACR recognises the benefits that registrar lock provides to domain names under its administration and calls on its registrar community to consider offering this as a value added service to its end users without detracting from the rights that domain name holders have to manage their own domain names,” the registry said.

Wow, the registry (ZACR) has been fighting against registrar lock for as long as registrars like ourselves have been fighting for it.

Currently ZACR does not support the clientTransferProhibited, clientUpdateProhibited and clientDeleteProhibited epp status codes. There is no way for a registrar to "offer registrar lock as a value added service" on co.za domain names.

ZACR simply does not support it and in fact goes out of it's way in their policies to remove all domain security controls (like locking a domain) from the registrars by allowing the registrant (or unscrupulous individual) to circumvent any registrar security controls and interact with the ZACR registry directly.

To explain, ZACR's current policy allows a situation whereby, if a registrants email is hacked, this unscrupulous individual can transfer all the registrants domains away, no matter how much 2-factor auth or protection the registrar puts in place to try and prevent it. This is because the email acceptance ticket is sent from ZACR directly to the registrants email address. There is no way for a registrar to protect against this without breaking the ZACR policies as they currently stand.

Locking a domain at the registry level would mitigate against such attacks, though.

Essentially, any modification to a domain would have to be authenticated by the registry itself. Verisign said it contacts the requester by phone, who must provide a security phrase for the name to be unlocked.

LOL - this is the most ridiculous thing I have ever read. The "solution" is to phone every registrant each time any update what-so-ever is done to a domain name... All domain updates are already delayed by the registry, Thus making ZACR the most "poll message" heavy registry we have ever integrated with.

Phoning of registrants on every update is just going to perpetuate this delay exponentially and needless to say, but they do not have the staff to even man this in an efficient way.

I also do not see the registry being equipped to handle the catch 22 issue of "I want to update my 2FA phone number to a new number, but in order to do it, you must first authorize the update using your old number, however if you don't have access to your old number" - the registrant is placed in a catch 22. This again is better handled by the registrars who already have a business relationship with the registrants.

I'm also confused by Verisign's comments, the "pass phrase" they referring to is only held by the Registrar and not the registrant. Currently Verisign does not even hold the contact object information for a domain name, only the registrar does. Also Verisign does not have access to this contact information due to GDPR, so I am not sure who exactly they are phoning.

All verisign has described in a long winded way is just just 2FA for domain updates. This can reside on the registrar side, it does not need to be done on the registry side. From a technical standpoint, registry and registrar lock function exactly the same.

If ZACR really cared about domain security, they would allow for EPP auth code usage on co.za domains with the client "Update / Delete / Transfer" prohibited statuses that registrars can set on the domain names and force a type of 2FA Forms of Authority (FOA) system which the registrars would be required to implement.

Regards,
Dave @ Domains.co.za
 
"....it is looking into implementing registry locking"

In layman's terms, give them another 10 years to introduce this as a "feature"?
 
Top
Sign up to the MyBroadband newsletter
X