.name Domain Drop: ICANN's Policy Sparks Identity Theft Fears
Alps Wang
Sep 8, 2026 · 1 views
The Perilous Fallout of .name Domain Deletion
The core issue highlighted is ICANN's approval of Verisign's request to discontinue third-level .name domain registrations. While Verisign cites declining usage and limited registrar support, the article effectively exposes the severe security ramifications. The deletion of these domains, particularly those registered for decades, opens the door for malicious actors to re-register the parent second-level domains. This could lead to widespread interception of communications, password resets, and account hijacking, effectively turning previously secure digital identities into vulnerabilities. The claim by Verisign that registrars identified no security concerns appears to have been disproven by the community's reaction and the technical arguments presented by individuals like Neil Fraser.
The implications extend beyond individual users to the broader trust and stability of the internet's naming system. The decision sets a worrying precedent for registry stewardship, where established and paid-for digital assets can be invalidated and subsequently exploited. The article accurately frames this as 'identity theft-as-a-service,' a potent description of the potential automated attacks that could ensue. The lack of a clear mitigation strategy from ICANN or Verisign, such as a phased deprecation, a transition period, or a mechanism to protect existing users, is a significant limitation. The current approach forces affected registrants into a reactive stance, evaluating legal challenges rather than being proactively protected.
This situation is particularly relevant for anyone relying on the .name TLD for long-term online presence, email services, or even IoT infrastructure. Developers and system administrators who have integrated these domains into their systems need to be aware of the potential for disruption. The article's strength lies in its clear articulation of the technical security risks and the potential for abuse, making it a critical read for anyone involved in domain management, cybersecurity, and internet governance. The lack of comparison with alternative solutions is a minor point, as the focus is on the specific policy change and its direct consequences, rather than a broader comparison of TLD management strategies.
Key Points
- ICANN has approved Verisign's request to discontinue third-level .name domain registrations (e.g., first.last.name).
- This change, effective after a 90-day notice period, will delete approximately 22,000 existing active registrations.
- The primary concern is that parent second-level .name domains will become available for public registration, posing significant security risks.
- Malicious actors could exploit these released domains to intercept communications, reset passwords, and hijack accounts associated with legacy addresses.
- The move has been met with strong criticism from the technical community, who view it as a failure in registry stewardship and a potential enabler of identity theft.
- Affected registrants are exploring legal and administrative avenues to seek protection for their long-standing domains.

📖 Source: Does ICANN Open the Door on Identity Theft by Dropping 3rd Level .name Domains Registrations?
Related Articles
Comments (0)
No comments yet. Be the first to comment!
