soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Cops Say #Waymo Snitched on Teens for Allegedly Drinking and Shooting a Toy Gun
https://www.404media.co/waymo-called-police-on-teens-san-mateo/
CryptPad is a free open source collaborative online office suite with the emphasis on privacy and "zero knowledge" encryption. You can find out more at:
You can follow the project at:
CryptPad can be self-hosted online, installation instructions are at:
🌱 https://docs.cryptpad.org/en/admin_guide/installation.html
It can also be self-hosted locally, instructions for local hosting are at:
🌱 https://docs.cryptpad.org/en/dev_guide/index.html#dev-guide
#SelfHosting #Privacy #Office #Encryption #ZeroKnowledge #FOSS
Ministerrat trickst EU-Parlament zu umstrittenen Geräte-Scans aus #ChatkontrolleStoppen
Mit einem fragwürdigen Manöver wollen die EU-Staaten für die Neuauflage der »Chatkontrolle 1.0« sorgen. So bleibt auch die Version 2.0 auf der Agenda……
#EU #Europa #Überwachung #Chatkontrolle #Datenschutz #Privacy
#Tuta One-Click Migration is now in closed beta!
Brave is a free browser built on Chromium that blocks ads, trackers, and fingerprinting scripts by default - no extensions needed. It includes private windows routed through the Tor network on desktop, and its own independent search engine that doesn't track searches.
Ghost is a free, open-source publishing platform for blogs, newsletters, and membership sites.
Self-host it, own your content, and enjoy built-in newsletters, memberships, SEO tools, and a fast headless CMS, making it a strong alternative to WordPress, Medium, and Substack.
More details: https://digitalescapetools.com/tools/tool.html?id=ghost
#OpenSource #SelfHosted #Blogging #CMS #Privacy #Linux
Most privacy apps still start by asking you to make an account. Which has always struck me as odd, the account is the thing that gets breached, leaked, or subpoenaed.
Which is why Catchlight has none. No email, no sign-up, no password to reset.
A 12-word phrase you generate on your phone is the only key, and it never leaves the device.
Less to trust, because there's less to take.
#NewZealand rules out a #VPN ban after a fierce #privacy backlash - https://thenextweb.com/news/new-zealand-vpn-ban-denial-social-media " Ministers deny the tools were ever in the frame for the under-16 social media ban, but the panic exposed how age-check laws keep drifting toward encryption "
Windows est un logiciel de surveillance” : un identifiant caché piste 1,4 milliard de PC, même sous VPN, la preuve vient de tomber
Un expert l'affirme, le FBI lui a donné raison
#vieprivée #privacy #sécurité #security #windows #surveillance
WEBCAST 9 JUL 16:00 UTC - Re-Drawing the Privacy Line: Chatrie's Legislative and Oversight Implications
The Congressional Internet Caucus Academy hosts a Rayburn lunch panel breaking down the Chatrie v US decision on geofence warrants, location data & the Fourth Amendment, with Jennifer Huddleston (Cato), Jake Laperruque (@CenDemTech) & Paul Taske (NetChoice).
AI Spy
Trying to live outside, without buying or selling with money, is prohibited.
"Audio sensors" have been installed, with the help of Yandex, in one of Russia's protected areas. Eavesdropping with artificial intelligence will detect violations:
hunting
cutting down trees and bushes
lighting fires
organizing tourist camps
Not allowed!
If you use #Google, you’re training its #AI. Here’s how to opt out.
https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/
Oracle CEO Larry Ellison, owner of Tik Tok, Paramount Skydance, & others recently noted in an industry discussion on AI surveillance that "citizens will be on their best behavior because we’re constantly recording and reporting."
#AI #privacy #surveillance
Canadian spy agency says it hacked drug traffickers, extremists, and a #ransomware gang last year
#Canada #privacy #surveillance #cybersecurity #intelligence #crime #CSE
#ICE’s Internal Watchdog Is Now Investigating Online Critics
https://www.wired.com/story/ices-internal-watchdog-is-now-investigating-online-critics/
Police have used genealogy DNA databases including GEDmatch to identify criminal suspects, implicating relatives who never consented to law enforcement use.
The FCC wants to change how we get cell service. 😬 Sounds good on paper (stopping robocalls!), but what about privacy & safety? This could seriously impact domestic violence survivors. New video explores the concerns. Check it out! #FCC #Privacy #DomesticViolence
Footage Shows #Cop #Stalking Woman He Met on a TV Set After #Surveilling Her With a License Plate Reader
US #AirForce Engineer Charged With Sawing Down #Flock #Surveillance Cameras Receives Thousands of Dollars from Supporters Across the Country
https://futurism.com/future-society/air-force-engineer-flock-surveillance-support-legal-gofundme
#Windows11 identifier code used to track #ScatteredSpider perp after #Microsoft shared info with FBI
Not all smart glasses have cameras, but no camera doesn't mean no recording. Camera-free pairs like the new Solos AirGo A6 still have mics that capture what you say. Get familiar with both: a lens and light mean video, but audio recordings count too.
Japan’s KDDI just disclosed a breach affecting up to 14.2 million email accounts across six providers. The detail that stands out: some passwords were stored in plain text, not even hashed.
This keeps happening because centralized services hold enormous pools of credentials, and one flaw in one vendor exposes all of them at once.
Zerion has no accounts, no passwords on any server, nothing pooled to steal. There’s simply no database to breach.
zerion.chat
EU Chat control is back on the table. Bart Preneel warns in De Morgen: scanning private messages at scale risks treating all citizens as suspects, without solid scientific basis for AI detection.
#Privacy matters. Proportionality matters.
https://www.demorgen.be/tech-ai/chat-control-duikt-voor-derde-keer-op-in-europees-parlement~b7d040d0/ (paywall)
The arrest of a teenage hacker has revealed that #Microsoft can track a Windows PC and its online activity through a “Global Device ID" that seems to have no easy opt-out, sparking fears about potential #surveillance.
https://www.pcmag.com/news/a-hackers-arrest-reveals-microsoft-can-track-users-via-a-windows-device
#privacy #digitalsovereignty #infosec #gdid
Privacy News That Actually Matters. Every Monday, one story from the data privacy world. Recent, relevant, and actually readable.
Another instance of why real-time plate tracking is really bad. I wish we had privacy legislation in the US. Flock and other companies like them shouldn't even be legal.
This game could be used as a huge explainer into how surveillance capitalism works and how people are exploited on both sides of the screen.
MajorOffline: Hae Stack – MajorLinux
#Gaming #HaeStack #Investigation #PointAndClick #Political #Privacy #Puzzle #Steam #SteamNextFest #Surveillance #Capitalism #Tech #YouTube
Ransomware is now the most common cause of retailer data breaches: 32% of claims and 61% of the losses, per Verizon's 2026 study. Every store you shop at holds your payment and personal data, and that data is the target.
#privacy #ransomware #databreach #retail #verizon #indigoprivacy
Musk’s X poses “serious risk to Americans’ privacy,” advocates warn #FTC
Ahead of a July 2 deadline to submit public comments, advocates are warning the Federal Trade Commission that it must keep close watch over Elon Musk’s X and firmly reject a recent bid to end the agency’s ongoing audits of the platform’s data handling.
Last month, the FTC posted a notice explaining that X had argued that an FTC order was no longer necessary due to changes #Musk had made to the platform.
#privacy #Twitter
#Flock Defense "No Expectation of #Privacy In Public" Is Wrong (Public Report)
Online, Flock draws far more critics than defenders. But among those who do, the most common argument is a familiar one: there is no expectation of privacy in public, and license plates are visible to anyone on the road, so what's the problem? It is a reasonable instinct. It is also an oversimplification, and not what courts are being asked to decide.
#alpr #surveillance #flocksafety
If you are out at the Stampede in #Calgary and you see us, come to say hi and sign the petition to bring political parties under #privacy law in person!
We will be talking with attendees about the privacy loophole and how to prevent the #Alberta breach from happening again!
Learn more at https://voterprivacy.ca/
Hospital emergency departments collect patient location data through mobile check-in apps and share it with marketing vendors through third-party analytics tools.
While the Trump administration is strong-arming developing countries into giving up their citizens' privacy, other countries can afford to be more conscious about keeping their data safe.
#digitalsovereignty #privacy
https://www.connexionfrance.com/practical/france-moves-to-cut-reliance-on-microsoft-for-health-data/796443
🚨 WHOIS privacy is under pressure.
GoDaddy is challenging an Indian court ruling that could fundamentally change how domain privacy works by requiring:
🔹 Mandatory e-KYC for domain registrations
🔹 WHOIS privacy no longer enabled by default
🔹 Registrars to disclose registrant details within 72 hours to parties claiming a "legitimate interest"
This isn't just about India.
The outcome could influence domain privacy, ICANN policy, RDAP adoption, cybersecurity investigations, trademark enforcement, and the future of online anonymity worldwide.
I break down:
✅ What the court actually ordered
✅ Why GoDaddy is appealing
✅ How WHOIS and RDAP really work
✅ The privacy vs law enforcement debate
✅ What it means for domain owners, security researchers, and businesses
Read the full analysis 👇
https://thecybersecguru.com/news/godaddy-india-whois-privacy-ruling/?utm_source=mastodon&utm_medium=social
#CyberSecurity #WHOIS #GoDaddy #DomainNames #Privacy #RDAP #ICANN #OSINT #DNS #InfoSec #CyberLaw #India #DataPrivacy #CyberNews
GoDaddy Is Quietly Fighting for WHOIS Privacy, and Almost No One’s Paying Attention
Delhi High Court ordered registrars to end default WHOIS privacy. GoDaddy's 5,000-page appeal explains why, and how it collides with RDAP's 2025 rollout [SENSITIVE CONTENT]
The order that has GoDaddy filing a 5,121-page appeal did not appear out of nowhere. It is the endpoint of a batch of Delhi High Court proceedings running since 2019, and the technical mechanism it targets, WHOIS privacy protection, happens to be a protocol that global internet governance had already spent the better part of a decade trying to fix through consensus rather than court order. Understanding why GoDaddy is worried requires understanding both threads: what an Indian judge actually ordered, and what WHOIS was already in the middle of becoming before she ordered it.
GoDaddy
The case and the numbers behind it
The order in question is Dabur India Limited v. Ashok Kumar & Ors. (CS(COMM) 135/2022, citation 2025:DHC:11862), delivered on December 24, 2025 by Justice Prathiba M. Singh. It was the lead matter in a consolidated batch stretching back to 2019, folding in suits from Colgate-Palmolive, Godrej Properties, The Himalaya Drug Company, and others, all chasing the same problem: domain names that mimicked their trademarks, sold fake franchises, or ran phishing operations, with the actual registrant hidden behind privacy protection features. The judgment blocked more than 1,100 such domains impersonating brands including Tata Sky, Amul, Bajaj Finance, Meesho, Croma, ITC, and Mont Blanc. Delhi Police’s Intelligence Fusion and Strategic Operations unit had traced crores of rupees extracted from victims through these sites, and the court noted that out of those 1,132 infringing registrations, barring one or two, not a single bona fide registrant ever came forward to claim a legitimate interest in the domain. Nobody showed up to defend their WHOIS-shielded identity, which the judge treated as fairly damning on its own.
The scale problem behind the ruling is real. India’s internet penetration went from 15 percent of the population in 2015 to roughly 70 percent by 2025, a jump that outpaced the average user’s ability to spot a spoofed domain. Home Minister Amit Shah cited a cybercrime victim roughly every 37 seconds nationally, and the National Technical Research Organisation logged over 1,100 phishing domains in Q1 2025 alone. Reuters reported 2.4 million cyber fraud complaints last year totaling $2.4 billion in losses. Justice Singh explicitly rejected the idea that case-by-case takedowns could keep up, describing the pattern as a whack-a-mole problem structurally incapable of being solved by injunctions against individually named domains.
The three directives GoDaddy is fighting
The judgment issued 14 directions to domain name registrars. Three are the ones under appeal:
Mandatory e-KYC with periodic re-verification for every domain registration, run by the registrar, functionally identical to what NIXI already does for .in domains.
Termination of privacy-by-default. Registrars can still offer WHOIS masking, but only as a paid opt-in, not a baseline feature bundled into every registration.
72-hour disclosure of registrant name, address, phone number, and email to any party asserting “legitimate interest,” a term the court borrows straight from GDPR without defining who qualifies or who adjudicates the claim.
GoDaddy’s appeal argues, correctly as a matter of engineering, that it has no scalable way to arbitrate “legitimate interest” claims within a 72-hour SLA across millions of domains. It also argues the order is jurisdictionally impossible to contain: DNS resolution doesn’t respect borders, so a registrar can’t run one WHOIS policy for Indian registrants and a separate one for everyone else without rebuilding its entire registration data pipeline around a single country’s court order. Farzaneh Badii, an internet governance researcher based in New York, made the point that WHOIS redaction was adopted globally in the first place because publicly listed contact data had been repeatedly exploited for stalking and harassment campaigns, meaning the rollback risks reintroducing the exact harm category the order claims to be solving, just aimed at a different population (private registrants and small businesses instead of the fraud operators who mostly used fabricated details anyway).
That last point matters technically. The Dabur judgment itself notes that WHOIS records tied to the fraudulent domains frequently contained fake names, dead phone numbers, and throwaway emails. Removing privacy-by-default doesn’t touch registrants who never entered real data in the first place. It mainly exposes people who did.
How Whois Privacy Services Work
Why this collides with a protocol transition that was already underway
Here’s the part that gets lost in the legal coverage: WHOIS, as a protocol, was already being retired independent of anything happening in Delhi. WHOIS dates to RFC 812 in 1982, a plaintext, unauthenticated, TCP port 43 query-response format with no standardized output. Every registry answered in its own dialect of free text, there was no encryption, and there was no way to distinguish a security researcher’s query from a spammer scraping contact data at scale. ICANN approved the RDAP Global Amendments in April 2023, setting a sunset date of January 28, 2025, after which gTLD registries and registrars were no longer contractually obligated to run WHOIS on port 43. Registration Data Access Protocol, standardized by the IETF (RFC 7480, 7481, and 9083, since updated by 9082/9083), replaced it with a RESTful HTTPS service returning structured JSON, discoverable through IANA’s bootstrap registry rather than a flat list of per-registry servers to memorize.
The adoption numbers moved fast once the deadline hit. ICANN logged around 122 billion WHOIS queries per month in January 2025 against 7 billion RDAP queries. By June 2025, RDAP query volume overtook WHOIS. By August, WHOIS had dropped to roughly 49 billion monthly queries against RDAP’s 65 billion, and 374 of about 1,000 gTLDs had shut off WHOIS entirely. In January 2026 ICANN revoked registrar Brennercom’s accreditation specifically for failing to implement RDAP, establishing that compliance is not optional going forward. For anyone doing domain recon as part of a pentest engagement or OSINT workup, this is the practical takeaway that matters more than the Indian litigation: if your tooling still shells out to a whois binary or opens a raw socket on port 43 for gTLD lookups, you’re querying a service nobody is obligated to keep answering. Grep your scripts for it. ccTLD coverage is patchier (roughly 60 percent RDAP adoption, with .de, .cn, and .jp still WHOIS-only in many configurations), so a mixed lookup strategy is still required if your target surface spans country-code domains.
The irony for the Delhi court’s order is that RDAP already ships with the exact capability the judges are trying to bolt onto WHOIS by judicial fiat. RDAP’s spec explicitly supports differentiated, role-based access: a registry can serve full contact data to an authenticated law enforcement query and a redacted response to an anonymous one, all through the same endpoint, governed by policy rather than a court re-litigating the question domain by domain. ICANN’s Registration Data Request Service (RDRS) exists precisely to handle law-enforcement and rights-holder requests for non-public registration data through participating registrars. GDPR is actually why any of this privacy tooling exists at all: the 2018 Tucows/EPAG dispute in Germany forced ICANN to adopt a Temporary Specification for WHOIS data handling almost overnight, and that temporary fix eventually hardened into the RDAP privacy model in use today. The Delhi court is essentially trying to solve, through a commercial trademark suit, a problem that the multilateral RDAP framework was purpose-built to solve through protocol design and contractual policy. Whether a system built for global consistency can survive a national court insisting on a different, manually-adjudicated disclosure standard is the actual question the larger bench has to answer on July 16.
The legal scaffolding under the order
The judgment leans on Section 7(e) of India’s Digital Personal Data Protection Act, which allows a data fiduciary to process personal data without consent when complying with a court order, and applies the Puttaswamy proportionality test to conclude that privacy protections cannot be used to shield ongoing illegality. GoDaddy’s appeal points out an inconvenient wrinkle: weeks before this ruling, the same Delhi High Court read the DPDP Act the opposite way in a right-to-be-forgotten matter, ordering Google and Indian Kanoon to de-index the names of acquitted persons. The larger bench has effectively been asked to decide which interpretation of the statute is going to govern going forward, since right now the same court has issued contradictory readings of the same law within the same season.
There’s also an enforcement lever most coverage skips. ICANN’s Registrar Accreditation Agreement, Section 5.5.2.1.4, allows ICANN to terminate a registrar’s accreditation if a court of competent jurisdiction finds the registrar failed to comply with an order relating to domains it sponsors. MeitY has already engaged ICANN’s Contractual Compliance Mechanism over non-compliant registrars in this same batch of litigation, and earlier orders in the case directed the Ministry to act under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 against registrars who hadn’t appointed grievance officers. Registrars operating in India also risk losing Section 79 IT Act safe harbor as intermediaries if courts decide they aren’t doing enough to prevent trademark infringement on their platforms. That’s the actual leverage India holds over a company like GoDaddy: not just a disclosure order, but the threat of losing both its ICANN accreditation and its intermediary liability shield in one of its largest markets.
The court didn’t stop at registrars, either. It ordered the RBI to build bank-side fraud tooling, and the Beneficiary Bank Account Name Lookup facility for RTGS and NEFT transfers went live on December 30, 2024, with mandatory bank-wide implementation by April 1, 2025, letting anyone verify the actual name on a receiving account before sending money. That single fix closes a gap that had nothing to do with domains: fraudsters were collecting payments into accounts that didn’t match the billing name a victim thought they were paying.
The trademark-scope argument
Separate from privacy, GoDaddy is also contesting the order’s bar on registering alphanumeric variations of a protected trademark. Its argument here is more linguistic than technical, but it’s a good illustration of how brand protection collides with the domain namespace. GoDaddy points out that “McDonald” is a Scottish surname predating the fast food chain by centuries, and that treating any string variation as off-limits risks handing a monopoly over common words and names to whichever company trademarked them first. Its filing cites Merriam-Webster research showing 118 English words contain the string “HUL,” Unilever’s Indian trademark, including “hulk” and “moghul,” and argues it’s close to impossible to register any domain in English that doesn’t overlap somewhere with a registered mark. Reuters found mcdonalds-india-franchise.com still purchasable on GoDaddy India for about $10 as of the reporting, which either undercuts the enforcement claims or just shows how far a 1,100-domain blocklist is from actually closing the gap, depending on how charitable you’re feeling.
Namecheap and Hosting Concepts (Openprovider’s parent) have filed separate challenges to the same order, though the specifics of their appeals haven’t surfaced publicly. The larger bench hears all three on July 16. If it narrows the December directives, that reaffirms that ICANN’s negotiated global frameworks still take precedence over a single national court’s order. If it upholds them, any court with jurisdiction over a major registrar has effectively been shown a template for rewriting WHOIS policy unilaterally, and the assumption that domain privacy works the same way everywhere stops being something you can rely on.
#chatcontrol fact check!
Chat Control is NOT about protecting children at its core. On the very surface, yes. But the proposed approach is so far reaching that it will enable surveillance of the whole population at the next political intersection.
We all really want to fight child abuse. CSAM is an incredibly cruel crime against defendless individuals. Yes, we want those criminals to be sentenced harshly and hard in courts.
But Chat Control is not the right solution. Do you really want to call out several hundred millions of European citizens as potential perpetrators just to catch the abusers?
What happened to the presumption of innocence? Which is the foundation in the law system across all of Europe. What kind of regime are we preparing for in Europe if we don't enforce and protect the presumption of innocence?
Europe has had a strong stance of opposing supressing regimes. Regimes which builds their power through controlling the population. Control which comes through surveillance of the population.
When did Europeans vote for a regime change in Europe? We threw fascists out of the political influence over 80 years ago. We do not want to do the same again.
We threw out communists from European influence 40 years ago. Communists who was behind Stasi in the DDR - Do we need to repeat what the state controlled surveillance did to the population there?
You may rightfully claim that Chat Control is not meant to be that extreme. No, it isn't right now. But it has the power of ending there. Once the tools to surveil the population has arrived, it is hard to withdraw them. And the idea behind Chat Control is in practice surveillance of what Europeans do on their electronic devices. Regardless if they are a suspect or innocent.
Chat Control MUST be stopped, once and for all. And the work to protect children must be more clever, more targeted at clearly defined suspects. Not to surveil the whole European population.
And this message has not even dug into the rabbit hole of how flawed the chat control approach is on a technical level. Where the real offenders and abusers will find technologic ways to avoid chat control and this surveillance. Leaving the rest of the innocent population, the majority of the population under surveillance by default.
🔒 A 19-year-old cybercriminal was caught despite using a VPN across multiple countries - because Windows has a tracking number built into every install that a VPN can't hide.
Peter Stokes, arrested in Finland in April and extradited to the US last week, is tied to Scattered Spider, the hacking group behind the 2023 MGM and Caesars casino breaches. The group is linked to 100+ intrusions and over $100 million in extortion.
The FBI didn't crack his VPN. Microsoft handed over his Global Device ID (GDID), a unique identifier baked into every Windows installation at setup. It doesn't change when you update, switch networks, or use a VPN. The only way to reset it is a full OS reinstall.
Investigators matched Stokes's GDID across IP addresses in Estonia, New York, and Thailand, correlating with login times on his Snapchat, Apple, and Facebook accounts. The same device that breached a luxury jewelry retailer and demanded $8 million in ransom also logged into Snapchat and a video game from his real network.
So while VPNs mask your IP address, they were never designed to hide device-level identifiers embedded in your operating system. The tracking can live one layer deeper than the one most people defend.
Read more:
https://www.itnews.com.au/news/microsoft-device-telemetry-key-to-unmasking-alleged-scattered-spider-hacker-627148
https://www.databreachtoday.com/scattered-spider-suspect-extradited-from-finland-to-us-a-32140
The order that has GoDaddy filing a 5,121-page appeal did not appear out of nowhere. It is the endpoint of a batch of Delhi High Court proceedings running since 2019, and the technical mechanism it targets, WHOIS privacy protection, happens to be a protocol that global internet governance had already spent the better part of a decade trying to fix through consensus rather than court order. Understanding why GoDaddy is worried requires understanding both threads: what an Indian judge actually ordered, and what WHOIS was already in the middle of becoming before she ordered it.

GoDaddy
The order in question is Dabur India Limited v. Ashok Kumar & Ors. (CS(COMM) 135/2022, citation 2025:DHC:11862), delivered on December 24, 2025 by Justice Prathiba M. Singh. It was the lead matter in a consolidated batch stretching back to 2019, folding in suits from Colgate-Palmolive, Godrej Properties, The Himalaya Drug Company, and others, all chasing the same problem: domain names that mimicked their trademarks, sold fake franchises, or ran phishing operations, with the actual registrant hidden behind privacy protection features. The judgment blocked more than 1,100 such domains impersonating brands including Tata Sky, Amul, Bajaj Finance, Meesho, Croma, ITC, and Mont Blanc. Delhi Police’s Intelligence Fusion and Strategic Operations unit had traced crores of rupees extracted from victims through these sites, and the court noted that out of those 1,132 infringing registrations, barring one or two, not a single bona fide registrant ever came forward to claim a legitimate interest in the domain. Nobody showed up to defend their WHOIS-shielded identity, which the judge treated as fairly damning on its own.
The scale problem behind the ruling is real. India’s internet penetration went from 15 percent of the population in 2015 to roughly 70 percent by 2025, a jump that outpaced the average user’s ability to spot a spoofed domain. Home Minister Amit Shah cited a cybercrime victim roughly every 37 seconds nationally, and the National Technical Research Organisation logged over 1,100 phishing domains in Q1 2025 alone. Reuters reported 2.4 million cyber fraud complaints last year totaling $2.4 billion in losses. Justice Singh explicitly rejected the idea that case-by-case takedowns could keep up, describing the pattern as a whack-a-mole problem structurally incapable of being solved by injunctions against individually named domains.
The judgment issued 14 directions to domain name registrars. Three are the ones under appeal:
Mandatory e-KYC with periodic re-verification for every domain registration, run by the registrar, functionally identical to what NIXI already does for .in domains.
Termination of privacy-by-default. Registrars can still offer WHOIS masking, but only as a paid opt-in, not a baseline feature bundled into every registration.
72-hour disclosure of registrant name, address, phone number, and email to any party asserting “legitimate interest,” a term the court borrows straight from GDPR without defining who qualifies or who adjudicates the claim.
GoDaddy’s appeal argues, correctly as a matter of engineering, that it has no scalable way to arbitrate “legitimate interest” claims within a 72-hour SLA across millions of domains. It also argues the order is jurisdictionally impossible to contain: DNS resolution doesn’t respect borders, so a registrar can’t run one WHOIS policy for Indian registrants and a separate one for everyone else without rebuilding its entire registration data pipeline around a single country’s court order. Farzaneh Badii, an internet governance researcher based in New York, made the point that WHOIS redaction was adopted globally in the first place because publicly listed contact data had been repeatedly exploited for stalking and harassment campaigns, meaning the rollback risks reintroducing the exact harm category the order claims to be solving, just aimed at a different population (private registrants and small businesses instead of the fraud operators who mostly used fabricated details anyway).
That last point matters technically. The Dabur judgment itself notes that WHOIS records tied to the fraudulent domains frequently contained fake names, dead phone numbers, and throwaway emails. Removing privacy-by-default doesn’t touch registrants who never entered real data in the first place. It mainly exposes people who did.

How Whois Privacy Services Work
Here’s the part that gets lost in the legal coverage: WHOIS, as a protocol, was already being retired independent of anything happening in Delhi. WHOIS dates to RFC 812 in 1982, a plaintext, unauthenticated, TCP port 43 query-response format with no standardized output. Every registry answered in its own dialect of free text, there was no encryption, and there was no way to distinguish a security researcher’s query from a spammer scraping contact data at scale. ICANN approved the RDAP Global Amendments in April 2023, setting a sunset date of January 28, 2025, after which gTLD registries and registrars were no longer contractually obligated to run WHOIS on port 43. Registration Data Access Protocol, standardized by the IETF (RFC 7480, 7481, and 9083, since updated by 9082/9083), replaced it with a RESTful HTTPS service returning structured JSON, discoverable through IANA’s bootstrap registry rather than a flat list of per-registry servers to memorize.
The adoption numbers moved fast once the deadline hit. ICANN logged around 122 billion WHOIS queries per month in January 2025 against 7 billion RDAP queries. By June 2025, RDAP query volume overtook WHOIS. By August, WHOIS had dropped to roughly 49 billion monthly queries against RDAP’s 65 billion, and 374 of about 1,000 gTLDs had shut off WHOIS entirely. In January 2026 ICANN revoked registrar Brennercom’s accreditation specifically for failing to implement RDAP, establishing that compliance is not optional going forward. For anyone doing domain recon as part of a pentest engagement or OSINT workup, this is the practical takeaway that matters more than the Indian litigation: if your tooling still shells out to a whois binary or opens a raw socket on port 43 for gTLD lookups, you’re querying a service nobody is obligated to keep answering. Grep your scripts for it. ccTLD coverage is patchier (roughly 60 percent RDAP adoption, with .de, .cn, and .jp still WHOIS-only in many configurations), so a mixed lookup strategy is still required if your target surface spans country-code domains.
The irony for the Delhi court’s order is that RDAP already ships with the exact capability the judges are trying to bolt onto WHOIS by judicial fiat. RDAP’s spec explicitly supports differentiated, role-based access: a registry can serve full contact data to an authenticated law enforcement query and a redacted response to an anonymous one, all through the same endpoint, governed by policy rather than a court re-litigating the question domain by domain. ICANN’s Registration Data Request Service (RDRS) exists precisely to handle law-enforcement and rights-holder requests for non-public registration data through participating registrars. GDPR is actually why any of this privacy tooling exists at all: the 2018 Tucows/EPAG dispute in Germany forced ICANN to adopt a Temporary Specification for WHOIS data handling almost overnight, and that temporary fix eventually hardened into the RDAP privacy model in use today. The Delhi court is essentially trying to solve, through a commercial trademark suit, a problem that the multilateral RDAP framework was purpose-built to solve through protocol design and contractual policy. Whether a system built for global consistency can survive a national court insisting on a different, manually-adjudicated disclosure standard is the actual question the larger bench has to answer on July 16.
The judgment leans on Section 7(e) of India’s Digital Personal Data Protection Act, which allows a data fiduciary to process personal data without consent when complying with a court order, and applies the Puttaswamy proportionality test to conclude that privacy protections cannot be used to shield ongoing illegality. GoDaddy’s appeal points out an inconvenient wrinkle: weeks before this ruling, the same Delhi High Court read the DPDP Act the opposite way in a right-to-be-forgotten matter, ordering Google and Indian Kanoon to de-index the names of acquitted persons. The larger bench has effectively been asked to decide which interpretation of the statute is going to govern going forward, since right now the same court has issued contradictory readings of the same law within the same season.
There’s also an enforcement lever most coverage skips. ICANN’s Registrar Accreditation Agreement, Section 5.5.2.1.4, allows ICANN to terminate a registrar’s accreditation if a court of competent jurisdiction finds the registrar failed to comply with an order relating to domains it sponsors. MeitY has already engaged ICANN’s Contractual Compliance Mechanism over non-compliant registrars in this same batch of litigation, and earlier orders in the case directed the Ministry to act under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 against registrars who hadn’t appointed grievance officers. Registrars operating in India also risk losing Section 79 IT Act safe harbor as intermediaries if courts decide they aren’t doing enough to prevent trademark infringement on their platforms. That’s the actual leverage India holds over a company like GoDaddy: not just a disclosure order, but the threat of losing both its ICANN accreditation and its intermediary liability shield in one of its largest markets.
The court didn’t stop at registrars, either. It ordered the RBI to build bank-side fraud tooling, and the Beneficiary Bank Account Name Lookup facility for RTGS and NEFT transfers went live on December 30, 2024, with mandatory bank-wide implementation by April 1, 2025, letting anyone verify the actual name on a receiving account before sending money. That single fix closes a gap that had nothing to do with domains: fraudsters were collecting payments into accounts that didn’t match the billing name a victim thought they were paying.
Separate from privacy, GoDaddy is also contesting the order’s bar on registering alphanumeric variations of a protected trademark. Its argument here is more linguistic than technical, but it’s a good illustration of how brand protection collides with the domain namespace. GoDaddy points out that “McDonald” is a Scottish surname predating the fast food chain by centuries, and that treating any string variation as off-limits risks handing a monopoly over common words and names to whichever company trademarked them first. Its filing cites Merriam-Webster research showing 118 English words contain the string “HUL,” Unilever’s Indian trademark, including “hulk” and “moghul,” and argues it’s close to impossible to register any domain in English that doesn’t overlap somewhere with a registered mark. Reuters found mcdonalds-india-franchise.com still purchasable on GoDaddy India for about $10 as of the reporting, which either undercuts the enforcement claims or just shows how far a 1,100-domain blocklist is from actually closing the gap, depending on how charitable you’re feeling.
Namecheap and Hosting Concepts (Openprovider’s parent) have filed separate challenges to the same order, though the specifics of their appeals haven’t surfaced publicly. The larger bench hears all three on July 16. If it narrows the December directives, that reaffirms that ICANN’s negotiated global frameworks still take precedence over a single national court’s order. If it upholds them, any court with jurisdiction over a major registrar has effectively been shown a template for rewriting WHOIS policy unilaterally, and the assumption that domain privacy works the same way everywhere stops being something you can rely on.
Opinion
"AI surveillance is being supercharged – and it will chill social progress
Bruce Schneier and Jon Penney
These systems will soon be able to track our public and private lives. But we can make the policy choices to reject it"
#privacy #surveillance #ai #noai #BruceSchneier
https://www.theguardian.com/commentisfree/2026/jul/06/ai-surveillance-policy
(the images cover about half of the article)
AI glasses with built-in cameras are making people uneasy about being recorded in public without consent. Critics say they blur everyday life into surveillance, and the pushback is real: workplace bans, public callouts, and apps that scan for hidden cameras.
#privacy #smartglasses #surveillance #consent #indigoprivacy
"Bits of Freedom: AIVD en MIVD lijken eigen AI te trainen met data van burgers
Inlichtingendiensten AIVD en MIVD lijken hun eigen AI te trainen met data van burgers, zo stelt burgerrechtenbeweging Bits of Freedom (BoF). De organisatie reageerde op een rapport van de Commissie Toezicht op de Inlichtingen- en Veiligheidsdiensten (CTIVD) over het onrechtmatig verwerken van persoonsgegevens in bulkdata door de inlichtingendiensten en dat die persoonlijke privacy beter moeten beschermen.
Bij de uitvoering van hun taken maken de AIVD en MIVD gebruik van zogenaamde bulkdatasets. Het gaat om omvangrijke verzamelingen persoonsgegevens met soms miljoenen regels gegevens. Daarbij kan het gaan om namen en telefoonnummers maar ook om locatiegegevens, socialmediagegevens of inhoudelijke communicatiegegevens. De gebruikte datasets zijn afkomstig van overheidsinstanties. Het kan echter ook gaan om commercieel verkrijgbare datasets, of gestolen datasets die door criminelen worden aangeboden."
.,,.,.,.,.
I'd like to share the latest version of my project.
It's a a decentralised P2P messaging app. The aim is of course privacy and security.
It demonstrates a fairly unique approach by using browser-based local-only storage with webrtc.
https://www.reddit.com/r/positive_intentions/comments/1tq1u62/introducing_enkrypted_chat
---
#Privacy #OnlinePrivacy #DataPrivacy #Infosec #CyberSecurity #OpSec #DigitalRights #AntiSurveillance #DataOwnership #E2EE #P2P #PeerToPeer #WebRTC #LocalFirst #LocalOnly #NoCloud #NoRegistration #PWA #SignalProtocol #PostQuantum #Cryptography #SecureMessaging #PrivateChat #EncryptedChat #Decentralized #OpenSource #SelfHosted #BetaTesting #FeedbackWelcome #TechDemo #ProofOfConcept #BuildInPublic #IndieDev #DevCommunity
not a supporter of ArcaneChat yet??? you can not only watch but also be part of the change! ✨
no amount is too small!
💜 join our contributors 👉 https://arcanechat.me/#contribute
#ArcaneChat #freedom #privacy #security #encryption #autonomy #digitalindependence #opensource #decentralization #europe #european
@ketan
Hi Ketan, many thanks for your report on Googles greed for energy. Great findings and great writing. https://ketanjoshi.co/2026/07/01/googles-exponential-path-to-climate-wrecking-digital-bloat/
But one thing bothers me: You have an e-mail account at GOOGLE? Is this a cognitive dissonance? For the sake of my privacy I for one NEVER communicate w/ gmail or the other big-tech US providers. Reasons here (in german): https://www.pc-fluesterer.info/wordpress/vorbeugen/e-mail/e-mail-und-privatsphaere/
And except for mastodon you are on a lot of commercial antisocial platforms. Is it for the "reach"? Then https://www.pc-fluesterer.info/wordpress/2025/09/22/reichweite-reichweite-reichweite/
#FlockSafety Credibility Lost as it Repeatedly Lies to City Councils, #Police Departments, and Public Across the Country
The #ACLU documents how an automatic license plate reader company has lied about its operations, signaling a need for reputable governments to avoid working with #Flock Safety.
#alpr #privacy #security #surveillance
Cape was founded by privacy-first innovators with deep expertise in security, telecom, and technology—built on the belief you can stay connected without compromising your privacy. As noted in The News, “a company is finally trying to seriously address privacy issues with aging telecommunications networks.” Learn more: https://www.cape.co/about 🔒📡🛡️ #Privacy #Cybersecurity #Telecom
LibreTranslate is a free, open-source machine translation server that you can use online or self-host for complete control over your data.
It supports multiple languages, offers a simple API, works without relying on Google Translate, and is a great privacy-friendly choice for websites, apps, and personal use.
More details: https://digitalescapetools.com/tools/tool.html?id=libretranslate
#OpenSource #Privacy #SelfHosted #Translation #Linux #FOSS #MachineTranslation