<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Segoe UI";
        panose-1:2 11 5 2 4 2 4 2 2 3;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
p.MsoBodyText, li.MsoBodyText, div.MsoBodyText
        {mso-style-priority:99;
        mso-style-link:"Body Text Char";
        margin-top:0in;
        margin-right:0in;
        margin-bottom:6.0pt;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
p.MsoBodyTextFirstIndent, li.MsoBodyTextFirstIndent, div.MsoBodyTextFirstIndent
        {mso-style-priority:99;
        mso-style-link:"Body Text First Indent Char";
        margin-top:0in;
        margin-right:0in;
        margin-bottom:12.0pt;
        margin-left:0in;
        text-indent:1.0in;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.BodyTextChar
        {mso-style-name:"Body Text Char";
        mso-style-priority:99;
        mso-style-link:"Body Text";}
span.BodyTextFirstIndentChar
        {mso-style-name:"Body Text First Indent Char";
        mso-style-priority:99;
        mso-style-link:"Body Text First Indent";
        font-family:"Times New Roman","serif";}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Dear Mr. Baril:<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoBodyTextFirstIndent" style="text-align:justify;text-indent:.5in"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif"">Microsoft Corporation (“Microsoft”) welcomes this opportunity to provide additional comments to the Expert Working
Group on gTLD Directory Services (“EWG”) regarding its Status Update Report of November 11, 2013.
</span><o:p></o:p></p>
<p class="MsoNormal" style="text-indent:.5in">In large part, the EWG has made commendable progress since its Initial Report. The EWG has answered many of Microsoft’s questions raised in its letter of September 6, 2013, including those relating to data validation
and data availability. However, Microsoft has several continuing concerns with the EWG’s proposals that could greatly impact the efficacy of a next generation gTLD Registration Directory Service (“RDS”):
<o:p></o:p></p>
<p class="MsoNormal" style="text-indent:.5in"> <o:p></o:p></p>
<p class="MsoListParagraph" style="margin-left:.75in;text-indent:-.25in">1)<span style="font-size:7.0pt;font-family:"Times New Roman","serif"">
</span><u>API-Based Searches:</u> Microsoft relies heavily on API-based searches to effectuate its botnet and malicious website takedowns. These automated searches allow Microsoft to identify criminal syndicates and hold them accountable for their criminal
activities, as it recently did with the <span style="color:#00B0F0"><a href="http://www.microsoft.com/en-us/news/press/2013/dec13/12-05zeroaccessbotnetpr.aspx"><span style="color:#00B0F0">ZeroAccess botnet</span></a></span> takedown, which infected over 2
million computers worldwide. Furthermore, these API-based searches assist in identifying domain names associated to trans-national organized crime networks involved in counterfeiting activities.<o:p></o:p></p>
<p class="MsoListParagraph" style="margin-left:.75in"> <o:p></o:p></p>
<p class="MsoListParagraph" style="margin-left:.75in">If Microsoft and criminal investigators lose the ability to run these automated API-based searches (e.g., by needing to manually justify each lookup), it would cripple current investigative techniques and
allow criminals to escape accountability. For this reason, Microsoft is encouraged that the EWG has listed as one of its Gated Access Principles that “[t]he RDS should accommodate automation for large-scale lookups for various use cases and purposes” (pg.
20), and we encourage the EWG to allow automated API-based searches in its Final Report without any obstacles for justified users.
<o:p></o:p></p>
<p class="MsoListParagraph" style="margin-left:.75in"> <o:p></o:p></p>
<p class="MsoListParagraph" style="margin-left:.75in;text-indent:-.25in">2)<span style="font-size:7.0pt;font-family:"Times New Roman","serif"">
</span><u>Reverse WHOIS Lookups:</u> Brand owners, including Microsoft, rely heavily on Reverse WHOIS lookups to investigate and pursue cybersquatters and infringers. However, other than the reference to “reverse WHOIS” on page 53, the Status Report does
not confirm that brand owners will be able to perform Reverse WHOIS lookups on certain data elements in the WHOIS information set. For example, brand owners can currently look up all domain names associated with a registrant’s e-mail address or name. They
can also order reports on a domain name’s WHOIS history. These reports allow brand owners to investigate the full scope of infringement and take action accordingly. If cybersquatters and infringers find a way to shield their activities behind multiple Contact
IDs, brand owners will need the ability to analyze overlapping data elements and WHOIS history. At a time when cybersquatting and infringement is bound to increase, preserving these tools is of paramount importance. <o:p></o:p></p>
<p class="MsoListParagraph" style="margin-left:.75in"> <o:p></o:p></p>
<p class="MsoListParagraph" style="margin-left:.75in;text-indent:-.25in">3)<span style="font-size:7.0pt;font-family:"Times New Roman","serif"">
</span><u>Privacy / Shield Reveal Requests:</u> While the EWG answered Microsoft’s question about the process for submitting a reveal request, Microsoft disagrees with the EWG’s recommendation that the proxy service provider assess whether a requester has
articulated an “actionable” harm (pg. 40). Determining whether something is “actionable” is necessarily a function of local law and could put the proxy service provider in the inappropriate position of making legal determinations. Instead, the requester
should simply be required to allege the legal basis for the reveal request along with a statement that the request is submitted in good faith.
<o:p></o:p></p>
<p class="MsoListParagraph"> <o:p></o:p></p>
<p class="MsoListParagraph" style="margin-left:.75in;text-indent:-.25in">4)<span style="font-size:7.0pt;font-family:"Times New Roman","serif"">
</span><u>Accreditation Process / Purpose-Based Access:</u> Several of Microsoft’s questions related to the RDS accreditation process and RDS lookup “purpose” have gone unanswered, though they remain vitally important. In the EWG’s next report, it should
clarify the “legal action” and “abuse mitigation” categories of “purpose-based access”, and explain that users are not required to take action on each and every lookup to remain a user in good standing.
<o:p></o:p></p>
<p class="MsoListParagraph"> <o:p></o:p></p>
<p class="MsoListParagraph" style="margin-left:.75in;text-indent:-.25in">5)<span style="font-size:7.0pt;font-family:"Times New Roman","serif"">
</span><u>Expiration Dates:</u> The EWG did not recommend that a domain name’s expiration date be included in the WHOIS data set. This data point is common in WHOIS reporting today, as evidenced by the sample WHOIS report displayed on page 35 of the Status
Update Report. The expiration date allows companies to decide whether to take legal action in the case of infringement or, in cases of non-infringement, whether to acquire a domain name or wait for it to lapse. Given the utility of this information and the
minor burden on registrars to provide it, the EWG should make a domain name’s expiration date available to all users.
<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">Microsoft would like to reiterate its appreciation for the work of the EWG in tackling this complex subject. If the EWG would like to schedule a call with a representative of Microsoft’s Cybercrime Center to discuss any of the above in
greater detail, please let us know.<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">Sincerely,<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">David Jaquette<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" style="border-collapse:collapse">
<tbody>
<tr style="page-break-inside:avoid;height:.2in">
<td width="240" valign="top" style="width:2.0in;padding:0in 0in 0in 0in;height:.2in">
<p class="MsoNormal" style="margin-top:2.0pt;line-height:15.0pt"><span style="font-size:15.0pt;font-family:"Segoe UI","sans-serif";color:#0172C6"><img border="0" width="138" height="30" id="Picture_x0020_17" src="cid:image003.jpg@01CF43BA.6E43D130" alt="Description: MSFT_logo_Gray DE sized SIG1.png"><o:p></o:p></span></p>
</td>
<td width="420" valign="top" style="width:3.5in;padding:0in 0in 0in 0in;height:.2in">
<p class="MsoNormal" style="line-height:15.0pt"><span style="font-size:15.0pt;font-family:"Segoe UI","sans-serif";color:#0172C6">David Jaquette<o:p></o:p></span></p>
</td>
</tr>
<tr style="page-break-inside:avoid;height:1.5in">
<td width="240" valign="top" style="width:2.0in;padding:0in 0in 0in 0in;height:1.5in">
<p class="MsoNormal" style="line-height:15.0pt"><span style="font-size:10.0pt;font-family:"Segoe UI","sans-serif";color:#505050"><o:p> </o:p></span></p>
</td>
<td width="420" valign="top" style="width:3.5in;padding:0in 0in 0in 0in;height:1.5in">
<p class="MsoNormal" style="line-height:15.0pt"><span style="font-size:10.0pt;font-family:"Segoe UI","sans-serif";color:#505050">Trademark Attorney<o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:15.0pt"><span style="font-size:10.0pt;font-family:"Segoe UI","sans-serif";color:#505050">LCA – Legal and Corporate Affairs<o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:15.0pt"><span style="font-size:10.0pt;font-family:"Segoe UI","sans-serif";color:#505050">Office: (425) 722-3829<o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:15.0pt"><span style="font-size:10.0pt;font-family:"Segoe UI","sans-serif";color:#505050"><a href="mailto:davidjaq@microsoft.com"><span style="color:blue">davidjaq@microsoft.com</span></a><o:p></o:p></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>