FROM A CONFERENCE TALK TO AN RDAP EXTENSION
REGISTERED WITH IANA.

Research & Innovation

From DeepSec Vienna 2025 to an RDAP extension registered with IANA

Registrar reliability: from a conference talk to an IANA-registered RDAP extension
Alessandro Bertoldi (Bertoldi Cybersecurity)
DeepSec talk, ideas and revisions: Enrico Bertoldi, Simon Pietro Romano, Emanuele Galdi, Giovanni Minotti
IETF Internet-Draft: Alessandro Bertoldi and Simon Pietro Romano (University of Naples Federico II)

1. The talk, DeepSec Vienna 2025. ∞ Day at Scale: Hijacking Registrars, Defeating 2FA and Spoofing 17,000+ Domains Even with DMARC.

What happens when a registrar is the weakest link in your security chain? This talk reveals how systemic failures in credential recovery, 2FA bypass, and email spoofing allow persistent exploitation even when domains have SPF, DKIM, and DMARC p=reject properly configured.

Based on real-world research conducted between 2018 and 2025, we present ∞-day (forever-day) vulnerabilities affecting over 17,000 domains, including cross-tenant spoofing in N-Able Mail Assure and flaws in Register.it's identity recovery procedures. We demonstrate full control over customer panels with zero credentials, using only PDF forms and social engineering.

We also propose a concrete solution: a Reliability Scoring System for registrars and a “Green Check” trust mark for end users, integrated with RDAP and aligned with the NIS2 directive. This talk challenges assumptions about authentication, identity, and trust in Internet infrastructure, and offers both attack and defense insights.

2. The Internet-Draft, IETF REGEXT. The Reliability Scoring proposed in the talk became draft-bertoldi-regext-rdap-reliability-scoring, written with Simon Pietro Romano and discussed in the IETF REGEXT working group. It defines how the result of a reliability or security assessment of a registrar or a domain travels inside an RDAP response: it standardises the transport of the result, not the way the result is calculated, and it does not express any judgement of its own. Revision -04 was published on 22 September 2026 and the draft is on the agenda of IETF 127 in San Francisco, November 2026. It is a work in progress and is not an IETF standard.

3. The registered extension, IANA, 6 October 2026. IANA added the extension identifier reliabilityAssessment to the RDAP Extensions registry, with Bertoldi Cybersecurity as the contact and the specification bcsec-RDAP-RA, Version 1, as its reference. The specification is published under CC BY 4.0; its bytes are frozen at the canonical URL and will not change, and any editorial note goes into a separate errata file. About the registration: it is not offered as IETF work, it asserts no consensus of any kind, and it states that it is not intended to foreclose any decision this working group may take. It exists so that implementers have a stable reference now, while the discussion in REGEXT continues.