An anonymous reader writes "Remember VeriSign's SiteFinder? Turns out that a couple of months back VeriSign was granted a patent on resolving unregistered domains. This came about thanks to its acquisition of eNic, operator of the .CC Domain. How long before Verizon, Earthlink, and OpenDNS are hit up for licensing fees?"
Well i think it would be cool if someone webcrawled my apache server and people could find it without me having to be a whatever.com of course i'd have to have a static ip but thats ok.
The bad news is, of course, that it's very likely not a patent troll -- that is, it's very likely that VeriSign actually intends to encourage this behavior.
Maybe we should patent REALLY BAD IDEAS to prevent them from spreading. Of course, it's hard to imagine in advance that ISPs and a company like VeriSign would make a business from poisoning and subverting DNS.
After having been trivial, obvious, and awash with prior art by the gallery for decades previously.
None of the presidential candidates, AFAIK, has said peep #1 about patent reform. Hm.
Are we discusing the same Verizon? The one that made every single failed lookup on DNS for the *.com domain, which htey manage, resolve to their advertising pages? It broke a huge number of DNS testing tools, and caused all sorts of nasty traffic problems.
The chance of Verisign blocking this kind of behavior, except to protect the turf so that only they can do it, is so small as to be the same of making SCO admit they lied about owning UNIX.
i start to use SSL certs other than verisign, and advise my clients to do as such too, and you all do that too, and with that reaction shove that patent up verisign's butt ?
And other than VeriSign, whose code signing certificates are accepted for 64-bit kernel mode code in Windows Vista? Comodo's certificates aren't [tech-pro.net].
I couldn't find home PCs with any operating system other than Windows Vista or Mac OS X at any store that I visited in Fort Wayne, Indiana. Even Wal-Mart didn't have any PCs running Linux for sale. So should everybody who wants to buy a home PC without contributing to VeriSign's driver signing monopoly get either a Mac or a Dell [dell.com]?
While that certainly helps OpenDNS users (though yours is the first mention I've *ever* seen of a means to disable their redirect advertising), it doesn't do a darn thing for all the Earthlink and Charter (and others) ISP subscribers who are having this forced down their throats by a service they PAID for.
That's not true. Look under "shortcuts" in your network preferences and turn off the proxy. It doesn't bother 99.99% of our users and it makes shortcuts and google work beautifully, as both should. But if you don't like it, turn it off.:-)
Imagine verisign charging an absolutely absurd amount for their licensing. I mean totally out of line, like $1M/month. Don't want to pay licensing? Don't infringe.
That would dramatically reduce the amount of this DNS perversion going on.
Not that this is going to happen, but it's an interesting prospect to think about. Heaven forbid the system be taken advantage of to the benefit of the people.
If they make it something reasonable, they get to collect license fees. Money for no work. If they use your idea they get nothing except respect from the community.
And if it were anyone but Verisign, I might believe you. Honestly, if I ever design a network protocol, I am going to patent every possible way I can think of to abuse it down the road...
However, since we are talking about Verisign here, I'm sure this is just business as usual. Watch for announcement of a licensing deal with Earthlink in the not to distant future.
My ISP has recently joined the ranks of retards who return an incorrect result when a domain is not found. I've been looking around but it's unclear who is out there running DNS that I am welcome to use, that is worth using, and that is likely to be at the same IP for a long time. Whose servers should I use?
OpenDNS is designed to give you almost exactly what you don't want.
designed to, yes, but it's not mandatory.
i've been using OpenDNS for the last month or so and have found it to be very good -- much, much faster than my ISP's DNS, and reliable. i get the standard "not found" messages rather than "useful" search results and ads if i type a wrong address, since i've switched off all OpenDNS's extra features for my IP. there were one or two features which looked like they may have been useful which had to al
my ISP gives me a dynamic ISP, and so i have to have a daemon keep OpenDNS up to date with my latest IP. no biggie.
I don't get it, does this result in leaving a long wake of IPs configured to not return stupid results in OpenDNS? I mean, if so, you're providing a valuable service, but it seems like they're pretty retarded. Then again, anyone who would return a bogus, non-compliant result when a standard service is requested is an ass, anyway.
i don't set OpenDNS up for all of my ISP's users -- just me!
The configuration is by-IP, right? So in that case, you're configuring it for that IP, right?
i wrote a little script which periodically checks our network's current IP against a file containing the last one recorded. if it's different, it queries OpenDNS's DNSomatic service, which then updates OpenDNS's record of my IP.
Do you really need to do any periodic checking? Whether it's pppd or dhclient, your system knows when the IP changes. Wouldn't it make more sense to fire on lease renewal, or when the ppp interface comes up?
i haven't heard of pppd before, but i don't see how it'd know my network's WAN IP unless it, too, checks periodically.
Oh, I see. I was somehow under the mistaken impression that you were running something more complicated.
Depending on the model you could load some alternate firmware that provided a simple Linux distribution, there's a few out there. But then management becomes more complicated, of course. If you did, though, you could install this functionality to the router.
pppd would apply to a modem connection. My gateway is a laptop running Linux, with two ethernet interfaces and a modem. One ethernet interface goe
It's optional. If you want the people using your network to do whatever they're supposed to do, rather than going to porn sites and reading Slashdot, you can specify sites to block. If you just want to use it because your ISP is run by a bunch of Cox, just disable the phish filter and typo correction while setting up your account. No ads, no voluntary censorship, and it doesn't suck as much as whatever you're trying to avoid.
As for Verislime's antics, make a wildcard record and complain loudly to ICANN.
My ISP has recently joined the ranks of retards who return an incorrect result when a domain is not found.
I've been annoyed to find this happening more and more. What really irks me is that this breaks Mozilla's handy location bar search [mozillazine.org] for one-word queries. Is there any workaround for this? Perhaps an addon could be made to ignores hostname lookup results that match common catch-all servers.
Typically the ISP is just having their own DNS servers do this (as opposed to using a hidden DNS proxy). The solution is to run your own resolving cache.
I'm trying to avoid going to the root servers, which I understand is considered to be rude if you're just joe schmoe and don't have a bunch of users behind you.
Thus, even running my own cache (actually, I'm using dnsmasq for local resolution) I still need forwarders. I just don't want to use the ones from my ISP.
Do you mean root (".") or TLD (".com" et al) servers. Sorry to ask but a lot of people say "root" but mean "tld". Anyway, primary the root zozne yourself. Run a copy of.com locally. Stop sucking on the tit of US government run DNS servers; we've been babied for 20 years and we really at this point should be doing this stuff for ourselves.
Somebody ought to look in the wayback machine for alternic.net. I have a vague memory of Kashpureff doing this well before 2001. Talk abourt irony. (He went to jail for hac
Do you mean root (".") or TLD (".com" et al) servers. Sorry to ask but a lot of people say "root" but mean "tld".
Not sure, don't feel bad. AFAIK I mean root. I've done it with both BIND 4 and 9 in the past. I have this tendency to quickly learn what I need to get something working and forget it though. I've more recently got into the habit of writing howtos whenever I do anything because of this. But I've done bind 9 with DDNS and all kinds of fun stuff like that in the past - right now I'm just on the lazy train.
There are so many things wrong with this. The first one is that it doesn't actually work as indicated in Claim 1, because it's operating at the wrong levels of the protocol stacks. DNS maps between names and IP addresses, and is used for many different kinds of Layer 4, 5, and 7 applications, but URLs are a Layer 7 function typically supported by browsers, and the identification of what kind of service the client is interested in is not known at name resolution time, or even what Layer 4 transport protocol or Layer 7 application protocol, and in fact the methods used in the patent have the DNS operator's web server decide what kind of response web page to provide in response to a URL included in a HTTP request, even though the client's DNS request might not have been intended to be used for HTTP. When Verisign implemented their annoying breakage of DNS functionality, they supported HTTP on port 80, and had a stub email server that did a sloppy approach to rejecting connections, and AFAICT didn't provide other services, such as correct rejections on SSL's TCP Port 443 or SSH's TCP port 22. It's not clear that they even did the right thing at Layer 3 - if you were trying to "ping misspellllled-example.com", they not only should have answered the DNS request with a "No Such Domain" error message, but if you sent it a ping, it shouldn't respond (I forget if they responded to pings or not; many systems don't do that for self-defense.)
Another reason this patent shouldn't have been accepted is that wildcard domains were a standard capability, and having a web server try to provide useful information in a 404 page was probably a known capability, or at least obvious to someone skilled in the trade. Responding to a DNS request with the IP address of a web server that isn't the one the customer was looking for might not count as "obvious to someone skilled in the trade" because it's obviously wrong.
There's no reason not to permit a patent on doing something noncompliant. There is however every reason not to permit them to do it. At the very least, they should not be permitted to refer to their name resolution service as "DNS" because they are not following the RFC; in addition they should be required to inform all customers that they are operating noncompliant services. This is the type of regulation that government should perform, in order to allow consumers to make well-informed choices.
Another reason this patent shouldn't have been accepted is that wildcard domains were a standard capability, and having a web server try to provide useful information in a 404 page was probably a known capability
It's stupid, but that doesn't mean nobody's ever done it - my ranting is as grumpy as it is because Verisign did it and several other sets of people have done it since then. Verisign's attempt was really egregious, since they're the main registrar for.com and.net, and ICANN yelled at them until they stopped (one of the few times I think ICANN has really done the Right Thing.) Most of the other people who've done it are ISPs (who shouldn't do that, but you can always set your system to point to some othe
''' The Federal Communications Commission has recently encountered mounting scrutiny in response to its broad deregulatory practices. Public frustration regarding the FCC has peaked at a time of fierce debate on net neutrality.
In a memo obtained Tuesday by The Washington Post, 30 current and former commission employees complained about the leadership of FCC Chairman Kevin Martin.
Staff members observed that "the FCC process appears broken and most of the blame appears to rest with Chairman Martin."
The memo, written to chairman of the House Energy and Commerce Committee John Dingell and chairman of the House Energy Subcommittee on Oversight and Investigations Bart Stupak, increases pressure on the FCC chairman, who, in particular, has been accused of a rigidly anti-regulatory, pro-corporate approach. Many critics assert that his approach has contributed to a lack of oversight over network providers. '''
What's a little deregulation between friends, right?
I sincerely hope they sue Earthlink, because maybe then Earthlink will stop the stupid practice of NOT returning a failure when the domain is not found.
It is getting ever more difficult to find DNS that just works as it should, instead of coming up with a result for every request, even if it has to make one up.:o(
Wildcarding domains is a very old, in Net terms, practice. All you have to do to have it work at the registry level is to wildcard the top level. It's a trivial one line per top-level domain for which you want to do this in BIND. There's nothing novel or even particularly interesting about it.
Doesn't patent 6,332,158 [uspto.gov] already cover what is in Verisign's patent 7,337,910 [uspto.gov]? It seems that the 2nd patent (7,337,910) should at least reference the 1st patent under the "Related US Patent Documents" section.
How does one submit a bug-report against a US Patent? Maybe the USPTO needs to open up a bugzilla DB to handle things like this?
Better link (Score:3, Informative)
Server (Score:2, Funny)
This is a useful patent for a change. (Score:1, Insightful)
Re: (Score:3, Funny)
Re: (Score:2, Interesting)
Re: (Score:2)
Oh the Humanity (Score:5, Insightful)
Flash Wars: Adobe in the History and Future of Flash [roughlydrafted.com]
Re: (Score:3, Funny)
Re: (Score:3, Interesting)
None of the presidential candidates, AFAIK, has said peep #1 about patent reform. Hm.
That might be a good thing... (Score:4, Insightful)
Re: (Score:3, Insightful)
The chance of Verisign blocking this kind of behavior, except to protect the turf so that only they can do it, is so small as to be the same of making SCO admit they lied about owning UNIX.
How about (Score:1)
Re: (Score:3)
VeriSign bought Thawte and GeoTrust.
And other than VeriSign, whose code signing certificates are accepted for 64-bit kernel mode code in Windows Vista? Comodo's certificates aren't [tech-pro.net].
Re: (Score:2)
VeriSign is the dot in .com (Score:2)
We can boycott Verisign
VeriSign is the dot in .com and .net [verisign.com]. Good luck boycotting that.
in addition to Vista. :P
I couldn't find home PCs with any operating system other than Windows Vista or Mac OS X at any store that I visited in Fort Wayne, Indiana. Even Wal-Mart didn't have any PCs running Linux for sale. So should everybody who wants to buy a home PC without contributing to VeriSign's driver signing monopoly get either a Mac or a Dell [dell.com]?
Re: (Score:2)
Dell, Mac or get a tech friend to make you one at three quarters of the price.
All get around having to buy a copy of Vista.
RapidSSL is VeriSign (Score:2)
But prior art... (Score:2, Funny)
Re: (Score:2, Funny)
This may be the only Slashdot thread ever that where a goatse link becomes on-topic.
Good! (Score:3, Insightful)
p
Re: (Score:2, Informative)
Re: (Score:2)
p
Re:Good! (Score:4, Informative)
-davidu
Parent
This COULD be a good thing, done properly (Score:2, Insightful)
That would dramatically reduce the amount of this DNS perversion going on.
Not that this is going to happen, but it's an interesting prospect to think about. Heaven forbid the system be taken advantage of to the benefit of the people.
Could, but won't (Score:2)
If they make it something reasonable, they get to collect license fees. Money for no work. If they use your idea they get nothing except respect from the community.
I know which one they're going to pick.
Re: (Score:2)
However, since we are talking about Verisign here, I'm sure this is just business as usual. Watch for announcement of a licensing deal with Earthlink in the not to distant future.
Obligatory Behind-the-times Question (Score:4, Interesting)
Re: (Score:3, Informative)
http://www.opendns.com/ [opendns.com]
Re: (Score:3, Informative)
Sorry.
Re: (Score:2)
Re: (Score:3, Informative)
designed to, yes, but it's not mandatory.
i've been using OpenDNS for the last month or so and have found it to be very good -- much, much faster than my ISP's DNS, and reliable. i get the standard "not found" messages rather than "useful" search results and ads if i type a wrong address, since i've switched off all OpenDNS's extra features for my IP. there were one or two features which looked like they may have been useful which had to al
Re: (Score:2)
I don't get it, does this result in leaving a long wake of IPs configured to not return stupid results in OpenDNS? I mean, if so, you're providing a valuable service, but it seems like they're pretty retarded. Then again, anyone who would return a bogus, non-compliant result when a standard service is requested is an ass, anyway.
Re: (Score:2)
i don't set OpenDNS up for all of my ISP's users -- just me!
The configuration is by-IP, right? So in that case, you're configuring it for that IP, right?
i wrote a little script which periodically checks our network's current IP against a file containing the last one recorded. if it's different, it queries OpenDNS's DNSomatic service, which then updates OpenDNS's record of my IP.
Do you really need to do any periodic checking? Whether it's pppd or dhclient, your system knows when the IP changes. Wouldn't it make more sense to fire on lease renewal, or when the ppp interface comes up?
Re: (Score:2)
i haven't heard of pppd before, but i don't see how it'd know my network's WAN IP unless it, too, checks periodically.
Oh, I see. I was somehow under the mistaken impression that you were running something more complicated.
Depending on the model you could load some alternate firmware that provided a simple Linux distribution, there's a few out there. But then management becomes more complicated, of course. If you did, though, you could install this functionality to the router.
pppd would apply to a modem connection. My gateway is a laptop running Linux, with two ethernet interfaces and a modem. One ethernet interface goe
Re: (Score:2)
As for Verislime's antics, make a wildcard record and complain loudly to ICANN.
Breaks location bar search; workarounds? (Score:2)
My ISP has recently joined the ranks of retards who return an incorrect result when a domain is not found.
I've been annoyed to find this happening more and more. What really irks me is that this breaks Mozilla's handy location bar search [mozillazine.org] for one-word queries. Is there any workaround for this? Perhaps an addon could be made to ignores hostname lookup results that match common catch-all servers.
Re: (Score:3, Interesting)
I'm trying to avoid going to the root servers, which I understand is considered to be rude if you're just joe schmoe and don't have a bunch of users behind you.
Thus, even running my own cache (actually, I'm using dnsmasq for local resolution) I still need forwarders. I just don't want to use the ones from my ISP.
Re: (Score:3, Interesting)
Anyway, primary the root zozne yourself. Run a copy of
Somebody ought to look in the wayback machine for alternic.net. I have a vague memory of Kashpureff doing this well before 2001.
Talk abourt irony. (He went to jail for hac
Re: (Score:2)
Do you mean root (".") or TLD (".com" et al) servers. Sorry to ask but a lot of people say "root" but mean "tld".
Not sure, don't feel bad. AFAIK I mean root. I've done it with both BIND 4 and 9 in the past. I have this tendency to quickly learn what I need to get something working and forget it though. I've more recently got into the habit of writing howtos whenever I do anything because of this. But I've done bind 9 with DDNS and all kinds of fun stuff like that in the past - right now I'm just on the lazy train.
Many Reasons this is Appalling (Score:5, Interesting)
Another reason this patent shouldn't have been accepted is that wildcard domains were a standard capability, and having a web server try to provide useful information in a 404 page was probably a known capability, or at least obvious to someone skilled in the trade. Responding to a DNS request with the IP address of a web server that isn't the one the customer was looking for might not count as "obvious to someone skilled in the trade" because it's obviously wrong.
Re: (Score:2)
There's no reason not to permit a patent on doing something noncompliant. There is however every reason not to permit them to do it. At the very least, they should not be permitted to refer to their name resolution service as "DNS" because they are not following the RFC; in addition they should be required to inform all customers that they are operating noncompliant services. This is the type of regulation that government should perform, in order to allow consumers to make well-informed choices.
Another reason this patent shouldn't have been accepted is that wildcard domains were a standard capability, and having a web server try to provide useful information in a 404 page was probably a known capability
I don't u
Re: (Score:3, Insightful)
rr is doing this too (Score:2)
on a related net neutrality issue: (Score:4, Interesting)
'''
The Federal Communications Commission has recently encountered mounting scrutiny in response to its broad deregulatory practices. Public frustration regarding the FCC has peaked at a time of fierce debate on net neutrality.
In a memo obtained Tuesday by The Washington Post, 30 current and former commission employees complained about the leadership of FCC Chairman Kevin Martin.
Staff members observed that "the FCC process appears broken and most of the blame appears to rest with Chairman Martin."
The memo, written to chairman of the House Energy and Commerce Committee John Dingell and chairman of the House Energy Subcommittee on Oversight and Investigations Bart Stupak, increases pressure on the FCC chairman, who, in particular, has been accused of a rigidly anti-regulatory, pro-corporate approach. Many critics assert that his approach has contributed to a lack of oversight over network providers.
'''
What's a little deregulation between friends, right?
I sincerely hope they sue Earthlink... (Score:3, Interesting)
It is getting ever more difficult to find DNS that just works as it should, instead of coming up with a result for every request, even if it has to make one up.
*mutter* *mutter* *mutter*
Tomas
Re: (Score:2)
good! (Score:2)
Sue the ISC and BIND book publishers? (Score:2)
tinydns patch to ignore sitefinder (Score:2)
Turns A records for certain IP addresses back into NXDOMAIN results.
BUG: Verisign patent conflicts with older patent? (Score:2)
How does one submit a bug-report against a US Patent? Maybe the USPTO needs to open up a bugzilla DB to handle things like this?