Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Paul Vixie And David Maher On VeriSign Wildcarding

Posted by timothy on Tue Sep 23, 2003 09:43 PM
from the ain't-fair-fellas dept.
chromatic writes "The O'Reilly Network has just published an interview with Paul Vixie, chairman of the board of the Internet Software Consortium and a primary author of BIND. Topics include the recent VeriSign controversy, ISC's BIND patch in response, and other potential issues that might come to light in the near future." On a related note, dmehus writes with a link to the letter sent by David Maher, chairman of the Public Interest Registry -- the .org registrar, to ICANN President and CEO Paul Twomey. "The letter says that it supports ICANN's call for VeriSign to voluntarily suspend SiteFinder and the Internet Architecture Board preliminary position paper. It goes on to say that PIR will not be implementing any DNS wildcard to the .ORG zone. It urges ICANN to stand its ground, but also to implement a policy preventing registries from taking this kind of unilateral action in the future." The letter is in .doc format, but AbiWord and OpenOffice.org both open it fine.
This discussion has been archived. No new comments can be posted.
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • by Anonymous Coward on Tuesday September 23 2003, @09:43PM (#7040160)
    They sure break up the SCO stories.
  • To be honest (Score:2, Flamebait)

    by Dancin_Santa (265275) <DancinSanta@gmail.com> on Tuesday September 23 2003, @09:44PM (#7040166)
    (Last Journal: Friday December 24 2004, @08:49PM)
    I kind of like the Verisign redirect. I sometimes mistype URLs and the Verisign page usually has a link to the page I was looking for. It's a pretty nice system considering the alternatives.
    • Re:To be honest by geoffspear (Score:1) Tuesday September 23 2003, @09:50PM
    • Re:To be honest (Score:5, Insightful)

      by Desert Raven (52125) on Tuesday September 23 2003, @09:52PM (#7040217)
      Gee, that's nice, but in the meantime, it aids spammers, since I can no longer tell if the sender's address is from a valid domain. With Verisign's corruption of the root servers, *all* .com and .net domains will now come back as being valid.

      You're telling me that if you get a "server not found" page, you're too stupid to figure out you misspelled something?

      This is an absolute abuse of Verisign's position. They are contracted to *maintain* the database, not warp it to their own *commercial* purposes. If this was actually a valid service, they would have had no trouble with proposing it to the Internet standards bodies before implementing it. Instead, they're defying those organizations. Worse yet, they've actually put me in the position of agreeing with ICANN.
      [ Parent ]
      • Re:To be honest by Anonymous Coward (Score:3) Tuesday September 23 2003, @10:20PM
        • Re:To be honest by ePhil_One (Score:2) Wednesday September 24 2003, @09:43AM
      • Re:To be honest by switcha (Score:2) Tuesday September 23 2003, @10:35PM
        • Re:To be honest (Score:5, Informative)

          by Atzanteol (99067) on Tuesday September 23 2003, @10:54PM (#7040520)
          (http://www.edespot.com/~amackenz/)
          The problem is that Verisign is doing their wildcarding at the DNS level. This effects the entire *internet*, not just the World Wide Web. So not only do you get directed to their site on your web-browser, but also if you lookup domains for telnet, ftp, ssh, smtp, etc. This causes problem for (among other things) spam filters, who check that your domain exists (well, now *all* .com domains exist) before delivering mail.

          Verisign is being extremely short-sighted. This whole deal reeks of a moronic manager who thught this would be a 'wonderful' idea.
          [ Parent ]
          • Re:To be honest (Score:4, Interesting)

            by BiggerIsBetter (682164) <richard.vems@co@nz> on Tuesday September 23 2003, @11:24PM (#7040665)
            (http://www.vems.co.nz/)
            Good point. We've heard lots of names or folks who are fighting the Good Fight (like Paul Vixie and David Maher) but who is actually responsible for this? Sure, Verisign is the company and they have their spokespersons/spindoctors, but who are the actual people who thought this up and implemented it? This shite affects all of us, so no more hiding behind the company doors.
            [ Parent ]
            • The Executive Team by BiggerIsBetter (Score:3) Tuesday September 23 2003, @11:28PM
              • Re:The Executive Team by Anonymous Coward (Score:1) Tuesday September 23 2003, @11:42PM
              • Re:The Executive Team (Score:5, Informative)

                by switcha (551514) on Wednesday September 24 2003, @12:05AM (#7040893)
                I'd guess the guy [verisign.com] responsible for "the company's globally deployed registration and resolution infrastructure that currently supports the Internet's Domain Name System (DNS)."
                [ Parent ]
              • 1 reply beneath your current threshold.
          • Re:To be honest by 11223 (Score:2) Wednesday September 24 2003, @01:07AM
        • Re:To be honest by iCEBaLM (Score:2) Wednesday September 24 2003, @07:36AM
        • 1 reply beneath your current threshold.
      • Re:To be honest (Score:4, Insightful)

        by gothicpoet (694573) on Wednesday September 24 2003, @03:23AM (#7041611)
        (http://www.designby.com/ | Last Journal: Wednesday October 22 2003, @05:12AM)
        This is an absolute abuse of Verisign's position. They are contracted to *maintain* the database, not warp it to their own *commercial* purposes. If this was actually a valid service, they would have had no trouble with proposing it to the Internet standards bodies before implementing it. Instead, they're defying those organizations. Worse yet, they've actually put me in the position of agreeing with ICANN.

        With those words (an absolute abuse) you just described most of what Verisign has done.

        Folks should remember, this is the company that was contracted to *maintain* the database until one day they decided that they *owned* the database... (errr... okay... if I get paid to clean all the cars at the dealership can I decide one day that I own them all and get away with it?)

        And yet somehow years after that magical acquisition of property rights they've still got the contracts. They've gotten away with all kinds of stuff and like a spoiled child they'll keep taking more until (if ever) someone takes away their privileges and sends them to time out.

        Gotta agree with you that there's no way that any benefits that stupid Sitefinder page provides make up for the abuse of position and random chaos it's caused.

        [ Parent ]
      • 1 reply beneath your current threshold.
    • Re:To be honest (Score:5, Insightful)

      by tehdely (690619) <usemike@spamblocked.com> on Tuesday September 23 2003, @09:56PM (#7040240)
      (Last Journal: Saturday November 29 2003, @03:51AM)
      Though you've been modded flaimbait, I'm assuming you were simply posting from the perspective of a strictly web user, who could presumably be helped (emphasis on presumably) by being redirected to SiteFinder and pointed to the proper site.

      I think the main thing that has admins screaming, however, is that SiteFinder breaks so many other services just to provide a questionable service for web surfers. Sure, surfers may benefit, but email admins, DNS admins, and many others are banging their heads against the wall because of the problems Verisign's divergence from accepted protocol has caused them.

      Just a thought.
      [ Parent ]
      • Re:To be honest (Score:5, Interesting)

        by Anonymous Coward on Tuesday September 23 2003, @10:43PM (#7040476)

        (Posted anonymously to avoid a rampaging mob outside my house)

        I'm a professional spammer. Well, that's a harsh term. I run bulk-email servers. I trust my clients that their entire list has double opted-in when they say so. Most are quite legitimate mailing lists; some are probably not.

        This new bug is a godsend, but not for the reason a lot of people are saying. I don't fake "from" addresses, so I don't get any added anonymity from a wildcard.

        What I do get is the ability to send my emails that have bad domains in them to a nominally but not effectively existant box at Verisign. I no longer get bad domain bounces to worry about.

        [ Parent ]
        • Re:To be honest by Anonymous Coward (Score:2) Tuesday September 23 2003, @10:51PM
        • Re:To be honest by Anonymous Coward (Score:3) Tuesday September 23 2003, @11:38PM
        • Re:To be honest by Desert Raven (Score:1) Wednesday September 24 2003, @12:36AM
        • Re:To be honest by AndrewRUK (Score:1) Wednesday September 24 2003, @09:30AM
      • Re:To be honest by stiggle (Score:1) Wednesday September 24 2003, @04:35AM
      • 1 reply beneath your current threshold.
    • Re:To be honest (Score:5, Insightful)

      by LostCluster (625375) on Tuesday September 23 2003, @10:49PM (#7040503)
      But, do you really like that it's Versign doing this for you? Assuming you use IE, MSN already provided this service to you. Verisign has just exploited the DNS system to make their service come up in situations where MSN's used to come up. Other browser developers could have designed their own responses to the "NXDOMAIN" signal, but now Verisign has stopped returning "NXDOMAIN" and instead returns a redirect to their own site... That's what really rubs people the wrong way. Instead of returning the error code that people thought they could depend on, they're returning a redirect to a service you didn't ask for. Yeah, it's a pretty good service on its merits if they tried to sell it to you... but instead they're forcing it on some people who were happy with MSN's service or happy with the traditional error...
      [ Parent ]
    • Re:To be honest by wo1verin3 (Score:1) Tuesday September 23 2003, @11:06PM
      • Re:To be honest by Anonymous Coward (Score:1) Tuesday September 23 2003, @11:55PM
      • Re:To be honest by raju1kabir (Score:2) Wednesday September 24 2003, @01:03PM
    • Re:To be honest by mlk (Score:3) Tuesday September 23 2003, @11:24PM
    • Re:To be honest by 0x0d0a (Score:3) Tuesday September 23 2003, @11:29PM
    • The "fix" is in the wrong place by Chuck Chunder (Score:2) Tuesday September 23 2003, @11:31PM
    • Re:To be honest by Anonvmous Coward (Score:2) Tuesday September 23 2003, @11:41PM
    • Re:To be honest by 11223 (Score:2) Wednesday September 24 2003, @01:01AM
    • Re:To be honest by ckd (Score:2) Wednesday September 24 2003, @01:51PM
    • 4 replies beneath your current threshold.
  • legalities (Score:5, Insightful)

    by micronix1 (590179) on Tuesday September 23 2003, @09:46PM (#7040169)
    legally, is veri allowed to redirect requests to their own domain? if not, who has the rights to unused domain names?
    • Re:legalities (Score:4, Informative)

      by the uNF cola (657200) on Tuesday September 23 2003, @09:55PM (#7040232)
      register.com lost a suit similar to what you are talking about.

      when you buy a domain from rcom, your page automagically defaults to a page. This page is pretty much an advertisement for rcom and such. it drives revenue towards rcom.

      many MANY people thought this was crooked, so there was a civil suit.. which rcom lost.

      I couldn't see a case like this wouldn't run the same, since both the rcom parked-page service and this have search links and nifo that drive revnue to their respective companies...
      [ Parent ]
      • Re:legalities (Score:4, Insightful)

        by strags (209606) on Wednesday September 24 2003, @12:20AM (#7040976)
        I think you're overstating things a bit here. The register.com "coming soon" page was a convenience, nothing more - the moment you set valid DNS server addresses, your domain information is updated.

        This lawsuit was fairly frivolous if you ask me. It was covered on Slashdot a while back here [slashdot.org].

        This is nothing like the Verisign case - what they are doing is abusing a monopoly position, and in doing so, causing havoc with a number of internet-based pieces of software, most notably spam filters.

        [ Parent ]
        • Re:legalities by the uNF cola (Score:2) Wednesday September 24 2003, @02:19AM
    • Re:legalities (Score:4, Informative)

      by the uNF cola (657200) on Tuesday September 23 2003, @10:04PM (#7040289)
      a second note:

      if i register abacadaba.com, and abacadaba.com becomes the biggest thing next to yahoo and slashdot combined with sex.com... everyone would want to go to abacadaba.com, or so i hope.

      all mispellings on my idea, and my trademark if ihave it trademarked, will go to versign. they'd effectively be making money off of me via a transitive property.. sorta. people want to see my site which makes money, verisign takes all mispellings of my site.. people make verisign money!

      whoa.. i think i just proved step 2 :\
      [ Parent ]
      • Re:legalities (Score:4, Funny)

        by orthogonal (588627) on Tuesday September 23 2003, @11:01PM (#7040558)
        (Last Journal: Sunday April 16 2006, @10:03PM)
        the biggest thing next to yahoo and slashdot combined with sex.com

        Please, please, please never suggest slashdot combined with sex.com again.

        The vision that flashed in my head when I read it made me what to flush my eyes with acid while destroying my occipital lobe with a baseball bat.

        And I don't think I'll be able to keep down food for a week.
        [ Parent ]
      • Re:legalities by nfsilkey (Score:1) Wednesday September 24 2003, @09:00AM
      • Re:legalities by magores (Score:1) Tuesday September 23 2003, @10:37PM
      • Re:legalities by the uNF cola (Score:2) Wednesday September 24 2003, @02:26AM
      • Re:legalities by Zagadka (Score:1) Wednesday September 24 2003, @08:51AM
      • 1 reply beneath your current threshold.
    • Re:legalities by laird (Score:2) Tuesday September 23 2003, @11:35PM
      • Re:legalities (Score:4, Informative)

        by laird (2705) <[lairdp] [at] [gmail.com]> on Tuesday September 23 2003, @11:39PM (#7040730)
        (Last Journal: Monday April 07 2003, @07:39AM)
        plain old text mangles my post a bit, so here it is again. Sorry I didn't catch it in preview...

        I believe that Verisign's use of a wildcard to map all DNS requests for *.com to their web site violates the relevant RFC's.

        Going through all of the DNS RFC's, all of them assume or require that when a name is not found, the DNS server return an error.

        Going through them in historical order: RFC 811 specifies that if the name is not found, a 'NAMNFD' code is returned. RFC 1034 also talks about sending "a name error indicating that the name does not exist" and "A name error (NE). This happens when the referenced name does not exist. For example, a user may have mistyped a host name." It also discusses caching name errors for efficiency, which of course only makes sense if the authoritative DNS servers actually issue name errors (which Verisign is now not doing). RFC 1035 specifies that if "the domain name referenced in the query does not exist" that a "Name Error" be returned.

        There is a wildcard mechanism in RFC 1034, but it's defined to apply to '"*.<anydomain>", where <anydomain> is any domain name' which makes it pretty clear to me that it's not intended to apply to domains. To emphasise this, all of the examples of DNS wildcards are of the form *.X.COM or *.A.X.COM.
        [ Parent ]
        • Re:legalities by jdreed1024 (Score:2) Wednesday September 24 2003, @07:04AM
          • Re:legalities by laird (Score:2) Wednesday September 24 2003, @11:54PM
        • 1 reply beneath your current threshold.
  • by Anonymous Coward on Tuesday September 23 2003, @09:46PM (#7040171)
    How many times have you meant to go to goatse.cx and missed a letter, like goats.cx. This sort of site would help out users quite a bit. It could also offer other helpful suggestions, such as dogse.cx and pigse.cx.
  • Get your Patched BIND for Slackware (Score:5, Informative)

    by ksuMacGyver (562019) on Tuesday September 23 2003, @09:46PM (#7040176)
    (http://www.cis.ksu.edu/~harmon/)
    Get your Patched BIND for Slackware here: [dropline.net]

    The more ISPs that use this, the more uncommon the SiteFinder 'service' becomes---the less users expect it.

    Remember when popups where not expected? After using mozilla for a while I simply cannot stand them now!
    ---
  • Now this is interesting (Score:5, Interesting)

    From Vixie:

    Some people suggest that administration of the DNS is a public trust, and that VeriSign is merely the caretaker of this system, not its owner. And now VeriSign has abused that trust. That may be true. Before a few days ago it didn't matter whether VeriSign was the owner or a caretaker. Now it matters a lot. VeriSign kicked a sleeping dog. It's a bizarre thing to do. Was it really VeriSign's decision to make, unilaterally? Did it need permission to make this decision? If so, what entity has the authority to grant such permission?

    If you think about this from a social point of view, not just technical, this is absolutely fascinating (rather than just irratating/punch-provoking): here's an ability, that was theoretically possible all along, to have this big effect on something lots and lots of people use. No one made use of it before. Now someone has, and it's

    1. (presumably) made a bunch of money for those who did it, and
    2. pissed off a lot of -- but not all -- people.

    Who's responsible? Who gets to say "No, you can't do that", or "Yes, you can"?

    I know what I think is the right answer, and it's what (probably) the rest of you think. But the final answer isn't up to you and me, or at least not you and me alone. Watching that process of who-gets-to-decide is going to be at least as interesting and precedent-setting as what the final decision ends up being.

    • Re:Now this is interesting (Score:5, Insightful)

      by GigsVT (208848) on Tuesday September 23 2003, @10:13PM (#7040334)
      (Last Journal: Saturday June 30, @01:22AM)
      It's a question of the duties of a provider of infrastructure.

      There's a certain relationship between a consumer of infrastructure and a provider of it. The consumer must trust the infrastructure to do what it is supposed to do, and nothing more.

      This is no different from ISPs randomly redirecting users to their own branded search engine when you type in "www.google.com", or an ISP's employee intercepting passwords and using them to steal money.

      Infrastructure providers inherently have a lot of control over the services they provide. There is a duty there to provide the service as expected, without changing the content that is carried.

      Verisign's position as a chartered monopoly makes this duty even more important, because consumers have no choice to use an alternative.

      I'm not sure what you mean by "No one's made use of it before"... No one else could make use of it (in .com and .net), Verisign is, as I said, a monopoly.

      Other CCTLDs have used wildcards before, but no one much cares about some island that is abusing the CC system to make extra money.
      [ Parent ]
      • Re:Now this is interesting (Score:5, Interesting)

        I'm not sure what you mean by "No one's made use of it before"... No one else could make use of it (in .com and .net), Verisign is, as I said, a monopoly.

        Bad choice of words: As you mentioned, I understand that other TLD registrars have made use of this before. Amended sentence: no one in this position of power (.com and .net being what they are) has made use of this before.

        This:

        This is no different from ISPs randomly redirecting users to their own branded search engine when you type in "www.google.com", or an ISP's employee intercepting passwords and using them to steal money.

        and this from the comment below:

        I do....I, and all the other sysadmins out there, decide whether SiteFinder works or not.

        are exactly what I'm talking about when I say that this debate is fascinating. In all honesty, I'd give a lot to sit down w/whoever at Verisign and ask them these same questions -- not necessarily to provoke the answer that I feel is right, but just to see how separate groups of intelligent people come to utterly different answers about these questions.

        [ Parent ]
      • Re:Now this is interesting by innocent_white_lamb (Score:1) Wednesday September 24 2003, @12:44AM
    • Re:Now this is interesting (Score:5, Insightful)

      by Anonymous Coward on Tuesday September 23 2003, @10:22PM (#7040383)
      Who's responsible? Who gets to say "No, you can't do that", or "Yes, you can"?

      I do. I run the DNS servers at an ISP, and I am planning to apply the ISC patch that restricts delegation from root servers (as soon as the bugs are shaken out of it -- give it a week or two.) I, and all the other sysadmins out there, decide whether SiteFinder works or not.

      [ Parent ]
    • Re:Now this is interesting by Fnkmaster (Score:3) Tuesday September 23 2003, @10:53PM
    • Re:Now this is interesting (Score:4, Interesting)

      by TheLink (130905) on Tuesday September 23 2003, @11:51PM (#7040815)
      (Last Journal: Saturday January 06 2007, @01:13AM)
      Actually we have a voice.

      How about we give verisign what it wants - traffic to nonexistent domains.

      People with webpages should start having 1x1 img links to nonexistent domains. Should be one pixel by one pixel, in case the image from verisign is not desirable.

      e.g. img src=http://www.asdasdnrerwtc.com/ height=1 width=1

      That way verisign gets traffic for every page.

      You can even make a "broken ribbon" logo with a fancy table and lots of 1x1 images and coloured 1x1 image. There's a small chance it could get subverted and show the wrong image.
      [ Parent ]
      • 1 reply beneath your current threshold.
    • Re:Now this is interesting by feder (Score:1) Wednesday September 24 2003, @02:42AM
  • Entirely a nitpick, but... (Score:3, Informative)

    by tehdely (690619) <usemike@spamblocked.com> on Tuesday September 23 2003, @09:53PM (#7040221)
    (Last Journal: Saturday November 29 2003, @03:51AM)
    PV: I hope but I don't think so. I've heard that the patch works well, but VeriSign could bypass the patch. It could make synthesized responses look more like delegations. I don't think it will do that. VeriSign's spokesperson, Brian O'Shaughnessy, suggested that if people don't want this, they're free to block it. It's really meant to be a service for the supposedly inconvenienced web surfers. VeriSign maintains that its search page is
    more useful than 404 error messages. If VeriSign bypassed the patch, it would have to escalate things and retract these statements about how folks were free to block the wildcard.


    Though I agree with everything he said (and thought he did so quite eloquently), it's a bit disheartening to see the chairman of the ISC refer to NXDOMAIN as a 404.
  • I think we should all go there at once.

    We can say that we were all on our way to the grocery, made a wrong turn, and ended up at his house.

    Then we can demand to buy groceries.
    I'm sure he won't mind. Everyones ends up at his site for that reason, right?
  • by Anonymous Coward on Tuesday September 23 2003, @09:54PM (#7040225)
    Dr. Paul Twomey
    President & CEO
    ICANN
    4676 Admiralty Way
    Suite 330
    Marina del Rey, CA 90292

    September 22, 2003

    Dear Paul,

    Public Interest Registry (PIR), the operator of the registry of the .ORG domain, supports ICANN's call for the voluntary suspension of VeriSign's deployment of a DNS wildcard service. We believe that ICANN (and the entire Internet community) should take steps to prevent all registries from unilaterally implementing changes to DNS that redirect requests for invalid domain names to any other site. PIR will not offer any service that makes such a change in the DNS.

    PIR also supports the Internet Architecture Board (IAB) statement on the same subject as set forth at:
    http://www.iab.org/documents/docs/2003-09-20- dns-w ildcards.html

    DNS is a critical piece of Internet infrastructure. Internet services such as the WWW and Email rely on DNS to function, and there should be no interference with the established protocols until there is complete assurance of no negative impact on the DNS.

    In another context, the Internet Architecture Board (IAB) has commented:

    "At the core of all of the IAB's concerns is the architectural principle that the DNS is a lookup service which must behave in an interoperable, predictable way at all levels of the DNS hierarchy. Furthermore, as a lookup service it is such a fundamental part of the Internet's infrastructure that converting it to an application-based search service ... is not

    Page 2

    appropriate even in the case where the query presented would not normally map to a registered domain."

    The architectural principle referred to by the IAB is clearly violated by the changes proposed for the .COM and .NET domains.

    On Monday, September 15, VeriSign changed the behavior of the .COM and .NET TLDs by adjusting servers to respond to requests for non-existent domains with a reference to the VeriSign Site Finder web site, (in other words, "wildcarding"). To a requesting user, it appears that non-existent domains are valid, because they are directed to the Site Finder. There is no difference between the responses for valid domains versus invalid domains from VeriSign's TLD servers.

    Because the VeriSign Site Finder server makes it appear that a non-existent domain exists, the service introduces significant problems to critical Internet infrastructure. Many other important Internet protocols rely heavily on proper DNS behavior. The impact of VeriSign's Site Finder is unclear with respect to security of the DNS. Site Finder unilaterally precludes the use of a prevalent type of anti-spam mail filter that uses DNS to validate the domain of legitimate eMails.

    Because VeriSign's servers are authoritative for the .COM and .NET TLDs, the most prevalent of the TLDs, Internet users have little protection against the imposition of this flawed system. VeriSign implemented the Site Finder system with little advance notice or public commentary by the Internet community. We believe such unilateral behavior in changing a critical resource necessary for the world's information systems is inconsistent with the responsibilities of registries under their contracts with ICANN, particularly because of the necessity of DNS for other Internet resources to function properly.

    We are informed that other domain registries may be exploring services similar to the VeriSign Site Finder. (As noted above, PIR will
    Page 3

    not be one of them.) If this is the case, our comments concerning Site Finder apply with equal force to those other services. We believe that any such efforts to alter the TLD DNS systems, of which the VeriSign Site Finder appears to be the most prominent example, adversely affect the Internet infrastructure and the entire Internet community.

    Therefore,
  • $ strings letter-to-ICANN-re-SiteFinder-030921.doc | fmt | less
  • Word (Score:1, Funny)

    by Anonymous Coward on Tuesday September 23 2003, @09:57PM (#7040249)
    The letter is in .doc format, but AbiWord and OpenOffice.org both open it fine.

    Yep, it's obvious that this is slashdot.
    • Re:Word by Guilly (Score:1) Tuesday September 23 2003, @10:09PM
    • 1 reply beneath your current threshold.
  • First they came for .cx (Score:5, Funny)

    by lightspawn (155347) on Tuesday September 23 2003, @10:10PM (#7040322)
    (http://domain.broken...registrar.joker.com/)
    But I didn't care because I don't celebrate Christmas.

    Then they came for .museum
    but I didn't care because I haven't been in one in ages.

    Then they came for .a bunch of small countries
    But I didn't care because I've never heard of them.

    Then they came for .com and .net,
    and nobody cared because it's common business practice.

    Note: according to a posting I just looked up, at least 11 TLDs (.cc, .cx, .io, .mp, .museum, .nu, .ph, .td, .tk, .tv, .ws) pulled the same stunt. I probably got the relative times wrong too.
    • Re:First they came for .cx by Anonymous Coward (Score:3) Tuesday September 23 2003, @10:26PM
      • Re:First they came for .cx (Score:4, Informative)

        by Zocalo (252965) on Wednesday September 24 2003, @04:23AM (#7041778)
        (http://www.zocalo.uk.com/)
        Yes, museum uses a wildcard, so what? Firstly the intention to wildcard was right up there and stated in the original proposal for the domain, before it was even approved by ICANN. Unlike Verisign's contract with ICANN, in which they are explicitly instructed to return NXDOMAIN on their .COM and .NET domains (.ORG too, but that is now moot), MuseDoma had approval to do this.

        Why? Well firstly, .musuem is a highly restricted domain, and secondly it's all to do with how museums operate. If I go to the London Science Museum and start asking for paleontology information, they will redirect me across to the National History Museum. The wildcarding is just a virtual way of helping people find what they are looking for, which makes sense.

        ".com" on the otherhand, is a largely unregulated free for all of firstcome first served registrations and lawsuits, trying to apply a structure to that is insane. A good analogy I saw from another poster here on Slashdot was the difference between the alt.* and comp.sci.* heirarchies on Usenet. Do *you* want to try being a moderator on .alt?

        [ Parent ]
      • Re:First they came for .cx by danielsfca2 (Score:1) Wednesday September 24 2003, @06:31PM
      • 1 reply beneath your current threshold.
  • .org, .us, .do .it (Score:5, Interesting)

    by krray (605395) * on Tuesday September 23 2003, @10:14PM (#7040339)
    Whatever. Why aren't more people just ditching their precious .COM names. Think UPS.com or Amazon.com couldn't get away with switching? Sure they could...

    For those in the .US take a look at NIC.US [nic.us] which can point you to all the various registrars. Heck, it's cheaper -- typically $15/yr.

    The only thing Verisign will understand is people speaking with their dollars. And yes, I personally have switched my domains over to .US -- of course I'll handle the .COM traffic until they expire in a year or two. In the mean time everything going out says .US as of yesterday.

    Sure, business cards and letter head still say .COM, but they surely won't on the next order. Maybe a year.
  • Did anybody have any luck (Score:5, Interesting)

    by lightspawn (155347) on Tuesday September 23 2003, @10:14PM (#7040344)
    (http://domain.broken...registrar.joker.com/)
    getting their ISP to upgrade DNS servers to counter this threat?

    I'd appreciate any suggestions.
  • The root of the problem (Score:4, Insightful)

    by Anthony (4077) <adavid@adavid.com.au> on Tuesday September 23 2003, @10:15PM (#7040349)
    (http://adavid.com.au/ | Last Journal: Tuesday July 10, @10:09PM)
    This started about 1995 when people begain to conflate the Web with the Internet.
  • by SEE (7681) on Tuesday September 23 2003, @10:18PM (#7040361)
    (http://jargon-file.org/)
    Not quite on-topic, and a repost, but . . .

    1. The Department of Commerce [mailto]; VeriSign's contract to operate .com and .org was originally with them.
    2. The Federal Communications Commission [fcc.gov], which oversees telecommunications.
    3. The Senate Commerce Committee's Subcommittee on Communications [senate.gov]; contact the committee itself [senate.gov], the chairman [senate.gov], the ranking member [senate.gov], and any of the other members you'd like.
    4. The House Subcommittee on Telecommunications and the Internet [house.gov], including the committee itself [house.gov], the chairman [house.gov], the vice-chairman [house.gov], and the ranking member [house.gov].

    By email, phone, fax, telegram, or letter (or better, several of these), let them know what you think. These are the people who can give Verisign reasons to change their behavior.

  • Stop Verisign DNS Abuse Petition (Score:5, Informative)

    by GeorgeK (642310) on Tuesday September 23 2003, @10:18PM (#7040364)
    (http://www.kirikos.com/)

    It's now here [whois.sc] having been Slashdotted last time....on a better server this time, though (we hope!), so be gentle....

    It's good to see that PIR is taking the high road. If .com/net are ever redelegated, I'd much rather they run it, than someone who would be looking for every opportunity to squeeze out nickels and dimes ($100 million/yr!) from the internet community, via abuse of their monopoly. Or, perhaps a corporation with a solid reputation (maybe IBM?) would step up, to replace Verisign.

  • bootleg patches? (Score:3, Interesting)

    by krokodil (110356) on Tuesday September 23 2003, @10:19PM (#7040365)
    (http://www.crocodile.org/)
    It is good interview but expression "bootleg patches" was someting I disliked. It does not fits well with free/open source spirit. It assumes that there are (in marketing terms) "offical" or "authorized" patches and everything else is "bootleg". It kind makes me feel my next patch to some open source product could be considered "bootleg" which makes me feel it is unwanted.

  • by Tisephone (709174) <tessag@kurofune.[ ]jp ['co.' in gap]> on Tuesday September 23 2003, @10:42PM (#7040475)
    VeriSign is better then porno.

    One day back in junior high, I was in a lab full of old Macs. Netscape suffered a lag attack and decided I wanted to go to 'hoo.com', not 'yahoo.com'. Hilarity ensued.

    I think that particular site is defunct, though.
    • 1 reply beneath your current threshold.
  • Take back the roots (Score:5, Interesting)

    by Skapare (16644) on Tuesday September 23 2003, @10:48PM (#7040494)
    (http://linuxhomepage.com/)

    Why not just take back the roots? The only reason Verisign can do what they do is because the GTLD servers they control are delegated to by the root servers (not sure who controls those anymore, but it can't be good). And those root servers are configured in the hint file of name servers all over the internet. So who controls those? We (who have our own name servers) do.

    It's a little harder, but not a lot harder, to just run your own root zone. The biggest thing is to gather up all the NS records and associated A records for each TLD. That's a small list (relatively speaking), so it could be done via a few hundred dig commands to the root servers. Or it can be downloaded. Now once you have that data, you replace the .com and .net zones with your own. Of course that begs the question, replace it with what?

    If enough people with enough server/network power get together, they can make their own independent "realm" of domain name space, starting with a replacement root zone (as has been done in the past to add new TLDs), and a replacement for both .com and .net.

    I can just hear the complaints now (and I've heard them before): "But this will fragment the internet". My answer is: Yes!!!! yes it will! all the better. Imagine being in a whole different name space realm away from spammers and evil corporations. And maybe you can meet me in the .mp3 TLD.

  • by xpl_the_myst (612106) on Tuesday September 23 2003, @10:58PM (#7040541)
    $ host www.werwearwer.com
    Host not found.
    $ host www.slshdt.org
    Host not found.

    I thought i should get verizon's ip? Anybody explain this? Or is there some way to get around this thing.
    • 1 reply beneath your current threshold.
  • by Skapare (16644) on Tuesday September 23 2003, @10:59PM (#7040550)
    (http://linuxhomepage.com/)

    Verisign can break Vixie's patch. All they have to do is set up a separate name server which pretends to be a .com and .net server, with the very same wildcarded A-record. Now just put in wildcarded NS-records in the actual .com and .net zones in the real GTLD servers (in place of the existing wildcarded A-record). There, now it really looks like a real delegation to a different name server, just like real domains have. The new delegated wildcard server gets the query next, due to the delegation (that looks like a delegation, hence fools the patch), and due to its wildcard (and it doesn't need any other data from the .com or .net zones, since it doesn't get delegated to for real domains), it will answer with an A record of Verisign's choosing. If Verisign wants to keep doing what they are doing, they can defeat this patch by that method.

    Then we'll have to make DNS servers filter out specific delegations (as opposed to filtering out non-delegation records where there should be only delegations). Verisign could rotate those delegations daily and fool efforts to block it.

  • by rock_climbing_guy (630276) on Tuesday September 23 2003, @11:00PM (#7040552)
    (Last Journal: Wednesday October 22 2003, @03:09AM)
    I keep hearing that the Verisign wildcard BS is causing problems with spam filtering because now all *.com domains appear to be valid.

    Why can't we work around this by instead of checking if the address is valid, check if the address comes back to Verisign's server???

  • by zapp (201236) on Tuesday September 23 2003, @11:06PM (#7040576)
    Now, I understand that what VeriSign has done is wrong in several ways, but to play devil's advocate, I want to ask you guys a question:

    What if rather than sitefinder, it redirected you to google? The "feature" they are trying to convince us they provide is basically spell checking the URL you type. "salshdot.org? Oh... you meant slashdot, here let me take you there."

    What if this had been done in a more acceptable way, where profit leeching wasn't a suspected motive? Would we still complain?

    And btw, the only downside I can personally think of with the concept in general is that you can no longer tell a site is down or exists just by pinging it, because you get the "spell checker" site's reply rather than nothing.

    Feedback?
    • Re:What if it was Google rather than sitefinder? by mlk (Score:3) Tuesday September 23 2003, @11:11PM
    • It's the same issue (Score:5, Insightful)

      by achurch (201270) on Tuesday September 23 2003, @11:40PM (#7040738)
      (http://achurch.org/index-e.html)

      Whether it's SiteFinder, Google, or even Slashdot, the issue is not so much (or at least not only) the fact that a website comes up instead of a 404. It's the fact that practically everything automated breaks because this "service" is oriented toward humans. Consider:

      • "Automatic domain completion" in browsers, where you can type "slashdot" and get it completed to "http://slashdot.org/" if slashdot.{com,net} don't exist. This will fail to work because DNS will no longer return NXDOMAIN for nonexistent domains. (Admittedly, with everyone and his brother registering .com domains this is something of a straw man...)
      • Spam filters. Many server admins have installed a filter that denies mail with a From: address in a nonexistent domain. With Verisign answering every .com/.net query with an A record, these filters have become essentially useless.

      I'm sure there are others, but the point is that what's good for human users is not good for computers, and it should be the client, i.e. the thing interacting directly with the human user, that interprets the computer responses and makes them easier to use for humans. (There wouldn't be nearly as much uproar over this if Verisign had, say, made a deal with Microsoft to redirect all NXDOMAIN queries to SiteFinder; in that case it would be an Internet Explorer, i.e. client issue, and DNS itself would be unharmed.)

      [ Parent ]
    • 1 reply beneath your current threshold.
  • Kerosene (Score:2)

    by jenkin sear (28765) * on Tuesday September 23 2003, @11:07PM (#7040579)
    (http://www.wdogsystems.com/ | Last Journal: Thursday October 06 2005, @10:10AM)
    A quart of kerosene can spoil a tanker-truck full of milk:

    #!/usr/bin/perl

    srand();

    my @alpha = (a..z);
    my @prefix= qw( www web1 web2 ftp mail dns ns1 ns2 ns3 dns1 dns2 dns3 );
    my @suffix = qw ( com net );
    $|=1;
    while(1) {
    my $length = int(rand(16)+1);
    my $n = "";
    for (0..$length) {
    $n.=$alpha[int(rand(26))];
    }
    my $p = $prefix[int(rand($#prefix))];
    my $s = $suffix[int(rand($#suffix))];
    $l = `nslookup $p.$n.$s`;
    print $l;
    sleep int(rand(5))+1;
    }

    enough crap in their database, it won't be good for marketing data anymore.
    • Don't do that! by pr0ntab (Score:2) Tuesday September 23 2003, @11:52PM
      • My guess is that Verisign does log the requests received, but does not normally go to the effort to correlate the DNS requests with hits to SiteFinder, and that if you want to mess with their marketing data, you would want to send bogus requests to the SiteFinder HTTP, not just bogus DNS queries.
        Does anyone know if you can directly ask a root server about a domain? I didn't think mere mortals could
        Yes you can.

        Any host can make non-recursive requests to the root servers.

        Technically, if a query for whatever.com arrives at a root server, it should only return the list of NS records for .COM, and if a query for whatever.com arrives at an authoritative server for .COM (many roots are also .COM servers), it should only return the registered NS records for whatever.com.

        In fact, that is exactly the problem -- the Verisign roots should return only NS or NXDOMAIN records, but for names in .COM .or .NET, they instead "synthesize" an A record, pointing to sitefinder, with a 15 minute TTL (cache lifetime).

        The various hacks either ignore the specific A record, or ignore records from root servers other than NS. The latter is a cleaner approach, IMHO.

        [ Parent ]
      • Re:Don't do that! by raju1kabir (Score:1) Wednesday September 24 2003, @01:56PM
      • 1 reply beneath your current threshold.
    • Re:Kerosene by pkiguruman (Score:1) Wednesday September 24 2003, @12:43AM
    • Forget Kerosene by SharpFang (Score:2) Wednesday September 24 2003, @01:33AM
  • Trademark Infringement (Score:4, Interesting)

    by Bob9113 (14996) on Tuesday September 23 2003, @11:08PM (#7040584)
    (http://www.traxel.com/)
    Here's a fun solution:

    If your ISP hasn't fixed this yet, go to http://ibm-asdf-hardware.com [ibm-asdf-hardware.com]

    Do you think IBM might be a little bit pissed off about their trademark being used to point to someone else's computer hardware site? Do you think they might, I dunno, sue?

    How about all these other blatant trademark infringements:
    http://ibm-asda-hardware.com
    http ://ibm-asdb-hardware.com
    http://ibm-asdc-hardware .com
    http://ibm-asdd-hardware.com
    http://ibm-asd e-hardware.com
    http://ibm-asdg-hardware.com
    http ://ibm-asdh-hardware.com
    http://ibm-asdi-hardware .com
    http://ibm-asdj-hardware.com

    As I see it, Verisign is facing a not-quite-infinite number of trademark infringement lawsuits. And, of course, if Verisign switches to point to IBM, I'm sure hardware.com would be delighted to fire their own volley of lawyers.
  • A 404 error message? (Score:3, Redundant)

    by Skapare (16644) on Tuesday September 23 2003, @11:10PM (#7040597)
    (http://linuxhomepage.com/)
    PV: I hope but I don't think so. I've heard that the patch works well, but VeriSign could bypass the patch. It could make synthesized responses look more like delegations. I don't think it will do that. VeriSign's spokesperson, Brian O'Shaughnessy, suggested that if people don't want this, they're free to block it. It's really meant to be a service for the supposedly inconvenienced web surfers. VeriSign maintains that its search page is more useful than 404 error messages. If VeriSign bypassed the patch, it would have to escalate things and retract these statements about how folks were free to block the wildcard.

    What? How the hell do you get an HTTP 404 error message if there's no server to even connect to?

  • Mr. Vixie is surprisingly neutral (Score:3, Insightful)

    by morelife (213920) <f00fbug@nOspaM.postREMOVETHISman.at> on Tuesday September 23 2003, @11:25PM (#7040671)
    I am surprised that Paul Vixie did not seem to exhibit much emotion regarding the Sitefinder situation - for someone who's been at the core of what we now know as the DNS for so many years (you would think it's like his own child:).

    He seemed reserved, while calmly pointing out, part by part, what is wrong with Verisign's actions. More of this is called for from the important people in the Internet technical and business community - the way community coverage has been heading, and the way comments are worded on Slashdot and other sites, is leading to resentment, anger, name-calling, and joking about Verisign and their policies, creating a situation in which the community is less likely to be taken seriously by Verisign, Microsoft, AOL, etc. Mr. Vixie also mentions that there are smart people at Verisign, reminding us that the Sitefinder "service" is the brainchild of but a handful of people, maybe even just one or two. It reminds me that as engineers, we still have to work with the other guy at a certain level.. becoming enemies doesn't help anything.

    Mr. Vixie is saying that perhaps ICANN should "do something about it". This whole situation should be approached by attorneys general, from the both the branding/business practices angle mentioned by Mr. Vixie, and also from the consumer rights angle (much like telemarketers). Right now the average consumer can get effectively get rid of telemarketers, thanks to recent laws, with a single verbal or written request, but the Sitefinder service can only be circumvented using DNS tools by an engineer or technician "in charge" of the DNS servers. The web-browsing consumer has no way around this by themselves.

  • Doublespeak? (Score:2, Insightful)

    by Tyrell Hawthorne (13562) on Tuesday September 23 2003, @11:42PM (#7040746)
    (http://dsv.su.se/~oscar-ja/)
    Am I the only one who finds it ironic that Verisign's slogan is "The Value of Trust"? They sure don't seem to be aware of just that, the value of the trust we have given them.
  • What the flip is ICANN doing? (Score:2, Insightful)

    by Vainglorious Coward (267452) on Tuesday September 23 2003, @11:51PM (#7040812)
    (Last Journal: Saturday August 28 2004, @12:14AM)

    In the past, ICANN has always made a song and dance about the crucial need for DNS stability, yet now, in the face of a unilateral move that causes great instability, they meekly ask Verisign to please stop. If ICANN are too spineless to act, then the Department of Commerce needs to step in. Despite the contractual complexities (see Karl Auerbach's blog [cavebear.com]), Verisign have committed a fundamental breach of trust, and the DoC should reallocate responsibility for .net and .com as soon as practically possible.

  • Terms of Use (Score:2, Interesting)

    by Joystickit (529613) on Wednesday September 24 2003, @12:07AM (#7040907)
    If you read the Terms of Use [verisign.com] you can see that

    # Sole Remedy.
    YOUR USE OF THE VERISIGN SERVICES IS AT YOUR OWN RISK. IF YOU ARE DISSATISFIED WITH ANY OF THE MATERIALS, RESULTS OR OTHER CONTENTS OF THE VERISIGN SERVICES OR WITH THESE TERMS AND CONDITIONS, OUR PRIVACY STATEMENT, OR OTHER POLICIES, YOUR SOLE REMEDY IS TO DISCONTINUE USE OF THE VERISIGN SERVICES OR OUR SITE.


    Couldn't they be sued for not providing some way for users to discontinue use of their service? It's like the shrink wrapped EULA, except on a way more annoying scale.

    We're all going to have to call their tech support to ask them how to discontinue use of the service because we do not agree with their terms of use.
    • Re:Terms of Use by innocent_white_lamb (Score:1) Wednesday September 24 2003, @01:00AM
  • by Trogre (513942) on Wednesday September 24 2003, @12:10AM (#7040926)
    (http://slashdot.org/)
    www..com
    Host www..com not found.

    www..net
    Host www..net not found.

    www..org
    Host www..org not found.

    Did we win?

  • What are ISP's out their doing? Patching BIND? Firewalling off the siteminder site? Letters?

    As a member of the BOD of a non-profit ISP Ive called on our board to send Verisign a letter requesting the suspension of the service and to star talking to the main stream press. What is everyone else doing?

    • 1 reply beneath your current threshold.
  • by SharpFang (651121) on Wednesday September 24 2003, @01:26AM (#7041203)
    (http://sharpy.xox.pl/ | Last Journal: Wednesday September 14 2005, @02:12PM)
    ...let them do it. Just charge them for all names registered. Assuming they wildcard the name with 26 letters plus "-", say, 20 chars deep, charge them 27^20 registered domain names. Even with a good discount, say, $0.01/domain name it will still be more than there is money on Earth :)
  • by MythMoth (73648) on Wednesday September 24 2003, @03:43AM (#7041679)
    (http://geeklondon.com/)

    After reading this story [theregister.co.uk] about Russell Lewis's (Verisign GM) memo to staff, I registered "bookstre.com" and pointed it to Google via the Easily.co.uk redirector.

    Now, until the DNS entry propagated, and in the 15 minute window before the non-existant domain timed out, I was still seeing the SiteFinder "domain". Obviously it's a contrived example, but I think it illustrates an important point:

    I paid good money for this domain
    Who said Verisign could use it ?

    Legitimate domain registrations are still going to suffer from this decision, so I suspect this would be a legitimate set of grounds for a class action against Verisign.

  • by chathamhouse (302679) on Wednesday September 24 2003, @03:51AM (#7041701)
    (http://www.chathamhouse.org)
    Has anyone tracked down a backport of the delegation-only patch for bind 8.x?

    So far, all I've got is unofficial patches, which will not be run on production systems.

  • random junk (Score:2)

    by hey (83763) on Wednesday September 24 2003, @05:26AM (#7041990)
    (Last Journal: Thursday December 08 2005, @04:33PM)
    The .cc domain is Verisign controlled and does
    the sitefinder-type thing...
    http://RandomJunk8347458475.cc

    Also, as Verisign so helpfully pointed out in their
    letter the other day many TLDs wildcard. ICANN should *ask* them to stop too.

    Bind has their option to prevent wildcarding from certain domains. Maybe they
    could ship it pre configured block all wildcarding domains. Or can you simply
    say block all wildcarding no matter what the TLD.

    Since BIND is prevalent it could take an end run around the existing .com and .net root servers. It could set up a parallel DNS!

  • by jkbull (453632) on Wednesday September 24 2003, @05:41AM (#7042049)
    If your ISP won't block it, it's simple to (partially) disable Verisign's power grab on "firewall" Cable/DSL routers, often used on home and small office networks.

    On a Linksys BEFSX41, for example, just put "sitefinder.verisign.com" in the "Blocked URL Contents" section of the router's "Firewall" configuration page.

    If you mistype a URL (I use the term loosly) Mozilla will put up an alert box: "The document contains no data". Internet Explorer brings up a "The page cannot be displayed" page.

    Caveats: (1) many routers don't have this "firewall" feature; (2) this works only for clients downstream from the router. It won't help your ISP bounce spam from "loser@verisignisdoingbadthingstotheinternet.com".
  • by wowbagger (69688) on Wednesday September 24 2003, @07:04AM (#7042356)
    (http://slashdot.org/~wowbagger/journal/87552 | Last Journal: Monday September 03, @08:07PM)
    This all is coming about because of what I consider to be a design flaw in DNS, to whit:

    For any given suffix .foo.bar.baz, there is one and only one possible dataset to answer that query.

    So if you are looking up bar.com, there is only one dataset that contains information on .com - thus whosoever controls that dataset controls .com.

    Now, what if a server for a given domain, in addition to having a parent had siblings? For example, if you were looking up narf.com, then the queries might look like this:

    my machine - Hey root, where's narf.com?
    Root - I don't know, but verisign.com should - ask him.
    My machine - Hey verisign.com, where's narf.com?
    Verisign.com - I don't know, maybe alternic.com does.
    My machine - Hey alternic.com, where's narf.com?
    alternic.com - narf.com is at 192.168.0.1


    In other words, for every zone record there would be a new configuration possible - a list of zero or more siblings. On a negative result, the sibling records would be returned, and the quering name server would consult them. As a result, you could allow joker.com, register.com, verisign.com et. al. to have just their records on their servers, with cross links to the other servers.

    Yes, this would increase the number of queries a name server might have to do to resolve a domain, especially in the negative case (domain does not exist). However, just as a name server can and will cache the servers for .com now, a name server could cache the list of name servers for .com now, and could send the queries out in parallel to the servers it knows about, reducing the time.

    Under this system, a failure of verisign's server would not black out .com, just the set of domains registered with .com. It would reduce (somewhat) the size of the servers needed to serve the .com domain (as the workload would be spread out among more servers), and would allow for each registrar to maintain their own database without having to go though Verisign.

    Extending this to the root servers would allow for things like Alternic to be added - the root servers could say "I don't recognize .foo, but maybe Alternic does".

    Yes, it would be possible for Joker.com and Register.com to create records for VerisignEngineersAreWeenies.com, and for those records to disagree. Yes, the set of owners of servers for the .com domain would have to do their homework in registering a domain - there would have to be a clearing house for domain registry.

    But were this idea implemented, it would prevent anybody from pulling the kind of unilateral crap that Verisign has.
  • Hold the phone... (Score:2)

    by Scratch-O-Matic (245992) on Wednesday September 24 2003, @07:35AM (#7042562)
    I just read the Terms of Service on the sitefinder site:

    COST OF THE VERISIGN SERVICES.
    The Verisign Service(s) are provided to you free of charge.


    Hey folks, we're getting this service for free. Looks like we don't have a leg to stand on.
  • by mindstrm (20013) on Wednesday September 24 2003, @07:57AM (#7042720)
    The more I feel that, regardless of paperwork, or whatever agreements they signed... most of us consider the .com registry and, to a larger degree, the entire DNS system to be a large public trust at the top levels. It works because we all cooperate, and agree to use it... and ONLY because of that.

    I think, though of course the devil is in the details, it's time that Verisign learned that it's power comes from us, only because we allow it.

    How we do that is another story.
  • by xenoweeno (246136) on Wednesday September 24 2003, @08:04AM (#7042773)

    Yet still my emails to VeriSign somehow end up at Network Solution's feet. At this point their responses aren't nearly so "helpful" [slashdot.org] with regard to volunteering opinions about the permissibility of VeriSign's decision to .com and .net into upheaval.

    Thank you for choosing Network Solutions. Site Finder is not controlled or maintained by the Network Solutions Registrar. We are unable to provide any support or assistance for this service. Please visit the Site Finder FAQs at http://www.verisign.com/nds/naming/sitefinder/faq. html for additional information.

  • by Hohlraum (135212) on Wednesday September 24 2003, @08:21AM (#7042947)
    (http://www.nocturnal.org/)
    I just got a call from an 'independent' survey company and about half way through I realized that it was sponsored by Verisign. They asked me all these questions about registering domain names and stuff really seemed to focus on Network Solutions/Verisign. They asked me how I would rate them and I said 1 (worst) and she acted kind of suprised. She had me explain why I felt that way and I said that they have jacked domain name registration and certificate pricing through the roof and that I strongly object to their SiteFinder service. Maybe some of you other guys will get the call as well. Sock it to em.
  • by Stratis Aftousmis (569934) on Wednesday September 24 2003, @08:28AM (#7043008)
    User's in other country's will be confused by this, granted the internet is an english langauge creation for the most part thus far, but when it come's to not understanding something, a error message is easier to understand than an english verisign page. If anyone doesn't agree with this, i suggest you, like i did, sign the petition! [petitiononline.com]
  • by geoff lane (93738) on Wednesday September 24 2003, @09:36AM (#7043733)
    because verislimes silly prank breaks a number of default behaviours within IE and various search options within Windows.

    In addition ISPs in non-English countries sometimes catch requests for unknown domains and put up a web page in the appropriate language - this is now also broken.
  • I just realized that if you can do

    zone "com" { type forward; forward first; forwarders { 204.152.184.76; }; };

    to make a BIND 8 server use the ISC public recursive servers for .com then you can use:

    zone "geek" { type forward; forward first; forwarders { 208.181.60.45; }; };

    to add the .geek zone

    http://www.opennic.geek/ [opennic.geek] now works for me while I'm using normal DNS for other TLDs.
  • by hey (83763) on Wednesday September 24 2003, @05:18AM (#7041965)
    (Last Journal: Thursday December 08 2005, @04:33PM)
    Arg, why does everyone says this removes 404's. You need a webserver to return a 404. Before wildcarding you didn't hit a websserver so no 404. And you can still get a 404 by hitting a page that doesn't exist [slashdot.org] on a webserver that does.
    [ Parent ]
  • 12 replies beneath your current threshold.