Paul Vixie on VeriSign (O'ReillyNet)
Paul Vixie on VeriSign (O'ReillyNet)
Posted Sep 24, 2003 20:38 UTC (Wed) by Baylink (guest, #755)Parent article: Paul Vixie on VeriSign (O'ReillyNet)
For those who missed the fuss, a couple weeks or so back, Verisign decided that if you sent a DNS query
for an unregistered domain in .com or .net, instead of getting the NXDOMAIN (domain doesn't exist) reply
specified by the standard, you should get the IP address of one of their servers, presenting a "we
couldn't fine it, try this" page similar to those presented by IE (until you turn it off, as I always
do).
This has, as you may imagine broken *lots* of stuff, including anti-spam programs which *need to know* if
a domain is valid or not, and inspired a thread on the North American Network Operators Group mailing
list titles "What *are* these people smoking?"
It's a fair question.
For me, it also raises questions about the supposed Chinese Wall between the registrar and registry sides
at Versign: the gtld servers are run by the *registry*, who are *supposed* to be engineers... they had
to hack the nameserver code to do this, I *think*. (Maybe bind will permit wildcarding the 2LD in the
zone files; I wouldn't expect it, but I'm not Albitz *or* Liu.)
