|
|
Log in / Subscribe / Register

VeriSign fends off critics at ICANN confab (News.com)

News.com's Declan McCullagh went to the special ICANN meeting on VeriSign's "SiteFinder" service, and has written this report. "But VeriSign made clear during the open meeting convened by ICANN's Security and Stability Advisory Committee that it had no intention of turning Site Finder off for good. Executives from the company said they were considering turning on Site Finder again but disabling the 'wild card' service for e-mail deliveries to nonexistent domains..." Declan has also posted a set of photos from the meeting.

to post comments

VeriSign fends off critics at ICANN confab (News.com)

Posted Oct 8, 2003 15:24 UTC (Wed) by dark (guest, #8483) [Link] (4 responses)

[...] VeriSign's decision to redirect Web surfers who mistype domain names to its own advertising-based Web site

That's the VeriSign line. The rest of the world disagrees that this is what they did!

Did he consider the real situation too complicated to describe in one sentence? Perhaps we should find some simple ways to describe it. I tried to compose a few short descriptions but they were all flamebait :) (But from my perspective, not as much flamebait as the one in the article!)

[...] considering turning on Site Finder again but disabling the "wild card" service for e-mail deliveries to nonexistent domains

What does this mean? You can't turn off the wildcard for just one protocol; that's the whole problem. So this statement needs some interpretation. Possibilities:

  1. They turn off the wildcard, but leave Site Finder as an accessible service on its normal address. Maybe they'll try to make deals with browser distributors. This would be a face-saving gesture. Removing the wildcard entry is what everyone wants; no-one has a problem with the existence of Site Finder. So this would be good news.
  2. They put back the wildcard but stop running an SMTP server. This would be Bad, it would cause many MTAs to keep retrying deliveries.
  3. They plan to do something evil involving wildcard MX records (I'm not sure what; maybe they figured something out) and then claim that this solves the problems.

In an unusual grassroots movement, some network administrators have adopted technical countermeasures against VeriSign.

Strange that he would call this unusual. I saw it as the normal and expected response. It's not as good as actually having a trustworthy source of information, but it's the usual "routing around damage" approach.

VeriSign fends off critics at ICANN confab (News.com)

Posted Oct 8, 2003 17:04 UTC (Wed) by smoogen (subscriber, #97) [Link] (2 responses)

It means they would not have their postfix email server running.. I am guessig that anything less than a google cluster of email servers would be burnt out from dealing with all misdirected spam and emails...

VeriSign never had a mail server there

Posted Oct 8, 2003 18:30 UTC (Wed) by 87C751 (guest, #11362) [Link] (1 responses)

The program known as 'Snubby Mail Rejector Daemon v1.3' was not a mail server. It was a small daemon that would exit on the QUIT command. Beyond that, it gave the same series of 5 responses to any input: 250, 250, 550, 250, 221. It was probably written to expect HELO, MAIL FROM, RCPT TO, RSET, QUIT.

Actually they did

Posted Oct 8, 2003 21:57 UTC (Wed) by dark (guest, #8483) [Link]

At some point they replaced that pseudo-server with something that looked like a proper Postfix one. It still bounced everything. For my own amusement I tried submitting mail to abuse@sitefinder.verisign.com, and it bounced that too :)

VeriSign fends off critics at ICANN confab (News.com)

Posted Oct 8, 2003 17:27 UTC (Wed) by Baylink (guest, #755) [Link]

Concerning "making deals with browser vendors", I find it interesting that there's been so little notice of the fact that their direct competition on this issue is *Microsoft*: IE dumps to Microsoft's *own* service like this *on NXDOMAIN replies* (unless, like me, you configure it to turn that off) -- so Verisign was *directly* stealing eyeballs (to which they weren't entitled) from Microsoft -- who arguably wasn't entitled to them either, but didn't break the entire Internet to *get* them...

But hell, maybe it's just me.

(Say it with me now :-) So many things are just me...

Verisign Didn't Deserve This Spanking---Business Week

Posted Oct 8, 2003 17:26 UTC (Wed) by Max.Hyre (subscriber, #1054) [Link]

I stumbled across this article on Business Week's web site. The sub-head reads:

The giant recorder of Web addresses sure sparked a fire when it redirected site-not-found messages to its own search engine. It's a bum rap

Their argument, I suspect, is ultimately based on the idea that ``On Sept. 15, Verisign unveiled a way for it to make money from these mistakes.'', even though they do offer other justifications. Their main one is the claim that it's OK for Verisign to capture mis-directed addresses because that's exactly what owners of one-letter-off domains are doing. They do note that the change broke ping and traceroute, but the last paragraph (page 2 of the article) says it's just a matter of consistency: if domain owners can do it, why not Verisign?

Because, first, that way lies a new form of spam, say I. The real cause of spam is that there's effectively no cost to send it. The only reason your metal mailbox contains only the amount of junk mail it does is that postal services the world over charge real money to send the stuff, even though it's less than what Jane Citizen has to pay to send a letter.

Verisign has, effectively, bought every unused domain for nothing, and are now spamming Internet users of all stripes because it's worth their while to do so. The off-by-one types have vastly higher costs, even if it's only $2/yr/domain, or whatever the current bottom-line registrar's cost is. Verisign gets off-by-one, off-by-two, ..., off-by-N domains for free.

The second, and vastly more important, reason is that one of the should-be stewards of the Internet has broken the basic principle on which the 'net has blossomed: dumb network, smart edges [1]. As examples, ping and traceroute might be written to handle "always find some domain" design, but they'd be more complex and much more subject to breakage as the misguided DNS-root-service provider thought up more ways to use and abuse the concept.

While some situations do call for a smarter network [2], we'll always need a dumb one, to show what can be done when the endpoints think up something new. That's what Verisign broke.

Best wishes,
Max Hyre
[1] I can't lay my hands on a definitive treatise on the matter, but a couple of pages which refer to it as a given are: Next-Generation IP Service Platforms, arguing that it's time to move away from that model, and [2]Quality of Service, pointing out how a dumb network prevents QoS operation.

The arrogance is just *breathtaking*

Posted Oct 8, 2003 17:36 UTC (Wed) by Baylink (guest, #755) [Link]

> Stephen Crocker, one of the Internet's original architects and the
ICANN committee's chairman, asked VeriSign why the wild card was
introduced without giving network operators any warning. "I know for a
fact that VeriSign has no problem finding its way to those (technical
discussion) forums," Crocker said, referring to the company's ongoing
participation in them.

> "I don't want to go beyond the agenda," replied Chuck Gomes, VeriSign's
vice president for its registry service. Citing concerns of proprietary
information and competitive advantage, he added that he didn't think he
could guarantee any advance notice of similar changes in the future.

IMNSHO, Verisign has proven by this comment that they are not
management-ually competent to have any authoritative position WRT the
engineering construct that is the Internet, and they should be relieved
of all of them as soon as humanly possible.

Whatever happened to alternative root servers?

Posted Oct 8, 2003 20:10 UTC (Wed) by iabervon (subscriber, #722) [Link] (2 responses)

I remember a while back there were some people running servers which acted like root nameservers, handled all the official names normally, but also handled some extras. People complained that having alternative root nameservers destabilized DNS. Now that it's been demonstrated that the official root nameservers aren't stable, I'm curious as to whether those are still around. Given the disregard with which Verisign treated XO, I could imagine XO deciding that it would use a different set instead of Verisign's ones.

Whatever happened to alternative root servers?

Posted Oct 8, 2003 20:22 UTC (Wed) by log2 (guest, #10024) [Link] (1 responses)

True, you can google for "open root servers" (no quotes) to find
some alternate root server information. The problem at hand would
require alternate .COM and .NET servers, since the alternate roots
still delegate .com and .net to the "official" servers, some of
which (not all, apparently) had the wildcard record. Alternate
.com or .net servers is a much harder problem thatn alternate root
servers, and I believe not realy possible at all because of the
special status of Verisign. Correct me if I'm wrong.

Whatever happened to alternative root servers?

Posted Oct 9, 2003 0:26 UTC (Thu) by proski (guest, #104) [Link]

It's possible if you have the list of the .com and .net domains. I don't think VeriSign will share it with you for free and keep it updated. It should be possible to set up a caching proxy that would request VeriSign but exclude the wildcard entry, based on the returned IP address or on the fact that VeriSign answers itself rather than redirects the request. VeriSign can try to foil this proxy by using multiple IP addresses for the SiteFinder and by delegating wildcard replies to another DNS server. In short, it would be a mess, maybe a full-blown DNS war.

Disclaimer: I'm not a DNS specialist.


Copyright © 2003, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds