TechnoMagician's Weblog
(aka Tim Aiello)
Any sufficiently advanced technology is indistinguishable from magic - Arthur C. Clarke.


Subscribe to "TechnoMagician's Weblog" in Radio UserLand.

Click to see the XML version of this web page.

click Click here to send an email to the editor of this weblog. to email tim

If this you can chat with me if i'm online (diamond) is green, click on it to chat with me.

Kosmo Systems Inc, along with Ashley IT are proud to present their spam detection service called SimpleFilter. It is so simple, there is absolutely no software to install and it works with virtually any email client on any operating system. Checkout www.simplefilter.com


Tuesday, September 16, 2003
 
VeriSign - The Sign of the devil.

In the last year or so I've equated VeriSign with the sign of the devil. They seem to go to any length in an attempt to gain/retain customers. Their latest asinine move is adding a wildcard record to the .com and .net top level domain records. What this means is that when a user enters a URL containing a nonexistent top-level domain (in .com and .net), they are returned an IP that points to VeriSign's SiteFinder service presenting the user with a web page and some search functionality. Here is what they claim in their SiteFinder implementation document:

VeriSign's Site Finder service improves the user web browsing experience when the user has submitted a query for a nonexistent second-level domain name in the .com and .net top-level domains. Before this service was implemented, when a user entered a URL containing a nonexistent (e.g., unregistered) domain name ending in .com or .net his or her web browser returned an error message that contained no useful information. With the rollout of Site Finder, in the same situation users now receive a helpful we page offering links to possible intended destinations and allowing an Internet search.

VeriSign refers users to the Site Finder web site through the use of a wildcard address (A) record entry in the .com and .net zones. As explained more fully below, VeriSign's processing of queries for nonexistent domain names is in full compliance with provisions of the DNS protocol that address wildcards as well as the operational best practices described in the document entitled Domain Name Systems Wildcards in Top-Level Domain Zones ("the Guidelines")

They claim they are in full compliance with provisions of the DNS protocol. I'd agree if they weren't mucking around at the top-level. Anyone can add wildcard records to their own zone/domain that they control. But adding it at the top-level is NOT compliance. It highway robbery.

Its like the good old "to serve you better" line. They are falsely claiming that they are providing this service to serve us web surfers better. What they really are doing is trying to get your eyeballs on their website. Furthermore they are breaking hundreds and probably thousands of programs and services that relied on DNS queries returning a FAILED lookup. A failed lookup is a perfectly legitimate response from a DNS service.

I think we should call on all the backbone ISP's and anyone that has any power to put in a bogus route that shoves 64.94.110.11 (the SiteFinder IP address) off to nowhere. At least in that way, some programs and services will find nothing and perhaps continue operating the way they expected. Also, that would keep eyeballs away from VeriSign. Any other ideas, just post a comment here?

Here is a decent writeup by Jasan Garman posted by Mohammad Haque.

Update: Looks like BIND is going to be patched to combat this. NICE.

 
9:25:52 AM    


Click here to visit the Radio UserLand website. © Copyright 2004 Tim Aiello.
Last update: 5/22/2004; 2:48:11 PM.
Monthly Archive's
April 2004
March 2004
February 2004
January 2004
December 2003
November 2003
October 2003
September 2003
August 2003
July 2003
June 2003
May 2003
April 2003
March 2003
February 2003
January 2003
December 2002
November 2002
October 2002
September 2002
August 2002
July 2002
June 2002
May 2002
April 2002
March 2002
February 2002
January 2002
December 2001
November 2001
October 2001

beta blogchatters:
(I'm Tim in this list)

=Online =Offline


If one of the blog chatters is in you'll see a green indicator or an appropriate graphic. Just click on the green icon or the graphic and a custom chat window will pop up. you don't need an account or any special software. works with ie and mozilla on win/mac/linux.

these chats are powered by blogchat

Comments by: YACCS