VeriSign slammed for helping spammers

Network operators, anti-spam campaigners, security experts and engineers have hit out at VeriSign over the changes it made to the top level domain system.

On Monday, VeriSign began to redirect domain lookups for misspelled or nonexistent names to its own site, a process that has confused Internet e-mail utilities and drawn angry denunciations of the company's business practices from frustrated network administrators. The Mountain View, California-based company enjoys a government-granted monopoly as the master database administrator for .com and .net.

The operator of the Spam and Open Relay Blocking System (SORBS), Matthew Sullivan, told ZDNet Australia the company's actions have thrown a huge spanner in the works. "All of the header checks that you normally do ... suddenly don't work," he said. "So of course all of these forged email addresses that spammers are using are getting through."

Spam software can no longer check the validity of a domain name to make sure it's not forged, Sullivan says. "I don't think they should have done it at all ... there is absolutely no reason at all that they should have done it," he said. "The Internet Architecture Board (IAB) has already said that it should be withdrawn."

Echoing those calls is Chris Wysopal, the research director with security company @stake. "When things that have been working one way for a long time change ... now they have to re-invent all of those things," he said.

However Wysopal says the problems experienced by anti-spam software could just be the tip of the ice-berg. "The anti-spam is one thing ... I'm sure there are other things out there that people don't even realise are going to break," he said.

"I think they should reverse it. Maybe there is some merit to this service but it shouldn't be a unilateral thing," he added.

Doubting the government will intervene, Wysopal says the only way a reversal of the change will occur is "if a lot of their big customers say 'we're unhappy with this and we're going to stop doing business with vsig'".

VeriSign's new policy is intended to generate more advertising revenue from additional visitors to its network of Web sites. On Monday, VeriSign released an eight-page paper describing the implementation of its "Site Finder" program, saying it "improves the user Web-browsing experience when the user has submitted a query for a nonexistent second-level domain in the .com and .net second-level domains.... [Previously] his or her Web browser returned an error message that contained no useful information."

In an unusual kind of grassroots movement, some network administrators have begun to invent and launch technical countermeasures against VeriSign. A discussion thread on the North American Network Operators' Group mailing list was titled "What *are* they smoking?" and offered technical tips on how to configure routers and servers to block access to VeriSign's site, so Web users would receive the traditional "nonexistent domain" error message.

"There are already modifications to BIND software to take responses that contain that VeriSign address and turn it into a nonexistent domain error," Karl Auerbach, a veteran Internet engineer and former board member of the Internet Corporation for Assigned Names and Numbers (ICANN), said about the standard utility used for domain name lookups. "There are also several Internet service provider-type people dealing with routing information who are already talking about blocking (the VeriSign site). I believe some have."

VeriSign is not the first domain-name company to try to profit from typos and errors, but because .com and .net represent such a huge percentage of Internet names, its decisions have the most profound impact. Some of the other top-level domains that have adopted a similar policy include .cc, .museum, .nu, .ph, .tm and .ws. Microsoft's Internet Explorer also returns a similar error message and search box, but because the redirection is performed by the end user's computer, the effect is limited.

VeriSign's decision, which was done without consulting the Internet standards groups, came just a few days after the US Federal Trade Commission accused the company of deceptive business practices for sending "domain name expiration notices" to competitors' customers in early 2002.

Earlier this year, VeriSign was dealt a harsh rebuke in a similar matter by the highly regarded IAB. Referring to the Domain Name System (DNS), the board's unanimous statement said: "The system VeriSign had deployed for .com and .net contains significant DNS protocol errors, risks the further development of secure DNS, and confuses the resolution mechanisms of the DNS with application-based search systems."

VeriSign shares closed Tuesday at US$15.81, up 4 cents.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

Cloud based TV recording services in Australia shutdown after negative ruling. http://t.co/9zlnSVJd

AD on azure, is all about APPS .. http://t.co/EMdsrHZF

children porn video

2 hours ago by nmhcqogu on Google to encrypt searches by default

#Biometric bugs too dangerous for public? http://t.co/IdIBiRUJ (via @zdnetau by @mukimu)

#Outsourcing is still on the rise http://t.co/ANaHIofI ^NK

#NBN users opt for 100Mbps
http://t.co/SmMFpItP #auspol

IBM's Intelligent Clusters - an old idea done well: IBM's pre-configured, pre-tested clusters take the uncertain... http://t.co/Z64vEYiL

33 must-have business and marketing iPad apps from Docstoc http://t.co/Bu7BhFRv

when and if NBN gets to Cairns FNQ, it is going to be a big white elephant tooo costly and to much of a monthly commitment. I am qui...

4 hours ago by beachking on NBN users opt for 100Mbps

Dell Secureworks talks with ZDNet about Android's biggest #security flaws - http://t.co/08kaKg6R #infosec RT @dellenterprise

33 must-have business and marketing iPad apps from Docstoc http://t.co/0XqdwbAN

33 must-have business and marketing iPad apps from Docstoc http://t.co/pf1m0CNP

RT @sergicles: Google vs Oracle, that was a quick one. http://t.co/AFIEf8vG Oracle trolling pw4ned

RT @MobiMediaMarket: Mobile Devices Were Wrecking My Health. Here's How I Plan to Change That. - ZDNet (blog) http://t.co/zMWCOZOr #mobiledevices

B.S Artist ? (M.A Oxford )

5 hours ago by Abel Adamski on NBN FUD: will Abbott ever learn?

B.S Artist ? (M.A Oxford )

5 hours ago by Abel Adamski on NBN FUD: will Abbott ever learn?

Mobile Devices Were Wrecking My Health. Here's How I Plan to Change That. - ZDNet (blog) http://t.co/zMWCOZOr #mobiledevices

"take up of the highest plan was again higher in April, making up 50 per cent of all services activated in April"

6 hours ago by Abel Adamski on NBN users opt for 100Mbps

What has not been considered which may well be the case, is the key attribute of the FTTP. Upload capability. 82% chose an upload capacit...

6 hours ago by Abel Adamski on NBN users opt for 100Mbps

"@ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/PiR0zeF1 #infosec #hack #cybersecurity"

Cool: NZ will host part of Square Km Array http://t.co/a2mz3DC5. Sad: @smh couldn't bring themselves to acknowledge it http://t.co/l90oLuYp

Build your own smartphone stand http://t.co/I0avWsRO

SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the Square Kilometre Array (... http://t.co/vA11Otks

SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the Square Kilometre Array (... http://t.co/FqSe1Uju

SKA bid ends in three-way tie AU/NZ/ZA http://t.co/aGw6dndH < interesting outcome

RT @MADinMelbourne: roxon "will enable more families to access credit" @MLolderandwiser: Privacy Act amendments http://t.co/Mv4c7PC2 via @zdnetaustralia

Is #PR dying at the hands of #SocialMedia? Check out how #UnitedAirlines suffered a Social PR hiccup in 2008 http://t.co/OVpYX8Uv

The interface is nowhere near as clean and user friendly as the Rdio streaming service apps. It doesn't compete with Rdio which has very ...

8 hours ago by Jeff12345 on Spotify finally goes live in Australia

RT @ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/0rCoszCl #infosec #hack #cybersecurity

by http://t.co/vmlLt4bh: SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the ... http://t.co/ySDRbo3l

It's official. The SKA bid has ended in a three-way tie between Australia, South Africa and New Zealand: http://t.co/Wn1niauX ^LH

Biometric bugs too dangerous for public?
http://t.co/48XQpWiY

Aussies getting ripped off by retail: Choice http://t.co/6ZQ0wuCJ via @zdnetaustralia

Thats really interesting to find this post especially in this period of my life I'm Italian, I'm owner of a website that ships worldwide...

9 hours ago by salbini on Aussies getting ripped off by retail: Choice

Android's biggest security flaws - ZDNET - ZDNet Australia http://t.co/4j4R1x6Q

RT @Techmeme: RIP webOS: Again and for good this time (@jkendrick / ZDNet) http://t.co/RhADp6WL http://t.co/fFYGIy5R

Cybercrime golden age over in two years? http://t.co/LyqqjWYU #Cybercrime #Gescrise #Riskmanagement (via @ECCOUNCIL)

RT: ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/X0In9ijs #infosec #hack #cybersecurity

Cybercrime golden age over in two years? http://t.co/VJnt6nEo #infosec #hack #cybersecurity

NBN users opt for 100Mbps - http://t.co/C2Vs7d3t

Yes, if only he had access to FTTP instead of wishing for wireless or space optics, perhaps the comedy site would still be up and running...

10 hours ago by Beta on NBN users opt for 100Mbps

I could not resist :-)

I remember that website well, you must too, it was full of so many comedy pieces.

10 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

Bazaarvoice acquires rival PowerReviews; adds SMBs to CRM portfolio: By Andrew Nusca | May 25, 2012, 4:42am PDT ... http://t.co/WngvcsxL

MikeSkoey, what a naive collection of words. How do you know what context Paul has been working in. How do you know he implemented whats ...

10 hours ago by AnonymousCIO on 30 servers to 7: BUPA redoes virtualisation

Post 'social' improved speed to information and context http://t.co/7u9odG7N

HC, don't be so mean to Todd...

He is actually one who may not be just politically opposed ;-)

10 hours ago by Beta on NBN users opt for 100Mbps

No, Quigley is, as CEO's of all companies are, quite simply motivated for his company to be a professional and successful company, as it ...

10 hours ago by Beta on NBN users opt for 100Mbps

Forced lol. btw I tried to load your website www.nonbn.org but all I got was a "website unavailable" I really wanted to donate some mone...

10 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

http://t.co/aDIOqQ4c http://t.co/NeUOcLt5

What has the debt level got to do with what plan people chose? I'd point out that the debt wont be $50 billion but i'd be wasting my bre...

11 hours ago by mstat_z on NBN users opt for 100Mbps

Quigley is entirely politically motivated, this is headline grabbing and nothing more. The statistic should read - "of those who took up ...

11 hours ago by merarischroeder on NBN users opt for 100Mbps

"the artificial speed tiers will mean that on average speeds the country will be left well behind others and social inequality will incre...

11 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

The most insulting aspect of the ads is CommBank's expectation that we would accept a bank account with fees unless you deposit $2000/mth...

12 hours ago by gikku on Triple J's Spotify conundrum

That's right. Quigley DOES know best. So when Quigley presents a plan to the shareholders (us) and says "this is our worst case scenario...

12 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

"NBNCo predict 13% of premises passed by fibre will opt for wireless because it is cheaper." Which leaves 87% well above the 70% estimate...

12 hours ago by Beta on NBN users opt for 100Mbps

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

3 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

3 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar