Takedowns run amok? The strange Secret Service/GoDaddy assault on JotForm
arstechnica.com
arstechnica.com
Does anyone else see the irony in Jotform making this statement to the Secret Service? Isn't this exactly what GoDaddy did to Jotform that is prompting the outrage?
Due process has its place in a commercial context, and it seems that both Go Daddy and Jotform might be well served to think about how to handle alleged misbehavior by their users when they receive a request from a government official.
In his eyes, his entire business was marooned with little hope of recovery due to the limited amount of information he was working with. He was fully in bargaining mode at that point, and if they could just identify to him what the problem was, he would resolve it -- by any means necessary -- for the sake of the rest of his users and revenue.
I'm not saying that makes it different, or if it's wrong or right. I am saying I understand.
Does anyone else see the irony in Jotform making this
statement to the Secret Service?
There's a difference in making this statement in a specific case and making a blanket statement saying "we will do this anytime the SS contacts us, without asking for, or verifying, the evidence".Everyone cracks under torture and for a business owner that has spent years building something this comes fairly close.
http://www.tucowsdomains.com/tucows-domain-promise/ "A thoughtful, “registrant-first” approach to dispute resolution. Tucows’ approach to any domain name dispute begins with the firm belief that your domain name is your own. We also have a full-time, dedicated Compliance Team to make sure these matters get the attention they deserve. We will not allow your domain name to be used as leverage in a dispute. We will not readily “seize” your domain name under public pressure as other registrars have done."
eNom is the other one where I know some of their management. They have killed some domains in the treasury table of deny orders, rather than going through the full ICANN process, but are nowhere near as arbitrary as GoDaddy.
Nor is it clear to me how such a request doesn't represent an undue taking. How can an official take property in such a manner without professional or / and personal consequences?
It's certainly possible. You could get reliable Mechanical Turk reviews of forms for $0.03 each, so $60k total. Or you could hire people to look at 500 forms / hour (phishing forms are instantly obvious) at $15 /hr, also $60k total.
Compared to the cost of a site seizure, it might be a good investment.
If your goal is only to figure out who's in the right I agree it doesn't matter.
Of course you can include decoy questions to try and detect this behavior, but I just don't see the whole MTurk review process being terribly reliable overall. I just don't think the worker quality is that great, and they will do whatever possible to just churn through HITs (because they get paid zero for them).
How many times are we gonna have to hear these horror stories before we all get moved away from GoDaddy?
I'm always curious, are people who downvote this in denial? Somehow downvoting me will keep the bad things from coming true to your domains? Funny, most of these stories also start out "I'd always heard bad things about GoDaddy, but..."
Nearly 10% (and that just assumes that all the accounts were made in the last year) of their users were using the site for phishing. That seems like a lot, and even if they were shut down, I wonder if they weren't doing enough to tackle misuse of their own site.
I'm glad JotForm is back up, but I'm curious how they transferred the domains so quickly. I would have expected GoDaddy to lock the domains and prevent them from being transferred away, either due to their own policies or because the Secret Service ordered them to. In my experience, it's always taken at least a few days to transfer registrars, even with an EPP code in hand and instantly responding to confirmation emails. Was NameCheap able to pull some strings to transfer the domains outside of the normal process?
It should take no more than an hour, usually less. If it's taking more than that something's gone wrong or your registrar is manually processing what everyone else does automatically.
I moved a couple dozen domains from GoDaddy in December... all were at their new registrar less than an hour after I confirmed the transfers.
One thing for people to check when choosing a new registrar is whether they have a way to "ack" a request to transfer out (in case you want to leave at some later date). Some registrars don't and that can mean either trying to get customer service to do this or waiting the default period.
Note that there can also be a delay with the new registrar that you choose putting the domain into whois as well.
Domain Name: JOTFORM.COM
Registrar: GODADDY.COM, LLC
Whois Server: whois.godaddy.com
Referral URL: http://registrar.godaddy.com
Name Server: JAY.NS.CLOUDFLARE.COM
Name Server: LEAH.NS.CLOUDFLARE.COM
Status: ok
Updated Date: 16-feb-2012
Creation Date: 09-nov-2005
Expiration Date: 09-nov-2020
>>> Last update of whois database: Fri, 17 Feb 2012 04:03:43 UTC <<<Second, as a registrar, we can transfer a domain same day if we have the Auth code and the other registrar provides a way to "ack" the request.
On transfer away, if we give someone an auth code we can have the domain released as soon as we are notified that the other registrar has input the auth code. Even if we aren't notified we can check manually and see if the code was entered.
So, in general it can be done pretty quickly depending on the two registrars involved. Quicker than it took me to write this reply.
One way to deter phishing forms, for example, is to charge enough for your service that it makes it very unlikely someone would use you for that. Jot mentions having taken down 65,000 phishing forms in the past year; charge $10 or $20 (or whatever, enough to wipe out the issue) upfront for each of those and that problem disappears instantly.
It's the difference between MegaUpload and DropBox fundamentally in how they deter piracy (or don't); applied to every web service.
Most of the time, when the government gets involved, the cost of a service or product skyrockets. They generate inflated costs either through monetization (eg education costs), or through regulation & compliance nightmares.
The government might just force a transition from the so called free web, to a nearly all paid services web. It would form a 'cost wall' that keeps a lot of the abuse users out.
Worse, if the government keeps lowering the bar on qualification for shutdown, the margin for mistake will be so small that the best effort possible won't be good enough. There will be mistakes, fraud will slip through, and boom you're toast.
If the Feds keep going in this direction, at some point the risk of a free system will not outweigh the benefit. Before 2012 is over, there will be enough of these examples to start scaring the hell out of the average web service - if we're not there already.
Government enforcement of policies like this rely on scaring large numbers of operators through a small number of intense persecutions. It works unfortunately.
By the way, the scammers on dating sites use a lot of paid accounts (and pay for them themselves most likely) considering they get a lot more money out of it and a paid account seems more legitimate. Just to say that making something paid does not necessarily remove all the abuse.
This matter is a mess all the way 'round.