That time Verisign typo-squatted all of .com and .net
rachelbythebay.com
rachelbythebay.com
Verisign is going to push every possible way to extract more money from .COM/.NET monopoly. They maximize price increases at every opportunity on their contracts (which has automatic renewal and no competition). For what? No added value to customers or the ecosystem as a whole.
SiteFinder was just one of many moves in a long series of bad for everyone but Verisign moves. Remember when .ORG had its price caps removed and then private equity tried to buy it? Guess where a lot of that backing came from...
I believe the registry contracts are bid out every few years. However it's a very difficult business with fixed prices that depends on lots of operational efficiencies.
They simply outsource the backend and collect a large profit. It's not a difficult business at all. The margins are insanely good in fact. They're doing at least 60% if not closer to 90% I suspect on the actual operations side if they competitively bid out their backend.
Registry contracts aren't bid out every few years for the most part, that's a giant problem. Why Verisign has a monopoly on com/net.
There are cheaper TLDs, everytime they go up for bid, the costs to run them comes out and it's under a dollar per domain. And you're comparing .COM an original gTLD to country code TLDs, which are owned by countries. Countries that can make their own rules and charge their own prices.
Incidentally, I was paranoid about this kind of front-running for years before I knew it had actually happened, and would just use whois from the terminal when searching for domain availability.
That was the last time i registered anything with GoDaddy
Later the 5-day grace period was added by ICANN to deal with accidental registrations, a full refund would be given if the domain was released in that time. Supposedly to protect end users against mistakes like typos and other errors, though I'm not sure why that would need five full days. This made “domain tasting” an open season and a great many registrars would do it, even registering a few times to extend the five days. Some actually did it as an advantage for the end user: they were not going to get snipped by waiting a few days and the registrar didn't jack up the price. But many were a bit more nefarious.
They later added a small processing fee to the refunds in the grace period after the first few domains per account per period (or similar) which vastly reduced this happening, so it is now pretty much a historic problem.
>According to the web traffic measurement company Alexa, in the year prior to the change verisign.com was around the 2,500th most popular website. In the weeks following the change, the site came into the top 20 most popular sites, and reached the top 10 in the aftermath of the change and surrounding controversy.
Oh, goodness.
dnsmasq got a feature to block site finder - the "bogus-nxdomain" option - which still exists and still mentions 64.94.110.11 in the documentation.
Was this legal?
If so what stopped them there, they could just hijack any domain?
Details here:
https://www.computerworld.com/article/2560283/icann-revises-...
https://archive.icann.org/en/topics/wildcard-history.html
In the end it resulted in what ICANN now calls the RSEP process.
Collision and needing to "divine" the domain seem inherent to having a name system. Both this and the need for a TLD-insensitive lookup were solved by making the address bar also the search bar so people can use search engines to find new things instead of DNS.
For one thing, changing how domains work like this would massively drive up the cost of any one domain to the point where hobbyists and open-source projects would be priced out. I have a few domains, none of which are duplicated across different TLDs, and each of which serves a different purpose. It would have been pretty much impossible for me to do this if everything was under one namespace.
In addition to the price aspect, it would pretty much force the system into being a much more restrictive version of the already-existing trademark system - except that there wouldn't even be any exceptions for different fields, as there is in the current trademark system. For example, one of my domains coincidentally (and unknowingly at the time I registered it over 20 years ago) collides with the name of a movie. It's in a completely different field (actually, it's a personal, non-commercial site for me and not much is public on it) but I almost certainly wouldn't have been able to get it if TLDs didn't exist.
Edit: seems to have been there from 2009 till 2019 (!) after users took legal actions. See https://www.golem.de/news/t-online-navigationshilfe-telekom-... (german)
Redirecting you to an add page is terrible enough, ensuring that the ads on that page eventually served malware was the icing on the cake.
I imagine they're still doing it.
An angle no one has mentioned it how this played into googles dominance. These predators made it legitimately safer to type into a search box than a URL bar. At least for a little while.
They don't.
So yeah, preying on users who make frequent typos would also serve to target less observant users, who have the potential be exploited more easily than the general population. AKA: typos imply an exploitable weakness
Case in point: Verisign and Telekom squatting on typo'd domains to extract revenue from exploitable users.
Better use OpenDNS, etc just to have more diversity
Edit: What’s really going to bake your noodle though, is that given all the issues with various kinds of URL squatting, they’re actually safer than those of us typing in the URL directly. Let’s hear it for my Dad, cybersecurity thought leader.
I heard there's something called a "bookmark" which makes it so you don't have to type in the URL though.
But that's arcane magic.
That is, unless, the site you're on is Technically Fucking Braindead and decides to intercept keystrokes. Fuck those sites though. There's an about:config to disable that behavior but a some certain sites stop working entirely without it. Google Documents... I'm looking at you...
https://threatresearch.ext.hp.com/adverts-mimicking-popular-...
1 Billion dollars a year is a good estimate.
But being located in switzerland that seems to be the obvious choice, right ;) ?
Stick to someone who specializes in email (ie. Gmail/Outlook/Zoho/Fastmail/etc).
I was just thinking this side-thread was a bit OT. And in my book, there are worlds of difference between Google and using Algolia’s custom HN search, which is really awesome IMHO. (I use it myself multiple times per week.)
But what the heck, I’ll bite and share my recommendations.
I personally prefer this setup:
• Google Workspace for email. FastMail seems to be a very popular alternative, I’ve never tried them. There’s also Tuta and Protonmail but personally I’m not interested in E2EE email. (I much rather use something based on Double Ratchet for comms that need E2EE.)
• Cloudflare for DNS. There are lots of solid options here. E.g. AWS Route 53.
• Dynadot as my registrar. Porkbun seems to be a solid alternative.
HTH!
I recently started to use NS1, which was taken over by IBM. It's nice and fast, comes with a great API, which even their web control panel also uses. The only negative side is that it's now owned by IBM.
I use some RHEL-alike products anyway, so I didn't mind NS1 now being IBM. NS1 doesn't mention any pricing, and I'm using their free developer accounts for my personal sites. I think it will get very expensive really quick once you become enterprise customers.
Fastmail has done me well for many years.
* Each transaction is signed by a "ring signature", where it's known that 1 of a set of 8 keys signed the transaction, but not which one. This is your actual input plus 7 other random inputs drawn from the same probability distribution as actual inputs.
* Double-spending is prevented by a "key image" which is something mathematically related to your actual key (not sure how that's verified without knowing which key it is). Each key image can only be used once, or it's a double-spend.
* Input amounts and output amounts have to balance using some kind of zero-knowledge proof.
Domain names are perfect for this purpose though, it's decentralized, secure and there's no way to claim the domain of somebody else.
That's a problem, surely, as it means all domain names become owned in perpetuity. That's good if you don't want governments to be able to have control, but it doesn't fit with current systems like Trademarks, but also just if there was an error or con that caused a domain to be transferred that you want to reverse. Also, over time domains become lost; which is sub-optimal in a limited namespace.
The current DNS is a bit like having HTTP everywhere, we need to upgrade to a more secure scheme.
The part that blockchain addresses would actually get generally worse: typosquatting is already a problem, but at least most registrars are working to limit it - some more proactively than others. ENS removes any ability to prevent typosquatting at all. I have never heard anyone complain that registrars or governments are being TOO proactive in delisting typosquatters or those using domains they don't own the trademark for.
Maybe you're thinking of trademarks as some bureaucratic intellectual property nonsense but they are practically important as well. I could own ycombinator.com in that system. What would you do about it besides changing the name of Y Combinator?
I do think their importance is vastly overstated yes but that's another debate.
Right now domains are also suspended for a lot of reasons, typosquatting being pretty much the only one I would describe as a valid reason. And the downsides of allowing domain suspension seems greater than the upsides.
I'd be okay changing my mind on the subject if DNS was used as intended and not as a political tool to suppress newspapers or block pirate websites.
We take a free internet for granted, but in places like China, the government knows exactly what you're doing on the internet. They have to, because they route your packets, and they won't send your packets to places they aren't already spying on. No technological solution can change that, except possibly by constructing a physically parallel internet, and that stops working when...
An FSF member recommended Tor to Uighurs. An Uighur responded: "You don't understand. They aren't just monitoring my Internet. They're living in my house."
I'd argue that historically it's the opposite, most social changes came from technical changes.
It's not about making it impossible to block websites but to increase the cost of doing it further.
There's a lot of in between places from Sweden to China and raising costs of doing the bad thing globally works.