Was Godaddy Caught Registering Domains Names After Availability Lookup?
billhartzer.com
billhartzer.com
They say they aren't front running and never have, and yet how many times have people looked up a domain on GoDaddy only to have it registered minutes or hours later by a GoDaddy account.
That doesn't mean that GoDaddy itself is doing this, but their employees certainly could be, or they could sell domain query data to a 3rd party to keep their hands clean. Some Godaddy employees certainly have access to the data of who is looking for what.
It would not be hard at all to have an algorithm that looks that those domains for dictionary words and possibly look at Google keyword search volume on each one and only buy the ones that pass some minimum criteria. That would be smarter than Network Solutions and harder to prove.
I personally stopped doing domain lookups on GoDaddy because they would register domains I didn't pull the trigger on fast enough and I've been moving domains away from them as well.
Just because some VP says they don't do it doesn't mean they aren't lying or there isn't some low level tech or manager who isn't doing this on their own.
http://www.gandi.net/static/contracts/en/g2/pdf/MSA-1.2-EN.p...
I'd avoid that. NameCheap has a history of standing on the side of its customers' rights. They're my current choice.
If a 3rd party is involved, shouldn't we move to stop Godaddy from providing this information to them? If it is a case of rogue employees domain squatting, shouldn't Godaddy act to put a halt to this practice?
I don't think any domain registrar will willingly not do it. There should be some kind of law, that makes this practice illegal - both the registrar doing it themselves, and giving the data to others so they could do it. In fact, there should be a law prohibiting the sale, sharing or even saving of this data completely. If I search for a domain at a registrar's site, that shouldn't be logged anywhere.
Not directly related, but - it would be nice if there is a law that says "any domain name can be sold only for a maximum of 10 dollars" - that would prevent the disgusting domain squatters. It would upset those who spent millions already, but it might have some affect on the future squatting of domains.
Um, no. That's not true. Sending armed men into your competitor's retail store to trash the place and scare off customers is not "fair". This is also why, among other reasons, it's illegal.
Commerce is one of the many mechanisms by which we collaborate in making a better world. If you have found a way to abuse that mechanism to enrich yourself at the expense of others, then you're an asshole.
That you can get away with something for a while does not make it right, and it does not make you less of an asshole. Indeed, I'd say that finding a new way to fuck people over, and therefore forcing the creation of a new regulatory apparatus that burdens us all, makes you more of an asshole.
Of course, if it's manual, it won't prove it.
I was taken aback when a domain I owned expired and Godaddy "held it for me" to the tune of $80. I just waited a few months and re-registered after they dropped it.
This is scary for many reasons.
Although it barely made a bleep on HN, GoDaddy recently acquired Outright.com
Once upon a time, Outright had a great vision. To be like Mint, but for small businesses. For "the little guy". People sign up, plug in their bank account info, credit cards, eBay + PayPal, etc and voila! Here's your P&L. Makes doing taxes easy. Customers? Generally of the unsuspecting "lifestyle business", sole prop, a person / family business kind that just didn't know any better. Over time, Outright's servers became chock full of data (yes, even from deleted accounts), such that it could paint a live stream of a person's or a business's financial health.
This would be fine and dandy but for the fact that Outright was taken over by an incredibly unethical and morally incomprehensible CEO who, apparently, decided to sell out all of his users' privacy and security to one of his kind. So GoDaddy is now in the business of "accounting" and has access to the live stream of financial health of a whole lotta small businesses - to exploit and do who knows what with.
Also, for every registration don't registrars have to pay the ICANN fees for each domain? At almost $10/domain it would seem unwise to automatically register any domain people are searching for as it could end up costing a lot of money in fees.
Disclosure: I work at GoDaddy, but I do not work on domains, so I have no knowledge about that area of the business.
That said a few points:
1) As others have pointed out the sheer volume of domain lookups that are done at godaddy make it unlikely this would be profitable for GD to do not to mention the PR problem for that matter. Registrars do pay for domain names. Currently the cost (including ICANN fees) are $8.03 per domain (plus some other minor type costs as well). All registrars pay the same price .com .net, volume doesn't matter. Very often registrars sell below cost btw.
2) "but their employees certainly could be, or they could sell domain query data to a 3rd party to keep their hands clean. Some Godaddy employees certainly have access to the data of who is looking for what."
Is possible of course. So far no proof of that. Important point of course is that even the info (as I pointed out in another comment) when you do a command line whois to the Verisign whois server can be sniffed and/or it's possible someone at Verisign is getting at the data (or that Verisign is selling it for that matter). Since GD is the largest registrar it is quite possible the info is sniffed elsewhere and registered at GD.
3) "algorithm that looks that those domains for dictionary words and possibly look at Google keyword search volume on each one and only buy the ones that pass some minimum criteria" Exactly the way back in the 90's that I registered domain names. Except it was by excite or yahoo I don't remember. I can vouch for that personally although most good names as we know are taken long ago.
4) "or there isn't some low level tech or manager who isn't doing this on their own." Then the culprit isn't GD but someone who works for them (in all fairness). So this could easily happen at any registrar. It is possible to setup a system where a rogue employee can't get at the data of course. But that doesn't prevent what can happen as detailed in #2 above.
I haven't personally had it happen to me, but too many people I trust say that it has happened to them for me to ignore it.
And yet, even if that did happen, GoDaddy gets millions of registrations per year, and many times that in lookups. So losing a domain minutes later is certain to happen many times per year for strictly innocent/coincidental reasons.
And some of the advice being given in these sorts of threads -- use DNS/whois lookups, use other random website services -- could be increasing the risk. (Those protocols are eavesdroppable, those services have less to risk than GoDaddy.)
ICANN investigated (generally, not godaddy specifically) 3 years ago, no evidence was found: http://www.techdirt.com/articles/20090807/0048175795.shtml
GoDaddy's own support background here: http://support.godaddy.com/godaddy/you-can-trust-go-daddy-wi...
The current CEO of GoDaddy is not Bob Parsons (the "elephant hunter"). GoDaddy was sold to a group of investors this year and Parsons stepped down shortly after: http://online.wsj.com/article/SB1000142405270230458400457642...
Warren Adelman took over for Parsons last year, followed by current CEO Scott Wagner who took over this month as interim CEO: http://techcrunch.com/2012/07/30/godaddy-ceo-steps-down-scot...
In high volume systems, low probability events happen very frequently.
I'm trying to believe this is just rotten luck, but every single account of this happening seems to link back to GoDaddy.
What makes this a massive effort? I assume that GoDaddy has existing software to register a domain name given the name, and some fixed configuration like who should be listed as owner, contact, etc. So we need to call that logic, passing as input each domain that has been searched for.
Upon every search for a domain name, enqueue the search term to a queue. (This can happen e.g. after the page load completes.) The search results already indicate whether the name is registered, so only write unregistered domains to the queue.
Set up a fleet of workers to pull items from that queue and call the functionality that registers a domain.
It seems feasible to have a basic prototype of this functionality operational within a day or two of effort (e.g., a dumb implementation that simply registers every search term that's a valid domain). I'm sure the production version will need to be smarter, like not registering every single search, or estimating the value of a prospect and only registering high-value prospects - but wouldn't a basic flagrant implementation be fairly simple?
Well for one, if you have ever worked on a well established high traffic site, even to add a "simple feature" without breaking something is not that simple.
Going with your logic: User Searching for a domain; Godaddy adds it to the queue; Pulls out the domains one by one from the queue and registers it for themselves. Although it might seem simple there are few flaws in it.
a) What happens if the user want to register the available domain, wait but we already added it to our queue for automatic registration. So we need to check if the user goes through with the registration or not.
b) We are going to make millions $ holding domains hostages. But since every registration will cost goddaddy atleast $5.50 to ICANN and that there are millions of searches of domains in a month, well it certainly is one way to tank your company.
c) Alright lets then try to filter out only the popular domain name searches. But how do we determine what is popular and what is not popular. Common words? Trends? Hyphenation? Numbers? TLD? User Profiling?
d) Lets hold the domain hostage and make the user wait until they agree to backorder it from us. That will always work out for user retention.
Given that I used to own a lot of domains from Godaddy, I can attest to the fact that they have much simpler ways to hold your domains hostage if they wanted to. For example: When a domain is about to expire, the sheer volume of emails you get from Godaddy reminding you to renew is outright annoying. If they had to score better money, cut it down to just one and sent them about 4 weeks before the expiration. When most people forget to do it, go ahead and charge them $80 to get it back from redemption!!
But even without that I'm hugely skeptical of your "massive effort" claim.
This isn't true, at least as of Dec. 2008: http://domainnamewire.com/2008/12/03/standard-tactics-llc-ho... .
Edit: The author has since edited the post. The part I quote was a direct copy-paste of the last sentence from the original version. He's since made a half-hearted attempt to qualify this.
But if GoDaddy is front-running, and they outright lie and deny front-running, then it adds to their liability. Fraud is far less defensible than front-running itself (which could be defended as a good capitalistic use of asymmetrical information, after all).
Given the increase in liability the denial presents for GoDaddy, my sense is that it lends credibility to the assertion that they are not, after all, front-running.
This, plus the rather weak evidence that they're doing so (the lone assertion of a single blogger) makes me believe that there is reasonable doubt about whether they are doing it. Hey, if there are more people stepping forward, then lets see a class-action and get the proof in the light.
They may also turn off this code if this blows up in public.
They are not selling them on behalf of anyone - they, the registrar, are illegally marking them up.
Please understand this is a sincere question. I'm asking because I think it's legal. If it's illegal, I want to know about that, and especially how the law might view a register's squatting and an individual's squatting differently.
Edit: Just so it's clear, by "register" I mean truly register the domain for a year -- not "taste" it for a few days and then cancel the registration, if that is even still allowed.
These were obscure names, one with numbers.
This is just my experience, could be plain bad luck/timing. However at the time I wondered about this (nice to know it has an actual term) - emailed them angrily and got a placating response.
This makes me reconsider.
I have searched for some obscure domains in unpopular niches (imagine <extremely obscure keyword><extremely rare/popular suffix>.com> to find them registered mysteriously 24 hours later to someone on.. you guessed it.. Go daddy. This has happened enough times to me that I now only search for domains after I login into the control panel at the domain provider I use.
Many domain/whois tools do the same things.
My semi-educated guess is all searches are queued, sorted by popular keywords, and most likely hand picked off by an official employee, or someone who may have access to the data.
OTOH, I'm surprised no one has done a honeypot experiment to catch this type of behaviour in the act.
OTOH, dns and whois are unencrypted protocols. Eavesdroppers could see your lookups. Depending on which DNS or WHOIS servers you are consulting, their administrators may be untrustworthy. For example, many whois installations default to asking NetworkSolutions, who at one point (2008) was definitely front-running by their own admission.
I searched for the domain godaddysucksbigbigballs.com multiple times and it ended up being taken after 10 mins.
I assume that since there was a grace period where people could simply drop a domain and get a refund after a couple days that squaters somehow obtained the information and weree buying domains that people were searching in hoping to profit.
* now-why-would-they-register-such-an-obscure-domain-122828178327
* now-why-would-they-register-such-an-obscure-domain-211278327
* now-why-would-they-register-such-an-obscure-domain-218398211
Also, given that GoDaddy is being accused of this right now, they'd be smart to stop any front-running for a few weeks.
They weren't taken today.
1. http://en.wikipedia.org/wiki/Betteridge%27s_Law_of_Headlines
Wasn't the problem that the registrars could retain the domain names without having to pay for a few days? I thought that ICANN had addressed it but am pretty hazy on that point.
Make a LOIC-like program that queries, say, 100 domains per minute. Brute-force up to 20 char dns names. Let godaddy purchase a few million before they find out what's going on.
One could lower the queries per minute to make it not look so brute-force-y.
I monitored the domain for a year and saw no activity. At the end of a year it became available, and I snagged it at a base price. Seemed like too much of a coincidence. I don't have that common of a name. I can't prove anything though.
damn!
Now, I just use whois from the terminal.
WECHEATPEOPLEOUTOFDOMAINSFORFUNANDPROFITANDWEHATEKITTENSTOO.COM is available. Just $12.99*
I wonder how long that will stay available?
This was around 2003 and since then I'm avoiding godaddy.