Why does iTunes 10.7 try to contact the domain bogusapple.com?
discussions.apple.com
discussions.apple.com
I registered bogusapple.com after a buddy of mine posted a screenshot of Little Snitch prompting iTunes' access to the domain. All credit for finding this snafu goes to gentmatt, and my bank account for allowing me the ability to frivolously buy a domain.
I don't believe that accessing this domain is built directly into the compiled code of apps, since (in my opinion) it did not happen close enough to a software update. I believe it is just some kind of a typo (bogus.apple.com?) for something used as part of the web page views that comprise the iTunes and the Mac App Store apps. I fully expect that this problem will quietly go away once they deploy new versions.
I picked up the domain just to see if any particularly exciting web requests were being made, and it's been fun to watch user agents, but as soon as Twitter, news sites, and forums got wind of it, it's pretty much impossible for me to discern any meaningful traffic anymore.
I suppose I could start filtering any requests with a referer, or ones not coming from *.apple.com. We'll see.
It's been a fun 13 hours.
Any questions?
What you did could to a layperson be construed as intentionally exploiting a bug in their software with the result that you're now intercepting requests from unsuspecting customers of theirs, and getting data via your logs that in some countries falls under privacy laws.
Depending on how big of an embarrassment this turns out to be for them and how well funded their legal department is this might not turn out to be hassle-free for you.
If it is true that there is anything illegal with owning that domain and receiving traffic, then it is also true that a nefarious agent could "mistakenly" send a bunch of requests containing "private information" to the server of an enemy, then report the enemy's "illegal actions" to the authorities.
But I do agree that any (hypothetical) legal ramifications would look bad for Apple.
I did a quick scan (not very definitive) through the Xcode SDK and didn't see anything hard coded with this name but you never know.
I don't really want to meaningfully count :).
http://slashdot.org/story/99/12/25/114201/microsoft-hotmailp...
More clueful, certainly.
Considering some of our active theories, it may have only started becoming used as a result of that Terms & Conditions snafu that occurred the other day.
Either way, the problem predates my registration of the domain, which was around 13 hours ago now. I registered bogusapple.com as a result of seeing use of the domain.
Most likely the real reason behind this is that some programmer in their employ who didn't know better hammered in "bogusapple.com" as the first thing he could come up with, committed it since it worked for him, and now a lot of people are trying to ascribe more complex intentions to Apple than that.
It tries to load a text file over HTTP (http://www.msftncsi.com/ncsi.txt) and fetch the DNS record of dns.msftncsi.com. If the return of either is not as expected, Windows indicates 'No Internet Access' (although you are connected to a network).
I can ping example.net and example.com.
see .invalid - http://en.wikipedia.org/wiki/.invalid
Of course, the question then is, why don't they just use that one?
They request http://www.msftncsi.com/ncsi.txt and check the DNS of msftncsi.com
The Apple implementation is "logically the same" as the Microsoft implementation, yet so much cleaner.
check for yourself. http://www.apple.com/library/test/success.html vs http://www.msftncsi.com/ncsi.txt
i won't comment on the differences, which include the meaningless URL and useless "ncsi" in the text, and the fact that it still looks like an error rather than a successful test page.
The Apple page is absolutely minimal. Yet everything is in its place, and it can't leave any developer confused for a millisecond, or make a typo, as it's a human English word at a human, English URL.
Apple is Apple. Microsoft is a split millisecond of headache for a developer who rechecks his spelling of "ncsi" and the whole meaning of the ncsi concept three times to make sure his code is correct.
just like windows versus mac. yeah, it's logically the same. but one just works, one requires a three-page document. http://technet.microsoft.com/en-us/library/cc766017%28WS.10%...
----
[1] This post is tagged as being creative (as opposed to rational). as a note, about half of my posts speak to creativity and design and half speak to rationality and logic. most people only do one or the other, so i can understand why each group is confused by the other. this lets me build two brands. just ignore the posts that don't apply to you.
Now stop trolling.
I was specifically talking about that one page and its location. It is English, meant to be parsed as a literal by a program, it's not a random number or a response to a query, that .txt file is literally logically equivalent to the "succss" html page.
so, why is it so convoluted English instead of also just reading "Success"? It's just Microsoft being Microsoft.
this is not trollish of me in the slightest. if it doesn't apply to you, please just ignore it. I stand by the statement.
I'm serious in kind, but not degree :) I do realize it's pretty frivolous, and a bit funny.
It's also a good minimal example!
Even though it is only meant to be used as a literal in a program to check against with a regex, still, someone has to write that regex. Someone will either write in "Success" or write in " -- i just flipped tabs, clicked a link, then flipped back to finish this sentence -- "Microsoft NCSI".
so, ha-ha, but a little serious. it's a good example that pervades every other creative choice made at the two companies.
...meanwhile, microsoft doesn't come within a mile of a current standard - it uses a .txt file (backwards compatibility to, in this case, 1982.)
> but one just works
Except when it doesn't: http://news.ycombinator.com/item?id=4546039
I can tell you with 100% certainty that standard HTTP request information is being sent to the domain. So, IPs for the connection, User Agents of the software used to connect, and the request URL. That's pretty much it in a nutshell.
I've seen a few iTunes UAs, both Windows and Mac, and since this news has made the rounds, the signal to noise ratio just went wayyyyyy down. (Go figure.)
And it looks like the issue's already been fixed too (two posts down).
Now, it's the reverse situation. If iTunes and the App Store expect bogusapple.com to not resolve, what happens when it does? Why did Apple not own this domain?
As said elsewhere, I think the theory that they likely intended 'bogus.apple.com' is the best guess. Either way it was just a consideration that some developer and/or their code reviewer(s) overlooked.
It happens.
Chrome's behaviour makes much more sense than Apple's -- who hadn't even secured the bogusapple.com domains for themselves (as Microsoft did with Contoso, for example).
STEVE JOBS IS ROLLING IN HIS GRAVE OVER THIS GOD AWFUL FAILURE ON TIM COOK'S PART!
https://discussions.apple.com/message/19852289#19852289
Perhaps for testing purposes? "What happens when the stats server isn't reachable?"
And then it got left that way, WHOOPS.
Long story short, this problem appears to have been resolved the same day it started, since it did not require a software update to fix, they just updated the web views for their store pages.
Is anyone still concretely still seeing the problem?
https://discussions.apple.com/message/19852289#19852289
And it appears it was never about DNS resolution / network discoverability.
Go on.
He's not trading using the Apple Computers trademark nor is their any confusion. There is nothing clear about his intention, there is no mens rea nor actus rea that can be established from the information in this thread AFAICT.
Apple have no automatic right to everything bearing the name "Apple". They have no more right to the bogusapple.com domain than they have a right to a box of [fruit] apples from your local grocer.
Will they get the domain if they wish it? Are mega-corps in control of the law in the USA?
WIPO - they've erred before and will do so again I feel; they appear to have a presumption that the world belongs to corporations and don't have an interest in protecting the rights of citizens. Not unlike some governments it seems.
Given the way he's using it I doubt Apple would ever do anything more than ask him for the domain. But if he were to do something like put up a porn site or even run ads, they might be pissed off enough to sue him for the domain + damages - and they'd likely win.
Moreover reading the page [as it was presented to me] shows he's clearly not intending to infringe the mark with the content of the website either. IIRC he makes it clear that he/the page doesn't have an association with Apple Computers.
If he puts up a porn site it will be even more obvious that he's not selling computers or consumer electronics. The actual ability to infringe Apple's marks would decrease hugely. Big name corps get special additional protections in some jurisdictions however that ignore things like the actualities of the situation.
If they sue him they'd probably win regardless of the spirit of the particular statutes that apply.
Do you think that these guys - http://www.usapple.org/ - are infringing Apple's trademarks too?
Apple is a tricky word because it's also generic. It's easier to discuss this when we're talking about an obvious trademark.
See: http://www.zdnet.com/blog/facebook/facebook-disputes-21-squa...
Those domains and bogusapple.com, as it is used here, are identical - and they are frequently lost by their owners whenever the people who own the trademarks go after them.
As DannyBee alluded to, when those corporations go up against deep pocketed squatters with good domain lawyers, they can sometimes be outsmarted and not get the domains. But the vast majority of the time they are successful.
People get scared by legal threats from massive corporations - that doesn't mean that proper legal process requires [or should require] that such domains are handed over.
That's an interesting viewpoint, but not one supported by the law.
Ggoogle is typo squatting. There's nothing inherently wrong with you using that domain but serving ads or having a search engine there would be most likely trademark infringements. If you had similar livery to Google then you'd probably be 'passing off' (in the legal sense).
Personally I find nothing morally or legally wrong as long as you make it clear that the origin of the domain content is not Google Inc. and that you don't use the domain commercially (in the copyright law sense of commercial).
Perhaps you can explain how a non-commercial use of that domain harms Google and indicate which laws prevent such a use.
Google wisely own ggoogle.
There are live examples of similar named sites: moogle, agoogle are domain-squatted, foogle hosts a business, etc..
Nothing here has anything to do with trademark infringement. Period. I started to write a longer post detailing all the legalities involved here, but it's simply not necessary.
Additionally, in every WIPO appeal i've been involved that bears any similarity to this case, where WIPO ruled in favor of the claimant, it was overturned on appeal to a court of competent jurisdiction.
As for the appeals process itself, yet it is a loophole that you can file an appeal in front of any podunk judge that will hear the case, whether or not he's ever even been on the internet or knows what a domain name is - and if that judge finds in your favor, you get to keep the domain. Again, that doesn't make what I said untrue.
You're clearly a typo-squatter or somebody who otherwise traffics in TM domains, so I'm never going to get you to agree with me on this, and that is fine, we don't need to agree. But your personal attacks are unnecessary.
You caught me.
Why not send it there is the question on my mind.