Hundreds of Thousands of Google Apps Domains’ Private WHOIS Leaked
blogs.cisco.com
blogs.cisco.com
The Internet isn't the nice place that it used to be, and I literally have never gotten anything but spam snail mail letters for my domains.
Perhaps we could even drop the email, and suggest that every domain monitor the abuse@ domain in order to receive DMCA requests, etc. If the abuse account isn't monitored, DMCA requests can be sent to the owner of the IP address block, which seems to be a popular approach anyway.
(For those who have never tried it, try doing a WHOIS on an IP address to get the WHOIS records for several layers of IP block ownership. This is a use case where contact information makes a lot more sense, as these blocks are going to be owned by businesses where there'd be no point to guarding privacy.)
[1] https://www.icann.org/resources/pages/approved-with-specs-20...
Also there is very little practically that prevents a registrar from putting in valid whois info (event their own info) and holding the domain on ice until the registrant shows up (if they want to for some reason that is). There is nominal carry cost vs. the aggravation of doing the wrong thing.
And there are cases where no whois info at all appears and ICANN is ok with that. There is a domain that I am trying to get now for someone that is at godaddy. The registrant (fearing a UDRP) told godaddy to delete the domain. Godaddy didn't do that they removed the name from whois so "no match" appears. Not kosher but they do that and ICANN doesn't seem to mind. They will wait 30 days and then sell it to us for $24 backorder fee. To me that makes more sense time wise then taking it up with ICANN (and I have high level contacts at that organization that I can tap but for $24 why bother?)
Back to the issue of invalid info. Typically the process would start with someone filing the complaint form with ICANN. Then we get notified by ICANN and get time to fix the problem. De facto, we can populate the whois with whatever we want and reply back to ICANN "problem fixed". ICANN will then reply back to the person who filed the complaint "problem fixed" (to simplify things). Can't vouch for what others may do, this is what we have seen happen.
I pay for Namecheaps hidden DNS stuff so I don't get spammed with offers and whatnot, but I'm under no illusion that it means my information is private, private.
Not surprisingly, when you talk to these folks they will assume you are either very wealthy or doing something which will make your future LLC "disliked" by a large number of people. Because I was neither of these things, the recommendation was just file the paperwork myself, save some money.
Sometimes it can seem like all our privacy is disappearing, but I think it's worth remembering the how some personal data has been public for years, and things were generally ok.
"PS. The reason I am transferring is because I signed up for whois protection yet my whois info has not been protected. From what I can find on the internet, this is a common problem with Google Apps, Google will not respond to support requests for free domains, and the only way I can fix it is by taking control myself. :("
Now two years later this problem is "discovered" by someone else and Google is treating it as a security disclosure? Hey Google, maybe you should have listened to the people all over your own fucking support forums that have been complaining about this for years?
In these instances it was only when somebody recognized these issues as being real security issues and repackaged them that they got the attention they deserved.
It is a strange reverse problem in the security world - issues only get treated seriously when they are reported by security people through a formal vulnerability reporting and disclosure program (or informally via full-disclosure and other lists/forums).
While Google and other companies take security reports through these formal channels very seriously, I doubt they have anybody dedicated to trawling through user feedback and forums and spotting anything that might be infosec related.
EDIT: I understand that bugs are unavoidable but Google should be bearing the cost of its bugs. Google should volunteer the refund of $6 X 300,000 (approx. 1.8M dollars) not including negligence penalty of course.
"Sorry about the rat feces in your soup, here's a coupon for another free visit."
Are you arguing you'd rather not have them attempt to fix the problem?
So google hasn't even paid 1/100 of 1 % of the true cost.
> However, due to a software defect in the Google Apps domain renewal system, eNom's unlisted registration service was not extended when your domain was renewed.
I'm not sure if this means they were charged for something they didn't receive, or if they simply weren't charged -- their subscription to the 'unlisted registration service' was not renewed.
This does seem to be a pertinent point, that the OP doesn't really clarify.
The real reason it still exists as is, is because the registrars make money off of an artificially manufactured benefit. They're selling air at an infinite mark-up. And they're the ones that will fight to keep the status quo.
A registrar the size of GoDaddy must earn tens of millions annually in nearly pure profit off of WHOIS privacy fees.
For commercial sites in Germany a "Web Imprint" (Impressum) is required by law. This "Web Imprint" has to be on a prominent, easy to reach position on the site. It lists the contact data for the owner(s) of the website.
Making anonymously-run webshops against the law shields the consumer against fraud and always gives non-law enforcement a place of contact to file their complaints.
Check for yourself the correlation between WHOIS protected/anonimized webshops and shady business.
For a service which is intended to serve those with hidden number or hidden address, 94% opt-in rate sound to dilute that purpose which makes the people in charge less careful in handling it. Might very likely even cause more leaks in the future.
There are legal ways to deal with this. There are D/B/A names and corporations. But hiding under a rock is not a valid option.
I have my name and address on all my domain registrations. It's not much of a problem. I've had two threats of litigation. One is now out of business and the other backed down. I get occasional phone calls. I may be getting spam, but my spam filters are dumping it before I see it.
[1] http://www.sitetruth.com/doc/californiabpcode17538.html [2] http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:...
Sadly this is the reality for individuals these days, until society catches up with technology - having your mailing address and phone number out and publicly accessible is actually quite dangerous.
Personal ones don't even list email contacts! :)
1. Get a mailbox (eg UPS Store) and use that instead of your home address. This is worth the $5-15/m cost for package delivery alone. No worrying about someone stealing packages from your home while you're at work. Privacy is a bonus.
2. Use a phone service like Google Voice to protect your phone number.
3. Add WHOIS privacy on top of that if you really feel you need it.
Email protection isn't really an issue. I use domains@[mydomain] and all the spam I get is filtered.
http://about.usps.com/news/national-releases/2012/pr12_125.h...
If you have been displaced and don’t have a permanent address, General Delivery service allows you to pick up your mail for up to 30 days at a designated Postal identified location in your current community. Make sure senders of your mail use the ZIP Code for the area’s designated Post Office. The ZIP+4 will indicate General Delivery. To find the Post Office that handles General Delivery in any area, call 1-800-ASK-USPS (1-800-275-8777) and request “Customer Service.”
An example of a properly-formatted General Delivery address looks like this: JOHN DOE GENERAL DELIVERY ANYTOWN, NY 12345-9999
EDIT: I use it as a /dev/null physical address, as I have no need for paper mail.
Seriously, Adam (at Google). You need to maintain some smart people who continue to monitor what your products are actually doing in production in the real world. People who can and do go beyond thinking and acting as insiders. User advocates.
It's not glamourous work. But it's necessary.
I can assert, through my use of a competitor's product, that I actively check that their WhoisGuard is actually in place and renewed for each of my relevant registrations. I find it difficult to imagine there's not a smart Googler, using your services for their own private endeavours, doing the same. Or are no Googler's privately using your registration services?
Trust, but verify.
P.S. I'll add that this is not the first time I've encountered, as an end user, a significant security concern with Google products. The previous one was fixed. And as an end-user, it was immediately obvious to me what the problem was. Though it took a bit of arguing. To be brief, in the real world, users share computers. That should not include cached access to private cloud documents. Try selling that to e.g. the government (who is a customer).