Slashdot Mirror


Cert Slamming, or, Desperate Companies Behaving Badly

the special sauce writes "A few months back, our customers (we run a regional ISP) started receiving deceptive domain renewal notices from Verisign and Verisign partners such as Interland. A couple of our customers temporarily lost their domains in the process as the registrant, contact information and hosting company was all changed. Yesterday, I received an e-mail from a customer. He was forwarding a "reminder" e-mail he had received. It was an SSL certificate "renewal" notice from a UK company, Comodo. It instructed him to "upgrade" his current certificate (issued by Equifax) before it expired." More information on this charming practice follows... the special sauce Continues: "For those who don't know, Equifax was just bought out by GeoTrust, who offers a QuickSSL product. Comodo's e-mail was advertising an "InstantSSL" product, which I myself mistook for the GeoTrust product on first reading the e-mail. When I realized my mistake, I contacted Comodo and inquired as to their relationships with Equifax and GeoTrust and how they came by my customer's information. The response: "We have no relationship with Equifax or GeoTrust. The information on a certificate is public information which we have used to inform this company that they have an option when they come to buy their certificate."

My interpretation: Comodo is harvesting contact information from certificates in bad faith, to market a competing product. Furthermore, I think they have targeted Equifax customers because the company was just bought out. In any buyout, confusion exists as to the "new" company's identity. I think they are offering a product whose name is confusing similar to a GeoTrust's product. The language in their e-mail does everything possible to obfuscate the fact that they are not affiliated with Equifax, encouraging customers to "renew" and "upgrade" their certificates. In reality, if my customer had clicked the links in the e-mail, he would have been purchasing a new certificate from a company with which he had no previous relationship.

So I ask, is this not cert slamming? I don't expect this to be as big a problem as Verisign's domain slamming: we simply host less certificates than domains so it is easier to warn all of our customers with secured web sites. Nevertheless, I've reported the practice to the FTC."

186 comments

  1. Recent case by essdodson · · Score: 2, Interesting

    There was a recent ruling against Verisign for this activity. Because of their deceptive mailings I will _NEVER_ consider using them as my registrar.

    --
    scott
    1. Re:Recent case by uncoveror · · Score: 3, Interesting

      I got those notices myself for Uncoveror.com, uncoverer.com, and dontbuycds.org, but my e-mail from GoDaddy warning me that they are bogus came first, and I was not fooled. I hope everyone behind this scam goes to the slammer, and finds out several times per day why it's called that.

      --
      The Uncoveror: It's the real news.
    2. Re:Recent case by Anonymous Coward · · Score: 0

      why the hell was this offtopic you drunken motherfuckers? Jesus.

  2. Slamming? by doc_traig · · Score: 3, Informative


    Don't customers have to have their service provider actually changed (w/o authorization) for the practice to be considered slamming?

    I mean, what's described here is disgusting, but I don't know that the terminology fits.

    - DDT

    --
    So long, michael. Don't let the door hit you...
    1. Re:Slamming? by ceejayoz · · Score: 2

      It should probably be considered "deceptive advertising" - I know there's a law against making advertisements that look like invoices (which this one does) in the US - instead of "slamming".

      Regardless of what you call it, though, it's a sleazy practice. If a company has to trick you into buying their services, what does that say about them and their services?

    2. Re:Slamming? by mduckworth · · Score: 1

      What exactly is disgusting about it? I mean did you actually read the email? It's plain english that they are not trying to slam in any way. It doesn't say anywhere "we are your registrar". It's a solicitation of service that is targeted, no different from other mailing lists and everything else used. People should grow a clue and if they're going to bitch at least bitch about the right things.

    3. Re:Slamming? by Anonymous Coward · · Score: 0

      He's right, and he's not off-topic. That moderator is a fucking retard.

    4. Re:Slamming? by Anonymous Coward · · Score: 0
      It's plain english that they are not trying to slam in any way.
      You fucking moron, I'm not trying to insult you in any way, but I think you are a weasel-humping hemaphrodite who wears combat boots and a ballet tutu. With respect and without any intention of causing you mental harm, it is obvious that your brain is made out of the same stuffing that is normally used in inflammable children's matresses. Despite the fact that your face looks like it was the bastard child of a DR-Chipper/Shredder and a poisonous South American toad I hope you are not insulted by this message.

      With all respect,

      An Anonymous Coward.
    5. Re:Slamming? by mduckworth · · Score: 1

      Oh stop flattering me. I'll be the first to agree that this kind of stuff sucks. But it isn't "slamming". They didn't do anything more wrong then other companies. They should all burn.

  3. Re: Cert spamming... by corey_lawson · · Score: 0, Redundant

    At least they aren't invalidating your certification. What they have done is not much different really than other net trolls who do nothing but suck email addresses from websites and Usenet posts. How many junk mail adverts have you gotten that try to look like: a federal government check (i.e., tax refund) certified US mail (credit card adverts) etc.?

  4. So, wait... by Mike+Schiraldi · · Score: 5, Funny

    What exactly does this story have to do with VeriSign?

    If we're going to start working slams against companies we don't like into unrelated stories, we should at least cover all the bases by saying something tangential about Microsoft or an RIAA member while we're at it.

    1. Re:So, wait... by sylvester · · Score: 3, Informative

      What exactly does this story have to do with VeriSign?

      This. I'll refrain from snide comments. :-)

      -Rob

    2. Re:So, wait... by DarkZero · · Score: 2

      Verisign started the trend and provided a similar case. Thus, including them as an example of what's going on provides a nice context for the story.

    3. Re:So, wait... by Reality+Master+101 · · Score: 2

      I'll refrain from snide comments.

      That's probably for the best, because you would just be more wrong. Verisign was sending out deceptive notices. There is NOTHING deceptive about this. It's just a simple advertisement.

      --
      Sometimes it's best to just let stupid people be stupid.
  5. Go Daddy and less Spam by RumGunner · · Score: 1

    I switched from one of the big evil registar companys to Go Daddy and I've gotten far less of this sort of spam.

    1. Re:Go Daddy and less Spam by Anonymous Coward · · Score: 0

      GoDaddy spams people as well - I've made a filter to keep my Pop3 mailbox clean of their garbage advertising.

    2. Re:Go Daddy and less Spam by CoolVibe · · Score: 2
      I went to these guys. Same results: less spam, more control, and lower prices than Verisign/NetSol/whatever.

      And on top of that, they gave me an extra year for free for transferring to them. How nice of them :)

    3. Re:Go Daddy and less Spam by Etcetera · · Score: 2

      Names4Ever is another pretty good registrar. Decent config options and no spam.

      Being located in the same city as I helps too... I believe they were the first Registrar in CA...

  6. Verisign... by moronic1 · · Score: 1

    sure verisign doesn't have a stake in Comodo? heh..

  7. Verisign doesnt care by www.sorehands.com · · Score: 5, Interesting
    Verisign doesnt care, why should anyone else?

    Verisign only complains if anything takes money from them. If they don't lose money, they don't care.

    I spoke with a person at Verisign about an obvously false whois registration, that belongs to a spammer. This clearly violates ICANN rules, but Verisign does not want to hear it.

    1. Re:Verisign doesnt care by Anonymous Coward · · Score: 1, Troll

      Do you even know what you're talking about? I worked for Verisign for a couple of years and saw a totally different picture. Verisign does alot of work for the internet community. They pump millions each year into investigating violations into the ICANN rules. The problem is that the problem is that rule breaking has become to widespread for them to tackle every situation. The system is flawed, but good companies like Verisign recieve the blame. I suggest you actually look into the situation before you start making accusations at a single company.

    2. Re:Verisign doesnt care by 1010011010 · · Score: 2, Offtopic


      Verisign is not "a good company." It is, other than one particular tow-truck company, the worst company I have ever done business with, or had to deal with in any other way. Over that last six years, I have never had what I would call a good experience with them. Each and every one has been annoying, agonizing, and more time-consuming than necessary.

      I don't care what your internal view of the company was like. From the outside -- which is what counts to us consumers -- Verisign and Network "Solutions" suck. There is no two ways about it.

      --
      Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
    3. Re:Verisign doesnt care by ceejayoz · · Score: 2, Offtopic

      As a Verisign customer (still - against my will) - I'll say they have the absolute worst customer service I've run across on the web.

      My domain was slammed over to Verisign. Called my old registrar to ask what was going on, they said it'd been transferred, so I called Verisign. They first told me that my registrar had been bought by them - complete fabrication. To retrieve my new "customer ID" and password, I had to fax something in to them (why not just send it to my registered e-mail address?) and wait 2 weeks.

      By now I was thinking "oh yay, I can transfer away now". But no - even though their WHOIS records say that the domain expires in March 2004, they rejected my transfer because it had "already expired". I'm still trying to get it back and am thinking I'll have to sue them.

      So, as a short response to Do you even know what you're talking about? - the answer is "yes, we do - Verisign sucks ass".

    4. Re:Verisign doesnt care by zerocool^ · · Score: 2

      ..other than one particular tow-truck company...

      You live in Blacksburg, Va, don't you? You're of course refering to Tek Tow. The company that had over 3000 signatures on Petition Online overnight wanting to shut it down, and remember how small Blacksburg is.

      One time they towed a mail truck. On sept 11, they towed people that had parked their cars at meters and lined up to give blood. They tow DD's from the bars downtown. And so forth.

      ~Will

      --
      sig?
    5. Re:Verisign doesnt care by Anonymous Coward · · Score: 0

      You have been trolled. Have a nice day :-D

  8. Re: Cert spamming... by Tri0de · · Score: 2

    Well, once you OPEN one of the psuedo-offical enevlopes you can usually figure out it's just an ad, the offical looking stuff is just to get you to open it (although those 'checks' are a rip). But this, from what I have seen, looks like an actual renewal notice, much more sleazy IMHO.

    --
    "Everyone is entitled to their own opinion, but not their own facts."
  9. Of course it is. by FreeLinux · · Score: 5, Insightful

    Sure it's Cert slamming. There's no doubt about that. The problem is though, that to date there is no law against it. That's right, perfectly legal. For example I have on my desk a letter from "The Admiistrative Office of RPR/OFV Records Division". It looks vaguely like something from the IRS, certainly it is from some government agency. When I open it, it looks like a check for $1600 and a ticket for a cruise. Of course, it is all a bogus marketing scam. Probably trying to sell time shares. It's totally and intentionally misleading but, at the same time it is still legal.

    Furthermore I wouldn't look for a law against it any time soon. Things like certificates and how they work are a bit on the technical side, at least for our poor overworked legislators. They have a lot of catching up to do and are currently bogged down trying to stop the MP3 swappers from being the scurge of humanity that they are.

    1. Re:Of course it is. by Golias · · Score: 1
      The problem is though, that to date there is no law against it.

      Does every new kind of fraud require a new law? Isn't it enough to say that they are deceiving consumers and shut them down?

      These sorts of scams look to me something for enforcement agents and courts to worry about, not lawmakers.

      --

      Information wants to be anthropomorphized.

    2. Re:Of course it is. by Reality+Master+101 · · Score: 2

      Sure it's Cert slamming. There's no doubt about that.

      Did you actually read the letter? Please quote me the passages that could be misinterpreted as anything other than an advertisement.

      --
      Sometimes it's best to just let stupid people be stupid.
    3. Re:Of course it is. by quantaman · · Score: 2

      "The Admiistrative Office of RPR/OFV Records Division"

      Usually I decide if they misspell "Administrative" it's probably a scam. Come to think of it that would sure explain of a lot of stories on slashdot...

      --
      I stole this Sig
    4. Re:Of course it is. by Paradise+Pete · · Score: 1
      Sure it's Cert slamming. There's no doubt about that.

      Yes there is. There's lots of doubt about it. It's not slamming at all. Weasely, perhaps, but not slamming.

    5. Re:Of course it is. by lobsterGun · · Score: 1

      Exactly what kind of fraud is being commited here?

      All they did was to offer their services as a cert provider. They never claimed anyting untrue. Heck, their letter actually sounds down right friendly... but you would know that if you had read the letter.

    6. Re:Of course it is. by jeremyp · · Score: 2

      Use of the word "upgrade" implies they have a legitimate connection with Equifax. I'd say they were misrepresenting themselves as agents of Equifax. Don't know if that is illegal, if they're defrauding anybody it's probably Equifax (i.e. they get the customer's money not Equifax).

      --
      All I want is a secure system where it's easy to do anything I want. Is that too much to ask ~~ Randall Munroe
    7. Re:Of course it is. by lobsterGun · · Score: 1

      With all due respect, I think you're wrong. I see no implication of association the term 'upgrade'. I really don't see any fraud here.

  10. While we are on the subject by Myuu · · Score: 1

    I really think that whois records should be kept more private to stop things like this.

    What pisses me off is that I get SPAM snailmail from companies that get my address off my whois.

    I have gotten numerous emails from companies doing the same thing.

    Unfornutately it is legal because they have a size 5 disclaimer at the bottom

    --

    forget it.
  11. Not related to Verisign at all by Reality+Master+101 · · Score: 3, Informative

    While I don't condone the spam advertising methods here, this is NOT comparable to Versign's shady practices. Verisign was sending out notices that tried to make people believe they were renewing their domains, but were actually switching providers.

    There is no deception here. It's a simple advertisement asking you to switch.

    Nothing to see here.

    --
    Sometimes it's best to just let stupid people be stupid.
  12. Riiiight.. by iONiUM · · Score: 3, Funny

    Verisign partners such as Interland

    Is it just me or are these internet companies' names getting more cheesy everyday?
    Soon we'll have CutCo, EdgeCom, and the ever waiting CompuGlobalHyperMegaNet joining the leagues of crap companies im sure.

    1. Re:Riiiight.. by EvilFrog · · Score: 1

      Microsoft already "bought them out".

    2. Re:Riiiight.. by Geekboy(Wizard) · · Score: 2

      "CompuGlobalHyperMegaNet? Buy them out boys!" *Smasing of the Simpsons house ensus.*

      -Bill Gates, via the Simpsons

    3. Re:Riiiight.. by Anonymous Coward · · Score: 0
      Shiiit. Three replies in a row to your clever post by people trying to show the world how cool they are for getting the Simpsons reference.

      Okay, okay, you know it was Homer's Internet start-up. We're happy for all of you. Now go out and get lives.

    4. Re:Riiiight.. by Anonymous Coward · · Score: 0


      There actually is a company called CutCo, and they manufacture fairly high-quality kitchen knives and utensils, and market them through personal sales agents via a marketing firm called Vector. Pretty snazzy!

    5. Re:Riiiight.. by Oddball · · Score: 1

      Actually, Cutco (unsure of spelling/capitalization) is a real company. They make fine cutlery for the discerning chef.

      Seriously.

      My sister was a Cutco salesperson.
      Good knives, too.

      --
      "A good programmer is someone who looks both ways before crossing a one-way street." - Doug Linder
    6. Re:Riiiight.. by caferace · · Score: 1
      The sky is falling!

      CutCo
      EdgeCom
      CompuGlobalHyperMegaNet

  13. What about the pre-trusted root cert? by joeflies · · Score: 3

    Anyone know if Comodo's cross-signed with another provider? I dont' see Comodo listed with their own top-level pre-trusted root in Konq 3.0 or Mozilla 1.0, so I sure hope they are cross-signed with someone.
    That would be truly unfortunate for the victim to fall for this and end up with a cert that nobody's browser trusts.

    1. Re:What about the pre-trusted root cert? by Zwack · · Score: 3, Informative

      If you take the time to visit their website, you will see that they sign using a Root provided by GlobalSign. A Belgian company who are in Mozilla...

      Z.

      --
      -- Under/Overrated is meta-moderation, and therefore is Redundant.
  14. Cybersquatting by TheKubrix · · Score: 1

    On a related noted, from CNN.com

  15. This is nothing new! by Wrexs0ul · · Score: 4, Informative

    Comodo is a spam-laden organization. I run a web hosting and network management firm in Edmonton and we've received countless offers for "CHEAP SSL" and other services from Comodo!

    It's been thoroughly discussed in other location such as WebHostingTalk.com which I suggest anyone interested in pursuing a Comodo service look at first. These guys actually responded in the forum with a nice show that they don't actually care who they spam provided it makes a buck.

    Sincerely,

    -Matt

    --
    --- Need web hosting?
    1. Re:This is nothing new! by Anonymous Coward · · Score: 0

      is spam-laden bin laden's brother?

    2. Re:This is nothing new! by Anonymous Coward · · Score: 0

      news.admin.net-abuse.sightings has also reported Comodo spam. Checking Google's archive is always a good idea.

  16. Domain Registry of Europe are slammers too by jdesbonnet · · Score: 1

    Beware of con letters from "Domain Registry of
    Europe" (based in UK). They are trying the same
    scam as Verisign.

    1. Re:Domain Registry of Europe are slammers too by ceejayoz · · Score: 2

      There's also the "Domain Registry of Canada" and the "Domain Registry of America". Wonder if it's the same outfit... they make 'em look like official govt. documents.

    2. Re:Domain Registry of Europe are slammers too by kiwimate · · Score: 3, Informative

      I had this with one of the afore-mentioned companies a few months ago. (I'm a coward and don't want to get into trouble, so I won't mention names.) They got e-mail addresses for every listed contact from our whois record, and sent off letters to anyone for whom they could find an address, warning that our domain name registration was about to expire.

      Including our CEO.

      Who, not understanding what it was, and also not realizing that I'd only just renewed the domain name for five years and we weren't in any danger of losing our domain name until 2007, passed it on to the secretary with instructions to pay the bill.

      Now, in fairness, the letter is cunningly worded, and probably can't be technically construed as slamming; it gives you the option. But, hoo boy, is it slimey!

      The first I knew about it was when I started getting automated e-mails from our original registrar asking me to go through certain steps to authorize the name transfer. I tracked down what was happening, and got on the phone to Dom. Reg. of ***.

      Forget the long, boring, tedious arguments. And the appalling insolence and downright rudeness of their people. Just a few points...

      * They're used to complaints. Despite their protestation that I was only the second person who'd ever complained about this, as soon as you mention the word slamming they've got a rehearsed speech about the wording of paragraph five which they quote to prove it's not slamming. Uh-huh. Try doing a Google search on them and see if it's that rare a complaint.
      * They're unhelpful buggers. No matter when I called, I was always told that nobody who was there could help me with my complaint, and I'd have to call back.

      In the end, it works out okay. All you have to do is not authorize the transfer and they can't do anything about it, and they have to refund your money. Except for a processing fee. Trust me -- I argued and bitched and generally made a nuisance of myself by pointing out there was nothing in any of the correspondence we'd received or on their website about a processing fee, and we got the money back.

      But believe me; there is one company who is now boycotted for life in my books.

  17. Why this is not cert slamming by pongo000 · · Score: 4, Insightful
    "Slamming" is generally recognized as the process of subscribing a user to a new product or service without their express permission. Sounds to me like Comodo is simply taking advantage of publicly-available information to market their own product. Since when is this a crime? Here are some other examples of companies using public information to market their own products:
    • A company uses publicly-available vehicle registration information to pitch extended warranties.
    • A tax company uses public appraisal tax rolls to offer their assistance in filing appraisal appeals.
    • A company sends a homeowner a form and fee request to file a homestead exemption, again using information from public tax rolls.
    • An insurance company sends a "reminder" about homeowner insurance renewal, using information publicly available in some states (usually loan information).
    • A doctor's office uses publicly-available information to notify a pilot that it's time for he/she to renew their medical certificate.
    In all these cases, companies are pitching their wares using public information, knowing full well that a small percentage of the population will choose not to check the details. Exploitive? Maybe...but certainly not illegal. And it can't even remotely be considered slamming.

    It even looks like Comodo was very straightforward with you when you requested additional information. I see no attempt by Comodo to obfuscate their purpose.
    1. Re:Why this is not cert slamming by DanEsparza · · Score: 1
      In all these cases, companies are pitching their wares using public information, knowing full well that a small percentage of the population will choose not to check the details. Exploitive? Maybe...but certainly not illegal. And it can't even remotely be considered slamming.

      I completely agree! And what you didn't point out (enough, I think) is that they had the CHOICE to read the email, the CHOICE to examine whether or not this was a good purchase decision, the CHOICE to get further information from Comodo (and Comodo made a good CHOICE by being honest), and the CHOICE to purchase the cert from Comodo, or any other company for that matter.

      Nevertheless, I've reported the practice to the FTC."

      This is exactly what's wrong with the Internet, at this point (IMHO). People are too used to government stepping in and 'protecting' them from 'overpowering' capitalist companies. ("Oh no -- look away, the SSL cert is too inviting ... don't stare directly at the cert!")

      Also, what happens if this was an overseas company? Who are you going to cry to then? Interpol?

      Give me a break -- Comodo is ingenius. I'm kicking myself for not starting up a company that sells certs and doing the same thing before they did. I'd be willing to bet that more folks will take advantage of this type of public information as they realize that Comodo and other companies are making a killing by 'out foxing' the competition.

    2. Re:Why this is not cert slamming by Anonymous Coward · · Score: 0

      I agree that this isn't "slamming" but I do think that calling it a RENEWAL is misleading.

    3. Re:Why this is not cert slamming by Snafoo · · Score: 2

      Wow. That explains why so much of
      the product I endure at poetry-slamming
      night is so godawful - I've been signed up as a member of the audience without my express permission!

      Everything is clear now. Thanks, Slashdot!

      --
      - undoware.ca
    4. Re:Why this is not cert slamming by BrookHarty · · Score: 2

      Well... It is Slamming if the email/form/letter looks like you're renewing an existing service with your current provider, even if the fine print states its switching service.

      Basically it comes down to "Permission", if your tricked, did you give permission? Phone companies will ask you to say, "I want to switch service" and record it. Do you see this level of candidness, that the customer is 100% clear on his actions? Nope.

    5. Re:Why this is not cert slamming by Anonymous Coward · · Score: 0

      In any of those cases, if the marketer passed themselves off as a completely different organization (because you've already done business with them), that's fraud. It's not slamming because it doesn't happen without your involvement (just without your informed consent).

    6. Re:Why this is not cert slamming by ceejayoz · · Score: 2

      Phone companies only have to do that because it's law - they were notorious for slamming, so the law was enacted.

      Now we need something like that for domain names.

  18. Simpsons law of the Internet! by Wrexs0ul · · Score: 1

    Careful what you say, if you remember the episode correctly Bill Gates may try to buy you out.

    -Matt

    --
    --- Need web hosting?
  19. Difference by MattCohn.com · · Score: 1, Insightful

    I read both notices and it seems like the VeriSign one was much more confusing then the one from Comondo.

    In the VeriSign renewal form, it had no indication that they were not your registar to begin with. However in the Comondo email it had wording such as...

    why not upgrade your Certificate with Comodo and join our many customers

    That made it clear to me that this wasn't sent to a current customer of Comondo.

  20. Office of fair trading by sh0rtie · · Score: 5, Informative


    If this company is UK based i would advise you to report them to the Office of fair trading and the UK Trading Standards , these kinds of practices are despicable and the OFT and TS do not take kindly to this sort of behaviour

  21. Bingo... by Rev.LoveJoy · · Score: 3, Interesting
    You're right on. This is simply more slimy marketing tactics from companies with bombing market shares.

    I cannot even count the number of bogus faxes / emails I have received telling me one of my domains (or some clever spelling thereof) is about to expire.

    Gee, marketing people are creepy slimeballs. I'm stunned. No. Really.

    Cheers,
    -- RLJ

    1. Re:Bingo... by Etcetera · · Score: 2

      This is simply more slimy marketing tactics from companies with bombing market shares.

      Actually, Comodo's market share has been increasing dramatically, considering how small they started at. We use them at and they're great. Very responsive and sell a great product.

      In fact, I'm surprised more Slashdot-ians aren't ENCOURAGING Comodo. These are guys who are selling basic 128-bit certs for only $49! A FAR more reasonable price than either VeriSign (evil) or Thawte are charging...

  22. OK, but who makes the CSR? by Jacco+de+Leeuw · · Score: 3

    So Comodo spams website owners. As a result, the website owners might get tricked into buying this cert "renewal".

    But who makes the Certificate Signing Request for website owners? In most cases the company hosting the web site. (Unless it's co-location).

    I expect competent tech support personnel to filter out these bogus certificate renewals immediately.

    --
    -------
    Warning: Slashdot may contain traces of nuts.
  23. See Also: Australia and New Zealand by Audent · · Score: 4, Informative

    Yup, even in the southern hemisphere it's happening.
    Internet Name Group (no URL any more that I can find) and Internet Registry have both been trying it on in Ausralia and New Zealand. The ACCC (commerce department in Aus) and the Commerce Commission in NZ are both keeping an eye on the matter.
    Stories on the subject here:
    http://www.idg.net.nz/webhome.nsf/nl/D6AC0A 53F05EC FC6CC256ABF00090DE4

    and here:

    http://www.idg.net.nz/webhome.nsf/nl/A8539751DEE A2 77DCC256BC9000CA1D2

    apologies for the evil links... goddam Notes.

    --
    I am a leaf on the wind
    1. Re:See Also: Australia and New Zealand by chump+daddy · · Score: 1

      yeh, but what you're talking about is for domain names, not certificates. but I guess this will keep happening on all manner of internet services. It's gonna be interesting when a company tries to sell dialup users an upgrade to their email huh? they'll have access to your email, your address book, maybe even your scheduler if they offer those services. they'll know what you do.. imagine how useful that will be... so many chumps... so little time. wonder how may xtra users will go for that..

  24. random by labratuk · · Score: 0, Offtopic

    test post, please ignore.

    --
    Malike Bamiyi wanted my assistance.
  25. renewal and upgrade by phriedom · · Score: 2

    Don't you think that calling their offering a RENEWAL is deceptive? It is a new and different certificate from the one that is expiring. It is not a renewal, it is a replacement.

    --
    Don't moderate flamebait as Troll. Know the difference or you will be Meta-moderated.
    1. Re:renewal and upgrade by Reality+Master+101 · · Score: 3, Informative

      Don't you think that calling their offering a RENEWAL is deceptive?

      Let's review the wording:

      "Did you know that your current SSL Certificate protecting [customer domain] will expire in only 60 days? "Before you renew please read the following important information from Comodo. "We offer SSL certificates that provide;"

      Note the "BEFORE you renew". Note the "We offer". Note that a list of services follows this, along with pricing. Please explain how this can be interpreted as a renewal notice coming from your certificate authority.

      As for the "upgrade", I certainly would consider it an upgrade of service to pay only $49 rather than the rip-off $1000 that Verisign charges.

      --
      Sometimes it's best to just let stupid people be stupid.
    2. Re:renewal and upgrade by phriedom · · Score: 2

      Lets review the rest of the wording:

      1 year renewal ($49):
      2 year renewal ($89):
      3 year renewal ($125):

      If you renew now with Comodo we will extend the lifetime of your new Certificate by 60 days at no extra cost - allowing you to begin using your upgraded Certificate immediately.


      What they are selling is not an renewal nor an upgrade of the current certification. It is a new certificate. I understand your arguement about the meaning of "upgrade", but I still think it is deceptive. If they were trying to be up front about what they are selling you, then they would say something like "Instead of renewing your old certificate before it expires, you should buy a new, better certificate from us. Its a better deal and we promise you won't regret it." But they don't, they make an ambiguous pitch.

      --
      Don't moderate flamebait as Troll. Know the difference or you will be Meta-moderated.
    3. Re:renewal and upgrade by Reality+Master+101 · · Score: 2

      I think you're being a little over critical of the wording. We can debate the exact meaning of "upgrade" or what word might be better, but the overall point is whether this e-mail can be misinterpreted as a renewal notice from your current certificate provider. And I don't think there is any chance of that.

      In fact, that's not even the overall question. The pertinent question is whether there is any deliberate attempt at deception, and I think that's even harder to make the claim. If they are trying to deceive people, then it's pretty damn piss-poor job of it.

      --
      Sometimes it's best to just let stupid people be stupid.
    4. Re:renewal and upgrade by andybak · · Score: 0

      yjays funny... My theory also is that the reason many Europeans hate Americans is because you care so little that we hate you! ;-)

    5. Re:renewal and upgrade by Reality+Master+101 · · Score: 2

      I'm not saying we don't PAY the $1000. It's worth it considering that Versign is compatible with every browser version. But that doesn't make it less of a rip-off.

      --
      Sometimes it's best to just let stupid people be stupid.
    6. Re:renewal and upgrade by RoninM · · Score: 2
      Well, it's really easy to not be fooled by the notice when you already know it's not from your provider. The customers in question, however, are receiving a timely "renewal" notice at a time when their current provider's identity is in flux. It's quite easy to see how they can be confused.

      The wording is not the sole reason for the spam being (decidedly) deceptive. The repeated use of "renewal" and "upgrade" only help to assure the already unsuspecting customer that the notice is from their current, recently bought-out provider. Those who go in with more caution will have the red flag raised by a more careful reading (as you've done) of the actual language of the notice.

      Without question, people should be more cautious when it comes to such things. However, not everyone's going to catch on to everything all of the time -- a lot of bright people have been known to fall for April Fool's jokes every now and then. It's much easier to overlook the clues that more objective/critical readers spot when you don't have a reason to suspect something's wrong.

      --
      If a corporation is a personhood, is owning stock slavery?
    7. Re:renewal and upgrade by Ben+Hutchings · · Score: 2
      What they are selling is not an renewal nor an upgrade of the current certification. It is a new certificate.

      You can't really renew a certificate, because the validity dates are (and must be) part of the certificate. So a new certificate will be needed after the existing one expires, whether or not the domain holder gets it from the same CA.

    8. Re:renewal and upgrade by Mr+Guy · · Score: 2

      It is a renewal. You had a valid certificate before, you will have a valid certificate after. It MAY be borderline sleazy, just as I consider legit cold calls from MCI to be sleazy (anyone have that lawyer from Washington's info? The one that sues spammers and telemarketers after he tells them to cease and desist?). It ISN'T decepetive, as near as I can tell though. You can't fool all of the people all the time, but you can for some of the people whether you want to or not.

  26. Screw Verisign by Anonymous Coward · · Score: 0

    I've moved all my domains off of Veri$ign, screw them all. godaddy.com has been working out well.

  27. Trust by flonker · · Score: 5, Insightful

    SSL and crypto in general is all about trust. Would you trust someone who engages in deceptive marketing? Then again, so does Verisign, with their domain stuff. Are there any good certificate issuers?

    1. Re:Trust by zerocool^ · · Score: 2

      We use Thawte. I haven't seen any deceptive marketing practices from them. They have a root cert in just about every browser I've seen. Plus their certs are only $150 and $125 to renew. They also offer wildcard certs (*.netmar.com), but those are 1.) rediculously expensive, and 2.) IE doesn't deal with them well, it still gives an error message about the site not matching the name on the cert. Insert random conspiracy theory about verisign's involvemenet with Microsoft.

      Basically, what you look for in an SSL cert is trust, price, and that it's in I.E. And I hate to say it, but of the people that issue certs, the only one that anyone in the general public has heard of is Verisign. (commercials - the value of trust, listed on nasdaq... Would I be proud to be listed on nasdaq nowadays?) If you're a webhosting provider, yes trust is important, and principles are important, but it's not the reason I would choose thawte over verisign, that would be price. Your customers most likely will never see who signs the cert as long as it's included in I.E. You would never want to use a cert that was included in moz, konq, galeon, netscape, but not in I.E. - You'll alienate 90% of the web.

      It just so happens that I trust Thawte, and they are cheaper than Verisign. It's a good combination.

      ~Will

      --
      sig?
    2. Re:Trust by Anonymous Coward · · Score: 0

      i remember something about verisign buying thawte...
      well, maybe its just me.

      whois thawte.com@whois.networksolutions.com
      [whois.netw orksolutions.com]
      The Data in the VeriSign Registrar WHOIS database is provided by VeriSign for
      information purposes only, and to assist persons in obtaining information about
      or related to a domain name registration record. VeriSign does not guarantee
      its accuracy. Additionally, the data may not reflect updates to billing contact
      information. By submitting a WHOIS query, you agree to use this Data only
      for lawful purposes and that under no circumstances will you use this Data to:
      (1) allow, enable, or otherwise support the transmission of mass unsolicited,
      commercial advertising or solicitations via e-mail, telephone, or facsimile; or
      (2) enable high volume, automated, electronic processes that apply to VeriSign
      (or its computer systems). The compilation, repackaging, dissemination or
      other use of this Data is expressly prohibited without the prior written
      consent of VeriSign. VeriSign reserves the right to terminate your access to
      the VeriSign Registrar WHOIS database in its sole discretion, including
      without limitation, for excessive querying of the WHOIS database or for failure
      to otherwise abide by this policy. VeriSign reserves the right to modify these
      terms at any time. By submitting this query, you agree to abide by this policy.

      Registrant:
      VeriSign, Inc. (THAWTE-DOM)
      487 East Middlefield Road
      Mountain View, CA 94043
      US

      Domain Name: THAWTE.COM

      Administrative Contact, Technical Contact:
      VeriSign Hostmaster (VH2134-ORG) vshostmaster@VERISIGN.COM
      VeriSign, Inc.
      487 East Middlefield Road
      Mountain View, CA 94043
      US
      650-961-7500
      Fax- - 650-961-8870
      Fax- - 650-961-8870

      Record expires on 12-Feb-2003.
      Record created on 10-Feb-1996.
      Database last updated on 24-Jul-2002 22:16:32 EDT.

      Domain servers in listed order:

      BAY-W1-INF5.VERISIGN.NET 216.168.254.20
      GOLDENGATE-W2-INF6.VERISIGN.NET 216.168.254.21
      NS1.CRSNIC.NET 198.41.3.39

    3. Re:Trust by Pootie+Tang · · Score: 1

      Thawte now charges $125 initially and $100 renewal (compared to $349/$249 from verisign). I got no response to an email I sent, but I'd probably use them again anyway.

    4. Re:Trust by XorNand · · Score: 1


      umm... Verisign owns Thawte; they just don't like advertise it. ;-)

      My two cents... I am a Thawte reseller and have had problems with their service on every single one. They take at least two weeks to get the cert issued (I had one that took a month) and are very unresponsive to emails.

      The conspiracy nut in me thinks that this is intentional in order to drive people to Verisign, when they sell the same cert for twice as much.

      --
      Entrepreneur : (noun), French for "unemployed"
    5. Re:Trust by zerocool^ · · Score: 2

      Really? We've had good luck with the time aspect. Their tech support isn't incredibly responsive, but I just thought that's cause they're (supposedly) in south africa or something and on a different sleep schedule.

      Hrm.. My thought on the matter is that if you're going to get bad support from verisign and about the same from somewhere else, ocham's economic razor - all else being equal, choose the cheaper one. Is verisign's support that much better for certs than it is for domains? I've delt with them for domains and it's horrid.

      ~Will

      --
      sig?
    6. Re:Trust by slayer99 · · Score: 1


      I got so fed up with Verisign that I simply don't bother with signed certs anymore for most applications.

      A self-signed certificate is as secure, if not more so (remember the compromised root certificates fiasco?), than a Verisign signed one.

      Besides, who do I trust more? Myself, or some money grabbing US company?

      --
      Martin Brooks / Slayer99 #linux / UIN 2178117
    7. Re:Trust by jeremyp · · Score: 2

      I can't bring myself to believe that a wildcard cert could possibly be a good idea. If my browser accepted them, I think I'd be looking for the option to turn them off.

      --
      All I want is a secure system where it's easy to do anything I want. Is that too much to ask ~~ Randall Munroe
    8. Re:Trust by zerocool^ · · Score: 2

      I don't think it would be such a bad idea. It would save you from having to buy a different cert, not only for different machines (we're about to buy one for homer.netmar.com), but also aliases - as in www.netmar.com and netmar.com don't need a different cert.

      You'd still have to have the default.key and default.cert, and as long as you held on to them, you wouldn't have problems. Obviously, you wouldn't let your dedicated server clients have access to it, even though they have a primary hostname of company.netmar.com. But having the wildcard would mean that I wouldn't have to buy 3 certs for netmar.com, www.netmar.com, and homer.netmar.com. It would just be easier.

      What do you see as the security risk? If they're only on our shared servers, and only we have access to httpd.conf, I'm missing how it could be used against us.

      Not that it's not a moot point, they're not supported in I.E., so we're not doing it.

      ~Will

      --
      sig?
    9. Re:Trust by flonker · · Score: 1

      FYI, Verisign is in South Africa.

  28. "Harvesting" isn't the best term to call this... by Nick+Driver · · Score: 1

    My interpretation: Comodo is harvesting contact information from certificates in bad faith

    The term "harvesting" seems to imply that they did honest work (like a farmer) to get to the position where they could then reap the rewards. May I suggest that the term "strip mining" might be more accurately descriptive of what's going on here?

  29. We need beneficiary oriented spam laws by Animats · · Score: 4, Interesting

    It's becoming clear that we need spam laws which provide for a penalty against the beneficiary of a spam, even if they did not originate it. An acceptable defense would be that the beneficiary had taken legal action against the spammer. That would make third-party spam actionable. (It may be, anyway, but it's a bigger legal battle under current law. I've been talking to an an anti-spam lawyer, and he's unwilling to take on Verisign because they have too much money.)

    1. Re:We need beneficiary oriented spam laws by Anonymous Coward · · Score: 1, Insightful

      How? If any of a number of spammers joe-jobs my site or my resume to a few million people (because I complained to their ISP about spamming me) through an open relay in East Fnordistan with no logs, what sort of "legal action" against an untraceable sender would establish that I didn't consent to the spamvertising? What if I can't afford a lawyer?

    2. Re:We need beneficiary oriented spam laws by SN74S181 · · Score: 1

      The problem with what you propose:

      I find an open relay and send out 300,000 spam advertisements claiming to come from Red Hat Linux. I am not affiliated with Red Hat Linux, in fact I actively oppose them as a company. This is the whole reason I sent out the spam.

      Red Hat Linux is forced to absorb a penalty for my actions?

    3. Re:We need beneficiary oriented spam laws by Anonymous Coward · · Score: 0
      It's becoming clear that we need spam laws which provide for a penalty against the beneficiary of a spam, even if they did not originate it.

      Nah. We need harsh punishment for sending out spam, and international treaties to enforce this. Any country who does not ratify the anti-spam treaty, violates it or does not bring spammers to justice shall be immediately disconnected from the Internet. within two weeks. Circumvention of this disconnection shall afterwards be considered an act of global information warfare and make the entire government of that country personally responsible. The UN should then be obliged to send an expedition force into the country to capture the culprits.

      Really, I am SO tired of spam. Make it stop already, I care not how :-(

  30. nice. by Rev.LoveJoy · · Score: 2
    Wow.

    So Mr. Coward worked for VeriSign? This explains the penis bird and the goat trolling.

    - RLJ

  31. Re:"Harvesting" isn't the best term to call this.. by silentbozo · · Score: 3, Informative

    I personally like the term "poaching" when referring to these types of practices. Strip mining is nasty, but not necessarily illegal (though it should be.) Poaching, by the very definition is:
    To take or appropriate something unfairly or illegally.
    I can't think of a better way of describing this type of information THEFT, for the gain of the THIEF.

  32. This has been going on for a while... by maikeru · · Score: 0

    I got similar notices from Verisign for domain names as far back as a year ago. Of course, Verisign/NSI sucked anyway, so I had no qualms with immediately changing my service.

  33. Re:"Harvesting" isn't the best term to call this.. by Nick+Driver · · Score: 1

    That'll work.

  34. whats public infor whats not by linuxislandsucks · · Score: 2, Interesting

    Correct me if I am wrong but

    Registar information was ruled as non public..ie you cannot use for mass mailings through postal office, mass caling telemarketing, and mass emailing..

    Would not cert information be on the same plane?

    --
    Don't Tread on OpenSource
  35. OT: Your Sig by Amazing+Quantum+Man · · Score: 1

    Who died and made ICANN boss?

    Jon Postel, who is probably spinning in his grave.

    Note to moderators: Self modded down (no score +1) as OT.

    --
    Fascism starts when the efficiency of the government becomes more important than the rights of the people.
  36. pbtttthhhhh by phriedom · · Score: 1

    I'm disappointed that CNN doesn't even list the names it asserts are confusingly similar to corporate websites. But I have to think that the confusing similarity shouldn't matter in this case. IMHO, this IS a free speech issue, as I think that this man's political commentary that relates directly to the domain names in question SHOULD be considered a valid interest in the domain name.

    --
    Don't moderate flamebait as Troll. Know the difference or you will be Meta-moderated.
    1. Re:pbtttthhhhh by Anonymous Coward · · Score: 0
      It does. Clearly. Read the damn article.

      bloodycocacola.com and pepsiatthemills.com. Taken down already of course.

  37. That "renewal notices" link... by errxn · · Score: 2, Funny

    They went to all the trouble to blur out the customer's address and items on the invoice, and then missed his info in smaller print, just plain as day.

    I wonder how this guy feels about that:
    Scott Rogers
    Cape Cod Computer Wholesalers
    P.O. Box 2842
    Orleans, MA 02653-6842


    Dumbasses.

    --
    In Soviet Russia, Chuck Norris will still kick your ass.
    1. Re:That "renewal notices" link... by Anonymous Coward · · Score: 0

      I'm, sure he'll appreciate you pointing that out...

  38. Re:"Harvesting" isn't the best term to call this.. by newt_sd · · Score: 1

    I prefer goatse"ing" the general public

    --
    ***I GOT NUTHIN***
  39. "Equifax" was not "bought out" by g051051 · · Score: 2, Insightful

    Just to clarify, Equifax sold just the small part of its business that was concerned with certificate management to GeoTrust. Equifax is still an independent company with lots of other businesses. (Yes, I work for Equifax).

  40. So can I use my list of UUnet customers? by Skapare · · Score: 2

    So can I use my list of UUnet customers to market to them network connectivity from a company not entering into bankruptcy? It is public information.

    --
    now we need to go OSS in diesel cars
    1. Re:So can I use my list of UUnet customers? by Anonymous Coward · · Score: 0

      As long as you don't have an agreement with UUNet not to, sure.
      Chances are though, you obtained that list from UUNet/WHOIS/whatever under some agreement not to sell, spam or send marketing info to them.

  41. nitpicking by Anonymous Coward · · Score: 0

    I work for Equifax and we did not get bought out by GeoTrust. just the certificate business.

  42. Speaking of Verisign by Anonymous Coward · · Score: 0

    Here's snippets from a renewal notice I got. I've never seen a more ridiculous abuse of domain registrations. I've got other emails from them that have even more domain names being used this way - it's like they're trying to encourage you to register a unique domain for every page on your site..

    --
    TO RENEW SERVICES
    Renew your domain name and other VeriSign Web Services now - it's fast and easy to do: ...

    Go to www.VSSavings.com and enter your domain name. ...

    Go to www.5DaysToRenew.com and enter your account number/login number and password*. ...

    TO UPDATE YOUR ACCOUNT
    Visit www.verisignaccount.info to update your address, view services and verify payments made. You will need the following to access your account: ...

    Your account/login number - listed above
    Your password. If you don't have your password, go to www.verisignpassword.info or call Customer Service at 1-866-847-2282. ...

    You can read our comprehensive Service Agreement at www.verisignagreement.info. ...

    Please do not reply to this message. For any VeriSign Customer Service inquiries, please e-mail us through the following link: www.contactverisign.com. Any replies to this message, other than unsubscribe requests, will not receive a response.

  43. No switch mentioned. by uberdave · · Score: 2, Insightful
    There is no deception here. It's a simple advertisement asking you to switch.

    The words renew, remind, upgrade, and expire (or variants thereof) occur 15 times

    The words switch, transfer, move (or variants) do not occur.

    The word new does occur once, but in relation to the certificate, not the issuer.
    1. Re:No switch mentioned. by Reality+Master+101 · · Score: 2

      So what? There are only two questions:

      Is there any possibility of misinterpreting this e-mail? The answer is no.

      Is there any evidence for deception here? The answer is no.

      --
      Sometimes it's best to just let stupid people be stupid.
    2. Re:No switch mentioned. by Anonymous Coward · · Score: 0

      Clearly the answers must be yes, because the submitter admitted to being deceived by this message. Describing a change in vendors as a "renewal" is obviously fraudulent--if they'd called it a "competitive upgrade" or something, arguably the reader should have known what they're offering.

    3. Re:No switch mentioned. by lobsterGun · · Score: 1

      The guy that misinterpreted this email is a moron and didn't read the email carefully.

      He made a big deal about it and now everyone is standing around nodding their heads all thinking, "I can see how he would think that. Lets fuck those Comodo bastards up." It's the mob mentality in a major way....but I suppose that is to be expected here.

      I think that pretty much sums it up.

      -- the above is just the opinion of a simple groundling, pay no attention.

    4. Re:No switch mentioned. by arkanes · · Score: 1, Flamebait

      what an amazingly moronic statement. At least 1 person was, in fact, confused, the story poster. Now, you can rant about how it'll only confuse stupid people, who deserve it, but the fact is that it CAN confuse people and in fact HAS confused people. As a previous poster said, it's alot easier to read an article about a scam and then post about how obvious the letter is, than to realize it's a scam when it never once explicitly states that it's a new service, and it's coming at just the same time as your existing provider is changing names.

  44. Obfuscation by obscurity by Darth_brooks · · Score: 3, Insightful

    "We have no relationship with Equifax or GeoTrust. The information on a certificate is public information which we have used to inform this company that they have an option when they come to buy their certificate."

    They aren't trying to 'inform', they're hard selling, in bad faith. They're misleading consumers into thinking there is no alternative. It's opportunistic, and pretty close to criminal.

    An insurance company sends a "reminder" about homeowner insurance renewal, using information publicly available in some states (usually loan information).

    I get notices from insurance agencies, credit card companies and any number of other bulk mailers. The difference is, they are out in the open about wanting to sell me a product i don't have, or informing me i have an alternative to the products i may already be using.

    These companies are playing dumb. "aww shucks, you mean folks didn't realize they didn't HAVE to re-up with us? well, gosh golly, i guess we'll be more careful next time." A mailing could just as easily be sent out that says "we noticed that your domain name / cert is about to expire. Please consider us as an alternative when you renew." That'd be a company hawking their wares. What they're doing now is a clearly deceptive business practice. Slamming just happens to be the closest description.

    --
    There are some people that if they don't know, you can't tell 'em.
    1. Re:Obfuscation by obscurity by TheMidget · · Score: 2, Insightful
      They aren't trying to 'inform', they're hard selling, in bad faith.

      Doesn't look like this to me. Just look at the following sentence of their e-mail:

      Before you renew please read the following important information from Comodo.

      To me, this looks like they aren't pretending to renew the certificate (prolonging the service with the same company), but rather proposing an alternative (i.e. switching companies). If they were pretending to be the same company they'd have said something like "Please read the following important information from Comodo for instructions on renewing your certificate". And they would also avoid naming two different companies (Equifax and Comodo) in the mail. Indeed, why mention the customer's existing supplier (Equifax) if you attempt to make the customer believe that he is already with you (Comodo)? To me this doesn't look like deception, but merely like the over-reaction from the customer, who wrongly assumes that all businesses are as sleazy as Verisign or those toner companies.

    2. Re:Obfuscation by obscurity by drudd · · Score: 2

      The problem with that argument is that the actual company you have a business relationship could also use that language if they want you to switch "plans".

      Couple that with the use of the term "upgrade" and it sounds very much like a sales pitch from your current company to get something with a few more perks on your next cycle.

      Doug

      --
      Venn ist das nurnstuck git und Slotermeyer? Ya! Beigerhund das oder die Flipperwaldt gersput!
  45. Equifax Bought Out? NOT by john_roth · · Score: 2, Informative

    I was kind of surprised to see this assertion. So I did a little due dilligence (I looked at the web sites of both parties). Nothing whatsoever in their press releases. I finally found it here http://www.equifax.com/DigitalCertificates/dc_pres s09252001.html Equifax sold their SSL Certificate business, not anything else, close to a year ago... They're still the same credit reporting, marketing and so forth company they've always been.

  46. Agree. Spam, but not "slamming" or a big deal. by Sean+Clifford · · Score: 3, Informative
    I think they are offering a product whose name is confusing similar to a GeoTrust's product. The language in their e-mail does everything possible to obfuscate the fact that they are not affiliated with Equifax, encouraging customers to "renew" and "upgrade" their certificates.

    IANAL. Now, of course you have to consider that it's up to a court to determine whether a servicemark or trademark is being infringed upon, but "confusingly similar" certainly meets the standard for infringement. However, the special sauce got a different reading than I did - no doubt coloured by the fact that Comodo [brings visions of flushing to mind] spammed his customers for competing (and probably lame) products. I'd be pissed too.

    However, my reading of the spam was that it's pretty straightforward. There's obsfucation, but it's arguable that they consider their product an "upgrade" in much the same way Microsoft salesdrones consider W2K Server an "upgrade" to your favorite Unix/Linux distro. Companies often offer "renewals" or "competitive upgrades" to entice users to switch from Brand X.

    IMHO, what Verisign has done in its spam "renewal" campaign is fraudulent. In a related anecdote, I've found it next to impossible to move my domains to another registrar; hell, I've had problems just moving them between hosting services.

    But, back to the topic, Comodo [flush] ain't slamming, I've experienced that joy on two occasions. BellSouth got a new Access app that had a *required* a selection from a lookup table of long distance providers. The default at the time was AT&T. I went from *no long distance* (I *PAID* a monthly fee for disabling long distance. Not that it mattered, because BellSouth was perfectly happy to sign me up with AT&T for my non-existent long-distance service at a $15 a month fee. I still haven't found out how much they got for it, but after repeated phone calls and legal threats I enjoyed 8 months of free local phone service to settle the matter. Of course, that was after about 8 weeks of haranguing dozens of people - your mileage may vary.

    Second was when I ordered DirecTV DSL for one of my company's East Texas offices. As in most places, the local Bell does the actual activation - molasses slow for competitors' customers, blazing quick (in comparison) for Bell customers. But I signed up for DirecTV DSL and SouthWestern Bell *canceled* that work order, telling DirecTV DSL that we'd already signed up with SouthWestern Bell; a blatant lie. Still dealing with that one.

  47. Wha...? by phyxeld · · Score: 2
    The supposedly deceptive letter linked doesn't seem too deceptive to me. To quote:
    So why not upgrade your Certificate with Comodo and join our many customers,
    including the US Government and some of the world's largest organisations.
    This is obnoxious spam, but it's not nearly as bad as it's being made to sound.
    --
    __
    Choose mnemonic identifiers. If you can't remember what mnemonic means, you've got a problem. - Larry Wall
  48. Versign by Anonymous Coward · · Score: 0

    I'd just like to say that versign blows ass worse than a 386 Packard Bell computer.

  49. Certs and DRM by philkerr · · Score: 1
    So look forward a few years when there's a possibility that you'll need a cert, or at least verification of your cert, in order to view/listen/watch something on your DRM enabled PC.

    Given the tactics in the story do you want to trust access to media that you own to companies that will screw each other (and us) as part of normal business practice?

    Cheers

    Phil

  50. "Tortious interference" by Mudcathi · · Score: 3, Informative
    In the mundane world of brick-and-mortar business, it's been my experience that sales activities sometimes go into a legal no-no land known as "tortious interference" -- specifically, interference with an existing client/vendor relationship that is based on a written contract.

    My attorney told me that if a contract exists, and I become aware that a competitor is trying to win my customer's business *prior* to the expiration of the contract between me & my customer, then the competitor can be sued for damages due to "tortious interference"...

    Most of the time, the competitor would back off until the contract was within 3 months or so of expiring. There were a couple of times, though, that we went to court - & got money both times for damages (customer for breach of contract, competitor for "TI").

    So how is this situation different from VeriSign, et al, slamming domain registrations? Why aren't the lawyers having a field day with this? Or are they, & I just missed the cloobus?

    --

    "He who throws mud, loses ground." - proverb

  51. Common problem everywhere by mccare · · Score: 1

    I guess you can complain as loud as you want, but there is no solution to people, trying to make money off "uneducated" customers/people. They will find a way. When founding a company in Germany, you will receive official looking letters asking you to pay a lot of euros to get listed in some register. At the 3rd look, they are scams. The bigger the company the more likely someone is going to pay these fees just be on the secure side (before your founding was illegal because you weren't listed?)
    I was in the same situation, and I'd like to have these companies sued, but they are stepping on a very fine, almost legal, but not 100% illegal line. And to be honest, for me it is easier to ignore and trash those scams than trying to fight someone in court.

  52. I got one... by Anonymous Coward · · Score: 0

    ...it claimed one of my domains was urgently due for renewal. This was four months ahead of the expiration date. These outfits are scum...plain & simple. I'm inclined to stop using dedicated domains altogether. I've been using the free dynamic domain/ip sites (register and create a psuedo domain with their tag, and then an app on your computer updates the ip. for weeks now, and they seem to work fine so far.

  53. It happens all the time... by Anonymous Coward · · Score: 0

    Bah, AAA the auto people recently sent out a pay 75 dollars or my service would be canceled. I dont have nor never will have AAA. What I do have is a garbage company called AAA Rainbow. In checking with my neigbhbors most of them recieved the same exact statement. Written to look like a bill. This practice is becoming all to frequent. They call it marketing, I call it fraud.

    If it doesnt stop soon Im gonna have to think of a scam like this so I can have my american dream too. Hrmm. Maybe ill bill all the advertising companys for cpu and video cycles. There using my hardware. If i do it right they wont even notice.

  54. Re:Certs? by FunkSoulBrother · · Score: 1

    Not at all. Certs are just as good as if not better then Altoids. You just think Altoids are better cause they've run an ad campaign to make themselves out a independent, non-corporate, alternative breath mint.

    Its not unlike people who thought their converse shoes and sketchers less corporate and more independent than Nike and Adidas.

    So eat some fucking certs. They're good.

  55. Identity Verification by pjrc · · Score: 5, Funny
    It's kind of ironic that the whole point of a SSL cert is to establish your site's true identity to the browser (where most users are not even aware of the certificate, the one true way that can tell who is going to receive their confidential information).

    And here we have a certificate authority (CA) who's masquerading as a competitor, in order to slam "subscribers" and certify their identity to end users.

  56. Re:Certs? by Anonymous Coward · · Score: 0
    No way! Altoids are the best. I never liked Certs much.

    All your Altoids are belong to us

  57. Leave Interland by Anonymous Coward · · Score: 1, Informative
    Interland are a bunch of crooks anyway. They'll switch you to automatic draft billing without warning, and e-mail you "urgent warnings" about registering your domains under .biz and .info tlds, with them, naturally, and at exorbitant prices.

    Check this out, for even worse: We were with them for years until earlier this year, after they merged with Micron. Our Miva merchant store (which our business is based on) started acting up and they, with no warning, shut our site down and referred it to their abuse department, over what turned out to be a server misconfiguration on their part. I found this out through user complaints that the site was unavailable. When I called Interland (after the requisite 45 minute hold time), I was told that the abuse department, the only one that could reinstate our site, had no phone. Yes, read that part again. So, we immediately moved to another host. The abuse department responded to my 25 emails 6 weeks later. Thanks, guys! Sorry I had to AC this, but my handle's my real name and, surprise, we're going to sue the crap out of them.

  58. Deceptive... I don't think so. by Anonymous Coward · · Score: 0

    The Interland notice CLEARLY states that you are authorizing them to switch your current registration; anybody who reads the text of the form will know that, it's not even fine print.

    If the people who received the notice failed to read it before sending their money in, they deserve what they get.

    Besides that, who the heck isn't aware of who their registrar is anyway.

    Abdul

  59. MOD PARENT UP PLEASE by chipotle_pickle · · Score: 1

    Equifax is a huge profitable multinational. Certificate mananagement could not have accounted for 1% of its revenue. For GeoTrust to buy out Equifax would be like WorldCom to buy out MCI. Wait, ... bad example, but EFX has not been bought out. If they dropped out of the certificates business, that was not important enough to make it to their press releases.

    No I don't work for EFX.

  60. Not SLAMMING by Anonymous Coward · · Score: 0

    Did the term originate in 1989?

    I remember being a victim of the long distance slamming. Only what they did was put their service on your bill without your consent or notice. At least here, they bother sending you an ad, and would need to get some feedback before they can actually charge you. In the phone slamming days, you just got the bill. Lots of
    people paid it for months or years because they didn't realize it.

  61. LURN TOO SPEL 8====D HEADS by Anonymous Coward · · Score: 0

  62. So can you not read or is it something else? by shiznit · · Score: 1

    You obviously did not even attempt to read it before you signed it. First off the Interland one... Near the bottom right below where you sign your name taking up a good chunk of the mailing, in a font larger than most on the mailing it clearly states that "By signing this order form you agree that Interland Inc. will process the indicated multi-year renewal for your domain name registration through VeriSign." and here is the good part you moron "You agree that this transaction will cause your registrar to be changed to VeriSign." OMG!! Right there in plain view in a font larger than your IQ, It says your switching registrars!

    The one from Comodo also states that there with be a switch in service provider ("So why not upgrade your Certificate with Comodo and join our many customers") had you taken the time to read it. However if you want I can send you a nice letter about the renewing the ownership of your house and automobile perhaps I will get lucky and you will just sign those away also.

  63. WTF? sumbags by colenski · · Score: 1

    Does it bother anyone else but me that Equifax is also the fuckwadding scumbags that have a say in my credit rating???

    1. Re:WTF? sumbags by WickerChap · · Score: 2, Insightful

      Equifax should have no hand in your credit rating. They collate the information about your credit HISTORY and let finance companies access that data to score you on how high a risk you are. If your credit history sucks, you caused it. If it is wrong, challenge it. All "credit agencies" have a legal obligation to correct the information, if it is brought to their attention as incorrect.

      --
      "I love deadlines. I love the wooshing sound they make as they fly past" Douglas N Adams
  64. The Most Effective Remedy for this by serutan · · Score: 2

    If you currently have any domains registered by Verisign, immediately change to a different registrant and notify Verisign's customer service department as to exactly why you are doing it. Don't just threaten to do it, really do it. Even if you can't get a refund and have to shell out another $20 to somebody else, even if Verisign offers you incentives not to leave. Leave. And unless it makes you feel better don't waste your time crafting an eloquent manifesto, because they don't care about you or your moral arguments. They care about your money. Be clear, be blunt, and just take your business elsewhere.

    1. Re:The Most Effective Remedy for this by Ioldanach · · Score: 2
      If you currently have any domains registered by Verisign, immediately change to a different registrant and notify Verisign's customer service department as to exactly why you are doing it.

      But first, before you do that, you should read the article so you know that verisign was mentioned because it tried something similar with domain names, and is not involved in this at all. The company actually causing grief here is Comodo. (Though why anyone would name their company so close to commode I don't know. I'd feel like I was flushing money down the toilet everytime I dealt with them.)

  65. I don't see it. by z84976 · · Score: 2

    Did you read the email? Sorry, I guess this would certainly qualify as a "company I don't want to do business with" but they plainly state that they are Comodo, and offer a supposedly better service/deal than you're getting now, etc. Shady, maybe, but you'd have to be a complete idiot (and hence maybe not the best network admin) to be fooled for even a second. It plainly states the company name "Comodo" many times. "Upgrade to Comodo's product" implies, to me, switching vendors.

    Given that it's obviously a sales email from a company with whom i do not do business, I would file it immediately in the spam bin, no further thought required. But I see no fraud.

    1. Re:I don't see it. by Anonymous Coward · · Score: 0

      I do not even see SPAM in this.
      It is just proposing a new certitficate that you will need to upgrade in a few days because it will expire anyway. So it is not large scale mailing, and it might even really interest the client to know that he can get his cert for cheaper.
      I had the idea to do exactly the same a few years ago in an other public CA but they refused because they where affraid and if they would have done it, they might be second public CA after Verisign/Thawte.
      I think that the guy that sent this to /. is not completly honnest or really stupid.

  66. This is silly. by NetMasta10bt · · Score: 1

    Anyone who has registered a domain name, should have enough competency to understand who is sending email to them to deem it as 'official'.

    Someone that enters into contracts with companies in a field that is as technical as computing should know a thing or two about how the Internet works.

    If this was a company employee that did this, I would say that they didn't know what they were doing and they need to find another job.

    If this was a private individual doing it, It would be like somone trying to build a bomb from instructions they found on the Internet, and it blowing up in their face.

    And in this case, the builder would try to sue Bob, and lose horribly.

  67. Ver$ign/NetworkSolutions... by Digiover · · Score: 2, Interesting

    We used to use Veri$ign/NetworkSolutions as our Registar, but due to too many problems (changing freeforms/faxforms, parking domainnames for no reason, fscked up database[*], and so on) we are moving all our domains to Tucows/OpenSRS and BulkRegister (trust me, we are not the only hosting provider in NL who does this).

    It also looks to me as if Veri$ign/NetworkSolution has made a pact with NameZero, since every domain which we host and has been registered through NameZero has become "parked" at NetworkSolutions.
    This can be very irritating for our customers (help! my domain doesn't work!), and the worst thing is that they never notify anyone about this (it's even worst because I get all these customers on the phone ;(.

    [*] A simple domaintransfer could take 3 months, only because Veri$ign/NetworkSolutions couldn't find the domain in it's database.

    In my personal opinion: Don't do business with Ver$ign/NetworkSolutions.

  68. Hardly objectionable at all. by SecurityGuy · · Score: 2
    I don't see the problem here. I read the email (did you?) and it looked clearly to be a solicitation from Comodo to leave their current CA and join them.


    So why not upgrade your Certificate with Comodo and join our many customers,
    including the US Government and some of the world's largest organisations.
    Yes, join our many customers. That's clearly a "You're not one now, but we'd like you to be!"

    We are so confident that you will be satisfied with our products and service
    that we offer as standard, a 30 day money back guarantee.


    Does this sound like any company you currently do business with? Most companies I do business with sound like this when you're not a customer. Once you're a customer, it's "Here's your bill for next year."

    Move along, nothing to see. This is nothing more than a solicitation for business and an oversensitive recipient. There are enough valid targets for our annoyance with corporate lack of ethics without targeting a company which did nothing more than find people whose certs are expiring and let them know they have a choice.

  69. SSL is such a joke by Anonymous Coward · · Score: 0
    Someone ought to start a "faith based" organization that worships the cert companies, so they can get money from Bush.

    The whole thing is a fucking scam. How can anyone trust a faceless corporation who has no regard for their own reputation? Trust and reputation are what certs are all about! That's the whole point of them! ARGH!! (Oops, better watch them blood vessels..)

    Zimmerman had the right idea. Webs of trust, with people taking personal responsibility for themselves and knowing the basis for their own trust judgements. You know what? It's a pain in the ass. But it's also the only approach that actually means anything. The alternative, blind faith in unresponsive unaccountable unshamable spamming faceless inhuman entities, is really way out there. The next time you buy a cert from one of these guys, maybe you should also ask the helpful Scientologists about their free personality test.

  70. National Crime Squad UK by Martin+S. · · Score: 2


    If you believe this is fraud and/or computer crime committed by a UK individual or company you can report it here:

    http://www.nationalcrimesquad.police.uk/nhtuc/nh tc u.html

  71. This comes under UK law not US: It is illegal by SomethingOrOther · · Score: 2

    The problem is though, that to date there is no law against it.

    Maybe not in the US, but as they are based in the UK I'm sure this would come under decpetive marketing.

    I'd report them to the UK Trading Standards.

    (Miss representing yourself and products like that is very illegal. Quite a few of the electricity commpanies have been fined in the UK for deciving customers to sign for information, but in reality changing there electricity suplier)

    --
    Anyone quoted by a reporter knows how little they understand
    Don't believe what you read is the truth.
  72. Re: Cert spamming... by SnapShot · · Score: 1

    I've received a snail/junk mail advertisement (which looked very official) asking me to "renew" my domain registratiosn. In the small fine print it was made somewhat clear that this wasn't, in fact, a renewal but a completly different company wanting me to switch registration. I think it is sleazy and I'm certain many people have fallen victim to the add.

    Slightly off topic, but along a similar vein, every magazine I have a subscribtion to asks me to renew my subscription about 3 months after I've renewed for the previous year. A friend of mine's father who has Parkinsons ended up with 6 years of advance subscription to Discover magazine because every time they sent out a new notice he'd send in a check since he really couldn't remember when he sent in the last check. Legal, I suppose, but very sleazy.

    --
    Waltz, nymph, for quick jigs vex Bud.
  73. [OT] "Barbie Girl" by Shimbo · · Score: 1

    I see Barbie's having a bad hair day-
    "Barbie Girl" is protected free speech.

  74. I think Dogbert had the right idea on this. by PhxBlue · · Score: 2

    Companies of the future will mix astronomical names with technical jargon: for instance, "Uranus-Hertz."

    --
    !#@%*)anks for hanging up the phone, dear.
    1. Re:I think Dogbert had the right idea on this. by Anonymous Coward · · Score: 0

      Even better. Imagine if this company:

      Fuchs Lubricants

      Merged with:

      Butz-Hacker Insurance

      We'd have "Fuchs-Butz-Hacker". Completely sick, but strangely compelling. Kind of like a car accident.

  75. Comodo's grasp of english. by Anonymous Coward · · Score: 0

    When you check out their $49 product
    here you will notice that DESIGNED is speeled "deisgned"..

    Would you buy an SSL certificate from a company so unprofessional it can't be bothered to spell check their site?

    1. Re:Comodo's grasp of english. by the_machine · · Score: 1
      When you check out their $49 product
      here [instantssl.com] you will notice that DESIGNED is speeled "deisgned"..

      Would you buy an SSL certificate from a company so unprofessional it can't be bothered to spell check their site?

      Would you read a post from an AC that can't be bothered to spell check their post?

    2. Re:Comodo's grasp of english. by Anonymous Coward · · Score: 0

      yes i would, because spelling doesnt matter in forums like this.

      get over it

  76. Junk Faxes by ansible · · Score: 2

    If you're receiving a lot of unsolicited advertising faxes, you may want to check out http://www.junkfax.org/ to see how to fight back.

  77. Re:FP by Anonymous Coward · · Score: 0

    I am gay!

    -klerck

  78. ...your sig by Anonymous Coward · · Score: 0

    My theory that the reason many Europeans hate Americans is because we care so little that they hate us

    Actually, it's because you're a bunch of arrogant wankers, for the most part.

    HTH, HAND, etc.

  79. Bare minimum for certs by UP_Minstrel · · Score: 1

    This is a reason for consideration of David Chaum's push for certs with the bare minimum information in them required by their usage.

    Email certs have email. (plus public key)
    SSL Certs have a hostname. (plus public key, etc)

    Any other information leads to data hijack operations.

  80. It's not just the Internet.... by Boss,+Pointy+Haired · · Score: 1

    The UK's utility companies use just as underhand tactics to get consumers to move their account to them :( One company in particular recently made a completely unrelated offer (nothing to do with Gas or Electricity), but hidden in the small print was a clause that said along the lines of "in signing up to this offer, I agree to move my Electricity supply contract to XXXXXXX".

    Home contents insurance companies send out extremely official looking documents that take on the appearance of a renewal notice, even though it's actually just junk mail.

    I've received a few of these, and anybody even just slightly off the ball (hangover?) could be duped into signing the form and sending it back.

    If it weren't for the libel risk, i'd love to start a website that named and shamed companies using these sort of trick tactics.