Slashdot Mirror


VeriSign Sued Over SiteFinder Service

dmehus writes "It was only a matter of time, the pundits said, and they were right. Popular Enterprises, LLC., an Orlando, Florida based cybersquatting so-called 'search services' company, has filed a lawsuit in Orlando federal court against VeriSign, Inc. over VeriSign's controversial SiteFinder 'service.' While PopularEnterprises has had a dodgy history of buying up thousands of expired domain names and redirecting them to its Netster.com commercial "search services" site, the lawsuit is most likely a good thing, as it provides one more avenue to pursue in getting VeriSign to terminate SiteFinder. According to the lawsuit, the company contends alleges antitrust violations, unfair competition and violations of the Deceptive and Unfair Trade Practices Act. It asks the court to order VeriSign to put a halt to the service. VeriSign spokesperson Brian O'Shaughnessy said the company has not yet seen the lawsuit and that it doesn't comment on pending litigation."

23 of 403 comments (clear)

  1. Nice tactic. by NightSpots · · Score: 5, Informative

    Anti-trust was one of the very few tactics I didn't hear discussed as possible ways to stop Verisign.

    Arguing that they get for free what other companies must pay for is probably one of the easier arguments for win, since it proves itself nearly by definition.

    I applaud the jackass who pays to abuse typos. At least they've finally proven their worth.

    1. Re:Nice tactic. by nocomment · · Score: 5, Informative

      Don't forget the petition!!! Go sign it.

      http://www.petitiononline.com/icanndns/

      --
      /* oops I accidentally made a comment, sorry */
      /* http://allyourbasearebelongto.us */
  2. Pert Peeve by QuantumSpritz · · Score: 5, Interesting

    Cybersquatting, though one of the great minor evils of the web, is damned hard to stop. I can't think of any way to regulate/legislate it without messing up the domain registration and transfer process for everyone else - though it would be nice to be able to buy domains BACK from these companies - I would imagine quie a few choice domains are in their hands. Nice to see a lawsuit taking on Verisign over this - even if it is a cybersquatter. I wonder if there's an intelligent way to reserve domain names for individuals and organizations which already have use for the name - maybe a form of 'prior branding' only better implemented...

  3. The pool by r_glen · · Score: 5, Funny

    OK guys, who had 3-5 days??

  4. and the IEFT now has an Internet-Draft by shostiru · · Score: 5, Informative
    which I just found, draft-main-typo-wcard-02. Worth a look, as is the IETF mailing list archive. They're definitely aware of the problem. I particularly like following paragraph from the Internet-Draft:
    An error response that only works correctly in one situation would be as bad as an SMTP server that ignored its input and always produced a fixed sequence of responses: it would work in the one situation it was designed to expect, but cause chaos whenever presented with any other situation.
    sounds like the Snubby Mail Rejector, hmm?
  5. another annoying 'feature' of sitefinder by ApheX · · Score: 5, Interesting

    My browsers - Firebird and IE both keep history for a few days. It used to be that when i accidentally typed something in and the domain could not be found that it wouldn't be in my history since it wouldn't resolve. Now - thanks to URL resolving my history is gradually starting to fill full of crap. So when im in a hurry and select something out of my history i sometimes end up getting a sitefinder page instead of what I was looking for. ARRRGH.

    Verisign Sucks. They always have and always will.

    --

    -
    aphex
    I Steal Music!
  6. Don't badmouth Netster too bad by Tyler+Eaves · · Score: 5, Informative

    Yes, it's semi-sleazy, but they don't cybersquat.

    Timeline:

    1997 or so: I registered tylereaves.com, mainly for use in e-mail

    2000: I let the domain lapse, not really using it, and tired of paying $40 a year or so for it (Hey, registering was expensive in '97!)

    200?: Netster becomes the owner of tylereaves.com

    2003: I nicely ask for it back.
    2003: I get my domain back. They didn't even charge me the trasnfer fees.

    --
    TODO: Something witty here...
  7. Technical defense against hijacked domains by ODBOL · · Score: 5, Informative

    This is a good time to look at Bob Frankston's dotDNS proposal for a layer of reliable but meaningless domain names. dotDNS lookups can be made self-verifiable using public-key signatures, but without the costly chain of trust required by DNSSEC methods. The validity of a dotDNS binding can be verified easily by the querier, without relying at all on the server that provided the putative binding.

    dotDNS does not solve the whole problem, since any layer that translates from humanly meaningful names to dotDNS names is still vulnerable to hijacking. But the reliable and verifiable name bindings in dotDNS will make it *much* easier to switch name-resolution services when we are dissatisfied with their policies.

    dotDNS is a cheap and immediately deployable positive step toward fixing the DNS mess, requiring no approval by any central agency. It's time for a visionary sponsor to step forward and just do it.

    --
    Mike O'Donnell http://people.cs.uchicago.edu/~odonnell/
  8. I'm not surprised... by Pan+T.+Hose · · Score: 5, Funny

    Their new ad campaign with naked women went too far in my opinion. They were basically asking to be sued. Didn't they think about the children?

    --
    Sincerely,
    Pan Tarhei Hosé, PhD.
    "Homo sum et cogito ergo odi profanum vulgus et libido."
  9. Electronic Communication Privacy Act by Anonymous Coward · · Score: 5, Interesting
    The Electronic Communication Privacy Act (ECPA) provides that "any person who intentionally intercepts, endeavors to intercept, or procures any other person to intercept or endeavor to intercept, any wire, oral, or electronic communication; . . .shall be punished as provided in subsection (4) or shall be subject to suit as provided in subsection (5).

    wherein, "intercept" means the aural or other acquisition of the contents of any wire, electronic, or oral communication through the use of any electronic, mechanical, or other device;

    The ECPA also provides that "In a civil action under this section, appropriate relief includes--(1) such preliminary and other equitable or declaratory relief as may be appropriate;(2) damages under subsection (c); and (3) a reasonable attorney's fee and other litigation costs reasonably incurred.

    Damages.--The court may assess as damages in a civil action under this section the sum of the actual damages suffered by the plaintiff and any profits made by the violator as a result of the violation, but in no case shall a person entitled to recover receive less than the sum of $1,000.

    Seems like a good case can be that emails to mistyped addresses are being intercepted by Verisign. Certainly, the emails where not intended to be sent to Verisign, and they appear to be collecting some information from the email (the from address).

  10. Verisign delusional by SnowWolf2003 · · Score: 5, Interesting

    In this article on on CNET O'Shaughnessy said "the service has been embraced by end users. "We've seen nothing but very positive results from the Internet community," he said. "Usage is extraordinary. Both individual users and enterprises are giving very positive feedback."

    So they are attributing a slashdotting, and a lot of media interest to people being positive about the service. I haven't seen one article, comment or anything that was even remotely positive. What are these guys on?

    He also claims they are fully compliant with every RFC. I don't see how this is possible, unless they have found some loophole.

  11. Re:Most ISPs have blocked it by shostiru · · Score: 5, Informative
    We (mid-sized midwestern ISP) had our main nameservers (tinydns and djbdns) patched by 2AM the night this mess started, using the patches we found here. By a few hours later, I'd kludged the BIND source myself on a couple of other machines to return NXDOMAIN for anything in all three of the /24 netblocks in AS30060 (it worked fine, at least until the ISC patch was released). AFAIK our customers never even noticed the wildcarding.

    If you work in an ISP or other network infrastructure company, you know first-hand the degree of astonishment and rage that Verisign's move elicited; the fallout (spam filtration, security, network monitoring, etc.) goes far beyond HTTP. I don't think any of us slept much that night ... it only took a few hours to restore normal DNS behaviour, the remaining ten or so I spent in shock with my jaw scraping the floor.

    I've dealt with Verisign before (try getting decent documentation on the cybercash application library!) and knew they were greedy and stupid, but I wasn't counting on raw, unfettered eeeeeevil.

  12. Re:Homesteading by jms · · Score: 5, Insightful

    Homesteading required that the homesteader develop and improve the property in order to receive title. You had to actually live on the land, and farm it, and build a house with a door and window, and after you had proved the land, you would receive title.

    Cybersquatters do no such thing. There's a difference between registering coffee.com to build a coffee site and registering www.coffee.com to resell it later. Cybersquatters are more akin to ticket scalpers than to homesteaders.

  13. Re:what the fuck? by IHateUniqueNicks · · Score: 5, Insightful

    Where have you been? Have you noticed the fact that it's important to be able to tell when a site doesn't exist? That this crap means typos can cripple most e-mail servers? That it invalidates a good section of the RFCs the Internet itself was based on???

    Wake up. If you want to find a site, you use Google. If you want to go to a non-existant one, you should damn well be told there's nothing there.

  14. Right... by Anonymous Coward · · Score: 5, Funny

    So if we're really lucky, just as the guilty verdict is being read, with the upper level management of both companies present...that asteroid that everyone said was going to destroy civilization twelve years from now, will crash in down on the courthouse, ionizing not only the leadership of both companies, but several ragged hordes of killer attack lawyers as well.

    Then when the press questions the astronomers on how their orbital calculations could have been so wrong, the astronomers (being the clever guys they are) will say, "but are calculations were right!" and then erupt in maniacal laughter.

    I for one welcome our new...[looks up at the sky]...never mind, I didn't start to say anything. Nope, nothing at all.

  15. Re:Give them a break, they just want more hit by Anonymous Coward · · Score: 5, Funny

    Awh come on now, we can do better than that! Use the built-in distro-standard apache benchmark tool! ab -n1000 -c100 sitefinder.verisign.com/ That will send out 100 requests at once, 10 times. Might want to increase that number.... Anyway, its a good way to test your bandwidth...

  16. Re:"Unfair advantage"? by Caled · · Score: 5, Insightful

    Verisign has just acquired more domain names than there are atoms in the universe. If Mountain View wanted them they'd have to pay more money than exists, whereas it only cost versign a line in their DNS records.

    This is clearly abuse of monopoly.

  17. Null space needs to remain null by mabu · · Score: 5, Insightful

    First off, the idea that Verisign can appropriate unregistered domains represents a huge conflict of interest with its management of the TLDs. Nobody should be able to reassign IPs for non-registered domains. This undermines the whole system, which has facilities to address this situation.

    The fact that ICANN didn't block this move is further evidence than this organization is totally useless and political.

    Along the same vein, I disagree with MS's misleading implementation of the IP-not-found error page to redirect users to their proprietary search engine.

    The Internet community should rally against any entity that seeks to appropriate undefined address space for their own gain.

    If Verisign is allowed to do this, what we're likely to see is each major ISP and browser manufacturer follow suit and hijack undefined space to promote their own systems.

    Imagine if you dialed a wrong number on the telephone and you got an advertisement for the phone company. What if local broadcasters bombarded all the unused frequency spectrum with their own promotions.

    This has less to do with Verisign than it does to protect the sanctity of null space.

    It makes me wonder if someone has a patent on silence yet?

  18. Re:Most ISPs have blocked it by Enigma+Deadsouls · · Score: 5, Funny

    the remaining ten or so I spent in shock with my jaw scraping the floor.

    Thats part of Verisigns new "Shock and Jaw" Campaign.

  19. Re:"Unfair advantage"? by bernywork · · Score: 5, Interesting

    This actually causes LARGE problems for people operating over VPN connections.

    What normally happens is this:

    People do a request for a site, e.g. intranet.internal.foo.org.

    The external DNS servers fail in that they don't come back with an answer, and then the client continues through its list of DNS servers until it gets to the internal servers where it gets an answer.

    What's happening now is that they ARE getting a good answer from the external servers, and the client is trying to connect to the 64.x.x.x address of Sitesearch. Now in most organisations the client isn't able to connect to that box (because its firewalled or whatever else), so it isn't a problem for VeriSign, however, it is a problem for the organisation, as the clients who are trying to work are getting given IP addresses for internal servers that are incorrect.

    I have had to change dial up settings on a few clients and change others over to using static IPs at the moment until a better solution comes around. Or even better till VeriSign stop doing this.

    Berny

    --
    Curiosity was framed; ignorance killed the cat. -- Author unknown
  20. Journalists should not write tech stories by flakac · · Score: 5, Funny

    From the article:

    Typically, Internet users are shown a generic "404 -- cannot be found" page when a Web address does not exist.

    Sooooo, if the web server can't be found, who's sending the HTTP 404 response (which incidentally means that a file on a server doesn't exist...)?

  21. maybe it's time to give DNS back to the public? by thomas_klopf · · Score: 5, Insightful

    When Verisign was given the authority to manage DNS for these TLDs, they were given this responsibility with the public trust.. The public trusted them NOT to do things exactly like this. You should do DNS, and that's it - nothing more, nothing less. In return, Verisign was given a source of income. I think that if Verisign continues in this way, it may be time to take back this thing entrusted to them. This has become yet another disaster in "privatization", and we should maybe consider moving this service back to the "public" sector (as much as it can be...).

  22. You need to reject their terms of use! by royles · · Score: 5, Interesting

    I have simply sent them an email and more importantly a 'letter' that informs Verisign that I do not accept their terms of service and that I am seeking their advice on how to stop making use of their software, considering I do not meet their terms of service.

    I have informed them that if they cannot stop providing me with this service, (for which I do not accept their terms, and by which I cannot be bound) then they will have to contact me to negotiate a new set of terms to which I do agree.

    I would imagine that if every user that is upset by this new 'service' was to do the same then Verisign would have to do 'something' about it.