Slashdot Mirror


MySpace and GoDaddy Shut Down Security Site

Several readers wrote in with a CNET report that raises novel free-speech questions. MySpace asked GoDaddy to pull the plug on Seclists.org, a site run by Fyodor Vaskovich, the father of nmap. The site hosts a quarter million pages of mailing-list archives and the like. MySpace did not obtain a court order or, apparently, compose a DMCA takedown notice: it simply asked GoDaddy to remove a site that happened to archive a list of thousands of MySpace usernames and passwords, and GoDaddy complied. Fyodor says the takedown happened without prior notice. The site was unavailable for about seven hours until he found out what was happening and removed the offending posting. The CNET article concludes: "When asked if GoDaddy would remove the registration for a news site like CNET News.com, if a reader posted illegal information in a discussion forum and editors could not be immediately reached over a holiday, Jones replied: 'I don't know... It's a case-by-case basis.'"

12 of 344 comments (clear)

  1. Case-by-case basis... by 192939495969798999 · · Score: 4, Insightful

    in case it would be bad for our PR, then no, in case it would be good for our PR, then yes, we take the site down. /sarcasm?

    --
    stuff |
    1. Re:Case-by-case basis... by nmb3000 · · Score: 4, Insightful
      The problem is that whatever the cause, this was bad for GoDaddy's PR, and Slashdot users should let them know.

      I'd suggest that everyone here who is disgusted with this action, especially those who have domains registered with GoDaddy, email GoDaddy public relations and/or email their domain registration support.

      Just as an example, here is what I sent:

      Regarding the recent action GoDaddy took against Seclists.org, I want to know just *why* I should keep my domains at GoDaddy, and not transfer to somebody who shows some respect for their customers.

      I find it disgraceful that GoDaddy would bend over when somebody like MySpace pushes a little. How can I now know that my domains are safe from being shut down on a whim? By not following any meaningful procedure to resolve the conflict, you have caused myself and many others to loose any faith we had with you as a registrar.

      When my domains expire in a few months, I will be transferring them to another registrar unless GoDaddy publicly apologizes to Fyodor Vaskovich, the owner of Seclists.org. In addition, he should also receive some compensation for his trouble, such as a free three-year renewal for all his domains.

      See http://it.slashdot.org/article.pl?sid=07/01/26/154 2218 for more information and more customer responses.
      Maybe if they get hit hard enough, somebody over there--maybe even ol' Bobby Parsons (does anyone know his email address?)--will figure out that companies can't pull this kind of crap anymore without repercussions.
      --
      "What do you despise? By this are you truly known." --Princess Irulan, Manual of Muad'Dib
      /)
  2. Overkill by Kelson · · Score: 4, Insightful

    Let's see... one page out of 250,000 on a site turns out to have content that could compromise security at another site. So MySpace contacts the registrar, and gets the entire site shut down?

    That's like using a hand grenade to swat a fly.

    The logical way to go about this is as follows:

    1. Contact the site maintainer and convince them them to take the page down.
    2. If that fails, contact the hosting provider, and convince them to take the page down. (Just the page, not the whole site.)
    3. If that fails, and only then, contact the registrar and convince them to suspend the site.

    Myspace should not have even contacted GoDaddy until they took the first two steps. And once GoDaddy was contacted, they should have done more investigation, which would have made it clear that they were looking at one page out of a quarter million... at which point they should have either told MySpace to contact the host, or done it themselves.

    Even if, after all these steps, GoDaddy still decided to suspend the registration, they should have contacted him first: remove this page or we'll have to disable your site. Failing that, they should have told him why it was being suspended (beyond the vague reference to TOS abuse) and how he could resolve it.

    Disabling the entire site with (apparently) minimal investigation is overreaction, plain and simple. That quote from Jones, where they refused to rule out taking down an entire news site to block access to one story -- or even one comment -- is telling.

    1. Re:Overkill by DBCubix · · Score: 5, Insightful

      Let's post some usernames and passwords on MySpace and ask for their domain to be taken down. It only sounds fair.

      --
      I called it a mighty Sperm Whale, she called it Finding Nemo.
  3. Case by case basis by popo · · Score: 4, Insightful


    In other words, "We have no backbone. We obey power. You have none. MySpace does. Any questions?"

    --
    ------ The best brain training is now totally free : )
  4. Myspace is the new AOL by brennanw · · Score: 4, Insightful

    In the linked article Fyodor calls MySpace the "new AOL." I can see it. It certainly seems to encourage people to throw all caution to the wind.

    As to what MySpace did, I'm honestly surprised how incredibly angry that makes me. I thought I was jaded by the petulance of businesses at this point. And Godaddy's response -- geez. I don't understand how a business can take your money and then refuse to talk to you.

    Well, no -- I understand how they can do it. I understand it perfectly well. They do it because they figure they can get away with it, because even if they piss off one customer, how are the rest ever going to find out? Or care?

    --
    Eviscerati.Org: All Hail the Eviscerati
  5. domain registrar neutrality by Anonymous Coward · · Score: 4, Insightful

    Domain registrars should remain neutral in content disputes. Quis custodies ipsos custodes?

  6. Overkill is an understatement by A+beautiful+mind · · Score: 5, Insightful

    It should be downright bloody illegal to do what Godaddy did. Or if not illegal, it should have serious repecussions for them as a registrar up to the point of dropping their registrar status.

    Besides, Myspace's effort was entirely useless. Those usernames/passwords were already compromised, Fjodor's site was just one that had it from the many places it can be found. The sensible thing would have been a forced password reset for the users involved not trying to coerce a registrar.

    My position is that unless a legal, court ordered action is forced on the registrar, it should be forbidden to drop anything. And in the case there is content that shouldn't be public on the site, that is a _hosting_ issue not a domain issue. Go bugger the hosting company with legal documents.

    --
    It takes a man to suffer ignorance and smile
    Be yourself no matter what they say
  7. I see a giant drop in revenue for GoDaddy by CharlieHedlin · · Score: 4, Insightful

    I see a lot of slashdot readers pulling their domains to another registrar. I don't know if any are better, but at least there have to be some that haven't already taken these draconian messures.

    I have a few domains up for renewal, and was considering GoDaddy. Not any more. I am sure slashot readers must control the registration of several million domains.

    I hope this publicity shows as a giant drop on their revenue graph.

  8. joker.com or any non-us registrar. by Zurk · · Score: 4, Insightful

    people -- if you dont like the DMCA or U.S registrars instead of whining about it simply switch to joker.com (it switzerland) or ghandi (in france) or any of the non-U.S. based registrars out there. They will take your credit cards and a currency coversion is handled automatically. if you dont like it -- SWITCH. vote with your wallet. eventually U.S. based registrars WILL GET IT. SALES depts will kick their asses until they do.

  9. Re:GoDaddy Response by MooUK · · Score: 4, Insightful

    The last few sentences of this post can be summarised in a much clearer fashion:

    "Think of the children!"

  10. Re:GoDaddy Response by Fulcrum+of+Evil · · Score: 5, Insightful

    As we have said to our customers - Go Daddy is committed to keeping the Internet a safe place. If there is material online that is jeopardizing Internet safety, we will take necessary action. I

    That's not your damn job! You are a registrar. If you take it upon yourself to police the contents of the sites in your registry, what happens when you get sud for failing to do so? Go do your job and stop trying to police things that are none of your business.

    --
    "We returned the General to El Salvador, or maybe Guatemala, it's difficult to tell from 10,000 feet"