Slashdot Mirror


Domains May Disappear After Search

Ponca City, We Love You writes "Daily Domainer has a story alleging that there may be a leak that allows domain tasters to intercept, analyze and register your domain ideas in minutes. 'Every time you do a whois search with any service, you run a risk of losing your domain,' says one industry insider. ICANN's Security and Stability Advisory Committee (SSAC ) has not been able to find hard evidence of Domain Name Front Running but they have issued an advisory (pdf) for people to come forward with hard evidence it is happening. Here is how domain name research theft crimes can occur and some tips to avoiding being a victim."

12 of 379 comments (clear)

  1. never use the web for such queries by jacquesm · · Score: 4, Informative

    Always use a command line tool. The webservices are notorious for such sniffing, I've never seen or heard about it happening from the unix command line.
    Better still, simply use your registrar to do a registration, if that works then it was free :)

    http://rndpic.com/

    1. Re:never use the web for such queries by Pyrion · · Score: 5, Informative
      SysInternals (now Microsoft) has a whois CLI tool for Windows as well.

      http://technet.microsoft.com/en-us/sysinternals/bb897435.aspx

      --
      "There is much pleasure to be gained from useless knowledge." - Bertrand Russell.
  2. Data mining by karl.auerbach · · Score: 4, Informative

    It has long been rumored that domain name registries snap up names when they see signs of interest. Unfortunately ICANN's committees don't have the tools to really open up the clamshell and see what is really going on deep inside registries and registrars.

    However, there is another matter - that of data mining of the query packets that arrive at root and top level domain servers.

    ICANN's contracts do not prohibit data mining of the query stream, in fact they openly permit it. Thus Verisign has the right to look at incoming queries and generate a body of information about what domain names are being uttered by users. It's not a big step from that to come up with a list of names that would be nice things to have if one wants to spatter up a bunch of Google Adsense ads and collect click revenue.

    (Also, because the entire domain name, not just the top level parts, hits root and top level domain servers, through a bit of statistical reduction, one can produce a data stream that is of interest not only to paying marketeers but, perhaps, to certain national intelligence agencies.)

  3. Not a new trend. by palegray.net · · Score: 4, Informative

    I'll swear this has been happening for years. I've taken to the habit of not searching for a new domain until I'm ready to buy it, right then and there. In the past, I've seen cases where customers have searched for a domain, found it to be available, and by the time they had a meeting the next morning to discuss buying it have it be registered by someone else (usually a squatter). In a sense, it's just common sense that a lot of the domain search "services" would engage in a competitive practice like this. I'm not saying it's ethical, but it's been going on for a long time.

    Maybe the community can come up with a list of guaranteed reputable domain search services that take measures to prevent this sort of activity, and support those organizations.

  4. nope, they dont pay by asv108 · · Score: 4, Informative
    Amusing. Increase the scale of that operation a bit and you could quickly bankrupt a careless squatter.

    Actually most of bigger squatting operations don't pay a dime on a per name basis. They hold the name for 30 days, then release it at no cost.

  5. https://www.easywhois.com/ by Simon+Carr · · Score: 4, Informative
    I'm more than just not surprised by this, I've known it without proof for years. Doing queries for total junk domains, and then three or four days later finding out that those domains had been registered? Too weird. And that was years ago.


    One of the problems stem from the fact that any whois query can be sniffed (or SNORTed) if it passes over the wrong network hop anyway, so there isn't much you can do unless you're ready on the trigger to register the domain almost immediately. One thing you CAN do if you're going to do web queries (because not everybody has a whois command line installed) is query via;


    https://www.easywhois.com/


    Note httpS. I can certify that Mark J doesn't do domain tasting, that's not the business EasyDNS is in. So if you do do a query via EasyWhois it's not going to get snagged after 24 hours (at least not from our end).


    [ Disclaimer: Yeah I work for EasyDNS :) ]

    --
    -- The unsig...
  6. Comment removed by account_deleted · · Score: 4, Informative

    Comment removed based on user account deletion

  7. Re:This has been happening a long time by orclevegam · · Score: 4, Informative

    As some have pointed out it costs the squatter nothing. They have a loophole because many registrars allow a 30 day trial period on a domain in which you can have it and if you decide you don't want it you can get rid of it for no cost. The squatters can then play a shell game by having a set of dummy companies swap the domain between themselves without ever passing the 30 day mark. With only 3 companies a squatter could tie a domain up for just under 3 months, and never have to pay a penny.

    --
    Curiosity was framed, Ignorance killed the cat.
  8. Omg don't do that! by sakdoctor · · Score: 4, Informative

    From the page linked from TFA:

    "It is such a strong urge to type the domain name into the address bar and see what website comes up. Most users think perhaps there is already a company using the name and this will be a quick end to the question. Wrong! This is the most dangerous thing to do. Internet Service Providers (ISP) sell NXD (Non-eXistent Domain) data."

  9. Comment removed by account_deleted · · Score: 4, Informative

    Comment removed based on user account deletion

  10. Re:its actually pretty common by zyzko · · Score: 4, Informative

    Could you back that up? There are horror stories for every registrar, but GoDaddy is in my opinion one of the best of the cheap ones. Their customer support actually works (I have always got a response to email within 2 hours - Network Solutions has 12-24 hour answer time at best and they cost 5x as much as GoDaddy, not to mention their refusal policy to transfer domains to other registrars without phonecalls (I'm not living in the USA so the phonecalls to them are expensive international ones) just because they think transfer is "suspicious").

    Also - GoDaddy has a quite nice spam policy - which other cheap registrars often don't have and they actually do not care much because being too strict about spam would not give them income.

    joker.com would be nice because their web interface is clean and they don't try to sell you a kitchen sink with your domain, but their spam policy has at least in the past been non-existant.

  11. Re:its actually pretty common by Grey_14 · · Score: 4, Informative

    check out http://nodaddy.com/ for a few horror stories, Admittedly every business that gets past a certain size will have 'hate' sites against it, but yanking a domain name from Fyoder was a pretty bad idea :P