Zorac (zorac) wrote,
Zorac
zorac

  • Mood:

VeriSign are Fucktards!

Gah! The evil scumbags who operate the .com and .net domains have decided to set up a wild-card DNS record for all non-existant domains. This means that sites like www.dygiehwlkgiuwekrf.com now exist, and take you to a nice little VeriSign plug page instead of a helpful error message telling you that the site does not exist.

Much worse is the effect this will have on email - checking for non-existent domains is a good way of blocking spam, and indeed just verifying email addresses. Also, as VeriSign are running a mail server that rejects all messages, old or incorrect MX records which previously be ignored will now cause all email to a domain to be bounced.

Update 1: Ooh! More fun! Any DNS blacklists (again popular for blocking spam) which no longer exist (eg orbs.dorkslayers.com) will now have sprung back into life listing every address on the internet - meaning more false positives in junk mail blockers.

Update 2: Here's a good article written a couple of hours after this started. There is, of course, much discussion on Slashdot, and an article on The Register (with quotes from my boss, alnitak). VeriSign's posting about it on NANOG can be found here, and there's apparently much backlash to be found there too.

Update 3: One other concern this raises is privacy/security - every mis-typed URL or email address that goes to a non-existant .com or .net domain will now hit VeriSign's servers - and their terms and conditions state that they will keep that information - what email addresses you were trying to send to and from, what websites you were trying to visit (including any form parameters, potentially including usernames and passwords). How nice.

Update 4: This doesn't just happen to un-registered domains - it also applies to domains which are paid for and owned by someone who just happens not to have st up any DNS servers for it. Leading to even further dubious legality.

WAY TO BREAK THE INTERNET!!!!!

Needless to say, large numbers of ISPs and the like will be looking to take their domain registration and SSL certificate business elsewhere.
Tags: internet, rant
Subscribe

  • Coming out of the WiP closet...

    Well, it seems that somebody has declared today to be WiP amnesty day, so I though it might be fun to join in, so here's my initial complete draft of…

  • Frivolous lawsuit of the day

    Gakked from a mailing list by alnitak. The typos are almost as amusing as the story itself. Made me chuckle at the dumbness of our…

  • Scrumping Branson's Blackberries

    Every year, Sir Richard Branson (he of Virgin fame) has an open garden in aid of charity. Every year, I mean to go along as his house is about…

  • Post a new comment

    Error

    Comments allowed for friends only

    Anonymous comments are disabled in this journal

    default userpic

    Your reply will be screened

    Your IP address will be recorded 

  • 8 comments