Verisign: the Ultimate in Typo-Squatting

September 16, 2003 2:48 PM

One reason Microsoft Internet Explorer annoys me is the typo feature. When you mistype a domain, rather than give you back an error-message, it redirects you to MSN's search site. I don't like this for two reasons: firstly it adds significantly to the time it takes to just correct the typo and load the right page. Secondly, it makes an annoying assumption at which search engine I might want to use. (Hint: it's not MSN)

This is one reason I try not to use MSIE. Mozilla throws up an error message when it can't find a domain, and makes it very easy for me to choose Google as my default search-engine.

Verisign, it seems, have the trump-card. By putting a wildcard DNS on '.net' and '.com', they are redirecting every single domain typo to their own search page. I can't even begin to describe how much this whole idea annoys me.

It's disreputable. I've always considered typo-squatting--the practise of registering domains that are similar to popular sites so as to get hits from typos--to be a pretty underhand tactic: something you'd expect from the second-hand car salesman school of marketing. Now Verisign are planning to typo-squat probably half the Internet.

It's technically reprehensible. It's breaking the DNS. In one fell swoop it removes the technical distinction between an unregistered domain and a registered domain. It's part of this stupid assumption that the whole Internet is just the World Wide Web with a few unimportant bits bolted on the side. So obviously it's OK to break a fundamental feature of the DNS just so that one company can exploit a few more web users.

It's vulnerable to cross-site scripting

It's an abuse of monopoly. If a web browser of an operating system plays this sort of trick, you can stop using it as I avoid MSIE. You can't avoid the DNS,1 and you can't just choose to go with some provider of the .com domain who isn't a scum-sucking bottom-feeder.2

The body that should slap Verisign down won't, of course. Verisign should be the caretaker of .com, they shouldn't own the whole namespace. Verisign are abusing the fact that they've been put in charge of a significant public resource, with too few checks on what they are permitted to do with it.

I'm just going to blackhole sitefinder.verisign.com

Update: This Bind8 patch allegedly fixes the issue (I haven't tested it), checking for the IP address that the wildcard resolves to.

This Linux ld_preload patch (again allegedly) intercepts calls like gethostbyname() and substitutes a 'domain not found' response for the IP address of the Verisign server.

Update: Overheard: "Verisign: We put the * in .com"

1 Yes, I'm aware of the existence of alternative TLD registries. Wake me when they are relevant to the real world.
2 There are alternative registrars, but Verisign still are own all your base.

5 Comments

If you install the newest version of the Google toolbar into your IE, it'll force that search page to come up as them, and not the other... creatures.

Gee... the folks down at MSN must be annoyed right now. There goes a good 25% of their search traffic :)

sites the are "under construction" are also routed their search page.

Did you (or anyone) actually try it?

I tried typing a few bogus domain names but they "successfully" did not resolve.

Either Verisign already backed down or the whole thing is a rumor.

It's not a myth. Not only is it happening to me on multiple networks, it has been verified from a large number of sources.

satori:~$ dig *.com
[most of response elided]

;; ANSWER SECTION:
*.com. 900 IN A 64.94.110.11

If it's not working on your machine, it means that either it is being blocked somewhere upstream of you, or perhaps the update still hasn't filtered through to all of the root nameservers.

This is the thread on NANOG where Verisign announced the change: http://www.cctec.com/maillists/nanog/current/msg05764.html. This is another thread: http://www.cctec.com/maillists/nanog/current/msg05756.html

Comments are no longer being accepted for this blog entry. If you really want to make your voice heard, you can always email me.

Previously: Basic Mathematics

Next: Caption Competition