Past News - Publish.com
Publish.com Ziff-Davis Enterprise  
SEARCH · ONLINE MEDIA · MOBILE · WEB DESIGN · GRAPHICS TOOLS · PRINTING · PHOTO · TIPS · OPINIONS
Home arrow Past News arrow The Great Domain Robbery of '05
The Great Domain Robbery of '05
By Larry Seltzer

Rate This Article:
Add This Article To:
Opinion: Not too long after ICANN changed the rules, a domain thief has stolen several domains. Have the new rules already failed, or have the registrars failed their customers?

A lot of people lost e-mail, access to Web administration and even their porno accounts over the weekend. Yes, it was a momentous and stressful couple of days.

Several domains were stolen, including panix.com, the home domain of Internet service provider Panix, the oldest ISP in the New York area (or so they say about themselves). This particular thievery is what raised most of the attention, because Panix customers who use a panix.com e-mail address stopped getting their mail.

According to this message on ICANN's message boards by George Kirikos, aem.com and f3.com (both of which, I think, are car-related sites), as well as xybererotica.com, appear to have been stolen as well. In fact, all three of these domains seem now to have the same whois data and point to the same Web site. Some serious traffic was diverted, and the new sites are spyware-infected. (Perhaps the old ones were too, I can't say.)

It may be the first great test of the response of ICANN and the domain registrar industry to a violation of their new policies implemented late in 2004. I expressed concern about these new policies at the time, but was reassured that one of the strengths of the new system was the well-defined mechanism for dealing with disputes.

But there's a good chance here that the central issue is not so much disputes between registrars but sloppy procedures at some registrars that allowed an unverified transfer through. Panix says on its home page (as of Monday morning, EST) that Melbourne IT, the Aussie registrar to whom the domain was illegitimately transferred, has reverted the domain back to them. This does indicate that there was no real dispute once Melbourne IT woke up Monday morning and realized what had happened. Incredibly, Melbourne IT, not a teeny company, has no support available over the weekend. The hijackers may have counted on this fact.

The motivation behind the ICANN rule changes was actually to streamline domain transfers between registrars. Some registrars (cough! Verisign! cough!) had a reputation for sitting on valid requests for transfers to other, almost certainly less-expensive registrars. The new rules create a presumption that the transfer will proceed after some period of time unless it is denied for some valid reason. The registrars still have to contact the owner of the domain, presumably through the whois records.

Next Page: Concern on two fronts.

I was concerned on two fronts: 1) that a "rogue registrar" could more easily steal domains this way, and 2) that so much data in whois is inaccurate, intentionally on the part of the owners, that notifications could go unnoticed by legitimate owners.

I still think phony whois data is a problem in this regard, but I was assured that the rogue registrar scenario wasn't credible, and this incident doesn't seem to be an example of it. On the other hand, it does appear to me that at least one registrar was delinquent in some way, in that I can't believe that all these domain owners didn't see a notification of a transfer request, not to mention changes in the whois records themselves.

For insights on security coverage around the Web, check out eWEEK.com Security Center Editor Larry Seltzer's Weblog.

The stolen domains have ended up with more than one registrar, but according the Kirikos post they were all previously at Dotster, a deep discounter that has domain names like killbush.com and hairyarmpits.net for sale on its home page.

Kirikos believes, and with good reason, that the answer is to use the registry LOCK feature. Actually, he says that registrars should, by default, lock all domains, and I can't see a good reason not to. It's just good security for a registrar, and that's what this story is probably all about: good practices, especially security practices, by domain registrars. The system may be all set up now to make transfers go smoothly, so it's up to the registrars to make sure that domain hijackings don't.

Security Center Editor Larry Seltzer has worked in and written about the computer industry since 1983.

Check out eWEEK.com's for the latest security news, reviews and analysis.

More from Larry Seltzer


Discuss The Great Domain Robbery of '05
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Past News Articles          >>> More By Larry Seltzer
 


Buyer's Guide
Explore hundreds of products in our Publish.com Buyer's Guide.
Web design
Content management
Graphics Software
Streaming Media
Video
Digital photography
Stock photography
Web development
View all >

ADVERTISEMENT


FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 10, 4 p.m. ET
    Eliminate the Drawbacks of Traditional Backup/Replication for Linux
    with Michael Krieger. Sponsored by InMage
  • Dec 11, 1 p.m. ET
    Data Modeling and Metadata Management with PowerDesigner
    with Joel Shore. Sponsored by Sybase
  • Dec 12, 12 p.m. ET
    Closing the IT Business Gap: Monitoring the End-User Experience
    with Michael Krieger. Sponsored by Compuware
  • Dec 12, 2 p.m. ET
    Enabling IT Consolidation
    with Michael Krieger. Sponsored by Riverbed & VMWare
  • VTS
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT
    IT LINK DISCUSSION - MIGRATION
    A Windows Vista® migration introduces new and unique challenges to any IT organization. It's important to understand early on whether your systems, hardware, applications and end users are ready for the transition.
    Join the discussion today!



    .NAME Charging For Whois
    Whois has always been a free service, but the .NAME registry is trying to change that.
    Read More >>

    Sponsored by Ziff Davis Enterprise Group

    NEW FROM ZIFF DAVIS ENTERPRISE


    Delivering the latest technology news & reviews straight to your handheld device

    Now you can get the latest technology news & reviews from the trusted editors of eWEEK.com on your handheld device
    mobile.eWEEK.com

     


    RSS 2.0 Feed


    internet
    rss graphic Publish.com
    rss graphic Google Watch

    Video Interviews


    streaming video
    Designing Apps for Usability
    DevSource interviews usability pundit Dr. Jakob Nielsen on everything from the proper attitude for programmers to the importance of prototyping in design to the reasons why PDF, Flash and local search engines can hurt more than they help.
    ADVERTISEMENT