Fury after Facebook messes up smartphone users’ address books:

Remember how Facebook sneakily changed your default email address to @facebook.com? … Some smartphone users…are reporting that their on-phone address books have been silently updated to make @facebook.com email addresses the default way to send a message to their contacts.Graham Cluley at Sophos

The lesson: Whenever you change something, always consider the impact on things that depend on it.

This reminds me of the ill-fated Network Solutions attempt to replace failed DNS lookups with responses directing web browsers to search pages, not considering that web browsers aren’t the only software that uses DNS, or that some of that software might depend on accurate “this domain does not exist” info.

Originally posted on Google+

After a list of companies publicly supporting SOPA (the censor-the-internet-in-the-name-of-stopping-piracy bill) went public last week, the complaints started rolling in…but the biggest target, at least in the circles that I frequent, was GoDaddy. People organized a boycott, transferred their business elsewhere, and GoDaddy eventually reversed course, but it was too late to stop a massive outflow of customers.

But why was GoDaddy such a target? And for that matter, why did so many people follow through, rather than just rant about it on the internet?

I think there are several reasons.

  1. The tech industry is mostly opposed to the bill on technical reasons. Pick a random hosting provider and chances are they’re officially against it. That made GoDaddy stand out in a way that a random movie studio doesn’t.
  2. They provide a service, not content, and there are many competitors who provide the same kind of service. (And it seems like they all came out with discount codes to encourage people to switch to their company.) With content, you can choose to read a book from another publisher, or watch a movie from another studio, but if you want to watch a particular movie, you can’t get it somewhere else. There are lots of comics publishers out there, but if you want to read Spider-Man, you can only get it from Marvel.
  3. Public opinion of GoDaddy was already low. For some it was their sexist ad campaigns. For some it was the CEO bragging about shooting elephants. For some it was their incessant email marketing, or focus on upselling unneeded services to people who didn’t understand what they were, or the fact that their website is such a %^$^@#%& pain to use. They’re cheap, and they’re well-known, which means a lot of people used them…but they weren’t that well-liked. Supporting SOPA ended up being the last straw.

As a result, you had a company that was tolerated at best painting a target on themselves, and a relatively easy way for people to vote with their wallets and not actually give anything up other than the time and money needed to make the transfer.

Full disclosure: I used to have about 10 domain names registered through GoDaddy, plus a few at DreamHost and one at Network Solutions. (Yes, Network Solutions.) GoDaddy was annoying, but cheap, and it was easier to renew than move. This week I consolidated them all at DreamHost, where I’ve had my websites hosted for the past year. DreamHost is offering a discount code for new customers who want to switch: SOPAROPA. I don’t get anything for telling you that, but if you sign up and list me (kelson – at – pobox – dot – com) as the person who referred you to DreamHost, I’ll get credits that I can apply to my hosting bill.

SiteFinder was a “service” Verisign offered for a few weeks in 2003 in which DNS lookups to any non-existant domain in .com or .net responded with a pointer to an ad page. Techies revolted because it broke a lot of stuff. Verisign attempted to paint opponents of Site Finder as a minority of anti-innovation “technology purists” who still resent the presence of commerce on the Internet. A shorter version of my response ran on CNet’s News.com as a letter to the editor.

Mark McLaughlin’s opinion piece, “Innovation and the Internet,” simply proves that Verisign has completely missed the point. The reason so many people objected to SiteFinder is not the service it provided, nor a rejection of innovation, but that it caused a significant number of non-web applications to fail. Verisign, a company that should know better, had forgotten that the Internet is more than just the web.

There are many applications besides the web which make use of the DNS system, and many of them take actions that depend on whether a domain exists or not. Some of the more obvious cases occur in spam blocking. For instance, mail servers often check to see whether a the sender’s domain exists before accepting email. The DNS wildcard that powered SiteFinder broke this: suddenly, all domains would appear to be valid. A spammer could claim to be sadkjfhdsaf@asdfsadfjsdf.com, and the message would be accepted.

Another issue is DNS-propagated blacklists: at least one (ORBS, if I remember correctly) had folded and allowed its domain name to expire, but many software packages still included it in their default configurations. Since people often install software without updating, they were seeing slightly slower results at first, but the SiteFinder wildcard suddenly caused all queries to return positive, and a number of servers began rejecting all mail. (Something similar happened with Osirusoft a month earlier, but that was intentional on the part of Osirusoft’s former administrator.)

Other people are concerned about the fact that misdirected email, instead of being routed to secondary servers (in the case of a bad configuration) or bounced back by the originating ISP, is being routed through Verisign. Here, it’s a matter of trust: if you trust Verisign to do the right thing and bounce it without looking at it, then you probably have no objection. But many people saw the arbitrary creation of the wildcard in the first place as a breach of trust, casting doubt on their trustworthiness in other areas.

There are ways to resolve the issue of mistyped websites that do not break other applications. Microsoft embedded this functionality in Internet Explorer some time ago. I believe AOL has done the same in their software. While there were probably some objections, in neither case did it cause other applications to stop working.

It’s not about being technology “purists,” stifling innovation, or keeping commercialism off the Internet. It’s about recognizing the fact that the Internet is a collaborative effort, not the private domain of any one company. If Verisign had submitted its idea for review, and given others a chance to point out its flaws and to make adjustments to their own software, this could all have been avoided. As it is, it is clear that Verisign neither thought through all the consequences nor is willing to recognize that there even are consequences. And that – not a desire to “hold the Internet back” – is the reason for the backlash.

Two years ago, the company I work for moved to a new office. We used to do most of our domain name registrations through Network Solutions, mainly out of habit from when they were the only registrar, and accounts were of two types:

  1. Contacts. This involved a person or role and contact information.
  2. Domain names. This involved the person or company who registered the domain name, and links to three contacts (admin, technical, and billing).

So I had a contact account for any registrations we did on our clients’ behalf. We moved – again, this was two years ago – and I updated the address.

Network Solutions has restructured their entire account system into something immensely complicated. Somehow this single contact account has been split into three separate accounts, none of which had the password I started with, and all of which had the old address.

Yes, all three redundant accounts showed the address and phone number that I deleted two years ago.

We used to have people lose their domain names (or at least get them put on hold) because they never gave NS their new address when they moved, and they wouldn’t get the renewal notice. I guess these days it doesn’t really matter. Even if you do update your address, they’ll revert it anyway.

ยปAll pages site-wide with this tag