There's a terrible enterprise security product that can be configured by IT to quasi-MITM your company web traffic. Instead of relying on enterprises pushing their own trusted root certs and MITMing the whole session this terrible product redirects all traffic to (and I'm not kidding here) urls like "www.terriblesecuritycompanyname.com/www.originalurl.com" when the user accesses www.originalurl.com. So this "enterpri…
> redirects all traffic to (and I'm not kidding here) urls like "www.terriblesecuritycompanyname.com/www.originalurl.com" when the user accesses www.originalurl.com.
What is the theoretical security feature they are selling by doing this?
Could anything worse than losing out on the registration fees ever actually happen?
If you actually caused say, reputational damage, you could be stuck with a lawsuit for more than just turning over the domain.
People have gotten in serious hot water over Internet traffic that was accidentally sent to them. Owning someone else's trademark as a domain name seems liable to increase the risk of that happening. Even if you aren't up to no good, you've now placed the onus on yourself of proving that you weren't, whereas if you weren't squatting on an obvious TM domain that wouldn't be true.
I don't really agree with the premise of this post. Why should Netflix or Google have to buy a domain for every stupid gTLD that someone paid a few $100k to create? The author makes it sound like that's somehow an oversight on their part. If anything, it's sad that they ended up having to own so many gTLDs just to prevent abuse.
I think that’s what he’s saying: that this system of hundreds of TLDs means that companies can easily miss one and that becomes a vector for phishing, etc. It sounded like he was blaming ICANN, not Netflix or Google.
I'm from Israel, and this is the first time I've heard about the .קום tld. I've never seen any website that uses it. The author mentioned that creating a new tld costs a minimum of 185k USD. This makes me wonder who would pay this kind of money for this completely useless tld.
Many national TLD holders (ccTLDs) control a TLD in local language.
.lk registry, for example, also controls .ලංකා and .இலங்கை (sounding "Lanka" "Ilangei" in Sinhalese and Tamil, the two other official languages in Sri Lanka), and they do not cost $185K. In fact, ccTLDs don't cost any money as far as I'm aware. DNS servers are run by the government funding but there is no cost to pay to ICANN.
Does anyone aggregate access to all 1500 TLD's? Is there a guide available on which combination of registrars to use to query them all?
Not all registries participate in the SRS registry protocol. Some of the lesser known ccTLDs must be registered by the individual authorities.
It's not accurate to run a DNS query to determine whether the domain is available because one can own the domain, but decide not to set any DNS records.
That is a thing for at least one Registry that I know of (and worked for), I don't know if Google does the same, but I don't believe there is anything stopping them (please correct me if I'm wrong).
Google does not do the same.
Which makes me doubly surprised! It was my impression that this product offering was quite lucrative.
>and were registered and used in "bad faith". How were they registered in bad faith? He's not extorting money from netfilx, nor is he trying to deceive people into thinking he's neflix.
UDRP typically rules in favor of the holder of the unambiguous trademark in these kinds of cases. As an example, "Exxon Mobil" refers unambiguously to a single entity only, and has no other possible uses, so anyone registering exxonmobil.{anything} would lose if the company came after them. No one else has any right to that trademark, and ICANN enforces trademark rights on domains. If the trademark already existed wh…
McDonald can use it after going through an expensive lawsuit where the big co will try to bully the little guy.
There's a terrible enterprise security product that can be configured by IT to quasi-MITM your company web traffic. Instead of relying on enterprises pushing their own trusted root certs and MITMing the whole session this terrible product redirects all traffic to (and I'm not kidding here) urls like "www.terriblesecuritycompanyname.com/www.originalurl.com" when the user accesses www.originalurl.com. So this "enterpri…
> redirects all traffic to (and I'm not kidding here) urls like "www.terriblesecuritycompanyname.com/www.originalurl.com" when the user accesses www.originalurl.com. What is the theoretical security feature they are selling by doing this?
The ability to block malware and phishing domains, insight to IT people about what sites are being visited, content filtering, etc. While most of this should be implemented in another way (like maybe a mandatory browser extension?), MITM is still the standard approach for many companies.