Sunday, April 9, 2006

The .EU landrush fiasco. A bumbling registry allows Europe's very own domain name to be highjacked!

Europe's .EU domain is being hijacked!
What happens when you match an inept registry with crafty businessmen? The answer is a really large scam. This is what is taking place with the "landrush" introduction of the new .EU top level domain name. This breaking story is a fascinating study of both grand manipulation and lax administration on the part of the EURid registry.

The landrush was supposed to make the process fair.
It's important to remember that the purpose of the landrush introduction period of a registry, is to provide a fair way to give everyone an equal chance at getting the really good names that are available early on. To do this, most registries take great pains to set up a level playing field, so that all registrars have an equal chance of getting these good names for their customers.

The requirements to be a .EU registrar were just too easy.
To be a registrar for the .EU registry, companies had to:

1. Attest that they were an individual business entity and were only applying for one registrar accreditation.
2. Attest that they were offering registrations to their customers on an equal basis.
3. Make a deposit of 10,000 euros (about US $12,000).

That was about all it took to be a .EU registrar. There was no verification that .EU registrars were *really* registrars, or were ICANN accredited. In fact, the EURid registry made no attempt to verify that those who applied to be .EU registrars were really businesses at all.

On paper -- to a simple-minded person -- it seemed fair.
The landrush process, which began April 7, is a very straightforward matter. Here's how it works: All the accredited registrars line up and each registrar gets to make one request for a .EU domain name. If the name is available, the registrar gets the name for its customer. If the name is not available, the registrar gets nothing. Either way, after making the request, the registrar goes to the back of the line and won't get to make another request, until all the registrars in the line in front of it make their requests. This continues until all requests have been made and the landrush process is over. For example, assume there are four registrars A, B, C and D. A requests a name then goes to the back of the line, then B requests a name, then goes to the back of the line. When B goes to the back of the line, it looks like this C-D-A-B. B will get to make its next request after C, D and A make their requests.

But something was very wrong.
The landrush process on the surface seems very fair. But there was something wrong with the process -- very wrong.

There was a flaw in the process. It was too easy to create a registrar.
A few sly companies, the most notorious being a company I'll call company "X" - which is believed to be backed by North American mega-millionaires -- saw a loophole in the process. These companies, instead of only registering their real active registrars, created hundreds of new "phantom" registrars. Two weeks before the landrush period began there were 800 -- many real, many not -- accredited .EU registrars. Then just before the landrush period began, Voila! Hundreds more registrars appeared. According to the EURid website - at least 300 more registrars appeared. Some legitimate registrars are claiming that the number of bogus registrars could even be much greater than this.

These new phantom registrars were created to hijack the .EU landrush.
These "new - last minute" registrars were engineered to show up just as the windows closed; many had the same phone number, many had no website, and just about all of them seem to have been created to game the .EU landrush process. It's important to note that none of these last minute registrars could have had time to take any landrush name applications. So the evidence is heavy that they were created for one purpose only --- to game the system.

How Company "X" and others hijacked the system.
During the landrush process, legitimate registrars like GoDaddy.com and others get one request for a .EU name - every time the selection process passes through the list of registrars. Company "X" and others might get to make one hundred or more requests - they get to make a request for every phantom registrar they were able to get accredited by the EURid registry. This increases considerably the likelihood that these companies will get the names that they are after. Legitimate registrars get one request. They might get one hundred or more. Let's go back to my earlier example where I showed how the landrush process worked. Now let's factor in the the phantom registrars that Company "X" and others have injected into the process. My guess is, if there are 1,100 registrars, that about 600 of them are phantoms, created solely to game the system. Not all of these are created by Company "X," a number of companies and groups are participating in this ploy. If I represent groups of legitimate registrars by the letters A through E, and those gaming the system by "X" the landrush process would look like this: "X, X, X, X, X, X, A, B, C, D, E." So you see, most of the names in the .EU landrush are falling into the hands of those gaming the systems.

Company "X" will make a fortune at the expense of the Europeans.
For the landrush orders that Company "X" did take, the game works as follow. The .EU names cost them $12.50 each. If the customer is the only one requesting the name, the customer will pay 50 - 75 euros. If more than one customer requests the name, then it is auctioned off - by Company "X" -- to the highest bidder. Many of these names will be auctioned off for thousands of dollars. And of course, the likelihood that Company "X" will get these names is good because they were responsible for many of the "phantom" registrars created and allowed by the registry, specifically for the landrush process. So you see, Company "X" and other companies who have successfully gamed the system should make a fortune on the .EU landrush - all at the expense of the Europeans.

Here's how the process should have worked.
Now compare this to the deal GoDaddy.com provides its customers. Our orders are taken at $14.75 and are on a "first come, first served" basis. So the first customer who requests a name gets it. No auctions, no scams.

Registrars can also work the landrush for their own account.
There's also the possibility that Company "X" and other companies participating in this gaming of the .EU landrush will be snapping up good names for their own account to be auctioned off later. After all, we've all been in the business for years. It's not difficult to know what names will prove to be valuable - certainly more than the initial $12.50 registration cost.

The big losers are the Europeans.
The irony of this fiasco is that the primary victims will be the Europeans. Because of the way the EURid registry allowed the landrush process to be gamed, the Europeans will have to pay ultra high premium prices for many of the names they should have had fair access to during the landrush period. This assumes that they'll be able to get those names to begin with.

We saw this whole thing coming.
Early on, we saw this whole scam coming. We tried to warn the EURid registry that their landrush process was problematic and that there was a large potential for abuse. These warnings fell on deaf ears. There have since been complaints filed by dozens of other legitimate registrars about this process. These complaints have been so numerous that the EURid registry has stopped responding to them. They seem to have simply hunkered down for the storm.

It's still not too late to fix the problem.
It's still early enough in the process for the EURid registry to step up and correct the landrush process. Here's what I suggest that they do:

1. Complete the landrush process.
2. Temporarily freeze all registrations until they can examine all registrars to be sure that they are genuine, and actually are in the business of securing domain registrations.
3. Decredit all registrars that were accredited but did not actually take .EU landrush applications, and were not previously active domain name registrars. This will eliminate hundreds of registrars.
4. Cancel all .EU domain names registered by decredited registrars.
5. Unfreeze the names registered during the original landrush process by the remaining accredited registrars.
6. Conduct a second landrush process for the remaining accredited registrars, allowing everyone access to the cancelled registrations.

I don't see the EURid stepping up to fix the problem on its own.
The problem with the above fix is that it would take huevos to step up and implement. This is something that we've seen little of from the people at the EURid registry. So we can be sure unless some authority in the European community steps up and forces them to do it, they will do nothing.

If you want to write to the EURid registry to express your feelings about the landrush process, you can do so at the following link: http://registrar.eurid.eu/en/shared/about/contactUs.html
 
 
 
 
 
Bob Parsons Twitter
@HardKnocksMoto It's an Arai Corsair V
about 19 hours ago from web :: in reply to HardKnocksMoto

Out on BMW 1200 GS today. Great day for riding. This new helmet chrome paint job is off the hook http://yfrog.com/esqqwj
12:39 PM Mar 20th from Tweetie

Chrome Paint job on my new Shoei Helmet by good friend Eric @ Steelvision. Bitchin! http://yfrog.com/17ntusj
5:36 PM Mar 19th from Tweetie

@SeanNieuwoudt Only to connect flights through Joburg.
12:07 AM Mar 18th from web :: in reply to SeanNieuwoudt

Skud is strange tasting Zimbabwe sorghum beer. Here's vid of Villager Skud party. :) http://tinyurl.com/yamyhqu
12:03 AM Mar 18th from web

Posted new video blog: "The secrets I used to sell online and make millions." http://www.bobparsons.me
8:27 AM Mar 17th from web

Please vote for GoDaddy Girl @DanicaPatrick in Esquire's Sexiest Woman Alive contest. http://bit.ly/cyJidT
9:45 PM Mar 16th from web

Headed to the beach bar for sundowners with @NayNay3. Last night in Hawaii. Got to make the most of it. I do miss Zimbabwe.
9:40 PM Mar 16th from web

Will be home soon. A NEW tricked out 2010 BMW 1200 GS Motorcycle in Black Metallic w/OH Cams is waiting 4 me. Think about it a lot.
8:58 PM Mar 16th from web

@rnuttachai Seriously? How much time have you spent in the communal lands dealing with the elephant?
8:31 AM Mar 15th from web :: in reply to rnuttachai

@nickarkell 1. The elephant are far from endangered. In fact there are too many of them. 2. Rarely do the villagers get any meat.
4:17 PM Mar 14th from web :: in reply to nickarkell

@ReidAdair I used a Westly Richards .500 Nitro double rifle.
11:00 AM Mar 14th from web :: in reply to ReidAdair

@rnuttachai Let's see, you watched that video and still make a statement like that? Idealistic naiveté simply knows no limits.
11:00 AM Mar 14th from web :: in reply to rnuttachai

@TokyoDan Hi Dan, We decided to discontinue it at least for now. Sorry that it couldn't continue. Best to you.
8:14 PM Mar 13th from web :: in reply to TokyoDan

My Vacation Video: Hunting Problem Elephant in Zimbabwe. Warning: A bit intense. http://tinyurl.com/yaos9oj
7:55 PM Mar 13th from web

@KuwaitReview Nice. I don't understand how you can resort to childish name calling & feel like much of a man.
11:20 PM Mar 11th from web :: in reply to KuwaitReview

Leaving Zimbabwe. Worked w/problem animal control team n corn/sorghum fields n Ndlovo communal lands. Intense. Vids later.
7:00 AM Mar 11th from Tweetie

This short video explains why I love being married to @NayNay3: http://tinyurl.com/yklnw2a
5:33 PM Feb 24th from web

Excited to watch NASCAR Nationwide race in Fontana CA. I love watching Danica Patrick drive GoDaddy.com Car #7.
2:28 PM Feb 20th from web

I guess Dennis Miller's right. Obama puts his smokes out on Joe Biden's forehead. :) http://tinyurl.com/ylg7pcj
8:01 PM Feb 19th from web

Vote For Blog
What did you think of this blog?
 Liked
 Disliked
 No Opinion
Share This Blog
Forward to a Friend
Your Name:


Your Email Address:

Send a copy of this article to me

Your Friend's Email Address:

Separate multiple addresses with commas (,)
Your Personal Note (optional):

Your comment is 0 of 1000 characters.

The information entered will not be used to send unsolicited email, and will not be sold to a 3rd party. Privacy Policy
Post This Article to Your Quick Blogcast Blog!
Blog URL:


Blog Username:


Blog Password:


You must have Remote Blogging enabled in your Quick Blogcast account in order to use this feature. If you don't have it set up yet, start here.
Don't have Quick Blogcast? For just $4.99/mo, publish your thoughts, opinions, comments and videos in your own blog, podcast - or both - anytime, day or night. Get your voice on the Internet today with Quick Blogcast! Learn more
 
Comments Display comments as (
Linear | Threaded
) 251 comments
Add a Comment!
Name
Email
Homepage
Comment
0 / 3000
characters
Email me when someone replies to my comment.
Email me when new comments are posted to this article.
Email me when a new article is posted.
Submitted comments are subject to moderation before posting.