This is how demon.co.uk ends, not with a bang but a blunder: Randomer swipes decommissioning domain
- Reference: 1600433106
- News link: https://www.theregister.co.uk/2020/09/18/demon_decommissioning_oopsie/
- Source link:
Vodafone [2]extended the licence to September to give Namesco's customers a little more time to get their affairs in order, but all good things must come to an end... even email addresses that have loyally served users for decades. Except it didn't quite manage that.
In a final twist of fate, the decommissioning of the sub-domain was swatted by the dread hand of bork.
"As a result of human error," the company explained in an email to customers, "an incorrect dummy domain name was used to manage the decommissioning process, and this domain was subsequently registered by a third party."
The result was that between 31 July and 6 August, sending an email to the now-defunct demon address would see both sender and recipient potentially logged by the mystery third-party server. Namesco was at pains to point out that "no email content was ever delivered to the third party, as the server rejected this content."
Oops. Once the mistake was spotted, Namesco swiftly changed the dummy domain name. And the third party in question submitted an undertaking promising that no shenanigans were intended.
Namesco email 'scripting error' has last bastion of Demon Internet holdouts scratching their heads [3]READ MORE
Namesco reported the incident to the UK's Information Commissioner's Office (ICO), and just over a month after the cock-up occurred, affected Register readers received the company's apology email. Exactly how a human managed to do the deed and what will stop something similar happening in the future remains unclear.
An ICO spokesperson told The Register : "People have the right to expect that organisations will handle their personal information securely and responsibly.
"When a data incident occurs, we would expect an organisation to consider whether it is appropriate to contact the people affected, and to consider whether there are steps that can be taken to protect them from any potential adverse effects.
"Names.co.uk has reported an incident to us and we will be making enquiries."
A spokesperson for Namesco told us the company had "undertaken a full investigation" into the matter, "and have obtained a signed legally binding undertaking from the operator of the third-party server confirming that no personal data, including in the form of email content, was accessed, forwarded, viewed or stored."
"Additionally," it said, "we have confirmed through our technical investigations that the logs were never accessed and have been permanently deleted."
The spokesperson also confirmed that most of the former Demon customers whose sub-domains were decommissioned this year were affected.
Still, those who have followed the fate of those elderly Demon email addresses (some of which were nearing the 30-year mark) will hopefully be pleased that they shuffled into the long night not quietly, or with head bowed, but with one final, human-induced TITSUP*. ®
* Transfer Into Temporary Sub-domain Utter Pants
Get our [4]Tech Resources
[1] https://www.theregister.com/2020/04/15/namesco_demon_subdomain/
[2] https://www.theregister.com/2020/04/30/demon_extension/
[3] https://www.theregister.com/2020/06/04/namesco_demon_scripting_error/
[4] https://whitepapers.theregister.com/
"no email content was ever delivered to the third party, as the server rejected this content."
Was this after it had been sent the content or in some prior handshake kind of step? If the former, then how do they know the third party wasn't logging the content and then claiming it had rejected it? Surely a case for the Information Commissioner.
If anyone gets reported to the IOC, it should be Vodafone for redirecting email to a domain they didn't own.
Hopefully the 3rd party is just someone who noticed this idiocy, registered the dummy domain, and put server on it to reject traffic, before anybody nasty got in there.
From the network logging I have permanently running, I see the test email I tried to send went to an Amazon hosted IP where it was greeted by an identifiable host name which is still there at the same IP, but unfortunately it did TLS though that did mean I got the public cert and contact email address but as it was a short test message I can't tell for sure at first glance if the exchange was an immediate reject but fortunately I had already moved everything.
The mail server here just logged it as "550 relay not permitted" which I had thought was an intentional thing to bounce things off a dummy server but started too early.
At this point I don't know how sarcastic to be when congratulating the selfless individual who generously registered the domain to protect us all from fraud and villainy.
A sad day
I was a Demon customer from the early days (32kbps dial-up USR modems) and I stayed with them until FTTC was available in my area. Demon did not offer the service - presumably as Vodafone knew it was going to can them - so I migrated to Zen (excellent BTW). Demon had excellent support staff which treated you like a valued customer with no scripts or foreign accents in sight....
R.I.P. Demon.
Re: A sad day
Yes, I am a little tearful that Demon is no more. The Good Olde Days when people were really passionate about their services.
And totally agree on Zen: rock-solid.
Re: A sad day
Zen also have decent support staff who actually know what they're talking about, at least that was my experience on the rare occasions I've needed to contact them.
I suppose I'd better complain ...
I was one of those subscribers ... very sad to see the email address disappear but that's at the whim of multinational organisations.
Me on very protracted chatbot call: Hello Vodafone, I have an email to tell me that my Demon email will stop working.
Bugger, being a crappy Techbot it does not work in any sensible way shape or form.
Eventually, and many digital exasperation later ...
Digi Tech: I understand your problem. Hello, are you on wi-fi at the moment?
Me: err yes. Why?
Tech: Can you open a browser window and sign into the router please. 192.168 ...
Me: Why?
Tech: So I can help you with your problem.
Me: Why? My Demon domain is being stopped. What's that got to do with my router?
Tech: It's to help you keep your email working. If you can just access 192.168 ...
Me: How is signing into my router going to help? (I neglected to mention I was in lockdown away from home so it wasn't even my service ...)
Tech: We've got to change DNS settings to keep your email working ...
Me: Why? What has that got to do with my email domain being withdrawn?
Tech: If you can just sign in to ...
Me: Why? What's that got to do with my Demon email being stopped?
Tech:
At this point I suspended things and lodged a formal complaint that I felt I was being scammed by an official Vodaphone "tech" trying to gain access to my system. After a month Vodafone denied it was a problem and called it 'a misunderstanding'.
Time passes ...
As it happens, the domain expiry date was that date and was fully paid up so I had already penned a draft "Give me my money back and compensate me for withdrawing the use of my domain early you gits" letter. I guess someone had realised the cock-up so the draft email was filed as almost the last entry in my Demon mailbox ... sad end to nearly three decades of use ...
Many thumbs up for Demon - thumbs down in as many ways as possible for Vodafone.
not with a bang but a cock-up
That's the way technology usually ends.
I've just thought about how many ISPs I've been with over the years who have been taken out in to the desert, shot in the back of the head and left in an unmarked grave. The total is now 5.
Freeserve (swallowed up by Orange after Wannadoo)
Publiconline (defunct)
Supanet (defunct)
Be Unlimited (swallowed up by O2)
Demon (swallowed up by Vodafone)
Happily with Origin these days, really hoping a mobile company doesn't decide to purchase them.
Ends? Opportunity for a sequel...
I note Vodafone's domain registration is due to expire on 5th May 2021. I wonder whether Vodafone will actually let it go and so enable some entrepreneur to resurrect it or they will simple domain squat for a decade or so...
bull CRP
"Additionally," it said, "we have confirmed through our technical investigations that the logs were never accessed and have been permanently deleted."
*it is flammable