On BNET: 5 classic computer pranks
BNET Business Network:
BNET
TechRepublic
ZDNet

June 20th, 2006

Craigslist scare story gets even stranger

Posted by George Ou @ 1:09 pm

Categories: Infrastructure, Net Neutrality, Networking, News, Security, Technology policy

Tags:

[Update: Now we have US Senator Wyden propagating the lie that this was a Cox conspiracy to block Craigslist because they have their own classified service.  The following blog proves that this was never the case and the original myth was retracted]

In my last blog about the lies being spread about Cox and Authentium, I showed how the Net neutrality lobbyists are lying about the situation to push their agenda even though they've been proven they were wrong.  Their rallying cry has been that Cox blocks Craigslist and this is what you get without their brand of Net neutrality and their key reference point is Tom Foremski's original blog that made the following claim:

Back on February 23rd Authentium acknowledged that their software is blocking Craigslist but it still hasn't fixed the problem, more than three months later. That's a heck of long time to delete some text from their blacklist.

This statement that blamed this on a Cox/Authentium blacklist had turned in to the battle cry for the Net neutrality gang demanding a stop to all tiered pricing structures though they sell it as a case of your first amendment.  It turns out that Tom Foremski's original blog that blamed this on Cox and Authentium's inability to change some text on a blacklist was indeed false.  Foremski now states "I assumed there was a blacklist - I have no idea how Craigslist is being blocked".

To make the case even more strange, Craigslist founder Craig Newmark decided to weigh in and say I "have it wrong" though he offered no specifics on what he believes I have wrong.  Newmark simply put up his own blog on this issue where he continued to pass the buck and took no responsibility on his part.  But the truth is that Craigslist is equally at fault and could have fixed the issue themselves long ago if they were simply following the RFCs for TCP/IP.  Many people have verified this to be the case and I took the time to verify it myself.  Here is a screenshot of an Ethernet capture when I tried to surf craigslist.org

Note the dark highlighted portion that reads "Window size: 0".  That literally means "don't talk to me now I'm busy" in TCP/IP.  That is the equivalent of putting up an "out to lunch" sign on the front door of a store.

Cox communications never blocked anything on the network so this was never a "Net neutrality" issue to begin with since the blocking is being done on a piece of software that users downloaded.  That software is Authentium's personal firewall which Cox offers to its customers for self protection.  Authentium's software fails in the sense that it never bothered to check back to see if the store was really open and simply took the "Window size: 0" literally and never checked back.

So whose fault is this?  It is a fault on both Craigslist and Authentium where a bug in Craigslist servers triggered a bug in Authentium and the problem could be fixed on either end.  Fixing the problem on Craigslist servers would immediately fix the problem for every single Authentium user which could be in the hundreds of thousands or more.  Fixing the Authentium personal firewall won't do anything until a massive notification and deployment effort with Cox customers (and other Authentium users).  Such a large scale deployment will take time and there is no guarantee that everyone will install an updated firewall or even bother reading the notification.

Craig Newmark could have corrected the problem for everyone globally on his own servers months ago yet he asks Cox and Authentium "why did it take so long".  But it seems to me that Authentium at least took ownership of the problem months ago and does have an actual fix that they've scheduled to release.  Craig Newmark on the other hand seems to have taken this to mean "see it's their fault and they admitted it" and refuses to even acknowledge what the blogsphere is saying about his responsibilities with his own servers.  So my question for Mr. Newmark is this:  Why didn't you fix this on your end months ago?

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 34 Talkback(s)
RE: Craigslist scare story gets even stranger
Anyone that has the intelligence to be concerned about net neutrality should be ashamed to have a product such as CSS(Cox Security Suite) on their PC. Heck, our CTS department doesn't even install it... (Read the rest)
Posted by: Trikein Posted on: 06/02/08 You are currently: a Guest | | Terms of Use
Has anyone tried emailing Craig?  nucrash | 06/20/06
I'll try that  georgeou | 06/20/06
Here is what I wrote.  nucrash | 06/20/06
nucrash  foremskiZDNet Moderator | 06/20/06
But he did use his own name in the email  georgeou | 06/20/06
Re: But he did use his own name in the email  none none | 06/20/06
I thought I did the name calling?  nucrash | 06/20/06
The lies were proven  georgeou | 06/20/06
Zero window might be necessary  tf2RI52WC873 | 06/21/06
I did use my real name  nucrash | 06/20/06
How about posting the COMPLETE trace?  rpmyers1 | 06/20/06
no need to, that isn't the point  georgeou | 06/20/06
Craig's list isn't screwing up  rpmyers1 | 06/21/06
Link Please  nucrash | 06/21/06
Oh yes it is.  Mr. Roboto | 06/21/06
Never mind... I got Ethereal and got some results myself...  Mr. Roboto | 06/21/06
Thank George and Myself  nucrash | 06/22/06
Credit where Credit is do  nucrash | 06/22/06
I was mistaken  nucrash | 06/23/06
win 0  none none | 06/20/06
You don't understand what "don't talk to me means"?  georgeou | 06/20/06
Re: You don't understand what "don't talk to me means"?  none none | 06/20/06
The lie is the "blacklist" part  georgeou | 06/20/06
George, time to calm down  TonyMcS | 06/20/06
I only call it like I see it  georgeou | 06/20/06
What about Authentium?  Robert Crocker | 06/20/06
No, I am not backing up  georgeou | 06/20/06
Final update available now  cnewmark | 06/20/06
But if you updated your end, it would universally be fixed  georgeou | 06/20/06
Possible security reasons?  Robert Crocker | 06/21/06
Whoa, hold that..  nucrash | 06/21/06
Are you a Swiftboat?  nucrash | 06/21/06
What??  opensourcepro | 06/23/06
RE: Craigslist scare story gets even stranger  Trikein | 06/02/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads