brianpuccio.net

it's dot com

John Nack Follows Up On The 192.168.112.2O7.net Issue

Saturday, January 12, 2008, 5:15pm
unethical business practices, freedom to privacy, adobe, omniture, john nack

Q.: Follow-on: Given that you can't give a good reason why Adobe is using a server whose name is so suspicious, are you going to change the name?
A.: Absolutely. We are working with Omniture on this right now, and will make this change as soon as we can. (I don't know how long this will take, but will post here when I do.)

Hey, looks like he finally got it.

Adobe Uses Specifically Crafted Hostname, Can't Figure Out Why People Are Upset

When you launch a CS3 application the application pings out to what looks like an IP address - and internal IP address: 192.168.112.2O7.

That makes sense, right? Adobe wants to be sure you aren't running multiple copies of their programs…. Wait something is wrong here.

The first clue something is fishy is that I don't use a 192.168.xxx.xxx numbering scheme in my network. Secondly, if you look at the address Little Snitch is displaying, the last "numbers" of the IP address (2O7) look funny. Also, IP address don't end in any .com/net/org suffix.

Turns out that 192.168.112.2O7.net is owned by Omniture, a huge behavioral analytics firm. Hmmmmmm, anybody curious why Adobe is doing this? Anybody care to sniff packets? I sense an invasion of privacy here!

The issue, as completely missed by John Nack the first time around, isn't that the software calls home, it is that a hostname that looks most like an IP address that belongs to a range that has been designated as private. Later, John Nack claims to have "miss[ed] a key point. No, John, you've missed the point and it seems you still don't get it. No one is complaining about the 2O7.net portion of the hostname, but the fact that it starts out with 192.168.112.2O7, which looks deceptively like an IP address in a range that has been designated by private. You can't honestly say that this name was picked at random.

192.168.110.2O7.net, 192.168.111.2O7.net, 192.168.113.2O7.net and 192.168.114.2O7.net don't appear to be valid hostnames at this time.

Syndicate

Syndicate content

User login