16 Austin Rd. Apt. #2
Medford, MA 02155
J. ******, et al
Dear Mr. ****** :
I am writing on behalf of the CounterExploitation web site, www.cexx.org, to address the concerns raised by your letter dated March 12, 2004, and received March 16, 2004. I currently act as the technical point of contact for the CounterExploitation web site. As you may know, one of the primary purposes of this Web site is to provide information regarding the detection and removal of a variety of software technologies. We aim to provide information that is helpful and accurate, while maintaining an opinionated style and personal touch. The CounterExploitation web site is a non-profit hobbyist project that is created and maintained in the author's limited spare time.
In your letter dated March 12, 2004 and received March 16, 2004, it is alleged that the CounterExploitation web site contains “improper characterizations” and “offending content” regarding the New.net Corporation (“New.net”) and the New.net Client Software (“Software”). The letter further alleges that the web site contains “false and misleading statements” concerning New.net and the Software. Your letter cites the following specific examples, which you allege constitute “falsehoods”:
Under a web page entitled “More NewDotNet BS,” your Website contains a copy of a purported letter from a user, dated July 6, 2001, that attributes the disappearance of the user’s hard drive to the presence of version 2.91 of the New.net Software on the user’s machine. New.net doubts the veracity of this letter, given that (a) the user claimed to have lost his hard drive but yet acknowledges that he thereafter searched his hard drive and found the New.net file (it is simply not possible to search a hard drive that has disappeared) and (b) neither New.net’s 2-person Customer Support department, nor New.net’s 7-person Quality Assurance department, has ever encountered such a problem with the New.net Software. Moreover, this user letter is entirely outdated, as version 2.91 of the New.net Software was released on May 30, 2001 and New.net has released twenty-three (23) new versions of its software since then.
As you have astutely noted, the cited article is linked as an unverified letter from an anonymous user, and is presented as such. The letter cites a number of issues that the user believed may have been related to the installation of the New.net client, including the disappearance of a logical drive, loss of Internet access, and the appearance of a RUNDLL warning dialogue reporting a missing Newdot~2.dll file. Since the maintainers of CounterExploitation and other sites have, through the course of the past several years, discussed and analyzed the New.net Client Software and its possible modes of failure at-length and have not observed any such mode that would directly result in the “loss” of a logical drive, we are willing to remove the user's letter from the site. However, as a purely technical point, it is not uncommon for a modern computer to contain more than a single physical drive, nor for a physical drive to be split or “partitioned” into multiple logical volumes. (For the record, I should also note that at no point does the user letter directly associate the hard drive issue with the New.net Software, declaring only that the failures mentioned occurred together.)
Your Website accuses New.net of lying to potential domain name subscribers about the nature of the domain names that we sell (“kind of like if I were to sell you ‘yoursite.free.cexx.org’ and tell you you’re getting your very own domain name ‘yoursite.free’”). You refer to New.net’s business practices as “sleight of hand.” There is nothing underhanded about the way we market our domain names. We are very clear about the fact that users must either have the New.net Software on their computers or be connecting to the Internet through one of New.net’s partner-ISPs to access New.net’s domain names. New.net domain names that are queried using the New.net Software do, in fact, resolve as fourth-level subdomains;1 however, those subdomains are the property of the user and cannot be taken way.
With no disrespect intended, the above paragraph appears to make statements not present in the original document; “putting words into our mouths”, as it were. At no point does our web site accuse New.net of “lying”, nor use any variant of this term. Your letter goes on to take issue with our example of marketing the subdomain 'yoursite.free.cexx.org' as a top-level domain name displayed as 'yoursite.free'. We have used this example to help illustrate the difference between a “domain name” and a “subdomain”. However, after taking issue with this example, your letter goes on to state that New.net names “do, in fact, resolve as fourth-level subdomains”, precisely as illustrated in the 'yoursite.free.cexx.org' example.
It appears that you are aware of the fact that New.net names are not valid Internet domain names. While we understand and acknowledge that New.net, Inc., posts legal disclaimers to this effect on its web site, we believe that the wording of such statements fails to adequately notify the customer that a significant percentage of Internet users will not be able to resolve the name. We in addition note that, despite your own admission that New.net names are not domain names, the New.net web site consistently uses the terms “domains” and “domain names” to refer to these fourth-level subdomains. This has been noted during a visit to the New.net web site on March 16, 2004.
To avoid confusion between the Internet DNS1 and the services offered by New.net, Inc., throughout the remainder of this letter I will use the term “domain name” to refer to a valid Internet domain name resolved via the standard DNS root servers, and “keyword”2 to refer to a name that exists only within New.net, Inc.'s proprietary namespace. We feel that the textual information provided publicly on the New.net, Inc. web site fails to adequately differentiate between domain names and New.net keywords. We further feel that we are well within our legal rights in expressing this opinion. This opinion has been formed due to the repeated use of the terms “domain” and “domain name” in reference to New.net keywords, as well as numerous consumer complaints we have been made aware of alleging that the consumer was not adequately informed of the difference between a New.net keyword and a valid Internet domain name.
To this end, I would like to take a moment to examine the disclaimer New.net provides on the New.net web site. At the very bottom of the New.net homepage, specified in a 10-pixel absolute font size, is the following message: “New.net domain names are accessible by persons that use one of our partner ISPs to access the Internet or who activate their browsers. This number is limited now, but growing daily.” It is interesting to note that this statement does not actually state that anyone is not able to access New.net keywords; for example, by stating that “New.net domain names are only accessible by persons that use one of our partner ISPs to access the Internet or who activate their browsers.”. As previously mentioned, this statement continues to use the term “domain names” to refer to New.net keywords.
The availability of the same name in multiple namespaces makes possible a condition known as a namespace collision, in which multiple parties simultaneously “own” the same name. The result of this condition is that the name would sometimes resolve to one site, and sometimes another, depending on the specific computer system or Internet Service Provider in use at the time. The situation would also promote disputes over the ownership of the name, and make it possible for one person's assigned name to direct Internet users to an unrelated site of unknown repute, or even a competitor. We feel that the New.net Web site fails to adequately inform potential customers of the very real possibility of namespace collisions, and the potential consequences of such collisions at such time that any top-level domain extension already allocated within the New.net proprietary namespace becomes part of the official DNS structure. CounterExploitation is informed and believes that New.net, Inc. has allocated names with top-level domain extensions, including, but not limited to, .law, .travel, .xxx and .kids, which “already overlap with applications to ICANN for new TLD introductions” (Source: Keeping the Internet a Reliable Global Public Resource: Response to New.net "Policy Paper", 20013).
With regard to the foregoing, we feel that the opinions expressed on the CounterExploitation web site constitute lawfully protected speech. However, in order to provide additional clarity and demonstrate good will, the text on the CounterExploitation web site will be revised to clarify our position.
Your letter also objects to our inclusion of the phrase 'sleight of hand' when pointing to a linked article located at http://www.internetnews.com/isp-news/article.php/8_709701 . This phrase refers directly to the linked article, and is in fact a direct quote from the article. We have been provided with no reason to question the lawfulness of the opinions expressed in the aforementioned article.
Finally, the above paragraph goes on to state that “those subdomains are the property of the user and cannot be taken way” (sic). It is unclear why you have taken the time to make this assertion. At no point does the CounterExploitation web site make any statement regarding the ownership of names within the New.net namespace.
Your Website also accuses New.net of banning users from New.net’s discussion forum and deleting their posts for merely discussing the New.net “sleight of hand.” New.net has never banned any user for such frivolous reasons.
A cursory inspection of the New.net discussion forum located at http://new.chat.new.net on March 16, 2004 shows the following threads in which a user specifically complains of being banned from the forum after expressing negative statements about the New.net company or products:
We are confident that, if necessary, we would be able to obtain a significant body of accounts from witnesses to administrative actions taken against vocal New.net critics, both in the current New.net forum software and previous iterations of the New.net forums. It is also notable that many posts criticizing New.net are removed from more heavily-trafficked areas and deposited in a special “Rants & Raves” forum located near the bottom of the forum list, regardless of where they were originally posted. Although this forum is designated as the appropriate forum for “Compliments, including testimonials, and complaints”, it is interesting to note the dearth of positive statements in this forum--these, unlike negative statements, seem to remain where they are posted. However, since you feel the wording on our web site is unclear, it will be changed to read: “...respondents have reported having posts deleted or being banned from the forum after making negative statements about the company or its software.”
Your Website maintains that the “NewDotNet software is surreptitiously bundled with unrelated software in typical Foistware fashion.” There is nothing “surreptitious” about New.net’s distribution practices. New.net provides very detailed download disclosures to all potential users and does not install without the explicit consent of the user. (See section below entitled “Foistware” for a more detailed discussion of the foistware misconception.)
Historically, CounterExploitation has fielded complaints from numerous users indicating that they did not request the New.net software and did not know how it came to be on their computers. However, since the newest procedure documents received on March 16, 2004 with your original letter indicate a goal of more prominent disclosure of your software, we will remove the word “surreptitiously” from our characterization of New.net's software bundling practices. For the record, we feel that the information we have provided concerning the distribution of the New.net software is accurate as of the time of publication.
CounterExploitation is the originator and inventor of the word “foistware”. We coined this term specifically to refer to unsolicited or “bundled” third-party software which did not meet the definitions of existing terms such as “adware” and “spyware”. We have been careful to avoid any reference to the New.net software as “adware” or “spyware”. As such, we do not feel that referring to your software, which is bundled with unrelated third-party software, as “foistware” constitutes a misconception on our part, nor do we feel that this statement places us in a legally actionable position.
Your Website states that “New.net now offers an uninstaller from their Web site. For some reason their lawyers don’t want anyone linking to it, so shh!” On the contrary, New.net is extremely forthcoming about how to uninstall its software. The Uninstaller is prominently included with the New.net Software in the Program File. In addition, the New.net Software may be easily uninstalled using the Microsoft Add/Remove Programs utility. Finally, the New.net Software comes with a ReadMe file that includes detailed instructions for uninstalling the software using any 1 of 4 different methods, as well as the phone number and email address for New.net’s Customer Support department. (See section below entitled “Uninstallation” for a more detailed discussion of uninstallation.)
At no point does the text you have cited, nor the remainder of the document, indicate that New.net is not “forthcoming about how to uninstall its software”. In fact, the “Removal” section of cexx.org's document begins with the following text:
The NewDotNet software places a reference in Windows' Add/Remove Programs dialogue. It is recommended that you use this to remove the program, as explained in more detail in the New.net FAQ.
The cexx.org site informs the viewer of two (2) New.net-supplied methods of removing the software immediately preceding the statement you have cited as stating that New.net is not “forthcoming about how to uninstall its software”.
This statement, which you have selectively quoted, states in full: “For some reason their lawyers don't want anyone linking to it, so shh! (Technically, we have linked to a page which links to it. Scan down and find the link to the uninstaller, which will have a name like uninstall#_##.exe)”. This statement refers specifically to a prominent legal disclaimer displayed in connection with the uninstaller which expressly forbids distributing or linking to the uninstaller. A visit to the New.net Support web site located at http://www.newdotnet.com/ on March 18, 2004 confirms the placement of the following text, displayed in a red font in all capital letters, closely following a link to the uninstaller:
THIS FILE IS NOT TO BE DISTRIBUTED, MIRRORED, OR LINKED WITHOUT THE EXPRESSED WRITTEN CONSENT OF NEW.NET.
In keeping with the CounterExploitation web site's entertaining, opinionated and sometimes humorous writing style, the comment you have cited refers to the irony of this prominent warning in the context of a “forthcoming” removal procedure, as well as the unfortunate fact of American society's level of reliance on lawyers and legal statements. The statement is a “tongue-in-cheek” method of expressing the factual observation that the author has avoided incurring the legal liability implied by New.net's statement by linking to a document that in turn links to the uninstaller, rather than linking to the uninstaller. However, since you have demonstrated displeasure with this statement, we will, as a demonstration of good will, revise this text to clarify our position. We are confident that you will find the revised text substantially less amusing.
Your Website claims that the New.net Software has compatibility problems with several third-party applications. These claims are not true. To the extent there may have been compatibility issues in the past with any of the programs listed, those issues were addressed long ago.
We at this time ask you to substantiate your assertion that claims on the CounterExploitation web site regarding known compatibility issues “are not true”. The specific software issues mentioned on the CounterExploitation web site are well documented. It is unclear whether you are suggesting that we are part of an elaborate conspiracy to fabricate evidence of software compatibility issues--including the ability to control the contents of third-party publications such as the Microsoft Knowledge Base--or that the latest versions of said software products, coupled with the latest version of the New.net client, will no longer experience compatibility issues, and for this reason, assert that we have no legal right to mention compatibility issues that may be experienced by users not running the most recent version of both the New.net client and the third-party software. With regard to the former, your letter goes on to specifically acknowledge your awareness of compatibility issues known to have existed between the New.net software and two (2) third-party applications, Microsoft Internet Security and Acceleration (ISA) and an unspecified McAfee product.
We feel that factual historical information about companies and products is an important tool to help consumers make informed decisions and resolve problems. We also feel that it is unreasonable to assume that all users are running the most up-to-date version of each software program on their computers. Since you appear to assert that all of the known compatibility issues listed on the CounterExploitation web site are resolved by installing the latest versions of the New.net software and the third-party software, we will revise this section to make very clear that the compatibility issues listed refer to older software versions. However, we have no intention of censoring factual historical information from the CounterExploitation web site.
Under a web page entitled “Manual NewDotNet foistware removal,” your Website provides improper instructions to users who wish to uninstall the New.net software. Using the instructions provided on your Website can lead to computer malfunction. The proper uninstallation instructions may be found in New.net’s ReadMe file.
Before addressing technical points, I shall first elucidate the process by which a reader of the CounterExploitation web site would arrive at the “Manual NewDotNet foistware removal” document. Beginning at the section entitled “Removal” on CounterExploitation's page of information regarding the New.net software, the reader is first directed to use the Windows “Add/Remove Programs” feature, is directed via hyperlink to the New.net FAQ located at http://www.new.net/help_faq.tp#p4, and is provided with detailed directions on locating and using the Windows “Add/Remove Programs” feature. In the event that the reader has missed this, the line immediately following consists of the following in bold text:
The supplied Add/Remove option has been known to fail in some circumstances. If this happens, New.net recommends that you e-mail New.net support or phone them at (626) 229-7800. As the New.net software is being constantly updated, removal information on this Web site can easily become out-of-date.
The above-cited text also contains a hyperlink to the New.net technical support e-mail address. In the event that the reader has missed this prominent bold text as well, or is still unable to resolve the issue, the reader is next directed to a page describing a total of four (4) free, software-agnostic Winsock repair tools. These tools are designed to correct errors in the Layered Service Provider (LSP) configuration on a Microsoft Windows operating system regardless of their cause, including errors that may be entirely unrelated to the New.net software.
If, after neither the “Add/Remove Programs” uninstall service, New.net technical support, nor the third-party repair tools are able to resolve the issue, the reader is directed once again to the New.net web site, this time to download and run a stand-alone uninstallation program.
It is only after having been presented with a total of seven (7) methods of either removing or deactivating the New.net software that the reader will see the following line:
Two manual removal procedures (easy and hard) are available For Reference only. Use without the advice of New.net is not sanctioned by us or New.net.
A hyperlink in the above sentence allows the user to reach the Manual removal document.
If, notwithstanding the foregoing, the reader has continued past all seven (7) of the methods outlined above and continued to the “Manual NewDotNet foistware removal” document, or has accessed this document directly via hyperlink from another site, the reader will see the following text preceding the contents of the document, in a bright pink italic font one size larger than the document text (relative HTML font size “+0”):
The text "WARNING WARNING WARNING" in all capital letters;
The text "If you have experienced problems with the new.net uninstall using Add/Remove Programs, it is recommended that you contact New.net tech support for assistance. The information below is provided FOR REFERENCE ONLY, and could make things worse if used improperly. Do not attempt unless you are a guru and willing to accept the possibility of your computer losing Internet access, and hold New.net and CEXX.ORG harmless for any results." including another hyperlink to New.net technical support;
The text "WARNING WARNING WARNING" repeated again in all capital letters;
The text "This procedure from New.net techs is intended to manually restore your previous Winsock settings. Do not use without advising by New.net support." in the default document font size.
By comparison, the notice on the New.net web site informing potential customers that New.net domains are available to "persons that use one of our partner ISPs to access the Internet or who activate their browsers" is displayed at the very bottom of the page in an absolute font size of 10 pixels, which corresponds to xx-small in CSS font size notation or "-2" in relative HTML font size notation.4
As stated within the document itself, the actual text of the removal instructions contained within the “Manual NewDotNet foistware removal” document was originally published by New.net, Inc. As a gesture demonstrating good will, we are willing to remove the removal information contained within the “Manual NewDotNet foistware removal” document. It will be replaced with a document which, while factually detailing changes made to the Windows Registry by the New.net software, will be void of imperative language such as “remove”, “rename”, or “edit”.
After raising the specific issues presented above, your letter goes on to address a number of conceived misconceptions regarding the purpose and functionalities of the New.net software, which we will address below.
At no point does the CounterExploitation web site accuse the New.net software of data mining, nor does the CounterExploitation web site at any point refer to the New.net software as spyware. The CounterExploitation web site does not assert, nor has it ever asserted, that the New.net software “capture[s] keystrokes, a history of websites visited, personally identifiable information, screenshots, or passwords.”
The CounterExploitation web site contains information regarding specific versions of the New.net client software which displayed pop-up advertising for a New.net-affiliated venture called the Firstlook.com Search Portal (“Firstlook”), and CounterExploitation can provide evidence to back this claim as necessary. This information was accurate at the time it was published. The text relating to advertising features associated with the New.net software and Firstlook will be modified to make clear that the New.net software no longer displays pop-up advertising. Again, however, we do not intend to censor a factual historical record.
Please refer to our comments regarding the use, definition and origin of the term “foistware” above.
As previously stated, the CounterExploitation web site specifically documents three (3) official software removal avenues provided by New.net, Inc. The web site makes no statements regarding the ease, or lack thereof, with which the New.net software can be removed using any of the three (3) official procedures. CounterExploitation takes issue with New.net's assertion that well-documented Internet connectivity issues historically associated with the New.net software have been “typically caused by the end-user having used an incorrect procedure to uninstall the New.net Software or one of its components.” A common failure mode in some earlier versions of the New.net client software caused the client system to lose Internet connectivity after the New.net client attempted to install an automatic update via the Internet. Such an update could occur weeks or months after the initial installation of the New.net client on the user's computer, and occur in the background without specific notice to the user. For these reasons, a user experiencing this failure mode would be unlikely to associate the failure with the prior installation of the New.net client, and thus, unable to correct the failure despite the availability of New.net technical support and uninstallation features.
CounterExploitation also takes issue with New.net's statement that issues resulting from deletion of New.net files are “no different than the standard problems that can arise when an end-user improperly attempts to uninstall virtually any software application.” The New.net software belongs to a class of software products known as Layered Service Provider (LSP) applications. Due to their low-level integration with the underlying operating system, LSP applications present unique difficulties not characteristic of the vast majority of common end-user software such as office applications, imaging software and media players.
Updates of the New.net Software
This section touts the security features of current versions of the New.net software at length, including the addition of code signing. However, at no point does the CounterExploitation web site state that the New.net client's Web-based update feature downloads or installs unsigned code, nor does it make reference to security issues associated with the installation of unsigned code, such as DNS poisoning or man-in-the-middle vulnerabilities.
This section appears to question the integrity of third-party technical resources referenced by the CounterExploitation web site, including, but not limited to, the Microsoft Knowledge Base. We acknowledge and understand that you are entitled to your opinion. However, CounterExploitation has no reason to doubt the accuracy of information published by these third-party technical resources. Additionally, CounterExploitation is not affiliated with, and does not control the content of, third-party technical resources. If New.net has concerns regarding the accuracy of information provided by third-party sites, we recommend contacting the third-party sites directly to address these concerns.
In closing, we note that your certified letter specifically implies the threat of legal action by notifying us of pending litigation initiated by New.net, Inc. against “an anti-spyware software publisher”, directly followed by the statement that New.net “will not tolerate” the information currently published on the CounterExploitation web site. We take this matter very seriously. In light of this, we have acted to amicably address New.net's allegations in a timely manner by provisionally removing the contested document pending resolution of this matter. We have further agreed to address a number of New.net's concerns by making revisions to the contested document and supporting materials. Such revisions shall not be construed as admissions of wrongdoing or inaccuracy on the part of CounterExploitation.
We feel that this letter has attempted to satisfactorily address each of the concerns expressed in New.net, Inc.'s letter dated March 12, 2004. An updated version of the contested materials will be submitted for your review within the next seven (7) business days. Please do not hesitate to contact me with any additional information, questions or concerns that you may have. This letter is sent in good faith without prejudice to any of CounterExploitation's rights or remedies in this matter, all of which are expressly reserved.
I look forward to hearing from you soon.
submitted on March 22, 2004,
Timothy R. Gipson
CounterExploitation - www.cexx.org
1The Internet Domain Name System (DNS) standard was created in 1983 by Paul Mockapetris as a platform-agnostic method to replace numeric Internet Protocol (IP) addresses such as “18.104.22.168” with easier-to-remember text strings such as “www.google.com”. One of the original Internet standards, this system stores domain resolution information on thirteen redundant “Root” servers across the globe, which in turn propagate their data to a larger number of secondary servers.
2Similar keyword namespaces have been implemented by companies such as CommonName and the (now-defunct) RealNames. The major difference between these services and that offered by New.net, Inc., is that the New.net namespace structure mimics the structure of the DNS by separating keywords into a “name” and one of a limited number of short “extensions” seperated by a period (“.”).