Industry News

The Heartbleed Bug – What’s going on!?

Heartbleed Bug

Image Source: Mashable.com

The internet is abuzz with reports on the Heartbleed Bug and how it could be one of the biggest security threats the Internet has ever seen. Earlier this week, security researchers announced a security flaw in OpenSSL (a popular data encryption standard) that gives hackers the ability to extract massive amount of data from the services that we use every day and assume are mostly secure. The bug has exposed the potential vulnerability on any machines powering services that transmit secure information, like Facebook and Gmail.

At LogicBoxes, we have already implemented remedial measures so as to secure the Businesses of our Partners from any further security threats due to this bug. In this blog post we’ll take you through:

  • What is the Heartbleed bug?
  • What steps are we taking?
  • What steps should you be taking?

What is the Heartbleed Bug?

Heartbleed is a flaw in OpenSSL, the open-source encryption standard used by majority of sites on the web to encrypt transmitted data that users want to keep secure. It basically gives you a “secure line” when you’re sending an email or chatting on IM. Encryption works by making the data that is sent, look like illogical to anyone but the intended recipient.

Occasionally, one computer might want to check that there’s still a computer at the end of its secure connection, so it will send out what’s known as a “heartbeat,” a small packet of data that asks for a response.

Due to a programming error in the implementation of OpenSSL, the researchers found that it was possible to send a well-disguised packet of data that looked like one of these heartbeats to trick the computer at the other end of a connection into sending over data stored in its memory.

How bad is that?

It is really bad. Web servers can keep a lot of information in their active memory, including usernames, passwords, and even the content that users have uploaded to a service. This flaw, however, has worse implications as it makes it possible for hackers to steal encryption keys – the codes used to turn gibberish encrypted data into readable information. With encryption keys, hackers can intercept encrypted data moving to and from a site’s servers and read it without establishing a secure connection. This means that unless the companies running vulnerable servers change their keys, even future traffic will be susceptible.

What steps are we taking?

The security of our Partners and their customers is our top priority. We began addressing this issue immediately upon disclosure and have successfully applied patches to all of our platforms. The likelihood that private information was compromised is very minimal due to the lack of a public exploit at the time of the disclosure.

We have updated the OpenSSL packages installed on all our Linux shared hosting servers. We have also re-issued Digital Certificates on affected web servers after moving to a patched version of OpenSSL.

As always, we will continue to work to protect the security of our Partners and their data.

What steps should you be taking?

The Heartbleed bug makes it practically impossible to detect history of abuse, but to be on the safer side, we strongly recommend that you change your Account passwords and also notify your customers to change their passwords. Not just that, we suggest that you should also change your passwords at other 3rd Party Services like Gmail, Facebook, etc.

For Partners selling Hosting and/or SSL certificates through us:

  • If you / your customers have purchased both Hosting and SSL Certificates for an installation from LogicBoxes, follow steps 1 and 3 below
  • If you / your customers have purchased Hosting from LogicBoxes and have SSL enabled on it with an SSL Certificate from a 3rd party vendor for your installation, follow steps 2 and 3 below
  • If you / your customers have purchased SSL Certificated from LogicBoxes but host with a 3rd party provider, follow step 1 below and reinstall the Certificate according to the instructions of your hosting provider
    1. Re-issue the SSL certificate from the OrderBox control panel by referring to the steps mentioned in the following KB article : http://manage.logicboxes.com/kb/servlet/KBServlet/faq1094.html
    2. Contact the SSL Certificate vendor to re-issue the SSL certificate. Once the SSL certificates are re-issued, you will need to install the new certificates under the hosting packages
    3. Install the reissued SSL Certificate by following the instructions relevant to you from the below options:
  • Also, partners reselling Hosting through us can use the force password reset option in WHM to ensure that all your hosting customers change their passwords

For Partners using LogicBoxes API:

We strongly recommend that you regenerate your API key by logging into your Control Panel and navigating to Settings >> API and clicking on the ‘Regenerate’ icon to get your revised API key. Update your API calls to use the new key.

Further Reading

If you are a Logicboxes Partner and require any further information regarding the Heartbleed Bug, please feel free to get in touch your Account Manager.

That’s it for our update on the Heartbleed bug. Have something to add to this post? Do share it in the comments.

Events

Meet Us @ WHD.Global 2014 in Germany!

WHD-2014

As is the case every year, we’re looking forward to attend WHD.Global 2014 at Rust, Germany from 1st to 3rd April, 2014. The conference is one of the biggest Hosting events of the year, giving everyone in the community an opportunity to meet & greet in person!

Siddharth, Clifford and Eeshaan will be present at the LogicBoxes Booth (A14) to meet Web Hosts and discuss business strategies to further boost their Hosting Business. Web Hosts can learn about the new LogicBoxes’ Elite Reseller Program – a new offering designed exclusively for web hosts that have sharp business trajectories.

Also, Siddharth will be presenting a talk on “5 insights about new gTLDs that will give web hosts an unfair advantage” on the 2nd day of the conference at 3.45 pm (local time). If you’re a web host looking to boost hosting sales, we suggest that you attend this talk!

We recommend that you schedule a meeting with us today to ensure that we can allot dedicated time for you.

Looking forward to meeting you in Germany!

P.S.: In case if you haven’t registered for the conference yet, feel free to use our free coupon code SM51VRO & gain free access to the entire event!

Articles, Voice of LogicBoxes

The Voice of LogicBoxes – Vol. 6

The Voice of LogicBoxes – Vol. 5

Hello folks! Welcome to the 6th edition of the Voice of LogicBoxes.

2014 has begun with a bang with 100+ New gTLDs being added to the root already – and there’s hundreds more in the pipeline this year! We’ve also put our best foot forward in keeping up with these developments!

Since the previous Voice of LogicBoxes post, we’ve introduced numerous new gTLDs and are integrating more by the week! We’ve also made several new product launches and upgrades to OrderBox, including the ICANN 2013 RAA compliance updates. We also ran a host of webinars for our partners to educate them about the ICANN 2013 RAA and the overall New gTLD Opportunity.

Here’s more details on all the updates from LogicBoxes over the past few months. Happy Reading!

 

NEW PRODUCT & SERVICES

1. Domain Names

    • New gTLDs are here! – LogicBoxes has been one of the first service providers to integrate with most of the New gTLDs as soon as they’ve launched. You can find the complete list of New gTLDs that are currently LIVE on OrderBox and those that will be launched soon on our New gTLD Calendar.

 

  • Premium Names – As one of our most anticipated launches, the Premium Domains feature went LIVE on OrderBox giving our partners the opportunity to offer secondary market domains to their customers

 

2. Web Products

    • Enterprise Email – We’ve launched a new & powerful email product meant for enterprise consumers & power users. The aptly titled ‘Enterprise Email’ is a powerful & secure email and collaboration suite and is also a wholesome communication tool. Follow the link for complete details on Enterprise Email

 

    • VPS Hosting – As a part of our constant drive to upgrade our Web Hosting infrastructure & services to cater to all types of users across the world, we’ve also launched VPS Hosting. Our VPS Hosting comes with industry-leading Control Panels like WHM/cPanel, WHMCS Client Management, Virtuozzo, etc.

 

  • Hong Kong Hosting – We’ve also launched Single Domain Hosting and Multi Domain Hosting in Linux & Windows flavors on Hong Kong Servers. Our Hong Kong Hosting Plans & Pricing aim to enable our Partners to be competitive and profitable while offering a markedly superior product in the Asian Markets

 

SYSTEM UPDATES

 

    • Profit%-based pricing – This was one of the most asked-for features by our partners and we’ve been more than happy oblige. Profit based pricing allows Registrars and Resellers on OrderBox to set selling prices for TLDs based on the profit % margin they wanted to make in 3 simple steps

 

    • Changes to ERRP – In order to comply with ICANN’s implementation of Expired Registration Recovery Policy (ERRP), we made certain updates to OrderBox. Two new e-mails have been introduced in the system for the pre as well as post expiry notifications mandated by ICANN

 

    • Disaster Recovery Setup for Control Panel – As part of our continuous endeavor to better our system, improve stability and increase redundancy, we’ve set up passive servers for all OrderBox Control Panels. In case of a network failure, an attack or any such unforeseeable disaster, OrderBox will be seamlessly transitioned to the mirror instance ensuring that our partners get maximum uptime, and can run your business smoothly in a hassle free manner

 

    • Alipay Payment Gateway integrated – Alipay, one of the most popular and trusted online payment gateways, has been integrated on OrderBox. Our partners can now accept payments from resellers and customers through this online payment gateway

 

    • Verifying Registrant Contact Information – As per the ICANN 2013 RAA, Registrars are required to verify the contact information for the Registrant contact of each gTLD domain name. To help our Registrars fulfill this obligation, we’ve developed the capability to verify the email address of the Registrant contact. We’ve also implemented mechanisms to handle situations where Registrants don’t verify these emails. All in all, major updates have been made to OrderBox in order to comply with the ICANN 2013 RAA!

 

  • SuperSite 2 Enhancements – In order to deliver a superior SuperSite experience to our Partners and their Customers, we’ve made further enhancements to our SuperSite2. Our latest upgrades have focused on enhanced functionality, better UX and unparalleled performance. To find out more about all the changes to the Supersite, please read our blog post

 

EDUCATIONAL WEBINARS FOR PARTNERS

In order to educate our partners about the ICANN 2013 RAA and New gTLDs, we held 2 webinars in the month of November.

    • Webinar fon ICANN 2013 RAA Impact – The webinar highlighted the new changes in the ICANN 2013 RAA and outlined the measures that Registrars need to take in order to comply with the changes.

 

  • Webinaron on Leveraging the New gTLD Opportunity – The webinar gave an overview of the entire New gTLD program introducing major New gTLD Applicants and process of integrating their TLDs. It also covered the list of activities that LogicBoxes is doing to give all the tools our partners will need to leverage the New gTLD Opportunity.

 

FIRST TIME IN THE INDUSTRY

 

  • Registy Wallet – The Registry Wallet is a first-in-the-industry all-encompassing solution for our Registrar Partners to manage billing and financial transactions with various Registries. Our Registrar Partners now have to manage funds only with one entity (us) and we take care of the leasing with all the Registries for managing funds in their accounts. We believe the Registry Wallet will be a great resource for all our Registrar Partners, especially with the advent of 1000+ gTLDs. Follow the link for complete details on Registry Wallet

 

As for the immediate future, we’ll be launching Dedicated Hosting by the end of this month. Also, we’ll continue to integrate with New gTLDs as and when they launch. We recommend you follow us on Twitter and Facebook to stay updated on all activities at LogicBoxes and also on all important Industry news.

That’s it for this edition of the Voice of LogicBoxes. If you have any queries about the same feel free to comment and let us know!

Events

Meet us at ICANN Singapore!

ICANN Singapore

It’s ICANN time! The community is heading back to Singapore for the first ICANN Conference of 2014. At the previous Singapore meet, the ICANN board passed the historic decision to open up the Internet to New gTLDs. This time around the community will convene with over 100 New gTLDs delegated and about 200,000+ domains already registered on these New gTLDs. It’s a testament to all the hard work put in by the entire ICANN community. As an active stakeholder in the ICANN community, we’re really excited to be present at the conference!

At the conference, Siddharth Taliyan and Rahul Raghunathan will be available at the LogicBoxes booth to meet New gTLD Applicants and discuss business strategies. New gTLD Applicants can learn about our Exclusive Market Access Solutions For gTLD Registries and Vertical Integration Solutions for New gTLDs. In case you wish to schedule a one-to-one meet with us at the conference, you can do so at our schedule a meeting page.

So if you’re around at the conference do feel free to drop by our booth to say Hi! Looking forward to meet you at ICANN Singapore!

Press Releases

Dot Desi Reseller, LLC selects LogicBoxes’ Vertical Integration solutions for the .desi gTLD

dotDesi

We are pleased to announce that we have been chosen by Dot Desi Reseller, LLC (an affiliate of Desi Networks, LLC Registry for .desi gTLD) to manage their wholesale and retail infrastructure and provide marketing assistance.

.desi is a new gtld for businesses, brands and individuals belonging to the Desi Community, which is vastly spread across the world.

As part of the deal, LogicBoxes will provide a custom Vertical Integration solutions package. We will help Dot Desi Reseller, LLC setup its exclusive Flagship retail store powered by our domain distribution and business automation SaaS platform, the Orderbox. We will also help it to establish and manage a specialized global .desi reseller affiliate network.

We will integrate the TLD on priority basis on the LogicBoxes platform, as a result, opening access to our network of 100+ Registrars and 100,000+ Resellers and eventually a global base of 4 million customers. The LogicBoxes team will also provide personalized business & marketing assistance to strengthen the Reseller’s efforts.

“The .desi community is unique in a way that while there is concentration in a few regions, we have potential buyers widely distributed across the world. LogicBoxes’ comprehensive package perfectly fit our unique needs; brilliant marketing solutions to help gain traction with relevant audiences, outreach via their extensive existing global supply chain, and a superb automation platform; a clear winner for us. We also deeply value the extensive domain industry experience they bring to the table,” said Ravin Ohri, CEO at Dot Desi Reseller, LLC.

“We were impressed with their knowledge about the industry, their vision for the .desi gTLD and their strong dedication to give back to the .desi community,” said Siddharth Taliyan, Manager of Sales at LogicBoxes, “We are indeed very proud to be their partner and are honored to have the opportunity to support their venture.”

About Dot Desi Reseller, LLC
Dot Desi Reseller, LLC is an affiliate of Desi Networks, LLC which was formed in 2011 for the purpose of operating the .desi gTLD. The Dot Desi Reseller, LLC will create a reseller channel and offer a platform for registrants to obtain .desi domains; thus, enabling desi people and diaspora to interact in a more personal way and bringing the community together without restriction to a geographic location. For more information on the .desi New gTLD, please visit: http://dotdesi.com/