Please do not fall for this scam!
Please do not fall for this scam!
We’re a little late in getting this out, but our office is closed for the season and will reopen on Monday 6 January 2025. Any non-emergent issues will be dealt with at that time; emergency support continues to be available 24/7.
Of course, our servers will continue to be monitored 24/7 for the remaining seven days of the 365 they are monitored this year, not to mention the first six of the next 365. 🙂 That is to say, they are monitored 24/7/365 each and every year!
We wish all of you, your employees, colleagues, families and friends all the best. We thank you for your ongoing patronage, and we look forward to talking to each of you in the New Year. We are pretty excited about what 2025 has in store for NinerNet.
Executive summary: Please pay your invoice on or before the due date!
We are writing this brief post to address a trend we have noticed in recent months. I want to make clear, though, this it does not apply to most of our clients, but it does apply to a significant number of them. However, it’s something everyone needs to know.
The trend is a tendency to leave payment of your invoice until what some people seem to think is an acceptable last minute.
I will admit that I myself have said a few times in the past that you have until the expiry date of your service to pay your invoice. My bad. This does apply to services that are 100% under our control — e.g., shared hosting (not VPS hosting though) — but if you wait until the expiry date of a service that is partially under the control of a third party — e.g., a domain registrar, a certificate authority, etc. — you are taking a big chance if you wait until the expiry date, because the chances are now significant that the service provided by the third party will go offline for a time.
If you look at our “billing procedures” page you will see that we aim to send our invoices on the 15th of the month. I admit that we don’t always meet that self-imposed deadline, but even if we miss it by a couple of days, this doesn’t affect the fact that our invoices must be paid in good time before your services expire. (Please keep a record of those dates and pay attention to our reminder emails.) Let’s look at the first example on that page, with an expiry date of 10 March. If it’s only your shared hosting that expires on that date, you get a one-week grace period (unless you’re in the process of transferring out), so even if you pay a day or two late, your hosting will not be interrupted.
However, if it’s your domain registration that expires on that date, it will go offline sometime on the expiry date between 00:01 and 23:59. So if you pay a couple of days late, your domain will be offline for a couple of days. If you’re one of the few people who don’t mind that, no problem; if you do mind that — as, I believe, most of you do — don’t wait until the last minute! Seriously.
The big however here though is that the registrar we currently use — which has changed names so many times in the last few years it’s difficult to keep track, but they currently go by the names “Team Internet” and/or “CentralNic Reseller” — actually deletes some domains before they expire! We currently know (without being informed in advance, mind you) that they delete dot-africa and dot-za domains two days before they expire. Why? We have no idea. We brought this to the attention of the dot-africa registry (Registry Africa Limited) and the dot-za registry (ZA Registry Consortium (Pty) Ltd.) earlier this year and, while they initially seemed to understand our outrage, six months later they sided with the registrar who is selling 365 days, but only providing 363 days. This is because the registrar has re-written contracts to redefine the term “year” to be whatever they want it to be. (They used to do this with dot-ca domains as well, but when we complained to the dot-ca registry, the Canadian Internet Registration Authority did the right thing and put our registrar in their place and made them comply with the dot-ca domain lifecycle.)
The result is that clients with dot-africa and dot-za domains who thought they had until the day their domains expired to pay their invoice, found that not only did their domains stop working two days before they were supposed to expire, but they also had to pay additional fees to have the registrar “un-delete” their domain, and wait for them to do so. These fees add up to several years worth of renewal fees. This also used to happen to dot-ca registrants until we complained and won that case.
It is also worth pointing out that if you acquired your domain through a “drop catcher” — a company that snaps up expiring domains the moment they “drop” — you also need to ensure that you pay your invoice well before your domain expires, at least a week if you’re paying by an electronic method. This is also because the domain registrar that almost always catches these domains (Network Solutions, aka Netsol) also engages in subterfuge to prevent our normal process of transferring your domain to our registrar, and also charges additional fees that add up to several years worth of renewal fees. If you wait until the day your domain expires to pay your invoice, you will find that we will have to issue a new invoice to you to pay these fees before we can transfer and renew your domain.
But the point of this post — which is much longer than I envisioned — is this: don’t delay paying your invoice until the day your service expires or a day or two beforehand. Sure, if the money sits in your bank account for a few more days, and you’re lucky enough to earn interest on your balance, you’ll earn a few cents or ngwees more, but at the risk you’ll have to pay significantly more dollars or kwachas! Is that worth it? No, it’s not.
Our invoices used to include a “PLEASE PAY BY” date, three weeks after the invoice date. That was our overly polite way (although that’s not the full reason) of describing a due date. Because most of our services are prepaid, and we stopped charging interest on late payments many years ago, we became quite loosey-goosey. However, we have gone back to describing that date as a “due date”, and on that date the clock starts; every day you wait to pay after that date increases the risk that your now-unpaid service will go offline when it expires.
DON’T TAKE THAT CHANCE. PAY BEFORE THE DUE DATE!
Update, 2024-11-25: Clarified that you only get a week’s grace period on shared hosting if you are not already in the process of transferring your hosting out.
This post confirms a mass email we have just sent to a number of registrants of dot-ca domains.
We have decided to change the registrar with which we register dot-ca domains. We are actually returning to OpenSRS; the reasons we left them in 2018 have never really been fixed, but we maintained our account with them because, despite their operational issues, they are a decent registrar that generally tries to do the right thing by dot-ca registrants. Considering the trouble we have had with our current registrar — who go by more names than you can shake a stick at, but they include “CENTRALNIC CANADA INC“, “Team Internet” and “CentralNic Reseller” — this is a significant improvement! The new (old) registrar is, as stated above, OpenSRS, but they also trade under the name of their parent company, Tucows.
We are letting you know that you (as your domain’s owner, or registrant) need to approve this transfer because you ultimately have choice in the matter and have control over your domain. As your domain advisor and host, we recommend that you accept this transfer because it means that pretty much everything will stay the same for your hosting and billing, and the domain renewal you have already paid for will take place at the same time. Additionally, approving this transfer will not interrupt your domain’s service in any way. This is how we continue to serve you and provide our services.
One of the ways in which OpenSRS has not improved — it blows my mind after six years — is that they still can’t seem to decide from which domain they send their emails! You will receive emails from addresses on the opensrs.email and opensrs.org domains. After your domain is transferred you will go back to receiving emails from the “domainsupport” address on the niner.net domain. The initial message will have the subject, “Transfer Request for DOMAIN.CA”, where DOMAIN.CA will be your dot-ca domain. Please click the approve.domainadmin.com link in the message, select the option to approve the transfer and enter your “transfer key”, which we will send to you separately immediately after this message.
After the transfer completes a few minutes later you will also receive confirmation emails from the Canadian Internet Registration Authority (CIRA) using the email address info_AT_cira.ca. All of these messages that you’ll receive around the time you approve the transfer(s) are legitimate, but if you have any questions please do contact NinerNet support.
Thank-you for following these instructions, and thank-you for your continued business.
We no longer invoice our Zambian clients or accept payments in kwachas due to the incompetence of Stanbic Bank. This will change in early 2025 due to our planned change in management structure, which will include banking with a competent Zambian bank. Until then invoices will be issued in US dollars.
We apologize for this temporary interruption.
As our Zambian clients are well aware, we have had nothing but trouble with Stanbic Bank of Zambia this year. Our business account has been locked/frozen multiple times, and it’s a huge hassle to get access again each time. In the meantime we can’t confirm receipt of payments so that we can send receipts to our clients. And we can’t manage our funds to pay bills and so on.
When I was in the country in May 2024 I approached Immigration and let them know that I wanted an Immigration permit for one reason and one reason only: To open a new bank account. I suppose my honesty must have flummoxed the first person I spoke to, so he referred me to a supervisor. The supervisor told me that I didn’t need to go that far (i.e., get a permit just to open a bank account); all I needed to do was talk to his unemployed friend who could “assist” me if I just “bought him lunch”. Of course, we all know what the quoted words in that last sentence mean: bribes.
I was desperate at this point. I joke to everyone I know that all of my grey hair is the result of dealing with Stanbic for the last sixteen years. It may be a slight exaggeration, but it’s not far from the truth. One of these days I will write a book, or at least document sixteen years of torment at the hands of Stanbic on an anonymous blog.
Anyway, considering my desperation I followed the supervisor’s advice and contacted his unemployed “friend”. However, besides the fact that I had no way to know how hungry said friend was planning to be at lunch time, it turned out this guy didn’t know anything about business accounts. So I just gave up and told him where to go.
This is relevant because my grandly named “business banker” at Stanbic decided in about June or July to start their officially sanctioned harassment project on NinerNet, known euphemistically as “KYC”, Know Your Client. It’s completely legitimate, of course, because since I opened our account in 2008 I may have changed my identity, and with the vast sums of money that our clients pay us NinerNet could single-handedly be financing all of the wars in the Middle East, Ukraine, Sudan … on and on the list and our largesse grows. Stanbic harassed us about a year or two ago, and I finally told them that either they could close our account and I would move our business out of the country, stop paying their exorbitant monthly fees, and stop paying taxes to the ZRA … or they could just let us carry on running our legitimate business as usual. I, of course, have no idea how the brain trust that runs Stanbic thinks, but that fended off the harassment.
Until now. Our business banker again made threats that our account would be closed if we didn’t produce a permit, despite the fact that we obviously produced a TP (temporary permit) to open the account in 2008. So the whole reason I abandoned the plan to open a new account back in May was now being forced on us by brainless bean counters at Stanbic. And then one day, we were locked (again!) out of online banking.
We tried to contact our “business banker” at Stanbic, but he was apparently on leave. Please note that when someone is on leave from Stanbic they do not feel the need to shift that person’s work to another employee so that the bank can continue serving their clients; you just have to wait until they get back from the beach to get help. Not satisfied with this, I reached out to another Stanbic employee. Miracle of miracles, I had access to our Stanbic account a couple of days later.
But that was the last straw. We can’t go on wondering from one day to the next if we’re going to have access to our account. We can’t go on wondering if we’re going to have access to our funds, that we have earned from our clients and had paid to us in our account to pay our suppliers. Tying to do business under these conditions is intolerable.
So we have pulled the plug. Starting with our invoices this month, we will no longer be invoicing our Zambian clients in kwachas. We will squeeze the few remaining kwachas in our account out to pay our suppliers — data centres, domains registrars, phone companies, “tax consultants” — and then we will abandon our Stanbic accounts. (What’s the point in jumping through Stanbic’s hoop to close them formally?!) By the end of September 2024 we will no longer accept payments into our Stanbic account. Our September invoices will be issued by our Canadian company and will be payable in US dollars. We are in the process of de-registering NinerNet Communications in Zambia, and we have stopped filing tax returns and paying taxes to the ZRA.
Zambia has won; we admit defeat.
We are not paying billions of kwachas in taxes; we are just a small Zambian business trying to do the right thing. We are trying to run a business that provides excellent service to Zambians, and we are trying to pay our taxes to contribute to the Zambian economy, an economy that is hobbled by ZESCO inflicting load shedding for up to 20 hours a day. (There are only 24 hours in a full day!) In return we are treated like absolute crap by Stanbic, ostensibly enforcing rules that make our ability to carry on doing business impossible. These conditions make it impossible for NinerNet Communications, a Zambian-registered and tax-paying company, to continue doing business in Zambia. And if one Zambian small business is driven out of the country in this manner, it’s only a matter of time before all Zambian small businesses are driven out of business.
We regret that we have been forced into this situation, but we see no other option at this time. In early 2025 NinerNet in Zambia will be reborn under a new management structure, and will again have a Zambian bank account, but not with Stanbic. When this happens we will again be able to invoice our clients and accept payments in kwachas. Until then, though, Zambian clients will be issued invoices by our Canadian company and accept payments only in US dollars, and our Canadian company will pay taxes to the Canadian government and will not pay taxes to the Zambian government.
After a very trying day for many customers around the world that use Microsoft Windows or rely on companies that use Microsoft Windows — like Hotmail/Outlook.com, Office 365, Google Cloud / Compute Engine, Amazon Web Services (AWS), Azure, etc., etc., etc. — we would like to take this opportunity to ensure that our clientele know that we were wholly unaffected by the worldwide chaos.
Is this blog post an opportunistic jab at people who rely on an operating system and company that was late to realise the potential of the Internet? Yes, of course. Why? Well, just look at the trouble that Microsoft gave us last month, and are still giving us today. Microsoft are not our favourite people these days, even though Microsoft themselves weren’t responsible for the Crowdstrike failure.
Hey, we get it, shi … stuff happens. Our status blog currently shows 207 posts in the “incidents” category since 2009. Of course, that’s not 207 failures; at the very most it’s 104 failures if you assume a post announcing an incident and a second announcing it’s over, but in reality some incidents had multiple posts and some posts were only to alert clients to issues with other companies. I’d say that there were far fewer than 100 incidents in fifteen years; feel free to do the maths and check our live uptime monitor for yourself. But one does wonder how an update was pushed out by Crowdstrike without it being tested. That’s just unfathomable. On the other hand, NinerNet doesn’t check every single update we apply to our servers, but we have to rely on our operating system vendors to do that for us. As Crowdstrike customers and their customers found out yesterday, the IT world is very interdependent.
Of course, NinerNet will almost certainly have some major incident in the future, and I know that some will then say that this post will come back to bite us in the ass. Not really. I’m always amused when an incident happens and people say or claim, “We will learn and it will never happen again!” That cracks me up. Incidents — whether they are global IT meltdowns or plane crashes — are almost always human-caused. So yeah, it will happen again, and NinerNet will have some issue at some time in the future and we will learn from it and promise that we will take steps to prevent it from happening again. But we have never and will never claim that it will never happen again.
The other purpose of this post is for marketing. The word “marketing” is a four-letter word to me, simply because about the only skill that marketers have is the ability to lie, with a straight face. I certainly wouldn’t accuse Microsoft or Crowdstrike of any kind of over-marketing or marketing subterfuge but, you know, there’s a part of me that looks askance at claims made by companies that over-promise and under-deliver … and over-promising and under-delivering are pretty much the meat and potatoes of marketers! It is far beyond my remit to determine whether or not either Microsoft or Crowdstrike have ever over-promised or under-delivered, but yesterday under-delivery was rampant.
Update, 2024-07-24: I wasn’t planning to drive home any of my points above, but I was cleaning up some open browser tabs and there were a few Crowdstrike-related tabs still open.
At “Helping our customers through the CrowdStrike outage” Microsoft proudly states, “We currently estimate that CrowdStrike’s update affected 8.5 million Windows devices, or less than one percent of all Windows machines.” Umm, so? Your point is? What they fail to state here is that those 8.5 million Windows devices affected many, many more millions (a billion?) of poor saps who rely on companies that rely on Crowdstrike that relies on Microsoft’s crappy operating system. It reminds me of a saying: “Figures don’t lie, but liars sure as hell can figure!”.
George Kurtz, CEO of Crowdstrike, also stated in a tweet, “Today was not a security or cyber incident. Our customers remain fully protected.” This statement is freaking hilarious! If you can’t turn on your “Windows device”, of course it’s “fully protected”! OMG, this is one for the comedy annals!
Browsing through Mr. Kurtz’s Twitter feed you see a lot of the aforementioned “marketing”:
* Wow… another great quarter in the books for $CRWD.
* $CRWD delivered a strong 2Q23 with record $218M net new ARR, $2.14B ending ARR, record net new customers & $136M free cash flow.
* $CRWD delivered record Q4 results.
*yawn*
Based on the current value of the Zambian kwacha in US dollars and recent trends, we are decreasing our retail kwacha prices effective today and until the next quarterly review by about 7%. The base USD rates remain the same, as do our kwacha rates for the Zambian TLDs, dot-zm and dot-zam.co.
Some sample rates:
Our new kwacha rates will be online within 24 hours. We are very sorry that this review is so late this quarter.
Due to a number of factors this month, our invoices are about as late as they have ever been, for those of you who are being invoiced this month.
As is often the case when things don’t go right, there wasn’t any single factor that caused this; it was the result of a number of factors, not the least of which was the considerable amount of time we spent dealing with the block of our mail server implemented by Microsoft. You know how important working email is to you, and it is not lost on us how important email is to you and therefore our business. So we literally dropped almost everything (including this month’s invoicing!) to deal with and mitigate the problem caused by Microsoft. In fact, on 28 June (Friday) we updated our blog post about this at:
NC036: Significant issue with delivery of email to Microsoft-hosted domains
You’ll find the update at the bottom of the post with Friday’s date on it in bold. The situation now is essentially that we are back to where we were before Microsoft started bouncing mail to domains they host on 20 June; in other words, to use the term used by some of you, the situation is “resolved”, and we’re back to dealing with individual bounces as necessary. Email bounces sometimes; it’s a fact of life. It’s the email system’s feedback loop to ensure that you know what has happened to an email you send if it wasn’t delivered as you expect. No news is generally good news, as that means your message was delivered, and now you’re waiting for the human on the other end to reply.
Also in the last two weeks we’ve had to address situations with two clients that were expecting different outcomes on issues they had brought to our attention; one of them has been dealt with as far as we can at this point, and the other will be dealt with right after our invoices go out shortly. We apologise to both clients who had to deal with the fact that we couldn’t give them as much attention as quickly as we usually do when clients need us. As of a couple of hours from now, everything will be back to normal, and we thank those clients and all of you expecting invoices on 15 June for your patience.
The date on our invoices will be 28 June (the most recent business day this month), and the suggested pay-by date is 19 July. However, if you are being invoiced this month please pay close attention to the expiry dates of your services and/or domains, as if they are before 19 July you do either need to pay your invoice before the earliest expiry date noted on your invoice, or contact us to make arrangements to ensure that we are aware that you will pay your invoice so that we renew your domains or services so that they stay online. Those of you who are again scheduled to be invoiced on 15 July will see your June balance carried forward, if you haven’t paid your June invoice yet, but since we don’t charge interest on unpaid balances this will not negatively affect anyone.
We apologise for making you do so much reading lately, and I can assure you that we work very hard to ensure that our systems run as close to 100%, 100% of the time as possible. We’ll never reach 100%, 100% of the time — nobody does, even Microsoft and Gmail — but the closer we can come to that goal, the easier your life is and the easier our life is.
Thank-you, as always, for your patience during troubling times. If you have any questions or feedback, please do contact NinerNet support.
Please be advised that there is a phishing message getting through the spam filters with the subject:
Oops, Error updating the POP/IMAP server of YOUR-DOMAIN.TLD
In the actual email, “YOUR-DOMAIN.TLD” just happens to be the domain of the email address to which the scam was sent (see screenshot below). (What a coincidence!) These are not sent by NinerNet, as even a cursory look at the “From” field will show. We also do not use folksy words like “Oops” in business and technical emails, and we don’t pose as the “webmaster” of your domain. We are NinerNet, and that is how we always present ourselves to you, our client.
If you click the button to “Update Preferences” (or whatever action your copy of the message urges you to take) — which we strongly urge you not to do! — you will be taken to a page that looks like the log-in page for a webmail system (not our webmail system, I hasten to emphasise!), where the scammers expect that you will enter your email log-in information. Your log-in will fail, of course, but you will have given your real email password to the scammer, who will then use it to hijack your account.
If you or someone in your organisation falls for this, change the password for that account immediately! It’s not shameful to fall for a scam; many are convincing and we are all busy people who sometimes do something we regret when we are busy and distracted. What is important is that you recognise what has happened and take action to prevent any further damage.
Please be aware of and do not fall for these types of messages! The spam filter has been catching a lot of these types of messages lately, but the casual language of this one seems to be defeating our spam filters.
Please ensure that your employees, colleagues and other associates know about these scam messages. You should also remind yourself and your employees, colleagues and associates of the information on our website at the following links:
Thank-you for your time and attention to this vitally important matter. Please contact NinerNet if you have any questions.
Subscriptions:
General Information:
Search:
Recent Posts:
Archives:
Categories:
Tags:
Resources:
On NinerNet: