Little Snitch just caught Parallels attempting to connect to ftp1.parallelz.com. I've manually verified that it is indeed Parallels' update feature by forcing an update check and having Little Snitch catch the event again. I did both a forward and reverse host for both domains, as well as a dig at their nameservers. I also checked both whois records of parallels.com and parallelz.com, and although the registrant address is different (one in Russia, one in Virginia), everything else matches,
My question is: Why would you set your update host to be one of your domain aliases, rather than a duplicate of your online presence? While useful for redirecting people to the proper spelling online—indeed, this is exactly what typing parallelz.com in a browser does—use of it in an official update capacity engenders wariness and the sense that somehow, someone is trying to fool you, like your Parallels machine has been infected or has a backdoor.
It's like getting a software update popup that says appel.com instead of apple.com
My question is: Why would you set your update host to be one of your domain aliases, rather than a duplicate of your online presence? While useful for redirecting people to the proper spelling online—indeed, this is exactly what typing parallelz.com in a browser does—use of it in an official update capacity engenders wariness and the sense that somehow, someone is trying to fool you, like your Parallels machine has been infected or has a backdoor.
It's like getting a software update popup that says appel.com instead of apple.com