Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

61–70 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#61
post #4

this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.

Fair point, my relucatance to stop was mainly due to companies usually disreguarding reports unless I have strong proof. Stopping short of the full scope would've left it up to speculation as to the full amount of vulnerable domains. It was my plan to delete the domains (or at least null route them so others couldn't take them over with more malicious intent). However my account was banned before I could do so.

That turned out to indeed be the case after their first response :/

How would it have ended if you hadn't reached out to one of their security people after being banned? They'd have given you the traffic, locked your account, and congratulated themselves on a job well done?

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#62
Banning his account was totally unjustified since he approached them first with the issue. A less ethical person could have tried to make money or sold this off on the back market. People like him should be rewarded not have their accounts banned. For all we know he just saved DO a lot of headache in sorting this issue had it gone wrong. I really wish the response from DO on this was different.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#63
post #59

Earlier quoted context omitted.

You've just condemned 99% of domains. You really think that's reasonable?

I do think it's reasonable. If the domain is added to the account there is no PoC, it's only for domains that have been removed from accounts but still have the nameserver values(meaning the domain is not being used at this point, there's no zone file if it isn't added to an account). So this is mostly only going to affect currently derelict domains. I'm not saying it isn't something to worry about, but I do think it…

What you just described as reasonable is not the scenario I asked about, which is just "pointing to someone else's nameservers".

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#64
post #6

This doesn't help my impression of Digital Ocean at all (even if I am a paying customer currently). A few years ago you could impersonate Digital Ocean staff on their support pages with no effort. They grabbed the username from your email, so whatever you put in front of the @ becamse your username on the forums, visible to everyone. And the avatar came from one of those email->avatar services where you can sign up a…

I can think of at least Cloudflare (somewhat), Linode, and Hurricane Electric off the top of my head. Anybody who operates a well-known ns1 type of resolver. It's more a problem with zone hygiene than hosts, honestly.

This seems like a great candidate for an ACME style protocol.

I would totally support the ACME spec being expanded to cover this, and various other domain verification related issues

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#66
post #19

Earlier quoted context omitted.

Do you know of an alternative that can host an instance of FreeBSD?

TransIP is similar to DO (except they've had large storage for years) and they support FreeBSD. I've been a happy customer for a couple of years now, never had any problems. https://www.transip.eu/

Yeah me too.. However, transip only has a dutch dc.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#67
post #35

I think most of the providers (e.g. DO, Linode, CloudFlare etc) do not check the authority of DNS due to the chicken-and-egg problem. The AWS way to handle this issue is definitely awesome but the infrastructure required is not worth for those companies who are providing "free DNS service" as an add-on to their existing customers. Anyway, IMO, it is your fault if you point to a nameserver but not utilizing it.

The random nameservers are only accidentally a defense against this attack. They're avoiding SPOFs, including TLDs -- you never receive nameservers in the same TLD for example. It's a reliability and scaling consideration with this accidental benefit. Most admins don't think about a complete TLD failure. Amazon did.

>> accidental benefit.

Agree

>> Most admins don't think about a complete TLD failure. Amazon did.

I think companies such as Google or Facebook did think that before, but I am not sure why they didn't follow this trick.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#68

Earlier quoted context omitted.

I can think of at least Cloudflare (somewhat), Linode, and Hurricane Electric off the top of my head. Anybody who operates a well-known ns1 type of resolver. It's more a problem with zone hygiene than hosts, honestly.

This seems like a great candidate for an ACME style protocol. I would totally support the ACME spec being expanded to cover this, and various other domain verification related issues

Or just claim your domain if you point it at a DNS service..

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#69

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

I have an account with DigitalOcean (and several competitors) and I'm not going anywhere or moving any sites around because of this. Sure, they could have handled things better and the security researcher could have too. I don't see any malice or incompetence here, nor do I see a reason to make the effort to switch to another provider. Where are you going to run off to? How is their security better over there? How ma…

Allowing adding a domain without verifying ownership, and banning someone who reported a security issue isn't incompetence?

I think you're looking more kindly on their security practices than most folks in the security world would.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#70
I find myself asking WW$D where $ is any large tech company with a "good" reputation. What would Google have done? Lyft? Spotify? Blizzard? Use some imagination to apply a similarly dangerous security breach to these companies.

I feel like this question yields better context to ethical arguments because it makes us aware of the cognitive biases and view things from a more abstract perspective..

EDIT: Is there a way to include plain asterisks in HN posts?

Post reply on HN