Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

111–120 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#111

Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.

If you'd just straight up cancel an account that fast I don't believe you had any service or clients hosted on DigitalOcean. Idle threats belong on Facebook and Twitter, not Hacker News.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#112
post #90

Earlier quoted context omitted.

I can think of at least Cloudflare (somewhat), Linode, and Hurricane Electric off the top of my head. Anybody who operates a well-known ns1 type of resolver. It's more a problem with zone hygiene than hosts, honestly.

Cloudflare does something similar to AWS. Each user gets different nameservers

Is that true? The nameserver I was given by CloudFlare is "nelly.ns.cloudflare.com". From some cursory searches, it seems like a large number of domains have that same nameserver. AWS nameserver hostnames have all kinds of numbers in them that seem a lot more like they're generated per user.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#113
post #30
post #19

Earlier quoted context omitted.

Do you know of an alternative that can host an instance of FreeBSD?

I believe Vultr offers FreeBSD (and custom ISO) hosting at about the same price and offers storage servers too. Their documentation and remote console tools leave a lot to be desired though (I wanted to install openSUSE and ended up resorting to manually entering the iPXE commands at a console to get the damn thing installed).

Looking at their DNS setup workflow[1] and API functions[2] I don't see any step where you would have to verify domain ownership - which is this whole thing is about, isn't it?

[1] https://serverpilot.io/community/articles/how-to-configure-d...

[2] https://www.vultr.com/api/#dns

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#114

Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.

You don't need to make a deletion request, you can deactivate your account from your account settings, and it offers to delete everything for you. That's what I did when I wanted to close my account recently (I wasn't using the droplets I had, and liked my other VPS better anyway.)

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#116

Amazon S3 has similar problems. To host static website you need use your domain name as the S3 bucket name. Amazon does not verify ownership of your domain, and bucket names use global namespace. Someone can easily block you from using S3 static website hosting by adding a bucket with your domain name before you do. Also if you delete a bucket and do not change your DNS, someone can recreate the bucket and will be se…

EDIT: Just tested it and looks like I'm wrong. Proxying with CloudFlare doesn't help either... Looks like I may have done this with CloudFront instead?

That's not correct. The S3 bucket name is always prefixed. The format is: bucketname.region.amazonaws.com.

https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteHosti...

To clarify, you're going to have to add a DNS record either way. Doesn't matter what you call your bucket. And no, you don't need to put CloudFlare in front of it for this.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#117

Earlier quoted context omitted.

Meh the owners of the domains gave up control by pointing to someone else's nameservers.

You've just condemned 99% of domains. You really think that's reasonable?

Huh? 99% of domains point to some nameserver they aren't contracting service? That is, 99% have invalid NS?

(Obviously when I say somebody else's NS I mean a NS they have zero reason to think would respond with correct records. Obviously not talking about outsourcing DNS hosting.)

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#118
post #90

Earlier quoted context omitted.

Cloudflare does something similar to AWS. Each user gets different nameservers

Is that true? The nameserver I was given by CloudFlare is "nelly.ns.cloudflare.com". From some cursory searches, it seems like a large number of domains have that same nameserver. AWS nameserver hostnames have all kinds of numbers in them that seem a lot more like they're generated per user.

It's not true at all, no. I got "dan" on two or three different accounts.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#119
post #110

This same thing happens with CloudFlare & is being actively exploited. We reported it to them within the last two weeks and we were told that it's expected behaviour and that they weren't going to do anything about it. I asked them to, at the absolute least, send an email notification to the prior-CloudFlare owner letting them know that the domain "your CF account used to control is now being controlled by a new CF a…

> according to CF, it's not an issue...?! According to CloudFlare, they are are a reverse proxy, and they are not responsible for anything. This has been their response to every issue that I've tried to bring up with them over any channel, including here on HN. CloudFlare just doesn't care.

But I read on their blog that they are saving the internet, like, everyday and twice on Sundays!

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#120

This same thing happens with CloudFlare & is being actively exploited. We reported it to them within the last two weeks and we were told that it's expected behaviour and that they weren't going to do anything about it. I asked them to, at the absolute least, send an email notification to the prior-CloudFlare owner letting them know that the domain "your CF account used to control is now being controlled by a new CF a…

[deleted]
Post reply on HN