Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

171–180 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#171

Earlier quoted context omitted.

The change was made a year prior. It was not communicated via email. That email you received was a reminder. We only put up a notification in the control panel. That was the communication failure, and I apologize for it. At no point should anyone be advising you to take legal action to retain your credit, and I would be grateful for the opportunity to review the ticket in question.

> The change was made a year prior. Why did I not receive any notification? A change in contract of that magnitude should have led to me being directly notified per email or other communication methods, so that I’d actually have a chance at still using the credit. This way, you notified me right when the credit ran out, which was extremely shady, and I’ve met hundreds of others with the same issue in IRC when you inv…

>I had had the credit on my account for over 2 years by that time, but hadn’t used it.

>A change in contract of that magnitude should have led to me being directly notified per email

It seems to me the credit is a form of charity for students, and you had not bothered to redeem it for 2 years. Now, you seem to be implying that DO is acting in an evil manner for only alerting you to the change via the dashboard (which the DO rep in this thread admitted was poor execution on their part). I don't think you are being charitable, and I think the underlying assumption you are making almost sounds conspiratorial.

I'm not a DO customer, and don't have any affiliation.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#172
I don't think that setting up custom DNS for everyone as suggested by the author is quite as simple as it sounds.

It's not enough to just come up with the custom nameservers. In order to use them in most TLDs they also need to be "registered" with the registry that operates the TLD.

So let's say you have myDNSdomain.com. You get a new customer who owns NewCustomer.com and wants to you your DNS, so you create these nameservers for them:

ns237.myDNSdomain.com ns2323.myDNSdomain.com

In order for your new customer to be able to use those on their NewCustomer.com domain, you will need to go to your registrar and set up these nameservers. The registrar will then create the corresponding nameserver records with Verisign, the registry. Only then, the customer will be able to use the nameservers on his domain.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#173
post #110

Earlier quoted context omitted.

> according to CF, it's not an issue...?! According to CloudFlare, they are are a reverse proxy, and they are not responsible for anything. This has been their response to every issue that I've tried to bring up with them over any channel, including here on HN. CloudFlare just doesn't care.

not at all accurate. If you find something abusive or malicious report it: cloudflare.com/abuse -- every report filed there is reviewed by a human.

It seems that this is getting downvoted, and I want to explain why I agree with the downvotes:

The policy on that web page has two egregious issues.

1) It does not have any provisions for SPAM. I regularly get e-mail SPAM that has CloudFlare-protected links. That abuse page does not even apply. Effectively, CloudFlare offers spammers a 'pink contract'.

2) CloudFlare has a reputation for ignoring abuse, and that page effectively says nothing about whether abuse will be stopped; that page only offers to transmit the personal information of someone who reports abuse off to an abuser. This is not a theoretical; this has happened in the past, and the personal information of someone who reported a site that contained child pornography was then posted all over the net for its users to begin harassment with.

So if you find something abusive or malicious, your best bet really is not to report it. CloudFlare won't act, other than to put you at risk.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#174

I don't think that setting up custom DNS for everyone as suggested by the author is quite as simple as it sounds. It's not enough to just come up with the custom nameservers. In order to use them in most TLDs they also need to be "registered" with the registry that operates the TLD. So let's say you have myDNSdomain.com. You get a new customer who owns NewCustomer.com and wants to you your DNS, so you create these na…

Well, yeah. That process already happens when you set up your domain to use DigitalOcean, but the nameserver used during the setup isn't unique.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#175

Earlier quoted context omitted.

They changed their ToS a year before, you got a notice to review them. What's illegal about revoking promotional credit? https://www.digitalocean.com/company/blog/details-on-expirin...

No, they changed their ToS in March, and invalidated all coupons older than April of the year before by April. That left me just 2 weeks. And what’s illegal is that in Germany, promotional credit or coupons given without a time limit is valid for at least 3 years.

Here are their terms from March 2015: http://web.archive.org/web/20150309163745/https://www.digita...

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#176
post #110

Earlier quoted context omitted.

> according to CF, it's not an issue...?! According to CloudFlare, they are are a reverse proxy, and they are not responsible for anything. This has been their response to every issue that I've tried to bring up with them over any channel, including here on HN. CloudFlare just doesn't care.

not at all accurate. If you find something abusive or malicious report it: cloudflare.com/abuse -- every report filed there is reviewed by a human.

I don't care whether it's reviewed by a human or not, the fact remains that CloudFlare does not act on abuse reports because they claim "reverse proxy = not responsible" in every abuse report I've sent them even on matters that do not pertain to their reverse proxy functionality at all.

They just don't want to be responsible, and unlike any other large network service provider that I sent abuse reports to, they just try and deflect and keep servicing spamming and phishing operations instead of booting them from their systems.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#177

Earlier quoted context omitted.

> The change was made a year prior. Why did I not receive any notification? A change in contract of that magnitude should have led to me being directly notified per email or other communication methods, so that I’d actually have a chance at still using the credit. This way, you notified me right when the credit ran out, which was extremely shady, and I’ve met hundreds of others with the same issue in IRC when you inv…

>I had had the credit on my account for over 2 years by that time, but hadn’t used it. >A change in contract of that magnitude should have led to me being directly notified per email It seems to me the credit is a form of charity for students, and you had not bothered to redeem it for 2 years . Now, you seem to be implying that DO is acting in an evil manner for only alerting you to the change via the dashboard (whic…

Yes, I had not redeemed it, because, as a student, I was trying to save it up knowing I’d want to do a project where I’d require servers during summer break between 2nd and 3rd year of my undergrad degree.

The credit was invalidated 3 months before that.

With the legal 3 year validity period of promotional credit and coupons that German law guarantees, I had expected being able to do that.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#178
post #73

Earlier quoted context omitted.

Adding 20k domains to your account is probably enough to flag as abuse even if you own the domains. Next time the author should probably try just the one or two. Bonus points if they're their own domains.

>Bonus points if they're their own domains. If the service doesn't understand the issue at all, then when you explain that they're your domains, then they'll probably just tell you it's working as intended and that users should be able to add their own domains.

Arseuming makes an arse out of you and me. Give the techies on the other end of security@ the benefit of the doubt on the first go.

When they fail to understand that then feel free to go ahead and pick one that's not yours to prove the point. One though, not 20 thousand.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#179
post #137

Earlier quoted context omitted.

I've reported multiple vulnerabilities to DigitalOcean before and they've fixed them rapidly, credited me for the effort, and gave me free time on their services. The difference is I didn't exploit 20 thousand domains to make flashy headlines and prove a point about something that isn't even a serious bug.

You're coming across as a shill either to make DO seem like an infalliable company or to blatantly astroturf enough to get people to hate DO (See jsmthrowaway's sibling comment). I'm less inclined to believe the latter. I'm looking forward to transferring my domains on DO to elsewhere tonight.

I'm just sharing my experience of what happens when you disclose bugs responsibly.

I'd be happy to share bug tickets with anyone who isn't on some silly chill hunting crusade, for sure, despite my trollish throwaway name.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#180

Earlier quoted context omitted.

I've reported multiple vulnerabilities to DigitalOcean before and they've fixed them rapidly, credited me for the effort, and gave me free time on their services. The difference is I didn't exploit 20 thousand domains to make flashy headlines and prove a point about something that isn't even a serious bug.

More throwaway astroturfing? You say "20 thousand" the same way as your other likely throwaway account, V8OaSsoA (that is to say: somewhat identifiably) and complained about someone ripping off DigitalOcean's Web design on this account. I'm doing math on the throwaways that are oddly attracted to this thread. You are making it very obvious that you are almost certainly a DigitalOcean employee across the two throwaway…

I really doubt DO would hire me. And any admin could look up what you said and disprove it. I'm not using any proxies or VPN.
Post reply on HN