So, the real question is: "How much should we freak out about this?" If you scroll back a few months to Cloudbleed/Cloudflare we sort of collectively decided that because cache data containing sensitive info (passwords, tokens, whatever) might be accessible for your site using Cloudflare that everything should be revoked, force password resets, etc. Now we have this vuln, which I'll dub "IOgate" because it's the cool…
Taking control of all .io domains with a targeted registration
31–40 of 258 posts
Re: Taking control of all .io domains with a targeted registration
#32Since you're getting political there for no reason at all, let me say this: might is right. Get over it.
Re: Taking control of all .io domains with a targeted registration
#33This is a huge screwup on the part of the people who run the 'root' of .IO, and their entire operation should be severely scrutinized by ICANN. In my opinion almost all of the 'weird' TLDs which are country codes that are actually operated by a third party commercial service are 95% spam and junk registrations. .TV is a good example. Technical screwups aside, the existence of .IO and the fact that it "belongs" to the…
Re: Taking control of all .io domains with a targeted registration
#34>Technical screwups aside, the existence of .IO and the fact that it "belongs" to the UK government is morally questionable, since the entire country code only exists because the British and American militaries forcibly removed the original inhabitants of islands such as Diego Garcia so that they could use the area as naval and air force bases. Since you're getting political there for no reason at all, let me say thi…
Re: Taking control of all .io domains with a targeted registration
#35Earlier quoted context omitted.
Bad actors are on those mailing lists too. What you describe would be the equivalent of mailing fulldisclosure with "Hi all, there might be more unregistered nameservers at .IO (or another 101domains-serviced TLD) that could be used to attack live traffic if anyone wants to grab those, kthx"
I'm fine with that happening, because the people who run .IO need to be spanked. If their customers are subsequently unhappy that their domain names have been hijacked, they can take it up with whatever corporate entity runs .IO. Same problem as publicly disclosing serious flaws with an SSL/TLS root CA.
Re: Taking control of all .io domains with a targeted registration
#36So, the real question is: "How much should we freak out about this?" If you scroll back a few months to Cloudbleed/Cloudflare we sort of collectively decided that because cache data containing sensitive info (passwords, tokens, whatever) might be accessible for your site using Cloudflare that everything should be revoked, force password resets, etc. Now we have this vuln, which I'll dub "IOgate" because it's the cool…
Well, if it's any consolation.. the domains weren't registered..
Re: Taking control of all .io domains with a targeted registration
#37So, the real question is: "How much should we freak out about this?" If you scroll back a few months to Cloudbleed/Cloudflare we sort of collectively decided that because cache data containing sensitive info (passwords, tokens, whatever) might be accessible for your site using Cloudflare that everything should be revoked, force password resets, etc. Now we have this vuln, which I'll dub "IOgate" because it's the cool…
Well, if it's any consolation.. the domains weren't registered..
Re: Taking control of all .io domains with a targeted registration
#38So, the real question is: "How much should we freak out about this?" If you scroll back a few months to Cloudbleed/Cloudflare we sort of collectively decided that because cache data containing sensitive info (passwords, tokens, whatever) might be accessible for your site using Cloudflare that everything should be revoked, force password resets, etc. Now we have this vuln, which I'll dub "IOgate" because it's the cool…
Re: Taking control of all .io domains with a targeted registration
#39This is a huge screwup on the part of the people who run the 'root' of .IO, and their entire operation should be severely scrutinized by ICANN. In my opinion almost all of the 'weird' TLDs which are country codes that are actually operated by a third party commercial service are 95% spam and junk registrations. .TV is a good example. Technical screwups aside, the existence of .IO and the fact that it "belongs" to the…
Responsible disclosure to the company that runs the TLD seems like the right first step. This should probably posted on ICANN, ARIN, etc mailing lists even now, but I think the writer's original response is the right one.
Re: Taking control of all .io domains with a targeted registration
#40>Technical screwups aside, the existence of .IO and the fact that it "belongs" to the UK government is morally questionable, since the entire country code only exists because the British and American militaries forcibly removed the original inhabitants of islands such as Diego Garcia so that they could use the area as naval and air force bases. Since you're getting political there for no reason at all, let me say thi…