Live data from Hacker News

Taking control of all .io domains with a targeted registration

thehackerblog.com

31–40 of 258 posts

Re: Taking control of all .io domains with a targeted registration

#31

So, the real question is: "How much should we freak out about this?" If you scroll back a few months to Cloudbleed/Cloudflare we sort of collectively decided that because cache data containing sensitive info (passwords, tokens, whatever) might be accessible for your site using Cloudflare that everything should be revoked, force password resets, etc. Now we have this vuln, which I'll dub "IOgate" because it's the cool…

Well, if it's any consolation.. the domains weren't registered..

Re: Taking control of all .io domains with a targeted registration

#32
>Technical screwups aside, the existence of .IO and the fact that it "belongs" to the UK government is morally questionable, since the entire country code only exists because the British and American militaries forcibly removed the original inhabitants of islands such as Diego Garcia so that they could use the area as naval and air force bases.

Since you're getting political there for no reason at all, let me say this: might is right. Get over it.

Re: Taking control of all .io domains with a targeted registration

#33

This is a huge screwup on the part of the people who run the 'root' of .IO, and their entire operation should be severely scrutinized by ICANN. In my opinion almost all of the 'weird' TLDs which are country codes that are actually operated by a third party commercial service are 95% spam and junk registrations. .TV is a good example. Technical screwups aside, the existence of .IO and the fact that it "belongs" to the…

Just so no one is misled: "original inhabitants" does not mean "indigenous peoples" with respect to the BIOT. The islands were not populated prior to late-18th Century European colonization. The depopulation was of post-colonial people.

Re: Taking control of all .io domains with a targeted registration

#34
post #32

>Technical screwups aside, the existence of .IO and the fact that it "belongs" to the UK government is morally questionable, since the entire country code only exists because the British and American militaries forcibly removed the original inhabitants of islands such as Diego Garcia so that they could use the area as naval and air force bases. Since you're getting political there for no reason at all, let me say thi…

Ladies and gentleman: Hacker News.

Re: Taking control of all .io domains with a targeted registration

#35

Earlier quoted context omitted.

Bad actors are on those mailing lists too. What you describe would be the equivalent of mailing fulldisclosure with "Hi all, there might be more unregistered nameservers at .IO (or another 101domains-serviced TLD) that could be used to attack live traffic if anyone wants to grab those, kthx"

I'm fine with that happening, because the people who run .IO need to be spanked. If their customers are subsequently unhappy that their domain names have been hijacked, they can take it up with whatever corporate entity runs .IO. Same problem as publicly disclosing serious flaws with an SSL/TLS root CA.

Ah, I see you follow President Trump's incident response methodology.

Re: Taking control of all .io domains with a targeted registration

#36

So, the real question is: "How much should we freak out about this?" If you scroll back a few months to Cloudbleed/Cloudflare we sort of collectively decided that because cache data containing sensitive info (passwords, tokens, whatever) might be accessible for your site using Cloudflare that everything should be revoked, force password resets, etc. Now we have this vuln, which I'll dub "IOgate" because it's the cool…

Well, if it's any consolation.. the domains weren't registered..

The post states that they were registered, used, then revoked.

Re: Taking control of all .io domains with a targeted registration

#37

So, the real question is: "How much should we freak out about this?" If you scroll back a few months to Cloudbleed/Cloudflare we sort of collectively decided that because cache data containing sensitive info (passwords, tokens, whatever) might be accessible for your site using Cloudflare that everything should be revoked, force password resets, etc. Now we have this vuln, which I'll dub "IOgate" because it's the cool…

Well, if it's any consolation.. the domains weren't registered..

Per the article, he got them registered and pointing at his own DNS test server and received actual .io resolution requests to it.

Re: Taking control of all .io domains with a targeted registration

#38

So, the real question is: "How much should we freak out about this?" If you scroll back a few months to Cloudbleed/Cloudflare we sort of collectively decided that because cache data containing sensitive info (passwords, tokens, whatever) might be accessible for your site using Cloudflare that everything should be revoked, force password resets, etc. Now we have this vuln, which I'll dub "IOgate" because it's the cool…

Cloudbleed was different in a lot of ways, not least of which because it could have been passively exploited by an unknowable number of attackers even after the bug was fixed. Here, this is an active attack that leaves a trail. The question is more like "do you trust the author?"

Re: Taking control of all .io domains with a targeted registration

#39

This is a huge screwup on the part of the people who run the 'root' of .IO, and their entire operation should be severely scrutinized by ICANN. In my opinion almost all of the 'weird' TLDs which are country codes that are actually operated by a third party commercial service are 95% spam and junk registrations. .TV is a good example. Technical screwups aside, the existence of .IO and the fact that it "belongs" to the…

People make mistakes. This seems like some manual configuration/technical debt issues. Don't get me wrong, mistakes for these big, highly used TLDs is pretty massive. The scale of this is could have been devastating.

Responsible disclosure to the company that runs the TLD seems like the right first step. This should probably posted on ICANN, ARIN, etc mailing lists even now, but I think the writer's original response is the right one.

Re: Taking control of all .io domains with a targeted registration

#40
post #32

>Technical screwups aside, the existence of .IO and the fact that it "belongs" to the UK government is morally questionable, since the entire country code only exists because the British and American militaries forcibly removed the original inhabitants of islands such as Diego Garcia so that they could use the area as naval and air force bases. Since you're getting political there for no reason at all, let me say thi…

Surprising behavior from a green username.
Post reply on HN