Live data from Hacker News

Taking control of all .io domains with a targeted registration

thehackerblog.com

71–80 of 258 posts

Re: Taking control of all .io domains with a targeted registration

#71
post #33

Earlier quoted context omitted.

Just so no one is misled: "original inhabitants" does not mean "indigenous peoples" with respect to the BIOT. The islands were not populated prior to late-18th Century European colonization. The depopulation was of post-colonial people.

Why is that an important distinction? Is forcible expulsion and dispropriration more acceptable if the people were brought to the island as slaves and laborers in the mid-1700s?

It doesn't really matter at all. The land didn't come with a .io ccTLD. It's dervived from a name the British chose, so it's not like they stole the domain name from those people, right?

Displacing settlers is a different question.

Re: Taking control of all .io domains with a targeted registration

#72

Earlier quoted context omitted.

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

ccTLDs don't appear to be held to very high standards. For example the .AF top level domain (which is controlled by the government's ministry of communications) doesn't even have a working website, www.nic.af

They're not held to any standards, really. Some of the smaller ccTLDs are basically just run using hand-edited zone files and spreadsheets to track ownership and expiration thereof.

Re: Taking control of all .io domains with a targeted registration

#73

Earlier quoted context omitted.

Why is that an important distinction? Is forcible expulsion and dispropriration more acceptable if the people were brought to the island as slaves and laborers in the mid-1700s?

It doesn't really matter at all. The land didn't come with a .io ccTLD. It's dervived from a name the British chose, so it's not like they stole the domain name from those people, right? Displacing settlers is a different question.

I think the morally questionable problem is this: I am highly doubtful that the original inhabitants of the islands are receiving any revenue whatsoever from the corporation which runs .IO. At least the small pacific island nation states that have hired third parties to run their ccTLD have contracts and agreements in place for a revenue share.

Re: Taking control of all .io domains with a targeted registration

#74

Wow, I don't think I would've even considered such an attack... DNSSEC, HSTS and Certificate Pinning would've made it more difficult to abuse this, but I guess it would've been pretty easy to get valid SSL certificates for all your favourite .io domains. Let's try to play malicious party here: Phase A: First set up a simple DNS forwarder playing by the rules and answering requests as we should (as to not get any unwa…

Author here, thanks - glad you liked the post! :)

Re: Taking control of all .io domains with a targeted registration

#76

Earlier quoted context omitted.

ccTLDs don't appear to be held to very high standards. For example the .AF top level domain (which is controlled by the government's ministry of communications) doesn't even have a working website, www.nic.af

They're not held to any standards, really. Some of the smaller ccTLDs are basically just run using hand-edited zone files and spreadsheets to track ownership and expiration thereof.

Like .ai, the new "hot" ccTLD.

Re: Taking control of all .io domains with a targeted registration

#77

Just to add some color to this: There was an attack last Friday on a few geo TLDs that ended up hijacking a bunch of traffic for a few hours, including .la, .es, and .jp: https://news.gandi.net/en/2017/07/report-on-july-7-2017-inci...

I'm one of the unlucky few that were affected by this (I own .ch).

One of my site user's reported that the website is inaccessible on Friday. I went to check and observed the DNS changing. Then went to check Route 53 status page[2] in which I learn that this is not specific to my site. The behavior is exactly the same as what is described in the SWITCH report[1]. Luckily that I have HSTS on my site, so the damage is limited (users not getting redirected), and Gandi seems to fixed this quick enough (I was in the middle of commuting back home by the time of the attack.)

[1]: https://securityblog.switch.ch/2017/07/07/94-ch-li-domain-na...

[2]: http://status.aws.amazon.com/ (The blue icon for Amazon Route 53 Domain Registration)

Re: Taking control of all .io domains with a targeted registration

#78
post #59

Earlier quoted context omitted.

This comment is in terrible taste but it isn't wrong. We can't just shove our hands in the sand and say it isn't fair so it isn't true.

> it isn't wrong are you referring to "might is right"? what makes you say that?

Thanks for asking that question. My original comment was made quickly and perhaps unintelligently. I don't mean to imply force makes something "right" where "right" is good or best society. I meant from a historical perspective success and strength often makes things culturally acceptable.

A pop culture reference I like to make is the protagonist in Wolf of Wall Street who defrauded many innocent and vulnerable people, is seen as a hero.

Relating back to OP and his American comment, we can reopen Guantanamo Bay for the purpose of torture yet every time our president sets foot in a foreign country he receives a celebration: partly due to the might of the American military and economy.

Relating back to tech and software in general: How do we feel about Microsoft, Bill Gates, after what they did in the 90s? How do we feel about the way Steve Jobs treated his employees and bought his higher placement on the organ transplant list?

"Might makes culturally acceptable" it seems.

Re: Taking control of all .io domains with a targeted registration

#79

Earlier quoted context omitted.

They're not held to any standards, really. Some of the smaller ccTLDs are basically just run using hand-edited zone files and spreadsheets to track ownership and expiration thereof.

Like .ai, the new "hot" ccTLD.

We just used ai.google instead of google.ai as the canonical domain name for Google's AI initiative for precisely this reason. (We run .google and you can see the source code at https://nomulus.foo )

Re: Taking control of all .io domains with a targeted registration

#80

Earlier quoted context omitted.

Well, if it's any consolation.. the domains weren't registered..

Per the article, he got them registered and pointing at his own DNS test server and received actual .io resolution requests to it.

Yes but [per the article] they weren't registered before he bought them. Obviously somebody could have done this before and stopped, or could control some of the other servers.
Post reply on HN