Live data from Hacker News

Taking control of all .io domains with a targeted registration

thehackerblog.com

81–90 of 258 posts

Re: Taking control of all .io domains with a targeted registration

#81

Earlier quoted context omitted.

ccTLDs don't appear to be held to very high standards. For example the .AF top level domain (which is controlled by the government's ministry of communications) doesn't even have a working website, www.nic.af

They're not held to any standards, really. Some of the smaller ccTLDs are basically just run using hand-edited zone files and spreadsheets to track ownership and expiration thereof.

There are also issues like the .LY ccTLD being owned by whatever government claims to be in control of Libya this month, and occasionally revoking domains for things they don't agree with. If I recall correctly for a long time there were several commercial services reselling .LY, but its stability is questionable at best.

Re: Taking control of all .io domains with a targeted registration

#82

Wow, I don't think I would've even considered such an attack... DNSSEC, HSTS and Certificate Pinning would've made it more difficult to abuse this, but I guess it would've been pretty easy to get valid SSL certificates for all your favourite .io domains. Let's try to play malicious party here: Phase A: First set up a simple DNS forwarder playing by the rules and answering requests as we should (as to not get any unwa…

Or, in Phase C, an attacker could proxy traffic through a botnet to avoid the single-ip-range issue; they could even find botnet participants geographically close to each user, so they might not even trigger any red flags from a close look at IP logs. Setting aside DNS hijacking altogether, the idea that phishing sites could do something like this, perfectly proxy i.e. a bank's content and remain largely undetectable, makes me very concerned that we're only just seeing the beginning of sophisticated phishing attacks.

Re: Taking control of all .io domains with a targeted registration

#83
post #59

Earlier quoted context omitted.

> it isn't wrong are you referring to "might is right"? what makes you say that?

Thanks for asking that question. My original comment was made quickly and perhaps unintelligently. I don't mean to imply force makes something "right" where "right" is good or best society. I meant from a historical perspective success and strength often makes things culturally acceptable. A pop culture reference I like to make is the protagonist in Wolf of Wall Street who defrauded many innocent and vulnerable peopl…

> is seen as a hero

He definitely isn't. Neither is Gordon Gecko except by those people who fail to understand the slightly deeper meaning of the telling of those stories.

> How do we feel about the way Steve Jobs treated his employees and bought his higher placement on the organ transplant list?

Or his partner for that matter. But that wasn't the subject, even so plenty of people detest Jobs for or even all of the above.

Re: Taking control of all .io domains with a targeted registration

#85
post #33

Earlier quoted context omitted.

Just so no one is misled: "original inhabitants" does not mean "indigenous peoples" with respect to the BIOT. The islands were not populated prior to late-18th Century European colonization. The depopulation was of post-colonial people.

Why is that an important distinction? Is forcible expulsion and dispropriration more acceptable if the people were brought to the island as slaves and laborers in the mid-1700s?

I'd say that using the land of your own country - owned by people in your country - for military purposes, while sketchy, is definitely more acceptable than taking an island from its indigenous occupants by force. The UK ownership then seems at least to be legitimate.

Re: Taking control of all .io domains with a targeted registration

#87
post #57

Earlier quoted context omitted.

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

There are a few ccTLDs that differ from that, though. DENIC and CZNIC are two that are generally very well-run, DENIC even offering better security and safety than many gTLDs (while also being a cooperative, not a commercial NIC, so prices are very low, too)

.me and .ca "seem" competently run.

More so for .me, ran by the owners of .org

Re: Taking control of all .io domains with a targeted registration

#88

Earlier quoted context omitted.

It doesn't really matter at all. The land didn't come with a .io ccTLD. It's dervived from a name the British chose, so it's not like they stole the domain name from those people, right? Displacing settlers is a different question.

I think the morally questionable problem is this: I am highly doubtful that the original inhabitants of the islands are receiving any revenue whatsoever from the corporation which runs .IO. At least the small pacific island nation states that have hired third parties to run their ccTLD have contracts and agreements in place for a revenue share.

I am similarly outraged that I haven't had any cheques from Nominet come through the post recently and as a UK tax paying citizen I am outraged at this oversight.

I want my £10!

Re: Taking control of all .io domains with a targeted registration

#89
Considering there are a grand total of 2500 people in the BIOT, all of whom are British or American military personnel, it might not be a great idea to route a good chunk of the world's tech traffic through them. The disparity between how important the .io TLD is for the Internet and how few resources must go to running it is pretty appalling.

Re: Taking control of all .io domains with a targeted registration

#90

Earlier quoted context omitted.

It doesn't really matter at all. The land didn't come with a .io ccTLD. It's dervived from a name the British chose, so it's not like they stole the domain name from those people, right? Displacing settlers is a different question.

I think the morally questionable problem is this: I am highly doubtful that the original inhabitants of the islands are receiving any revenue whatsoever from the corporation which runs .IO. At least the small pacific island nation states that have hired third parties to run their ccTLD have contracts and agreements in place for a revenue share.

Are the original inhabitants of these islands still alive?
Post reply on HN