Live data from Hacker News

Taking control of all .io domains with a targeted registration

thehackerblog.com

91–100 of 258 posts

Re: Taking control of all .io domains with a targeted registration

#91

Earlier quoted context omitted.

Bad actors are on those mailing lists too. What you describe would be the equivalent of mailing fulldisclosure with "Hi all, there might be more unregistered nameservers at .IO (or another 101domains-serviced TLD) that could be used to attack live traffic if anyone wants to grab those, kthx"

I'm fine with that happening, because the people who run .IO need to be spanked. If their customers are subsequently unhappy that their domain names have been hijacked, they can take it up with whatever corporate entity runs .IO. Same problem as publicly disclosing serious flaws with an SSL/TLS root CA.

That will most likely cause widespread havoc without solving anything and even slow down the actual resolution of the problem.

Strategy is important.

Re: Taking control of all .io domains with a targeted registration

#92
post #90

Earlier quoted context omitted.

I think the morally questionable problem is this: I am highly doubtful that the original inhabitants of the islands are receiving any revenue whatsoever from the corporation which runs .IO. At least the small pacific island nation states that have hired third parties to run their ccTLD have contracts and agreements in place for a revenue share.

Are the original inhabitants of these islands still alive?

Yes. https://en.wikipedia.org/wiki/Chagossians

Re: Taking control of all .io domains with a targeted registration

#93
post #57

Earlier quoted context omitted.

There are a few ccTLDs that differ from that, though. DENIC and CZNIC are two that are generally very well-run, DENIC even offering better security and safety than many gTLDs (while also being a cooperative, not a commercial NIC, so prices are very low, too)

There's probably around a dozen ccTLDs that are really competently run and that are world-class. Beyond that I'd stick with competently run gTLDs. I actually just met a bunch of the denic guys at a conference they hosted a month ago in Frankfurt. They're on point with their Internet stuff.

given the incredible importance to global internet infrastructure of things like the DE-CIX in frankfurt, I am not surprised that the Germans have their shit together when running critical back end systems.

Re: Taking control of all .io domains with a targeted registration

#94

This is a huge screwup on the part of the people who run the 'root' of .IO, and their entire operation should be severely scrutinized by ICANN. In my opinion almost all of the 'weird' TLDs which are country codes that are actually operated by a third party commercial service are 95% spam and junk registrations. .TV is a good example. Technical screwups aside, the existence of .IO and the fact that it "belongs" to the…

People make mistakes. This seems like some manual configuration/technical debt issues. Don't get me wrong, mistakes for these big, highly used TLDs is pretty massive. The scale of this is could have been devastating. Responsible disclosure to the company that runs the TLD seems like the right first step. This should probably posted on ICANN, ARIN, etc mailing lists even now, but I think the writer's original response…

The people that make this sort of mistake should not be responsible for a TLD. This is one of the worst possible blunders imaginable.

Considering they control the .io TLD these should have been registered and locked as reserved. That this wasn't the policy is but one of the many failings that lead to this outcome.

If I were ICANN I'd slap them with a huge fine to send a message.

Re: Taking control of all .io domains with a targeted registration

#95

Earlier quoted context omitted.

It doesn't really matter at all. The land didn't come with a .io ccTLD. It's dervived from a name the British chose, so it's not like they stole the domain name from those people, right? Displacing settlers is a different question.

I think the morally questionable problem is this: I am highly doubtful that the original inhabitants of the islands are receiving any revenue whatsoever from the corporation which runs .IO. At least the small pacific island nation states that have hired third parties to run their ccTLD have contracts and agreements in place for a revenue share.

Why should they get any revenue from .io? The .io is an invention of the government and has nothing to do with the original inhabitants. The "original" people were removed well before .io even existed.

Might as well demand they get paid for any inventions the military makes while testing stuff out there.

And if the British hadn't done this and gave control over to the people living there 50 years ago, they wouldn't get .io either, because they wouldn't call themselves British Indian Ocean Territories. They'd have used something reflecting the name in their language.

So again, this is a "resource" purely created by the British government being there.

Maybe it's terribly unfair and bad what they've done to those peoples, but .io doesn't figure into that at all.

Edit: I suppose if they had their own nation state, they could make some money that they couldn't otherwise. But why stop at domain names (which, again, wouldn't be .io, it'd be .cx or something for Chagossians)? They can't issue passports, a potentially valuable resource, not being a sovereign nation. They can't run "tax haven" schemes, etc. Seems like getting upset over .io itself is pointless compared to all the other stuff they could do with an internationally recognized government.

Re: Taking control of all .io domains with a targeted registration

#96
post #45

Earlier quoted context omitted.

HSTS preloading doesn't help if you can get a Domain Validated certificate. HPKP preloading helps, but only if you pin to a CA that won't issue a DV certificate to someone who controls 4 out of 7 of the nameservers for the TLD your domain is in. And also only helps if the incident is cleaned up before the browser preload process catches the malicious server when confirming the preload. It might be a good idea to requ…

Edited in a correction, thanks. But also: you can pin to a specific certificate, not just a CA. > It might be a good idea to require DV certificate issuance to respect DNSSEC -- in this case, the poison nameservers wouldn't be able to sign the responses properly, and .io is DNSSEC enabled. That seems like a good idea. DNSSEC isn't perfect, but for this purpose it's better than nothing. (That said, I'd love to know wh…

> But also: you can pin to a specific certificate, not just a CA.

I think the general best practices for pinning are to pin a CA or two, and a backup key; in case your keys get compromised, you can reissue with your preferred CA; in case your CA gets delisted, you can get a cert issued with your backup key from a still trusted CA. You could have a series of keys and trust those, but it seems like that would be an easy way for you to shoot yourself in the foot.

Re: Taking control of all .io domains with a targeted registration

#97

So, the real question is: "How much should we freak out about this?" If you scroll back a few months to Cloudbleed/Cloudflare we sort of collectively decided that because cache data containing sensitive info (passwords, tokens, whatever) might be accessible for your site using Cloudflare that everything should be revoked, force password resets, etc. Now we have this vuln, which I'll dub "IOgate" because it's the cool…

> Now we have this vuln, which I'll dub "IOgate" because it's the cool thing to name these

No

Re: Taking control of all .io domains with a targeted registration

#99

Earlier quoted context omitted.

I'm fine with that happening, because the people who run .IO need to be spanked. If their customers are subsequently unhappy that their domain names have been hijacked, they can take it up with whatever corporate entity runs .IO. Same problem as publicly disclosing serious flaws with an SSL/TLS root CA.

I own an .IO domain. Do I deserve to have fake LetsEncrypt certs issued against me and my domain hijacked because some engineer forgot to remove some critical NS records or forgot to register some aliases? Responsible disclosure cat is responsible!

Frankly, yes, a little bit. You're choosing to run your website/infrastructure/etc with a dependency on a sketchy service with no oversight (the ccTLD system in general, but .io in particular). Unless you suffer for this choice, the market for provider competence will be broken.

Re: Taking control of all .io domains with a targeted registration

#100
post #62

Earlier quoted context omitted.

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

As an average user, how do I know which is which? How can I tell whether .ABCXYZ is competently run and trustworthy? gTLDs & ccTLDs have to be some of the worst ideas in Internet history.

> gTLDs have to be some of the worst ideas in Internet history.

Not if you're an investor in Donuts, LLC, they're not...

Post reply on HN