Live data from Hacker News

Taking control of all .io domains with a targeted registration

thehackerblog.com

151–160 of 258 posts

Re: Taking control of all .io domains with a targeted registration

#151

Earlier quoted context omitted.

It is really nice, that the .de domain is seen more as infrastructure than some business. But there are a few downsides to DENIC as well. 1. you need to have a person (juridicial or natural) with an address in Germany to register and list that person as ADMIN-C 2. if you run a website that provide contents which COULD generate revenue, you have to have an Impressum [1] which includes the address, names, etc. of the w…

Well, this is what every domain should have, though. A Ladungsfähige Anschrift of a person that is liable. This is a major criticism I have with many other domains, I don’t know where to send a C&D, or whom to sue if they violate my rights. And requiring only commercial entities to have these things also makes sense.

Agree to disagree. Of the top of my head I can think of several useful things where a public (private) address would be problematic:

1. you want to do something like wiki leaks

2. you want to publish your thoughts anonymously, let's say you are from the LGTB spectrum and want to engage with people by building a forum or blog to communicate with them -> this could lead to potential problems with family, friends and work

3. you have political views and publish them. Now say someone disagrees with your views and is potentially aggressive. Do you want them to know where your family lives?

4. you do not wan't annoying calls by people who crawl the DENIC records (happens to me regularly)

I agree with you that a person should be liable for the stuff they do, but should also be able to engage in open discussion while protecting their privacy. FWIW If someone does bad stuff on a .de domain there are several options:

a) take down the domain via DENIC, or b) take down the domain via ISP or c) take down the domain via Hosting provider

If you really did illegal stuff, I am with you and someone (DENIC, ISP or Host) probably should have the knowledge of the domain owner which could be subpoenaed to lawfully prosecute someone.

Re: Taking control of all .io domains with a targeted registration

#152
post #32

>Technical screwups aside, the existence of .IO and the fact that it "belongs" to the UK government is morally questionable, since the entire country code only exists because the British and American militaries forcibly removed the original inhabitants of islands such as Diego Garcia so that they could use the area as naval and air force bases. Since you're getting political there for no reason at all, let me say thi…

We've banned this account for trolling. If you don't want to be banned on HN, you're welcome to email hn@ycombinator.com and give us reason to believe that you'll only post civilly and substantively in the future. But please (re)-read the following first:

https://news.ycombinator.com/newsguidelines.html

https://news.ycombinator.com/newswelcome.html

We detached this subthread from https://news.ycombinator.com/item?id=14737670 and marked it off-topic.

Re: Taking control of all .io domains with a targeted registration

#153
post #69

This is a huge screwup on the part of the people who run the 'root' of .IO, and their entire operation should be severely scrutinized by ICANN. In my opinion almost all of the 'weird' TLDs which are country codes that are actually operated by a third party commercial service are 95% spam and junk registrations. .TV is a good example. Technical screwups aside, the existence of .IO and the fact that it "belongs" to the…

yeah...yeah...and the UK seized ".UK" from the Ukraine and this means... save your politics for politics, not for a technology discussion. We get it, you're moral.

That's not the same thing?

If you're interested, the Ukraine TLD is .ua.

To say they stole it from Ukraine in the same way they stole the .io TLD would mean that they would have to take over the entire country of Ukraine. Maybe the Russian government will have control of the .ua TLD someday.

Re: Taking control of all .io domains with a targeted registration

#154

This is a huge screwup on the part of the people who run the 'root' of .IO, and their entire operation should be severely scrutinized by ICANN. In my opinion almost all of the 'weird' TLDs which are country codes that are actually operated by a third party commercial service are 95% spam and junk registrations. .TV is a good example. Technical screwups aside, the existence of .IO and the fact that it "belongs" to the…

Cloudflare For Top Level Domains? :)

Re: Taking control of all .io domains with a targeted registration

#155
post #126

I had a similar issue with the .IM domain three months ago. One of the four NS for the domain was not responding. Two of the guys at Cloudflare diagnosed it for me: https://twitter.com/xxdesmus/status/855858441289572353

One Cofounder of cloudflare, pretty impressed they picked up tweets directly.

Re: Taking control of all .io domains with a targeted registration

#156

Wow, I don't think I would've even considered such an attack... DNSSEC, HSTS and Certificate Pinning would've made it more difficult to abuse this, but I guess it would've been pretty easy to get valid SSL certificates for all your favourite .io domains. Let's try to play malicious party here: Phase A: First set up a simple DNS forwarder playing by the rules and answering requests as we should (as to not get any unwa…

Your missing a ton of potential here by assuming that all DNS is good for is Web traffic. For one thing, taking over or intercepting email (remember, you now control the DNS, so you also control SPF and DKIM records) becomes trivial. you could even leverage that control of email to get SSL certificates for domains you really want to do https for (letsencrypt will even generate a wildcard cert using only dns based verification).

You could also be much more surgical, and target specific people/organizations using that .tld, ignoring dns requests for everyone that you don’t want to alert to your control. Hijack their email, and you control access to things like account recovery for domain users, and have a great method for phishing account credentials for the domains customers.

Honestly, the list of what you could do here is almost only limited by your imagination

Re: Taking control of all .io domains with a targeted registration

#157
post #110

Earlier quoted context omitted.

We were also affected by this on a major e-commerce site. It was a .se domain. Their post mortem isn't really convincing ( https://news.gandi.net/en/2017/07/report-on-july-7-2017-inci... ) since they do not state what really happened and how it can be prevented again. I issued a support ticket to aws today to see what measures can be taken, otherwise we might need to change registrar.

There is a more detailed followup today: https://news.gandi.net/en/2017/07/detailed-incident-report/

> These credentials were likewise not obtained by a breach of our systems and we strongly suspect they were obtained from an insecure connection to our technical partner’s web portal (the web platform in question allows access via http).

This makes no sense - how did the attacker get between gandi.net and their technical partner in order to MITM them? MITMs aren't magic - simply sending an unencrypted password somewhere doesn't result in it becoming public knowledge unless a router or switch in the path is malicious.

Re: Taking control of all .io domains with a targeted registration

#158

Earlier quoted context omitted.

Like .ai, the new "hot" ccTLD.

We just used ai.google instead of google.ai as the canonical domain name for Google's AI initiative for precisely this reason. (We run .google and you can see the source code at https://nomulus.foo )

Any ETA on .app?

Re: Taking control of all .io domains with a targeted registration

#159

Earlier quoted context omitted.

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

Besides the old .org, what better options are there for software projects?

.sh and .run come to mind in some cases.

Re: Taking control of all .io domains with a targeted registration

#160
post #54

Earlier quoted context omitted.

Why is that an important distinction? Is forcible expulsion and dispropriration more acceptable if the people were brought to the island as slaves and laborers in the mid-1700s?

> an important distinction That it is a distinction is important to me. Having difficult discussions is made more difficult if we obscure facts or conflate terms. > more acceptable I applied no normative judgement.

> That it is a distinction is important to me.

Why ?

Post reply on HN