Live data from Hacker News

Taking control of all .io domains with a targeted registration

thehackerblog.com

221–230 of 258 posts

Re: Taking control of all .io domains with a targeted registration

#221
post #163

Earlier quoted context omitted.

> That it is a distinction is important to me. Why ?

Are you being deliberately obtuse? It's a pretty important distinction that these were not some native tribesmen with millennia of ancestral history tied up in the lands.

By European standards the US is mostly inhabited by non-natives. So I guess it'd be okay to forcibly expel everyone but the Natives because they don't have millennia of ancestral history?

I'd hope the more important distinction is how people are removed, not how many generations of dead people there were before them.

Re: Taking control of all .io domains with a targeted registration

#222
post #171

Earlier quoted context omitted.

100s of years though, so from the perspective of an individual on the island it's exactly the same -- their entire life was on that island. So, the distinction is pointless and reeks of apologetics IMO. " Sir Bruce Greatbatch, KCVO, CMG, MBE, governor of the Seychelles, ordered all the dogs on Diego Garcia to be killed. More than 1000 pets were gassed with exhaust fumes. "They put the dogs in a furnace where the peop…

By that logic, ethnic Europeans are the 'original inhabitants' of North America. I'm also unclear on why you quoted what the British did in your post - how does it relate to whether or not calling those people 'original inhabitants' is misleading? Do you believe that, if the British did something sufficiently wrong to them, that calling them 'original inhabitants' will be less misleading?

What would you call the descendant of a Frenchman who settled in Quebec during the 1600s ?

Immigrant? No. Settler? Not really after so many years.

As an immigrant, I view them as natives Quebecers.

What would you call them?

Re: Taking control of all .io domains with a targeted registration

#223
post #171

Earlier quoted context omitted.

100s of years though, so from the perspective of an individual on the island it's exactly the same -- their entire life was on that island. So, the distinction is pointless and reeks of apologetics IMO. " Sir Bruce Greatbatch, KCVO, CMG, MBE, governor of the Seychelles, ordered all the dogs on Diego Garcia to be killed. More than 1000 pets were gassed with exhaust fumes. "They put the dogs in a furnace where the peop…

By that logic, ethnic Europeans are the 'original inhabitants' of North America. I'm also unclear on why you quoted what the British did in your post - how does it relate to whether or not calling those people 'original inhabitants' is misleading? Do you believe that, if the British did something sufficiently wrong to them, that calling them 'original inhabitants' will be less misleading?

Not everything is a contest. It doesn't matter how "original" natives are if they're natives.

The reason "ethnic Europeans" aren't "the original inhabitants of North America" is that European settlers violently displaced (or killed) the previous inhabitants.

Heck, the "original" inhabitants of North America (as far as we know) actually originated in what is now mostly Russia if you go back a few dozen millenia. And if you go back further than that (according to mainstream scientific consensus) we all likely originated in Africa. Defining the term "original inhabitants" as an absolute is blatantly begging the question (specifically it only works if you're a creationist).

People were subjected to physical and psychological violence to be forcibly removed from their home and birthplace. That's bad enough, no matter how many generations lived in the same place before. This isn't about who's had it worse.

Re: Taking control of all .io domains with a targeted registration

#224
post #207

Earlier quoted context omitted.

Just about every country has had some war with people removed or killed by an occupier. America, for instance.

So? That doesn't make it right anyway.

Direct your "so?" at the original poster who pointed out that a particular land was acquired by force, as if that was somehow notable.

Re: Taking control of all .io domains with a targeted registration

#225
post #223

Earlier quoted context omitted.

By that logic, ethnic Europeans are the 'original inhabitants' of North America. I'm also unclear on why you quoted what the British did in your post - how does it relate to whether or not calling those people 'original inhabitants' is misleading? Do you believe that, if the British did something sufficiently wrong to them, that calling them 'original inhabitants' will be less misleading?

Not everything is a contest. It doesn't matter how "original" natives are if they're natives. The reason "ethnic Europeans" aren't "the original inhabitants of North America" is that European settlers violently displaced (or killed) the previous inhabitants. Heck, the "original" inhabitants of North America (as far as we know) actually originated in what is now mostly Russia if you go back a few dozen millenia. And i…

So why oppose clarifications on what 'original' means in this context?

Re: Taking control of all .io domains with a targeted registration

#226

Earlier quoted context omitted.

Besides the old .org, what better options are there for software projects?

We have .dev and .foo, which seem like they'd be good options, but neither are available for open registration. Sorry :(

> .dev

I really hope that one never becomes available..

Re: Taking control of all .io domains with a targeted registration

#227

Earlier quoted context omitted.

I own an .IO domain. Do I deserve to have fake LetsEncrypt certs issued against me and my domain hijacked because some engineer forgot to remove some critical NS records or forgot to register some aliases? Responsible disclosure cat is responsible!

Frankly, yes, a little bit. You're choosing to run your website/infrastructure/etc with a dependency on a sketchy service with no oversight (the ccTLD system in general, but .io in particular). Unless you suffer for this choice, the market for provider competence will be broken.

That nobody had any idea was sketchy or un-oversighten until recently. It was not a choice to run their website/infrastructure/etc on sketchy services at all.

Re: Taking control of all .io domains with a targeted registration

#228
post #223

Earlier quoted context omitted.

Not everything is a contest. It doesn't matter how "original" natives are if they're natives. The reason "ethnic Europeans" aren't "the original inhabitants of North America" is that European settlers violently displaced (or killed) the previous inhabitants. Heck, the "original" inhabitants of North America (as far as we know) actually originated in what is now mostly Russia if you go back a few dozen millenia. And i…

So why oppose clarifications on what 'original' means in this context?

They were expelled in 1965. The current year is 2017. If we wait a few more decades this discussion will be pointless either way.

I'm not opposing clarifications. I'm opposing quibbling over the semantics of "original" as if the distinction adds anything to the conversation.

Their parents lived there, they were born there, they were violently expelled and suffered emotional abuse. The number of dead ancestors (or lack thereof) in the ground does not invalidate the suffering these people were forced to endure.

Re: Taking control of all .io domains with a targeted registration

#229

Wow, I don't think I would've even considered such an attack... DNSSEC, HSTS and Certificate Pinning would've made it more difficult to abuse this, but I guess it would've been pretty easy to get valid SSL certificates for all your favourite .io domains. Let's try to play malicious party here: Phase A: First set up a simple DNS forwarder playing by the rules and answering requests as we should (as to not get any unwa…

If you control the root DNS servers for .io, you can simply not answer the DNSSEC queries. Many resolvers will fail open. HSTS requires the site is HTTPS with a valid cert. If you own all .io, you can use LetsEncrypt to get that for free. They now even support Wildcard Certs! :-) That said, you would have to choose your targets carefully and/or load balance your requests to LetsEncrypt. There is a rate limit. There a…

LetsEncrypt don't support wildcards yet. They will, starting January next year.

Re: Taking control of all .io domains with a targeted registration

#230
post #173
post #110

Earlier quoted context omitted.

We were also affected by this on a major e-commerce site. It was a .se domain. Their post mortem isn't really convincing ( https://news.gandi.net/en/2017/07/report-on-july-7-2017-inci... ) since they do not state what really happened and how it can be prevented again. I issued a support ticket to aws today to see what measures can be taken, otherwise we might need to change registrar.

I doubt changing the registra would change anything, as this seems more likely a problem on the TLD backend side than a problem on the registra itself, since it affect not only Gandi but also Route 53 Domain Registration. I'm under a serious consideration to switch from .ch to something else.

Route53 domain registration uses gandi as a partner.
Post reply on HN