Live data from Hacker News

Someone is trying to steal archive.is's domain

twitter.com

31–40 of 48 posts

Re: Someone is trying to steal archive.is's domain

#31

DNS Monitoring is a mandatory security requirement for anyone serious about DNS Security today. https://dnsspy.io is a good example of this. Also, although I don’t think there is 100% agreement on this in the community, use LONG ttl’s. No reason to make yourself vulnerable by constantly reaching out to DNS every 5 minutes. Also makes you more likely to pick up a spoofing / hijacking attempt. NOTE: also quick shout ou…

> use LONG ttl’s It really depends on what you want to achieve. Australian census for example shot themselves in the foot by publishing relatively long ttl and not being able to migrate away from a failing system fast enough.

Acknowledged and this is a really good point. Currently I’m straddling the fence on this one and doing a 2 hour DNS Record time.

Also want to mention GEOIP blocking. I hate it’s come to this for the interment, but for a lot of sites, especially small businesses and local/state gov, there is very little reason someone outside the country or say outside the EU / bordering countries might need to access your site. Again this is debatable advice but worth considering. All of the major cloud providers have GeoIP Blocking or are rolling it out.

Re: Someone is trying to steal archive.is's domain

#32

Earlier quoted context omitted.

> use LONG ttl’s It really depends on what you want to achieve. Australian census for example shot themselves in the foot by publishing relatively long ttl and not being able to migrate away from a failing system fast enough.

Acknowledged and this is a really good point. Currently I’m straddling the fence on this one and doing a 2 hour DNS Record time. Also want to mention GEOIP blocking. I hate it’s come to this for the interment, but for a lot of sites, especially small businesses and local/state gov, there is very little reason someone outside the country or say outside the EU / bordering countries might need to access your site. Again…

What do you aim to achieve with geoblocking?

Re: Someone is trying to steal archive.is's domain

#33

Earlier quoted context omitted.

> use LONG ttl’s It really depends on what you want to achieve. Australian census for example shot themselves in the foot by publishing relatively long ttl and not being able to migrate away from a failing system fast enough.

Acknowledged and this is a really good point. Currently I’m straddling the fence on this one and doing a 2 hour DNS Record time. Also want to mention GEOIP blocking. I hate it’s come to this for the interment, but for a lot of sites, especially small businesses and local/state gov, there is very little reason someone outside the country or say outside the EU / bordering countries might need to access your site. Again…

In real life geoip blocking is terrible. IPs are traded from one organization to another all the time. It often takes months for services to update their databases mapping IPs to locations.

What is a user supposed to do when a random website blocks him because it uses an outdated database?

Re: Someone is trying to steal archive.is's domain

#34

Earlier quoted context omitted.

Acknowledged and this is a really good point. Currently I’m straddling the fence on this one and doing a 2 hour DNS Record time. Also want to mention GEOIP blocking. I hate it’s come to this for the interment, but for a lot of sites, especially small businesses and local/state gov, there is very little reason someone outside the country or say outside the EU / bordering countries might need to access your site. Again…

In real life geoip blocking is terrible. IPs are traded from one organization to another all the time. It often takes months for services to update their databases mapping IPs to locations. What is a user supposed to do when a random website blocks him because it uses an outdated database?

This also impacts law enforced limits. What do you do when you're a Polish user under an ISP sharing a block of IPs with Ukrainian part of that company, which is now blocked because of being geolocated in Crimea.

Re: Someone is trying to steal archive.is's domain

#35

Earlier quoted context omitted.

> use LONG ttl’s It really depends on what you want to achieve. Australian census for example shot themselves in the foot by publishing relatively long ttl and not being able to migrate away from a failing system fast enough.

Acknowledged and this is a really good point. Currently I’m straddling the fence on this one and doing a 2 hour DNS Record time. Also want to mention GEOIP blocking. I hate it’s come to this for the interment, but for a lot of sites, especially small businesses and local/state gov, there is very little reason someone outside the country or say outside the EU / bordering countries might need to access your site. Again…

> especially small businesses and local/state gov, there is very little reason someone outside the country or say outside the EU / bordering countries might need to access your site

That is terribly shortsighted. I'm located long way away from many tiny shops I'm using for presents for friends and family. Local gov's published development plans are likely interesting to foreign investors. There are many other cases surely...

Re: Someone is trying to steal archive.is's domain

#36
post #8

I really hope this domain hijacking doesn't succeed, because I use archive.is all the time.

Not to worry. They have other domains too, as stated in the Twitter thread: .TODAY .FO .LI .VN .MD .PH

Yes, but a lot of links posted around the web (e.g. reddit) are for the .is TLD. Most people won't know to change the url and could even be directed to malware.

Re: Someone is trying to steal archive.is's domain

#37

I don't see the value in a high profile stolen domain for a trader. Anyone have any ideas on why this would be financially worthwhile? I am assuming financial motives.

It could be a large organization who is upset for some links archived. Taking .is would make existing links break. Or big media upset with view hijacking. Or it could just be malware.

Whatever the reason, it's terrible.

Re: Someone is trying to steal archive.is's domain

#38

Could someone please explain this? What is going on? Either you hack a domain or you don’t—but once the owner finds out, shouldn’t they be able to verify that it’s locked down. How can someone steal a domain, permanently, and trade with it. Can this happen at any TLD or is .is just negligent/apathetic? Why would I ever buy a .is domain if the TLD lets people steal it? I don’t understand...

I'm guessing the Icelandic registrar has some provision that you have to be a citizen to get a domain, and someone told the registrar that the owner is not, so they can get it canceled and then take it.

Re: Someone is trying to steal archive.is's domain

#39

Could someone please explain this? What is going on? Either you hack a domain or you don’t—but once the owner finds out, shouldn’t they be able to verify that it’s locked down. How can someone steal a domain, permanently, and trade with it. Can this happen at any TLD or is .is just negligent/apathetic? Why would I ever buy a .is domain if the TLD lets people steal it? I don’t understand...

I'm guessing the Icelandic registrar has some provision that you have to be a citizen to get a domain, and someone told the registrar that the owner is not, so they can get it canceled and then take it.

You don’t need to be a citizen of Iceland, but the address needs to be valid. The broker can’t see the address because ISNIC per default hides this information.

Re: Someone is trying to steal archive.is's domain

#40

Earlier quoted context omitted.

You can't un-ring a bell.

That doesn't really justify the decision to continue publishing private information. Just because someone somewhere may have access to it doesn't mean you need to make it easier for everyone to have access to it.

The point is so that anything that is available to anyone, is available to anyone else.

It might have been unfortunate for some things to have ben made public in the first place, but once it's done, there is no value in letting just some people still know the truth while everyone else is subject to manipulation by a few who know some truth.

It's about equalizing the power to harm and the power to defend against harm. The reason to preserve and re-publish something that was once known, is so that no single party gets to use it, or use it's absense, against everyone else. All deleting something does is reduce the number of people with the power to use it. It does not make it actually go away. It just makes it go away from you, while someone else who you may not like still has it.

While there are reasons to forget history, the reasons for preserving it far far far outweigh the reasons for forgetting it. And there is NO valid reason to allow editing history. Selective forgetting allows for substitution, revision, balkanization, manipulation, and at the very least, doubt.

Post reply on HN