Live data from Hacker News

EasyDNS threatened with criminal complaint if client data not disclosed

easydns.com

111–120 of 190 posts

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#111
post #104

Earlier quoted context omitted.

How could you possibly compare that to > we may also wildcard your DNS to localhost and set the TTL on your zone out to a year This is going way beyond suspending a customer, this is an active attack by EasyDNS.

It does indeed go beyond a suspension, it's a ban , and that's why I equate it to Amazon and Google blocking any new accounts - they are banning you from their platform, arguably for life. At least EasyDNS offer it to be 12 months. I'm no DNS expert, but AFAIK, you can transfer the zone to another provider (one that you don't violate the T&Cs with) and from there you could conceivably regain control over the domain.

You completely misunderstand, this is strictly different from a ban. This is like DDoSing someone after you banned them.

The TTL tells DNS resolvers to cache the "localhost" result for 1 year, it's specifically an attempt to prevent you from regaining control over the domain at another provider.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#112
post #110

Earlier quoted context omitted.

>we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned Go ahead, name some "professional" hosting companies with similar practices.

With how tongue-in-cheek the whole document is, this is clearly a joke to emphasize their point (which, I agree, has no place in a legal document, no matter how plain). My point is that everything else in the document is pretty much industry standard, except that others are less...direct about it. https://easydns.com/terms-of-service

>My point is that everything else in the document is pretty much industry standard

Is it really surprising that a hosting industry company is similar to the other companies doing exactly the same thing? I feel like this is always going to be the case.

It's specifically the weird stuff in this document that makes them stand out from the crowd.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#113
post #111

Earlier quoted context omitted.

It does indeed go beyond a suspension, it's a ban , and that's why I equate it to Amazon and Google blocking any new accounts - they are banning you from their platform, arguably for life. At least EasyDNS offer it to be 12 months. I'm no DNS expert, but AFAIK, you can transfer the zone to another provider (one that you don't violate the T&Cs with) and from there you could conceivably regain control over the domain.

You completely misunderstand, this is strictly different from a ban. This is like DDoSing someone after you banned them. The TTL tells DNS resolvers to cache the "localhost" result for 1 year, it's specifically an attempt to prevent you from regaining control over the domain at another provider.

Okay, fair point. I can only assume they would only do this for persistent and malicious violation of the rules; it's a pretty good incentive not to do anything nasty with them if they can lock you globally out of your zone for a year. In fairness, so could any other provider if they so chose. As a registrar, I can guess the amount of abuse they have to deal with (spam domains, illegal content etc.) is high enough that they're pretty tired of dealing with it, so they take the Roosevelt approach:

Speak softly, and carry a big stick.

Again, I don't agree with this approach personally if it affected me, but I do understand it from a business POV. Letting the customer know in advance that they do have this power will weed out the ones who are most likely to fall into it.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#115
post #111

Earlier quoted context omitted.

You completely misunderstand, this is strictly different from a ban. This is like DDoSing someone after you banned them. The TTL tells DNS resolvers to cache the "localhost" result for 1 year, it's specifically an attempt to prevent you from regaining control over the domain at another provider.

Okay, fair point. I can only assume they would only do this for persistent and malicious violation of the rules; it's a pretty good incentive not to do anything nasty with them if they can lock you globally out of your zone for a year. In fairness, so could any other provider if they so chose. As a registrar, I can guess the amount of abuse they have to deal with (spam domains, illegal content etc.) is high enough th…

> I can only assume they would only do this for persistent and malicious violation of the rules

No, they specifically state this in a context which does not leave room for such an interpretation.

>We are NOT a DDoS Mitigation Service. Yes, we have a lot of DDoS mitigation in place. No, this isn’t here so that you can get cheap DDoS mitigation. You cannot use any services here if you are, have been or think you may be the direct target of a DDoS attack. Contact us instead for a referral to a real DDoS mitigation company. If you come on this system knowingly bringing a DDoS on your heels we shut down service (we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned).

>it's a pretty good incentive not to do anything nasty with them if they can lock you globally out of your zone for a year.

Sure, like violence is a good incentive too. Both of these are likely to be illegal.

>In fairness, so could any other provider if they so chose.

So fucking what, the whole point is that nobody else would do this.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#116
post #86

Earlier quoted context omitted.

Let me just further highlight this specific part: >we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned Maliciously tampering with customer DNS configs to DoS them for extended periods? Fucking incredible.

And I'd be surprised if it couldn't lead to a successful legal claim against them for damages.

Wait, you want to expose your shady spam operation so you can claim damages? Tell me how that works out for you.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#117
post #72

Earlier quoted context omitted.

easyDNS here. 1) We do not advertise in Germany. 2) Our client is not German.

You offer .de domains. Customers buying .de domains have to be, necessarily, German, so you’re necessarily advertising to German customers.

> Customers buying .de domains have to be, necessarily, German

According to DENIC's TOS, the domain owner doesn't have to be German (as long as they appoint a Germany-based representative for receiving correspondence official and court correspondence, but that's not easyDNS' concern).

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#118
post #84
post #62

Earlier quoted context omitted.

It's unprofessional to let prospective customers know that EasyDNS is not a company that specializes in handling DDOS, so just keep looking for a company that can help you out? Seems refreshingly honest to me. And as a customer of theirs, I appreciate that they're looking to protect the infrastructure that I rely upon. Regarding that second part; if you do any kind of online service provision like EasyDNS, you'll qui…

> we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned No, this is simply indefensible. There's simply no way you could ever excuse this. Suspending a customer domain is OK, this is not.

I think it depends on what you did. If you did something crazy like run a DDoS C&C layer off your subdomains then it would make perfect sense for them to respond like this.

As others said every service reserves the right to do things like this, they just typically phrase differently. To quote GoDaddy:

> You acknowledge and agree that GoDaddy and registry reserve the right to deny, cancel or transfer any registration or transaction, or place any domain name(s) on lock, hold or similar status, as either deems necessary, in the unlimited and sole discretion of either GoDaddy or the registry: .. snip .. (ii) to protect the integrity and stability of, and correct mistakes made by, any domain name registry or registrar,

Emphasis mine and a bit snipped out since this is already long. This says if it affects their stability they can transfer your registration as they see fit. It doesn't include any protections on when you can change the domain or what they can change it to meaning blackholing you into localhost for a year is fine.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#119
post #86

EasyDNS's Plain English Terms of Service make them seem like a really unprofessional company: >We are NOT a DDoS Mitigation Service. [...] If you come on this system knowingly bringing a DDoS on your heels we shut down service (we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned). or >Guilt-by-Association: not only do we terminate any domains or websites which vio…

Let me just further highlight this specific part: >we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned Maliciously tampering with customer DNS configs to DoS them for extended periods? Fucking incredible.

agree it's an overkill solution -

but, devils advocate, maybe it's just there to scare off potential spammers/scammers?

Having worked at an ISP in security/spam/abuse, these people are a huge drain on resources.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#120
post #82
post #65

Earlier quoted context omitted.

>These guys are extraordinarily [...] professional. I think part of OP's complaint is they are not coming across as professional. It is entirely reasonable to take those stances but their tact is way off and definitely portrays their company in an unprofessional manner. They might be good at what they do, I wouldn't know personally, but they come off as edgy/abrasive/unprofessional and those two quotes alone would ha…

The only difference between them and others is that they're plain in their language rather than obfuscating it behind lawyer speak. All providers have similar provisions hidden in their TOS, it's just buried behind layers of legalese and addendums. Personally although it might not look "professional" I wish more companies would use plain language that states what they actually mean plainly without forcing you to high…

If you use that sort of rude plain language, and make a mistake, good luck.
Post reply on HN