Live data from Hacker News

EasyDNS threatened with criminal complaint if client data not disclosed

easydns.com

121–130 of 190 posts

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#121

Earlier quoted context omitted.

And I'd be surprised if it couldn't lead to a successful legal claim against them for damages.

Wait, you want to expose your shady spam operation so you can claim damages? Tell me how that works out for you.

Where exactly does the quoted text mention shady spam operations? It's about DDoS victims, not cybercriminals.

>We are NOT a DDoS Mitigation Service. Yes, we have a lot of DDoS mitigation in place. No, this isn’t here so that you can get cheap DDoS mitigation. You cannot use any services here if you are, have been or think you may be the direct target of a DDoS attack. Contact us instead for a referral to a real DDoS mitigation company. If you come on this system knowingly bringing a DDoS on your heels we shut down service (we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned).

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#122
post #65

Earlier quoted context omitted.

>These guys are extraordinarily [...] professional. I think part of OP's complaint is they are not coming across as professional. It is entirely reasonable to take those stances but their tact is way off and definitely portrays their company in an unprofessional manner. They might be good at what they do, I wouldn't know personally, but they come off as edgy/abrasive/unprofessional and those two quotes alone would ha…

People have such a strange idea of "professionalism". It's about your principles and what you do, not the semantics and aesthetics.

"What you do?" You mean like breaking a customer's domain name for the next year if EasyDNS thinks they brought a DoS attack "on their heels?"

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#123
post #119
post #86

Earlier quoted context omitted.

Let me just further highlight this specific part: >we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned Maliciously tampering with customer DNS configs to DoS them for extended periods? Fucking incredible.

agree it's an overkill solution - but, devils advocate, maybe it's just there to scare off potential spammers/scammers? Having worked at an ISP in security/spam/abuse, these people are a huge drain on resources.

>but, devils advocate, maybe it's just there to scare off potential spammers/scammers?

Why are you engaging in these bizarre mental gymnastics to defend this? The threat is made in a context strictly unrelated to spammers/scammers.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#124
post #20

Earlier quoted context omitted.

Is there any indication that they solicited business in Germany? And how, in practice, could they enforce that if this canadian entity has not broken any canadian law and canada as such has no impetus to enforce german law?

> Is there any indication that they solicited business in Germany? My understanding is making the website available to a country can be soliciting business. > And how, in practice, could they enforce that if this canadian entity has not broken any canadian law and canada as such has no impetus to enforce german law? Don't they have deals for such thing? I remember reading that a British court judgement for damages co…

> My understanding is making the website available to a country can be soliciting business.

Oh dear, that would make publishing any website extremely dangerous..

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#125

IANAL, but here's my assessment on this: First and foremost, as far as I know, a registrar disclosing customer data without a warrant would violate the law in Germany as well. For `.de`-Domains the holder information used to be publicly available, at the dismay of privacy activists; in the same way the ICANN wanted the same. Then GDPR came and pretty much put a legally binding end to this. And it comes down to this:…

Do you have an approximate translation of Abmahnanwalt? Google translate punts on it

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#126
post #84

Earlier quoted context omitted.

> we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned No, this is simply indefensible. There's simply no way you could ever excuse this. Suspending a customer domain is OK, this is not.

I think it depends on what you did. If you did something crazy like run a DDoS C&C layer off your subdomains then it would make perfect sense for them to respond like this. As others said every service reserves the right to do things like this, they just typically phrase differently. To quote GoDaddy: > You acknowledge and agree that GoDaddy and registry reserve the right to deny, cancel or transfer any registration…

Come on. They made this threat in a very specific context, it has nothing to do with abusive activity like running a DDoS C&C.

>As others said every service reserves the right to do things like this, they just typically phrase differently. To quote GoDaddy:

Suspending a domain is standard practice, sabotaging one by setting long EOLs is not. It is dishonest to suggest that these are similar.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#127
post #86

EasyDNS's Plain English Terms of Service make them seem like a really unprofessional company: >We are NOT a DDoS Mitigation Service. [...] If you come on this system knowingly bringing a DDoS on your heels we shut down service (we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned). or >Guilt-by-Association: not only do we terminate any domains or websites which vio…

Let me just further highlight this specific part: >we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned Maliciously tampering with customer DNS configs to DoS them for extended periods? Fucking incredible.

Correct me if I am wrong, but a TTL is specific to nameservers. So if you switch from easyDNS to say cloudflare your TTLs get completely reset and the caching does as well.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#128
post #7

Attorney here! (Not legal advice, consult a licensed attorney in your jurisdiction.) Don't get me wrong, but easyDNS may be jumping hastily to conclusions. In many countries, soliciting business there makes you subject to its jurisdiction and laws, regardless of where your business is based. I don't know German law, but I hope that easyDNS consulted their own attorneys on the subject before publishing this post, or t…

I'm sure I have something on a public httpd somewhere my company owns that is insulting to the Thai king. Better look out, I'm going to Thai prison for lese majeste!

Actually had a customer (or just angry netizen) complain about this at a hosting company. Was very satisfying to return our boilerplate about how we were in 'murica and this didn't apply.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#129
post #115

Earlier quoted context omitted.

Okay, fair point. I can only assume they would only do this for persistent and malicious violation of the rules; it's a pretty good incentive not to do anything nasty with them if they can lock you globally out of your zone for a year. In fairness, so could any other provider if they so chose. As a registrar, I can guess the amount of abuse they have to deal with (spam domains, illegal content etc.) is high enough th…

> I can only assume they would only do this for persistent and malicious violation of the rules No, they specifically state this in a context which does not leave room for such an interpretation. >We are NOT a DDoS Mitigation Service. Yes, we have a lot of DDoS mitigation in place. No, this isn’t here so that you can get cheap DDoS mitigation. You cannot use any services here if you are, have been or think you may be…

I'm guessing they have had to deal with DDoS attacks a lot, and as a sysadmin I can sympathise with their frustrations - it doesn't just affect the person fleeing to them, it affects their entire hosting platform, their other customers, and ultimately them getting paid for hosting those other customers. They're probably sick of it, which explains the drastic action. I can understand why they would threaten this if they've had to ride through multiple attacks, especially if it appears someone under fire is using them for 'cheap DDoS mitigation' when it's specifically a service they don't offer.

Re: EasyDNS threatened with criminal complaint if client data not disclosed

#130
post #119
post #86

Earlier quoted context omitted.

Let me just further highlight this specific part: >we may also wildcard your DNS to localhost and set the TTL on your zone out to a year. You’ve been warned Maliciously tampering with customer DNS configs to DoS them for extended periods? Fucking incredible.

agree it's an overkill solution - but, devils advocate, maybe it's just there to scare off potential spammers/scammers? Having worked at an ISP in security/spam/abuse, these people are a huge drain on resources.

Speaking as a consumer, I'm kind of tired of companies giving themselves enormous amounts of power and then saying, "don't worry, we won't use it."

That's not a professional relationship to me. And I would hazard a guess that if I tried to contract with EasyDNS and added clauses that gave myself similar amounts of power over them, they wouldn't be as trusting of me.

The point of a legal document is to set explicit boundaries, not to set a "tone" to the relationship or scare off scammers. Setting tone is what your FAQ is for.

Post reply on HN