Live data from Hacker News

Sinkholed

susam.in

1–10 of 135 posts

Re: Sinkholed

#2
It is really unbelievable that a legitimate domain can be transferred so easily without any verification or due process. Isn't there an EPP-code-based domain transfer process to prevent exactly things like this?

Re: Sinkholed

#3
post #2

It is really unbelievable that a legitimate domain can be transferred so easily without any verification or due process. Isn't there an EPP-code-based domain transfer process to prevent exactly things like this?

It looks like here the whole domain transfer was bypassed on the pretext of a possible botnet participation. The OP is absolutely right. Domain transfer needs to be much more robust than this.

Re: Sinkholed

#4
post #2

It is really unbelievable that a legitimate domain can be transferred so easily without any verification or due process. Isn't there an EPP-code-based domain transfer process to prevent exactly things like this?

A registry is little more than a DB at heart. In EPP you'd of course send a request with password, it'd go pending Transfer, need to be acked, etc. But nothing stops an employee from just changing things manually, outside of company policy and restrictions. Due to the large amount of immediate domain takedown requests(usually some danger or highly illegal activity involved), there's always a process in place. It sounds like this fault lies on the Gov't agency making the request, for not doing its due diligence prior.

Re: Sinkholed

#5
Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2]

This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of them and special thanks to Namecheap CEO, Richard Kirkendall, for looking into this issue on priority as soon as he became aware of it.

I wish the domain name management, in particular, and the Internet, in general, had a higher degree or decentralization, so that it were technically impossible for something like this to happen but I think there are many factors at play that are currently preventing from such an Internet to become mainstream at this time.

[1]: https://news.ycombinator.com/item?id=21671579

[2]: https://twitter.com/susam/status/1200678538254393345

Re: Sinkholed

#7
post #2

It is really unbelievable that a legitimate domain can be transferred so easily without any verification or due process. Isn't there an EPP-code-based domain transfer process to prevent exactly things like this?

As mentioned in this blog post, the domain transfer was done as part of an international operation against the Avalanche botnet. As such, it was a legal action as opposed to an administrative action. Further, the action was taken at registry level as opposed to registrar level (which is one level lower than the registry). Therefore, no EPP code was necessary and the "clientTransferProhibited" domain transfer record was ignored.

Re: Sinkholed

#8
post #5

Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…

This is great news!

Have you consulted a lawyer?

It seems that the Shadowsecurity Foundation did act recklessly. But you'd need to prove monetary damages.

But perhaps they'd settle to avoid the hassle.

Edit: This is an admission of guilt:

> He explained in his email that my domain name was sinkholed accidentally as part of their Avalanche operation.

Re: Sinkholed

#9
post #2

It is really unbelievable that a legitimate domain can be transferred so easily without any verification or due process. Isn't there an EPP-code-based domain transfer process to prevent exactly things like this?

The FBI and analogous TLAs do this all the time. And generally, there's no recourse.

In many cases, sites have resorted to distributing their IP addresses.

Post reply on HN