Live data from Hacker News

Sinkholed

susam.in

41–50 of 135 posts

Re: Sinkholed

#41

So, did a court just order a domain to be taken down based on erroneous information from a private entity?

I don't see any mention of a court; the TLD manager (NIXI) probably took the initiative based on said erroneous information.

NIXI is subject to the jusrisdiction of CERT-IN (Indian Computer Emergency Response Team - https://cert-in.org.in/), which in turn was one of the participants of the Avalanche takedown program.

A legal request originating from Germany would have been approved by CERT-IN and NIXI would have had to comply.

https://www.cyberswachhtakendra.gov.in/alerts/avalanche.html

Re: Sinkholed

#42
post #25
post #14

Earlier quoted context omitted.

Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…

Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…

>But arguably your time is worth something. Such as your customary billing rate, times three.

Wouldn't the legal fees and time spent litigating exceed the winnings?

Re: Sinkholed

#43

How is one supposed to get this resolved if the CEO OF NAMECHEAP doesn't see your tweet to get involved? Is your domain just gone at that point? Is it really that easy to lose a domain name...by someone doing an 'oopsie'?

The idea would be that the support ticket with namecheap should be enough. Though I doubt it would be, for the average person.

Re: Sinkholed

#44
post #14
post #8

Earlier quoted context omitted.

This is great news! Have you consulted a lawyer? It seems that the Shadowsecurity Foundation did act recklessly. But you'd need to prove monetary damages. But perhaps they'd settle to avoid the hassle. Edit: This is an admission of guilt: > He explained in his email that my domain name was sinkholed accidentally as part of their Avalanche operation.

Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…

> The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back.

MTAs should queue undeliverable addresses for more than four days, so you may not miss much unless someone’s DNS resolver had a poor caching strategy or Shadowserver used a long TTL. At least the name still resolved (else the mail would have been dropped immediately). Some mass mail senders may go to less effort to get their messages through.

The fact that people responded so “quickly” helped here. I put “quickly” in quotes as it was quick enough to possibly cause no message to be lost — I’m sure it was super stressful and didn’t feel quick at all!

Glad you got your name back.

Re: Sinkholed

#45
What I find interesting here is the interplay and mix between private, public, and governmental concerns.

In the physical space, in the states you're free to walk out into the public park, put on a hat saying something atrocious like "I hate cats!" and peacefully petition your fellow citizens to destroy all cats or something silly.

When we moved to printed distribution, there was still a clear bit of guidance; as long as you weren't directing people towards violence, you were good. Most newspapers were locally owned and would even be happy to print your letter to the editor about cats.

But now? We've got a foundation doing something like a regex match on domain names, we've got a criminal element hijacking computers, we've got various government-condoned organizations for managing tlds, we've got registrars. All of these are different types of organizations working in different countries and established for vastly different reasons.

I am reminded of two things. First, Thomas Paine made the point that it was better to live under a dictator than a complex system that hurt you. Under a dictator, you had a guy to point to when things went wrong. It was them! They are responsible for this awful thing! Under a complex system? There's nobody. Bad things just happen, and when you try to ask about it, each party can explain to you that they were working for good reasons to the best of their ability. There was a problem, but no reasonable way to discuss, diagnose, or propose fixes to it.

The second thing was a story from the 80s about a U.S. official, Raymond Donovan. He served fairly well in public office but was accused of some serious crimes. He was destroyed in the media. Then they found out he was innocent. He asked a famous question "Which office do I go to to get my reputation back?"

I'm extremely happy this was resolved, but good grief, if I didn't know anything about the net, and my domain had just been set up instead of being in my control for 12 years, which office would I go to to get my domain back?

Either we own things or we don't. If every bit of our participation online is owned by somebody else, this should be a lot bigger deal than it is currently.

Re: Sinkholed

#46
post #25

Earlier quoted context omitted.

Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…

>But arguably your time is worth something. Such as your customary billing rate, times three. Wouldn't the legal fees and time spent litigating exceed the winnings?

Yes, that's a good point.

But maybe some attorney might do it pro bono.

Re: Sinkholed

#47

Looking forward to hear from Shadowserver on a few points... • What led to the false positive. • What actions were taken to notify the domain owner about the actions being taken against them. • Why there was not a comment put into the Whois entry — or in some other obvious place — saying what had been done to the domain.

I'd rather like to know, what gives shadowserver the authority to initiate such domain takedowns/sinkholing in an act that's pretty much vigilantism?

Re: Sinkholed

#48
post #14
post #8

Earlier quoted context omitted.

This is great news! Have you consulted a lawyer? It seems that the Shadowsecurity Foundation did act recklessly. But you'd need to prove monetary damages. But perhaps they'd settle to avoid the hassle. Edit: This is an admission of guilt: > He explained in his email that my domain name was sinkholed accidentally as part of their Avalanche operation.

Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…

The scariest part is that it looks like this got resolved quickly only because your tweet got noticed and retweeted. I wonder how long it would have taken otherwise.

Re: Sinkholed

#49
I don't find this surprising at all.

This can happen in any scenario where a special shortcut has been added to get around a standard process (where standard process usually involves some human review and judgement).

I imagine that in most cases, the shortcuts were created simply to speed up a process where some (perceived) harm is significant, and a rapid change would alleviate this harm. This would allow some enforcement agency to rapidly take down a child porn site, for example.

Such shortcuts can also be designed to prevent any other party from knowing what is going on - why the change is being made. This would be the case where some high level governmental agency (FBI, for example) wants to change something to prevent a situation they deem as bad or to perhaps to enable better awareness of a process/communication by inserting themselves into the middle of it.

And finally, in this case, an automated or human error resulted in this person's domain name being included on a "bad list", and the shortcut swept their domain along with the trash.

This particular situation doesn't bother me as much as the "Google/Apple/FB suddenly closed all my accounts" scenario (which is often triggered by some opaque artificial wishful-intelligence system).

Regardless of the situation, it's not ideal that our best course of action in recovering something wrongfully taken is by complaining on public forums. It's a shame that we have to hope for the attention and generosity of someone with more power to champion our case to right the wrongs.

So I say, bring the humans back into the process! :)

Re: Sinkholed

#50
post #5

Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…

This is something that can absolutely be decentralized. Problems aside namecoin shows that it can be done. The entire domain name system needs to be overhauled, central certificate authorities need to be avoided.

The internet in general is infrastructure, and protocols that are increasingly controlled by governments and organizations in bed with governments.

Post reply on HN