Live data from Hacker News

Sinkholed

susam.in

61–70 of 135 posts

Re: Sinkholed

#61

What I find interesting here is the interplay and mix between private, public, and governmental concerns. In the physical space, in the states you're free to walk out into the public park, put on a hat saying something atrocious like "I hate cats!" and peacefully petition your fellow citizens to destroy all cats or something silly. When we moved to printed distribution, there was still a clear bit of guidance; as lon…

Blaming the dictator doesn't solve the problem. Sure, you could try to overthrow a dictator, but you can also try to fix a system, by talking to any of the people involved in it (or if there are no people involved, try to modify the system yourself, since there's no one to stop you).

Re: Sinkholed

#62
Namecheap rocks, been using them for years.

Really wish they'd pick another name: it's really hard to convince clients to take them seriously and let me choose them. If I had a dollar for every time someone insisted on GoDaddy... :-(

Re: Sinkholed

#63
post #49

I don't find this surprising at all. This can happen in any scenario where a special shortcut has been added to get around a standard process (where standard process usually involves some human review and judgement). I imagine that in most cases, the shortcuts were created simply to speed up a process where some (perceived) harm is significant, and a rapid change would alleviate this harm. This would allow some enfor…

> This particular situation doesn't bother me as much as the "Google/Apple/FB suddenly closed all my accounts" scenario This situation bothers me so much more. Google/Apple/FB are private corporations. If they continue to adopt user hostile practices it is possible for some other company to out compete them in the more or less free market of internet services. TLDs are government controlled entities administering sca…

Here's the problem: A big corp is never going to alienate 10% of its user base at large, enough to motivate a competitor. But they are highly incentivized to alienate 1% -- millions of people, as a cost-cutting measure. Or they might even alienate 20-40% of potential users, as long as those users are not wealthy or powerful enough to "matter" (see: chattel slavery).

This is the history of society, of marginalization of the disabled or other outgroups. It's hard work to overcome that, often through force (Civil War) or the threat thereof (Americans with Disabilities Act).

Re: Sinkholed

#64
post #25
post #14

Earlier quoted context omitted.

Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…

Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…

> I get that many think that Americans are hugely too litigious

No, really they aren't. There are a lot of lawyers in America, but most never set foot in a courtroom. They mostly just do "important" paperwork and give advice on following rules.

I know a lawyer who last month wanted to sue someone in federal court, only to discover that Joe Random lawyer is not allowed to file lawsuits in federal court; he had no idea that there was such a thing as a federal trial bar and that membership requires significant experience in federal court under the supervision of a member. He spent a week trying to find anyone that would be willing to file his lawsuit but none would. So he hired a law firm to sue in state court - that is much easier I guess. Anyway, the point is that he is a good lawyer with years of experience doing the lawyer thing, but no experience with litigation. That's normal.

Re: Sinkholed

#65

Someone less technical would likely have no idea what happened to their domain. An individual relying on their web presence for income could be massively impacted by something like this. There really does not seem to be a clear way for someone to a) know what the problem is, and b) get it resolved quickly.

Every domain has a technical contact, it's part of the WHOIS schema. A non-technical website owner hires someone to handle technicalities, just as a non-mechanical car owner hires someone to handle their cars mechanics.

Sure, if you don't pay attention to the care of your domain, it can break in incomprehensible ways, just as if you don't pay attention to the care of your car, it can break in incomprehensible ways.

Re: Sinkholed

#66
post #21

Interesting. I noticed that the blog post mentions the Nymaim malware family. I read about Susam's case when it hit Twitter the other day and might have even followed a link to his URL. Then a few days later got an email from my ISP Virgin Media claiming they'd detected Nymain on my home network. I run macOS only and as far as I can tell Nymaim is Windows only. Still, I ran an malware scan on my Macbooks and nothing…

I have been at the receiving end of German authorities reporting an uninfected server of mine to the hosting company as Avalanche-infected based on Shadowserver information. It was unpleasant, particularly because it happened a day before a family holiday, so my spouse was annoyed when instead of participating in preparations, I was researching what had happened and explaining my innocence.

Although my server wasn't infected, it had connected to a Shadowserver sinkhole.

While it's good that there are folks who work to sinkhole botnets, the next step of accusing others of being infected based of what the sinkhole sees needs more care. I'm disappointed that, evidently, my expression of these concerns to the German authorities three years ago hasn't lead to a substantial change at the Shadowserver end.

As can be seen from your case (and mine), you can get blamed even if the software at your end of the connection wasn't the botnet software. Considering how a basic premise of the Web is that it's safe to dereference a URL and everyone runs software that does so (Web browsers!), it's a bad idea that Shadowserver doesn't require a narrower indicator of compromise.

There'd be less chance of folks weaponising this system against bystanders by framing them as botnet-infected if the Shadowserver Foundation sinkhole required the other end of the connection to exhibit more specific hallmarks of the botnet software.

Re: Sinkholed

#68

Earlier quoted context omitted.

Personally I’d rather deal with the FBI accidentally seizing a domain than some foreign entity.

The National Internet Exchange of India shouldn't be a foreign entity for holders of .in domains.

> Shadowserver Foundation

Re: Sinkholed

#69
post #61

What I find interesting here is the interplay and mix between private, public, and governmental concerns. In the physical space, in the states you're free to walk out into the public park, put on a hat saying something atrocious like "I hate cats!" and peacefully petition your fellow citizens to destroy all cats or something silly. When we moved to printed distribution, there was still a clear bit of guidance; as lon…

Blaming the dictator doesn't solve the problem. Sure, you could try to overthrow a dictator, but you can also try to fix a system, by talking to any of the people involved in it (or if there are no people involved, try to modify the system yourself, since there's no one to stop you).

This is the Fallacy of Gray. Just because neither option is perfect, doesn’t mean that one option isn’t better. It’s clearly easier for a bloc of concerned citizens to solve problems in dictator-land than in bureaucracy-land: in dictator-land, you just have to remove one (probably very unpopular) guy, while in bureaucracy-land, you have to... um...

Re: Sinkholed

#70
post #49

I don't find this surprising at all. This can happen in any scenario where a special shortcut has been added to get around a standard process (where standard process usually involves some human review and judgement). I imagine that in most cases, the shortcuts were created simply to speed up a process where some (perceived) harm is significant, and a rapid change would alleviate this harm. This would allow some enfor…

This is not really ok. There must be a clear contact point for the affected people (not only namecheap). Also it was very bad on the transparency front. If they are taking down a domain, the operation is not secret anymore, so they can tell why. No telling you is bullshit. That being a German operation, I would expect much better on the democratic handling of it. And it being an international operation, India should…

I think there is a clear point of contact, and it is your registrar. This is part of the reason a hierarchy of registrars exist, rather than each TLD just being one organization maintaining its own registry service: so that the people with ultimate authority (the TLD, in this case) can have personal relationships with representatives of “constituencies” of domains (the registrars), rather than necessarily-impersonal relationships with a flat collective of millions of individual accounts (the domain owners).

By analogy: Google has necessarily-impersonal relationships with millions of Gmail users; but rather more personal relationships with far fewer GSuite and Google Cloud organization owners. If you were an employee of a company that uses either of those, and your service was breaking, you’d ask your GSuite organization-owner (i.e. the person Google has a personal relationship with) to contact them for you.

Post reply on HN