Earlier quoted context omitted.
I want to know why law enforcement allows a private organization to seize private property based on some algorithm. I have heard bad things about shadowserver in the past. Now I wonder how much other collateral damage they have done over the years.
Domain names are not property, and this is not under the pervue of law enforcement. The country registrar (NIXI) is working together with someone to prevent abuse of their systems. When you purchase a DNS entry, you agree to this sort of thing as part of the ToS.
Sinkholed
71–80 of 135 posts
Re: Sinkholed
#72Earlier quoted context omitted.
>But arguably your time is worth something. Such as your customary billing rate, times three. Wouldn't the legal fees and time spent litigating exceed the winnings?
Yes, that's a good point. But maybe some attorney might do it pro bono .
Re: Sinkholed
#73P2P systems do not get this by design. For load bearing infrastructure like DNS, escape hatches to stop bad actors putting humanity’s hive mind at risk is a handy tool that has been used effectively.
There are the philosophical questions of “how do we define a bad actor” and “who gets to decide what’s acting in bad faith?” But many botnets don’t suffer from that ambiguity, a well deployed/utilized botnet can take down load bearing internet infrastructure.
Being able to stop future threats without requiring migrating a P2P network _seems_ like a feature, and reminds me a bit of common law. In law, we know there will be cases we can’t anticipate upfront and leave the courts room to interpret. P2P seems to still be in a state where we have to identify and protect against every form of “bad actor” upfront in our game theory in order for our network to be stable moving forward.
Re: Sinkholed
#74Re: Sinkholed
#75It is really unbelievable that a legitimate domain can be transferred so easily without any verification or due process. Isn't there an EPP-code-based domain transfer process to prevent exactly things like this?
Re: Sinkholed
#76Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…
This is something that can absolutely be decentralized. Problems aside namecoin shows that it can be done. The entire domain name system needs to be overhauled, central certificate authorities need to be avoided. The internet in general is infrastructure, and protocols that are increasingly controlled by governments and organizations in bed with governments.
Re: Sinkholed
#77I'm not sure that's the correct conclusion to come to from this experience. Yes, the registrant happened to get lucky in this case, in that they had significant enough reach on Twitter and HN to get the right people to pay attention and get eyes on resolving the issue. But that easily could not have been the case (and might still be the case in the future), and with a ccTLD, you have no recourse.
I think the correct lesson here is to go with a gTLD, because if worse comes to worst you will always have recourse through ICANN if necessary (since the gTLD operator is contracted with them). On a ccTLD it's not always gonna work out. Heck, the registrant was already ignored by the ccTLD operator in this case anyway; it's frankly kind of lucky that they had the CEO of their well-known registrar go to bat for them. That's not the kind of intervention you should be regularly relying on to keep and maintain your domain name!
Re: Sinkholed
#78Re: Sinkholed
#79What options are there to prevent this? Would a registrar such as MarkMonitor provide at least some notice or protection?
Re: Sinkholed
#80Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…
Anyways I've since then stopped buying .in and sticked with .com. I'm glad OP got his domain back, but I'm quite sure it wouldn't have been simple (or even possible) if he had chosen some registrar based in India (due to their incompetence and general nature to not contend with higher authorities) instead of Namecheap; especially since Namecheap's .in domain costs more than that of any registrar based in India.