Live data from Hacker News

Sinkholed

susam.in

71–80 of 135 posts

Re: Sinkholed

#71
post #35

Earlier quoted context omitted.

I want to know why law enforcement allows a private organization to seize private property based on some algorithm. I have heard bad things about shadowserver in the past. Now I wonder how much other collateral damage they have done over the years.

Domain names are not property, and this is not under the pervue of law enforcement. The country registrar (NIXI) is working together with someone to prevent abuse of their systems. When you purchase a DNS entry, you agree to this sort of thing as part of the ToS.

Right; this is essentially the same as a mail server operator relying on a DNSBL.

Re: Sinkholed

#72
post #46

Earlier quoted context omitted.

>But arguably your time is worth something. Such as your customary billing rate, times three. Wouldn't the legal fees and time spent litigating exceed the winnings?

Yes, that's a good point. But maybe some attorney might do it pro bono .

You know, for the exposure.

Re: Sinkholed

#73
I feel there is an important point between the lines here: a central authority is well positioned to stop bad actors by working outside the definition of “expected behavior” of the system.

P2P systems do not get this by design. For load bearing infrastructure like DNS, escape hatches to stop bad actors putting humanity’s hive mind at risk is a handy tool that has been used effectively.

There are the philosophical questions of “how do we define a bad actor” and “who gets to decide what’s acting in bad faith?” But many botnets don’t suffer from that ambiguity, a well deployed/utilized botnet can take down load bearing internet infrastructure.

Being able to stop future threats without requiring migrating a P2P network _seems_ like a feature, and reminds me a bit of common law. In law, we know there will be cases we can’t anticipate upfront and leave the courts room to interpret. P2P seems to still be in a state where we have to identify and protect against every form of “bad actor” upfront in our game theory in order for our network to be stable moving forward.

Re: Sinkholed

#74

Earlier quoted context omitted.

The National Internet Exchange of India shouldn't be a foreign entity for holders of .in domains.

> Shadowserver Foundation

The Foundation didn't seize the domain, it just suggested to the NIXI that they should do so.

Re: Sinkholed

#75
post #2

It is really unbelievable that a legitimate domain can be transferred so easily without any verification or due process. Isn't there an EPP-code-based domain transfer process to prevent exactly things like this?

.in is a ccTLD, so there are no requirements on its transfer process whatsoever. There are plenty of ccTLDs out there that don't use EPP at all, and simply maintain everything in a hand-edited database or provide a web console (but not programmatic interface). I doubt that .in is one of these ccTLDs that doesn't support EPP, because the big ones tend to support it for obvious scaling reasons, but there's still no protections being offered because the Indian government can always just do what it wants, like provide an API to an anti-botnet company in Germany that can instantly yank any domain name it wants to.

Re: Sinkholed

#76
post #5

Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…

This is something that can absolutely be decentralized. Problems aside namecoin shows that it can be done. The entire domain name system needs to be overhauled, central certificate authorities need to be avoided. The internet in general is infrastructure, and protocols that are increasingly controlled by governments and organizations in bed with governments.

That also has its downsides though. For starters, it would no longer be possible to take down domains used for controlling botnets.

Re: Sinkholed

#77
> I also wondered if a domain name under a country code top-level domain (ccTLD) like .in is more susceptible to this kind of sinkholing than a domain name under a generic top-level domain (gTLD) like .com. I asked Benedict if it is worth migrating my website from .in to .com. He replied that in his personal opinion, NIXI runs an excellent, clean registry, and are very responsive in resolving issues when they arise.

I'm not sure that's the correct conclusion to come to from this experience. Yes, the registrant happened to get lucky in this case, in that they had significant enough reach on Twitter and HN to get the right people to pay attention and get eyes on resolving the issue. But that easily could not have been the case (and might still be the case in the future), and with a ccTLD, you have no recourse.

I think the correct lesson here is to go with a gTLD, because if worse comes to worst you will always have recourse through ICANN if necessary (since the gTLD operator is contracted with them). On a ccTLD it's not always gonna work out. Heck, the registrant was already ignored by the ccTLD operator in this case anyway; it's frankly kind of lucky that they had the CEO of their well-known registrar go to bat for them. That's not the kind of intervention you should be regularly relying on to keep and maintain your domain name!

Re: Sinkholed

#78
I still don't get it, what exactly was flagged that caused the domain to get noticed by... Who exactly? Did it have anything to do with the owner logging into his server? What is the sequence of events in bullet point format? I know the author tried to be clear but I'm confused as to what actually happened.

Re: Sinkholed

#79
As a small business owner, this terrifies me. Since the TTL for NS records is 48 hours, a domain takeover like this could easily bankrupt a lot of SaaS companies.

What options are there to prevent this? Would a registrar such as MarkMonitor provide at least some notice or protection?

Re: Sinkholed

#80
post #5

Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…

My guess is since .in is one of the cheapest (if not THE cheapest) ccTLD the malwares/botnets are exploiting them. I received an email couple of years back from a top domain registrar based in India that the govt. requires actual Registrant contact address and not that of any privacy protection service (to protect from WHOIS); I don't remember whether it was only for .in or for any TLD's registered from India.

Anyways I've since then stopped buying .in and sticked with .com. I'm glad OP got his domain back, but I'm quite sure it wouldn't have been simple (or even possible) if he had chosen some registrar based in India (due to their incompetence and general nature to not contend with higher authorities) instead of Namecheap; especially since Namecheap's .in domain costs more than that of any registrar based in India.

Post reply on HN