Live data from Hacker News

Sinkholed

susam.in

91–100 of 135 posts

Re: Sinkholed

#91

Looking forward to hear from Shadowserver on a few points... • What led to the false positive. • What actions were taken to notify the domain owner about the actions being taken against them. • Why there was not a comment put into the Whois entry — or in some other obvious place — saying what had been done to the domain.

I'd rather like to know, what gives shadowserver the authority to initiate such domain takedowns/sinkholing in an act that's pretty much vigilantism?

The decision is made by the registrar, so that's who should be answering these questions.

Re: Sinkholed

#93
post #25
post #14

Earlier quoted context omitted.

Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…

Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…

Average Americans are not litigious, because the overwhelming majority of Americans would not actually be able to afford a lawyer if it came to it. Lawyers are expensive.

Re: Sinkholed

#94

I still don't get it, what exactly was flagged that caused the domain to get noticed by... Who exactly? Did it have anything to do with the owner logging into his server? What is the sequence of events in bullet point format? I know the author tried to be clear but I'm confused as to what actually happened.

A particular malware contacted its command and control servers via procedurally generated domain names (to make it difficult to shut down just a single domain that controlled it).

Malware researchers reversed a sample of the malware and started blackholing domains that matched the pattern to get ahead of the malware by preventing it from communicating with the domain du jour.

It just so happens that the authors domain pattern-matched domains that would be contacted by the malware.

Re: Sinkholed

#95
post #25

Earlier quoted context omitted.

Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…

> I get that many think that Americans are hugely too litigious. But there is the argument that there ought to be compensation for damages. That point of view is rather unfortunate. Why does it have to be about damages? GP even ends his comment on a very postitive note about things that would help. Not every mistake needs to be punished. It was a false positive, and it was heartening to see that all the parties acted…

I was kind heartened by how quick they reacted. However it is quite true that Americans are very litigious; however, austria, germany, israel are worse than us, and England isn't far behind.

Re: Sinkholed

#96
Wow! "Accidentally?" That's inexcusable. He should be compensated, and the people who made this mistake should not be doing this sort of work anymore.

> He explained in his email that my domain name was sinkholed accidentally as part of their Avalanche operation.

Would it hurt the people doing domain takeovers to at least try sending an email to the registrant with contact info and a case number?

Re: Sinkholed

#97

This kind of thing makes picking a personal email address a tricky decision. Do I go with a @gmail.com or other corporate address? Then I risk losing my email if my account is suspended. Do I go with a domain I own? Then I risk losing it if something like this happens. Either way is serious because email is effectively a master key into all my accounts. I'm honestly not sure what's best.

Do both, and add both email addresses to every account that you can.

Re: Sinkholed

#98
post #49

I don't find this surprising at all. This can happen in any scenario where a special shortcut has been added to get around a standard process (where standard process usually involves some human review and judgement). I imagine that in most cases, the shortcuts were created simply to speed up a process where some (perceived) harm is significant, and a rapid change would alleviate this harm. This would allow some enfor…

This is not really ok. There must be a clear contact point for the affected people (not only namecheap). Also it was very bad on the transparency front. If they are taking down a domain, the operation is not secret anymore, so they can tell why. No telling you is bullshit. That being a German operation, I would expect much better on the democratic handling of it. And it being an international operation, India should…

I did not say it was ok. I think it's a bad system, and I think it's getting worse - company by company, and month by month.

But when it comes to not telling someone, that's usually because there's some high level legal/law enforcement situation. In those cases, there is sometimes a reasonable argument for not alerting someone. The problem is that if there's no human oversight, innocent people sometimes get caught in the net.

Re: Sinkholed

#99

> I also wondered if a domain name under a country code top-level domain (ccTLD) like .in is more susceptible to this kind of sinkholing than a domain name under a generic top-level domain (gTLD) like .com. I asked Benedict if it is worth migrating my website from .in to .com. He replied that in his personal opinion, NIXI runs an excellent, clean registry, and are very responsive in resolving issues when they arise.…

Would the experience be any better in gTLD? The registry of .com gTLD is VeriSign Global Registry Services. Would ICANN handle a domain-related dispute themselves or would they redirect us to Verisign? Is Verisign any better than NIXI?

Re: Sinkholed

#100
post #58

Earlier quoted context omitted.

>But arguably your time is worth something. Such as your customary billing rate, times three. Wouldn't the legal fees and time spent litigating exceed the winnings?

In a lawsuit, the fees can be added to the damages.

Generally no, they can't. In the US. Other countries have different rules.

https://en.wikipedia.org/wiki/American_rule_(attorney%27s_fe...

Post reply on HN