Looking forward to hear from Shadowserver on a few points... • What led to the false positive. • What actions were taken to notify the domain owner about the actions being taken against them. • Why there was not a comment put into the Whois entry — or in some other obvious place — saying what had been done to the domain.
I'd rather like to know, what gives shadowserver the authority to initiate such domain takedowns/sinkholing in an act that's pretty much vigilantism?
Sinkholed
91–100 of 135 posts
Re: Sinkholed
#92Re: Sinkholed
#93Earlier quoted context omitted.
Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…
Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…
Re: Sinkholed
#94I still don't get it, what exactly was flagged that caused the domain to get noticed by... Who exactly? Did it have anything to do with the owner logging into his server? What is the sequence of events in bullet point format? I know the author tried to be clear but I'm confused as to what actually happened.
Malware researchers reversed a sample of the malware and started blackholing domains that matched the pattern to get ahead of the malware by preventing it from communicating with the domain du jour.
It just so happens that the authors domain pattern-matched domains that would be contacted by the malware.
Re: Sinkholed
#95Earlier quoted context omitted.
Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…
> I get that many think that Americans are hugely too litigious. But there is the argument that there ought to be compensation for damages. That point of view is rather unfortunate. Why does it have to be about damages? GP even ends his comment on a very postitive note about things that would help. Not every mistake needs to be punished. It was a false positive, and it was heartening to see that all the parties acted…
Re: Sinkholed
#96> He explained in his email that my domain name was sinkholed accidentally as part of their Avalanche operation.
Would it hurt the people doing domain takeovers to at least try sending an email to the registrant with contact info and a case number?
Re: Sinkholed
#97This kind of thing makes picking a personal email address a tricky decision. Do I go with a @gmail.com or other corporate address? Then I risk losing my email if my account is suspended. Do I go with a domain I own? Then I risk losing it if something like this happens. Either way is serious because email is effectively a master key into all my accounts. I'm honestly not sure what's best.
Re: Sinkholed
#98I don't find this surprising at all. This can happen in any scenario where a special shortcut has been added to get around a standard process (where standard process usually involves some human review and judgement). I imagine that in most cases, the shortcuts were created simply to speed up a process where some (perceived) harm is significant, and a rapid change would alleviate this harm. This would allow some enfor…
This is not really ok. There must be a clear contact point for the affected people (not only namecheap). Also it was very bad on the transparency front. If they are taking down a domain, the operation is not secret anymore, so they can tell why. No telling you is bullshit. That being a German operation, I would expect much better on the democratic handling of it. And it being an international operation, India should…
But when it comes to not telling someone, that's usually because there's some high level legal/law enforcement situation. In those cases, there is sometimes a reasonable argument for not alerting someone. The problem is that if there's no human oversight, innocent people sometimes get caught in the net.
Re: Sinkholed
#99> I also wondered if a domain name under a country code top-level domain (ccTLD) like .in is more susceptible to this kind of sinkholing than a domain name under a generic top-level domain (gTLD) like .com. I asked Benedict if it is worth migrating my website from .in to .com. He replied that in his personal opinion, NIXI runs an excellent, clean registry, and are very responsive in resolving issues when they arise.…
Re: Sinkholed
#100Earlier quoted context omitted.
>But arguably your time is worth something. Such as your customary billing rate, times three. Wouldn't the legal fees and time spent litigating exceed the winnings?
In a lawsuit, the fees can be added to the damages.
https://en.wikipedia.org/wiki/American_rule_(attorney%27s_fe...