Live data from Hacker News

Sinkholed

susam.in

101–110 of 135 posts

Re: Sinkholed

#101

A couple of years ago we lost our domain [1] due to a registrar (that we were not a customer of) erroneously issuing a suspension. The amount of honor system involved in the whole process, particularly in ccTLDs without as much oversight, was really surprising. [1]: https://medium.com/thisiscala/the-duct-tape-holding-the-inte...

That's worth resubmitting to HN.

Done. https://news.ycombinator.com/item?id=21705976.

Re: Sinkholed

#102

Earlier quoted context omitted.

This is something that can absolutely be decentralized. Problems aside namecoin shows that it can be done. The entire domain name system needs to be overhauled, central certificate authorities need to be avoided. The internet in general is infrastructure, and protocols that are increasingly controlled by governments and organizations in bed with governments.

That also has its downsides though. For starters, it would no longer be possible to take down domains used for controlling botnets.

The GNU Name System https://gnunet.org/en/use.html already has a distributed DNS-like system built out.

Re: Sinkholed

#103

What I find interesting here is the interplay and mix between private, public, and governmental concerns. In the physical space, in the states you're free to walk out into the public park, put on a hat saying something atrocious like "I hate cats!" and peacefully petition your fellow citizens to destroy all cats or something silly. When we moved to printed distribution, there was still a clear bit of guidance; as lon…

> First, Thomas Paine made the point that it was better to live under a dictator than a complex system that hurt you.

Interesting; can you point to the quote/source on that? (I'm also reminded of the Jobs quote: "Conspiracy is optimistic! You can shoot the bastards!")

I'm not sure one is "better", per se, but problems with complex distributed systems tend to be painfully intractable. Worse, I think human nature is to map such problems to narrowly-scoped villain narratives which feel tractable; and so not only does the root complexity go unaddressed, but great efforts are undertaken to thwart the alleged villains, sometimes making the real problems worse.

Re: Sinkholed

#104
post #44
post #14

Earlier quoted context omitted.

Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…

> The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. MTAs should queue undeliverable addresses for more than four days, so you may not miss much unless someone’s DNS resolver had a poor caching strategy or Shadowserver used a long TTL. At least the name still resolved (else the mail would have been dropped immediately). Some mass mail senders may…

> so you may not miss much unless someone’s DNS resolver had a poor caching strategy

Microsoft Exchange used to (hope it doesn't still?) cache MX records until the service restarted. :( There's a long tail of braindead software in the DNS space

Re: Sinkholed

#105
post #25
post #14

Earlier quoted context omitted.

Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…

Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…

[deleted]

Re: Sinkholed

#106
post #65

Someone less technical would likely have no idea what happened to their domain. An individual relying on their web presence for income could be massively impacted by something like this. There really does not seem to be a clear way for someone to a) know what the problem is, and b) get it resolved quickly.

Every domain has a technical contact, it's part of the WHOIS schema. A non-technical website owner hires someone to handle technicalities, just as a non-mechanical car owner hires someone to handle their cars mechanics. Sure, if you don't pay attention to the care of your domain, it can break in incomprehensible ways, just as if you don't pay attention to the care of your car, it can break in incomprehensible ways.

In theory, sure. But according to most of my domain WHOIS records, the technical contact is somebody named asdflkj_34890f@privacyprotection.com.

Re: Sinkholed

#107
post #82

Earlier quoted context omitted.

Personally I’d rather deal with the FBI accidentally seizing a domain than some foreign entity.

You'd be in luck, the Shadowserver Foundation is essentially a proxy for the FBI. They control various seized assets seemingly unrelated to their publicly stated mission, like libertyreserve.com. Shadowserver used to host the seizure page for liberty reserve too.

That’s a pretty big claim. Source?

Re: Sinkholed

#108
post #62

Namecheap rocks, been using them for years. Really wish they'd pick another name: it's really hard to convince clients to take them seriously and let me choose them. If I had a dollar for every time someone insisted on GoDaddy... :-(

Ah, GoDaddy: a name that is much easier to take seriously.

Re: Sinkholed

#109

> My website was missing. In fact, the domain name resolved to an IPv4 address I was unfamiliar with. Do you guys know this stuff? If my domain started resolving to a new IP address, that would be just as unfamiliar to me, as the current address. Should I ping my domain and write the results down?

I tend to know recognize the networks my servers are on, because I only have one or two.

Re: Sinkholed

#110

tldr; Collateral damage from law enforcement taking down a botnet, resolved reasonably fast.

It wasn't law enforcement taking the domain name, it also was only solved fast because of intervention from the Namecheap CEO.

I didn't say it was law enforcement directly taking down the domain name, I said that it was collateral damage from law enforcement operation against botnet.

As the original operation was run by interpol, europol etc i think this was a fairly accurate description, especially in context of a tldr; which gives some constitutional rights to simplify things :)

Post reply on HN