Live data from Hacker News

Sinkholed

susam.in

111–120 of 135 posts

Re: Sinkholed

#111
post #69
post #61

Earlier quoted context omitted.

Blaming the dictator doesn't solve the problem. Sure, you could try to overthrow a dictator, but you can also try to fix a system, by talking to any of the people involved in it (or if there are no people involved, try to modify the system yourself, since there's no one to stop you).

This is the Fallacy of Gray. Just because neither option is perfect, doesn’t mean that one option isn’t better. It’s clearly easier for a bloc of concerned citizens to solve problems in dictator-land than in bureaucracy-land: in dictator-land, you just have to remove one (probably very unpopular) guy, while in bureaucracy-land, you have to... um...

In dictator-land, you first have to remove the dictator. You still have to actually solve the problem after removing the dictator.

It's easy to say "the dictator is bad" but historically getting rid of dictators without a specific and concrete plan for what to do afterwards has not turned out so well.

Re: Sinkholed

#112
post #35

Looking forward to hear from Shadowserver on a few points... • What led to the false positive. • What actions were taken to notify the domain owner about the actions being taken against them. • Why there was not a comment put into the Whois entry — or in some other obvious place — saying what had been done to the domain.

I want to know why law enforcement allows a private organization to seize private property based on some algorithm. I have heard bad things about shadowserver in the past. Now I wonder how much other collateral damage they have done over the years.

This is what I was wondering as well, it seemed bizarre to me and I expected there to be much more outrage here about it. I wonder if it's a bit like local parking regulations, which tend to be written in ways that allow towing companies to abuse you as much as possible.

Re: Sinkholed

#113
post #5

Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…

Thank you for this. We are definitely seeing the declining use of centralized domain-resolution. It has advantages only when it is not _itself_ being gamed, and increasingly companies and governmental orgs have found ways to do just that. At the very least every domain should have dual central + decentral resolutions, and browsers should give you options when the resolutions conflict.

Re: Sinkholed

#114

Looking forward to hear from Shadowserver on a few points... • What led to the false positive. • What actions were taken to notify the domain owner about the actions being taken against them. • Why there was not a comment put into the Whois entry — or in some other obvious place — saying what had been done to the domain.

Shadowserver runs the sinkhole, its up to the registrar/dns company (in this case namecheap) to point it at the sinkhole. The Feds provide a list of "identified" domains to all the major providers for the avalanche take down. Since this is an on going thing, someone at namecheap blindly ran the list without any verification.

Re: Sinkholed

#115
post #71

Earlier quoted context omitted.

Domain names are not property, and this is not under the pervue of law enforcement. The country registrar (NIXI) is working together with someone to prevent abuse of their systems. When you purchase a DNS entry, you agree to this sort of thing as part of the ToS.

Right; this is essentially the same as a mail server operator relying on a DNSBL.

Exactly

Re: Sinkholed

#116

This kind of thing makes picking a personal email address a tricky decision. Do I go with a @gmail.com or other corporate address? Then I risk losing my email if my account is suspended. Do I go with a domain I own? Then I risk losing it if something like this happens. Either way is serious because email is effectively a master key into all my accounts. I'm honestly not sure what's best.

Option 3: Contract with a mail forwarding service like pobox.com. That way, you can move your mailbox service with the click of a button. Since they are not involved in delivering your mail, the chance that you'll get your account suspended for anything short of doing real crime is essentially zero.

Re: Sinkholed

#117
post #25

Earlier quoted context omitted.

Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…

> I get that many think that Americans are hugely too litigious. But there is the argument that there ought to be compensation for damages. That point of view is rather unfortunate. Why does it have to be about damages? GP even ends his comment on a very postitive note about things that would help. Not every mistake needs to be punished. It was a false positive, and it was heartening to see that all the parties acted…

> Why does it have to be about damages?

If someone attacks you, and causes physical or even mental damage, they typically face criminal and/or civil penalties.

That's common, throughout the world.

> Not every mistake needs to be punished.

Maybe so. But the people responsible for the damage could proactively offer compensation. That'd arguably be the honorable and compassionate thing to do.

> It was a false positive, and it was heartening to see that all the parties acted fast enough.

It's clear that they acted recklessly. So it's not just a "false positive". And what's "fast enough"? A few days after a totally implausible attack isn't that fast. It should have been fixed within the day. After at most a few emails.

Re: Sinkholed

#118
post #69

Earlier quoted context omitted.

This is the Fallacy of Gray. Just because neither option is perfect, doesn’t mean that one option isn’t better. It’s clearly easier for a bloc of concerned citizens to solve problems in dictator-land than in bureaucracy-land: in dictator-land, you just have to remove one (probably very unpopular) guy, while in bureaucracy-land, you have to... um...

In dictator-land, you first have to remove the dictator. You still have to actually solve the problem after removing the dictator. It's easy to say "the dictator is bad" but historically getting rid of dictators without a specific and concrete plan for what to do afterwards has not turned out so well.

In doctor-land, you are trying to solve a particular problem with a particular patient, the assumption being that once that problem is solved, the patient will remain self-regulating.

In political-theory-land, you assume all actors are bad, are at least will become bad at some point in the future. The question then becomes *how can we organize our political structures so that if we can't prevent dying, can we at least provide guidance to the next government that follows?"

It naturally follows that the real goal is not solving problems: it is providing problems and solutions that people can accept. If nothing else, providing problems and solutions in terms that future generations can reason about.

Re: Sinkholed

#119

This kind of thing makes picking a personal email address a tricky decision. Do I go with a @gmail.com or other corporate address? Then I risk losing my email if my account is suspended. Do I go with a domain I own? Then I risk losing it if something like this happens. Either way is serious because email is effectively a master key into all my accounts. I'm honestly not sure what's best.

> Do I go with a domain I own?

This one, it’s this one.

Losing your domain tends to require human action: from someone forgot to pay the renewal to someone messed up and sinkholed it because they thought it was a C2 server.

But because humans are in the system there tend to be layers of processes that try to prevent you from getting to this state and can get your world back to normal if you do.

Gmail offers nothing like this. When the ML algorithms decide you are too many sigma in the “abnormal” category, you are done. And there is no one to talk to who can fix your problem.

Re: Sinkholed

#120

This kind of thing makes picking a personal email address a tricky decision. Do I go with a @gmail.com or other corporate address? Then I risk losing my email if my account is suspended. Do I go with a domain I own? Then I risk losing it if something like this happens. Either way is serious because email is effectively a master key into all my accounts. I'm honestly not sure what's best.

> Do I go with a domain I own? This one, it’s this one. Losing your domain tends to require human action: from someone forgot to pay the renewal to someone messed up and sinkholed it because they thought it was a C2 server. But because humans are in the system there tend to be layers of processes that try to prevent you from getting to this state and can get your world back to normal if you do. Gmail offers nothing l…

Although if your using your own email address, be prepared for emails you send to end up in junk.
Post reply on HN