Earlier quoted context omitted.
You'd be in luck, the Shadowserver Foundation is essentially a proxy for the FBI. They control various seized assets seemingly unrelated to their publicly stated mission, like libertyreserve.com. Shadowserver used to host the seizure page for liberty reserve too.
That’s a pretty big claim. Source?
Sinkholed
121–130 of 135 posts
Re: Sinkholed
#122I still don't get it, what exactly was flagged that caused the domain to get noticed by... Who exactly? Did it have anything to do with the owner logging into his server? What is the sequence of events in bullet point format? I know the author tried to be clear but I'm confused as to what actually happened.
A particular malware contacted its command and control servers via procedurally generated domain names (to make it difficult to shut down just a single domain that controlled it). Malware researchers reversed a sample of the malware and started blackholing domains that matched the pattern to get ahead of the malware by preventing it from communicating with the domain du jour. It just so happens that the authors domai…
Re: Sinkholed
#123This kind of thing makes picking a personal email address a tricky decision. Do I go with a @gmail.com or other corporate address? Then I risk losing my email if my account is suspended. Do I go with a domain I own? Then I risk losing it if something like this happens. Either way is serious because email is effectively a master key into all my accounts. I'm honestly not sure what's best.
Maintaining a domain you control, with a couple of privacy-aware (Protonmail, Fastmail) fallback / out-of-band email contacts, and possibly a few online presences (Twitter, Mastodon, Reddit, etc.) which you can use for signalling, helps.
Knowing actual postal or phone contact information for key partners is also useful. You can use these to communicate in an emergency as well, and spread word.
Operating as a pseudonymous nym online for a decade and experiencing several lockouts / shutdowns over the period ... has been interesting.
Re: Sinkholed
#124Earlier quoted context omitted.
That also has its downsides though. For starters, it would no longer be possible to take down domains used for controlling botnets.
The GNU Name System https://gnunet.org/en/use.html already has a distributed DNS-like system built out.
Re: Sinkholed
#125Earlier quoted context omitted.
> I get that many think that Americans are hugely too litigious. But there is the argument that there ought to be compensation for damages. That point of view is rather unfortunate. Why does it have to be about damages? GP even ends his comment on a very postitive note about things that would help. Not every mistake needs to be punished. It was a false positive, and it was heartening to see that all the parties acted…
I was kind heartened by how quick they reacted. However it is quite true that Americans are very litigious; however, austria, germany, israel are worse than us, and England isn't far behind.
What is your source for that?
Re: Sinkholed
#126Earlier quoted context omitted.
I want to know why law enforcement allows a private organization to seize private property based on some algorithm. I have heard bad things about shadowserver in the past. Now I wonder how much other collateral damage they have done over the years.
Domain names are not property, and this is not under the pervue of law enforcement. The country registrar (NIXI) is working together with someone to prevent abuse of their systems. When you purchase a DNS entry, you agree to this sort of thing as part of the ToS.
Evidently law enforcement was involved in some capacity.
Re: Sinkholed
#127Earlier quoted context omitted.
I'd rather like to know, what gives shadowserver the authority to initiate such domain takedowns/sinkholing in an act that's pretty much vigilantism?
The decision is made by the registrar, so that's who should be answering these questions.
1. shadowserver had an oopsie (i.e. added a false entry to their list)
2. that list was taken by the prosecutor's office to without further checks and by the authority of the prosecutor's office (i.e. state attorneys) of Niedersachsen in Germany and contacted the registrar in India.
3. The registrar transferred the domain
Between each of these steps, there are so many things that went wrong, on so many levels.
Between 1 and 2: Why is the word of some rando org taken as gospel? Without being independently investigated by the office, which sole raison d'être is (independent) investigation of the claims brought to it.
Between 2 and 3: A German prosecutor's office has no authority outside the EU; and even if it did, it could not tell anyone anything to take enforcing actions without a proper court order, even if it's an international request.
Also in the grand scheme of things, considering this was all done to "take down a botnet", this is a path to hell paved with good intentions. How about creating incentive that software and hardware manufacturers get their shit together and secure their shit?
Re: Sinkholed
#128Earlier quoted context omitted.
> Do I go with a domain I own? This one, it’s this one. Losing your domain tends to require human action: from someone forgot to pay the renewal to someone messed up and sinkholed it because they thought it was a C2 server. But because humans are in the system there tend to be layers of processes that try to prevent you from getting to this state and can get your world back to normal if you do. Gmail offers nothing l…
Although if your using your own email address, be prepared for emails you send to end up in junk.
If it ever becomes a problem I flip my MX record elsewhere.
Re: Sinkholed
#129Earlier quoted context omitted.
You'd be in luck, the Shadowserver Foundation is essentially a proxy for the FBI. They control various seized assets seemingly unrelated to their publicly stated mission, like libertyreserve.com. Shadowserver used to host the seizure page for liberty reserve too.
That’s a pretty big claim. Source?
Re: Sinkholed
#130This kind of thing makes picking a personal email address a tricky decision. Do I go with a @gmail.com or other corporate address? Then I risk losing my email if my account is suspended. Do I go with a domain I own? Then I risk losing it if something like this happens. Either way is serious because email is effectively a master key into all my accounts. I'm honestly not sure what's best.
Do both, and add both email addresses to every account that you can.
I think that's because I was coming at this from the perspective of trying to prevent getting hacked, but really I'm less worried about that than I am about losing access.