DNS abuse and criminal infrastructure
21–30 of 51 posts
Re: DNS abuse and criminal infrastructure
#22That seems beyond any reasonable due process and legal standards. Or am I missing some international legal standard and judicial oversight that would play a role here? I'm genuinely confused.
Re: DNS abuse and criminal infrastructure
#23Re: DNS abuse and criminal infrastructure
#24Re: DNS abuse and criminal infrastructure
#25I have some experience of dealing with this when working for .gov.uk A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims. By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on w…
Better would be a "this site is suspiciously new" warning in browsers.
At $WORK, newly registered sites are blocked by default by the network appliance.
Re: DNS abuse and criminal infrastructure
#26Earlier quoted context omitted.
On the other hand, I struggle to think of a reason how harm could come from delayed activation of a registered public name. Can you describe a use case that cannot be solved by opting for a subdomain of an already-existing domain?
England have just scored the winning goal in the world cup and I want to celebrate by launching my personal tribute on Lionesses.rock Why shouldn't that go live instantly? A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now. I've had a brilliant idea for an eCommerce website but it is 1705 on a Friday night and, because…
Re: DNS abuse and criminal infrastructure
#27This article is pretty light on details. The linked presentation goes into a lot more detail with statistics about which registrars and organizations are the worst offenders etc. https://view.officeapps.live.com/op/view.aspx?src=https%3A%2...
Re: DNS abuse and criminal infrastructure
#28Why should alleged "cybercriminals" not be be allowed to register domain names? There are procedures of seizing domain names in various countries, and these are in my opinion already somewhat questionable, but the premise of this article seems to go far beyond that and suggest that what they call "malicious actors" should somehow be deprived of infrastructure because they are suspected criminals. The rationale for th…
Much like micropayments could solve the text spam problem.
Re: DNS abuse and criminal infrastructure
#29I have some experience of dealing with this when working for .gov.uk A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims. By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on w…
I'd say "legitimate objections" is doing a lot of heavy lifting there and I don't like the idea. Having the time and resources to monitor registrations becomes a barrier and that makes it a time and resource based system. IE: Rich individuals and companies can pay a monitoring service that objects very broadly.
I've always been frustrated by systems like that and it seems like a lot of the tech industry is set up that way. I've had my personal, family name, 25 year old domain put on Google's safe browsing block list and being the collateral damage in a hugely scaled system isn't fun. Spending the time and resources needed to deal with it are far more of a burden for me than for a big company. I was able to get it removed, but why should I be forced to pay for their mistake?
Ultimately though, any system is going to cost money no matter how it's structured. If you're not paying directly, you're spending time or resources of some kind. I'd rather pay directly because it's easier to understand.
I don't think you can build an all or none system for handling abuse because so much of it is subjective. Even using what's legal vs illegal is difficult because a global system is going to have contradictions. Online gambling is a good example. Some countries would want the related domains banned for being illegal while others don't have a problem with it.
Domains are one of the core building blocks that makes a decentralized internet work. Adding strong moderation tools to that is a huge risk because moderation and censorship are closely related. Who determines what's trustworthy or legitimate or abuse or anything else? What happens if a newly appointed authority claims transparency will enable bad actors?
Highly transparent systems with independent trust ranking make the most sense to me. Any solutions need to be opt-in, or, at the very least, opt-out.
Re: DNS abuse and criminal infrastructure
#30I agree with the premise but this article doesn't really provide a strong argument. It mentions stats about child exploitation but doesn't show how that's related to gtlds. Stats about the block list are good (10% of gtld domains are blocked) but thay requires comparing it with a baseline. How many of non gtld domains are blocked?
> It mentions stats about child exploitation but doesn't show how that's related to gtlds. Yeah, I wondered about that too. Any young people I know can barely tell you what a domain is. They're not directly visiting websites AFAIK and I don't think any of the platforms require a domain to participate. > 9% experience online sexual extortion before the age of 18 That's an astronomical number and I'd assume it has to b…
These days especially it seems like nearly every measure relating to "cybersecurity" or regulation in the online space in any way is always hitching itself loudly to some form of child sex abuse - I don't blame these various lobbyists for trying, since it's obviously a winning formula. Bring up a universally loathed offense, explain that your new scheme is somehow "needed" to cut down on it, then shout down your opposition as "soft on child abuse."
It's the playbook used in 2001 when it was The Terrorists. I suspect that since moral relativism has resulted in many people being unsure if even the sickest terrorists, who behead their prisoners on camera with a dull sword, might actually just be misunderstood freedom-fighters, now there's a new favorite bogeyman, this one more resistant to political reframing.