DNS abuse and criminal infrastructure
31–40 of 52 posts
Re: DNS abuse and criminal infrastructure
#32Earlier quoted context omitted.
> It mentions stats about child exploitation but doesn't show how that's related to gtlds. Yeah, I wondered about that too. Any young people I know can barely tell you what a domain is. They're not directly visiting websites AFAIK and I don't think any of the platforms require a domain to participate. > 9% experience online sexual extortion before the age of 18 That's an astronomical number and I'd assume it has to b…
I'm no domain registry expert but I'm inclined to agree with you on 100% of this. Who needs a domain registration to cyber extort? Pretty sure they just DM that type of material to the victim and threaten to DM it to others. Simple. Same for distributing illicit materials. Pretty sure it's either dark web or private groups on platforms. These days especially it seems like nearly every measure relating to "cybersecuri…
Is there money to invest in resources for kids that need help? Nope. Is there money to implement a global surveillance system that tracks and logs everything for AI analysis while attributing it to verified identities? You betcha!
When I was a kid deleting your account and creating a new one was a good solution if someone started harassing you. That's been taken away and, even worse, normalizing verified IDs is eliminating the last tiny bit of privacy everyone has, including kids. The bad actors are going to be able to follow people around forever IMO.
Re: DNS abuse and criminal infrastructure
#33Earlier quoted context omitted.
A delay doesn’t even really hurt this use case. The first person to register the domain would still get it, 24 hours later, unless there’s an actual objection.
I think the "actual objection" is the hardest part. The UK Government might legitimately object to the registration of `dwpgov-uk-payments.pizza` but should they be allowed to object to `dwp-gov-uk-stole-my-payments.fart`? One might be obviously dodgy, the other is someone ranting about their experience. Do you think Governments should be able to object to domains complaining about them?
Re: DNS abuse and criminal infrastructure
#34Just just seems like a reason to have a truely distributed DNS system that is censorship resistant. The complaints presented should be _unfixable_ since they are a feature, not a bug.
an effort to do this: https://github.com/pubky/pkarr
Re: DNS abuse and criminal infrastructure
#35If you're starting a new commercial venture, something that cost $1000 and took a week would still be one of the cheapest and fastest parts of that process. If you're doing a hobby project or a speculative startup, using a subdomain would be fine. It worked for Altavista.digital.com and Google.stanford.edu.
The argument for shifting (back) to a model like that would be that the hierarchial DNS served as a chain of responsibility. Today a lot of companies irresponsibly use dozens of domains, presumably either because they think people are too stupid to learn to type an additional period in a name, or because their internal dysfunction makes provisioning a subdomain an 11-month project. It's terrible that citibankonline.com, citibank.com, citicards.com, citientertainment.com, citi.com, and citigroup.com are all official domains that Citigroup uses. A user seeing a link to, say, 'citicardbenefits dot com' has zero methods of establishing provenance.
And of course, under conditions where 2LDs were expensive again, 'free subdomains' would certainly still be a thing, as they even back were when .coms were $50 or whatever. We had cjb.net, a bunch of clever '.to' domains, afraid.org, etc.
Under the 'modern' system, the problem of "who do we need to contact about an obvious scam site" has been pushed up to the largest possible scale - the GTLD registries, whereas a scammer abusing a "free subdomain" would be shut down by the admins at that second level.
In the end though, I admit we're stuck with the current way, or, (possibly) some hare-brained KYC scheme that will subject everyone to a high level of government censorship and make anonymity unavailable to good actors who really deserve it.
Re: DNS abuse and criminal infrastructure
#36Earlier quoted context omitted.
England have just scored the winning goal in the world cup and I want to celebrate by launching my personal tribute on Lionesses.rock Why shouldn't that go live instantly? A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now. I've had a brilliant idea for an eCommerce website but it is 1705 on a Friday night and, because…
None of these require a domain to work. There’s plenty precedent of things taking off without having a domain, eg Wordle, all Neal.fun sites, Hacker News, and I’m probably forgetting a few obvious ones. I know that “mystupidvibecodedidea.com” is all the rage but nobody cares if that’s instead on yourname.com/mystupidvibecoded idea except you.
projects.example.com or new.cool.thing.example.com
So nothing stops me from registering a legitimate domain, using it for a bit, then launching the subdomain `pay-your-tax.gov.uk.official.example.com`
It must be legit - it has the .gov.uk in it!
Re: DNS abuse and criminal infrastructure
#37This article is pretty light on details. The linked presentation goes into a lot more detail with statistics about which registrars and organizations are the worst offenders etc. https://view.officeapps.live.com/op/view.aspx?src=https%3A%2...
For example, claiming 4 registry families having over a million blocker domains. But there aren't that many registries... and the domains under management by registry is... skewed. .com (verisign) is 37% of all domain registrations. Not to mention .net and other TLDs they manage. So the fact they come in below that number seems meaningless and skewed? I say this as someone who hates Verisign because they're a terrible monopolist.
Then the registrar families with highest domains blocked.
NameCheap registered 14m and had 1.1m abuse domains (~8%) gname had 3.1m with 1m abuse (~32%), dynadot (~20%), namesilo (~20%), godaddy (~5%). That feels pretty unfair calling out NameCheap and GoDaddy who have a fraction of the abuse the other 3 have but show up simply because of their scale?
The registrars with 50%+ of domains blacklisted and top one being 87% screams for an investigation though.
It seems to highlight some potentially suspect actors but also throwing some large companies under the bus simply because they're big?
Re: DNS abuse and criminal infrastructure
#38While I'm definitely not inclined to trust whoever wants to introduce new barriers, part of me actually thinks that the availability of second-level names (e.g. example.com), instantly, for trivially-low prices... maybe you could make a case that we get more harm than good from it. If you're starting a new commercial venture, something that cost $1000 and took a week would still be one of the cheapest and fastest par…
It’s still cheap to register and renew, but requires a traceable real connection to a company or a person:
> 5. Requirements for the applicant - who can apply?
> Organisations
> 5.1 The applicant must be an organisation that is registered in the Norwegian Central Coordinating Register for Legal Entities, see the list of which types of organisations can apply (Appendix E). The organisation must in fact conduct business and/or have activities and a presence according to information specified in the Central Coordinating Register, and it must document its actual existence if Norid requests such documentation. The organisation must have a Norwegian postal address.
> 5.2 Each organisation may at any time subscribe to up to 100 domain names directly under .no. In addition, an organisation may subscribe to up to 5 domain names under each geographic domain to which the organisation belongs, as well as 5 domain names under each category domain to which the organisation belongs.
> Private individuals
> 5.3 The applicant must be over age 18, registered in the Norwegian National Population Register with a Norwegian national identity number and have a Norwegian postal address.
> 5.4 Each private individual may at any time subscribe to up to 5 domain names directly under .no. In addition, a private individual may subscribe to up to 5 domain names under each geographic domain to which the person in question belongs, as well as 5 domain names under priv.no.
https://www.norid.no/en/om-domenenavn/regelverk-for-no/#5.-R...
It works well, and on top of that it is still possible for someone to host content on behalf of someone else to protect the anonymity of that other person, for example by as you said handing out free subdomains to others and handling complaints about scams and other undesirable or illegal things. With all the responsibility and legal liability that doing so incurs.
Re: DNS abuse and criminal infrastructure
#39Just just seems like a reason to have a truely distributed DNS system that is censorship resistant. The complaints presented should be _unfixable_ since they are a feature, not a bug.
Re: DNS abuse and criminal infrastructure
#40While I'm definitely not inclined to trust whoever wants to introduce new barriers, part of me actually thinks that the availability of second-level names (e.g. example.com), instantly, for trivially-low prices... maybe you could make a case that we get more harm than good from it. If you're starting a new commercial venture, something that cost $1000 and took a week would still be one of the cheapest and fastest par…
That's highly dependent on where you live.
I don't agree with the 3rd level domain structure. In fact, I don't think ICANN should allow registrars to sell those without clear disclosure informing registrants they're not ICANN domains. At the very least, registrars shouldn't be doing that to their customers.
In terms of abuse handling, you don't want to be a sibling to some unknown person or entity.
> Under the 'modern' system, the problem of "who do we need to contact about an obvious scam site" has been pushed up to the largest possible scale - the GTLD registries, whereas a scammer abusing a "free subdomain" would be shut down by the admins at that second level.
But I want my legitimate domain pushed up to the largest possible scale with a clear set of rules and independence from other registrants. In terms of governance, the average registrant couldn't tell you the difference between a 2nd level domain and a 3rd level domain and the 3rd level domain comes along with additional risk.
As soon as you add 3rd level domains, that's an extra party that can drop your domain. The 3rd level domain providers don't have a standard abuse handling mechanism. I think most of them try to defer to ICANN's rules, but there's nothing that says they must do that. As far as I know, ICANN only deals in TLDs [1].
What happens if you're on a 3rd level domain, there's an influx of abusive behavior by sibling domains, and the 2nd level owner doesn't do a good job of handling it? Does the 2nd level domain get banned by the gTLD? What kind of collateral damage does that cause?
Maybe you create something like the public suffix list, but then it's the same problem with more complexity regarding responsibilities.
I do agree with the general sentiment of letting people pay to prove trust. I think it's really hard to come up with a number that makes sense, but I'd be willing to pay $X into an abuse handling fund if it bought me extra trust for my domain(s).
1. https://www.icann.org/en/contracted-parties/registry-operato...