Live data from Hacker News

DNS abuse and criminal infrastructure

labs.ripe.net

41–50 of 52 posts

Re: DNS abuse and criminal infrastructure

#42
"The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis."

I don't disagree with the general assertion / hypothesis that bad actors register a lot of domains. But the data comes from an industry which does a poor job of categorization, doesn't agree on categories, and absolutely does not publish statistics on corrections. Nor is it easy to request corrections. Nor does it seem that corrections are felt to be necessary absent customer complaints. There is too little basic science and integrity in the process.

This is not new, the industry has quite frankly always been like this.

"Any industry confronted with evidence that a material share of its output may be controlled by bad actors should be seriously concerned." Too much category confusion to go through it all, for this statement, in this context. But yes. The domain sector isn't just people selling domains, it is also people who make money preventing you from being able to use a domain, and people doing arbitrage on your domain before you can even put it on-line. So I ask: are these "good" actors? How do we know? What's the standard?

It's too hard to get a response from most parts of this sector, and a lot of it is corrupt.

Let's start with registrars, because nobody starts there: I had a registrar literally catch fire. Basically out of business at that point. Because their systems were down they couldn't transfer the domains. I had to file a formal dispute with ICANN, six weeks of back and forth and waiting later, they handed the domains to some registrar I'd never heard of and had no existing business relationship with. (Not a great registrar.) This happened in 2017, don't tell yourself that things have improved since then.,

Then we have the email reputation services which spam on their own account: http://athena.m3047/pub/soe/abusix-spam-backstory.html

As well as reputation services spamming because someone paid them to do it (they send email to domains which they block, with their own servers): http://athena.m3047/pub/soe/pphosted-vmed.png I'd originally put this down to a three body problem: https://consulting.m3047.net/dubai-letters/blocking-esps-pla... (technically what you're seeing in the screenshot is me blocking them as a favor since they can't seem to manage it on their own).

The industry is rotten. https://consulting.m3047.net/dubai-letters/ptn-industry-trus...

Re: DNS abuse and criminal infrastructure

#43

This article is pretty light on details. The linked presentation goes into a lot more detail with statistics about which registrars and organizations are the worst offenders etc. https://view.officeapps.live.com/op/view.aspx?src=https%3A%2...

Wow I was at ICANN Seville and missed this talk. Thanks for the link.

Re: DNS abuse and criminal infrastructure

#46
post #45

Earlier quoted context omitted.

One key to one name?

Cool cool cool, where can I get a key? What if some other key has a name I've trademarked in my region?

Generally, clients generate keys. If someone gets there before you do, then you are SOL. You will have to take a name close to but not identical to your trademark.

Re: DNS abuse and criminal infrastructure

#47

The internet DNS system is broken in multiple ways. We would do better to have a shared DHT table with unique keys addressable to names.

Checkout the GNU name system https://www.gnunet.org/en/gns.html

However, the problem is inherently "{unique, short, decentralized}, pick two". GNUnet allows everyone to freely build their associations of names to public keys. But people still desire globally unique urls they can share and print on paper, so naturally, distributions will still package such "root certificates" by default and most people will trust the same provider of "com". But it's easy for anyone to share their own set of name-key pairs and for users to decide to call them "com" instead, for example if the original organisation managing .com censors some domains (stops published a record signed with their key). However, one would then need to translate urls when sharing them to others, or convicntthem to reconfigure their systems

Re: DNS abuse and criminal infrastructure

#48
post #2

I have some experience of dealing with this when working for .gov.uk A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims. By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on w…

What legitimate users need something provisioned so quickly on no/short notice.

One of those "a lack of planning on your part does not constitute an emergency on my part" situations.

There could always be special dispensation for known entities to break the rules, if they've got an existing relationship / agreement (which essentially means they've already done the necessary KYC).

Re: DNS abuse and criminal infrastructure

#49
post #6
post #5

Earlier quoted context omitted.

On the other hand, I struggle to think of a reason how harm could come from delayed activation of a registered public name. Can you describe a use case that cannot be solved by opting for a subdomain of an already-existing domain?

England have just scored the winning goal in the world cup and I want to celebrate by launching my personal tribute on Lionesses.rock Why shouldn't that go live instantly? A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now. I've had a brilliant idea for an eCommerce website but it is 1705 on a Friday night and, because…

... and nothing of value was lost

Re: DNS abuse and criminal infrastructure

#50
post #47

The internet DNS system is broken in multiple ways. We would do better to have a shared DHT table with unique keys addressable to names.

Checkout the GNU name system https://www.gnunet.org/en/gns.html However, the problem is inherently "{unique, short, decentralized}, pick two". GNUnet allows everyone to freely build their associations of names to public keys. But people still desire globally unique urls they can share and print on paper, so naturally, distributions will still package such "root certificates" by default and most people will trust the…

Yep, Gnu has a lot of great ideas, but it seems like the implementations always get scotched.
Post reply on HN