Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

21–30 of 261 posts

Re: Microsoft takes down No-IP.com domains

#21
So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware?

Where is the due process? Where is the oversight in this? All I'm seeing is vigilanteism.

Re: Microsoft takes down No-IP.com domains

#22
So let me get this straight. Microsoft got a court order to route all of another entity's DNS traffic to their servers. Giving them the ability to route a metric crap-ton of private traffic through their data centers. For "security". I call shenanigans.

I'm also assuming this is why my no-ip domain disappeared this morning, leaving me with no access to my home servers.

Perhaps the linux on my servers is considered malware. It sure is malicious to Microsoft's bottom line. I kid, but only a little.

Re: Microsoft takes down No-IP.com domains

#24
post #21

So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware? Where is the due process? Where is the oversight in this? All I'm seeing is vigilanteism.

Court-authorized vigilantism.

Re: Microsoft takes down No-IP.com domains

#25
post #3

FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).

I use their service and am a bit concerned that I've not heard about this until now and taking a look at their blog/website I see no information about this.

i believe everything I see in uncited hacker news comment threads too.

Re: Microsoft takes down No-IP.com domains

#26
According to Reuters, Microsoft is only sending traffic from computers that are infected with malware to Microsoft instead of No-IP.

http://uk.reuters.com/article/2014/06/30/us-cybercrime-micro...

That may still make people uncomfortable, but it seems much less egregious than Microsoft taking control of No-IP's domains, which is what this press release implies.

Edit: the reuters article is in error here, not the Microsoft Blog. See below. Turns out this really is as egregious as it sounds.

Re: Microsoft takes down No-IP.com domains

#27
post #4
post #3

FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).

While I'm not familiar with the exact situation here, I suspect the real problem is that the malware domains are being automatically created en masse, and No-IP have been slow or reluctant to do anything to slow that down. Being responsive to complaints is good for small-scale problems involving individual domains, but basically useless for large-scale abuse.

what if a company like microsoft approach you and say "look, i make billions while you make a few thousands, but please, go ahead and change your service because it is impacting my billion dollar windows sales and i can't be bothered to patching it on my product"

granted, i'm not familiar with the matter. but I know what I would answer. also, removing noip or noip enabling whatever microsoft was bullying them to implement, would just delay it a few days until the worm creators rolled out their own service. heck that can even motivate them to get creative and encode IPs in a obfuscated pastebin, or stenographed in cat pictures in reddit, or noise mp3 in soundcloud... maybe having them rely on noip was good....

but again, i have no knowledge of the matter. maybe noip was being paid even after knowing it was for worms. who knows?

Re: Microsoft takes down No-IP.com domains

#28
post #19

Earlier quoted context omitted.

A quick search shows exactly what he means. No elaboration necessary. http://www.webhostingtalk.com/showthread.php?t=1235995 http://www.organicweb.com.au/17240/internet/cloudflare-secur... http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...

In all 3 links this is the only relevant part I've been able to find regarding them being malicious: > Heck, if the DDoS for hire services protect themselves against DDoS attacks by using CloudFlare then CloudFlare must be damn good! So they protect their customers from DDoS attacks. All of them. I see nothing bad in this. Saying they shouldn't is like saying a government should put all criminals together in a villag…

The point being made above is that Cloudflare charges users to protect them from attacks, but they're also providing protection (from attacks and identification) to the people performing the attacks. To many, it appears that they're helping to allow malicious activity because it benefits the sale of their services.

Re: Microsoft takes down No-IP.com domains

#29
post #21

So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware? Where is the due process? Where is the oversight in this? All I'm seeing is vigilanteism.

The due process is that Microsoft sued the malware distributors and the court granted them a restraining order.

"In a civil case filed on June 19, Microsoft named two foreign nationals, Mohamed Benabdellah and Naser Al Mutairi, and a U.S. company, Vitalwerks Internet Solutions, LLC (doing business as No-IP.com), for their roles in creating, controlling, and assisting in infecting millions of computers with malicious software — harming Microsoft, its customers and the public at large. ...

On June 19, Microsoft filed for an ex parte temporary restraining order (TRO) from the U.S. District Court for Nevada against No-IP. On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats."

Re: Microsoft takes down No-IP.com domains

#30
post #5
post #3

FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).

> unlike, say, CloudFlare Care to elaborate?

Sure. I made a post a few weeks ago at https://news.ycombinator.com/item?id=7880514. There's other relevant posts in the same thread as well, but that's probably the best overview.
Post reply on HN