Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

31–40 of 261 posts

Re: Microsoft takes down No-IP.com domains

#31
post #25

Earlier quoted context omitted.

I use their service and am a bit concerned that I've not heard about this until now and taking a look at their blog/website I see no information about this.

i believe everything I see in uncited hacker news comment threads too.

Which part of this is un-cited? The article linked is fairly conclusive evidence that this is in fact a real thing.

Re: Microsoft takes down No-IP.com domains

#32
post #19

Earlier quoted context omitted.

A quick search shows exactly what he means. No elaboration necessary. http://www.webhostingtalk.com/showthread.php?t=1235995 http://www.organicweb.com.au/17240/internet/cloudflare-secur... http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...

In all 3 links this is the only relevant part I've been able to find regarding them being malicious: > Heck, if the DDoS for hire services protect themselves against DDoS attacks by using CloudFlare then CloudFlare must be damn good! So they protect their customers from DDoS attacks. All of them. I see nothing bad in this. Saying they shouldn't is like saying a government should put all criminals together in a villag…

As far as I understand it the problem is as follows:

1. Bad guys get a site behind cloudflare, and host illegal content

2. You want to report said bad guys to their host, for whatever reason.

3. You discover they use cloudflare. You now do not know where they are hosted.

4. Cloudflare will not tell you their actual IP addresses.

Re: Microsoft takes down No-IP.com domains

#33
post #21

So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware? Where is the due process? Where is the oversight in this? All I'm seeing is vigilanteism.

Court-authorized vigilantism.

By definition, if it's court-authorized, it's not vigilantism.

Re: Microsoft takes down No-IP.com domains

#34

According to Reuters, Microsoft is only sending traffic from computers that are infected with malware to Microsoft instead of No-IP. http://uk.reuters.com/article/2014/06/30/us-cybercrime-micro... That may still make people uncomfortable, but it seems much less egregious than Microsoft taking control of No-IP's domains, which is what this press release implies. Edit: the reuters article is in error here, not the Micr…

> Microsoft is only sending traffic from computers that are infected to Microsoft instead of No-IP.

Unfortunately that's false. See below:

dig -t ns no-ip.biz

; > DiG 9.9.2-P2 > -t ns no-ip.biz ;; global options: +cmd ;; Got answer: ;; ->>HEADER;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4000 ;; QUESTION SECTION: ;no-ip.biz. IN NS

;; ANSWER SECTION: no-ip.biz. 7154 IN NS ns8.microsoftinternetsafety.net. no-ip.biz. 7154 IN NS ns7.microsoftinternetsafety.net.

;; ADDITIONAL SECTION: ns8.microsoftinternetsafety.net. 3560 IN A 157.56.78.93

;; Query time: 3 msec ;; SERVER: 10.1.1.3#53(10.1.1.3) ;; WHEN: Mon Jun 30 14:14:47 2014 ;; MSG SIZE rcvd: 117

Re: Microsoft takes down No-IP.com domains

#36

Loads of self-congratulating tripe. Microsoft why don't you simply provide free OS upgrades or fixes for the millions of XP computers out there? They are not going anywhere soon. Next thing we know your lawyers and lobbyists are going to come up with some legislative wheeze and you will be running the biggest botnet in the world. You created the problem so fix it yourself.

Wholly predictable downvoting by anonymously cowardly Microsoft brown-nosers.

Re: Microsoft takes down No-IP.com domains

#38
post #19

Earlier quoted context omitted.

In all 3 links this is the only relevant part I've been able to find regarding them being malicious: > Heck, if the DDoS for hire services protect themselves against DDoS attacks by using CloudFlare then CloudFlare must be damn good! So they protect their customers from DDoS attacks. All of them. I see nothing bad in this. Saying they shouldn't is like saying a government should put all criminals together in a villag…

As far as I understand it the problem is as follows: 1. Bad guys get a site behind cloudflare, and host illegal content 2. You want to report said bad guys to their host, for whatever reason. 3. You discover they use cloudflare. You now do not know where they are hosted. 4. Cloudflare will not tell you their actual IP addresses.

If it's illegal and you're harmed I'm sure you can sue the people who did it and CloudFlare will have to hand over IP addresses. But is it CloudFlare's duty to police the Internet? Like ISPs, I think they should be content neutral unless illegal content like child porn is being hosted. Merely talking about services is not illegal as far as I know; only performing the DDoS attacks is.

Re: Microsoft takes down No-IP.com domains

#39
post #21

So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware? Where is the due process? Where is the oversight in this? All I'm seeing is vigilanteism.

Next time, read the rest of the article?

> Microsoft has seen more than 7.4 million Bladabindi-Jenxcus detections over the past 12 months, which doesn’t account for detections by other anti-virus providers. Despite numerous reports by the security community on No-IP domain abuse, the company has not taken sufficient steps to correct, remedy, prevent or control the abuse or help keep its domains safe from malicious activity.

> On June 19, Microsoft filed for an ex parte temporary restraining order (TRO) from the U.S. District Court for Nevada against No-IP. On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats.

No-IP in the past has denied allegations, e.g. the Cisco blog post linked to by Microsoft was denied here: http://www.noip.com/blog/2014/02/12/cisco-malware-report/

This is also a temporary order, it's not permanent.

Sure, it's creepy when courts have control over DNS entries, but ... they do. The Internet isn't lawless, it operates within the legal bounds of each country that participates.

I wonder what No-IP will say next and if figures collected by independent groups verify their "swift action" against security threats. As a company providing DDNS services, I wouldn't expect them to understand and use the latest in packet filtering techniques, but ... abuse is abuse and I'm sure they submitted evidence that this was required, temporarily.

Post reply on HN