Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

41–50 of 261 posts

Re: Microsoft takes down No-IP.com domains

#42
post #6

Any alternatives for free dynamic DNS?

If you own a domain name, a lot of registrars let you query some https endpoint to update DNS, which you can plug into firmware like DD-WRT. Namecheap, for one, does. I know this because I did it this morning after no-ip stopped working for me.

Re: Microsoft takes down No-IP.com domains

#43
post #19

Earlier quoted context omitted.

A quick search shows exactly what he means. No elaboration necessary. http://www.webhostingtalk.com/showthread.php?t=1235995 http://www.organicweb.com.au/17240/internet/cloudflare-secur... http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...

In all 3 links this is the only relevant part I've been able to find regarding them being malicious: > Heck, if the DDoS for hire services protect themselves against DDoS attacks by using CloudFlare then CloudFlare must be damn good! So they protect their customers from DDoS attacks. All of them. I see nothing bad in this. Saying they shouldn't is like saying a government should put all criminals together in a villag…

> Should CloudFlare play for judge and ban people that do not violate their terms? Because I'm sure they boot people that perform illegal activities on their network or otherwise harm their network from within, but I can see why they don't proactively take down any website mentioning "we offer DDoS attacks".

DDoS attacks are illegal in most countries, including the US where CloudFlare operates. It would be reasonable for them to include something in their terms about not allowing illegal activities. Then, if it's brought to their attention via a verifiable abuse complaint, yes, they should cease providing service to that user. They are a private company and do not have the obligation to provide service to any particular person; there is no "rights" issue here.

Proactively, as in proactively monitoring and reviewing each site they provide service to, would no doubt be a huge burden and difficult or impossible, but I don't think anyone has suggested that. The only thing they need to be doing is the same as any responsible ISP, have an abuse@ mailbox (which they do), review and take the appropriate action on complaints.

Re: Microsoft takes down No-IP.com domains

#44

Loads of self-congratulating tripe. Microsoft why don't you simply provide free OS upgrades or fixes for the millions of XP computers out there? They are not going anywhere soon. Next thing we know your lawyers and lobbyists are going to come up with some legislative wheeze and you will be running the biggest botnet in the world. You created the problem so fix it yourself.

Probably because Windows XP is well over 10 years old. You can't possibly expect them to support it forever just because some organisations can't be bothered to upgrade.

Re: Microsoft takes down No-IP.com domains

#45

> On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. Something about this bothers me. So the courts granted MS the rights to essentially take over No-IP's DNS in order to "identify" ... "bad traffic?" The implications of this are...…

Agreed. Arguably the net effect in this particular case was positive, but I can easily imagine reading this press release in a parallel universe:

"Today, Sony Pictures has upped the ante against global cybercrime, taking legal action to clean up piracy... We're taking YouTube to task as the owner of infrastructure frequently exploited by cybercriminals to infringe copyrights by uploading unauthorized movie clips... On June 26, the court granted our request and made Sony the DNS authority for youtube.com, allowing us to identify and route all known infringing traffic to the Sony sinkhole and identify users who posted unauthorized content."

Re: Microsoft takes down No-IP.com domains

#46

According to Reuters, Microsoft is only sending traffic from computers that are infected with malware to Microsoft instead of No-IP. http://uk.reuters.com/article/2014/06/30/us-cybercrime-micro... That may still make people uncomfortable, but it seems much less egregious than Microsoft taking control of No-IP's domains, which is what this press release implies. Edit: the reuters article is in error here, not the Micr…

> Microsoft is only sending traffic from computers that are infected to Microsoft instead of No-IP. Unfortunately that's false. See below: dig -t ns no-ip.biz ; > DiG 9.9.2-P2 > -t ns no-ip.biz ;; global options: +cmd ;; Got answer: ;; ->>HEADER ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4000 ;; QUESTION SECTION: ;no-ip.biz. IN NS ;; ANSWER SECTION: no-ip.biz. 7154 IN NS ns8.microsoftinternetsafety.net. n…

What DNS are you using?

On Google (8.8.8.8) or Comcast DNS I'm not seeing this for their top domains (no-ip.org, no-ip.biz, no-ip.info).

I wonder if your ISP is working with Microsoft.

Re: Microsoft takes down No-IP.com domains

#47
post #38

Earlier quoted context omitted.

As far as I understand it the problem is as follows: 1. Bad guys get a site behind cloudflare, and host illegal content 2. You want to report said bad guys to their host, for whatever reason. 3. You discover they use cloudflare. You now do not know where they are hosted. 4. Cloudflare will not tell you their actual IP addresses.

If it's illegal and you're harmed I'm sure you can sue the people who did it and CloudFlare will have to hand over IP addresses. But is it CloudFlare's duty to police the Internet? Like ISPs, I think they should be content neutral unless illegal content like child porn is being hosted. Merely talking about services is not illegal as far as I know; only performing the DDoS attacks is.

Have fun filing lawsuits and sending out subpoenas when you're just trying to host a game server as a hobby and not making money off it. Cross-jurisdictional issues will also make this very difficult, even if you know who the attacker is.

Re: Microsoft takes down No-IP.com domains

#49
post #20

Has I understood this correctly? Microsoft, a private company, has been granted the right to filter all dns traffic, and choose what will bee forward to this other company, No-IP. No-IP will so bee allowed to run there service for the remaining customers Microsoft approves? Is this common practices in the us legal system? Would it work like this in the offline world also? If my neighbor sometimes had loud parties tha…

It's a temporary restraining order. It obviously affects Microsoft's products and its customers. It would be equivalent to say, blocking a phone switch that was misbehaving and calling you continuously causing a denial of service attack. That Microsoft customers are suffering more than Microsoft itself and that No-IP appeared to be in denial seems to support the temporary restraining order -- No-IP, aware of such reports via blog posts, chooses to do nothing by asking for reports rather than investigating and stopping the behaviour themselves.

Re: Microsoft takes down No-IP.com domains

#50
post #38

Earlier quoted context omitted.

As far as I understand it the problem is as follows: 1. Bad guys get a site behind cloudflare, and host illegal content 2. You want to report said bad guys to their host, for whatever reason. 3. You discover they use cloudflare. You now do not know where they are hosted. 4. Cloudflare will not tell you their actual IP addresses.

If it's illegal and you're harmed I'm sure you can sue the people who did it and CloudFlare will have to hand over IP addresses. But is it CloudFlare's duty to police the Internet? Like ISPs, I think they should be content neutral unless illegal content like child porn is being hosted. Merely talking about services is not illegal as far as I know; only performing the DDoS attacks is.

I agree they should not be policing. Instead they should allow you to contact the people who are hosting the actual content. Which is where DMCA notices have to go to, for example. Since they do not host the content, they claim the DMCA should not be sent to them, but they won't tell you who to contact instead.
Post reply on HN