Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

51–60 of 261 posts

Re: Microsoft takes down No-IP.com domains

#51
post #5
post #3

FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).

> unlike, say, CloudFlare Care to elaborate?

I have multiple horror stories from my days at Malwarebytes about CloudFlare. They absolutely refuse to take down people who abuse their network- at best they'll block a single file from being distributed, but then the malware authors simply change the name of the file (or, more commonly, dynamically name the file something completely random). Their network is fantastic for malicious activity, not only because of the technology but because of their policies around it.

They will do everything to keep bad sites up, even flat out lying. Here's Matt Prince, their CEO, claiming that Malwarebytes was blocking their CDN because of "political" reasons, even though we had emailed him actual PCAP files showing that their network was distributing malware-

https://forums.malwarebytes.org/index.php?/topic/108447-my-s...

Despite the fact that Malwarebytes actively engages with communities and groups that teach people who to manage malware removal, and have always stood for free speech and only removes harmful software, Matt Prince tried to deflect front the truth of the situation by claiming this was about censorship. Really all it was about was that multiple clients of theirs were hosting pages that were actively infecting thousands of computers.

To make matters worse they put these customers who are hosting active exploits and malware right next to their small business customers, so any time someone threatens to block them they hide behind the innocent victims who are caught in the cross fire.

I should point out that I no longer work at Malwarebytes, and this all took place several years ago. I am only speaking about the portions of this that were public, and you can find all of that in the Malwarebytes forums and other places online.

Re: Microsoft takes down No-IP.com domains

#53

"On June 19, Microsoft filed for an ex parte temporary restraining order (TRO) from the U.S. District Court for Nevada against No-IP. On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. " How can this be legal? Does this mean that if…

It's an ex parte order, so presumably Vitalwerks didn't show up in court despite the summons? If you filed for a TRO against Microsoft and their lawyers ignored it, something bad might happen to them too.

Re: Microsoft takes down No-IP.com domains

#54
post #44

Loads of self-congratulating tripe. Microsoft why don't you simply provide free OS upgrades or fixes for the millions of XP computers out there? They are not going anywhere soon. Next thing we know your lawyers and lobbyists are going to come up with some legislative wheeze and you will be running the biggest botnet in the world. You created the problem so fix it yourself.

Probably because Windows XP is well over 10 years old. You can't possibly expect them to support it forever just because some organisations can't be bothered to upgrade.

What organizations? Do you have an idea about how many small business and home users are still running Windows XP?

As far as they are concerned if it is capable of doing what they bought it for, why should they upgrade? Software doesn't wear out or breakdown like a physical good and a lot of the hardware is still fine. Those systems are going to be around forever until the hardware breaks down.

They are also committed to providing upgrades for their bigger customers, so why can't they extend to everyone else, as though it will cost them extra? The only caveat for the non corporate customers should be that if they are not under a support contract and the upgrades break their systems they are out of luck.

Re: Microsoft takes down No-IP.com domains

#55

Loads of self-congratulating tripe. Microsoft why don't you simply provide free OS upgrades or fixes for the millions of XP computers out there? They are not going anywhere soon. Next thing we know your lawyers and lobbyists are going to come up with some legislative wheeze and you will be running the biggest botnet in the world. You created the problem so fix it yourself.

Wholly predictable downvoting by anonymously cowardly Microsoft brown-nosers.

Fine. I downvoted you, and it's no longer anonymous. I downvoted you because both of your comments were filled with passionate garbage rather than any well-reasoned thought. I'd be willing to bet other downvoters were not simply cowardly Microsoft brown-nosers.

Re: Microsoft takes down No-IP.com domains

#56

Earlier quoted context omitted.

> Microsoft is only sending traffic from computers that are infected to Microsoft instead of No-IP. Unfortunately that's false. See below: dig -t ns no-ip.biz ; > DiG 9.9.2-P2 > -t ns no-ip.biz ;; global options: +cmd ;; Got answer: ;; ->>HEADER ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4000 ;; QUESTION SECTION: ;no-ip.biz. IN NS ;; ANSWER SECTION: no-ip.biz. 7154 IN NS ns8.microsoftinternetsafety.net. n…

What DNS are you using? On Google (8.8.8.8) or Comcast DNS I'm not seeing this for their top domains (no-ip.org, no-ip.biz, no-ip.info). I wonder if your ISP is working with Microsoft.

It's strange, I've yet to see it too, in Canada. Must be within a limited area for the ISP, or thanks to the collaboration with A10 Networks.

E.g. https://www.whatsmydns.net/#NS/no-ip.com

Re: Microsoft takes down No-IP.com domains

#57
post #44

Loads of self-congratulating tripe. Microsoft why don't you simply provide free OS upgrades or fixes for the millions of XP computers out there? They are not going anywhere soon. Next thing we know your lawyers and lobbyists are going to come up with some legislative wheeze and you will be running the biggest botnet in the world. You created the problem so fix it yourself.

Probably because Windows XP is well over 10 years old. You can't possibly expect them to support it forever just because some organisations can't be bothered to upgrade.

"Software doesn't wear out or breakdown like a physical good"

Well, uh, then why does Microsoft need to do anything, if it's still as good as they day it was first sold?

Re: Microsoft takes down No-IP.com domains

#58
Just ran a dig +trace on no-ip.biz. Just... wtf. Who had acted upon that court order?! I thought that the days the US had full control over the internet were LONG past. `

    biz.                    172800  IN      NS      a.gtld.biz.
    biz.                    172800  IN      NS      b.gtld.biz.
    biz.                    172800  IN      NS      c.gtld.biz.
    biz.                    172800  IN      NS      e.gtld.biz.
    biz.                    172800  IN      NS      f.gtld.biz.
    biz.                    172800  IN      NS      k.gtld.biz.
    ;; Received 308 bytes from 192.203.230.10#53(192.203.230.10) in 526 ms

    no-ip.biz.              7200    IN      NS      NS7.MICROSOFTINTERNETSAFETY.NET.
    no-ip.biz.              7200    IN      NS      NS8.MICROSOFTINTERNETSAFETY.NET.
    ;; Received 90 bytes from 209.173.58.66#53(209.173.58.66) in 150 ms

    no-ip.biz.              76834   IN      NS      nf5.no-ip.com.
    no-ip.biz.              76834   IN      NS      nf2.no-ip.com.
    no-ip.biz.              76834   IN      NS      nf4.no-ip.com.
    no-ip.biz.              76834   IN      NS      nf3.no-ip.com.
    no-ip.biz.              76834   IN      NS      nf1.no-ip.com.
    ;; Received 206 bytes from 157.56.78.73#53(157.56.78.73) in 344 ms

Re: Microsoft takes down No-IP.com domains

#59
post #27
post #4

Earlier quoted context omitted.

While I'm not familiar with the exact situation here, I suspect the real problem is that the malware domains are being automatically created en masse, and No-IP have been slow or reluctant to do anything to slow that down. Being responsive to complaints is good for small-scale problems involving individual domains, but basically useless for large-scale abuse.

what if a company like microsoft approach you and say "look, i make billions while you make a few thousands, but please, go ahead and change your service because it is impacting my billion dollar windows sales and i can't be bothered to patching it on my product" granted, i'm not familiar with the matter. but I know what I would answer. also, removing noip or noip enabling whatever microsoft was bullying them to impl…

> "look, i make billions while you make a few thousands, but please, go ahead and change your service because it is impacting my billion dollar windows sales and i can't be bothered to patching it on my product"

How can they patch it in their product without turning desktop Windows into something like iOS or Windows Phone/RT?

Even Android has a ton of malware so the notion that Windows is somehow more hole ridden than other platforms stopped being true starting about 10 years ago with their Secure computing initiative. If the user can install Firefox, they can install malware. If Firefox doesn't need to get permission from MS for their next version, Windows cannot distinguish between Firefox.exe and Codec_Flash_Shady.exe. Sandboxing will disable system level utilities.

MS is capable of making secure OSes. How many viruses and trojans do the 3 Xboxes, Windows Phone and RT have? Even Windows Server is pretty secure(atleast as secure as Linux) unless the admins start browsing on it. Malware is a real threat to any popular OS unless third party apps are entirely blocked or restricted by the use of a approval based App Store. Windows gives much more control to the user, which is why many users are able to stay away from infections. And it's ironic that you're blaming MS here instead of the folks that propagate it(including a YC company https://www.techdirt.com/articles/20130115/17343321692/why-a...) and people who install it(users).

Remember the shitstorm that was raised against MS on here and elsewhere when they tried to secure users by preventing undetectable rootkits by enabling Secure Boot?

Re: Microsoft takes down No-IP.com domains

#60

Earlier quoted context omitted.

> Microsoft is only sending traffic from computers that are infected to Microsoft instead of No-IP. Unfortunately that's false. See below: dig -t ns no-ip.biz ; > DiG 9.9.2-P2 > -t ns no-ip.biz ;; global options: +cmd ;; Got answer: ;; ->>HEADER ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4000 ;; QUESTION SECTION: ;no-ip.biz. IN NS ;; ANSWER SECTION: no-ip.biz. 7154 IN NS ns8.microsoftinternetsafety.net. n…

What DNS are you using? On Google (8.8.8.8) or Comcast DNS I'm not seeing this for their top domains (no-ip.org, no-ip.biz, no-ip.info). I wonder if your ISP is working with Microsoft.

Ha. Good point. This was done at work, where we use MS Server's DNS.

I'm not sure if this is an artifact of our longer TTL, if MS is updating MS server DNS entries, or something else. Either way, at some point in time or in certain places, traffic resolved by no-ip was/is under Microsoft control.

EDIT: Looks like it may actually be a result of our shorter TTL, since google DNS appears to have 5.7 hours left on their records for no-ip.

Confirmed by a couple queries to the {a..k}.gtld.biz nameservers.

Post reply on HN