Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

61–70 of 261 posts

Re: Microsoft takes down No-IP.com domains

#62

Earlier quoted context omitted.

> Microsoft is only sending traffic from computers that are infected to Microsoft instead of No-IP. Unfortunately that's false. See below: dig -t ns no-ip.biz ; > DiG 9.9.2-P2 > -t ns no-ip.biz ;; global options: +cmd ;; Got answer: ;; ->>HEADER ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4000 ;; QUESTION SECTION: ;no-ip.biz. IN NS ;; ANSWER SECTION: no-ip.biz. 7154 IN NS ns8.microsoftinternetsafety.net. n…

What DNS are you using? On Google (8.8.8.8) or Comcast DNS I'm not seeing this for their top domains (no-ip.org, no-ip.biz, no-ip.info). I wonder if your ISP is working with Microsoft.

This is simply a side-effect of how DNS updates. The data is propagating right now, as the root nameservers for the .biz tld are already returning the Microsoft DNS servers as the correct response. The TTL for the root appears to be a day, so you should see this everywhere in 14 hours from this post.

Source: 'whois' and 'dig +trace'

Re: Microsoft takes down No-IP.com domains

#63

So does this mean no-ip.com is no more, or only a subset of their domains?

It means, temporarily, a subset of traffic known to be from these viruses should be blocked, within part of the US, it seems.

Being in the Netherlands I can confirm that I got the same results as https://news.ycombinator.com/item?id=7967853, so not just the US.

Re: Microsoft takes down No-IP.com domains

#64
post #21

So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware? Where is the due process? Where is the oversight in this? All I'm seeing is vigilanteism.

Next time, read the rest of the article? > Microsoft has seen more than 7.4 million Bladabindi-Jenxcus detections over the past 12 months, which doesn’t account for detections by other anti-virus providers. Despite numerous reports by the security community on No-IP domain abuse, the company has not taken sufficient steps to correct, remedy, prevent or control the abuse or help keep its domains safe from malicious ac…

It's not clear who determines what "sufficient steps" would be, however. That could range from 'No-IP did nothing at all' to 'they tried and we weren't impressed'. The MS claim that "free dynamic dns is frequently exploited by cybercriminals" seems like hand-waving, to me. It's also used legitimately by millions of people who have home routers which came with support for No-IP baked into firmware...

Re: Microsoft takes down No-IP.com domains

#66

> On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. Something about this bothers me. So the courts granted MS the rights to essentially take over No-IP's DNS in order to "identify" ... "bad traffic?" The implications of this are...…

Agreed. Arguably the net effect in this particular case was positive, but I can easily imagine reading this press release in a parallel universe: "Today, Sony Pictures has upped the ante against global cybercrime, taking legal action to clean up piracy... We're taking YouTube to task as the owner of infrastructure frequently exploited by cybercriminals to infringe copyrights by uploading unauthorized movie clips... O…

Isn't that close to what happened to Mega Upload and domain handed over to the government?

Re: Microsoft takes down No-IP.com domains

#67
post #53

"On June 19, Microsoft filed for an ex parte temporary restraining order (TRO) from the U.S. District Court for Nevada against No-IP. On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. " How can this be legal? Does this mean that if…

It's an ex parte order, so presumably Vitalwerks didn't show up in court despite the summons? If you filed for a TRO against Microsoft and their lawyers ignored it, something bad might happen to them too.

Ex parte order can be given even if Vitalwerks does show up (source: divorce court). Ex-parte simply means that it was an emergency and couldn't wait.

However, it also means that a new full hearing has been setup (likely in 2 weeks or so) where both parties can argue their case. The full decision will be taken then.

Re: Microsoft takes down No-IP.com domains

#69
post #20

Has I understood this correctly? Microsoft, a private company, has been granted the right to filter all dns traffic, and choose what will bee forward to this other company, No-IP. No-IP will so bee allowed to run there service for the remaining customers Microsoft approves? Is this common practices in the us legal system? Would it work like this in the offline world also? If my neighbor sometimes had loud parties tha…

>If my neighbor sometimes had loud parties that bothered me, could I be granted the right to stand in front of his door

What if they were bothering 7.4 million people and inconveniencing many more?

And then didn't show up in court in spite of summons? The police or courts will take that far more seriously.

Re: Microsoft takes down No-IP.com domains

#70

Earlier quoted context omitted.

Next time, read the rest of the article? > Microsoft has seen more than 7.4 million Bladabindi-Jenxcus detections over the past 12 months, which doesn’t account for detections by other anti-virus providers. Despite numerous reports by the security community on No-IP domain abuse, the company has not taken sufficient steps to correct, remedy, prevent or control the abuse or help keep its domains safe from malicious ac…

It's not clear who determines what "sufficient steps" would be, however. That could range from 'No-IP did nothing at all' to 'they tried and we weren't impressed'. The MS claim that "free dynamic dns is frequently exploited by cybercriminals" seems like hand-waving, to me. It's also used legitimately by millions of people who have home routers which came with support for No-IP baked into firmware...

> It's not clear who determines what "sufficient steps" would be

its perfectly clear. the courts.

Post reply on HN