Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

101–110 of 261 posts

Re: Microsoft takes down No-IP.com domains

#101

Just ran a dig +trace on no-ip.biz. Just... wtf. Who had acted upon that court order?! I thought that the days the US had full control over the internet were LONG past. ` biz. 172800 IN NS a.gtld.biz. biz. 172800 IN NS b.gtld.biz. biz. 172800 IN NS c.gtld.biz. biz. 172800 IN NS e.gtld.biz. biz. 172800 IN NS f.gtld.biz. biz. 172800 IN NS k.gtld.biz. ;; Received 308 bytes from 192.203.230.10#53(192.203.230.10) in 526 m…

"full control over the internet" is distinct from control over US corporations. Dot biz is operated by Neustar and they are based in Virginia and thus subject to US Courts.

For example, they likely would have had less success enforcing a change on a .ir domain as the registry isn't located in US jurisdiction.

Re: Microsoft takes down No-IP.com domains

#102
post #3

FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).

At CloudFlare, we have a Trust & Safety team dedicated to dealing with the abuse of our network. We sit in front of more than 2 million sites. The vast majority of them are not controversial (the site you're reading this on, for instance), but some are not.

The majority of the abuse requests we receive are DMCA requests, but we get other reports as well. Dealing with these requests is a hard problem because a large number of the abuse requests we receive turn out to be attackers trying to get the origin IP in order to circumvent our protection. As I've blogged about before (http://blog.cloudflare.com/thoughts-on-abuse), we've designed an abuse system that attempts to act as a proxy: passing abuse requests to the customer and their host without exposing the customer's origin to attack.

Malware is one of the situations where we'll actually take content down because it is, per se, harmful. However, we also don't think terminating the customer who has malware hosted on their site is a good solution. Since we're a proxy, terminating the customer doesn't remove the malware from the Internet but instead just kicks the problem down the road to the host. Instead, we developed a system that replaces the infected URLs with a warning page to protect users. This has the ancillary benefit when a site is being used for botnet command and control of allowing us to gather data on machines that make up the botnet. This data is fed back into our system in order to better protect our customers and we're talking other organizations about a way of responsibly sharing this data.

Our Trust & Safety team works with trusted malware reporters regularly, including the team at Microsoft that handled the no-ip.com takedown. We will continue to adjust our process to walk the careful line between ensuring our network isn't causing per se harm while, at the same time, avoiding the risk of becoming a censor.

Matthew Prince / Co-founder & CEO, CloudFlare

Re: Microsoft takes down No-IP.com domains

#103
post #38

Earlier quoted context omitted.

If it's illegal and you're harmed I'm sure you can sue the people who did it and CloudFlare will have to hand over IP addresses. But is it CloudFlare's duty to police the Internet? Like ISPs, I think they should be content neutral unless illegal content like child porn is being hosted. Merely talking about services is not illegal as far as I know; only performing the DDoS attacks is.

I agree they should not be policing. Instead they should allow you to contact the people who are hosting the actual content. Which is where DMCA notices have to go to, for example. Since they do not host the content, they claim the DMCA should not be sent to them, but they won't tell you who to contact instead.

So what? It's not their job to help copyright holders, their job is to protect their clients' privacy. Even the cops have to get a court order to find someone's private data from a business, but since it's copyright every man and his dog claiming to be the copyright holder should be handed private information willy nilly?

Re: Microsoft takes down No-IP.com domains

#104
post #38

Earlier quoted context omitted.

As far as I understand it the problem is as follows: 1. Bad guys get a site behind cloudflare, and host illegal content 2. You want to report said bad guys to their host, for whatever reason. 3. You discover they use cloudflare. You now do not know where they are hosted. 4. Cloudflare will not tell you their actual IP addresses.

If it's illegal and you're harmed I'm sure you can sue the people who did it and CloudFlare will have to hand over IP addresses. But is it CloudFlare's duty to police the Internet? Like ISPs, I think they should be content neutral unless illegal content like child porn is being hosted. Merely talking about services is not illegal as far as I know; only performing the DDoS attacks is.

1. Websites hosting services that have no other purpose but to DDoS other computers are absolutely illegal. Many such sites have been taken down by the FBI before, and both users and owners of the sites have been arrested. The problem is that there are many hundreds of such sites and tens of thousands of users, and law enforcement simply can't take down each and every one. Cloudflare is relying on the fact that most people won't be able to get a subpoena or file a lawsuit.

2. You could apply that same argument to any hosting provider. They're just letting people see content that you yourself have uploaded; why should they act as Internet police? And yet every hosting provider has a legal responsibility to take action if someone is using their services to spread malware, launch DDoS attacks, or hack other websites.

Cloudflare is able to weasel itself out of it because it is not actually a hosting provider. However, they won't even let you discover the real hosting provider after showing proof of extremely blatant criminal activity. This is why many criminals flock to them: they know they will be harbored and their botnet command & control / DDoS service / malware distribution network can stay up for longer than it would normally.

I work in the information security field and we're definitely seeing more and more malicious network operators moving to Cloudflare and staying there for a long time.

Re: Microsoft takes down No-IP.com domains

#105

According to Reuters, Microsoft is only sending traffic from computers that are infected with malware to Microsoft instead of No-IP. http://uk.reuters.com/article/2014/06/30/us-cybercrime-micro... That may still make people uncomfortable, but it seems much less egregious than Microsoft taking control of No-IP's domains, which is what this press release implies. Edit: the reuters article is in error here, not the Micr…

Microsoft has been doing more and more of this stuff lately, and it does start to worry me quite a bit. The last time they worried me was when "Microsoft shut down a million-strong Tor botnet, by uninstalling Tor from the computers ". I don't want Microsoft to have that kind of power, let alone use it. Worse yet, they make it sound like it's some kind of PR win for them. "Microsoft the hero, takes down evil network".…

>The last time they worried me was when "Microsoft shut down a million-strong Tor botnet, by uninstalling Tor from the computers".

>Very few articles mentioned they were uninstalling Tor from the computers the last time around. Most were just churning Microsoft's press release and the hero narrative.

Microsoft's security software did that, that too only stopped it from automatically starting if it was installed by a known virus. So if you install and run a virus scanner, why wouldn't you expect it to block such attacks?

If you didn't want it to do that, I am sure there are ways to opt out from using Microsoft's security tools. Were there any reports of legitimate Tor users getting affected by the action?

Re: Microsoft takes down No-IP.com domains

#106
post #47
post #38

Earlier quoted context omitted.

If it's illegal and you're harmed I'm sure you can sue the people who did it and CloudFlare will have to hand over IP addresses. But is it CloudFlare's duty to police the Internet? Like ISPs, I think they should be content neutral unless illegal content like child porn is being hosted. Merely talking about services is not illegal as far as I know; only performing the DDoS attacks is.

Have fun filing lawsuits and sending out subpoenas when you're just trying to host a game server as a hobby and not making money off it. Cross-jurisdictional issues will also make this very difficult, even if you know who the attacker is.

Fair trials are hard, let's go shopping!

Re: Microsoft takes down No-IP.com domains

#107
post #20

Has I understood this correctly? Microsoft, a private company, has been granted the right to filter all dns traffic, and choose what will bee forward to this other company, No-IP. No-IP will so bee allowed to run there service for the remaining customers Microsoft approves? Is this common practices in the us legal system? Would it work like this in the offline world also? If my neighbor sometimes had loud parties tha…

>If my neighbor sometimes had loud parties that bothered me, could I be granted the right to stand in front of his door What if they were bothering 7.4 million people and inconveniencing many more? And then didn't show up in court in spite of summons? The police or courts will take that far more seriously.

Microsoft is not the police or courts.

Re: Microsoft takes down No-IP.com domains

#108
post #3

FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).

At CloudFlare, we have a Trust & Safety team dedicated to dealing with the abuse of our network. We sit in front of more than 2 million sites. The vast majority of them are not controversial (the site you're reading this on, for instance), but some are not. The majority of the abuse requests we receive are DMCA requests, but we get other reports as well. Dealing with these requests is a hard problem because a large n…

My own comments about your company are based on what I described in https://news.ycombinator.com/item?id=7880514. Would you care to respond to my statements in that post?

Re: Microsoft takes down No-IP.com domains

#109
post #3

FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).

Hey pktgen: I'm new at CloudFlare, but I'd be really interested in chatting with you (or grabbing a beer) to hear if there's something we could do better. Contact info in my profile. I'll be at Defcon and HOPE too if that's easier.

(Free speech vs. keeping the overall network safe is a hard decision. I think all pro-privacy and pro-liberty services have had to answer this question -- same thing happened with cypherpunks list, HavenCo, Freenet, various payment systems, etc.)

Post reply on HN