Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

161–170 of 261 posts

Re: Microsoft takes down No-IP.com domains

#161
post #135

Earlier quoted context omitted.

> the judge in question was probably just paid off or otherwise influenced That's a hell of an accusation.

'influenced' could just be fast-talking

True, but that's not really the tone of the post. Accusations of bribery and calling court orders the "violent arm of the state" means he's lost benefit of the doubt.

Re: Microsoft takes down No-IP.com domains

#162

According to Reuters, Microsoft is only sending traffic from computers that are infected with malware to Microsoft instead of No-IP. http://uk.reuters.com/article/2014/06/30/us-cybercrime-micro... That may still make people uncomfortable, but it seems much less egregious than Microsoft taking control of No-IP's domains, which is what this press release implies. Edit: the reuters article is in error here, not the Micr…

Microsoft has been doing more and more of this stuff lately, and it does start to worry me quite a bit. The last time they worried me was when "Microsoft shut down a million-strong Tor botnet, by uninstalling Tor from the computers ". I don't want Microsoft to have that kind of power, let alone use it. Worse yet, they make it sound like it's some kind of PR win for them. "Microsoft the hero, takes down evil network".…

Not saying that it's right but Amazon, Google and Apple also have admin rights on their devices... (for example: http://www.nytimes.com/2009/07/18/technology/companies/18ama... , also http://www.computerworld.com/s/article/9213641/Google_throws... )

Re: Microsoft takes down No-IP.com domains

#163
post #127

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Namecoin Distributed DNS is the only solution

And meshnets. DNS is just a layer on top of an already vulnerable IP stack. IP can work between broad and anonymous mesh nets, but when an IP address can be resolved to a business or person it provides an exploit vector.

Like MaidSafe? Are there other alternatives?

Re: Microsoft takes down No-IP.com domains

#164

Earlier quoted context omitted.

Microsoft is not the police or courts.

It was the court that allowed Microsoft to do this.

the court deciding that a company (Microsoft) should act as the police (or in this analogy, a bouncer) is still terribly short-sighted, especially when that company has been historically accused by the DOJ of attempting to form varying monopolies.

a capable government should not be in the habit of contracting valuable state-needed cyber-defense to private companys, as the 'keys to the kingdom', in this case domain records, should not be in the hands of a company that can benefit privately but rather a state-ran agency which employs proper check and balances.

Re: Microsoft takes down No-IP.com domains

#165

Earlier quoted context omitted.

Wholly predictable downvoting by anonymously cowardly Microsoft brown-nosers.

Fine. I downvoted you, and it's no longer anonymous. I downvoted you because both of your comments were filled with passionate garbage rather than any well-reasoned thought. I'd be willing to bet other downvoters were not simply cowardly Microsoft brown-nosers.

Apparently the sheer abuse of power entailed by Microsoft hijacking and disrupting the inbound traffic of a lot of innocent no-ip customers to track the few C&C servers is entirely lost on you.

If something like that is to be done it should be done by a state body, not a private corporation. What gives them the right to spy on innocent peoples traffic?

Did the judges even understand the nature of the power they were granting Microsoft? Couldn't it have been handled differently?

Re: Microsoft takes down No-IP.com domains

#166

Earlier quoted context omitted.

Microsoft has been doing more and more of this stuff lately, and it does start to worry me quite a bit. The last time they worried me was when "Microsoft shut down a million-strong Tor botnet, by uninstalling Tor from the computers ". I don't want Microsoft to have that kind of power, let alone use it. Worse yet, they make it sound like it's some kind of PR win for them. "Microsoft the hero, takes down evil network".…

>The last time they worried me was when "Microsoft shut down a million-strong Tor botnet, by uninstalling Tor from the computers". >Very few articles mentioned they were uninstalling Tor from the computers the last time around. Most were just churning Microsoft's press release and the hero narrative. Microsoft's security software did that, that too only stopped it from automatically starting if it was installed by a…

To opt out uninstall Microsoft's malicious software removal tool.

Re: Microsoft takes down No-IP.com domains

#167

So does this mean no-ip.com is no more, or only a subset of their domains?

It means, temporarily, a subset of traffic known to be from these viruses should be blocked, within part of the US, it seems.

it's more than that. i cannot get to my (presumably clean, running linux, carefully maintained) home machine situated in chile, connecting from the uk.

Re: Microsoft takes down No-IP.com domains

#168
post #108

Earlier quoted context omitted.

My own comments about your company are based on what I described in https://news.ycombinator.com/item?id=7880514 . Would you care to respond to my statements in that post?

Sure. Pardon the copy-and-paste reply, but it's a perfect opportunity for me to publish up a draft blog post I wrote half a year ago in anticipation of a Brian Krebs post on the topic of Booter sites. Brian's article didn't turn out nasty enough to warrant a response, but I've had the post sitting around in by drafts folder for a while and it addresses your points as well. ======== Why a Hunger Games-Like Vision for…

First off, thankyou for a detailed and well laid out post.

I do however think that there is a material difference between hosting unpleasant speech (to which the counter is speech pointing out that the speaker is wrong/idiotic/etc) and hosting malware/botnet sites (to which the counter is... what? what IS the counter to a sufficiently large botnet? ultimately we all have a limit at which point we can receive no more traffic. You might not have hit it - yet - but you will).

The internet - as you are aware - is based on protocols not designed with any significant security in mind. No-one in their right mind would today sit down and design something like BGP, for example. With that in mind, any large provider (or large consumer with capability to cause harm) has the responsibility to be a good citizen of the internet, and not to (by action or inaction) advance the agendas of those who would see its demise. As much as it might be convenient from an operational POV, and justifiable from a moral POV, washing your hands of responsibility and saying "It's not up to us, it's up to the courts" just doesn't work when the infrastrucure we're all building on is so very fragile. I'd also like to note that there's a semi-hidden US bias here - what if the target of a botnet, who's admin interface is hosted by CF - is based in a country where there is no reasonable ability to recourse to the US courts? Iran, for example?

It's admirable that you do not censor content in response to political pressure, but there IS a difference between protecting freedom of speech and protecting malware, and saying that censoring the malware is a slippery slope is at least partly disingenuous - any vaguely controversial decision can be described as a slippery slope to something else. Please at least consider making it easier for those of us who are trying to fight malware, botnets, etc, etc to get the original source of the content. I know this will involve some human judgement, and invetiably some mistakes and poor descions - but that would still in my view be far prefferable to what we have now. Thanks.

Re: Microsoft takes down No-IP.com domains

#169
post #21

So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware? Where is the due process? Where is the oversight in this? All I'm seeing is vigilanteism.

The due process is that Microsoft sued the malware distributors and the court granted them a restraining order. "In a civil case filed on June 19, Microsoft named two foreign nationals, Mohamed Benabdellah and Naser Al Mutairi, and a U.S. company, Vitalwerks Internet Solutions, LLC (doing business as No-IP.com), for their roles in creating, controlling, and assisting in infecting millions of computers with malicious…

Ex parte means that only one party is before the court. That means No-IP had only no opportunity to respond to Microsoft's request to seize the names.

Due process, maybe. But not very good due process.

Re: Microsoft takes down No-IP.com domains

#170

Earlier quoted context omitted.

Wholly predictable downvoting by anonymously cowardly Microsoft brown-nosers.

Fine. I downvoted you, and it's no longer anonymous. I downvoted you because both of your comments were filled with passionate garbage rather than any well-reasoned thought. I'd be willing to bet other downvoters were not simply cowardly Microsoft brown-nosers.

In any case have you read the Microsoft blog statement at all?

IT IS smug, self preening, self congratulatory tripe.

I suggest you read it if you haven't.

Post reply on HN