Live data from Hacker News

No-IP's Formal Statement on Microsoft Takedown

noip.com

51–60 of 116 posts

Re: No-IP's Formal Statement on Microsoft Takedown

#51

Earlier quoted context omitted.

I don't think they had any opportunity to contest. IT IS FURTHER ORDERED that the Registry Operators must: ... d. Shall completely refrain from providing any notice or warning to, or communicating in any way with Defendants or Defendants’ representatives and shall refrain from publicizing this Order until this Order is executed in full, except as necessary to propagate the changes ordered herein to all parts of the D…

Edit: Looks like Microsoft filed for and got a emergency temporary restraining order against all the defendants including No-IP. http://www.noticeoflawsuit.com/docs/Second%20Amended%20Order... Also this is No-IPs response to Cisco's previous accusations. http://www.noip.com/blog/2014/02/12/cisco-malware-report/ They did have lot of chances to contest. Apart from Microsoft's notices, the court sent a notice to No-IP w…

I'm not sure they did, the order has this statement (emphasis mine);

8. Microsoft’s request for this emergency ex parte relief is not the result of any lack of diligence on Microsoft’s part, but instead based upon the nature of Defendants’ unlawful conduct. Therefore, in accordance with Federal Rule of Civil Procedure 65(b) and Civil Local Rule 7-5, good cause and the interest of justice require that this Order be Granted without prior notice to Defendants, and accordingly, Microsoft is relieved of the duty to provide Defendants with prior notice of Microsoft’s motion.

I should note my laymans reading is that Microsoft proved exigent circumstances that negated the need for prior notice.

Re: No-IP's Formal Statement on Microsoft Takedown

#52
post #28

Earlier quoted context omitted.

You might just as well say it is the IANA's fault for issuing the IP addresses the malware authors used, or Ford's fault for building the getaway car used in a bank robbery.

Your argument is ridiculous. Turning over IANA or Ford over to Microsoft would not prevent malware or robberies. Turning over NoIP to Microsoft will prevent malware (at least in the short term).

You're kidding right? I honestly burst out with a laugh when I read this. In what world do you live in where Microsoft seizing control of a single dynamic DNS provider will "prevent malware" (even in the short term)?

It's not like this motion has created some insurmountable wall that malware creators can't possibly work around.

Re: No-IP's Formal Statement on Microsoft Takedown

#53

So when will Canonical file an ex-parte TRO against Microsoft for failing to secure Windows XP against malware? It would be nice to see a windows update which upgrades to linux :P Later edit: Isn't this ironic, how most botnet members are running Microsoft's software, yet they get to do this?

Creating the tools by which anyone might theoretically spawn abuse is not the same as proactively hosting those engaging in the same.

E.g. one might reasonably disrupt a farmer's market known to be selling beef infected with salmonella without banning cows of the same breed across the world.

Re: No-IP's Formal Statement on Microsoft Takedown

#54

Earlier quoted context omitted.

Edit: Looks like Microsoft filed for and got a emergency temporary restraining order against all the defendants including No-IP. http://www.noticeoflawsuit.com/docs/Second%20Amended%20Order... Also this is No-IPs response to Cisco's previous accusations. http://www.noip.com/blog/2014/02/12/cisco-malware-report/ They did have lot of chances to contest. Apart from Microsoft's notices, the court sent a notice to No-IP w…

Did you read that document that you linked to? There are two things about it that you may want to look at: - First, it says "Within 21 days after service of this summons on you...you must serve on the plaintiff an answer.." - Second, it is dated 06/19/2014 21 days from 06/19/2014 is July 10, 2014, a date which is still in the future. Do you have any other evidence that they didn't respond? Because the document you li…

"Second, it is dated 06/19/2014"

but signed on 6/26.

Re: No-IP's Formal Statement on Microsoft Takedown

#55
post #36

Earlier quoted context omitted.

How do we file the same action against Microsoft? I would like to take their domains for my own purposes, which are obviously far more worthy than what Microsoft is doing with them (I swear).

A good start would be to actually read the legal documents behind the case instead of assuming a lot from someone's comments with cherrypicked facts. http://www.noticeoflawsuit.com/index.htm

I am still looking through these files, but everything that I have read points to insufficient, or zero notice having been given to the defendants prior to this order. For instance, the complaint itself...

http://www.noticeoflawsuit.com/docs/Revised_Final%20No-IP%20...

...is dated June 19, 2014.

And from the order itself...

http://www.noticeoflawsuit.com/docs/Second%20Amended%20Order...

...we see the following instruction:

"IT IS FURTHER ORDERED, pursuant to Federal Rule of Civil Procedure 65(b) that the Defendants shall appear before this Court on July 10, 2014, at 3:00 p.m., in LV Courtroom 7D to show cause, if there is any, why this Court should not enter a Preliminary Injunction, pending final ruling on the Complaint against the Defendants, enjoining them from the conduct temporarily restrained by the preceding provisions of this Order."

Of course, July 1 is tomorrow.

In this document, Microsoft seems to be requesting that all of this stuff be sealed until it is ready to disclose the existence of the lawsuit to the defendant, presumably after it has completed its seizure the domains:

http://www.noticeoflawsuit.com/docs/Final%20Motion%20to%20Se...

The facts of this seem pretty clear from your link. What I am wondering is if there is any precedence for this, and if this is really considered due process?

Re: No-IP's Formal Statement on Microsoft Takedown

#56
post #44

Earlier quoted context omitted.

Practically every instance of malware runs on Microsoft Windows. If the stated goal is to defeat malware then windowsupdate.microsoft.com should be seized and routed to a non-interactive Windows Uninstaller.

Except all the malware on Android. But who's counting? https://www.google.com/search?&q=android+malware&ie=UTF-8&oe...

I'm pretty sure virtually none of the spam mails in my spamfilter were sent from a phone. Nor do phones have the bandwidth to carry out DDoS attacks or host phishing sites. Nor do many people do onlinebanking on their phone (though that number is certainly on the rise).

So yes, while malware exists on android, I doubt the total damages caused by it are more than a drop in the bucket when compared to windows malware.

Re: No-IP's Formal Statement on Microsoft Takedown

#57

Earlier quoted context omitted.

Edit: Looks like Microsoft filed for and got a emergency temporary restraining order against all the defendants including No-IP. http://www.noticeoflawsuit.com/docs/Second%20Amended%20Order... Also this is No-IPs response to Cisco's previous accusations. http://www.noip.com/blog/2014/02/12/cisco-malware-report/ They did have lot of chances to contest. Apart from Microsoft's notices, the court sent a notice to No-IP w…

I'm not sure they did, the order has this statement (emphasis mine); 8. Microsoft’s request for this emergency ex parte relief is not the result of any lack of diligence on Microsoft’s part, but instead based upon the nature of Defendants’ unlawful conduct. Therefore, in accordance with Federal Rule of Civil Procedure 65(b) and Civil Local Rule 7-5, good cause and the interest of justice require that this Order be Gr…

Here is Federal Rule of Civil Procedure 65(b):

http://www.law.cornell.edu/rules/frcp/rule_65

(1) Issuing Without Notice. The court may issue a temporary restraining order without written or oral notice to the adverse party or its attorney only if:

(A) specific facts in an affidavit or a verified complaint clearly show that immediate and irreparable injury, loss, or damage will result to the movant before the adverse party can be heard in opposition; and

(B) the movant's attorney certifies in writing any efforts made to give notice and the reasons why it should not be required.

So, if all of this is considered a "temporary restraining order", then it must be based on these rules, which also seem to provide certain protections to the affected party, including requiring the plaintiff to put up security to reimburse the affected party for any damages they may suffer as a result of the order.

I hope that a lawyer can chime in here and give a decent opinion as to whether this is kosher, and also to answer whether it seems correct to effectively transfer control over property such as domain names through this mechanism.

Re: No-IP's Formal Statement on Microsoft Takedown

#58

They also deny Cisco's allegations here. http://www.noip.com/blog/2014/02/12/cisco-malware-report/ It doesn't compute that Cisco is casting blame on them and Microsoft got a court order when all they had to do is send an email. It's kind of strange, they're probably unable to keep up with the abuse reports and validating them or something. There are a lot of dynamic DNS providers so why do the bad guys pick them for…

The press release smells to me like they're playing the innocent, and are savvy to the kind of language their audience likes. "We were very surprised this morning"... "Had Microsoft contacted us, we could and would have taken immediate action."? Surely at some point legal proceedings would have initiated some contact?

Re: No-IP's Formal Statement on Microsoft Takedown

#59
post #56

Earlier quoted context omitted.

Except all the malware on Android. But who's counting? https://www.google.com/search?&q=android+malware&ie=UTF-8&oe...

I'm pretty sure virtually none of the spam mails in my spamfilter were sent from a phone. Nor do phones have the bandwidth to carry out DDoS attacks or host phishing sites. Nor do many people do onlinebanking on their phone (though that number is certainly on the rise). So yes, while malware exists on android, I doubt the total damages caused by it are more than a drop in the bucket when compared to windows malware.

Your original statement was:

>Practically every instance of malware runs on Microsoft Windows.

Even according to Google, about 5 million Android devices are infected with malware. http://bgr.com/2014/06/26/google-on-android-malware-and-secu...

I would suppose that your statements aren't support by fact, but the HN downvotes have got me thinking.

Re: No-IP's Formal Statement on Microsoft Takedown

#60
post #50

Earlier quoted context omitted.

"Turning over NoIP to Microsoft will prevent malware" Really? Not according to anyone with anything resembling a passing familiarity with malware and it's distribution...

In any event, the malware will at least not resolve to a no-ip.com address, since apparently nothing is able to consistently resolve to such addresses anymore...

Unfortunately malware tends to be the one kind of No-Ip client that actually has (lots of) redundancy built into its peer discovery mechanism.

Malware authors anticipate their communication channels to fail and usually account for it with a whole series of fallbacks.

Quite unlike your NetGear or LinkSys home router, which many people suddenly can't reach anymore from e.g. their vacation home...

Post reply on HN