Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

171–180 of 261 posts

Re: Microsoft takes down No-IP.com domains

#171
So on a different side topic, if the service was free and I assume the TOS from noip didn't guarantee an SLA, does this mean all the end users are basically out of Luke suing Microsoft for failure to properly resolve their domains?

If the cliche isn't true, then I guess the next/new one is, if its free you're SOL.

Re: Microsoft takes down No-IP.com domains

#172
post #148

Earlier quoted context omitted.

That's quite a stretched analogy. A fully updated Windows XP computer will still be vulnerable to malware and botnets. That is because Windows, OS X, Android and Linux allow their users to install third party programs without whitelisting them. There is nothing stopping users from installing malware. OS X and Linux have less malware because they're not as popular as Windows and Android. That's opposite to iOS, Window…

On OSX you actually have to whitelist software as a user. If something doesn't come from an approved developer, user has to say "Yup, I really do actually want this to be able to run" (unless we're talking things installed through homebrew, pip, gems and whatnot, but those aren't likely to be used by inexperienced users)

Yeah but what fraction of home users are going to consider that prompt as opposed to just clicking on the OK button? I've noticed a lot of software will include that in its install steps.

Re: Microsoft takes down No-IP.com domains

#173

Earlier quoted context omitted.

Sure. Pardon the copy-and-paste reply, but it's a perfect opportunity for me to publish up a draft blog post I wrote half a year ago in anticipation of a Brian Krebs post on the topic of Booter sites. Brian's article didn't turn out nasty enough to warrant a response, but I've had the post sitting around in by drafts folder for a while and it addresses your points as well. ======== Why a Hunger Games-Like Vision for…

First off, thankyou for a detailed and well laid out post. I do however think that there is a material difference between hosting unpleasant speech (to which the counter is speech pointing out that the speaker is wrong/idiotic/etc) and hosting malware/botnet sites (to which the counter is... what? what IS the counter to a sufficiently large botnet? ultimately we all have a limit at which point we can receive no more…

Agree, which is why we do take malware and phishing sites, which we can judge as per se harmful, offline. Read more here:

http://blog.cloudflare.com/thoughts-on-abuse

Malware and sites advertising so-called "booter" services are different discussions.

Re: Microsoft takes down No-IP.com domains

#174
post #148

Earlier quoted context omitted.

On OSX you actually have to whitelist software as a user. If something doesn't come from an approved developer, user has to say "Yup, I really do actually want this to be able to run" (unless we're talking things installed through homebrew, pip, gems and whatnot, but those aren't likely to be used by inexperienced users)

Yeah but what fraction of home users are going to consider that prompt as opposed to just clicking on the OK button? I've noticed a lot of software will include that in its install steps.

You now actually need to specifically open the application with a right click to even have the option to open it, simply double clicking just says it's unsafe and closes. I think that safeguard probably has saved significant numbers of people from unsavory malware.

Re: Microsoft takes down No-IP.com domains

#175
post #21

So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware? Where is the due process? Where is the oversight in this? All I'm seeing is vigilanteism.

The due process is that Microsoft sued the malware distributors and the court granted them a restraining order. "In a civil case filed on June 19, Microsoft named two foreign nationals, Mohamed Benabdellah and Naser Al Mutairi, and a U.S. company, Vitalwerks Internet Solutions, LLC (doing business as No-IP.com), for their roles in creating, controlling, and assisting in infecting millions of computers with malicious…

>The due process is that Microsoft sued the malware distributors and the court granted them a restraining order. //

In what way is the court at liberty to grant a plaintiff permission to enforce a restraining order though, sounds ultra vires? Aren't the only ones enabled legally to do so law enforcement officers?

Re: Microsoft takes down No-IP.com domains

#176

So let me get this straight. Microsoft got a court order to route all of another entity's DNS traffic to their servers. Giving them the ability to route a metric crap-ton of private traffic through their data centers. For "security". I call shenanigans. I'm also assuming this is why my no-ip domain disappeared this morning, leaving me with no access to my home servers. Perhaps the linux on my servers is considered ma…

Not exactly. > allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. According to MSFT, they are only looking at known "bad" traffic. You can take their word for it... or not.

If that last line were true then surely the GP's noip domain would still work and traffic would be routing without any interference. Ergo, they are telling lies as they are not simply routing "bad traffic" elsewhere but also "good traffic".

Re: Microsoft takes down No-IP.com domains

#177
post #129

Earlier quoted context omitted.

Microsoft has been doing more and more of this stuff lately, and it does start to worry me quite a bit. The last time they worried me was when "Microsoft shut down a million-strong Tor botnet, by uninstalling Tor from the computers ". I don't want Microsoft to have that kind of power, let alone use it. Worse yet, they make it sound like it's some kind of PR win for them. "Microsoft the hero, takes down evil network".…

It is almost like giving one company monopoly control of the personal computer industry through a proprietary OS nobody can audit might not be the best plan.

Not necessarily "nobody". They do have a shared source program:

https://www.microsoft.com/en-us/sharedsource/default.aspx

Re: Microsoft takes down No-IP.com domains

#178

According to Reuters, Microsoft is only sending traffic from computers that are infected with malware to Microsoft instead of No-IP. http://uk.reuters.com/article/2014/06/30/us-cybercrime-micro... That may still make people uncomfortable, but it seems much less egregious than Microsoft taking control of No-IP's domains, which is what this press release implies. Edit: the reuters article is in error here, not the Micr…

My home VPN is unable to connect right now. I use a noip.me domain. The actions of both the courts and Microsoft are extremely concerning to me.

Re: Microsoft takes down No-IP.com domains

#179
post #92

Earlier quoted context omitted.

Well, no, it isn't perfectly clear from the article - are the courts in a position to independently evaluate No-IP's efforts, or did they trust Microsoft's legal team regarding their insufficiency?

isn't this how all lawsuits work all the time? there's a finding of fact where each side presents arguments.

Except that only one side presented any arguments on this case.

Re: Microsoft takes down No-IP.com domains

#180

According to Reuters, Microsoft is only sending traffic from computers that are infected with malware to Microsoft instead of No-IP. http://uk.reuters.com/article/2014/06/30/us-cybercrime-micro... That may still make people uncomfortable, but it seems much less egregious than Microsoft taking control of No-IP's domains, which is what this press release implies. Edit: the reuters article is in error here, not the Micr…

My home VPN is unable to connect right now. I use a noip.me domain. The actions of both the courts and Microsoft are extremely concerning to me.

Same here, I was confused this afternoon when my home vpn hosted on a servebeer.com subdomain wouldn't connect. Now it makes a lot more sense, but I'm left with a very bad taste in my mouth.
Post reply on HN