If the cliche isn't true, then I guess the next/new one is, if its free you're SOL.
Microsoft takes down No-IP.com domains
171–180 of 261 posts
Re: Microsoft takes down No-IP.com domains
#172Earlier quoted context omitted.
That's quite a stretched analogy. A fully updated Windows XP computer will still be vulnerable to malware and botnets. That is because Windows, OS X, Android and Linux allow their users to install third party programs without whitelisting them. There is nothing stopping users from installing malware. OS X and Linux have less malware because they're not as popular as Windows and Android. That's opposite to iOS, Window…
On OSX you actually have to whitelist software as a user. If something doesn't come from an approved developer, user has to say "Yup, I really do actually want this to be able to run" (unless we're talking things installed through homebrew, pip, gems and whatnot, but those aren't likely to be used by inexperienced users)
Re: Microsoft takes down No-IP.com domains
#173Earlier quoted context omitted.
Sure. Pardon the copy-and-paste reply, but it's a perfect opportunity for me to publish up a draft blog post I wrote half a year ago in anticipation of a Brian Krebs post on the topic of Booter sites. Brian's article didn't turn out nasty enough to warrant a response, but I've had the post sitting around in by drafts folder for a while and it addresses your points as well. ======== Why a Hunger Games-Like Vision for…
First off, thankyou for a detailed and well laid out post. I do however think that there is a material difference between hosting unpleasant speech (to which the counter is speech pointing out that the speaker is wrong/idiotic/etc) and hosting malware/botnet sites (to which the counter is... what? what IS the counter to a sufficiently large botnet? ultimately we all have a limit at which point we can receive no more…
http://blog.cloudflare.com/thoughts-on-abuse
Malware and sites advertising so-called "booter" services are different discussions.
Re: Microsoft takes down No-IP.com domains
#174Earlier quoted context omitted.
On OSX you actually have to whitelist software as a user. If something doesn't come from an approved developer, user has to say "Yup, I really do actually want this to be able to run" (unless we're talking things installed through homebrew, pip, gems and whatnot, but those aren't likely to be used by inexperienced users)
Yeah but what fraction of home users are going to consider that prompt as opposed to just clicking on the OK button? I've noticed a lot of software will include that in its install steps.
Re: Microsoft takes down No-IP.com domains
#175So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware? Where is the due process? Where is the oversight in this? All I'm seeing is vigilanteism.
The due process is that Microsoft sued the malware distributors and the court granted them a restraining order. "In a civil case filed on June 19, Microsoft named two foreign nationals, Mohamed Benabdellah and Naser Al Mutairi, and a U.S. company, Vitalwerks Internet Solutions, LLC (doing business as No-IP.com), for their roles in creating, controlling, and assisting in infecting millions of computers with malicious…
In what way is the court at liberty to grant a plaintiff permission to enforce a restraining order though, sounds ultra vires? Aren't the only ones enabled legally to do so law enforcement officers?
Re: Microsoft takes down No-IP.com domains
#176So let me get this straight. Microsoft got a court order to route all of another entity's DNS traffic to their servers. Giving them the ability to route a metric crap-ton of private traffic through their data centers. For "security". I call shenanigans. I'm also assuming this is why my no-ip domain disappeared this morning, leaving me with no access to my home servers. Perhaps the linux on my servers is considered ma…
Not exactly. > allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. According to MSFT, they are only looking at known "bad" traffic. You can take their word for it... or not.
Re: Microsoft takes down No-IP.com domains
#177Earlier quoted context omitted.
Microsoft has been doing more and more of this stuff lately, and it does start to worry me quite a bit. The last time they worried me was when "Microsoft shut down a million-strong Tor botnet, by uninstalling Tor from the computers ". I don't want Microsoft to have that kind of power, let alone use it. Worse yet, they make it sound like it's some kind of PR win for them. "Microsoft the hero, takes down evil network".…
It is almost like giving one company monopoly control of the personal computer industry through a proprietary OS nobody can audit might not be the best plan.
Re: Microsoft takes down No-IP.com domains
#178According to Reuters, Microsoft is only sending traffic from computers that are infected with malware to Microsoft instead of No-IP. http://uk.reuters.com/article/2014/06/30/us-cybercrime-micro... That may still make people uncomfortable, but it seems much less egregious than Microsoft taking control of No-IP's domains, which is what this press release implies. Edit: the reuters article is in error here, not the Micr…
Re: Microsoft takes down No-IP.com domains
#179Earlier quoted context omitted.
Well, no, it isn't perfectly clear from the article - are the courts in a position to independently evaluate No-IP's efforts, or did they trust Microsoft's legal team regarding their insufficiency?
isn't this how all lawsuits work all the time? there's a finding of fact where each side presents arguments.
Re: Microsoft takes down No-IP.com domains
#180According to Reuters, Microsoft is only sending traffic from computers that are infected with malware to Microsoft instead of No-IP. http://uk.reuters.com/article/2014/06/30/us-cybercrime-micro... That may still make people uncomfortable, but it seems much less egregious than Microsoft taking control of No-IP's domains, which is what this press release implies. Edit: the reuters article is in error here, not the Micr…
My home VPN is unable to connect right now. I use a noip.me domain. The actions of both the courts and Microsoft are extremely concerning to me.