Live data from Hacker News

No-IP's Formal Statement on Microsoft Takedown

noip.com

61–70 of 116 posts

Re: No-IP's Formal Statement on Microsoft Takedown

#61
post #56

Earlier quoted context omitted.

I'm pretty sure virtually none of the spam mails in my spamfilter were sent from a phone. Nor do phones have the bandwidth to carry out DDoS attacks or host phishing sites. Nor do many people do onlinebanking on their phone (though that number is certainly on the rise). So yes, while malware exists on android, I doubt the total damages caused by it are more than a drop in the bucket when compared to windows malware.

Your original statement was: >Practically every instance of malware runs on Microsoft Windows. Even according to Google, about 5 million Android devices are infected with malware. http://bgr.com/2014/06/26/google-on-android-malware-and-secu... I would suppose that your statements aren't support by fact, but the HN downvotes have got me thinking.

If "5 million" sounds like a large number to you then this may help to put it into perspective; http://en.wikipedia.org/wiki/Botnet#Historical_list_of_botne...

Re: No-IP's Formal Statement on Microsoft Takedown

#62

If this action is troubling, then we need to stop putting the blame in the wrong place. Microsoft does not have the power to seize domains. A federal court order made that happen. This order is (apparently) the responsibility of the U.S. District Court of Nevada. If you want to blame someone, then blame the court. Obnoxious people ask courts to do obnoxious things every day. Good courts do not comply.

> Good courts do not comply.

Problem is, there is no good court. It's always vary case by case. Is the Supreme Court good court? It did rule in favor of gay married couples entitled to federal benefits but not so on some other issues. Laws are meant to be interpreted differently and handled differently by different judges at different time.

What you (and I and everyone is doing) is expressing our own opinion of how the complaint should be handle based on our interpretation of the law, responsibility, and society.

Re: No-IP's Formal Statement on Microsoft Takedown

#63
post #29

Earlier quoted context omitted.

Presumably because they have a free basic service if you use one of their subdomains. While other companies I'm not aware of might offer the same I've yet to stumble across them.

DynDNS and afraid, which as far as I know are the next two most popular services like this, both have free options. EDIT: Looks like DynDNS recently got rid of their free offering. I wonder if that was related to this?

DynDNS dropped their free offering a couple of years ago. If you had created your account before then, you were grandfathered in, and still got 5(?) domains for free; as long as you logged in frequently enough.

Re: No-IP's Formal Statement on Microsoft Takedown

#64

Earlier quoted context omitted.

We assume that this is on-going (No-IP was the go-to since 2004) and Microsoft has finally decided they'd be able to take it over. Unfortunately they didn't plan enough to anticipate the amount of traffic they'd receive. If I was No-IP, I'd be out for blood. Someone sends a court order to essentially handicap your business, putting it at risk for the sake of malevolent users. This was a situation where No-IP's "resol…

>Someone sends a court order to essentially handicap your business, putting it at risk for the sake of malevolent users. "Someone" in this is case is a federal district court which did that because there was no communication from No-IP. MS does not have the power to send court orders. The court ordered No-IP to send a response and looks like there was no response. >If I was No-IP, I'd be out for blood. Who's blood?

Sorry I worded that incorrectly. Someone requests for a court order to essentially handicap your business. It's not that No-IP didn't respond, it's that they don't continuously respond. Arguably No-IP does cater for these types of users who pay using gift cards bought with cash and generally only last a few weeks before signing up under another alias..

Re: No-IP's Formal Statement on Microsoft Takedown

#65
post #56

Earlier quoted context omitted.

Except all the malware on Android. But who's counting? https://www.google.com/search?&q=android+malware&ie=UTF-8&oe...

I'm pretty sure virtually none of the spam mails in my spamfilter were sent from a phone. Nor do phones have the bandwidth to carry out DDoS attacks or host phishing sites. Nor do many people do onlinebanking on their phone (though that number is certainly on the rise). So yes, while malware exists on android, I doubt the total damages caused by it are more than a drop in the bucket when compared to windows malware.

Android botnets are very valuable because they use mobile network IPs that confuse fraud and login classifiers that use ASN or GeoIP.

Re: No-IP's Formal Statement on Microsoft Takedown

#66

Earlier quoted context omitted.

I'm not sure they did, the order has this statement (emphasis mine); 8. Microsoft’s request for this emergency ex parte relief is not the result of any lack of diligence on Microsoft’s part, but instead based upon the nature of Defendants’ unlawful conduct. Therefore, in accordance with Federal Rule of Civil Procedure 65(b) and Civil Local Rule 7-5, good cause and the interest of justice require that this Order be Gr…

Here is Federal Rule of Civil Procedure 65(b): http://www.law.cornell.edu/rules/frcp/rule_65 (1) Issuing Without Notice. The court may issue a temporary restraining order without written or oral notice to the adverse party or its attorney only if: (A) specific facts in an affidavit or a verified complaint clearly show that immediate and irreparable injury, loss, or damage will result to the movant before the adverse…

Later in the order they required Microsoft to post a $200,000 bond. Not sure if that actually covers the potential damages.

Re: No-IP's Formal Statement on Microsoft Takedown

#67
post #23

Earlier quoted context omitted.

That responsibility is not absolute, and could be interpreted differently in the frameworks of ethicality, legality, economics, and liberty. Ethically, I think you're correct that it's their responsibility to do what they can. Legally, the court in this situation thought it was somehow Microsoft's responsibility to fix it. Economically, I'd say being held liable to what users do on your platform will hurt innovation…

You believe in terms of liberty that botnets who compromise machines in order to steal data, spam and many other nefarious activities doesn't compare to one business being temporarily affected ? That is a strange perspective I have to say.

In terms of liberty, one crime doesn't excuse another, especially when they're not directly related. If I manufacture cigarettes and someone dies of lung cancer, I could be ethically liable but my liberty to make cigarettes shouldn't be impacted. If someone uses YouTube to upload copyrighted things, should YouTube have its domain stolen and its users unable to use the site any more?

Re: No-IP's Formal Statement on Microsoft Takedown

#68

Earlier quoted context omitted.

This is America. With enough money, you can do whatever you want.

You can see it that way. Others will see it as Microsoft proactively removing bots and spam.

It is the FBI's job to enforce cyber criminal law and execute takedowns of malicious domains. Not Microsoft's[or any other NGO].

Re: No-IP's Formal Statement on Microsoft Takedown

#69

Earlier quoted context omitted.

I don't think they had any opportunity to contest. IT IS FURTHER ORDERED that the Registry Operators must: ... d. Shall completely refrain from providing any notice or warning to, or communicating in any way with Defendants or Defendants’ representatives and shall refrain from publicizing this Order until this Order is executed in full, except as necessary to propagate the changes ordered herein to all parts of the D…

Edit: Looks like Microsoft filed for and got a emergency temporary restraining order against all the defendants including No-IP. http://www.noticeoflawsuit.com/docs/Second%20Amended%20Order... Also this is No-IPs response to Cisco's previous accusations. http://www.noip.com/blog/2014/02/12/cisco-malware-report/ They did have lot of chances to contest. Apart from Microsoft's notices, the court sent a notice to No-IP w…

That's not true. On June 19, Microsoft filed the Complaint, Motion to Seal, and Ex Parte TRO Application all at the same time.

The TRO actually says: “...good cause and the interest of justice require that this Order be Granted without prior notice to Defendants, and accordingly, Microsoft is relieved of the duty to provide Defendants with prior notice of Microsoft’s motion.”

It says that because Microsoft wanted it to say that; Microsoft used that language in their proposed TRO for the judge to sign, and the judge apparently agreed.

The Summons has nothing to do with this. The court issued the Summons, but the court doesn't do anything with it. It's the plaintiff's obligation to serve a summons on a defendant, and they have 120 days to do so before the Court would require the plaintiff dismiss the case without prejudice. The plaintiff could serve them the same day, or they could take their time. Corporations with registered agents are much easier to serve than an individual that dodges a process server.

There's often a good chance a defendant will receive a solicitation from an attorney (who searches court records for new cases) to represent them before they actually get served with the summons and complaint. However, nothing would come up in court records in this case because the entire docket is sealed.

There's no way Vitalwerks/No-IP would have known about this, and it sounds like they weren't served until today, after Microsoft's action.

I think it's pretty clear that Microsoft wanted to ensure that nobody, including No-IP, knew about the case until they were able to strike.

Re: No-IP's Formal Statement on Microsoft Takedown

#70
The Microsoft hate here is unfounded and ill informed.

Those of us working defense at large organizations have known for a while that No-IP domains are wretched hives of scum and villainy. Any company with a threat model that includes at least one of a diverse set of characters ranging from malware authors to organized crime to nation state teams should be logging all DNS requests and treating any request to a No-IP domain as an indicator of compromise.

Microsoft has a successful history of disrupting botnet C&C and distribution channels via domain seizures, which is why this request probably sailed through Federal Court. The only difference in this situation is that there are innocent bystanders affected, which generally doesn't happen since the other domains they have seized have been 100% used for fraud.

I feel bad for those folks and the people at No-IP who maybe meant well, but the truth is that the fight to keep normal people safe is bigger than just technological, and needs to include civil legal actions like this.

Post reply on HN