Live data from Hacker News

No-IP's Formal Statement on Microsoft Takedown

noip.com

81–90 of 116 posts

Re: No-IP's Formal Statement on Microsoft Takedown

#81
post #34

What I don't understand is the legal basis of Microsoft, a private entity, simply being handed over the property (the domain names) of another private entity. I understand that this is something that was ordered by a court, but under what legal theory was the order issued? I'm not a lawyer, but I think I've got at least a basic idea of the circumstances under which the government can take someone's property. This doe…

A competitor no less! no-ip and such are a required service for people to host their own "cloud" solutions from their home connections. Microsoft makes money with their own "cloud" offering. which does not require such services. So by closing down on those services (or using the redirect to collect data) they are making their offering more attractive. Obligatory car analogy: This is very well like Ford closing down a…

Nah, not really. A closer analogy is Ford shutting down all of Tesla's charging stations because the chargers had a nasty habit of attempting to bazooka any Ford cars that drove past.

The competition from no-ip to Microsoft from this is virtually zero. Any serious hoster will have a static IP, or own their own domain.

Re: No-IP's Formal Statement on Microsoft Takedown

#82
post #70

The Microsoft hate here is unfounded and ill informed. Those of us working defense at large organizations have known for a while that No-IP domains are wretched hives of scum and villainy. Any company with a threat model that includes at least one of a diverse set of characters ranging from malware authors to organized crime to nation state teams should be logging all DNS requests and treating any request to a No-IP…

You seem to miss a key takeaway from this: the analogous comparisons to this in physical services companies is laughable: If, as a car company, i sell cars with potentially lethal flaws, i am required/told to recall and fix those vehicles. Other companies who sell cars are NOT allowed to have a court order the seizure of my phone numbers and have them direct to competitive business, so they can figure out who is driv…

I did not miss that, nor did I make any comparisons to car dealers. In fact, I've been to seven ICANN meetings and have participated in the debate on the proper role of law enforcement and civil seizure in policing the namespace.

Microsoft presented evidence to the court that No-IP domains were being used to facilitate real crimes against real people, and the court acted. I think there is an interesting debate to be had on venue and the level of malicious activity that needs to happen before a domain is seized, but instead all I see is standard HN smashing of the keyboard and "Microsoft Bad!"

Re: No-IP's Formal Statement on Microsoft Takedown

#83
post #67

Earlier quoted context omitted.

You believe in terms of liberty that botnets who compromise machines in order to steal data, spam and many other nefarious activities doesn't compare to one business being temporarily affected ? That is a strange perspective I have to say.

In terms of liberty, one crime doesn't excuse another, especially when they're not directly related. If I manufacture cigarettes and someone dies of lung cancer, I could be ethically liable but my liberty to make cigarettes shouldn't be impacted. If someone uses YouTube to upload copyrighted things, should YouTube have its domain stolen and its users unable to use the site any more?

I don't think cigarettes are the best example because there is no use for them that doesn't potentially invoke the harmful effects for every single user. YouTube, ISPs, and dynamic domain providers have valid, widespread, legitimate, harmless uses, so YouTube is a better analogy IMO.

If one accepts the idea that courts should be seizing entire swaths of domains just to fight malware, it's still absolutely bizarre that Microsoft themselves should be given control of them, rather than an independent policing body. If there are to be Internet police, they should be independent of any one corporation, industry group, or government.

Re: No-IP's Formal Statement on Microsoft Takedown

#84
post #70

The Microsoft hate here is unfounded and ill informed. Those of us working defense at large organizations have known for a while that No-IP domains are wretched hives of scum and villainy. Any company with a threat model that includes at least one of a diverse set of characters ranging from malware authors to organized crime to nation state teams should be logging all DNS requests and treating any request to a No-IP…

You seem to miss a key takeaway from this: the analogous comparisons to this in physical services companies is laughable: If, as a car company, i sell cars with potentially lethal flaws, i am required/told to recall and fix those vehicles. Other companies who sell cars are NOT allowed to have a court order the seizure of my phone numbers and have them direct to competitive business, so they can figure out who is driv…

How does missing the 'car analogy' help at all? Analogies are only ever useful to explain to those who do not understand the first case - trying to draw parallels otherwise inevitably leads to gross simplifications, and they're incredibly frequently abused to try and make another point. Analogies are great if John Oliver, or you're at the bar and talking to Erv the local HVAC guy - but this is hacker news, we normally understand this - and trying to port it to a completely different legal framework is probably disingenuous.

Re: No-IP's Formal Statement on Microsoft Takedown

#85
post #58

They also deny Cisco's allegations here. http://www.noip.com/blog/2014/02/12/cisco-malware-report/ It doesn't compute that Cisco is casting blame on them and Microsoft got a court order when all they had to do is send an email. It's kind of strange, they're probably unable to keep up with the abuse reports and validating them or something. There are a lot of dynamic DNS providers so why do the bad guys pick them for…

The press release smells to me like they're playing the innocent, and are savvy to the kind of language their audience likes. " We were very surprised this morning "... " Had Microsoft contacted us, we could and would have taken immediate action. "? Surely at some point legal proceedings would have initiated some contact?

This comment (and its siblings in the thread) suggest that Microsoft got this order without prior notification to NoIP: https://news.ycombinator.com/item?id=7968762

Re: No-IP's Formal Statement on Microsoft Takedown

#86
post #65
post #56

Earlier quoted context omitted.

I'm pretty sure virtually none of the spam mails in my spamfilter were sent from a phone. Nor do phones have the bandwidth to carry out DDoS attacks or host phishing sites. Nor do many people do onlinebanking on their phone (though that number is certainly on the rise). So yes, while malware exists on android, I doubt the total damages caused by it are more than a drop in the bucket when compared to windows malware.

Android botnets are very valuable because they use mobile network IPs that confuse fraud and login classifiers that use ASN or GeoIP.

Pretty much all botnets target consumer devices and thus have ip addresses that are common for consumer devices. I'm not sure I buy that a mobile IP is worth more than a Comcast one, especially factoring in the available bandwidth.

Re: No-IP's Formal Statement on Microsoft Takedown

#87
post #3

This smells like BS, this also isn't the first time that other entities have had to step in to cleanup their crap. Especially this quote: "Apparently, the Microsoft infrastructure is not able to handle the billions of queries from our customers." Azure DNS, Microsoft.com, Bing. Yeah, all of those already require billions of DNS queries. I don't doubt things are not working correctly, but insinuating Microsoft can't h…

Try and query anything.no-ip.biz. At the moment, I'm getting regular timeouts on queries to both ns7.microsoftinternetsafety.net and ns8.microsoftinternetsafety.net. It shouldn't take much for microsoft to log all incoming dns requests and put in an NS record to let traffic continue flowing down to no-ip's actual nameservers. A simple `dig whatever.no-ip.biz @a.root-servers.net +trace` will show you this.

Re: No-IP's Formal Statement on Microsoft Takedown

#88
post #36

Earlier quoted context omitted.

How do we file the same action against Microsoft? I would like to take their domains for my own purposes, which are obviously far more worthy than what Microsoft is doing with them (I swear).

A good start would be to actually read the legal documents behind the case instead of assuming a lot from someone's comments with cherrypicked facts. http://www.noticeoflawsuit.com/index.htm

You can make it sound like he has no idea what hes talking about, but theres no reason why microsoft is playing FBI.

Re: No-IP's Formal Statement on Microsoft Takedown

#89
post #63
post #29

Earlier quoted context omitted.

DynDNS and afraid, which as far as I know are the next two most popular services like this, both have free options. EDIT: Looks like DynDNS recently got rid of their free offering. I wonder if that was related to this?

DynDNS dropped their free offering a couple of years ago. If you had created your account before then, you were grandfathered in, and still got 5(?) domains for free; as long as you logged in frequently enough.

Dyn permanently ended its free hostname program in May 2014, with 30-day notice given on April 7. http://dyn.com/blog/why-we-decided-to-stop-offering-free-acc...

Re: No-IP's Formal Statement on Microsoft Takedown

#90
post #53

So when will Canonical file an ex-parte TRO against Microsoft for failing to secure Windows XP against malware? It would be nice to see a windows update which upgrades to linux :P Later edit: Isn't this ironic, how most botnet members are running Microsoft's software, yet they get to do this?

Creating the tools by which anyone might theoretically spawn abuse is not the same as proactively hosting those engaging in the same. E.g. one might reasonably disrupt a farmer's market known to be selling beef infected with salmonella without banning cows of the same breed across the world.

Creating a faulty lock mechanism that can be circumvented by anyone, then putting a gate at the end of the street to stop people getting back to their own houses that are now full of crack dealers because of the faulty locks...

Yep totally the same...

Post reply on HN