Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

211–220 of 261 posts

Re: Microsoft takes down No-IP.com domains

#211
There are serious problems with this, firstly that it's technically impossible to implement effectively, beyond that it's extremely impractical. Any benefit will be so so transient as to render the entire exercise pointless.

For the moment, let us ignore the scary implications of the court's part in this and consider this from a technical perspective in a logical manner:

The hypothetical sub-domain abc.no-ip.org resolves to 1.2.3.4, a host somewhere that contains malicious payloads, is botnet C&C or is a member of a botnet. In any case, he's the bad guy - one of the people Microsoft are looking to exclude from the Internet.

So how can this be accomplished? Let's ignore for the moment that the bad guys are free to use any other dyndns service they please and assume that no-ip is the only one.

Approach 1

----------

Every time a host connects to no-ip to update its IP, Microsoft scans tcp & udp ports of the host looking for known C&C services, scans hosted data (public web or ftp). This will simply result in the bad guys hiding all of this in an undetectable manner, many bot-nets already use either Tor or SSH for C&C - without authentication it will be impossible to differentiate Joe Average with an SSH or Tor exit from the "targets".

As for scanning for content, this is possible assuming the content has to be public (ie. malicious payload) but even then, it's not practical - payloads can be hidden in anything and obfuscated beyond detection. Essentially all that's accomplished is another arms race based around signature detection for malicious content, with the disadvantage that unlike AV solutions this scanning is conducted remotely and the scan source is known. So the malicious guy with 2 or three lines just uses a stateful firewall to point microsoft's "scanning service" to good content, everyone else to the bad.

So what other options are there? A blacklist of IPs? Well, they're dynamic IPs, sooner or later you'll end up with every dynamic IP in the entire ipv4 range blacklisted as the bad dudes just release/renew.

Then there's banning the sub-domains/users! Also impractical because for each user and domain you ban, another will emerge.

Approach 2

----------

Microsoft resolves every request for abc.no-ip.org to their own service, all the time, this service performs stateful packet analysis before forwarding it on to the destination host. Impractical because you're essentially routing all no-ip traffic via Microsoft and once again you can only filter what you can detect -- and once the requests themselves are encrypted, that becomes impossible. This is effectively a MITM attack.

All the while we've assumed no-ip is the only alternative, it's not - and many others are beyond Microsoft and the courts jurisdiction. So ultimately the only way this "approach" could be temporarily feasible is if all Internet traffic were routed through Microsoft's service. So effectively you need to give control of every domain, TLD, ipv4 and ipv6 range to Microsoft. Not workable.

Someone is bound to point out that Microsoft's approach in this may be distributed, agents running on installs of their operating system which does address some aspects of my points above, but once again -- if Microsoft is capable of implementing effective detection on the workstation, remind me again why any of this is needed?

I must be missing something fundamental.

Re: Microsoft takes down No-IP.com domains

#212

> On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. Something about this bothers me. So the courts granted MS the rights to essentially take over No-IP's DNS in order to "identify" ... "bad traffic?" The implications of this are...…

Microsoft was able to demonstrate that they were actually involved in committing the crimes. The court didn't give them the domains so that they could then come up with evidence. They already had the evidence.

Oh nevermind...NSA...M$ is teh suxor...oh mer gurd!!!!

Re: Microsoft takes down No-IP.com domains

#215

Earlier quoted context omitted.

That's quite a stretched analogy. A fully updated Windows XP computer will still be vulnerable to malware and botnets. That is because Windows, OS X, Android and Linux allow their users to install third party programs without whitelisting them. There is nothing stopping users from installing malware. OS X and Linux have less malware because they're not as popular as Windows and Android. That's opposite to iOS, Window…

A fully updated Windows XP computer will still be vulnerable to malware and botnets. That is because Windows, OS X, Android and Linux allow their users to install third party programs without whitelisting them. Then clearly Microsoft aren't doing enough to look after their own back yards, and their domains should be seized and potential Microsoft customers rerouted to information about the dangers of using Microsoft…

Because you're a fucking expert, huh?

Re: Microsoft takes down No-IP.com domains

#216

Earlier quoted context omitted.

But that's an awful analogy and frankly you should be ashamed for even trying to paint it in that light. NOIP did nothing illegal whatsoever, their only "crime" was that they didn't do enough about malware distribution to keep Microsoft happy- which last I heard wasn't illegal. To use your car wash analogy, it's more like the car wash unknowingly washed the car of a drug trafficker and then was essentially put out of…

I am uneasy about this situation, but the car wash in question is more like the car painting shop in Grand Theft Auto. Even if painting cars is a legitimate activity, when 75% of your customers are trying to mask illegal activity you should be doing some due diligence to ensure that you're not enabling illegal activity. I'm not totally okay with what happened here, but I'm confident that it was not a "oops, sorry, we…

no-ip primary use case is certainly not botnets. It's used by dsl users to connect to their home network, or to get an easy to remember address for a vps, or maybe while developing something before getting a proper domain.

Re: Microsoft takes down No-IP.com domains

#218

Earlier quoted context omitted.

My home VPN is unable to connect right now. I use a noip.me domain. The actions of both the courts and Microsoft are extremely concerning to me.

Same here, I was confused this afternoon when my home vpn hosted on a servebeer.com subdomain wouldn't connect. Now it makes a lot more sense, but I'm left with a very bad taste in my mouth.

Buy your own domain, preferably with a company outside the US. I use gandi.net and http://code.google.com/p/gandi-automatic-dns/

It's more expensive, but you control it.

Re: Microsoft takes down No-IP.com domains

#219

Earlier quoted context omitted.

1. Websites hosting services that have no other purpose but to DDoS other computers are absolutely illegal. Many such sites have been taken down by the FBI before, and both users and owners of the sites have been arrested. The problem is that there are many hundreds of such sites and tens of thousands of users, and law enforcement simply can't take down each and every one. Cloudflare is relying on the fact that most…

Is requiring legal due process such a bad thing?

In some cases? Yes.

The legal system simply cannot process every single civil or criminal complaint everyone in the US may have. If a security researcher had to go through a court, and/or law enforcement, every single time they wanted a malicious domain taken down then their work would be nigh impossible.

Legal due process should be required when there are legal penalties or punishments. In this case, the bot herders and malware distributors are not subject to any criminal or civil penalties in response to abuse complaints: they do not go to jail and are not fined. Some of them will be fined or imprisoned, many years later, but everyone's better off if their botnets are shut down immediately instead of in 2-5 years.

It's a dealing between private entities: private entity X agrees to stop providing server or domain hosting for the bot herder after seeing a good faith report. A provider has every right to stop offering you service.

Without this sort of cooperation between entities, the Internet would be even more of a mess right now.

Re: Microsoft takes down No-IP.com domains

#220

What I don't understand and haven't seen anyone ask is, why Microsoft? I mean, obviously some shady legal tactics are at work here, but why did Microsoft got to control those domains instead of, Mozilla for example? or Google? even more so, why wasn't control transferred to ICE for example? Not saying it's a better alternative or even that I agree with it, but it's very VERY unsettling (and I'm not even American) tha…

Our government has a pretty long track record of privatizing law enforcement (not to mention prisons, warfare, etc...) so it's not surprising to see this handed off to Microsoft. If anything, a company like MS, Google or Mozilla at least has the expertise to do a good job.

Still not happy to see it, though.

Post reply on HN