Live data from Hacker News

Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

techweekeurope.co.uk

11–20 of 36 posts

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#11
post #4

I get really irritated with companies that put absolutely no effort into cleaning up their services on their own. When nearly 20,000 of No-IP's accounts are being used for malicious purposes, crying about how Microsoft didn't give them any warning just makes them seem incompetent. There was another article recently on HN about some free tunneling service whose creator tried to automate account shutdowns whenever his…

It is a very dangerous notion that the federal courts can seize the domains of one company and just hand them over to another company... It was bad enough when ICE was doing it, this takes that bad practice to a whole other level...... What is even worse is they got the order ex parte, meaning No IP did not have a chance to defend or explain themselves to the judge before their business was irreparably harmed by the…

[deleted]

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#12
post #4

I get really irritated with companies that put absolutely no effort into cleaning up their services on their own. When nearly 20,000 of No-IP's accounts are being used for malicious purposes, crying about how Microsoft didn't give them any warning just makes them seem incompetent. There was another article recently on HN about some free tunneling service whose creator tried to automate account shutdowns whenever his…

It is a very dangerous notion that the federal courts can seize the domains of one company and just hand them over to another company... It was bad enough when ICE was doing it, this takes that bad practice to a whole other level...... What is even worse is they got the order ex parte, meaning No IP did not have a chance to defend or explain themselves to the judge before their business was irreparably harmed by the…

Question of fact: did the court attempt to contact No-IP.com? Or did they attempt contact, and No-IP.com failed to show up?

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#13

This is even more ridiculous than I thought, given TFA -- Microsoft could have just asked them to change the IP associated with the relevant accounts, disable update for them and/or hand over access to those accounts. To quote myself from the other thread, the approach they did take is more than slightly bizarre: "There are serious problems with this, firstly that it's technically impossible to implement effectively,…

While I do think Microsoft's approach here is pretty insane, your proposed solution would not have helped at all:

>Microsoft could have just asked them to change the IP associated with the relevant accounts, disable update for them and/or hand over access to those accounts.

The botnet operators are using this service because of how transient it is. They likely have hundreds of accounts, each with thousands of domains, and can make more accounts and more domains on the fly.

What Microsoft should've done is worked with no-ip's team to implement some code in the account and domain registration process to catch these kind of patterns, in a way where the botnet operator thinks he's configured them correctly, but Microsoft is actually using no-ip's nameservers to point those domains to their sinkholes. After setting this up, they could've then generalized this checking process to catch and automatically ban (or shadowban) other registrants who appear to be using no-ip for botnet command & control or malware distribution. They also could implement evercookies and browser fingerprinting to track threat actors who keep making new accounts in combination with the heuristic detection.

They could've achieved a lot of good by doing this; but now every miscreant out there knows all about this due to the publicity, so they're not going to touch no-ip with a 50 foot pole.

If no-ip refused to implement something like this, then maybe Microsoft could've gotten a temporary court order so that they could basically force them to. But instead they forced them to give up control of their entire DNS space, all to take down 1 botnet.

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#14
post #10
post #4

I get really irritated with companies that put absolutely no effort into cleaning up their services on their own. When nearly 20,000 of No-IP's accounts are being used for malicious purposes, crying about how Microsoft didn't give them any warning just makes them seem incompetent. There was another article recently on HN about some free tunneling service whose creator tried to automate account shutdowns whenever his…

Lets be honest about the problem and this isn't some slashdot-esque rant: a) Windows is a piece of crap when it comes to staying clean. If it wasn't, Microsoft wouldn't have to go after people like this. Not joking but I clean out a fair number of PCs every year and they are crawling with malware. b) Users are dumb and install any old crap on kit if prompted to. Microsoft's SmartScreen did very little to prevent this…

>They're a pretty easy target as the architecture of Windows is incredibly complicated and they're playing plug the holes rather than designing it properly to start with. For ref, I know the NT kernel, win32 and CLR inside out and no longer would I poke it with a stick.

Not sure what you mean by that. Does Linux have any protections beyond Windows to stop malware? Why does Android have a malware problem?

This is the text of a post I made yesterday in reply to a similar comment:

How can they patch it in their product without turning desktop Windows into something like iOS or Windows Phone/RT? Even Android has a ton of malware so the notion that Windows is somehow more hole ridden than other platforms stopped being true starting about 10 years ago with their Secure computing initiative. If the user can install Firefox, they can install malware.

If Firefox doesn't need to get permission from MS for their next version, Windows cannot distinguish between Firefox.exe and Codec_Flash_Shady.exe. Sandboxing will disable system level utilities.

MS is capable of making secure OSes. How many viruses and trojans do the 3 Xboxes, Windows Phone and RT have? Even Windows Server is pretty secure(atleast as secure as Linux) unless the admins start browsing on it. Malware is a real threat to any popular OS unless third party apps are entirely blocked or restricted by the use of a approval based App Store. Windows gives much more control to the user, which is why many users are able to stay away from infections.

And it's ironic that you're blaming MS here instead of the folks that propagate it(including a YC company https://www.techdirt.com/articles/20130115/17343321692/why-a...) and people who install it(users).

Remember the shitstorm that was raised against MS on here and elsewhere when they tried to secure users by preventing undetectable rootkits by enabling Secure Boot?

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#16

Earlier quoted context omitted.

It is a very dangerous notion that the federal courts can seize the domains of one company and just hand them over to another company... It was bad enough when ICE was doing it, this takes that bad practice to a whole other level...... What is even worse is they got the order ex parte, meaning No IP did not have a chance to defend or explain themselves to the judge before their business was irreparably harmed by the…

Question of fact: did the court attempt to contact No-IP.com? Or did they attempt contact, and No-IP.com failed to show up?

Courts never contact anyone. It is normally up to the Plaintiff to "Serve" the defendant. Except when the Plaintiff seeks an ex parte motion,order,etc which allows to court to act with out contacting the defendant.

Further if this would have been a situation where contact was attempted and failed it would have been a "default" judgment/order not ex parte

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#17
post #10
post #4

I get really irritated with companies that put absolutely no effort into cleaning up their services on their own. When nearly 20,000 of No-IP's accounts are being used for malicious purposes, crying about how Microsoft didn't give them any warning just makes them seem incompetent. There was another article recently on HN about some free tunneling service whose creator tried to automate account shutdowns whenever his…

Lets be honest about the problem and this isn't some slashdot-esque rant: a) Windows is a piece of crap when it comes to staying clean. If it wasn't, Microsoft wouldn't have to go after people like this. Not joking but I clean out a fair number of PCs every year and they are crawling with malware. b) Users are dumb and install any old crap on kit if prompted to. Microsoft's SmartScreen did very little to prevent this…

This reminds me of a friend of mine:

"But mom! Why did you 'sudo sh LOVE-LETTER-FOR-YOU.txt.sh' in the first place? Didn't I tell you not to trust email?". Security's no1 problem is the user.

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#18

Earlier quoted context omitted.

Question of fact: did the court attempt to contact No-IP.com? Or did they attempt contact, and No-IP.com failed to show up?

Courts never contact anyone. It is normally up to the Plaintiff to "Serve" the defendant. Except when the Plaintiff seeks an ex parte motion,order,etc which allows to court to act with out contacting the defendant. Further if this would have been a situation where contact was attempted and failed it would have been a "default" judgment/order not ex parte

Fine, did any party before the court attempt to serve No-IP.com?

If No-IP.com avoided service like Charles Carreon, I have little sympathy. If there was no attempt at service, that's a different story.

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#19
post #10
post #4

I get really irritated with companies that put absolutely no effort into cleaning up their services on their own. When nearly 20,000 of No-IP's accounts are being used for malicious purposes, crying about how Microsoft didn't give them any warning just makes them seem incompetent. There was another article recently on HN about some free tunneling service whose creator tried to automate account shutdowns whenever his…

Lets be honest about the problem and this isn't some slashdot-esque rant: a) Windows is a piece of crap when it comes to staying clean. If it wasn't, Microsoft wouldn't have to go after people like this. Not joking but I clean out a fair number of PCs every year and they are crawling with malware. b) Users are dumb and install any old crap on kit if prompted to. Microsoft's SmartScreen did very little to prevent this…

> Windows is a piece of crap when it comes to staying clean.

All operating systems at the face of the earth are a piece of crap when the users have admin rights and install every piece of sXXt they can put their hands on.

There isn't a single one that does it better.

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#20

Earlier quoted context omitted.

Courts never contact anyone. It is normally up to the Plaintiff to "Serve" the defendant. Except when the Plaintiff seeks an ex parte motion,order,etc which allows to court to act with out contacting the defendant. Further if this would have been a situation where contact was attempted and failed it would have been a "default" judgment/order not ex parte

Fine, did any party before the court attempt to serve No-IP.com? If No-IP.com avoided service like Charles Carreon, I have little sympathy. If there was no attempt at service, that's a different story.

Perhaps one should read my full post, as I answer this question in my "Further" second paragraph

I think you are just grasping to find any justification for what MS and the courts have done here... There are none.

Post reply on HN