Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

241–250 of 261 posts

Re: Microsoft takes down No-IP.com domains

#241

Earlier quoted context omitted.

First off, thankyou for a detailed and well laid out post. I do however think that there is a material difference between hosting unpleasant speech (to which the counter is speech pointing out that the speaker is wrong/idiotic/etc) and hosting malware/botnet sites (to which the counter is... what? what IS the counter to a sufficiently large botnet? ultimately we all have a limit at which point we can receive no more…

Agree, which is why we do take malware and phishing sites, which we can judge as per se harmful, offline. Read more here: http://blog.cloudflare.com/thoughts-on-abuse Malware and sites advertising so-called "booter" services are different discussions.

(Sorry I'm just responding to all this now, 15 hours later)

> Malware and sites advertising so-called "booter" services are different discussions.

There's an important distinction here. You refer to "sites advertising so-called "booter" services." However, with the kind of sites I speak of, "sites providing so-called "booter" services" would be a better description. They aren't just advertising it; enter a valid username and password, enter an IP, click the "attack" button and an attack is launched, all from that single site.

Malware, phishing, and booters have two things in common: they have far-reaching effects (that is, they affect other, unrelated/unwilling people) and they are not in any way good for the target of the effort. Malware is only good for the operator who benefits from the keylogger, showing ads, or whatever; phishing is only good for the operator who benefits from the stolen information; booters are only good for the booter operator (who profits from selling it) and for the user who paid for it to attack a target. Based on that, it's difficult for me to see the difference between the harmfulness of any of these.

In your post, the standard you applied to malware and phishing was "harmfulness" (in your opinion). I agree with that standard, and I think you'll be hard-pressed to find a single person who agrees that any of these three issues are not harmful. So, in your opinion, what makes booters less harmful than malware and phishing sites, which you are willing to take offline?

Censorship is a slippery slope, indeed. But I think it is generally accepted that _some_ basic level of what is effectively censorship, is a necessary evil for the health of the Internet. For example, malware and phishing sites, as you mentioned; spam; DDoS attacks. That's why laws exist in so many jurisdictions to prohibit all of these, and why the AUP of every single reputable ISP in existence prohibits them. This isn't uncharted territory, this isn't something new CloudFlare is just getting into - the industry standard (and legal standard) is to prohibit all of these.

Re: Microsoft takes down No-IP.com domains

#242

Earlier quoted context omitted.

> Sure, it's creepy when courts have control over DNS entries, but ... they do. In this case it was a US court and between two US companies, what if no-ip.com was French or UK or... Would the US court still have authority in this case? Would MS have to go to a French / UK court?

.com is US-owned, so it wouldn't have to. See e.g. megaupload

Which makes it infinitely creepier / problematic for non US companies.

Re: Microsoft takes down No-IP.com domains

#243
post #221

Earlier quoted context omitted.

>you control it. Hardly. Any domain in the existing domain name system can be seized.

I'd like to see that on a global TLD. If you mean that any arbitrary country can seize a TLD belonging to that country, then yeah I guess you are right. You can always get a distributed TLD but then you have the problem of them not being resolvable unless the PC you are at is correctly configured.

What's a global TLD?

Re: Microsoft takes down No-IP.com domains

#244
Complete BS. They claimed they were just going to stop bad traffic. But they can't handle the overall traffic load and so NO traffic is getting through. I was using the service to provide access to an API server in-house. A very simple server, nothing but JSON requests in-and-out. Absolutely NO malware. But since MS takeover - no traffic has gotten through.

I pay for my noip account, so I'm happy to join any lawsuits against MS for this action. Personally, I see a class action suit being VERY viable.

I also have issue with the courts even allowing this. Did they do ANY research on what is actually going on? I can't see how they could let this happen.

I feel violated!

Re: Microsoft takes down No-IP.com domains

#245
post #243

Earlier quoted context omitted.

I'd like to see that on a global TLD. If you mean that any arbitrary country can seize a TLD belonging to that country, then yeah I guess you are right. You can always get a distributed TLD but then you have the problem of them not being resolvable unless the PC you are at is correctly configured.

What's a global TLD?

Sorry, I should say international non-US tld, or in other words, a TLD not under the control of the US.

Re: Microsoft takes down No-IP.com domains

#246

There are serious problems with this, firstly that it's technically impossible to implement effectively, beyond that it's extremely impractical. Any benefit will be so so transient as to render the entire exercise pointless. For the moment, let us ignore the scary implications of the court's part in this and consider this from a technical perspective in a logical manner: The hypothetical sub-domain abc.no-ip.org reso…

You are missing the late 90s adage: "Where does the 900-pound gorilla sit?" The answer is, of course, "Anywhere it wants to."

Re: Microsoft takes down No-IP.com domains

#247
post #243

Earlier quoted context omitted.

What's a global TLD?

Sorry, I should say international non-US tld, or in other words, a TLD not under the control of the US.

US controls root/'.' via ICANN and can theoretically seize anything under the DNS system

Only reason they don't for gTLDs is because of the political fallout

Re: Microsoft takes down No-IP.com domains

#248
I would just add @andor, that the Police DO NOT own enough tools and equipment to do this. The Private sector has to, for better or for worse.

I have domains with NO-IP and I've had no problem with them. It would all have been better had Microsoft made a statement about seizing the DNS but I respect the DON'T TELL THE ENEMY WE'RE COMING AND ON TO THEM !

Re: Microsoft takes down No-IP.com domains

#249
post #79

Earlier quoted context omitted.

Isn't that close to what happened to Mega Upload and domain handed over to the government?

Of course a court can seize domains. But if an investigation follows, it should be carried out by the police, not by private companies (and especially not by the plaintiff). At least that's what I'd expect from a constitutional state ;-)

The Police DO NOT have the necessary hardware and software to take on such a task Andor. The Private Sector does because that is what they do.

Re: Microsoft takes down No-IP.com domains

#250

> On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. Something about this bothers me. So the courts granted MS the rights to essentially take over No-IP's DNS in order to "identify" ... "bad traffic?" The implications of this are...…

Microsoft was able to demonstrate that they were actually involved in committing the crimes. The court didn't give them the domains so that they could then come up with evidence. They already had the evidence. Oh nevermind...NSA...M$ is teh suxor...oh mer gurd!!!!

Really... so the hundreds of thousands innocent users that was not doing any crimes? What about them?

This just proves that the current authorized domain system is not working, and its the beginning of the end.

Post reply on HN