Live data from Hacker News

No-IP's Formal Statement on Microsoft Takedown

noip.com

111–116 of 116 posts

Re: No-IP's Formal Statement on Microsoft Takedown

#111
post #56

Earlier quoted context omitted.

I'm pretty sure virtually none of the spam mails in my spamfilter were sent from a phone. Nor do phones have the bandwidth to carry out DDoS attacks or host phishing sites. Nor do many people do onlinebanking on their phone (though that number is certainly on the rise). So yes, while malware exists on android, I doubt the total damages caused by it are more than a drop in the bucket when compared to windows malware.

Your original statement was: >Practically every instance of malware runs on Microsoft Windows. Even according to Google, about 5 million Android devices are infected with malware. http://bgr.com/2014/06/26/google-on-android-malware-and-secu... I would suppose that your statements aren't support by fact, but the HN downvotes have got me thinking.

The downvotes are because you're derailing the thread with something that is completely off-topic.

Re: No-IP's Formal Statement on Microsoft Takedown

#112
post #91

Earlier quoted context omitted.

Wouldn't a similar line of reasoning be "It seems that computers running Microsoft Windows are a hotspot of botnet activity. Year after year, a vast majority of computers used in botnets are running Windows; they are clearly not doing enough to prevent abuse by their users. Lets give control of the Windows code base to Linus"

I think most of the judges would be able to see through it and recognize that running a free DNS service which ignores abuse by botnets and having an OS which can be used to run various programs on, including malware, is a bit different thing. If you could prove Microsoft "clearly not doing enough to prevent abuse", you could probably win a juicy class-action lawsuit, but proving this would be extremely hard.

How would NO-IP detect C&C servers aliased to their subdomains, even if they connected to every single one of their subdomains daily -- they wouldn't know what ports to scan. By my, possibly naive thinking, they'd have to impose denial of service attacks on their own customers, constantly, and they would be easily thwarted by port knocking schemes. Probably their only recourse is to stop offering free service, and instead take payment, or require and verify customer IDs. I'm not sure there's a technical solution. Microsoft seems to be attacking their business model.

Re: No-IP's Formal Statement on Microsoft Takedown

#113
post #28

Earlier quoted context omitted.

You might just as well say it is the IANA's fault for issuing the IP addresses the malware authors used, or Ford's fault for building the getaway car used in a bank robbery.

Your argument is ridiculous. Turning over IANA or Ford over to Microsoft would not prevent malware or robberies. Turning over NoIP to Microsoft will prevent malware (at least in the short term).

Well, how exactly does this prevent malware? Oh, that's right: by shutting down thousands of malware-serving DNS records. (And, btw, millions of legitimate records - but hey, that's just collateral damage; a thousand, a million, same thing, right?)

Using the same logic, let's just prevent malware altogether by blackholing all of the Internet traffic - problem solved!

Re: No-IP's Formal Statement on Microsoft Takedown

#114
post #99
post #91

Earlier quoted context omitted.

I think most of the judges would be able to see through it and recognize that running a free DNS service which ignores abuse by botnets and having an OS which can be used to run various programs on, including malware, is a bit different thing. If you could prove Microsoft "clearly not doing enough to prevent abuse", you could probably win a juicy class-action lawsuit, but proving this would be extremely hard.

If they went through with their intended plan to stop supporting Windows XP, then proving that they were "clearly not doing enough to prevent abouse" would be trivially easy.

How so? Microsoft never promised it would support XP forever. EOLing old versions is a standard and widely accepted industry practice. Just buy (or install for free) a newer operating system. Buying a license to run Windows XP on your computer does not entitle you to unlimited amount of free labor from Microsoft. If you think that makes XP suck, nobody forces you to buy it or keep using it. Are you also expecting Linus to still make patches for Linux kernel 1.0?

Re: No-IP's Formal Statement on Microsoft Takedown

#115

They also deny Cisco's allegations here. http://www.noip.com/blog/2014/02/12/cisco-malware-report/ It doesn't compute that Cisco is casting blame on them and Microsoft got a court order when all they had to do is send an email. It's kind of strange, they're probably unable to keep up with the abuse reports and validating them or something. There are a lot of dynamic DNS providers so why do the bad guys pick them for…

Presumably because they have a free basic service if you use one of their subdomains. While other companies I'm not aware of might offer the same I've yet to stumble across them.

http://dhcp.io/ is (my) new service, launched only recently.

Mine doesn't use the same dyn update API, just curl, and you can self-host if you have an Amazon Route53 account.

Re: No-IP's Formal Statement on Microsoft Takedown

#116

If this action is troubling, then we need to stop putting the blame in the wrong place. Microsoft does not have the power to seize domains. A federal court order made that happen. This order is (apparently) the responsibility of the U.S. District Court of Nevada. If you want to blame someone, then blame the court. Obnoxious people ask courts to do obnoxious things every day. Good courts do not comply.

So why not blame the "obnoxious people" in this case, too? It's like the patent system abusers (which perhaps not by coincidence, Microsoft is one, too) excuse: "don't hate the player, hate the game". Yeah, right. Nobody held a gun to their head to do this. It was a premeditated action by Microsoft.

You are correct that Microsoft would deserve some of the blame, if there is to be blame. However, user pessimizer put it very well:

> Microsoft has no obligation to you. Your judicial system does.

In any case, there is no "hating the game" here. The fault -- if one has a problem with this action -- is not with "the system", but with a very specific player: the federal judge who issued the order. (I don't feel like going through the trouble of finding his/her name, but I doubt it would be difficult.)

Post reply on HN