Live data from Hacker News

It's Way Too Easy to Get a .gov Domain Name

krebsonsecurity.com

1–10 of 184 posts

Re: It's Way Too Easy to Get a .gov Domain Name

#2
Good reporting, until this paragraph:

Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs had gone off at polling stations in Democrat-leaning districts. Such a hoax could well decide the fate of a close national election.

Why the need to specify "Democrat" strongholds? Doesn't this attack work for any other political-party strongholds as well? Seems like an unnecessarily partisan position to take.

Re: It's Way Too Easy to Get a .gov Domain Name

#4

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

Due to differences in Democrat and Republican voter demographics, one is more heavily affected than the other.

Re: It's Way Too Easy to Get a .gov Domain Name

#5

The title reminds me when someone reported that it was just as easy to get fully-automatic firearms and other military gear from homeland security for free by pretending to be a police department (fake website) and a simple form.

There are other more straightforward ways to illegally purchase post-hughes machine guns. This is an extremely high risk scheme.

Re: It's Way Too Easy to Get a .gov Domain Name

#6

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

I see what you mean, but I suspect the author might be referring to the Russian disinformation campaign to favour Republicans. I see it just as an example - obviously it can be adapted in either direction, or both just to deter voter participation altogether.

Re: It's Way Too Easy to Get a .gov Domain Name

#7

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

[deleted]

Re: It's Way Too Easy to Get a .gov Domain Name

#8

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

It's a figure, not every sentence needs to have stand-in characters written in to appeal to sensitivities like this. Also, maybe if he chose “Republican” it wouldn't hit home, and it'd sound like he's threatening his audience with a good time. ;- )

It could be criticized regardless of the characters chosen.

Re: It's Way Too Easy to Get a .gov Domain Name

#9

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

That specific paragraph is a lot of weirdness.

But once you have the domain, somebody who knows what they're doing with DNS and SMTP absolutely could set up proper email services on it (forward-confirmed rDNS, SPF, DKIM signing, DMARC), and send spam with it. It's functionally equivalent to any other domain. Particularly if the intention was to be a one-shot approach that would "burn" both the domain and the hosting services, such as in the days leading up to an election.

A really smart bad actor would use some IP space from an ISP that traditionally has not been a source of spam. Eg: Not an ISP with a lot of low-dollar-value VPS/VM/hosting customers.

There's still some totally "clean" /24 IP blocks out there in the various RBLs and spam listing services if you go searching.

If I were an evil person and did this, I'd try to get the domain at least a few weeks in advance and try to generate a moderate volume of totally legit looking emails, destined for the top 20 major destinations (office365, gmail, etc) and verify from a bunch of sockpuppet accounts that the mail was actually getting delivered. Then I'd turn loose the fire hose.

Should a person want to be really evil, they'd do something like the reverse of what happened to the City of Baltimore with the cryptolocker trojan. Find a list of municipal (water, sewer, gas, electrical, property tax) bill payers and email each of them a plausible looking invoice, with cryptolocker attached. The likelihood of people opening it would be high.

Re: It's Way Too Easy to Get a .gov Domain Name

#10

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

Large cities tend to be blue, and you want to pick a recognizable large city name to get the point across. Politics aside, the example would've had less impact for a republican stronghold just because it wouldn't be as recognizable a city name.
Post reply on HN