Live data from Hacker News

It's Way Too Easy to Get a .gov Domain Name

krebsonsecurity.com

11–20 of 184 posts

Re: It's Way Too Easy to Get a .gov Domain Name

#11

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

Agreed, that was totally gratuitous and it detracts from the article.

Re: It's Way Too Easy to Get a .gov Domain Name

#12
> who said he got a .gov domain simply by filling out and emailing an online form, grabbing some letterhead off the homepage of a small U.S. town that only has a “.us” domain name, and impersonating the town’s mayor in the application.

He also can get prosecuted and potentially jail time for such a gamble.

Re: It's Way Too Easy to Get a .gov Domain Name

#13

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

One of the major political parties in the US has been repeatedly engaging in voter suppression. Is it partisan to observe repeated behavior on one side of the political spectrum, and to extrapolate accordingly?

https://en.wikipedia.org/wiki/Voter_suppression_in_the_Unite...

Re: It's Way Too Easy to Get a .gov Domain Name

#14

The title reminds me when someone reported that it was just as easy to get fully-automatic firearms and other military gear from homeland security for free by pretending to be a police department (fake website) and a simple form.

There are other more straightforward ways to illegally purchase post-hughes machine guns. This is an extremely high risk scheme.

Yeah but

A) military gear is more than automatic weapons. Sometimes they send out things harder to come by than guns to police departments.

B) This scheme costs less than pennies on the dollar.

Re: It's Way Too Easy to Get a .gov Domain Name

#15
If you want some irony, from the "dotgov.gov" website linked in the post:

>An official website of the United States government. Here's how you know:

>The .gov means it's official. Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site.

Re: It's Way Too Easy to Get a .gov Domain Name

#16

The title reminds me when someone reported that it was just as easy to get fully-automatic firearms and other military gear from homeland security for free by pretending to be a police department (fake website) and a simple form.

An alarming amount of societal functionality depends on what effectively amounts to the honor system. This is especially true when it comes to any sort of gatekept specialty profession, like coroners for example.

There was a great talk at DefCon about faking death: https://m.youtube.com/watch?v=9FdHq3WfJgs

Re: It's Way Too Easy to Get a .gov Domain Name

#17
> A review of the Top 10 most populous U.S. cities indicates only half of them have obtained .gov domains, including Chicago, Dallas, Phoenix, San Antonio, and San Diego.

> Yes, you read that right: houston.gov, losangeles.gov, newyorkcity.gov, and philadelphia.gov are all still available. As is the .gov for San Jose, Calif., the economic, cultural and political center of Silicon Valley.

A minor nit: Many of these cities do have a .gov domain. For example, NYC has nyc.gov. So, I would suspect (or I’d hope) the GSA wouldn’t issue newyorkcity.gov to a random fraudster as easily.

Houston has houstontx.gov.

Philadelphia has phila.gov.

San Jose has sanjoseca.gov.

LA has .. lacity.org? That’s a bit unexpected.

Some cities may also use a subdomain of their states domain, which may or may not be a .gov.

Re: It's Way Too Easy to Get a .gov Domain Name

#19

> who said he got a .gov domain simply by filling out and emailing an online form, grabbing some letterhead off the homepage of a small U.S. town that only has a “.us” domain name, and impersonating the town’s mayor in the application. He also can get prosecuted and potentially jail time for such a gamble.

> He also can get prosecuted and potentially jail time for such a gamble.

I'm sure such a threat is definitely going to stop the bad guys, so let's not worry about actual security. /s

The people that should be prosecuted are the ones falling for such an obvious fraud. If you're in control of the .gov TLD and explicitly tell people to use the domain as a sign of legitimacy you are expected to know what you're doing and not be an idiot like the people currently running it.

Re: It's Way Too Easy to Get a .gov Domain Name

#20

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

One of the major political parties in the US has been repeatedly engaging in voter suppression. Is it partisan to observe repeated behavior on one side of the political spectrum, and to extrapolate accordingly? https://en.wikipedia.org/wiki/Voter_suppression_in_the_Unite...

Specifying "democrat" in this particular example of how an adversary having a .gov domain could be bad adds nothing to the example.
Post reply on HN