Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

111–120 of 261 posts

Re: Microsoft takes down No-IP.com domains

#112
post #3

FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).

At CloudFlare, we have a Trust & Safety team dedicated to dealing with the abuse of our network. We sit in front of more than 2 million sites. The vast majority of them are not controversial (the site you're reading this on, for instance), but some are not. The majority of the abuse requests we receive are DMCA requests, but we get other reports as well. Dealing with these requests is a hard problem because a large n…

spam?

Re: Microsoft takes down No-IP.com domains

#114
post #109
post #3

FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).

Hey pktgen: I'm new at CloudFlare, but I'd be really interested in chatting with you (or grabbing a beer) to hear if there's something we could do better. Contact info in my profile. I'll be at Defcon and HOPE too if that's easier. (Free speech vs. keeping the overall network safe is a hard decision. I think all pro-privacy and pro-liberty services have had to answer this question -- same thing happened with cypherpu…

Thanks, I'm also interested in having a chat with you about it, so I'll take you up on that offer in a bit. :)

Re: Microsoft takes down No-IP.com domains

#115

So let me get this straight. Microsoft got a court order to route all of another entity's DNS traffic to their servers. Giving them the ability to route a metric crap-ton of private traffic through their data centers. For "security". I call shenanigans. I'm also assuming this is why my no-ip domain disappeared this morning, leaving me with no access to my home servers. Perhaps the linux on my servers is considered ma…

Not exactly.

> allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats.

According to MSFT, they are only looking at known "bad" traffic. You can take their word for it... or not.

Re: Microsoft takes down No-IP.com domains

#116
post #108

Earlier quoted context omitted.

At CloudFlare, we have a Trust & Safety team dedicated to dealing with the abuse of our network. We sit in front of more than 2 million sites. The vast majority of them are not controversial (the site you're reading this on, for instance), but some are not. The majority of the abuse requests we receive are DMCA requests, but we get other reports as well. Dealing with these requests is a hard problem because a large n…

My own comments about your company are based on what I described in https://news.ycombinator.com/item?id=7880514 . Would you care to respond to my statements in that post?

And without your usual comment of "the attack traffic is not from our network, so it's not our problem".

Re: Microsoft takes down No-IP.com domains

#117

Loads of self-congratulating tripe. Microsoft why don't you simply provide free OS upgrades or fixes for the millions of XP computers out there? They are not going anywhere soon. Next thing we know your lawyers and lobbyists are going to come up with some legislative wheeze and you will be running the biggest botnet in the world. You created the problem so fix it yourself.

[deleted]

Re: Microsoft takes down No-IP.com domains

#118
post #108

Earlier quoted context omitted.

At CloudFlare, we have a Trust & Safety team dedicated to dealing with the abuse of our network. We sit in front of more than 2 million sites. The vast majority of them are not controversial (the site you're reading this on, for instance), but some are not. The majority of the abuse requests we receive are DMCA requests, but we get other reports as well. Dealing with these requests is a hard problem because a large n…

My own comments about your company are based on what I described in https://news.ycombinator.com/item?id=7880514 . Would you care to respond to my statements in that post?

Sure. Pardon the copy-and-paste reply, but it's a perfect opportunity for me to publish up a draft blog post I wrote half a year ago in anticipation of a Brian Krebs post on the topic of Booter sites. Brian's article didn't turn out nasty enough to warrant a response, but I've had the post sitting around in by drafts folder for a while and it addresses your points as well.

========

Why a Hunger Games-Like Vision for the Internet is Wrong

Earlier this afternoon Brian Krebs, a well-respected security writer, published a story which, in part, calls for CloudFlare to censor the websites of a handful of our users [http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...]. These websites are known as "booter" sites. The sites claim to offer point-and-click DDoS services. The thrust of Brian's argument is that CloudFlare is a hypocrite for allowing these sites that advertise DDoS services to be protected by our network while, at the same time, offering as a core feature the ability to stop DDoS attacks.

Brian acknowledges that there's a bit more nuance to the argument. He understands that CloudFlare is not a hosting provider and that terminating any customer wouldn't make the content of the booter sites go away, it would just make them slower and more vulnerable to attack. He also acknowledges that no attack traffic actually originates from CloudFlare's network. His assumption, which we discussed at length before he published the article, is that if CloudFlare weren't in the equation then the booter sites would simply DDoS each other into oblivion.

Stop for a second and think about that: Brian is arguing for a Hunger Games-like vision of the Internet. It's the functional equivalent of if the police stopped prosecuting crimes committed against people they suspected to be criminals.

Brian is not the first person to make this argument and he won't be the last. A few weeks ago Kayne West's attorneys contacted CloudFlare insisting that we terminate protection for a customer they said was causing irreparable harm to their client: the parody crypto currency called Coinye. Ken Carter, our legal counsel, explained to Mr. West's lawyers that terminating the Coinye CloudFlare account wouldn't make it go away, it would just make it more vulnerable to attack. They thought that would be terrific. Ken respectfully disagreed.

CloudFlare's mission is to build a better Internet. Inherently there is content on our network that I find distasteful or even harmful. In the past, we've been called to task by other journalists [http://blog.cloudflare.com/cloudflare-and-free-speech] for allowing controversial websites to use our network. There is currently a campaign that has gathered over 22,000 signatures [http://www.change.org/petitions/matthew-prince-remove-chimpm...] for us to terminate the account of what I consider a horribly racist and distasteful website.

While I, personally, agree that the site the petition was started over is truly awful, I don't believe my personal opinion of what is good or bad content should be what governs what is allowed online. If CloudFlare succeeds, even in small part, at building a better Internet, inherently we must honor and respect one of the Internet's greatest qualities: that it is a network open to anyone.

Note that this isn't everyone's policy. Amazon, for instance, terminated Wikileak's account after political pressure [http://www.theguardian.com/technology/2010/dec/11/wikileaks-...]. More recently an article circulated that they were censoring books where people fantasized about having sex with dinosaurs [http://observationdeck.io9.com/amazon-now-at-war-with-dinosa...]. Other CDN providers are notorious for taking content offline at the first hint of pressure. We don't do that, even when the pressure comes from someone we truly respect like Brian. Fundamentally, we won't play the role of the Internet's morality cops. It's above our pay grade.

Booter sites, you may argue, are different. But the key question is where do you draw the line. If a site says you can push a button and launch an attack should we take that down? What about one that has a phone number you can call? Or gives you instructions on launching the attack yourself? CloudFlare is many things, but one thing we are not is the Internet cops.

Don't get me wrong, we don't believe in a lawless frontier. While we believe deeply in principles of due process and will push back against what we deem abusive legal requests [http://blog.cloudflare.com/fighting-back-responsibly], ultimately if ordered by a court through valid legal process we will comply. While booter sites may be successful at using us to protect their content from being knocked offline by a DDoS attack, they will not be successful at using us to hide from law enforcement if they are breaking the law.

Brian and I have known each other for almost a decade. He left the Washington Post and started Krebs On Security around the same time as we were launching CloudFlare. I actually tried to hire him back then. Thankfully he didn't accept the offer because he has become one of the leading security journalists writing anywhere today. He breaks important stories, which is something we need in the security space.

On this issue, I respect Brian's opinion but think he's ultimately wrong, That said, I have no problem with him fostering the debate. I think the discussion is hard, but it is healthy and important. To that end, if there are any large security or technology conferences that would like to host such a debate between me and Brian on stage, just let me know when and where and I'm in.

Re: Microsoft takes down No-IP.com domains

#119
post #114
post #109

Earlier quoted context omitted.

Hey pktgen: I'm new at CloudFlare, but I'd be really interested in chatting with you (or grabbing a beer) to hear if there's something we could do better. Contact info in my profile. I'll be at Defcon and HOPE too if that's easier. (Free speech vs. keeping the overall network safe is a hard decision. I think all pro-privacy and pro-liberty services have had to answer this question -- same thing happened with cypherpu…

Thanks, I'm also interested in having a chat with you about it, so I'll take you up on that offer in a bit. :)

(Offer is open to anyone who ever has security/privacy/etc. issues w.r.t. CloudFlare. I like talking to people about security and "Internet politics", either at conferences or at home.)

Re: Microsoft takes down No-IP.com domains

#120
post #72

Their status twitter is interesting, they aren't going into any details as to why their service stopped working, and they haven't made any statements about the accusations against them. https://twitter.com/NoIPStatus

No-ip's official response is here: https://www.noip.com/blog/2014/06/30/ips-formal-statement-mi...

Thanks, I checked their site and they had not posted a response when I commented.
Post reply on HN