Live data from Hacker News

Sinkholed

susam.in

131–135 of 135 posts

Re: Sinkholed

#131

Earlier quoted context omitted.

> Do I go with a domain I own? This one, it’s this one. Losing your domain tends to require human action: from someone forgot to pay the renewal to someone messed up and sinkholed it because they thought it was a C2 server. But because humans are in the system there tend to be layers of processes that try to prevent you from getting to this state and can get your world back to normal if you do. Gmail offers nothing l…

Although if your using your own email address, be prepared for emails you send to end up in junk.

That's if you use your own _server_. You don't have to point your DNS records to a server you own.

Re: Sinkholed

#132
post #21

Interesting. I noticed that the blog post mentions the Nymaim malware family. I read about Susam's case when it hit Twitter the other day and might have even followed a link to his URL. Then a few days later got an email from my ISP Virgin Media claiming they'd detected Nymain on my home network. I run macOS only and as far as I can tell Nymaim is Windows only. Still, I ran an malware scan on my Macbooks and nothing…

I would say it should be concerning to you that your ISP is actually watching what DNS addresses you resolve. I'd either suggest using secure DNS or using your own DNS server or some DNS server not owned by your ISP.

Re: Sinkholed

#133

How is one supposed to get this resolved if the CEO OF NAMECHEAP doesn't see your tweet to get involved? Is your domain just gone at that point? Is it really that easy to lose a domain name...by someone doing an 'oopsie'?

The idea would be that the support ticket with namecheap should be enough. Though I doubt it would be, for the average person.

Doubt is an understatement. lol

Re: Sinkholed

#134

Earlier quoted context omitted.

This is something that can absolutely be decentralized. Problems aside namecoin shows that it can be done. The entire domain name system needs to be overhauled, central certificate authorities need to be avoided. The internet in general is infrastructure, and protocols that are increasingly controlled by governments and organizations in bed with governments.

That also has its downsides though. For starters, it would no longer be possible to take down domains used for controlling botnets.

That's a similar nonsense as is the broad-scale surveilence to prevent terrorism. Botnets can already build a decentralized store of IP addresses, bypassing public DNS completely. Centralization makes some people, organizations or state just too much powerful.

Re: Sinkholed

#135
post #124

Earlier quoted context omitted.

The GNU Name System https://gnunet.org/en/use.html already has a distributed DNS-like system built out.

This does not look like something my grandma would use.

I don't think she has to. As long as your ISPs run GNS themselves, and offer you DNS via DHCP, then you can just forego the ISP DNS server and drop in your own local GNS. Mount .com and the other TLDs you want from direct from ISP off their pubkey, and overwrite the TLDs you don't care much for.
Post reply on HN