Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

141–150 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#141

Banning his account was totally unjustified since he approached them first with the issue. A less ethical person could have tried to make money or sold this off on the back market. People like him should be rewarded not have their accounts banned. For all we know he just saved DO a lot of headache in sorting this issue had it gone wrong. I really wish the response from DO on this was different.

> The main reason I did not reach out with the theory instead of the proof-of-concept was because I believed that it would be ignored due to lack of evidence (as is my experience with past disclosures)

I think this was his mistake.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#142
post #133

This same thing happens with CloudFlare & is being actively exploited. We reported it to them within the last two weeks and we were told that it's expected behaviour and that they weren't going to do anything about it. I asked them to, at the absolute least, send an email notification to the prior-CloudFlare owner letting them know that the domain "your CF account used to control is now being controlled by a new CF a…

> according to CF, it's not an issue...?! Definitely not the case. I work at CloudFlare, not in DNS or on this code, and have mentioned this incident in the all-company chat. There is a healthy conversation happening there and it turns out a fix was already in the works for the underlying issue. adanto6840 has supplied the support ticket number (thank you), and this specific incident is also being reviewed.

If only it was possible for them to get proper support outside of hoping an engineer sees their HN comment!

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#143
post #97

Earlier quoted context omitted.

And the ban reminds me of the recent case, where DO invalidated the credits of many people within of 2 weeks with a simple TOS change. I had to pay 5€ to even be able to add the 100$ credit from the GitHub students pack to my account (for "verification purposes"), and then they – illegally – delete it just like that? (I never got to use any of it) DO is one of the shadiest hosters I know.

On one hand, the policy change was made a year prior. On the other hand, we didn't communicate it as well as we should have. I apologize for that. I consider myself as much responsible as anyone else on that. If you ever want that account credit back, please let me know. I'm an easy find on Google, or you can open a support ticket anytime. For what it's worth, we posted on our blog about just this. https://www.digita…

I was affected by this - I lost some credit that I had remaining from the Github Student Pack due to it expiring with relatively short notice. If I open a support ticket, will I be able to ask to get that credit back?

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#144
post #127

Earlier quoted context omitted.

You don't need to make a deletion request, you can deactivate your account from your account settings, and it offers to delete everything for you. That's what I did when I wanted to close my account recently (I wasn't using the droplets I had, and liked my other VPS better anyway.)

>and liked my other VPS better anyway Which ones?

Ramnode. Their prices are good and their support is phenomenal. I've always gotten replies to my tickets within minutes, often from Nick Adams himself (Ramnode's CEO.)

A few examples:

- Whenever a new release of OpenBSD comes out, I send a request for them to add the new install media, and they make it available ASAP.

- I switched from OpenVZ to KVM after a couple months and having paid for a year of the OpenVZ service, and they put my remaining credit toward the new service.

- I completely hosed my machine one time and had them restore from backup. Took a while because they wanted to be double-extra-sure of what I wanted, but it was overall a quick and painless process.

I don't know how things will change as they grow, but right now they just seem like a good company, run by people who care about the quality of their product and the satisfaction of their customers.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#145
post #110

This same thing happens with CloudFlare & is being actively exploited. We reported it to them within the last two weeks and we were told that it's expected behaviour and that they weren't going to do anything about it. I asked them to, at the absolute least, send an email notification to the prior-CloudFlare owner letting them know that the domain "your CF account used to control is now being controlled by a new CF a…

> according to CF, it's not an issue...?! According to CloudFlare, they are are a reverse proxy, and they are not responsible for anything. This has been their response to every issue that I've tried to bring up with them over any channel, including here on HN. CloudFlare just doesn't care.

not at all accurate. If you find something abusive or malicious report it: cloudflare.com/abuse -- every report filed there is reviewed by a human.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#146

Something similar happened to me a few months ago with Cloudflare. I set up a new domain to use Cloudflare's nameservers but did not immediately get around to setting it up on the admin panel. By the time I wanted to add the domain, someone else had already grabbed it and set up some sort of spam page. Took a few emails to Cloudflare support to resolve this one. They also didn't seem to care much about the security i…

"They also didn't seem to care much about the security implications when I questioned them about it." no one ever said that was the case.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#147

Earlier quoted context omitted.

How does making a domain that does not resolve suddenly resolve negatively impact a user, again? The domain could not have possibly been operational before the circumstances that brought about this scenario, and there is no legitimate traffic they could possibly be receiving. DigitalOcean could certainly improve authentication here but there are dozens of authoritative services that do not, and this is not a new prob…

What was his/her flagged follow up if you don't mind me asking?

dang would ask me not to import the content to the discussion, and in this case I agree. Suffice to say it was a snarky comment directed at you, deleted after being flagged.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#148

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

Meh, it was just mild incompetence. I expect the only providers (hell, large companies in general) who never responded this way are the ones who haven't been around long enough.

[deleted]

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#149
post #97

Earlier quoted context omitted.

And the ban reminds me of the recent case, where DO invalidated the credits of many people within of 2 weeks with a simple TOS change. I had to pay 5€ to even be able to add the 100$ credit from the GitHub students pack to my account (for "verification purposes"), and then they – illegally – delete it just like that? (I never got to use any of it) DO is one of the shadiest hosters I know.

They changed their ToS a year before, you got a notice to review them. What's illegal about revoking promotional credit? https://www.digitalocean.com/company/blog/details-on-expirin...

No, they changed their ToS in March, and invalidated all coupons older than April of the year before by April.

That left me just 2 weeks.

And what’s illegal is that in Germany, promotional credit or coupons given without a time limit is valid for at least 3 years.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#150

Earlier quoted context omitted.

Not quite, only one person can, so if you add first, it's yours. Typically they have you add the domain and then you switch the DNS and in that configuration you wouldn't be vulnerable at all.

It sounds like this only impacts people that weren't using their domain, eh? If I leave my NS pointing to some random provider and delete my account, I'm sorta handing off control... At first I thought it was an issue where DO was using their own DNS servers but letting you add domains. So if Microsoft.com wasn't registered, you'd register it then all DO customer traffic would get your DNS records. Some telcos have t…

Yes, security of number porting is too lax. My number was once ported by a telco (accidentally in this case). They did call me and I had to confirm that I would get a new SIM card and which size I needed, but since I was expecting a new SIM card from the very same telco I didn't understand that they were in fact porting my number. They forgot to say that.

Luckily I was able to get my number back, after many calls to customer support (they managed to undo the porting when I wanted to check how it was going) and a couple of weeks of waiting.

Post reply on HN