Live data from Hacker News

Taking control of all .io domains with a targeted registration

thehackerblog.com

141–150 of 258 posts

Re: Taking control of all .io domains with a targeted registration

#141

Earlier quoted context omitted.

I own an .IO domain. Do I deserve to have fake LetsEncrypt certs issued against me and my domain hijacked because some engineer forgot to remove some critical NS records or forgot to register some aliases? Responsible disclosure cat is responsible!

"Responsible disclosure" is a coercive term. It implies that it's irresponsible to do anything else. "Coordinated disclosure" is far better. That said, coordinated disclosure is the neighborly thing to do, but it's by no means a moral obligation. It would be perfectly fine for the author to tweet about it, for example.

No moral obligation? I don't think many people would agree with you on that.

If you are actively poking around at someone's home and you find an unlocked window, you don't think there is a moral obligation to inform the owner of the security issue? No moral issues if you then find a group of hoodlums down the street and announce that house 123 has an unlocked window?

I can see if you were just driving by and saw the window open, you don't really have any obligation (unless you plan to announce it publicly) but if you are actively seeking out security flaws in someone else's property, not disclosing it to the owner and then announcing it or worse, selling it to potentially bad actors seems morally reprehensible.

Re: Taking control of all .io domains with a targeted registration

#142

Earlier quoted context omitted.

We just used ai.google instead of google.ai as the canonical domain name for Google's AI initiative for precisely this reason. (We run .google and you can see the source code at https://nomulus.foo )

Hey, when are you guys gonna open .meme? Asking for a friend :-)

https://dickbutt.meme ?

Re: Taking control of all .io domains with a targeted registration

#143

Earlier quoted context omitted.

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

ccTLDs don't appear to be held to very high standards. For example the .AF top level domain (which is controlled by the government's ministry of communications) doesn't even have a working website, www.nic.af

Why you assume that nic.$cctld must exist?

Re: Taking control of all .io domains with a targeted registration

#144

Earlier quoted context omitted.

We just used ai.google instead of google.ai as the canonical domain name for Google's AI initiative for precisely this reason. (We run .google and you can see the source code at https://nomulus.foo )

Hey, when are you guys gonna open .meme? Asking for a friend :-)

I'd love to open it up tomorrow, but alas, I'm not the decision maker.

Re: Taking control of all .io domains with a targeted registration

#145

Earlier quoted context omitted.

ccTLDs don't appear to be held to very high standards. For example the .AF top level domain (which is controlled by the government's ministry of communications) doesn't even have a working website, www.nic.af

Why you assume that nic.$cctld must exist?

because that's the URL that the admins of .AF publish. It could be http://whatever.af if they wanted that, but if it had an httpd not showing any content, would be equally as suspect.

https://en.wikipedia.org/wiki/.af

http://www.wipo.int/amc/en/domains/cctld_db/codes/af.html

Re: Taking control of all .io domains with a targeted registration

#146

Wow, I don't think I would've even considered such an attack... DNSSEC, HSTS and Certificate Pinning would've made it more difficult to abuse this, but I guess it would've been pretty easy to get valid SSL certificates for all your favourite .io domains. Let's try to play malicious party here: Phase A: First set up a simple DNS forwarder playing by the rules and answering requests as we should (as to not get any unwa…

Thanks for this; as very-much-not-a-security guy, the alarm sounded by the original post was surprisingly clear, but fleshing out a plausible attack scenario like this really helps drive the point home while also teaching me a bit.

Re: Taking control of all .io domains with a targeted registration

#148

Earlier quoted context omitted.

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

ccTLDs don't appear to be held to very high standards. For example the .AF top level domain (which is controlled by the government's ministry of communications) doesn't even have a working website, www.nic.af

Shame: Afghanistan could really use a stream of teen marketing/hipster revenue for various domains that are x AF.

At least somebody grabbed the delightfully multilayered dope.af domain already...

Re: Taking control of all .io domains with a targeted registration

#149
post #141

Earlier quoted context omitted.

"Responsible disclosure" is a coercive term. It implies that it's irresponsible to do anything else. "Coordinated disclosure" is far better. That said, coordinated disclosure is the neighborly thing to do, but it's by no means a moral obligation. It would be perfectly fine for the author to tweet about it, for example.

No moral obligation? I don't think many people would agree with you on that. If you are actively poking around at someone's home and you find an unlocked window, you don't think there is a moral obligation to inform the owner of the security issue? No moral issues if you then find a group of hoodlums down the street and announce that house 123 has an unlocked window? I can see if you were just driving by and saw the…

This isn't equivalent to "If I leave my door unlocked..." scenarios. It's perfectly legal to register any .io name you want. You can't go poking around someone's house.

The situation is more analogous to discovering that a certain type of door offers no protection, even though it seems to lock. It's perfectly fine to tweet about that, regardless of how many people have that door. The blame lies on the company, not the messenger.

Re: Taking control of all .io domains with a targeted registration

#150
post #33

This is a huge screwup on the part of the people who run the 'root' of .IO, and their entire operation should be severely scrutinized by ICANN. In my opinion almost all of the 'weird' TLDs which are country codes that are actually operated by a third party commercial service are 95% spam and junk registrations. .TV is a good example. Technical screwups aside, the existence of .IO and the fact that it "belongs" to the…

Just so no one is misled: "original inhabitants" does not mean "indigenous peoples" with respect to the BIOT. The islands were not populated prior to late-18th Century European colonization. The depopulation was of post-colonial people.

How is that relevant to this discussion? They are original habitants, or are you contesting that?
Post reply on HN