Live data from Hacker News

Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

news.ycombinator.com

141–148 of 148 posts

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#142
post #123
post #42

Earlier quoted context omitted.

Well in my case (and a lot of other people), 192.168.1.1 is the local address of my home router. So if I go to microsoft.com I have a 1 in 7 chance of getting my home router instead (if I ignore the certificate warning). Other random breakage will happen depending on what that local address is assigned to for you. In theory this could be leveraged for hacking, but I think that would require setup in advance.

yep. If a hacker can somehow control 192.168.1.1 or 192.168.0.1 they get access to your microsoft.com cookies at least. I'm sure there are more microsoft specific ways to leverage this too (e.g. data/updates hosted on microsoft.com that misuse HTTPS as a poor man's authentication. The curl | sh crowd are especially susceptible to this problem.)

They would still need the private key to a https cert that your browser considers valid.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#144
post #39

Wait wait wait wait. Bunny.net accidentally changed their DNS to 127.0.0.1 and took a bunch of their CDN users down today too. Coincidence? Weird day.

Probably just developers trying to meet deliveries/targets before the holidays.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#145
post #27
post #15

Through a series of connections I know a guy that knows a guy that works at Microsoft that was made aware and the changes have been reverted. Give 'er 30 minutes TTL ;)

This is my favorite HN comment of 2023.

HN is a wormhole through which you can connect pretty much anyone in tech industry.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#148
post #139
post #82

Earlier quoted context omitted.

Only one of those is authoritative. All of the authoritative servers have dropped it. Microsoft has fixed the issue.

Yea, sure, but that's like saying "company X stopped selling poison, it's Shop Y's fault that they're still selling it". Nope. This is still Microsoft's fault while non-auth servers update.

First we wanted to see Microsoft update the authoritative nameservers, then move on to monitoring propagation. Conflating the two makes it difficult to monitor whether Microsoft actually fixed it correctly this time, as they appear to have screwed up their first attempt.

I wasn't attempting to address blame since I figured that was obvious enough.

Post reply on HN