Live data from Hacker News

It's Way Too Easy to Get a .gov Domain Name

krebsonsecurity.com

171–180 of 184 posts

Re: It's Way Too Easy to Get a .gov Domain Name

#172

Earlier quoted context omitted.

> That's not how .nyc is used or is expected to be used. It's a top-level domain, not a dotless host name. While it is prohibited by the ICANN policy [1], it is not strictly enforced so that there are multiple TLDs with A/AAAA records. They traditionally could be resolved with a trailing dot (thus it is not a dotless host name, that would have no dot), but nowadays many browsers refuse to resolve them without an expl…

http://ai./ is a better example.

both pn and ai are giving me DNS errors in chrome on ubuntu.

Re: It's Way Too Easy to Get a .gov Domain Name

#174
post #43

Earlier quoted context omitted.

I don't know if that is a solvable problem. Society is trust, and it always takes trusting someone to make any system work. People try to build trust-less systems all the time (like blockchains) but always run up against someplace where trust is required.

Trust, but verify. In the TFA case at least, it shouldn’t be that hard to call the office’s number (not the filled out Google Voice number of course, but there has to be a number published by/available through reliable parties) and confirm “is it really your office who’s registering the domain”? if (printed on official letterhead) { return authorized; } is beyond stupid.

Right, but then you are trusting that number list... how is that generated? Can I call someone up and get that number changed?

Re: It's Way Too Easy to Get a .gov Domain Name

#175

> “I used a fake Google Voice number and fake Gmail address,” said the source, who asked to remain anonymous for this story but who said he did it mainly as a thought experiment. I don't think "thought experiment" applies to actually carrying out what you were thinking about.

>Technically, what my source did was wire fraud (obtaining something of value via the Internet/telephone/fax through false pretenses); had he done it through the U.S. mail, he could be facing mail fraud charges if caught. Yeah, I'm pretty confident that a true thought experiment can't lead to wire fraud charges. "Security research" seems like a more popular, and reasonable, umbrella to hide behind.

Re: It's Way Too Easy to Get a .gov Domain Name

#176
post #76

Does anybody know why the USA hogs the toplevel domain? It's not the only government in the world. It would seem more just to make it more like .com than .edu.

In addition to all the siblings, government isn't always spelled with 'gov' so it would be useful to the subset of countries where those letters make sense. Compared to say Mexico with http://gob.mx .

Re: It's Way Too Easy to Get a .gov Domain Name

#177

Earlier quoted context omitted.

This scheme only makes economic sense if you neglect to factor in the cost of being sent to federal prison for many years.

Isn't that part of the cost with all the schemes?

Some schemes create paper trails in federal agencies, others do not. In America you can acquire rifles without filling out any paperwork at all, let alone lying to a federal agency on paper. Converting those rifles to automatics can, again, be done without lying on any paperwork in a variety of ways (some more effective than others.) Somebody up to no good would be better served by low-profile acquisition schemes that fly under the radar of regulators, rather than getting their attention then trying to actively deceive them.

All schemes may be risky, but they're not all equally risky. Some schemes are more risky than others. However all of these schemes probably have negative expected payouts if you factor in the FBI being pretty damn good at their jobs. Whatever crime you hypothetically plan on committing with automatic rifles will almost certainly not have a positive payoff when you include the cost of getting busted, and you almost certainly will eventually get busted. When smart people decide to be criminals, they choose white collar crime (arrest rates are very low, and sentencing for those captured is frequently lax.) Violent crime is for idiots who fail to rationally consider the likely consequences of their actions.

Re: It's Way Too Easy to Get a .gov Domain Name

#178

Earlier quoted context omitted.

I would assume the LA City one was chosen because it’s still shorter than Los Angeles and it also differentiates from LA County. Much of the LA metropolitan area is within the county limits but not part of the city of LA.

The issue with lacity.org is the TLD, which creates confusion amongst the general public. Legitimate domains for government entities should ALL be on .gov, which should be rigorously controlled. Then I can tell my family to trust any .gov site, and assume that anything else is fraudulent. lacity.org undermines this.

You'd be better off telling your family to distrust .gov sites by default.

Re: It's Way Too Easy to Get a .gov Domain Name

#179

Earlier quoted context omitted.

Isn't that part of the cost with all the schemes?

Some schemes create paper trails in federal agencies, others do not. In America you can acquire rifles without filling out any paperwork at all, let alone lying to a federal agency on paper. Converting those rifles to automatics can, again, be done without lying on any paperwork in a variety of ways (some more effective than others.) Somebody up to no good would be better served by low-profile acquisition schemes tha…

Sure, but the point is that federal prison is always a factor in illegal arms, regardless of how you acquire them.

With modern machining and 3D printing, "ghost" guns can just be manufactured from scratch. There are even companies that sell legal components, blueprints and raw material meant to be easily tweaked and machined into a complete weapon.

Re: It's Way Too Easy to Get a .gov Domain Name

#180

Earlier quoted context omitted.

Your .pn link doesn't work for me without www part. At least for https://www.fi/ the case is that someone registered "www" as the domain name in the early days.

Hmm, I guess the current browsers simply don't like such domain and automatically put www. At the very least, the Google DNS gives the following: ai. 209.59.119.34 cm. 195.24.205.60 dk. 193.163.102.58 gg. 87.117.196.80 je. 87.117.196.80 pn. 80.68.93.100 tk. 217.119.57.22 uz. 91.212.89.8 ws. 64.70.19.33 But I agree that these domains are now out of luck, given that browsers no longer even remotely support them.

I see that the Vatican has given up. Long ago, http://va/ was it. No other name under va existed. Netscape Navigator was able to navigate to that part of the net.

It really did make sense for such a tiny place.

Post reply on HN