Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

181–190 of 261 posts

Re: Microsoft takes down No-IP.com domains

#181

So let me get this straight. Microsoft got a court order to route all of another entity's DNS traffic to their servers. Giving them the ability to route a metric crap-ton of private traffic through their data centers. For "security". I call shenanigans. I'm also assuming this is why my no-ip domain disappeared this morning, leaving me with no access to my home servers. Perhaps the linux on my servers is considered ma…

Not exactly. > allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. According to MSFT, they are only looking at known "bad" traffic. You can take their word for it... or not.

How do they know that some data is "bad" before looking at it?

And I'm asking only because I know the answer - that it's impossible, they are looking at the entire traffic and (officially) deciding if it's "bad" afterwards.

Re: Microsoft takes down No-IP.com domains

#182
post #108

Earlier quoted context omitted.

My own comments about your company are based on what I described in https://news.ycombinator.com/item?id=7880514 . Would you care to respond to my statements in that post?

Sure. Pardon the copy-and-paste reply, but it's a perfect opportunity for me to publish up a draft blog post I wrote half a year ago in anticipation of a Brian Krebs post on the topic of Booter sites. Brian's article didn't turn out nasty enough to warrant a response, but I've had the post sitting around in by drafts folder for a while and it addresses your points as well. ======== Why a Hunger Games-Like Vision for…

What makes a site hosting malware per se harmful, and how can you consider malware per se harmful while booters avoid being classified identically? Malware is illegal and obviously a detriment to the internet, as are booter services. Perhaps you're just willing to deal with malware so you don't end up in the same boat as No-IP did here.

Booter services are so incredibly common that the police aren't going waste their time on them, especially since once the cops get the real IP from your convenient obfuscation service, it's likely hosted in China, Russia, or some other country where no action will be taken.

Re: Microsoft takes down No-IP.com domains

#183
post #134

Earlier quoted context omitted.

No-ip was complicit in the illegal activity. If you use a car wash that is also laundering money, your legitimate need for a clean car is not a defense against shutting the business down.

But that's an awful analogy and frankly you should be ashamed for even trying to paint it in that light. NOIP did nothing illegal whatsoever, their only "crime" was that they didn't do enough about malware distribution to keep Microsoft happy- which last I heard wasn't illegal. To use your car wash analogy, it's more like the car wash unknowingly washed the car of a drug trafficker and then was essentially put out of…

I am uneasy about this situation, but the car wash in question is more like the car painting shop in Grand Theft Auto. Even if painting cars is a legitimate activity, when 75% of your customers are trying to mask illegal activity you should be doing some due diligence to ensure that you're not enabling illegal activity.

I'm not totally okay with what happened here, but I'm confident that it was not a "oops, sorry, we'll ban that botnet" situation. no-ip's primary use case is botnets, and they do have a responsibility to minimize botnet use. They can't claim ignorance given the widespread use.

Re: Microsoft takes down No-IP.com domains

#184
What I don't understand and haven't seen anyone ask is, why Microsoft?

I mean, obviously some shady legal tactics are at work here, but why did Microsoft got to control those domains instead of, Mozilla for example? or Google? even more so, why wasn't control transferred to ICE for example?

Not saying it's a better alternative or even that I agree with it, but it's very VERY unsettling (and I'm not even American) that a corporation can basically say "dibs on this" backed up by a court order!

I would understand if the procedure went some more like, MS cries wolf, a court order is issued and a gov agency takes temporary control. At least it's "the government" doing the policing (even if guided by a corporation or whatever).

What's next now? Comcast and Verizon sending their IP Police to arrest you because they have a log showing piracy was downloaded at an IP owned by you? And they get to seize your stuff and now your house is a Comcast/Verizon store?

Wtf is this? It's so unreal.

Edit: typo

Re: Microsoft takes down No-IP.com domains

#187
If the way to prevent malware is by blocking domains (which only prevent a few of them), with the same logic another great solution would be blocking Microsoft's operating systems (which would prevent most of them).

Ubuntu should ask the government the same power and show how little malware Ubuntu users has and how much Windows users has to suffer.

Re: Microsoft takes down No-IP.com domains

#188

Earlier quoted context omitted.

Yeah but what fraction of home users are going to consider that prompt as opposed to just clicking on the OK button? I've noticed a lot of software will include that in its install steps.

You now actually need to specifically open the application with a right click to even have the option to open it, simply double clicking just says it's unsafe and closes. I think that safeguard probably has saved significant numbers of people from unsavory malware.

That's the very first option everyone turns off because it gets in the way.

Re: Microsoft takes down No-IP.com domains

#189
post #3

FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).

At CloudFlare, we have a Trust & Safety team dedicated to dealing with the abuse of our network. We sit in front of more than 2 million sites. The vast majority of them are not controversial (the site you're reading this on, for instance), but some are not. The majority of the abuse requests we receive are DMCA requests, but we get other reports as well. Dealing with these requests is a hard problem because a large n…

Trust & Safety maybe, but it's still impossible to use CloudFlare in Russia, due to harboring some drug-selling websites at your services. ISPs ban them by IP, and taking whole subnetworks of websites that reside on the same IP down with them too.

As much as I love your services, it's not possible to use them here, and ministry of communication even issued a recomendation not to use your services due to your unresponsiveness about takedown requests.

Re: Microsoft takes down No-IP.com domains

#190
post #20

Has I understood this correctly? Microsoft, a private company, has been granted the right to filter all dns traffic, and choose what will bee forward to this other company, No-IP. No-IP will so bee allowed to run there service for the remaining customers Microsoft approves? Is this common practices in the us legal system? Would it work like this in the offline world also? If my neighbor sometimes had loud parties tha…

>If my neighbor sometimes had loud parties that bothered me, could I be granted the right to stand in front of his door What if they were bothering 7.4 million people and inconveniencing many more? And then didn't show up in court in spite of summons? The police or courts will take that far more seriously.

Hotmail.com and outlook.com are regularly used to send out malware. I know this because I have received some personally every couple of months for the last 4-5 years.

It's highly likely that over the years, more that 7.4 million spam emails have been sent through Microsoft's systems.

Under the bar set by this judge, I should be able to apply for, and receive, ownership of outlook.com based on the fact that Microsoft doesn't always rush to comply with emails that I send them.

It won't happen, of course, because Microsoft has more money than I do (and because it's a fucking stupid idea).

This is an appalling remedy and I hope Microsoft and the Judge in question face serious repercussions for it.

Post reply on HN