Live data from Hacker News

Tell HN: U.S. gov't blacklisted all DNS entries pointing to Linode machines

news.ycombinator.com

21–27 of 27 posts

Re: Tell HN: U.S. gov't blacklisted all DNS entries pointing to Linode machines

#22
post #20

Earlier quoted context omitted.

I wouldn't use any provider that took an active interest in monitoring my traffic or examining my VPS.

It's not about that, it's about figuring out who you are before you sign up.

How? By adding a "Are you a terrorist?" checkbox in signup form? Doing full CIA scan for all new users? Maybe they should require web serving license issued by govt, like they do for guns?

Re: Tell HN: U.S. gov't blacklisted all DNS entries pointing to Linode machines

#24
post #22
post #20

Earlier quoted context omitted.

It's not about that, it's about figuring out who you are before you sign up.

How? By adding a "Are you a terrorist?" checkbox in signup form? Doing full CIA scan for all new users? Maybe they should require web serving license issued by govt, like they do for guns?

There are ways that are less intrusive, but still somewhat effective. Security is mostly about probabilities. The more circles you remove from the venn diagram, the lower the probability of problems.

So if you remove everyone from China, sure, you remove a lot of fine customers, but you also remove a huge swath of the internet crime rings. Require a US based address. Email the people and have a conversation. Require a phone call.

It's the same as renting out an apartment, If you start renting your apartments to criminals, pretty soon, all you'll have is criminals.

Re: Tell HN: U.S. gov't blacklisted all DNS entries pointing to Linode machines

#25
post #3

Heard that the top level domain linode.com was black holed due to its association with malicious activity [...] Reading this sentence, reminded me of Google using Linode when that incident happened with Chinese hackers.

http://blog.linode.com/2010/01/15/linode-and-the-google-cybe... "No Linodes were involved in malicious activity related to this event. In fact, it was Google itself that chose to use Linode to aid in their investigation of the attacks"

http://www.us-cert.gov/cas/techalerts/TA10-055A.html suggests otherwise.

Re: Tell HN: U.S. gov't blacklisted all DNS entries pointing to Linode machines

#26
post #25

Earlier quoted context omitted.

http://blog.linode.com/2010/01/15/linode-and-the-google-cybe... "No Linodes were involved in malicious activity related to this event. In fact, it was Google itself that chose to use Linode to aid in their investigation of the attacks"

http://www.us-cert.gov/cas/techalerts/TA10-055A.html suggests otherwise.

So, McAfee identifies a single node as "associated" with the incident: li107-40[dot]members[dot]linode[dot]com. And Linode has a post which specifically references a single node being associated but under Google's control and not malicious control at all times.

Doesn't appear to me that there's any contradiction. There is no evidence that a Linode was used for anything malicious. There is evidence that a Linode was used.

Re: Tell HN: U.S. gov't blacklisted all DNS entries pointing to Linode machines

#27
post #26
post #25

Earlier quoted context omitted.

http://www.us-cert.gov/cas/techalerts/TA10-055A.html suggests otherwise.

So, McAfee identifies a single node as "associated" with the incident: li107-40[dot]members[dot]linode[dot]com. And Linode has a post which specifically references a single node being associated but under Google's control and not malicious control at all times. Doesn't appear to me that there's any contradiction. There is no evidence that a Linode was used for anything malicious . There is evidence that a Linode was…

From the cert page:

"the following malicious domains were identified"

Post reply on HN