Live data from Hacker News

Taking control of all .io domains with a targeted registration

thehackerblog.com

251–258 of 258 posts

Re: Taking control of all .io domains with a targeted registration

#251

Earlier quoted context omitted.

The best way to protect yourself against this kind of attack is DNSSEC. Plain and simple.

I dispute this, even though this seems like the one case where we're talking about an attack that actually lines up with what DNSSEC actually does. The reason is, what we're talking about is a massive misconfiguration. It's not an elaborate technical spoofing attack that takes advantage of the weakness of the underlying DNS. The mistake the .IO team made is just as easy to make in DNSSEC as it is with vanilla DNS.

But if the attacker is unable to sign DNS responses, and you're validating those responses, then you're not going to have a bad time.

I don't really understand your argument. I'm talking specifics and you seem to be talking about some hypothetical.

Re: Taking control of all .io domains with a targeted registration

#252

Earlier quoted context omitted.

I dispute this, even though this seems like the one case where we're talking about an attack that actually lines up with what DNSSEC actually does. The reason is, what we're talking about is a massive misconfiguration. It's not an elaborate technical spoofing attack that takes advantage of the weakness of the underlying DNS. The mistake the .IO team made is just as easy to make in DNSSEC as it is with vanilla DNS.

But if the attacker is unable to sign DNS responses, and you're validating those responses, then you're not going to have a bad time. I don't really understand your argument. I'm talking specifics and you seem to be talking about some hypothetical.

The underlying "vulnerability" here is misconfiguration. DNSSEC doesn't defend against misconfiguration. That's the simple point I'm making.

Re: Taking control of all .io domains with a targeted registration

#253

Earlier quoted context omitted.

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

Besides the old .org, what better options are there for software projects?

.build ?

Re: Taking control of all .io domains with a targeted registration

#254
post #163

Earlier quoted context omitted.

Are you being deliberately obtuse? It's a pretty important distinction that these were not some native tribesmen with millennia of ancestral history tied up in the lands.

If a man shows up with a gun to run me off my land, it doesn't matter whether it was my father that bought it or my grandfather or my great-grandfather. What's important is the forcible dispropriation itself. Cases like this just make a mockery of the Lockean natural rights theory of property.

I made no comment on if it was right or not, I simply maintain that there is an important distinction there.

Re: Taking control of all .io domains with a targeted registration

#255
post #163

Earlier quoted context omitted.

Are you being deliberately obtuse? It's a pretty important distinction that these were not some native tribesmen with millennia of ancestral history tied up in the lands.

No its not.

it's

Re: Taking control of all .io domains with a targeted registration

#256
post #255

Earlier quoted context omitted.

No its not.

it's

Rather than correcting grammar, why don't you respond to the numerous rebuttals of your point of view elsewhere in this thread ?

You says its important but don't explain why, and empathise that you place no "normative judgement" on it.

Normative judgment doesn't make sense btw, judgement adhering to the norm - eh wat ? I think you meant moral/ethical.

Re: Taking control of all .io domains with a targeted registration

#257
post #227

Earlier quoted context omitted.

Frankly, yes, a little bit. You're choosing to run your website/infrastructure/etc with a dependency on a sketchy service with no oversight (the ccTLD system in general, but .io in particular). Unless you suffer for this choice, the market for provider competence will be broken.

That nobody had any idea was sketchy or un-oversighten until recently. It was not a choice to run their website/infrastructure/etc on sketchy services at all.

No. People who care about internet-scale infrastructural issues have known about these issues for a very long time. However, most people who utilize (and depend on) these services have not taken the time to understand how they work.

Re: Taking control of all .io domains with a targeted registration

#258
post #227

Earlier quoted context omitted.

That nobody had any idea was sketchy or un-oversighten until recently. It was not a choice to run their website/infrastructure/etc on sketchy services at all.

No. People who care about internet-scale infrastructural issues have known about these issues for a very long time. However, most people who utilize (and depend on) these services have not taken the time to understand how they work.

Because it's a simple transaction. I pay someone for a domain, I get said domain.

Jimmy Throwawaysite shouldn't have to take the time to understand how DNS works above knowing how to set DNS records, the oversight should come from above. If ICANN wants to let anyone with a couple hundred thou run a TLD they should be making sure that entity can technically manage the TLD.

Post reply on HN