Live data from Hacker News

Microsoft takes down No-IP.com domains

blogs.technet.com

251–260 of 261 posts

Re: Microsoft takes down No-IP.com domains

#252

Earlier quoted context omitted.

Linux solved this problem almost twenty years ago. You have a package manager that does not contain malware and does contain 95% of the software any user would install on a regular basis, and you make the process of installing software outside of the package manager possible but not trivial . You download a binary and it doesn't have the execute bit set, and you don't get any kind of friendly thing that pops up to as…

Package manager and repositories are not completely foolproof. http://www.zdnet.com/blog/hardware/how-much-more-malware-is-... If Linux were to get as popular as Windows, the problem is going to way worse. Also, there's lot of Android malware that's installed from outside the app store, typically for piracy reasons which is another big malware vector on Windows.

> Package manager and repositories are not completely foolproof.

Nothing is completely foolproof.

http://www.theguardian.com/technology/appsblog/2013/aug/19/i...

> If Linux were to get as popular as Windows, the problem is going to way worse.

Everybody says this but it doesn't make any sense. Are the repositories going to get more malware when there are more people and funding available to notice and report it?

> Also, there's lot of Android malware that's installed from outside the app store, typically for piracy reasons which is another big malware vector on Windows.

All the more reason why it wouldn't happen on Linux. Nobody really pirates LibreOffice or gcc.

Re: Microsoft takes down No-IP.com domains

#253

Earlier quoted context omitted.

But that's an awful analogy and frankly you should be ashamed for even trying to paint it in that light. NOIP did nothing illegal whatsoever, their only "crime" was that they didn't do enough about malware distribution to keep Microsoft happy- which last I heard wasn't illegal. To use your car wash analogy, it's more like the car wash unknowingly washed the car of a drug trafficker and then was essentially put out of…

I am uneasy about this situation, but the car wash in question is more like the car painting shop in Grand Theft Auto. Even if painting cars is a legitimate activity, when 75% of your customers are trying to mask illegal activity you should be doing some due diligence to ensure that you're not enabling illegal activity. I'm not totally okay with what happened here, but I'm confident that it was not a "oops, sorry, we…

75% is a HUGE overstatement, No-IP allegedly has ~4 million active accounts. Of those 4 million, 3rd party security firms claimed ~12k of them were involved in the distribution of these two bits of malware, No-IP said the number was more like 2k. If those numbers are correct then you're talking thousandths of a percentile being the reason for this domain seizure.

Re: Microsoft takes down No-IP.com domains

#254

Earlier quoted context omitted.

That's the very first option everyone turns off because it gets in the way.

It's the first option everyone you know turns off, but don't mistake anyone who even knows that Hacker News exists with a typical computer user.

Good point.

Re: Microsoft takes down No-IP.com domains

#256

Earlier quoted context omitted.

Which ever way you cut it technically speaking Microsoft runs the biggest botnet because they have control all the computers running Windows upgrade, and if they can't shut them down, they might as well fix them. Whether you like it or not for better or worse a botnet is an economic resource whose value is not lost on Microsoft and sooner or later they are going to come up with a wheeze to exploit them.

You are missing the point. He said why he downvoted you and you replied with a general rationalization on why he should agree with you, when that's entirely NOT the point. You'll catch more flies with honey than you will with vinegar. We probably all agree with you in some fashion, just not the way you put it. And, just in case YOU can't figure it out, the blaming statements you are making are due to the use of 'you'…

I read the statement on the Microsoft blog, before coming to see the comments and that blog statement IS smug, self preening, self-congratulary tripe created by a lawyer and a company who want to ingratiate themselves with government for whatever agenda they have in mind.

That blog entry is not targeted at computer users, it is targeted at the government.

Re: Microsoft takes down No-IP.com domains

#257

> On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. Something about this bothers me. So the courts granted MS the rights to essentially take over No-IP's DNS in order to "identify" ... "bad traffic?" The implications of this are...…

This is the singlemost monstrously misrepresentational and dubious thing I have seen any tech company do in my 20 years experience as a tech. It also profoundly concerns us all that this type of judgment can be made by our government without any of warning or consent by the people. Millions of users lost their home security and surveillance systems instantly due to this ill-advised decision. We should hold the federal government and Microsoft directly responsible for any losses that happened today, and any that happen in the future as a result of any such action. We might as well go ahead with emotional damages for causing the concern in the first place.

Re: Microsoft takes down No-IP.com domains

#258
When are a group of no-ip customers going to file a class action suit against Microsoft?

Just because an ignorant judge gave them access to some no-ip domains did not give them the right bite more then they could che and fsck it up.

The whole thing is just bizarre, WTF were they trying to accomplish? ie they took over the business of providing name service to over 4 million hosts, way bigger more than most large service providers with the intention of traffic to and from the C & C servers, or identify which of the computers were infected and inform their owners?

Why didn't they simply set up some monitoring devices and get the judges or the FBI to compel no-ip to allow them to plug it into their network so they could monitor what they wanted without disrupting the service?

If the no-ip owners were directly involved in the scam then why didn't the hand the evidence to the law enforcement authorities and let them carry on from there?

Re: Microsoft takes down No-IP.com domains

#259
post #191

Earlier quoted context omitted.

It doesn't serve No-IP's market, because No-IP is for frequently changing IP addresses. Namecoin charges for each record change, to my knowledge.

How often are updates necessary? It costs 0.8 cents to update a namecoin domain.

One of the main reasons to use a dynamic DNS service is because your IP address changes frequently. A service that requires you to pay for each record update is a non-starter for that use case.

Re: Microsoft takes down No-IP.com domains

#260

> On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. Something about this bothers me. So the courts granted MS the rights to essentially take over No-IP's DNS in order to "identify" ... "bad traffic?" The implications of this are...…

Don't use .com, .net, .org, .edu; use domain names in your own sovereignty! Microsoft would have it much harder to get no-ip.ru or no-ip.zh (granted, a little easier grabbing no-ip.fr).
Post reply on HN