Live data from Hacker News

Zoom outage caused by accidental 'shutting down' of the zoom.us domain

status.zoom.us

281–290 of 324 posts

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#281
post #244

Noob here: could this issue have been worked around if you had a personal list of the IP addresses that the domain resolved to?

Most DNS issues can, yes. Your hosts file is going to be thick though, and a pain to keep up to date ;P

> Your hosts file is going to be thick though, and a pain to keep up to date

I'm guessing you already know, but for the others: This is precisely what the DNS protocol was created for.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#282
This kind of possibility is why Fastmail purchased fastmail.com and migrated away from our old 'fastmail.fm' domain. .fm was cool, but we ran into a couple of outages on the .fm servers meaning we went offline. No such issues since we've been on .com.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#283
post #85

That seriously devalues MarkMonitor's services. MarkMonitor claims to be a "an ICANN-accredited registrar and recognized industry leader since 1999". The whole point of paying for MarkMonitor is that they're an expensive service for valuable domains and are not allowed to screw up. GoDaddy should not be involved here at all.

> The whole point of paying for MarkMonitor is that they're an expensive service for valuable domains A while ago and, out of curiosity, I did a Whois Lookup to see what big tech companies are using as their domain registrar and found that Microsoft, Google, Amazon, Tesla, Netflix and Shopify are all using MarkMonitor. On the other hand Apple uses "Nom-iq Ltd. dba COM LAUDE", Meta (and its children) uses RegistrarSaf…

That’s interesting, Apple used to use CSC, which is the “other” big corporate registrar, competitor to MarkMonitor.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#284
post #79

Earlier quoted context omitted.

Whatever happens is going to set some really important precedent for sure.

I think '.su' is already that precedent, since it had many active domains, recently had active registration, and ICANN has announced plans to phase it out. https://en.wikipedia.org/wiki/.su See also '.yu' and friends, which have already been deleted.

How many domains are we talking though, and how many .io are there? Genuine question since I have no idea.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#285
post #206

Earlier quoted context omitted.

The Chagossians are not by any meaningful standards indigenous. The land was uninhabited when George Washington was rebelling against the British. If the Chagossians are indigenous so are old stock white Americans. And Mauritius have treated the Chagossians like dirt for decades, with no signs of that changing. None of this is to deny the Chagossians were extremely ill treated by the British, but the idea that the Ma…

I have some sympathy for your position, but I'll add that the prevailing moral opinion seems to be "whoever got there first is the rightful owner". Of course you have to allow for armchair ethnologists not being particularly good at distinguishing between similar groups and later revisionism. A lot of Pacific islands territories have complicated histories like this (e.g. Hawaii, New Zealand), but the focus usually en…

Absolutely. For example, the Maoris are not the original indigenous. What happened to them you may ask? They became literal dinner for the Maoris. This has happened elsewhere too. True original indigenous are rare.

The thing with the island of Diego Garcia is quite strange and I strongly suspect there is corruption involved. The UK wishes to divest itself? Instead of holding an auction where the rest of the planet can bid on purchasing the territory, the UK decided that Mauritius would take it (who doesn't really want it) and to entice them, the UK is going to PAY Mauritius to take the territory and leave the base alone. The amount is £90 million annually, adjusted for inflation for 99 years.

This is a lot of money, why not just NOT turn it over and not have to give away £90 million a year for a century? So, it begs the question.. is someone from the UK side benefiting from this no-bid deal?

Give the island to me, and I won't charge the UK to have the base.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#286
To try to convince my employer at the time to drop Zoom, I decided to see how many security vulns I could find in 2-3 hours.

Found 12 confirmed bugs in that window using only binwalk and osint.

The worst was that I noticed the zoom.us godaddy account password reset email address was the personal gmail account of Eric S Yuan, the CEO.

So, I tried to do a password reset on his gmail account. No 2FA, and only needed to answer two reset questions. Hometown, and phone number. Got those from public data and got my reset link, and thus, the ability to control the zoom.us domain name.

They were unable to find a single English speaking security team member to explain these bugs to, and it took them 3 months to confirm them and pay me $800 in bug bounties, total, for all 12 bugs.

The one bright side is this did convince my employer to drop them.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#287

Godaddy is such an incompetent organisation. Should not be allowed to administer anything of importance.

Who knew a company who ran ads with women dressed like Hooters waitresses would turn out to be a fucking clowncar. I mean what are the odds?

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#288
post #48

Amazing how many service outages are caused by doing business with GoDaddy.

Also after dividing the number of outages by the number of customers? I'm not a customer (wouldn't buy my domain overseas) and have no solid opinion on GoDaddy besides that I hate the name. I hear the horror stories also. I'm just wondering if this is a knee-jerk reaction

Here's something you all need to learn about site (or for that matter, tool) reliability:

Nobody gives a shit about how many good outcomes between incidents there are. They care about how many good hours happen between incidents, and they care how big the incidents are.

So if you make a tool that your coworkers use 5 times as much as the old process, that tool better make things at least 6x more stable or people will start talking about how the process fails 'all the time'.

"all the time", as near as I've been able to figure out, after people have been yelling at me, my team, or a team I'm privy to, is not "every day". No, all the time just means that it happens every couple of weeks and one time happened twice in one day, twice in consecutive days, or with two customers in rapid succession. Usually the day they're screaming about.

So if you're doing that thing every day all day long, where you used to do it rarely, but you made some progress on making it more frequent, nobody cares that it's every 100th run that fails, when it used to be every 10th. They just see the drama has gotten more frequent (and nowhere near as frequent as their narrative says, but you've already lost that argument)

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#289
post #252

Earlier quoted context omitted.

They did buy zoom.com from someone in 2019, though, for $2M. https://domainnamewire.com/2019/03/23/did-zoom-pay-2-million...

Interesting. I used to buy Zoom modems in the 80s-90s ( https://en.wikipedia.org/wiki/Zoom_Telephonics ), but apparently they have nothing to do with either of the other two Zoom companies mentioned here. I had occasionally wondered but never looked into it until now.

Back in the day, wasn't it either Zoom or Hayes?

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#290
post #286

To try to convince my employer at the time to drop Zoom, I decided to see how many security vulns I could find in 2-3 hours. Found 12 confirmed bugs in that window using only binwalk and osint. The worst was that I noticed the zoom.us godaddy account password reset email address was the personal gmail account of Eric S Yuan, the CEO. So, I tried to do a password reset on his gmail account. No 2FA, and only needed to…

How long ago was this? A few years ago they were hiring aggressively for security team members in the US, including a dedicated fuzzing team. I’m guessing this was from early on when Zoom was just getting popular?
Post reply on HN