So, did a court just order a domain to be taken down based on erroneous information from a private entity?
Sinkholed
31–40 of 135 posts
Re: Sinkholed
#32Re: Sinkholed
#33Do you guys know this stuff? If my domain started resolving to a new IP address, that would be just as unfamiliar to me, as the current address.
Should I ping my domain and write the results down?
Re: Sinkholed
#34Earlier quoted context omitted.
This is great news! Have you consulted a lawyer? It seems that the Shadowsecurity Foundation did act recklessly. But you'd need to prove monetary damages. But perhaps they'd settle to avoid the hassle. Edit: This is an admission of guilt: > He explained in his email that my domain name was sinkholed accidentally as part of their Avalanche operation.
Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…
Re: Sinkholed
#35Looking forward to hear from Shadowserver on a few points... • What led to the false positive. • What actions were taken to notify the domain owner about the actions being taken against them. • Why there was not a comment put into the Whois entry — or in some other obvious place — saying what had been done to the domain.
I have heard bad things about shadowserver in the past. Now I wonder how much other collateral damage they have done over the years.
Re: Sinkholed
#36> My website was missing. In fact, the domain name resolved to an IPv4 address I was unfamiliar with. Do you guys know this stuff? If my domain started resolving to a new IP address, that would be just as unfamiliar to me, as the current address. Should I ping my domain and write the results down?
But generally, the better your setup is documented, the better you can detect or diagnose when something goes awry.
Re: Sinkholed
#37Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…
the server is down it seems https://github.com/susam/susam.in/commit/91405150ff3f44fd094...
I have created a mirror of the blog on GitHub Pages for you. Visit https://susam.github.io/blog/sinkholed/ to read the mirrored blog post.
Re: Sinkholed
#38The server is down it seems https://github.com/susam/susam.in/commit/91405150ff3f44fd094...
Re: Sinkholed
#39Looking forward to hear from Shadowserver on a few points... • What led to the false positive. • What actions were taken to notify the domain owner about the actions being taken against them. • Why there was not a comment put into the Whois entry — or in some other obvious place — saying what had been done to the domain.
I want to know why law enforcement allows a private organization to seize private property based on some algorithm. I have heard bad things about shadowserver in the past. Now I wonder how much other collateral damage they have done over the years.
Re: Sinkholed
#40Is your domain just gone at that point?
Is it really that easy to lose a domain name...by someone doing an 'oopsie'?