Live data from Hacker News

How I hijacked the top-level domain of a sovereign state

labs.detectify.com

31–40 of 65 posts

Re: How I hijacked the top-level domain of a sovereign state

#31
post #16

Earlier quoted context omitted.

The guy has no reason to expect a reward if the city has no bug bounty program. They could just sue him.

What are their damages? He's not required to disclose their security vulnerabilities to them. It's his work not theirs.

I think lovasoa is pointing out what could happen in real-life, not 'what should happen morally/ethically/etc'.

Re: How I hijacked the top-level domain of a sovereign state

#32
post #20

The most ethical move would have been to write to people listed at https://www.iana.org/domains/root/db/cd.html and put IANA in copy (likely ROOT-MGMT@IANA.ORG as listed in the public document: 24x7 Emergency Process Step-by-Step Description).

I assume you mean that he should have done that when he noticed the domain was pending renewal? (edited to "renewal", not deletion)

He definitely acted decently overall (and did reach out to the people you mention afterwards). But I can empathize with the author for simply thinking "pending renewal? alright whatever" and later on "pending DELETE? shit I should make sure they're OK!".

I guess there's always what's best in hindsight and what's actually done.

Re: How I hijacked the top-level domain of a sovereign state

#33
post #30
post #17

I had a gut feeling it will be '.cd' before clicking on the article and I was right. Dealing with the state entity (SCPT) that manages this TLD is quite a pain. It's so painful that I've given up managing all the .cd domains I used to own. .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously.

> .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously. I bought one a few years ago for 80 Euros / year. Aren't there a lot of TLDs that are way more expensive?

Not too many ccTLDs. AI comes to mind (Anguilla, expensive for obvious reasons), but it’s still cheaper than .CD.

Many gTLDs are expensive due to their target demographics or to dissuade bad actors (eg .auto, .bank).

Re: How I hijacked the top-level domain of a sovereign state

#34
post #30
post #17

I had a gut feeling it will be '.cd' before clicking on the article and I was right. Dealing with the state entity (SCPT) that manages this TLD is quite a pain. It's so painful that I've given up managing all the .cd domains I used to own. .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously.

> .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously. I bought one a few years ago for 80 Euros / year. Aren't there a lot of TLDs that are way more expensive?

The new crop of TLDs are really cheap. I bought a .download for like $2 a year or something. Not all are that cheap (I bought it as a throwaway for a project that relied on my having DNS control) but there are literally hundreds of them that are.

Re: How I hijacked the top-level domain of a sovereign state

#35
post #20

The most ethical move would have been to write to people listed at https://www.iana.org/domains/root/db/cd.html and put IANA in copy (likely ROOT-MGMT@IANA.ORG as listed in the public document: 24x7 Emergency Process Step-by-Step Description).

That would be the most ethical, sure. But this was a faster and safer course of action. And it wasn’t unethical.

Re: How I hijacked the top-level domain of a sovereign state

#36
post #32
post #20

The most ethical move would have been to write to people listed at https://www.iana.org/domains/root/db/cd.html and put IANA in copy (likely ROOT-MGMT@IANA.ORG as listed in the public document: 24x7 Emergency Process Step-by-Step Description).

I assume you mean that he should have done that when he noticed the domain was pending renewal? (edited to "renewal", not deletion) He definitely acted decently overall (and did reach out to the people you mention afterwards). But I can empathize with the author for simply thinking "pending renewal? alright whatever" and later on "pending DELETE? shit I should make sure they're OK!". I guess there's always what's bes…

[deleted]

Re: How I hijacked the top-level domain of a sovereign state

#37
post #20

The most ethical move would have been to write to people listed at https://www.iana.org/domains/root/db/cd.html and put IANA in copy (likely ROOT-MGMT@IANA.ORG as listed in the public document: 24x7 Emergency Process Step-by-Step Description).

I feel it's problematic that whenever someone writes about an ethically tricky security vulnerability disclosure someone will come up with some variant of "but doing it a bit differently would've been more ethical".

The reason I think this is problematic is that there are already more than enough people in the security community who will either say "fuck it, I'm not gonna bother with that" or "let's sell it to the highest bidder".

We should appreciate more when people are trying to do the right thing and worry more about the people doing clearly the wrong thing and less about whether the people doing overall the right thing did it perfectly.

Re: How I hijacked the top-level domain of a sovereign state

#38
post #7
post #3

It pisses me off that for something of this magnitude this guy will probably only be paid no more than a couple thousand dollars, if at all. He still has no response.

DR Congo is one of the poorest countries in the world. GDP/cap is $457 a year. If he does get a few thousand that is more than one worker earns in 10 years. https://en.wikipedia.org/wiki/List_of_countries_by_GDP_(nomi...

What on earth does that have to do with anything here? I probably make more as a software developer than some Americans make in 10 years.

Re: How I hijacked the top-level domain of a sovereign state

#39
post #10
post #7

Earlier quoted context omitted.

DR Congo is one of the poorest countries in the world. GDP/cap is $457 a year. If he does get a few thousand that is more than one worker earns in 10 years. https://en.wikipedia.org/wiki/List_of_countries_by_GDP_(nomi...

Understandable stance, but the damage he was capable of causing was probably millions of dollars worth. So yeah, a few thousand bucks as a thank you is reasonable.

> the damage he was capable of causing was probably millions of dollars

That applies to most of us.

It also doesn’t change the fact that there is very little money available in the DRC.

Re: How I hijacked the top-level domain of a sovereign state

#40
post #16
post #11

Earlier quoted context omitted.

I work for a few a cities in Europe, and happen to know one of the cities had a site with an sql injection issue. An external person found and let the city know but didn't want to reveal the specifics before getting money. The city has no bounty program and for some people in the City it came across as if the guy was distorting them. The guy probably felt like he didn't get money for his work. Probably both have a po…

The guy has no reason to expect a reward if the city has no bug bounty program. They could just sue him.

sue him for what? Discovering an exploit without disclosing the details?
Post reply on HN