Live data from Hacker News

Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

techweekeurope.co.uk

31–36 of 36 posts

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#31

Earlier quoted context omitted.

>They're a pretty easy target as the architecture of Windows is incredibly complicated and they're playing plug the holes rather than designing it properly to start with. For ref, I know the NT kernel, win32 and CLR inside out and no longer would I poke it with a stick. Not sure what you mean by that. Does Linux have any protections beyond Windows to stop malware? Why does Android have a malware problem? This is the…

1) Linux and other unixes were created with the idea of privilege separation and permission baked in. Windows had to add it later, while keeping compatibility 2) Linux has a variety of kernels and libraries versions across its base, making it difficult to exploit it uniformly 3) MS is indeed capable of making secure OSes, I don't deny it, but you should not use Xbox, Windows Phone and RT as examples, since all three…

1) IIRC, The Windows NT family had more granular level permissions than Linux. Granted before XP Windows was quite insecure, as I said in my original comment

2) Still we do see a lot of bugs and exploits that affect large swathes of Linux machines.

3) My entire point is that popular OSes that are used by nontechnical users that allow third party installs

4) Even OS X got a lot of burn for sanboxing apps and making third party apps difficult to install. They tried difficult UAC with Vista and it didn't go so well.

There isn't much stopping Linux malware in repos if the Linux desktop gets more popular. http://www.zdnet.com/blog/hardware/how-much-more-malware-is-...

Heck, even kernel.org was rooted and they still haven't revealed what happened. Not to mention other distros which were also compromised at some point.

5) http://www.pcworld.com/article/2099421/report-malwareinfecte...

6) Which ones? (apart from RT ARM machines that were a total flop in the marketplace and are like iPads)

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#32
post #26

Earlier quoted context omitted.

> Not sure what you mean by that. Does Linux have any protections beyond Windows to stop malware? Why does Android have a malware problem? This is the key question that I'd like to hear the answer to. People often claim Linux/OS X/et al are more secure but they struggle to explain WHY. What technical mechanism is in place in those systems that is not in place in [current] Windows? A few years ago you could definitely…

Ubuntu ships with AppArmor enabled. Fedora ships with SELinux. It's been that way for a long time. Other distributions like Arch come with packages for other frameworks, including grsecurity. But I think the primary "technical mechanism" that makes Linux more secure is the fact that users install software from distribution repositories, rather than from the web. The repos are basically impenetrable since packages are…

>I've never heard of there being malware in a major distribution

Not much to stop malware if desktop linux becomes more popular.

http://www.zdnet.com/blog/hardware/how-much-more-malware-is-...

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#33

This is even more ridiculous than I thought, given TFA -- Microsoft could have just asked them to change the IP associated with the relevant accounts, disable update for them and/or hand over access to those accounts. To quote myself from the other thread, the approach they did take is more than slightly bizarre: "There are serious problems with this, firstly that it's technically impossible to implement effectively,…

While I do think Microsoft's approach here is pretty insane, your proposed solution would not have helped at all: >Microsoft could have just asked them to change the IP associated with the relevant accounts, disable update for them and/or hand over access to those accounts. The botnet operators are using this service because of how transient it is. They likely have hundreds of accounts, each with thousands of domains…

I think it would, from Microsoft's technet article [1] -- the reason they went this route seems to be because they're having detecting these two worms (they're polymorphic) -- so they went for decapitation: kill the C&C.

Besides, knocking out no-ip still doesn't "fix" anything - there're a billion and one easy ways around it - C&C lists in alternate dyndns providers, 3rd party namespaces,Tor based C&C, pastebins, public/anonymous forums, hidden in bit-torrent blockchain etc etc etc

Heck, pushing an update to every Windows machine that simply resolved *.no-ip.org to 127.0.0.1 would be better than this. At least then folks that wanted to use it would have an easy recourse.

[1] http://blogs.technet.com/b/mmpc/archive/2014/02/11/msrt-febr...

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#34

Earlier quoted context omitted.

1) Linux and other unixes were created with the idea of privilege separation and permission baked in. Windows had to add it later, while keeping compatibility 2) Linux has a variety of kernels and libraries versions across its base, making it difficult to exploit it uniformly 3) MS is indeed capable of making secure OSes, I don't deny it, but you should not use Xbox, Windows Phone and RT as examples, since all three…

1) IIRC, The Windows NT family had more granular level permissions than Linux. Granted before XP Windows was quite insecure, as I said in my original comment 2) Still we do see a lot of bugs and exploits that affect large swathes of Linux machines. 3) My entire point is that popular OSes that are used by nontechnical users that allow third party installs 4) Even OS X got a lot of burn for sanboxing apps and making th…

I agree in general with all your point, apart from 4 and 5.

Malware in linux repositories is "practically" impossible. Software is most of the times peer reviewed and patched in different ways by different distros. And if a particular software becomes more popular it also comes under scrutiny by more people that want to change the source to add their own features. All the packages are checksummed and repositories have cryptographic keys to establish authenticity.

Of course bugs and security vulnerabilities exist, but the same applies to other OSes as well. And I do understand that UAC is obnoxious for users, but they didn't care about creating problems for legitimate users with the no-ip case since it was posing danger.

That android report makes two assumption: a very wide definition or malware (also installing java should be considered a malware because toolbar), and the fact that a malware doesn't usually last more than a day before being removed automatically.

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#35

Earlier quoted context omitted.

While I do think Microsoft's approach here is pretty insane, your proposed solution would not have helped at all: >Microsoft could have just asked them to change the IP associated with the relevant accounts, disable update for them and/or hand over access to those accounts. The botnet operators are using this service because of how transient it is. They likely have hundreds of accounts, each with thousands of domains…

I think it would, from Microsoft's technet article [1] -- the reason they went this route seems to be because they're having detecting these two worms (they're polymorphic) -- so they went for decapitation: kill the C&C. Besides, knocking out no-ip still doesn't "fix" anything - there're a billion and one easy ways around it - C&C lists in alternate dyndns providers, 3rd party namespaces,Tor based C&C, pastebins, pub…

>Heck, pushing an update to every Windows machine that simply resolved *.no-ip.org to 127.0.0.1 would be better than this.

...I don't know if you're joking or not, but that would've been far worse.

At least in this case, Microsoft is attempting to make an effort to preserve all non-malicious domains.

Re: Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider

#36
post #4

I get really irritated with companies that put absolutely no effort into cleaning up their services on their own. When nearly 20,000 of No-IP's accounts are being used for malicious purposes, crying about how Microsoft didn't give them any warning just makes them seem incompetent. There was another article recently on HN about some free tunneling service whose creator tried to automate account shutdowns whenever his…

How many of Microsoft's customers are being used for malicious purposes? Am I as an ISP allowed to summarily disconnect all Microsoft customers from my network?
Post reply on HN