Live data from Hacker News

Zoom outage caused by accidental 'shutting down' of the zoom.us domain

status.zoom.us

311–320 of 324 posts

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#311
post #286

To try to convince my employer at the time to drop Zoom, I decided to see how many security vulns I could find in 2-3 hours. Found 12 confirmed bugs in that window using only binwalk and osint. The worst was that I noticed the zoom.us godaddy account password reset email address was the personal gmail account of Eric S Yuan, the CEO. So, I tried to do a password reset on his gmail account. No 2FA, and only needed to…

You're admitting to committing a felony?

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#312
post #286

To try to convince my employer at the time to drop Zoom, I decided to see how many security vulns I could find in 2-3 hours. Found 12 confirmed bugs in that window using only binwalk and osint. The worst was that I noticed the zoom.us godaddy account password reset email address was the personal gmail account of Eric S Yuan, the CEO. So, I tried to do a password reset on his gmail account. No 2FA, and only needed to…

You're admitting to committing a felony?

White hat hacking is fine.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#313
post #208

Earlier quoted context omitted.

gTLDs are regulated by ICANN. As much as an organization can achieve to be a global multistakeholder group, at least the intention is to be global. ICANN have a mostly hand-off approach to ccTDLs. The intention is that each country decide on their own regulations and management when it comes to their country code specific domains. .nl is a very special case, and it is true that the Dutch government was not involved.…

IIRC one of the Balkan countries physically stole the DNS servers of another one's ccTLD.

After the breakup of Yugoslavia in 1992 there was a dispute between Slovenia and FYR Serbia and Montenegro over the .yu domain that lasted until 1994 when Jon Postel intervened.

As you might notice from the dates and names, this was very early in the history of TLDs.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#314

Earlier quoted context omitted.

You're admitting to committing a felony?

White hat hacking is fine.

If you password reset my personal Gmail account I will sic the FBI on your tail without a second thought. Not cool.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#315
post #206

Earlier quoted context omitted.

I have some sympathy for your position, but I'll add that the prevailing moral opinion seems to be "whoever got there first is the rightful owner". Of course you have to allow for armchair ethnologists not being particularly good at distinguishing between similar groups and later revisionism. A lot of Pacific islands territories have complicated histories like this (e.g. Hawaii, New Zealand), but the focus usually en…

Absolutely. For example, the Maoris are not the original indigenous. What happened to them you may ask? They became literal dinner for the Maoris. This has happened elsewhere too. True original indigenous are rare. The thing with the island of Diego Garcia is quite strange and I strongly suspect there is corruption involved. The UK wishes to divest itself? Instead of holding an auction where the rest of the planet ca…

Māori were the first settlers of NZ. There’s no record of any earlier population being “dinner” for anyone.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#316

Earlier quoted context omitted.

White hat hacking is fine.

If you password reset my personal Gmail account I will sic the FBI on your tail without a second thought. Not cool.

You can try, but they will not do anything unless I do actual harm.

https://www.justice.gov/archives/opa/pr/department-justice-a...

If you do not want your gmail password reset, I recommend hardware 2FA.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#317

Earlier quoted context omitted.

White hat hacking is fine.

If you password reset my personal Gmail account I will sic the FBI on your tail without a second thought. Not cool.

The story says that the password reset link was received, which proves the vulnerability without actually denying service, causing loss, etc. As an analogy, the attacker found a key to a door but did not proceed to open the door.

It doesn't say the password reset link was used to change the password, which would deprive the account owner access and grant unauthorized access which of course would be illegal.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#318

Earlier quoted context omitted.

> The registrar for .us (GoDaddy) is in fact the “root dns for .us” “root DNS” has a very specific meaning, and you’ve misused it again. Root DNS means ‘.’ and only ‘.’ There is no other “root”. That’s why it’s called “root” to be unambiguous. In fact, in recent history, the root name servers use their own domain for convenient forward DNS resolution: ‘root-servers.net’ GoDaddy doesn’t run this either... Surprise, su…

The whole point of a tree is that every node is the root of its subtree.

Exactly!

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#319

Earlier quoted context omitted.

It actually didn’t help at all. Read the part quoted again, OP specifically indicated .us, not “root zone”. The registrar for .us (GoDaddy) is in fact the “root dns for .us”

The original clarification was perfectly fine to and arguing about the correction is reply-all-unsubscribe line noise. There was confusion, it error corrected, move on.

Yet you chose to reply-all-unsubscribe line noise further. Maybe take your own advice and move on bro.

Re: Zoom outage caused by accidental 'shutting down' of the zoom.us domain

#320

Earlier quoted context omitted.

Are there any actual recent examples of this? The major examples I've always heard are solidly in the 20th century. It's not like Google has had any problem holding their trademark.

Kleenex and Xerox were both (somewhat) recently in danger of loosing theirs. They both pulled pretty big campaigns to un-verb their trademarks. Google still has a bunch of other products that people are familiar with, so they are in less danger of loosing theirs right now, but give it some time (like 50 years, not 10) and it may happen, especially if they get broken up for being a monopoly. (Which has been mentioned)

I'm usually a big proponent of longer-term corporate thinking, but deciding your name around problems you might have five decades after becoming a household name is a little much.
Post reply on HN