Live data from Hacker News

It's Way Too Easy to Get a .gov Domain Name

krebsonsecurity.com

41–50 of 184 posts

Re: It's Way Too Easy to Get a .gov Domain Name

#41
Isn't the main issue that TLDs are a poor way of establishing trust?

Otherwiae does every company and government need to get specialized TLDs to prevent impersonation? Even then it only works is users know and always notice the domain.

EV certs are dead for good reason but nothing seems to have replaced them.

I guess the only option is to verify each site once and then bookmark it and always make sure it's https. But on the first visit, how do I know chase.com is Chase Bank?

Re: It's Way Too Easy to Get a .gov Domain Name

#42
I would also like to add signing up for an AWS Gov account was at least 12 months ago...a completely automated process where I was approved in no more than 15 mins. The account had a credit card but otherwise was 100% still in free tier mode, and in fact was being used by an open source team so it included ppl from around the world.

The CIA has stated multiple times in court documents (typically they have emerged in cases where the FBI attaché that all embassies have post-911 or someone similar is testifying) concerns about this and why they demanded and got “AWS secret”, a level higher than gov, that was opened in 2017.

Keep in mind though that many governments at state and local still use the TLD of “.us”. For instance Texas has widely used, until within the last year, “https:state.tx.us”. Many states have this legacy naming convention left over, and of course the restrictions are about as somewhat paper thin and avoided on .us as they are on .gov but more. There are changes in the works for this though.

More concerningly though is that the recent issue with the .org TLD clearly, and this can be proven in a straightforward manner, involves a group with unlimited funding by the People’s Liberation Army making this purchase. Ethol Capital is a joke of a firm. They’ve already sanitized the Google Search Results about them, which lol should be obvious when you realize they have taken out a Google Ad for “keypointsabout.org” when you Google them. The proof though is that if you look at court documents from 2015 you will find mention of a firm...SharkTech. Another front company that the PLA loans out from time to time to the Middle East and even as I recall Israel. Anyway as I’ve stated before in comments if you do the reverse Whois searches and dns subdomain enumeration you can find the trail back to No 31 Jin-rong Street. I’ve been asked before to write a post about this always elaborating and Christ I finally took out a domain https://blog.12security.com ... it has nothing on it but Jesus just look at the DNS records it took forever to get that DMARC record to the strictest level involving no 3rd parties and also to split that DKIM key across 3 txt records...which you have to do sometimes for the 2048 keys.

EDIT: forgot to mention there is obviously a connection between SharkTech and Ethol Capital. That will be proven in the blog and it is on me and my very tardy credibility to do it :) look at http://dcsmanage.com out of Los Angeles though if you want to get a head start, and if anyone claims that’s a real IT firm...

Re: It's Way Too Easy to Get a .gov Domain Name

#43

Earlier quoted context omitted.

An alarming amount of societal functionality depends on what effectively amounts to the honor system. This is especially true when it comes to any sort of gatekept specialty profession, like coroners for example. There was a great talk at DefCon about faking death: https://m.youtube.com/watch?v=9FdHq3WfJgs

I don't know if that is a solvable problem. Society is trust, and it always takes trusting someone to make any system work. People try to build trust-less systems all the time (like blockchains) but always run up against someplace where trust is required.

Trust, but verify. In the TFA case at least, it shouldn’t be that hard to call the office’s number (not the filled out Google Voice number of course, but there has to be a number published by/available through reliable parties) and confirm “is it really your office who’s registering the domain”? if (printed on official letterhead) { return authorized; } is beyond stupid.

Re: It's Way Too Easy to Get a .gov Domain Name

#44

Sounds to me like this researcher is going to be brought up on charges. Well deserved charges. We don’t know what he did with this domain before he contacted krebs. He very well could be covering his tracks and creating plausible deniability. You break the law, you go to jail. Simple as that. They aught to make an example out of him.

Surely everyone already knows what happens if you maliciously create a .gov domain? What would making an example of this security researcher do, other than have a chilling effect on the field as a whole?

Re: It's Way Too Easy to Get a .gov Domain Name

#46
post #17

> A review of the Top 10 most populous U.S. cities indicates only half of them have obtained .gov domains, including Chicago, Dallas, Phoenix, San Antonio, and San Diego. > Yes, you read that right: houston.gov, losangeles.gov, newyorkcity.gov, and philadelphia.gov are all still available. As is the .gov for San Jose, Calif., the economic, cultural and political center of Silicon Valley. A minor nit: Many of these ci…

> Some cities may also use a subdomain of their states domain, which may or may not be a .gov. This reminds me of how longwinded the domain hierarchy for .us originally was. In MN (not sure if it's the same for every state), city domains were "www.ci.cityname.mn.us". Then the school district's web site was "www.cityname.k12.mn.us". Not only was the order inconsistent (why not www.k12.cityname etc.?) but sometimes the…

In Norway, people employed by the local municipalities have email adresses that are literally of the style

  $firstname[.$middlename].$lastname@employee.$municipalityName.municipality.no  
where "employee" and "municipality" are literal strings (in Norwegian) and the others are variables. It's incredible, I've seen people with 50 character long email addresses.

Re: It's Way Too Easy to Get a .gov Domain Name

#47

Earlier quoted context omitted.

We have a TLD for NYC. It is, expectedly, not used for the city's official website. I guess people don't know how to visit TLDs in their browser. (I believe it would be "nyc.")

That's not how .nyc is used or is expected to be used. It's a top-level domain, not a dotless host name. Here's an example of how it's used: https://thecity.nyc/

> That's not how .nyc is used or is expected to be used. It's a top-level domain, not a dotless host name.

While it is prohibited by the ICANN policy [1], it is not strictly enforced so that there are multiple TLDs with A/AAAA records. They traditionally could be resolved with a trailing dot (thus it is not a dotless host name, that would have no dot), but nowadays many browsers refuse to resolve them without an explicit scheme. But they do still exist: try `http://pn./` for example.

[1] https://serverfault.com/a/907228

Re: It's Way Too Easy to Get a .gov Domain Name

#48

I would also like to add signing up for an AWS Gov account was at least 12 months ago...a completely automated process where I was approved in no more than 15 mins. The account had a credit card but otherwise was 100% still in free tier mode, and in fact was being used by an open source team so it included ppl from around the world. The CIA has stated multiple times in court documents (typically they have emerged in…

If all the above is reasonably easy to verify, you might like to email Krebs about it for wider dissemination. ;)

Re: It's Way Too Easy to Get a .gov Domain Name

#49
post #17

> A review of the Top 10 most populous U.S. cities indicates only half of them have obtained .gov domains, including Chicago, Dallas, Phoenix, San Antonio, and San Diego. > Yes, you read that right: houston.gov, losangeles.gov, newyorkcity.gov, and philadelphia.gov are all still available. As is the .gov for San Jose, Calif., the economic, cultural and political center of Silicon Valley. A minor nit: Many of these ci…

> Some cities may also use a subdomain of their states domain, which may or may not be a .gov. This reminds me of how longwinded the domain hierarchy for .us originally was. In MN (not sure if it's the same for every state), city domains were "www.ci.cityname.mn.us". Then the school district's web site was "www.cityname.k12.mn.us". Not only was the order inconsistent (why not www.k12.cityname etc.?) but sometimes the…

School districts are separate from municipalities and often will span multiple.

Re: It's Way Too Easy to Get a .gov Domain Name

#50

Earlier quoted context omitted.

or losangeles.ca.gov would be neat

LA gov doesn't belong to CA gov, federalism, etc.

> LA gov doesn't belong to CA gov, federalism, etc.

Federalism does not exist within states but between states and the federal government. Los Angeles (whether county or city) is an administrative subdivision of the State of California, not an separate sovereignty.

OTOH, Los Angeles isn't getting a .ca.gov domain because the state government doesn't want to dilute it's brand with local government websites, but that's about branding, not Federalism.

Post reply on HN