Live data from Hacker News

How I hijacked the top-level domain of a sovereign state

labs.detectify.com

51–60 of 65 posts

Re: How I hijacked the top-level domain of a sovereign state

#51
post #3

It pisses me off that for something of this magnitude this guy will probably only be paid no more than a couple thousand dollars, if at all. He still has no response.

Why should he get anything at all? Does every "ethical hacker" need to hold his hand out for a reward? (Doesn't seem as ethical, then, does it?)

Re: How I hijacked the top-level domain of a sovereign state

#52
post #16

Earlier quoted context omitted.

The guy has no reason to expect a reward if the city has no bug bounty program. They could just sue him.

sue him for what? Discovering an exploit without disclosing the details?

It depends on the country, but in France for instance, there is a maximum sentence of one year in prison and a 15000€ fine just for "fraudulently accessing a data processing system", or trying to do so even if you don't succeed.

Re: How I hijacked the top-level domain of a sovereign state

#53
post #17

I had a gut feeling it will be '.cd' before clicking on the article and I was right. Dealing with the state entity (SCPT) that manages this TLD is quite a pain. It's so painful that I've given up managing all the .cd domains I used to own. .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously.

What’s to stop a TLD seller doubling their price? Is there any regulation against the practice?

Re: How I hijacked the top-level domain of a sovereign state

#54

> Although one of the contacts replied and delegated to their colleague, as of this writing, I haven’t received any follow-up confirmation that they fixed the issue. Wonder if that means they're investigating a "legal response" to his report? eg the old "shoot the messenger" approach :/

The Democratic Republic of the Congo does not have a lot of muscle to flex on the world stage.

Re: How I hijacked the top-level domain of a sovereign state

#55
post #29

Earlier quoted context omitted.

Quoting the article: >On January 7th, I reached out to the Administrative and Technical contacts listed for .cd on [ https://www.iana.org/domains/root/db/cd.html ].

A week after he registered the domain name. That's not the same thing as "before," which I believe the top comment in this thread was implying about what he should have done instead of what he did do.

Yes I spotted that “week” too.

Seems odd to wait a week to make contact if this was purely a white-hat exercise.

Re: How I hijacked the top-level domain of a sovereign state

#56
post #30

Earlier quoted context omitted.

> .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously. I bought one a few years ago for 80 Euros / year. Aren't there a lot of TLDs that are way more expensive?

The new crop of TLDs are really cheap. I bought a .download for like $2 a year or something. Not all are that cheap (I bought it as a throwaway for a project that relied on my having DNS control) but there are literally hundreds of them that are.

Only issue is I don't think there's anything preventing the price going sky-high in coming years, for most of these TLDs. For a throwaway it doesn't matter, but could really hurt if you start relying on one.

Re: How I hijacked the top-level domain of a sovereign state

#57
post #37
post #20

The most ethical move would have been to write to people listed at https://www.iana.org/domains/root/db/cd.html and put IANA in copy (likely ROOT-MGMT@IANA.ORG as listed in the public document: 24x7 Emergency Process Step-by-Step Description).

I feel it's problematic that whenever someone writes about an ethically tricky security vulnerability disclosure someone will come up with some variant of "but doing it a bit differently would've been more ethical". The reason I think this is problematic is that there are already more than enough people in the security community who will either say "fuck it, I'm not gonna bother with that" or "let's sell it to the hi…

I think this situation is like knowing a car crash is about to happen and then still waiting for it to happen though. Why not email someone to pay their bill?

Re: How I hijacked the top-level domain of a sovereign state

#58
post #52

Earlier quoted context omitted.

sue him for what? Discovering an exploit without disclosing the details?

It depends on the country, but in France for instance, there is a maximum sentence of one year in prison and a 15000€ fine just for "fraudulently accessing a data processing system", or trying to do so even if you don't succeed.

And they'll prove that without knowing what the exploit is?

Re: How I hijacked the top-level domain of a sovereign state

#59
post #44
post #42

Earlier quoted context omitted.

Kiribati (.ki) comes to mind - 900€ per year via ghandi.net or 1350€ at eurodns...

According to tld-list.com, the .th TLD is the most expensive ccTLD at $5000 and .ru is the cheapest at $2.99

Top-level .th (Thailand) is very expensive, but .co.th is reasonable ($50/yr).

Re: How I hijacked the top-level domain of a sovereign state

#60
post #37

Earlier quoted context omitted.

I feel it's problematic that whenever someone writes about an ethically tricky security vulnerability disclosure someone will come up with some variant of "but doing it a bit differently would've been more ethical". The reason I think this is problematic is that there are already more than enough people in the security community who will either say "fuck it, I'm not gonna bother with that" or "let's sell it to the hi…

I think this situation is like knowing a car crash is about to happen and then still waiting for it to happen though. Why not email someone to pay their bill?

It's worse than that. It's knowing a car crash will happen, wait until it does, and then writing a self promotional article about how awesome you are at predicting car crashes in an attempt to sell your car crash prediction services.
Post reply on HN