What I find interesting here is the interplay and mix between private, public, and governmental concerns. In the physical space, in the states you're free to walk out into the public park, put on a hat saying something atrocious like "I hate cats!" and peacefully petition your fellow citizens to destroy all cats or something silly. When we moved to printed distribution, there was still a clear bit of guidance; as lon…
Sinkholed
61–70 of 135 posts
Re: Sinkholed
#62Really wish they'd pick another name: it's really hard to convince clients to take them seriously and let me choose them. If I had a dollar for every time someone insisted on GoDaddy... :-(
Re: Sinkholed
#63I don't find this surprising at all. This can happen in any scenario where a special shortcut has been added to get around a standard process (where standard process usually involves some human review and judgement). I imagine that in most cases, the shortcuts were created simply to speed up a process where some (perceived) harm is significant, and a rapid change would alleviate this harm. This would allow some enfor…
> This particular situation doesn't bother me as much as the "Google/Apple/FB suddenly closed all my accounts" scenario This situation bothers me so much more. Google/Apple/FB are private corporations. If they continue to adopt user hostile practices it is possible for some other company to out compete them in the more or less free market of internet services. TLDs are government controlled entities administering sca…
This is the history of society, of marginalization of the disabled or other outgroups. It's hard work to overcome that, often through force (Civil War) or the threat thereof (Americans with Disabilities Act).
Re: Sinkholed
#64Earlier quoted context omitted.
Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…
Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet. However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal. I get that many think that Americans are hug…
No, really they aren't. There are a lot of lawyers in America, but most never set foot in a courtroom. They mostly just do "important" paperwork and give advice on following rules.
I know a lawyer who last month wanted to sue someone in federal court, only to discover that Joe Random lawyer is not allowed to file lawsuits in federal court; he had no idea that there was such a thing as a federal trial bar and that membership requires significant experience in federal court under the supervision of a member. He spent a week trying to find anyone that would be willing to file his lawsuit but none would. So he hired a law firm to sue in state court - that is much easier I guess. Anyway, the point is that he is a good lawyer with years of experience doing the lawyer thing, but no experience with litigation. That's normal.
Re: Sinkholed
#65Someone less technical would likely have no idea what happened to their domain. An individual relying on their web presence for income could be massively impacted by something like this. There really does not seem to be a clear way for someone to a) know what the problem is, and b) get it resolved quickly.
Sure, if you don't pay attention to the care of your domain, it can break in incomprehensible ways, just as if you don't pay attention to the care of your car, it can break in incomprehensible ways.
Re: Sinkholed
#66Interesting. I noticed that the blog post mentions the Nymaim malware family. I read about Susam's case when it hit Twitter the other day and might have even followed a link to his URL. Then a few days later got an email from my ISP Virgin Media claiming they'd detected Nymain on my home network. I run macOS only and as far as I can tell Nymaim is Windows only. Still, I ran an malware scan on my Macbooks and nothing…
Although my server wasn't infected, it had connected to a Shadowserver sinkhole.
While it's good that there are folks who work to sinkhole botnets, the next step of accusing others of being infected based of what the sinkhole sees needs more care. I'm disappointed that, evidently, my expression of these concerns to the German authorities three years ago hasn't lead to a substantial change at the Shadowserver end.
As can be seen from your case (and mine), you can get blamed even if the software at your end of the connection wasn't the botnet software. Considering how a basic premise of the Web is that it's safe to dereference a URL and everyone runs software that does so (Web browsers!), it's a bad idea that Shadowserver doesn't require a narrower indicator of compromise.
There'd be less chance of folks weaponising this system against bystanders by framing them as botnet-infected if the Shadowserver Foundation sinkhole required the other end of the connection to exhibit more specific hallmarks of the botnet software.
Re: Sinkholed
#67tldr; Collateral damage from law enforcement taking down a botnet, resolved reasonably fast.
Re: Sinkholed
#68Re: Sinkholed
#69What I find interesting here is the interplay and mix between private, public, and governmental concerns. In the physical space, in the states you're free to walk out into the public park, put on a hat saying something atrocious like "I hate cats!" and peacefully petition your fellow citizens to destroy all cats or something silly. When we moved to printed distribution, there was still a clear bit of guidance; as lon…
Blaming the dictator doesn't solve the problem. Sure, you could try to overthrow a dictator, but you can also try to fix a system, by talking to any of the people involved in it (or if there are no people involved, try to modify the system yourself, since there's no one to stop you).
Re: Sinkholed
#70I don't find this surprising at all. This can happen in any scenario where a special shortcut has been added to get around a standard process (where standard process usually involves some human review and judgement). I imagine that in most cases, the shortcuts were created simply to speed up a process where some (perceived) harm is significant, and a rapid change would alleviate this harm. This would allow some enfor…
This is not really ok. There must be a clear contact point for the affected people (not only namecheap). Also it was very bad on the transparency front. If they are taking down a domain, the operation is not secret anymore, so they can tell why. No telling you is bullshit. That being a German operation, I would expect much better on the democratic handling of it. And it being an international operation, India should…
By analogy: Google has necessarily-impersonal relationships with millions of Gmail users; but rather more personal relationships with far fewer GSuite and Google Cloud organization owners. If you were an employee of a company that uses either of those, and your service was breaking, you’d ask your GSuite organization-owner (i.e. the person Google has a personal relationship with) to contact them for you.