[flagged]
Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
91–100 of 148 posts
Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
#92Earlier quoted context omitted.
This isn’t something that I think should be diluted. If it’s that simple for a stray record to be included in the dns round robin it could have been bad if it was an external ip with a machine setup by a phisherman especially since control of a domain is all you need to get an ssl cert now. Couple this with the fact that it’s Microsoft, one of the most relied on companies in our computer world, this is pretty darn ho…
Microsoft also has some of the phishiest looking domains when you are redirected around the O365 cloud.
Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
#93Earlier quoted context omitted.
This isn’t something that I think should be diluted. If it’s that simple for a stray record to be included in the dns round robin it could have been bad if it was an external ip with a machine setup by a phisherman especially since control of a domain is all you need to get an ssl cert now. Couple this with the fact that it’s Microsoft, one of the most relied on companies in our computer world, this is pretty darn ho…
For all this to work you need to control the domain. Is that easier than simply breaking into their systems and owning their servers?
Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
#94Earlier quoted context omitted.
This isn’t something that I think should be diluted. If it’s that simple for a stray record to be included in the dns round robin it could have been bad if it was an external ip with a machine setup by a phisherman especially since control of a domain is all you need to get an ssl cert now. Couple this with the fact that it’s Microsoft, one of the most relied on companies in our computer world, this is pretty darn ho…
For all this to work you need to control the domain. Is that easier than simply breaking into their systems and owning their servers?
> it could have been bad if it was an external ip with a machine setup by a phisherman
I.e. one of the IPs for microsoft.com belongs to $phisher, which means they control (a subset of the traffic going to) the domain. They can't add CNAME records for certificate validation, but LetsEncrypt for example offers HTTP-based validation.
Not sure how Microsoft sets up their certificate pinning, it might not be quite that easy.
Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
#95Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
#96Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
#97Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
#98How the hell did that pass any sort of responsible review process at Microsoft? Now Microsoft owns all your home networks, only like the default address on every home router out there...
Microsoft's mindnumbingly dense ClickOps culture strikes again.
at a serious org this would have involved at least some level of oversight or intervention
Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
#99How the hell did that pass any sort of responsible review process at Microsoft? Now Microsoft owns all your home networks, only like the default address on every home router out there...
Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
#100Earlier quoted context omitted.
> Serve malicious updates from a locally controlled machine. Lord knows about auth. Wouldn't they have to break into my local machine first, plant an update service, and an update? That doesn't seem to scale well at all, and wouldn't it be easier to just break into the machine they want to 'update'?
A fairly prominent update service already runs from the domain microsoft.com Many machines come with it preinstalled.