Live data from Hacker News

Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

news.ycombinator.com

91–100 of 148 posts

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#92

Earlier quoted context omitted.

This isn’t something that I think should be diluted. If it’s that simple for a stray record to be included in the dns round robin it could have been bad if it was an external ip with a machine setup by a phisherman especially since control of a domain is all you need to get an ssl cert now. Couple this with the fact that it’s Microsoft, one of the most relied on companies in our computer world, this is pretty darn ho…

Microsoft also has some of the phishiest looking domains when you are redirected around the O365 cloud.

The only thing that competes is the redirecting when you log into any health portal.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#93

Earlier quoted context omitted.

This isn’t something that I think should be diluted. If it’s that simple for a stray record to be included in the dns round robin it could have been bad if it was an external ip with a machine setup by a phisherman especially since control of a domain is all you need to get an ssl cert now. Couple this with the fact that it’s Microsoft, one of the most relied on companies in our computer world, this is pretty darn ho…

For all this to work you need to control the domain. Is that easier than simply breaking into their systems and owning their servers?

Sometimes it’s easier to bribe then to break

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#94

Earlier quoted context omitted.

This isn’t something that I think should be diluted. If it’s that simple for a stray record to be included in the dns round robin it could have been bad if it was an external ip with a machine setup by a phisherman especially since control of a domain is all you need to get an ssl cert now. Couple this with the fact that it’s Microsoft, one of the most relied on companies in our computer world, this is pretty darn ho…

For all this to work you need to control the domain. Is that easier than simply breaking into their systems and owning their servers?

That's exactly what they're saying.

> it could have been bad if it was an external ip with a machine setup by a phisherman

I.e. one of the IPs for microsoft.com belongs to $phisher, which means they control (a subset of the traffic going to) the domain. They can't add CNAME records for certificate validation, but LetsEncrypt for example offers HTTP-based validation.

Not sure how Microsoft sets up their certificate pinning, it might not be quite that easy.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#97
post #35
post #15

Through a series of connections I know a guy that knows a guy that works at Microsoft that was made aware and the changes have been reverted. Give 'er 30 minutes TTL ;)

30 minutes minutes or 30 Windows minutes? :P

[flagged]

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#98

How the hell did that pass any sort of responsible review process at Microsoft? Now Microsoft owns all your home networks, only like the default address on every home router out there...

click click click -- "it's done, boss."

Microsoft's mindnumbingly dense ClickOps culture strikes again.

at a serious org this would have involved at least some level of oversight or intervention

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#100

Earlier quoted context omitted.

> Serve malicious updates from a locally controlled machine. Lord knows about auth. Wouldn't they have to break into my local machine first, plant an update service, and an update? That doesn't seem to scale well at all, and wouldn't it be easier to just break into the machine they want to 'update'?

A fairly prominent update service already runs from the domain microsoft.com Many machines come with it preinstalled.

The erroneous DNS change wouldn't help that sort of exploit. It just redirects attempts to contact microsoft.com to a local address, probably a router.
Post reply on HN