<html>
  <head>
    <meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">If you read the comments, you'll note
      that they didn't even get the 'take-over' right.<br>
      <br>
      In fact, the M$ servers listed as 'authoritative' tried to
      implement a selective forwarding/proxy service, since they<br>
      didn't have the zone data.  This is non trivial.  The DNS is not
      architected for meddling, and as many who have tried to implement
      load balancers, typo-trappers, ad inserters and other forms of
      meddling have found out, 'there be dragons there'.<br>
      <br>
      Now imagine such an attempt in a DNSSEC-secured domain.  Or one of
      those new TLDs.  How about .ru or .cn (hotbeds of crime)?  Or the
      biggest source of crime - .com?<br>
      <br>
      Botnets certainly are a menace, and deserve attention.  However,
      attacking the DNS seems to be in-vogue as it's the thing best
      known to the law enforcement community.  As this case shows, many
      innocent users of no-ip had their operations disrupted.  And the
      fixes aren't trivial for them.  Consider the one in the comments
      who uses X.509 certificates for security (a good thing), and was
      told 'just get another domain name'.  And re-issue all
      certificates to his users.  Oh, and by the way, if the technical
      person is traveling when this happens, oops, there's no way to
      make the server-side changes.<br>
      <br>
      A more reasonable approach would have been to monitor the traffic
      to the botnet hubs and black-hole route the infected IP
      addresses.  That would have required some technical sophistication
      and work.  But it was easier for LEO/M$ to attack the DNS -  there
      being no penalty for collateral damage.  <br>
      <br>
      "When the only tool one has is a hammer, every problem looks like
      a nail"; er, um, 'When the only part of the internet that is well
      known is the DNS, attacking is the solution to all ills.'  The
      LEOs/courts know about the DNS...<br>
      <br>
      All of the DNS community - not just NCSG - should be up in arms
      about this.  LEOs need to be educated.  Better methods for going
      after the miscreants/criminals need to be developed.  And the DNS
      needs to be defended from these sorts of well-intentioned, but
      technically incompetent attacks made in the name of fighting
      crime.  Crime fighters should adopt the Hippocratic oath...
      "First, do no harm"<br>
      <br>
      <pre class="moz-signature" cols="72">Timothe Litt
ACM Distinguished Engineer
--------------------------
This communication may not represent the ACM or my employer's views,
if any, on the matters discussed. 
</pre>
      On 08-Jul-14 11:31, Seun Ojedeji wrote:<br>
    </div>
    <blockquote
cite="mid:CAD_dc6iLTAViOG1oaL8agi5=MWiD=aV2QwOGzn4pyxVV2S4jng@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div>Hello Timothe,<br>
          <br>
        </div>
        Thanks for bringing this up here; when i first read the news of
        Microsoft hijacking no-ip domain. The first technical question
        that came to mind was; Is Microsoft now some form of an hacker
        because i was just wondering how they took-over without any form
        of authorisation from the domain owner. However i guess the
        section below from your url clears it for me<br>
        <br>
        <blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px
          solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">Under
          the terms of the court decision, the DNS lookups for the
          domains were passed to Microsoft's name servers, with the plan
          being that Redmond would filter out No-IP subdomains linked to
          malicious activity and let legitimate subdomains resolve as
          expected.<br>
        </blockquote>
        <div><br>
        </div>
        <div>Having cleared the technical sides of the story, the
          question now is whether no-ip should bound to respond to such
          call from Microsoft especially since its not an act from no-ip
          itself but the users. One could liken this to running botnets
          on systems that exist on a large ISP network to attack a
          particular organisation. Does the victim sue the ISP or the
          users who don't even know they are botnet nodes.  <br>
          <br>
        </div>
        <div>Cheers!<br>
        </div>
      </div>
      <div class="gmail_extra"><br>
        <br>
        <div class="gmail_quote">On Tue, Jul 8, 2014 at 3:51 PM, Timothe
          Litt <span dir="ltr"><<a moz-do-not-send="true"
              href="mailto:litt@acm.org" target="_blank">litt@acm.org</a>></span>
          wrote:<br>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">I haven't
            been following things here for a while, so sorry if this has<br>
            already been noticed.<br>
            <br>
            If not, here's a case of judicial interference with the DNS,
            coupled<br>
            with incompetent 'solutions'.<br>
            <br>
            This is highly relevant to the ncsg constituency as many
            non-commercial<br>
            users live with dynamic IP addresses, using services such as
            no-ip to<br>
            have stable names in the DNS.<br>
            <br>
            Of course, our terms of membership can be read to exclude
            these users -<br>
            but note that there's nothing to prevent a similar action
            being taken<br>
            against direct holders of domain names...<br>
            <br>
            Here's the story:<br>
            <a moz-do-not-send="true"
href="http://www.theregister.co.uk/2014/07/01/sorry_chaps_microsoft_unborks_legitimate_noip_users_domains/"
              target="_blank">http://www.theregister.co.uk/2014/07/01/sorry_chaps_microsoft_unborks_legitimate_noip_users_domains/</a><br>
            <br>
            The comments provide more detail - which for technical
            readers is tragic.<br>
            <span class="HOEnZb"><font color="#888888"><br>
                --<br>
                Timothe Litt<br>
                ACM Distinguished Engineer<br>
                --------------------------<br>
                This communication may not represent the ACM or my
                employer's views,<br>
                if any, on the matters discussed.<br>
                <br>
                <br>
              </font></span></blockquote>
        </div>
        <br>
        <br clear="all">
        <br>
        -- <br>
        <div dir="ltr">------------------------------------------------------------------------<br>
          <font color="#888888">
            <blockquote style="margin:0pt 0pt 0pt 0.8ex;border-left:1px
              solid
              rgb(204,204,204);padding-left:1ex;font-family:garamond,serif">
              <i><span style="color:rgb(0,102,0)">Seun Ojedeji,<br
                    style="color:rgb(0,102,0)">
                </span><span style="color:rgb(0,102,0)">Federal
                  University Oye-Ekiti<br style="color:rgb(0,102,0)">
                </span><span style="color:rgb(0,102,0)">web:      </span><a
                  moz-do-not-send="true" href="http://www.fuoye.edu.ng"
                  target="_blank">http://www.fuoye.edu.ng</a><br>
                <span style="color:rgb(0,102,0)"></span><span
                  style="color:rgb(0,102,0)">Mobile: <a
                    moz-do-not-send="true" value="+2348035233535">+2348035233535</a></span><span
                  style="color:rgb(0,102,0)"></span><br>
              </i><i><span style="color:rgb(0,102,0)">alt email:<a
                    moz-do-not-send="true" href="http://goog_1872880453"
                    target="_blank"> </a><a moz-do-not-send="true"
                    href="mailto:seun.ojedeji@fuoye.edu.ng"
                    target="_blank">seun.ojedeji@fuoye.edu.ng</a></span></i><br>
              <br>
              <blockquote style="margin:0px 0px 0px
                0.8ex;border-left:1px solid
                rgb(204,204,204);padding-left:1ex">The key to
                understanding is humility - my view !<br>
              </blockquote>
            </blockquote>
          </font><br>
        </div>
      </div>
    </blockquote>
    <br>
  </body>
</html>