<html>
<head>
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix">If you read the comments, you'll note
that they didn't even get the 'take-over' right.<br>
<br>
In fact, the M$ servers listed as 'authoritative' tried to
implement a selective forwarding/proxy service, since they<br>
didn't have the zone data. This is non trivial. The DNS is not
architected for meddling, and as many who have tried to implement
load balancers, typo-trappers, ad inserters and other forms of
meddling have found out, 'there be dragons there'.<br>
<br>
Now imagine such an attempt in a DNSSEC-secured domain. Or one of
those new TLDs. How about .ru or .cn (hotbeds of crime)? Or the
biggest source of crime - .com?<br>
<br>
Botnets certainly are a menace, and deserve attention. However,
attacking the DNS seems to be in-vogue as it's the thing best
known to the law enforcement community. As this case shows, many
innocent users of no-ip had their operations disrupted. And the
fixes aren't trivial for them. Consider the one in the comments
who uses X.509 certificates for security (a good thing), and was
told 'just get another domain name'. And re-issue all
certificates to his users. Oh, and by the way, if the technical
person is traveling when this happens, oops, there's no way to
make the server-side changes.<br>
<br>
A more reasonable approach would have been to monitor the traffic
to the botnet hubs and black-hole route the infected IP
addresses. That would have required some technical sophistication
and work. But it was easier for LEO/M$ to attack the DNS - there
being no penalty for collateral damage. <br>
<br>
"When the only tool one has is a hammer, every problem looks like
a nail"; er, um, 'When the only part of the internet that is well
known is the DNS, attacking is the solution to all ills.' The
LEOs/courts know about the DNS...<br>
<br>
All of the DNS community - not just NCSG - should be up in arms
about this. LEOs need to be educated. Better methods for going
after the miscreants/criminals need to be developed. And the DNS
needs to be defended from these sorts of well-intentioned, but
technically incompetent attacks made in the name of fighting
crime. Crime fighters should adopt the Hippocratic oath...
"First, do no harm"<br>
<br>
<pre class="moz-signature" cols="72">Timothe Litt
ACM Distinguished Engineer
--------------------------
This communication may not represent the ACM or my employer's views,
if any, on the matters discussed.
</pre>
On 08-Jul-14 11:31, Seun Ojedeji wrote:<br>
</div>
<blockquote
cite="mid:CAD_dc6iLTAViOG1oaL8agi5=MWiD=aV2QwOGzn4pyxVV2S4jng@mail.gmail.com"
type="cite">
<div dir="ltr">
<div>Hello Timothe,<br>
<br>
</div>
Thanks for bringing this up here; when i first read the news of
Microsoft hijacking no-ip domain. The first technical question
that came to mind was; Is Microsoft now some form of an hacker
because i was just wondering how they took-over without any form
of authorisation from the domain owner. However i guess the
section below from your url clears it for me<br>
<br>
<blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px
solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">Under
the terms of the court decision, the DNS lookups for the
domains were passed to Microsoft's name servers, with the plan
being that Redmond would filter out No-IP subdomains linked to
malicious activity and let legitimate subdomains resolve as
expected.<br>
</blockquote>
<div><br>
</div>
<div>Having cleared the technical sides of the story, the
question now is whether no-ip should bound to respond to such
call from Microsoft especially since its not an act from no-ip
itself but the users. One could liken this to running botnets
on systems that exist on a large ISP network to attack a
particular organisation. Does the victim sue the ISP or the
users who don't even know they are botnet nodes. <br>
<br>
</div>
<div>Cheers!<br>
</div>
</div>
<div class="gmail_extra"><br>
<br>
<div class="gmail_quote">On Tue, Jul 8, 2014 at 3:51 PM, Timothe
Litt <span dir="ltr"><<a moz-do-not-send="true"
href="mailto:litt@acm.org" target="_blank">litt@acm.org</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">I haven't
been following things here for a while, so sorry if this has<br>
already been noticed.<br>
<br>
If not, here's a case of judicial interference with the DNS,
coupled<br>
with incompetent 'solutions'.<br>
<br>
This is highly relevant to the ncsg constituency as many
non-commercial<br>
users live with dynamic IP addresses, using services such as
no-ip to<br>
have stable names in the DNS.<br>
<br>
Of course, our terms of membership can be read to exclude
these users -<br>
but note that there's nothing to prevent a similar action
being taken<br>
against direct holders of domain names...<br>
<br>
Here's the story:<br>
<a moz-do-not-send="true"
href="http://www.theregister.co.uk/2014/07/01/sorry_chaps_microsoft_unborks_legitimate_noip_users_domains/"
target="_blank">http://www.theregister.co.uk/2014/07/01/sorry_chaps_microsoft_unborks_legitimate_noip_users_domains/</a><br>
<br>
The comments provide more detail - which for technical
readers is tragic.<br>
<span class="HOEnZb"><font color="#888888"><br>
--<br>
Timothe Litt<br>
ACM Distinguished Engineer<br>
--------------------------<br>
This communication may not represent the ACM or my
employer's views,<br>
if any, on the matters discussed.<br>
<br>
<br>
</font></span></blockquote>
</div>
<br>
<br clear="all">
<br>
-- <br>
<div dir="ltr">------------------------------------------------------------------------<br>
<font color="#888888">
<blockquote style="margin:0pt 0pt 0pt 0.8ex;border-left:1px
solid
rgb(204,204,204);padding-left:1ex;font-family:garamond,serif">
<i><span style="color:rgb(0,102,0)">Seun Ojedeji,<br
style="color:rgb(0,102,0)">
</span><span style="color:rgb(0,102,0)">Federal
University Oye-Ekiti<br style="color:rgb(0,102,0)">
</span><span style="color:rgb(0,102,0)">web: </span><a
moz-do-not-send="true" href="http://www.fuoye.edu.ng"
target="_blank">http://www.fuoye.edu.ng</a><br>
<span style="color:rgb(0,102,0)"></span><span
style="color:rgb(0,102,0)">Mobile: <a
moz-do-not-send="true" value="+2348035233535">+2348035233535</a></span><span
style="color:rgb(0,102,0)"></span><br>
</i><i><span style="color:rgb(0,102,0)">alt email:<a
moz-do-not-send="true" href="http://goog_1872880453"
target="_blank"> </a><a moz-do-not-send="true"
href="mailto:seun.ojedeji@fuoye.edu.ng"
target="_blank">seun.ojedeji@fuoye.edu.ng</a></span></i><br>
<br>
<blockquote style="margin:0px 0px 0px
0.8ex;border-left:1px solid
rgb(204,204,204);padding-left:1ex">The key to
understanding is humility - my view !<br>
</blockquote>
</blockquote>
</font><br>
</div>
</div>
</blockquote>
<br>
</body>
</html>