15 ms·
Someone bought 'Google.com' from Google for one minute
- GauntletWizard 11y agoMy guess is it's just a bug in Google domains, allowing them to 'register' domains that the lookup RPC failed for. Google doesn't act as the registrar for their own domain, so there was never any risk of the ownership actually getting transferred to him.
- dang 11y agoAlso https://news.ycombinator.com/item?id=10308378 https://news.ycombinator.com/item?id=10308378.
- 0x0 11y agoWhat would happen if someone actually managed to move google.com to a non-google registrar account under their control? Would someone step in and just seize it back? Can you imagine the magnitude of client devices hitting the wrong server for gmail,android updates,chrome even for a few minutes?
- christianmann 11y agoDNS takes a few hours to fully propagate, last time I checked.
- bulatb 11y agoThe propagation "speed" is the effect of clients honoring the records' TTLs. Clients and intermediate servers are responsible for pulling updates to whatever records they believe are stale; the DNS itself just sits there serving queries. Clients and caches sometimes disregard the TTL or use their own, so sometimes changes to a record "haven't propagated" to some clients, but what's really going on is something that's supposed to keep its info fresh decided not to. Though it's possible for clients to get out of date, the story of a built-in propagation speed you can't do anything about is based on misconceptions. The record owner has a lot of say in how and when their records get refreshed.
- rdancer 11y agoThat depends on the expiry time ("Time To Live / TTL") set for the particular record. Minimum TTL is 1s, and maximum is 2e32 -1 seconds, or slightly over 136 years[1]. Resolver libraries and daemons keep cached results in volatile memory, so in practical terms, if a high TTL is set, the spoofed result will continue to be used until the given machine is rebooted. For some middle boxes, this can be years. [1] RFC 1035 section 2.3.4 https://www.ietf.org/rfc/rfc1035.txt https://www.ietf.org/rfc/rfc1035.txt
- arihant 11y agoI think the point is -- if the TTL is set low, most ISPs simply ignore it to a minimum setting of at least a few hours. So changing/pointing a Google hostname to a victim might not have that big an impact if done only for a few minutes.
- rdancer 11y agoI have seen ever-lower TTLs in the wild, sub-minute even, in the past few years. Even historically, TTLs have in my experience always been respected. I think what really tends to happen, and this gets the folks confused, is that the initial TTL is high (say, 3 days), then the sysadmin wants to do some changes, and because they want to be able to keep changing the IP quickly, while they're working on it, they set the TTL low (say, 1 minute). Only you cannot retroactively lower the TTL of the records that have been sent previously, they'll expire whenever during the following 3 days. Your point still stands, mostly. The probability of the old record with a high TTL to be evicted from a resolver's cache during any given short period of time is low.
- TomGullen 11y agoBack in the day I remember this was true, but nowadays when I make changes to DNS in USA, the change is nearly instantly reflected over here in the UK, and a matter of minutes for apparent propagation worldwide. It's gotten a lot faster!
- TrevorJ 11y agoThat would be like buying the worlds biggest DDOS botnet holy cow.
- jldugger 11y agoWell, maybe second biggest. https://citizenlab.org/2015/04/chinas-great-cannon/ https://citizenlab.org/2015/04/chinas-great-cannon/
- rdancer 11y agoI can imagine that such an attack would be dealt with a mix of manual intervention and technical measures, something in between the Google.com search page outage that happens once in a blue moon, and the false routes for YouTube.com IPs that have been propagated several times during the past few years. Big companies that rely on Internet presence are quite pro-active, and there are teams of people whose job is to prevent something like this from happening in the first place. DNS is not a secure protocol, and you can redirect connections intended for google.com from the same local network easily, yet the world still keeps turning.
- _RPM 11y agoHow exactly would that work. modify an instance of bind and check if the client is requesting to resolve 'google.com'? If true, then respond with the rouge IP? First we must make sure the client machine is set up to use our name servers, the ones we have control over.
- colechristensen 11y agoYou can do it by listening in promiscuous mode and injecting packets into the network pretending to be the DNS server. You can also setup a rouge DHCP server that sends a different DNS address. There are likewise many other methods.
- tracker1 11y agoYou don't even need to setup the client, if you have control over any number of intermediate routers, you can snag/reroute port 53 tcp/udp traffic any way you like. I tend to setup my home router to do this, so that all open dns traffic goes where I tell it to. It's also advised to do so for unauthenticated users on shared/public wifi so that you can provide an agreement page/site. Also, so that unauthenticated users can't use DNS as a tunnel method, which is pretty damned cool, but insecure.
- _RPM 11y agoI've set up my laptop to go to my home internal server (old laptop) for DNS. My quality-of-development-environment has increased because I can associate any internal in development app I want with a hostname tied to my internal DNS prefix. Very useful for setting up nginx for multiple applications.
- HappyTypist 11y agoGoogle has HSTS so requests will be prematurely terminated, however it'll still be a huge DDoS attack.
- 0x0 11y agoWell if you control the domain you can easily get an SSL cert (except some clients might pin the CA for google.com).
- nly 11y agoIIRC, all Chrome users are pinned for *.google.com
- LgWoodenBadger 11y agoHowever, chrome will still trust certs issued for Google domains that come from non-Google trusted issuers (things in your local trusted keystore) It sucks because now your employee can MITM you for gmail/google chat/etc
- HappyTypist 11y agoCertificates are pinned too.
- toast0 11y agogoogle.com is under a registry lock, nobody can touch it without going through a security song and dance involving the registry (Verisign) and the registrar (MarkMonotor), so it's unlikely to happen. This looks like because Google's domain selling tool thought he bought the domain, he was authorized for the domain for all the rest of the Google tools, which is scary, but probably not earth shattering. Kind of depends on what you can do in the tools to send people to another site. If they actually hijacked the domain, they would probably kill their DNS servers, but they could do a lot of things; including likely get some domain control certificates (but likely not from the registrars Google pins to, and a lot of people have google's certificate pins)
- michaelmior 11y agoIt seems highly likely that the tools he gained access to would actually be completely useless for google.com.
- sauere 11y agoThis happened before with the German TLD, google.de http://www.spiegel.de/netzwelt/web/domain-gekapert-google-und-denic-weisen-schuld-von-sich-a-461728.html http://www.spiegel.de/netzwelt/web/domain-gekapert-google-un...
- philip1209 11y agoI wonder whether Google hard-codes their authoritative nameservers through their consumer recursive DNS
- avinassh 11y ago> Can you imagine the magnitude of client devices hitting the wrong server for gmail,android updates,chrome even for a few minutes? This somehow reminds me about Gamil [0] [0] - https://en.wikipedia.org/wiki/Gamil_Design#Gmail https://en.wikipedia.org/wiki/Gamil_Design#Gmail
- scrollaway 11y agoMods can you please change to the source URL instead? (Not that I'm a fan of linkedin...) https://www.linkedin.com/pulse/i-purchased-domain-googlecom-via-google-domains-sanmay-ved https://www.linkedin.com/pulse/i-purchased-domain-googlecom-... Edit: Here's a mirror for those that happen to have linkedin.com nullrouted in hosts or something: https://archive.is/HKPhn https://archive.is/HKPhn
- deleted 11y ago[deleted]
- BinaryIdiot 11y agoWhoa thanks for mention this; I've always been "logged in" to LinkedIn that I never knew you had to be logged in to see their content. That's a shame. Edit: jschmitz28 is a liar; you can access without being logged in just fine.
- jschmitz28 11y agoIt is working for me now. At the time of my post, opening the link incognito redirected to the same page as when you click the "Join today" link in the top right: https://www.linkedin.com/start/join?trk=hb_join https://www.linkedin.com/start/join?trk=hb_join
- dang 11y ago> jschmitz28 is a liar Not cool. Perhaps you meant it humorously, but please don't post things like that here.
- scrollaway 11y agoI'm not logged on linkedin and I don't have a problem. I don't even have an account.
- joshschreuder 11y agoI just tried opening it in private browsing (not logged in) and I could access the LinkedIn article just fine.
- pyrrhotech 11y agoDefinitely a bug in Google domains. The real one expires 9/14/2020. https://who.is/whois/google.com/ https://who.is/whois/google.com/
- jldugger 11y agoYea, but if Google says you own google.com, how 'unreal' is your claim?
- dendory 11y agoRegistrars can say whatever they want, it doesn't mean anything until the domain is properly listed in the TLD's main database, in this case VeriSign.
- BMorearty 11y agoYeah, Google only bought the five-year renewal cuz they wanted to save a few bucks in case they change the name later.
- chrissnell 11y agoI remember a Slashdot article back in the 90s about a guy who renewed hotmail.com for Microsoft when they accidentally let it expire. The guy needed to get to his email but couldn't and he quickly discovered the problem and fixed it for them.
- fletchowns 11y agoYou mean the incident they mention in the article that was linked? http://www.npr.org/2014/04/01/297690717/why-doesnt-america-read-anymore http://www.npr.org/2014/04/01/297690717/why-doesnt-america-r...
- jbellis 11y agoNope. The details don't match not because GP has a bad memory but because it was a separate incident. Don't be a dick.
- fletchowns 11y agoAh, maybe it was the passport.com incident that was mentioned in another comment. Fair enough!
- chrissnell 11y agoIt was the same. http://www.doublewide.net/ http://www.doublewide.net/
- nodesocket 11y agoHe never actually owned it. This was just a bug in the Google domains control panel. The source of truth (I believe ICANN) would never showed a change of ownership.
- yitchelle 11y agoI wonder how common it is to have such a bug? I would have though the type of functions would be bullet proof.
- scintill76 11y agoWell, the original post talks about him getting Google Webmaster tools for google.com, which while still not "owning" the domain itself, is interesting because it means more happened than just the domain buying app thinking he owned it.
- callesgg 11y agoHe bought it using googles own domain buying app, Presumably it is connected to the rest of googles stuff and the other way around.
- scintill76 11y agoYeah, I didn't mean the effects spread out of Google's stuff, just spread farther than Google's domain app.
- enos_feedler 11y agoThis sounds like some kind of PR stunt for google domains.
- BinaryIdiot 11y agoWhy? Wouldn't that be a lousy PR stunt? Domain services are the keepers to your most prized possessions and Google's let someone buy their own domain creating this nebulous set of thoughts to where many might think this allowed the person to control google.com itself.
- enos_feedler 11y agoIts just funny that it was an ex-googler buying google.com from Google Domains. and they happened to state the price ($12) in the ad errrr article. relax people. downvotes? come on.
- downandout 11y agoApparently this happened in 1999 with Microsoft's Passport.com as well [1], and again later with hotmail.co.uk [2]. While I understand that snafus like this can happen, I don't understand why the new owner would simply hand back the domain for essentially no compensation (especially in the case of hotmail.co.uk - this appeared to be a clean transfer of an expired domain). If they let the domain expire, it's fair game and should go for market price. [1] http://www.doublewide.net/ http://www.doublewide.net/ [2] http://www.bloomberg.com/apps/news?pid=newsarchive&sid=at_jli4Blw0g&refer=uk http://www.bloomberg.com/apps/news?pid=newsarchive&sid=at_jl...
- dendory 11y agoIf a company can reasonably show they own a trademark for a name in a region and should be awarded a domain, registrars will give away the domain. There has been plenty of cases where even old domains were taken away.
- deleted 11y ago[deleted]
- plonh 11y agoICANN has policies in place to preempt ridiculous arguments like this.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- chrsstrm 11y agoYou are not awarded a domain name simply because you hold a trademark. There is evidence that domains have been awarded to trademark holders after a UDRP hearing and the trademark holder contested the validity of the registration. Read the UDRP guidelines [0]. There is also the counterpoint of the case of Nissan Motor Co vs. Nissan Computer Corp [1] where Nissan Motors owns the trademarks but have not been granted nissan.com. [0] https://www.icann.org/resources/pages/policy-2012-02-25-en#4 https://www.icann.org/resources/pages/policy-2012-02-25-en#4 [1] http://www.internetlibrary.com/cases/lib_case292.cfm http://www.internetlibrary.com/cases/lib_case292.cfm
- valevk 11y agoOn the 20.09, I received a totally legit invoice from invoice@google.com (99.99€ Candyclub - Bag of Gems). The sender is invoice@google.com, but no names, no other personal information. I thought it was somewhat strange, and reported it, but no answer.
- mikkom 11y agoIt's extemely simple to fake the sender of email. That's what probably happened.
- valevk 11y agoI just thought it's strange, becuase gmail usually detects email spoofing.
- tokenizerrr 11y agoSure, but google uses SPF and DKIM. The spam mail would not validate and be marked as spam.
- unicornporn 11y agoWouldn't it be better to link to the original post at https://www.linkedin.com/pulse/i-purchased-domain-googlecom-via-google-domains-sanmay-ved https://www.linkedin.com/pulse/i-purchased-domain-googlecom-... ?
- y0ghur7_xxx 11y agono, because that one requires registration to read.
- tokenizerrr 11y agoIt does not.
- m_st 11y agoI can easily read it, no registration required it seems.
- pygy_ 11y agoMaybe LinkedIn detected a previous session and therefore wants you to log in? Do you have the same behavior in a private window?
- monort 11y agoThis link requires login for me even in private window.
- theGimp 11y agoI'm pretty sure LinkedIn filters by IP address. A long time ago, I noticed they let me through without logging in if I used my home connection, but made me log in if I were connecting through my VPN. Note: exact same browser session, minutes apart.
- bigbugbag 11y agonope. linkedin is a company/website I wouldn't touch with a stick.
- anonu 11y agoThe article says "He frantically took screenshots along the way and detailed the whole ordeal in a LinkedIn post." ... I find the choice of words funny. If he hadn't bothered to buy a domain he knew he would never be able to keep, there would be no ordeal!!!
- mcs_ 11y agofinally. i like the idea someone can remove my last purchase and manipulate my account.
- CydeWeys 11y agoIt wasn't a valid purchase. What would you expect to happen? Google.com, like the Brooklyn Bridge, isn't for sale.
- CydeWeys 11y agoTo expand on this, google.com is registered through MarkMonitor, which is a registrar. Google Domains is also a registrar. A registrar cannot sell a domain that is owned, and certainly not one that is owned by a client on another registrar! There was some error on the Google Domains side that indicated a domain was available for purchase that was in fact not available for purchase. That's it. The money was refunded when the error was reported. It's the only possible sane solution to the problem. Your comment implies that the sale should have gone through anyway, which is nonsensical. Otherwise we could have situations where I steal foo.bar from you (which you have registered with, say, NameCheap) by buying it through, say, GoDaddy, which is currently experiencing a similar bug that incorrectly marks your domain as available.
- snowy 11y agoIn Ireland some one managed to redirect google.ie (The irish google search domain): http://technology.ie/google-ie-hijacked/ http://technology.ie/google-ie-hijacked/ The ccTLD register (The IEDR) had a vulnerability in their management portal that was exploited (I believe it was an SQL injection if I recall correctly). The attacker changed the DNS servers to their own and then put an A name record pointing google.ie to their own server. The server just displayed a hijacked by page. It was probably just some kid. If it was a criminal they would have done some thing far more malicious. yahoo.ie also got hijacked. It was an absolute pain, for months after the IEDR's portal was disabled, you had to call them to make any changes to any .ie domain.
- wahsd 11y agoHonest question. If he bought the domain from Google and the transaction went through, is that not technically a legitimate transaction and "cancelling" and refunding the money is essentially theft? How is that any different than walking in to someone's house and leaving them $20 for the TV you took? It seems to me that "oops, take-backs" Is not a legitimate enough justification to reverse a transaction under contract law. It seems rather ominous if even this kind of situation is permitted because it sets a precedent that corporations can simply decide to change their mind when something is not in their favor. Sure, it's an example that many people will simply rationalize or defend, but just on matters of assuring the credibility of the integrity of the whole market based system, Google should not be allowed to simply step away from this as if nothing happened without at least a fine that gets noticed by the executive suite. How would you feel if in the future mega consolidated food corporation can arbitrarily decide that "oops, we changed our mind. That food you ate and sold to you for $X should have really been charged at $3X. Don't worry, we will charge your account. Have a nice day" How about a different scenario; the airline industry decides that "oops, someone else was willing to pay more for that last seat on that flight you just booked. We just cancelled it and refunded your money. Have a nice day" I get that it was probably a mistake of some kind. But what is it that immunizes corporations from the consequences of mistakes? I guess that's kind of rampant right now in our society and economy, but still.
- Khao 11y agoThere are consumer protection laws that protect both consumers and sellers when mistakes are made like in this case (at least here in Québec and Canada, it must be similar in the US). Let's say you're selling a 10$ gift card on your website but through some bug/error it's now worth 1000$ (an easy mistake to make, just forget the decimal place). What if someone bought the 1000$ worth gift card for the original intended price of 10$? I'm sure you would invalidate that purchase and send them an email explaining that it was a mistake, and it would be perfectly within your rights to do so. It goes both ways too, if a mistake is made that advantages the seller, they have to fix it.
- CydeWeys 11y agoGoogle Domains is not the registrar for google.com. MarkMonitor is. Your situation is analogous to agreeing to buy a deep-discount TV from someone off Craigslist, who meets up with you in a hotel parking lot, goes inside with you, points you to the TV in the lobby that you just "bought" and says take it. That TV was not for sale and the person "selling" it didn't own it. It's unreasonable to expect MarkMonitor to honor a sale that couldn't happen because some other registrar messed up. Mistakes can and do happen in business all the time, because businesses are composed of people and people aren't perfect. The solution is to deal with mistakes in whatever is the most sane way.
- eccstartup 11y agoSo what? He earned nothing but your carelessly attention.
- lovemetender 11y agoI'm surprised I didn't see this on the morning news and wow what a thrill it must have been.