7 ms·
Obviously this was a huge mistake on Mastercards part, but does anyone else think it's a mistake to even /have/ domains that are literally one letter away from
by fuzzer371 2y ago
Obviously this was a huge mistake on Mastercards part, but does anyone else think it's a mistake to even /have/ domains that are literally one letter away from the original TLD's? For instance .com and .co, .net and .ne. It just seems to be asking for trouble. If those didn't exist, they couldn't be registered and the erroneous DNS request would just go nowhere.
- abound 2y agoNot exactly, since typos can occur anywhere in the name, not just the TLD. Hell, even without typos, you can bitsquat [1] on domains one bit away from popular site names (usually CDNs) and get some traffic because of various computer glitches. Here's a random paper I found (and skimmed) with some examples [2] [1] https://en.wikipedia.org/wiki/Bitsquatting https://en.wikipedia.org/wiki/Bitsquatting [2] https://www.securitee.org/files/bitsquatting_www2013.pdf https://www.securitee.org/files/bitsquatting_www2013.pdf
- esnard 2y agoBack in 2018, I was wondering how that paper was still relevant, considering all the new security features added to web browsers. The consensus seemed to be that it wasn't that impactful anymore (if it ever was). https://security.stackexchange.com/q/185435/76718 https://security.stackexchange.com/q/185435/76718
- mattl 2y agoWhat's your solution for Niger and Colombia ISO 3166-2 codes?
- diggan 2y agoEasy, get rid of .net and .com so accidentally adding a letter won't be a problem anymore :)
- mattl 2y agoGet rid of .int too, incase people mistake it for India.
- oasisbob 2y ago.int is a fun one, some orgs squat on it to use as an internal TLD. It used to be easy to trawl through certificate transparency logs and find certificate mis-issuance on the .int TLD because there are very few organizations allowed to be registered in this zone legitimately.
- mattl 2y agoYeah, I've encountered maybe a handful of .int domain names ever. Remember tpc.int?
- dataflow 2y agoHow is this any different from having a phone number that's just one digit away from another sensitive one?
- bandrami 2y agoThe North American Numbering Plan specifically reserves numbers to forbid that (to the extent that the DTMF for 1 is actually handled differently by the line discipline, or at least was 20 years ago)
- fuzzer371 2y agoWell nobody has the phone number 912 for instance. We specifically make sensitive numbers distinct from "regular" numbers. 911, 411, 311, 999, etc.
- dataflow 2y agoYou seem to have no clue what numbers are sensitive? Bank or government phone number could be used to impersonate and steal people's identities, among a whole host of other numbers. Not everything is a life and death matter (and neither was the Mastercard incident).
- aidenn0 2y agoI had a friend whose phone number was 591-1XXX and if I picked up the phone and dialed too fast, the 5 might not get recognized by the switch and I'd end up on 911, where I had to say "sorry, wrong number"
- toast0 2y agoI mean, the ISO 3166-1 alpha-2 TLDs are clearly useful, but given the address space, there's lots of one away typos there. It's not a big difference when the non contry code domains are also one dropped letter away from an ccTLD. On the other hand, this sort of misconfiguration would show up in any sort of good DNS checking tool. One of your registered nameservers doesn't resolve and/or one of your name servers doesn't return the same zone serial (likely) or actual response if you check a name. In .is, they wouldn't let me register a domain unless I provided two known good nameservers, but .com isn't picky anymore.
- indigodaddy 2y agoI would think you'd get client query errors from time to time as well if one of the auth NS names doesn't even route/not registered. Even a big cacher like Google or CF might have noticed query errors and I'd actually be surprised if there wasn't communication from one of those entities to MC about the issue.
- toast0 2y agoI think most recursive servers will try more than one of the authoritatives before giving up. And it's common to keep stats on which servers work, and send traffic to those. So if you get the glue that says mastercard has 5 servers, and you already know 4 of them are good, probably send your query to one and don't even bother trying to find the address of the .ne server. I'd be surprised if it bubbles up in logging unless all/ maybe most of the authoritative servers for a popular hostname/domain name are unresponsive.
- indigodaddy 2y agoyeah you're probably right actually, likely not enough noise to be meaningful
- paulddraper 2y agoEmail addresses, physical addresses, phone numbers, etc are always one letter/digit from another one.
- miki123211 2y agoSometimes physical addresses are even 0 letters from each other! In my (distant) family, there was a guy who married a woman whose name was the same as his sister's, and she changed her family name to his. They all lived together for a short while. Letters addressed to his wife and his sister would have the exact same address and exact same name on them, with no way to distinguish who the letter was for. One more edge case to add to the "falsehoods programmers believe about names" list.
- Cthulhu_ 2y agoMy brother and I have the same initial letter, same problem, but it was possible to use the first two letters as initial with some services. But in practice my mom would open letters to see who it was for, lol.
- cbhl 2y agoI'd expect big companies to use Markmonitor to handle this problem -- basically, they _also_ register all of the one-edit-distance away typos that they can. According to Wikipedia, Akamai is one of Markmonitor's customers, so it is surprising that this wasn't already registered by them.
- stackskipton 2y agoI've found that Markmonitor is generally signed up for "public" address like akamai.com but rarely signed up for service domains since "who is going to screw up the service domain?"
- cobertos 2y agoIsn't that the more dangerous space to have a typo? Less noticable and more valuable traffic from the data it contains? Seems odd MarkMonitor wouldn't prioritize that
- AndroTux 2y agomastercard.net mastercar.net astercard.net nastercard.net... your suggestion changes nothing.
- emmelaich 2y agoYep, when .cm (cameroon) and .co (colombia) started, there were many many domains registered hoping for typo errors for .com.