4 ms·
So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malw
by nathanb 12y ago
So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware?
Where is the due process? Where is the oversight in this? All I'm seeing is vigilanteism.
- andrewstuart2 12y agoCourt-authorized vigilantism.
- cwyers 12y agoBy definition, if it's court-authorized, it's not vigilantism.
- JacobEdelman 12y agoIf a court legalizes Batman then its court authorized, but he's still not a publicly controlled entity and those still a vigilante.
- MBCook 12y agoVigilante. N. A member of a self-appointed group of citizens who undertake law enforcement in their community WITHOUT LEGAL AUTHROITY, typically because the legal agencies are thought to be inadequate.
- wtracy 12y agoIt's called "deputizing", and a deputy is not a vigilante pretty much by definition.
- Dylan16807 12y agoThe judiciary has the ability to deputize law enforcement? I thought those were supposed to have independent structure.
- greenyoda 12y agoThe due process is that Microsoft sued the malware distributors and the court granted them a restraining order. "In a civil case filed on June 19, Microsoft named two foreign nationals, Mohamed Benabdellah and Naser Al Mutairi, and a U.S. company, Vitalwerks Internet Solutions, LLC (doing business as No-IP.com), for their roles in creating, controlling, and assisting in infecting millions of computers with malicious software — harming Microsoft, its customers and the public at large. ... On June 19, Microsoft filed for an ex parte temporary restraining order (TRO) from the U.S. District Court for Nevada against No-IP. On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats."
- andrewfong 12y agoEx parte means that only one party is before the court. That means No-IP had only no opportunity to respond to Microsoft's request to seize the names. Due process, maybe. But not very good due process.
- pbhjpbhj 12y ago>The due process is that Microsoft sued the malware distributors and the court granted them a restraining order. // In what way is the court at liberty to grant a plaintiff permission to enforce a restraining order though, sounds ultra vires? Aren't the only ones enabled legally to do so law enforcement officers?
- lstamour 12y agoNext time, read the rest of the article? > Microsoft has seen more than 7.4 million Bladabindi-Jenxcus detections over the past 12 months, which doesn’t account for detections by other anti-virus providers. Despite numerous reports by the security community on No-IP domain abuse, the company has not taken sufficient steps to correct, remedy, prevent or control the abuse or help keep its domains safe from malicious activity. > On June 19, Microsoft filed for an ex parte temporary restraining order (TRO) from the U.S. District Court for Nevada against No-IP. On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. No-IP in the past has denied allegations, e.g. the Cisco blog post linked to by Microsoft was denied here: http://www.noip.com/blog/2014/02/12/cisco-malware-report/ http://www.noip.com/blog/2014/02/12/cisco-malware-report/ This is also a temporary order, it's not permanent. Sure, it's creepy when courts have control over DNS entries, but ... they do. The Internet isn't lawless, it operates within the legal bounds of each country that participates. I wonder what No-IP will say next and if figures collected by independent groups verify their "swift action" against security threats. As a company providing DDNS services, I wouldn't expect them to understand and use the latest in packet filtering techniques, but ... abuse is abuse and I'm sure they submitted evidence that this was required, temporarily.
- blacksmith_tb 12y agoIt's not clear who determines what "sufficient steps" would be, however. That could range from 'No-IP did nothing at all' to 'they tried and we weren't impressed'. The MS claim that "free dynamic dns is frequently exploited by cybercriminals" seems like hand-waving, to me. It's also used legitimately by millions of people who have home routers which came with support for No-IP baked into firmware...
- andylei 12y ago> It's not clear who determines what "sufficient steps" would be its perfectly clear. the courts.
- kordless 12y agoI'll tack on the fact that Microsoft wrote the piece of crap software that the malware installs itself onto as well. Something smells awful about this whole thing.