3 ms·
The Microsoft hate here is unfounded and ill informed. Those of us working defense at large organizations have known for a while that No-IP domains are wretche
by secalex 12y ago
The Microsoft hate here is unfounded and ill informed.
Those of us working defense at large organizations have known for a while that No-IP domains are wretched hives of scum and villainy. Any company with a threat model that includes at least one of a diverse set of characters ranging from malware authors to organized crime to nation state teams should be logging all DNS requests and treating any request to a No-IP domain as an indicator of compromise.
Microsoft has a successful history of disrupting botnet C&C and distribution channels via domain seizures, which is why this request probably sailed through Federal Court. The only difference in this situation is that there are innocent bystanders affected, which generally doesn't happen since the other domains they have seized have been 100% used for fraud.
I feel bad for those folks and the people at No-IP who maybe meant well, but the truth is that the fight to keep normal people safe is bigger than just technological, and needs to include civil legal actions like this.
- pbhjpbhj 12y ago>No-IP domains are wretched hives of scum and villainy // Is that rather like saying "Bing domains are full of malware". You appear to be claiming that No-IP are complicit in the actual hosting of content that gets pointed to with No-IP domains. MS facilitates a ton of illegal activity, I could spin up a Windows box and break 5 laws before bedtime. Of course shutting down MS would harm some innocent bystanders but handing their windowsupdate domains over to Google will lead to less malware, less spam, less successful scamming.
- liquidise 12y agoYou seem to miss a key takeaway from this: the analogous comparisons to this in physical services companies is laughable: If, as a car company, i sell cars with potentially lethal flaws, i am required/told to recall and fix those vehicles. Other companies who sell cars are NOT allowed to have a court order the seizure of my phone numbers and have them direct to competitive business, so they can figure out who is driving safe cars and who isn't. Secondly, the idea that private companies can be labeled "wretched hives of scum and villainy" by other private employees and have that permissible as anything other than meaningless hearsay is itself, nonsense. I have read many documents on this today and every HN comment and I have yet to find someone present a case as to why on earth this is a good and sustainable precedent.
- secalex 12y agoI did not miss that, nor did I make any comparisons to car dealers. In fact, I've been to seven ICANN meetings and have participated in the debate on the proper role of law enforcement and civil seizure in policing the namespace. Microsoft presented evidence to the court that No-IP domains were being used to facilitate real crimes against real people, and the court acted. I think there is an interesting debate to be had on venue and the level of malicious activity that needs to happen before a domain is seized, but instead all I see is standard HN smashing of the keyboard and "Microsoft Bad!"
- CHY872 12y agoHow does missing the 'car analogy' help at all? Analogies are only ever useful to explain to those who do not understand the first case - trying to draw parallels otherwise inevitably leads to gross simplifications, and they're incredibly frequently abused to try and make another point. Analogies are great if John Oliver, or you're at the bar and talking to Erv the local HVAC guy - but this is hacker news, we normally understand this - and trying to port it to a completely different legal framework is probably disingenuous.