4 ms·
Microsoft Cybercrime Shutdown Hit Users Says DDNS Provider
- higherpurpose 12y agoWho made Microsoft the Internet police?
- kevingadd 12y agoThe courts.
- alandarev 12y agoThey do have a good looking chart [1] explaining everything. Isn't that enough? [1] - http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-80-54/MS_5F00_LCA-DCU_5F00_Infographic_5F00_062914_5F00_v5e.png http://blogs.technet.com/cfs-file.ashx/__key/communityserver...
- malka 12y agothe $ god.
- rmrfrmrf 12y agoI get really irritated with companies that put absolutely no effort into cleaning up their services on their own. When nearly 20,000 of No-IP's accounts are being used for malicious purposes, crying about how Microsoft didn't give them any warning just makes them seem incompetent. There was another article recently on HN about some free tunneling service whose creator tried to automate account shutdowns whenever his ISP sent a complaint letter, which I found to be similarly annoying -- these services are essentially forcing other companies to spend money to do the work that they themselves should be doing. IMO No-IP is responsible for its legitimate customers' outages. Waiting around for other companies to do your job for you will result in ham-handed solutions like this one.
- manicdee 12y agoHow many of Microsoft's customers are being used for malicious purposes? Am I as an ISP allowed to summarily disconnect all Microsoft customers from my network?
- the_ancient 12y agoIt is a very dangerous notion that the federal courts can seize the domains of one company and just hand them over to another company... It was bad enough when ICE was doing it, this takes that bad practice to a whole other level...... What is even worse is they got the order ex parte, meaning No IP did not have a chance to defend or explain themselves to the judge before their business was irreparably harmed by the actions of their competitor. Even if the malware claim is true (which I doubt because I trust MS about as much as the NSA) No IP should have been given basic Due Process to explain their side to the Judge before their business was harmed.
- deleted 12y ago[deleted]
- danielweber 12y agoQuestion of fact: did the court attempt to contact No-IP.com? Or did they attempt contact, and No-IP.com failed to show up?
- the_ancient 12y agoCourts never contact anyone. It is normally up to the Plaintiff to "Serve" the defendant. Except when the Plaintiff seeks an ex parte motion,order,etc which allows to court to act with out contacting the defendant. Further if this would have been a situation where contact was attempted and failed it would have been a "default" judgment/order not ex parte
- danielweber 12y agoFine, did any party before the court attempt to serve No-IP.com? If No-IP.com avoided service like Charles Carreon, I have little sympathy. If there was no attempt at service, that's a different story.
- Nanzikambe 12y agoThis is even more ridiculous than I thought, given TFA -- Microsoft could have just asked them to change the IP associated with the relevant accounts, disable update for them and/or hand over access to those accounts. To quote myself from the other thread, the approach they did take is more than slightly bizarre: "There are serious problems with this, firstly that it's technically impossible to implement effectively, beyond that it's extremely impractical. Any benefit will be so so transient as to render the entire exercise pointless. For the moment, let us ignore the scary implications of the court's part in this and consider this from a technical perspective in a logical manner: The hypothetical sub-domain abc.no-ip.org resolves to 1.2.3.4, a host somewhere that contains malicious payloads, is botnet C&C or is a member of a botnet. In any case, he's the bad guy - one of the people Microsoft are looking to exclude from the Internet. So how can this be accomplished? Let's ignore for the moment that the bad guys are free to use any other dyndns service they please and assume that no-ip is the only one. Approach 1 ---------- Every time a host connects to no-ip to update its IP, Microsoft scans tcp & udp ports of the host looking for known C&C services, scans hosted data (public web or ftp). This will simply result in the bad guys hiding all of this in an undetectable manner, many bot-nets already use either Tor or SSH for C&C - without authentication it will be impossible to differentiate Joe Average with an SSH or Tor exit from the "targets". As for scanning for content, this is possible assuming the content has to be public (ie. malicious payload) but even then, it's not practical - payloads can be hidden in anything and obfuscated beyond detection. Essentially all that's accomplished is another arms race based around signature detection for malicious content, with the disadvantage that unlike AV solutions this scanning is conducted remotely and the scan source is known. So the malicious guy with 2 or three lines just uses a stateful firewall to point microsoft's "scanning service" to good content, everyone else to the bad. So what other options are there? A blacklist of IPs? Well, they're dynamic IPs, sooner or later you'll end up with every dynamic IP in the entire ipv4 range blacklisted as the bad dudes just release/renew. Then there's banning the sub-domains/users! Also impractical because for each user and domain you ban, another will emerge. Approach 2 ---------- Microsoft resolves every request for abc.no-ip.org to their own service, all the time, this service performs stateful packet analysis before forwarding it on to the destination host. Impractical because you're essentially routing all no-ip traffic via Microsoft and once again you can only filter what you can detect -- and once the requests themselves are encrypted, that becomes impossible. This is effectively a MITM attack. All the while we've assumed no-ip is the only alternative, it's not - and many others are beyond Microsoft and the courts jurisdiction. So ultimately the only way this "approach" could be temporarily feasible is if all Internet traffic were routed through Microsoft's service. So effectively you need to give control of every domain, TLD, ipv4 and ipv6 range to Microsoft. Not workable. Someone is bound to point out that Microsoft's approach in this may be distributed, agents running on installs of their operating system which does address some aspects of my points above, but once again -- if Microsoft is capable of implementing effective detection on the workstation, remind me again why any of this is needed? I must be missing something fundamental."
- bagosm 12y agoWhat I read from this whole thing, is that Microsoft wants to privately monitor some of the subdomains. This makes me believe they aren't mainly interested in malware but in legitimate though "illegal" traffic. Be safe out there hacktivists