Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The comments here are surprisingly pro-Microsoft. I'd personally rather deal with spam and botnets over a corporation legally being able to take over the DNS of other companies due to the actions of users of a service. Despite pretty clear slippery-slope arguments, I recognize this isn't a universal opinion. There are many people who would like to curb cyber-bullying at the expense of freedom of speech or curb terrorism at the expense of privacy and civil liberties. It takes all kinds, I guess.


It wasn't actually due to the actions of their user though, was it? It was because of the actions of NoIP themselves, who did not act to prevent abuse by their users.

From what Cisco and Microsoft are reporting NoIP is (was?) a hotspot of botnet activity. If NoIP was not doing anything against that Microsoft's lawsuit doesn't sound that unreasonable.

How this was actually implemented in the end (MS just taking over the DNS) does seem a bit strange to me though. They should at least have been taking over by a government agent.


Wouldn't a similar line of reasoning be "It seems that computers running Microsoft Windows are a hotspot of botnet activity. Year after year, a vast majority of computers used in botnets are running Windows; they are clearly not doing enough to prevent abuse by their users. Lets give control of the Windows code base to Linus"


I think most of the judges would be able to see through it and recognize that running a free DNS service which ignores abuse by botnets and having an OS which can be used to run various programs on, including malware, is a bit different thing. If you could prove Microsoft "clearly not doing enough to prevent abuse", you could probably win a juicy class-action lawsuit, but proving this would be extremely hard.


How would NO-IP detect C&C servers aliased to their subdomains, even if they connected to every single one of their subdomains daily -- they wouldn't know what ports to scan. By my, possibly naive thinking, they'd have to impose denial of service attacks on their own customers, constantly, and they would be easily thwarted by port knocking schemes. Probably their only recourse is to stop offering free service, and instead take payment, or require and verify customer IDs. I'm not sure there's a technical solution. Microsoft seems to be attacking their business model.


If they went through with their intended plan to stop supporting Windows XP, then proving that they were "clearly not doing enough to prevent abouse" would be trivially easy.


How so? Microsoft never promised it would support XP forever. EOLing old versions is a standard and widely accepted industry practice. Just buy (or install for free) a newer operating system. Buying a license to run Windows XP on your computer does not entitle you to unlimited amount of free labor from Microsoft. If you think that makes XP suck, nobody forces you to buy it or keep using it. Are you also expecting Linus to still make patches for Linux kernel 1.0?


I think some related arguments to your point are that you could say ISPs don't do enough to prevent pirated content from being transmitted on their networks or that Muslims don't do enough to prevent Islamist extremists in their communities. These claims might be true, but should companies or governments be stepping in to solve these situations? Who is mandating that they need to be "solved"? What are the consequences of solving things these ways? Could there be more nuanced implications than the solving of the thing they're trying to fix on the face of it?


You might just as well say it is the IANA's fault for issuing the IP addresses the malware authors used, or Ford's fault for building the getaway car used in a bank robbery.


Your argument is ridiculous.

Turning over IANA or Ford over to Microsoft would not prevent malware or robberies. Turning over NoIP to Microsoft will prevent malware (at least in the short term).


And what about any innocent users of Dynamic DNS who are currently suffering from the consequences of this action? No-IP's statement implies that this is somewhat widespread and due to Microsoft's inability to handle the responsibility it has somehow acquired in this case. Others on HN seem to be posting independent verification of this using standard tools from their own systems.

In short, it is neither obvious that turning over NoIP's domains to Microsoft will prevent malware, nor clear what should happen if it doesn't, and it is certainly not clear that Microsoft will not cause more damage than they repair by acting in this way or what should happen if they do.


You're kidding right? I honestly burst out with a laugh when I read this. In what world do you live in where Microsoft seizing control of a single dynamic DNS provider will "prevent malware" (even in the short term)?

It's not like this motion has created some insurmountable wall that malware creators can't possibly work around.


It of course did not create insurmountable wall, but many malware platforms rely on free DNS services for establishing communications, and if particular strain is hardcoded to use no-ip, the instances that rely on it would not be able to establish the connections and thus would not be controlled by botnet owner anymore, at least for the time it takes to either deliver update by other means (provided such means are coded in particular strain) or re-infect the machine with different strain of malware. Of course, once malware authors know no-ip is no longer their friend, they'd move on to use different services, but the instances that were produced before that may very well be disrupted.


"Turning over NoIP to Microsoft will prevent malware"

Really? Not according to anyone with anything resembling a passing familiarity with malware and it's distribution...


In any event, the malware will at least not resolve to a no-ip.com address, since apparently nothing is able to consistently resolve to such addresses anymore...


Unfortunately malware tends to be the one kind of No-Ip client that actually has (lots of) redundancy built into its peer discovery mechanism.

Malware authors anticipate their communication channels to fail and usually account for it with a whole series of fallbacks.

Quite unlike your NetGear or LinkSys home router, which many people suddenly can't reach anymore from e.g. their vacation home...


Well, how exactly does this prevent malware? Oh, that's right: by shutting down thousands of malware-serving DNS records. (And, btw, millions of legitimate records - but hey, that's just collateral damage; a thousand, a million, same thing, right?)

Using the same logic, let's just prevent malware altogether by blackholing all of the Internet traffic - problem solved!


I would imagine most DDNS services push traffic to a blacklisted node. Your ISP blacklists the D-IP so that you, as a lowly end-user, can't run something like an email server. So, I would imagine effectively sorting out which IP addresses are blacklisted because of malware infection or simply ISP infection would be very hard indeed...


>It was because of the actions of NoIP themselves, who did not act to prevent abuse by their users

The article of this thread (that is the blog post of NoIP in response to MS's actions) which I'm sure we all read, says that NoIP themselves DID act to prevent abuse. They were not informed of this action by Microsoft.


I don't agree with the precedent set here but it does seem No-IP was doing a pretty bad job of responding to mass abuse.

While I do take issue to the actions of Microsoft and the courts I also think No-IP hasn't done themselves any favours and are at least partially to blame for this coming to pass.

It stands to reason that it's close to impossible to create a free service that is impervious to abuse however it's still their responsibility to avoid mass abuse of their platform to orchestrate botnets.


That responsibility is not absolute, and could be interpreted differently in the frameworks of ethicality, legality, economics, and liberty.

Ethically, I think you're correct that it's their responsibility to do what they can.

Legally, the court in this situation thought it was somehow Microsoft's responsibility to fix it.

Economically, I'd say being held liable to what users do on your platform will hurt innovation and competition.

In terms of liberty, botnets and spam don't seem like they compare to an attack on someone's business, their users, and their freedom to operate independently.

I guess you can choose which perspective makes the most sense to you, personally.


I don't believe they should be held liable for the actions of malicious users, that would violate all sorts of safe harbour provisions.

However, safe harbour does atleast imply reasonable effort to curb mass abuse.

Responding case by case is nice but it's not the same. As it leaves open the proverbial DDoS attack where botnets just create so many domains that the process put in place to resolve them is too burdensome for companies like Microsoft (or even law enforcement) to reasonably utilize.

Hence if you have a platform that is vulnerable to such abuses you should have systems in place to handle this at a bigger scale than single case by case means.


You believe in terms of liberty that botnets who compromise machines in order to steal data, spam and many other nefarious activities doesn't compare to one business being temporarily affected ?

That is a strange perspective I have to say.


In terms of liberty, one crime doesn't excuse another, especially when they're not directly related. If I manufacture cigarettes and someone dies of lung cancer, I could be ethically liable but my liberty to make cigarettes shouldn't be impacted. If someone uses YouTube to upload copyrighted things, should YouTube have its domain stolen and its users unable to use the site any more?


I don't think cigarettes are the best example because there is no use for them that doesn't potentially invoke the harmful effects for every single user. YouTube, ISPs, and dynamic domain providers have valid, widespread, legitimate, harmless uses, so YouTube is a better analogy IMO.

If one accepts the idea that courts should be seizing entire swaths of domains just to fight malware, it's still absolutely bizarre that Microsoft themselves should be given control of them, rather than an independent policing body. If there are to be Internet police, they should be independent of any one corporation, industry group, or government.


>>> In terms of liberty, one crime doesn't excuse another,

Except it is not a crime if it's done under lawful authority (by definition) or in self-defense. Otherwise you'd argue imprisoning a murderer or using force to defend your life is a crime, because outside of these circumstances limiting one's freedom of movement or using force on somebody is a crime.

>>> If someone uses YouTube to upload copyrighted things, should YouTube have its domain stolen and its users unable to use the site any more?

If that's the only thing his domain is used for, it very well may happen, and similar things already happened. Seizures of domains used for illegal activities are commonplace.


It is even more strange because botnets are the source of most DDoS, so there are ton of companies out there who have been crippled by DDoS and/or blackmail.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: