TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Microsoft takes down No-IP.com domains

315 点作者 anExcitedBeast将近 11 年前

47 条评论

Zancarius将近 11 年前
&gt; On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats.<p>Something about this bothers me. So the <i>courts</i> granted MS the rights to essentially take over No-IP&#x27;s DNS in order to &quot;identify&quot; ... &quot;bad traffic?&quot;<p>The implications of this are... chilling. As much as I want to reserve judgement, this makes me <i>uneasy</i> (malware aside).
评论 #7967802 未加载
评论 #7969582 未加载
评论 #7968113 未加载
评论 #7970294 未加载
评论 #7975746 未加载
评论 #7968020 未加载
评论 #7996973 未加载
评论 #7969972 未加载
alasdair_将近 11 年前
&quot;On June 19, Microsoft filed for an ex parte temporary restraining order (TRO) from the U.S. District Court for Nevada against No-IP. On June 26, the court granted our request and made Microsoft the DNS authority for the company’s 23 free No-IP domains, allowing us to identify and route all known bad traffic to the Microsoft sinkhole and classify the identified threats. &quot;<p>How can this be legal? Does this mean that if I get malware from a hotmail.com address, I can file for a TRO against Microsoft and control their domains?<p>I honestly don&#x27;t understand why Microsoft should be given this ability.
评论 #7967835 未加载
nostromo将近 11 年前
According to Reuters, Microsoft is only sending traffic from computers that are infected with malware to Microsoft instead of No-IP.<p><a href="http://uk.reuters.com/article/2014/06/30/us-cybercrime-microsoft-idUKKBN0F52A920140630" rel="nofollow">http:&#x2F;&#x2F;uk.reuters.com&#x2F;article&#x2F;2014&#x2F;06&#x2F;30&#x2F;us-cybercrime-micro...</a><p>That may still make people uncomfortable, but it seems much less egregious than Microsoft taking control of No-IP&#x27;s domains, which is what this press release implies.<p>Edit: the reuters article is in error here, not the Microsoft Blog. See below. Turns out this really is as egregious as it sounds.
评论 #7967765 未加载
评论 #7968100 未加载
评论 #7968871 未加载
runarb将近 11 年前
Has I understood this correctly? Microsoft, a private company, has been granted the right to filter all dns traffic, and choose what will bee forward to this other company, No-IP. No-IP will so bee allowed to run there service for the remaining customers Microsoft approves?<p>Is this common practices in the us legal system? Would it work like this in the offline world also? If my neighbor sometimes had loud parties that bothered me, could I be granted the right to stand in front of his door and turn any potential troublemakers away.
评论 #7967939 未加载
评论 #7967815 未加载
评论 #7969801 未加载
hendersoon将近 11 年前
It&#x27;s just plain outrageous that this court order was granted. It essentially puts no-ip out of business when they were not complicit in anything illegal.<p>It took me 5 minutes to switch my completely legitimate hosts over to ddns.net. I&#x27;m sure the evil botnet owners have backup hostnames and will do the same, or more likely switch to another provider entirely.<p>The end result will be a short-lived dip in criminal activity over the next 72 hours or so, inconveniencing many thousands of legit users, and putting a completely innocent company out of business. Nice move, MS.
评论 #7968470 未加载
评论 #7969203 未加载
评论 #7968356 未加载
andrewstuart2将近 11 年前
So let me get this straight. Microsoft got a court order to route all of another entity&#x27;s DNS traffic to their servers. Giving them the ability to route a metric crap-ton of private traffic through their data centers. For &quot;security&quot;. I call shenanigans.<p>I&#x27;m also assuming this is why my no-ip domain disappeared this morning, leaving me with no access to my home servers.<p>Perhaps the linux on my servers is considered malware. It sure is malicious to Microsoft&#x27;s bottom line. I kid, but only a little.
评论 #7968231 未加载
pktgen将近 11 年前
FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I&#x27;ve never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).
评论 #7968164 未加载
评论 #7967633 未加载
评论 #7968207 未加载
评论 #7967638 未加载
评论 #7967653 未加载
nathanb将近 11 年前
So let me get this straight...Microsoft took down a free provider of dynamic DNS services because people have used those services to distribute and control malware?<p>Where is the due process? Where is the oversight in this? All I&#x27;m seeing is vigilanteism.
评论 #7967785 未加载
评论 #7967751 未加载
评论 #7968026 未加载
评论 #7967736 未加载
gtirloni将近 11 年前
1 - Court seems to quick to grant Microsoft control of the domains<p>2 - No-IP statement that they have an open channel with Microsoft executives but never (never?) received a complain from MS about any malicious activity is doubtful (sure MS can produce evidence to the contrary)<p>3 - What was the urgency and how was this presented to the judge? Personally I don&#x27;t feel the urgency to use a takeover maneuver in this case, but is there information that shows the impact of not acting was too great?<p>4 - Our governments are so inept at fighting cyber-crime that instead of sending the request to a govt-regulated cyber-security unit they had to trust Microsoft&#x27;s with the enforcement? That&#x27;s sad.<p>Like others, I am uneasy but thankful to MS. Just wish more details would be shared.
评论 #7968335 未加载
spion将近 11 年前
This is quite outrageous. I&#x27;ve been using no-ip.com for very legitimate purposes and this will surely result with a lot of breakage. Thanks Microsoft. Thanks a lot.
评论 #7968462 未加载
norswap将近 11 年前
Just when you thought it had been a long time since Microsoft was last evil.
评论 #7968539 未加载
saganus将近 11 年前
What I don&#x27;t understand and haven&#x27;t seen anyone ask is, why Microsoft?<p>I mean, obviously some shady legal tactics are at work here, but why did Microsoft got to control those domains instead of, Mozilla for example? or Google? even more so, why wasn&#x27;t control transferred to ICE for example?<p>Not saying it&#x27;s a better alternative or even that I agree with it, but it&#x27;s very VERY unsettling (and I&#x27;m not even American) that a corporation can basically say &quot;dibs on this&quot; backed up by a court order!<p>I would understand if the procedure went some more like, MS cries wolf, a court order is issued and a gov agency takes temporary control. At least it&#x27;s &quot;the government&quot; doing the policing (even if guided by a corporation or whatever).<p>What&#x27;s next now? Comcast and Verizon sending their IP Police to arrest you because they have a log showing piracy was downloaded at an IP owned by you? And they get to seize your stuff and now your house is a Comcast&#x2F;Verizon store?<p>Wtf is this? It&#x27;s so unreal.<p>Edit: typo
评论 #7970262 未加载
评论 #7970340 未加载
noipcom将近 11 年前
You can read No-IP&#x27;s formal statement here: T<a href="https://www.noip.com/blog/2014/06/30/ips-formal-statement-microsoft-takedown/" rel="nofollow">https:&#x2F;&#x2F;www.noip.com&#x2F;blog&#x2F;2014&#x2F;06&#x2F;30&#x2F;ips-formal-statement-mi...</a>
评论 #7968135 未加载
reality_czech将近 11 年前
People were starting to forget why everyone hates Microsoft. Even on this site, I see a lot of comments about how Microsoft &quot;isn&#x27;t so bad&quot; anymore. Hopefully this will lay that and similar naive comments to rest.
moe将近 11 年前
Wouldn&#x27;t it make more sense to make Microsoft financially liable for damages caused by their continued [criminal?] negligence?<p>[1] <a href="http://www.zdnet.com/after-seven-months-and-no-microsoft-patch-internet-explorer-8-vulnerability-is-revealed-7000029765/" rel="nofollow">http:&#x2F;&#x2F;www.zdnet.com&#x2F;after-seven-months-and-no-microsoft-pat...</a><p>[2] <a href="http://www.microsoftproductreviews.com/microsoft-news/internet-explorer-8-security-flaw-remains-unfixed-need-worry/" rel="nofollow">http:&#x2F;&#x2F;www.microsoftproductreviews.com&#x2F;microsoft-news&#x2F;intern...</a>
mschuster91将近 11 年前
Just ran a dig +trace on no-ip.biz. Just... wtf. Who had acted upon that court order?! I thought that the days the US had full control over the internet were LONG past. `<p><pre><code> biz. 172800 IN NS a.gtld.biz. biz. 172800 IN NS b.gtld.biz. biz. 172800 IN NS c.gtld.biz. biz. 172800 IN NS e.gtld.biz. biz. 172800 IN NS f.gtld.biz. biz. 172800 IN NS k.gtld.biz. ;; Received 308 bytes from 192.203.230.10#53(192.203.230.10) in 526 ms no-ip.biz. 7200 IN NS NS7.MICROSOFTINTERNETSAFETY.NET. no-ip.biz. 7200 IN NS NS8.MICROSOFTINTERNETSAFETY.NET. ;; Received 90 bytes from 209.173.58.66#53(209.173.58.66) in 150 ms no-ip.biz. 76834 IN NS nf5.no-ip.com. no-ip.biz. 76834 IN NS nf2.no-ip.com. no-ip.biz. 76834 IN NS nf4.no-ip.com. no-ip.biz. 76834 IN NS nf3.no-ip.com. no-ip.biz. 76834 IN NS nf1.no-ip.com. ;; Received 206 bytes from 157.56.78.73#53(157.56.78.73) in 344 ms</code></pre>
评论 #7968151 未加载
rblatz将近 11 年前
Their status twitter is interesting, they aren&#x27;t going into any details as to why their service stopped working, and they haven&#x27;t made any statements about the accusations against them.<p><a href="https://twitter.com/NoIPStatus" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;NoIPStatus</a>
评论 #7968128 未加载
motters将近 11 年前
So if I declare that the Bing web crawler is ignoring robots.txt and DDoSing my server then I can take over microsoft.com to &quot;clean&quot; out the bad stuff and redirect all traffic to zombo.com?
xxdesmus将近 11 年前
So based on Microsoft&#x27;s ingenious logic someone could get a court order and take over part of their business because they have so many infected Windows XP machines out there. Right?
rippa242将近 11 年前
I&#x27;m wondering how Microsoft managed to take down the noip.me base domain, since the court stated (footnote 1 on page 5 of the 2nd amended TRO, 2:14-cv-00987-GMN-GWF-019) that the noip.me domain is controlled by the country of Montenegro and outside US legal system control. While there are noip.me 3rd level domains in Appendix A of the TRO, mine were NOT listed and yet I&#x27;m being sinkholed by Microsoft.
tokenizerrr将近 11 年前
So does this mean no-ip.com is no more, or only a subset of their domains?
评论 #7967875 未加载
评论 #7969789 未加载
sanbor将近 11 年前
If the way to prevent malware is by blocking domains (which only prevent a few of them), with the same logic another great solution would be blocking Microsoft&#x27;s operating systems (which would prevent most of them).<p>Ubuntu should ask the government the same power and show how little malware Ubuntu users has and how much Windows users has to suffer.
vfclists将近 11 年前
When are a group of no-ip customers going to file a class action suit against Microsoft?<p>Just because an ignorant judge gave them access to some no-ip domains did not give them the right bite more then they could che and fsck it up.<p>The whole thing is just bizarre, WTF were they trying to accomplish? ie they took over the business of providing name service to over 4 million hosts, way bigger more than most large service providers with the intention of traffic to and from the C &amp; C servers, or identify which of the computers were infected and inform their owners?<p>Why didn&#x27;t they simply set up some monitoring devices and get the judges or the FBI to compel no-ip to allow them to plug it into their network so they could monitor what they wanted without disrupting the service?<p>If the no-ip owners were directly involved in the scam then why didn&#x27;t the hand the evidence to the law enforcement authorities and let them carry on from there?
kqr2将近 11 年前
Any alternatives for free dynamic DNS?
评论 #7967673 未加载
评论 #7967791 未加载
评论 #7967733 未加载
评论 #7967671 未加载
ars将近 11 年前
Wait what?<p>If I have a domain with no-ip.com will it continue to work? Does Microsoft effectively own them now?
评论 #7967788 未加载
评论 #7967787 未加载
hd502将近 11 年前
Complete BS. They claimed they were just going to stop bad traffic. But they can&#x27;t handle the overall traffic load and so NO traffic is getting through. I was using the service to provide access to an API server in-house. A very simple server, nothing but JSON requests in-and-out. Absolutely NO malware. But since MS takeover - no traffic has gotten through.<p>I pay for my noip account, so I&#x27;m happy to join any lawsuits against MS for this action. Personally, I see a class action suit being VERY viable.<p>I also have issue with the courts even allowing this. Did they do ANY research on what is actually going on? I can&#x27;t see how they could let this happen.<p>I feel violated!
dimman将近 11 年前
Do they want a thank you? So sad really because lately they&#x27;ve shown some small steps in what I thought was the right direction. Ignorance is bliss.
jajaja2014将近 11 年前
microsoft now spying legitimate no-ip trafic based on non applicable us laws?<p>fuck you microsoft!
Labrynth2014将近 11 年前
I would just add @andor, that the Police DO NOT own enough tools and equipment to do this. The Private sector has to, for better or for worse.<p>I have domains with NO-IP and I&#x27;ve had no problem with them. It would all have been better had Microsoft made a statement about seizing the DNS but I respect the DON&#x27;T TELL THE ENEMY WE&#x27;RE COMING AND ON TO THEM !
imrehg将近 11 年前
We are using a no-ip.biz address for the Taipei Hackerspace website (because need DynamicDNS due to stupid settings of our network provider). After the whole day it was still working, I thought we will be not affected. No such luck, microsoftinternetsafety.net took our address as well, and the website + all services associated is inaccessible.<p>Thanks a lot, M$!
评论 #7971747 未加载
jrs235将近 11 年前
So on a different side topic, if the service was free and I assume the TOS from noip didn&#x27;t guarantee an SLA, does this mean all the end users are basically out of Luke suing Microsoft for failure to properly resolve their domains?<p>If the cliche isn&#x27;t true, then I guess the next&#x2F;new one is, if its free you&#x27;re SOL.
bobloblawblah将近 11 年前
I use no-ip in conjunction with my phone. I get within 200m of home and my home computer gets wakeonlan&#x27;ed.<p>Today that didn&#x27;t happen.<p>I had originally blamed no-ip for this...<p>To me, Microsoft seems to be the bully and is now actually guilty of conduct No-IP was only peripherally involved in.
Geiko将近 11 年前
So shouldn&#x27;t Spamcop.net (or anyone else) be able to seize microsoft.com, outlook.com and hotmail.com. They have been blocking those email servers for years due to spam sent from their domains and email servers.
sakawa将近 11 年前
I guess this is a shortcut to solve some problems. No-IP domains are used only by who hasn&#x27;t a good infrastructure to support his infected network.<p>And especially, why don&#x27;t Microsoft take care of making his OS more secure?
deniska将近 11 年前
And I was wondering, why did my no-ip.biz subdomain stop working…
评论 #7967938 未加载
davidu将近 11 年前
This is an incredible action by Microsoft, and the courts.
andmarios将近 11 年前
Which dynamic DNS service will be next?<p>But I have a better idea. Windows are an easy target for cybercriminals; maybe someone should step up and take Microsoft down.
评论 #7969936 未加载
评论 #7967955 未加载
teddyh将近 11 年前
I suddenly feel a lot better for having set up my own dynamic DNS solution. (Using plain Dynamic DNS and nsupdate(1) on the clients.)
marcelocamanho将近 11 年前
Oh.. That explains the issues we were having today. This seems to be affecting our no-ip even when we have no malware or threat.
kurenyen将近 11 年前
I&#x27;ve spent years of efforts on my site, people like it, now it&#x27;s unreachable, fuck you Microsoft...
johnnyxp64将近 11 年前
what the fuck is wrong with the world this days!!!??? are you all in prison because few morons stole something??? wtf Microsoft is wrong with you and you damn courts!???? i will sue you bastards because i am loosing money due to your stupid actions!!!!
bluejellybean将近 11 年前
Holy fuck... if this doesn&#x27;t get solved my company is dead in the water...
评论 #7969988 未加载
Nanzikambe将近 11 年前
There are serious problems with this, firstly that it&#x27;s technically impossible to implement effectively, beyond that it&#x27;s extremely impractical. Any benefit will be so so transient as to render the entire exercise pointless.<p>For the moment, let us ignore the scary implications of the court&#x27;s part in this and consider this from a technical perspective in a logical manner:<p>The hypothetical sub-domain abc.no-ip.org resolves to 1.2.3.4, a host somewhere that contains malicious payloads, is botnet C&amp;C or is a member of a botnet. In any case, he&#x27;s the bad guy - one of the people Microsoft are looking to exclude from the Internet.<p>So how can this be accomplished? Let&#x27;s ignore for the moment that the bad guys are free to use any other dyndns service they please and assume that no-ip is the only one.<p>Approach 1<p>----------<p>Every time a host connects to no-ip to update its IP, Microsoft scans tcp &amp; udp ports of the host looking for known C&amp;C services, scans hosted data (public web or ftp). This will simply result in the bad guys hiding all of this in an undetectable manner, many bot-nets already use either Tor or SSH for C&amp;C - without authentication it will be impossible to differentiate Joe Average with an SSH or Tor exit from the &quot;targets&quot;.<p>As for scanning for content, this is possible assuming the content has to be public (ie. malicious payload) but even then, it&#x27;s not practical - payloads can be hidden in anything and obfuscated beyond detection. Essentially all that&#x27;s accomplished is another arms race based around signature detection for malicious content, with the disadvantage that unlike AV solutions this scanning is conducted <i>remotely</i> and the scan source is known. So the malicious guy with 2 or three lines just uses a stateful firewall to point microsoft&#x27;s &quot;scanning service&quot; to good content, everyone else to the bad.<p>So what other options are there? A blacklist of IPs? Well, they&#x27;re <i>dynamic</i> IPs, sooner or later you&#x27;ll end up with every dynamic IP in the entire ipv4 range blacklisted as the bad dudes just release&#x2F;renew.<p>Then there&#x27;s banning the sub-domains&#x2F;users! Also impractical because for each user and domain you ban, another will emerge.<p>Approach 2<p>----------<p>Microsoft resolves every request for abc.no-ip.org to their own service, all the time, this service performs stateful packet analysis before forwarding it on to the destination host. Impractical because you&#x27;re essentially routing <i>all</i> no-ip traffic via Microsoft and once again you can only filter what you can detect -- and once the requests themselves are encrypted, that becomes impossible. This is effectively a MITM attack.<p>All the while we&#x27;ve assumed no-ip is the only alternative, it&#x27;s not - and many others are beyond Microsoft and the courts jurisdiction. So ultimately the only way this &quot;approach&quot; could be temporarily feasible is if <i>all</i> Internet traffic were routed through Microsoft&#x27;s service. So effectively you need to give control of every domain, TLD, ipv4 and ipv6 range to Microsoft. Not workable.<p>Someone is bound to point out that Microsoft&#x27;s approach in this may be distributed, agents running on installs of their operating system which does address some aspects of my points above, but once again -- if Microsoft is capable of implementing effective detection on the workstation, remind me again why <i>any</i> of this is needed?<p>I must be missing something fundamental.
评论 #7973125 未加载
sadfaceunread将近 11 年前
Anyone got a link to the TRO? Is this part of the public record?
评论 #7968573 未加载
notsoMicrosoft将近 11 年前
Appears as though Level 3&#x27;s dns servers are still pointing where they should.<p>4.2.2.2<p>4.2.2.3<p>4.2.2.4
vfclists将近 11 年前
Loads of self-congratulating tripe. Microsoft why don&#x27;t you simply provide free OS upgrades or fixes for the millions of XP computers out there? They are not going anywhere soon.<p>Next thing we know your lawyers and lobbyists are going to come up with some legislative wheeze and you will be running the biggest botnet in the world. You created the problem so fix it yourself.
评论 #7967799 未加载
评论 #7968244 未加载
评论 #7967767 未加载
moblahbl4hblah将近 11 年前
All of you pant-shiting bitches...Oh Noes! MS took down a botnet...what&#x27;s to stop the court from giving my TF2 hosting domain?<p>Grow up. You guys bitch about malware. You bitch about MS. Mainly you just bitch...and talk about Haskell.<p>It&#x27;s boring.