[HN Gopher] Sinkholed: A DNS Horror Story (2019)
___________________________________________________________________
Sinkholed: A DNS Horror Story (2019)
Author : susam
Score : 52 points
Date : 2023-07-07 19:23 UTC (3 hours ago)
(HTM) web link (susam.net)
(TXT) w3m dump (susam.net)
| teddyh wrote:
| So, nothing to do with the actual DNS, but instead with the
| domain name registrar.
| klysm wrote:
| Nothing to do with DNS? Just something to do with the
| organization that controls some DNS records
| teddyh wrote:
| At least, not a technical problem, and not even with the zone
| for their domain, but with the zone of the .in domain.
| [deleted]
| inopinatus wrote:
| systems include people
| e63f67dd-065b wrote:
| This is actually terrifying to me. If my domain goes, so goes my
| email -- everything is @myname.com, so I won't receive any email.
| If my email is gone then I just instantly lost access to a big
| chunk of the internet services I use, and my online identity
| might as well be dead. Sure I still have my work email but that's
| no consolation for all the services registered to my domain
| email.
|
| I'm not sure what the right course of action here is to mitigate
| such a risk. Add backup emails on a different domain registered
| with a different registrar to services that support such a thing?
| Stop worrying because it's rare enough that it's a waste of time?
| Is this what happens to people that get banned on gmail?
| nucleardog wrote:
| It's a rabbit hole to go down, for sure.
|
| I spent a while one week going through all my online identity,
| services I use, etc and putting together basically a dependency
| tree.
|
| What kicked this off was an overlapping but probably more
| unusual concern. Basically, I was worried that I had things
| _too_ secure. If I lost certain access, I'd be _screwed_. It's
| great that this account needs 45 factor 6 dimensional
| holographic password authentication to log in, but what happens
| if I lose something or get bonked on the head and forget
| something or... how can I recover access, but also set this up
| in a way where the backdoor I leave is _not_ once that's easily
| accessible to others.
|
| Anyway, long story short is I have a separate ccTLD domain from
| my country that is _exclusively_ for use as the root of my
| identity/recovery. Everything related to it is in a separate
| account. It charges to a credit card that's not used for
| anything else. The only thing it does is receives email and
| dumps them into object storage so I can periodically review. (I
| don't want them forwarded elsewhere in case the email is
| something like a password recovery email.)
|
| The recovery solution for this is the ccTLD's dispute
| resolution policy, and finally my (local) courts. As sexy as
| that Cocos Islands or Indian Ocean Territory or vanity TLD is,
| I have a lot more options more easily available to me with my
| local ccTLD administrator and local courts. I'm pretty much
| relying on the court's ability to accurately verify my identity
| as the lock on the back door.
| Arnavion wrote:
| Yes, different domain on a different registrar is the usual
| solution.
| qingcharles wrote:
| I've recently been through this and it is a total nightmare. I
| lost my phone number too, so there was no way to use that
| validation channel. And many systems have no human support now,
| so you are super screwed.
|
| And then things break for no reason at all and panic the shit
| out of me. My Namecheap TOTP stopped working today for no
| reason at all. So I had to go through hours of support to
| verify my identity, but the whole way through I was thinking
| "What if I can't verify?"
| cryptonector wrote:
| > Unfortunately, their operation inadvertently flagged my domain
| name as one of the domain names to be sinkholed because it
| matched the pattern of command and control (C2) domain names
| generated by a malware family named Nymaim, one of the malware
| families hosted on Avalanche. Although, they had validity checks
| to avoid sinkholing false-positives, my domain name unfortunately
| slipped through those checks. [...]
|
| That's incredible. That "[the domainname] matched the pattern of
| command and control (C2) domain names generated by a malware
| family named Nymaim" was enough to get it sinkholed is nuts.
| There should be a fair bit of manual checks here before applying
| this sort of death penalty.
|
| Take my username. I actually got targeted by my bank some years
| ago for a similar reason: "crypto" surely means you're doing
| crypto-currencies, right?, so you must register as a money
| services business (MSB)! Uh, no, nothing of the sort, and
| thankfully I was able to disabuse them of the notion that I had
| anything to do with crypto-currencies. (Indeed, I'm vehemently
| opposed to proof-of-work currencies, and as for proof-of-stake,
| why not just do double-spend detection and leave it at that?)
| KirillPanov wrote:
| Reminder: you can't really own a domain name.
|
| Use public keys instead. Like i2p and tor do.
| klysm wrote:
| Unfortunately the rest of the world uses DNS
| nvy wrote:
| I like to be able to actually tell someone my domain name/email
| address/etc., verbally.
|
| Rattling off a 56-character base32 string just doesn't work.
___________________________________________________________________
(page generated 2023-07-07 23:00 UTC)