[HN Gopher] Sinkholed: A DNS Horror Story (2019)
       ___________________________________________________________________
        
       Sinkholed: A DNS Horror Story (2019)
        
       Author : susam
       Score  : 52 points
       Date   : 2023-07-07 19:23 UTC (3 hours ago)
        
 (HTM) web link (susam.net)
 (TXT) w3m dump (susam.net)
        
       | teddyh wrote:
       | So, nothing to do with the actual DNS, but instead with the
       | domain name registrar.
        
         | klysm wrote:
         | Nothing to do with DNS? Just something to do with the
         | organization that controls some DNS records
        
           | teddyh wrote:
           | At least, not a technical problem, and not even with the zone
           | for their domain, but with the zone of the .in domain.
        
         | [deleted]
        
         | inopinatus wrote:
         | systems include people
        
       | e63f67dd-065b wrote:
       | This is actually terrifying to me. If my domain goes, so goes my
       | email -- everything is @myname.com, so I won't receive any email.
       | If my email is gone then I just instantly lost access to a big
       | chunk of the internet services I use, and my online identity
       | might as well be dead. Sure I still have my work email but that's
       | no consolation for all the services registered to my domain
       | email.
       | 
       | I'm not sure what the right course of action here is to mitigate
       | such a risk. Add backup emails on a different domain registered
       | with a different registrar to services that support such a thing?
       | Stop worrying because it's rare enough that it's a waste of time?
       | Is this what happens to people that get banned on gmail?
        
         | nucleardog wrote:
         | It's a rabbit hole to go down, for sure.
         | 
         | I spent a while one week going through all my online identity,
         | services I use, etc and putting together basically a dependency
         | tree.
         | 
         | What kicked this off was an overlapping but probably more
         | unusual concern. Basically, I was worried that I had things
         | _too_ secure. If I lost certain access, I'd be _screwed_. It's
         | great that this account needs 45 factor 6 dimensional
         | holographic password authentication to log in, but what happens
         | if I lose something or get bonked on the head and forget
         | something or... how can I recover access, but also set this up
         | in a way where the backdoor I leave is _not_ once that's easily
         | accessible to others.
         | 
         | Anyway, long story short is I have a separate ccTLD domain from
         | my country that is _exclusively_ for use as the root of my
         | identity/recovery. Everything related to it is in a separate
         | account. It charges to a credit card that's not used for
         | anything else. The only thing it does is receives email and
         | dumps them into object storage so I can periodically review. (I
         | don't want them forwarded elsewhere in case the email is
         | something like a password recovery email.)
         | 
         | The recovery solution for this is the ccTLD's dispute
         | resolution policy, and finally my (local) courts. As sexy as
         | that Cocos Islands or Indian Ocean Territory or vanity TLD is,
         | I have a lot more options more easily available to me with my
         | local ccTLD administrator and local courts. I'm pretty much
         | relying on the court's ability to accurately verify my identity
         | as the lock on the back door.
        
         | Arnavion wrote:
         | Yes, different domain on a different registrar is the usual
         | solution.
        
         | qingcharles wrote:
         | I've recently been through this and it is a total nightmare. I
         | lost my phone number too, so there was no way to use that
         | validation channel. And many systems have no human support now,
         | so you are super screwed.
         | 
         | And then things break for no reason at all and panic the shit
         | out of me. My Namecheap TOTP stopped working today for no
         | reason at all. So I had to go through hours of support to
         | verify my identity, but the whole way through I was thinking
         | "What if I can't verify?"
        
       | cryptonector wrote:
       | > Unfortunately, their operation inadvertently flagged my domain
       | name as one of the domain names to be sinkholed because it
       | matched the pattern of command and control (C2) domain names
       | generated by a malware family named Nymaim, one of the malware
       | families hosted on Avalanche. Although, they had validity checks
       | to avoid sinkholing false-positives, my domain name unfortunately
       | slipped through those checks. [...]
       | 
       | That's incredible. That "[the domainname] matched the pattern of
       | command and control (C2) domain names generated by a malware
       | family named Nymaim" was enough to get it sinkholed is nuts.
       | There should be a fair bit of manual checks here before applying
       | this sort of death penalty.
       | 
       | Take my username. I actually got targeted by my bank some years
       | ago for a similar reason: "crypto" surely means you're doing
       | crypto-currencies, right?, so you must register as a money
       | services business (MSB)! Uh, no, nothing of the sort, and
       | thankfully I was able to disabuse them of the notion that I had
       | anything to do with crypto-currencies. (Indeed, I'm vehemently
       | opposed to proof-of-work currencies, and as for proof-of-stake,
       | why not just do double-spend detection and leave it at that?)
        
       | KirillPanov wrote:
       | Reminder: you can't really own a domain name.
       | 
       | Use public keys instead. Like i2p and tor do.
        
         | klysm wrote:
         | Unfortunately the rest of the world uses DNS
        
         | nvy wrote:
         | I like to be able to actually tell someone my domain name/email
         | address/etc., verbally.
         | 
         | Rattling off a 56-character base32 string just doesn't work.
        
       ___________________________________________________________________
       (page generated 2023-07-07 23:00 UTC)