logoalt Hacker News

DNS Abuse and Criminal Infrastructure

21 pointsby jruohonenyesterday at 2:30 PM8 commentsview on HN

Comments

SpaceLawnmowertoday at 3:20 PM

This article is pretty light on details. The linked presentation goes into a lot more detail with statistics about which registrars and organizations are the worst offenders etc.

https://view.officeapps.live.com/op/view.aspx?src=https%3A%2...

edenttoday at 2:42 PM

I have some experience of dealing with this when working for .gov.uk

A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims.

By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists.

At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?

I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless.

show 1 reply
azeembatoday at 2:50 PM

I agree with the premise but this article doesn't really provide a strong argument. It mentions stats about child exploitation but doesn't show how that's related to gtlds.

Stats about the block list are good (10% of gtld domains are blocked) but thay requires comparing it with a baseline. How many of non gtld domains are blocked?

thataccounttoday at 2:51 PM

The internet DNS system is broken in multiple ways. We would do better to have a shared DHT table with unique keys addressable to names.

TZubiritoday at 3:29 PM

If you are thinking of launching your own TLD, or second level tld, or effective TLD (like vercel.app). I suggest being creative instead of making yet another TLD with the standard checkbox rules.

If your TLD is location based for example, consider verifying and linking the TLD to an identity, by local means, like a national ID.

fenestellatoday at 3:42 PM

[dead]

thinkaftertoday at 3:04 PM

[flagged]