The Hostile Takeover of no-ip.com

This is just a warning of what will become of the Internet when judges and government agencies inject themselves into technical issues

First a brief explanation of what no-ip.com does. Let’s say you had a web server hanging from your Time Warner Cable account, and the IP address constantly changes. You want to people to be able to reach the web site at www.streamingradioguide.com, even if the IP address of the connection changes. This is a non-issue for me, since my IP hasn’t changed in six months – if it did change often, I would have to manually set my new IP address. That requires that I notice it changed, am not asleep, and even so the web site would be unreachable for up to 3 days [typically more like 4 hours]

So someone a very long time ago came up with the idea of “Dynamic DNS” to allow a redirection service to automatically follow my web server, no matter what its current IP address is. If you’ve ever poked around in your router, you may have seen DDNS and kept far away from it 🙂

ddns

I would go to the DDNS provider (like no-ip.com) and create an account – then this screen would login to my account and do the busy work to make sure that srguide.no-ip.com always pointed where it needed to be. My own DNS would stop being involved, and just answer “I don’t know – go to srguide.no-ip.com”. This adds a second step for visitors behind the scenes, but you would barely notice the speed difference.
—– end background material ———

Microsoft decided that it is fed up with people turning their Windows machines into Swiss cheese and went to a judge and demanded that the no-ip.com domain be forfeited to them because no-ip.com “allowed” hackers to use their service…. by creating imabadguy.no-ip.com, hackers would stay on the move by using a redirection service. The Judge said “That sounds resonable!” and granted the order for Microsoft to take over another company’s business.

http://www.noip.com/blog/2014/06/30/ips-formal-statement-microsoft-takedown/

noip.com is a global company – there are an estimated 4 million web sites that depend on this service. Each time a visitor goes to one of those web sites, it generates a DNS request – which is billions of requests per day. Microsoft turned 4 million web sites dark in an instant.

Their “purpose” in doing this is they want to be able to “filter” out “bad web sites” [“bad” in their opinion with no independent oversigh] . If they had pulled this off without dropping the ball, Microsoft would be acting as a DNS proxy, being able to watch (and LOG for the NSA) every single attempt by people to use one of the 4 million web sites all over the world. If I’m on the jury, I’m awarding no-ip.com $100 billion in damages for this.

This entry was posted in Collapse of America, Global Instability. Bookmark the permalink.

16 Responses to The Hostile Takeover of no-ip.com

  1. Microsoft’s alleged failure to ask no-ip.com to help get rid of the bad actors should have had some effect on a judge — is it possible that no-ip.com wasn’t given notice about the impending action?

  2. Nidster says:

    Doesn’t Microsoft have a history of stomping on whomever they wish? Gotta be partly because of the huge campaign donations they make, and in addition it could be those big, fat, un-addressed, un-stamped, white envelopes they hand out to the Criminal Class.

    • Art Stone says:

      Yes they do!

      One little insight I remember reading about Bill Gates. Back when he was single, he was dating a woman who worked for another technology company. During the course of their date, she happened to mention some project her company was working on. Gates immediately went back to Microsoft and started working on a competitor to put them out of business. Needless to say, she did not become Mrs. Bill Gates. In my deep dark thoughts, I wonder if Bill Gates’ child was the result of artificial insemination.

      You know, I don’t miss using Windows at all. Having the test machine be another identical Fedora Linux machine speeds up my development enormously, has the last couple days have demonstrated.

      There are a few quirky things like how copy/paste works but general web browsing and playing RuneScape is much faster and more reliable.
      I’m able to access my old Excel spreadsheets sitting on the windows disk without having to boot Windows or run a windows emulator like WINE or a virtual machine.

      Today, I let Fedora take over responsibility for my email account. All that it needed was to know my email address, and then prompted for the password one time. That’s it. I’m immediately able to access my Gmail account without having to go through a web browser and it worked the first time

      • CC1s121LrBGT says:

        A few years back, I had suggested that readers consider the free Linux rather than the endless upgrade fees from Microsoft – it has a free browsers and a free Office suite compatible with Windows.

        I had suggested that it is a good option for most users that just use web sites, send emails, use spreadsheets, documents and presentations and they my 6 year old had no difficulties. I advised against it for people that had custom code or needed to run unique or less common apps, or specific Microsoft micros in Office. You had cautioned against that and cited some of the technical issues you had running a development environment and server with it.

        I am curious on your perspective today after reading your post above. It seems that you might be warmer toward it than before.

        • Nidster says:

          Of course your reply is not directed toward me, but I just need to acknowledge I have to use proprietary software that is captive to Microsoft, and all condolences are accepted.

  3. Art Stone says:

    As a rough analogy, this is like if Pizza Hut was having problems with AT&T cell phone users ordering 1000 pepperoni pizzas as a prank – going to a judge and demanding that every phone call made by an AT&T cell phone by routes through Pizza Hut’s PBX so they could catch the people placing the fake orders.

    This puts in clear focus why the rest of the world doesn’t want the US government controlling .com – if the .com root server was controlled by a global entity, a US Judge would not automatically have his orders followed

    I think this episode is a big enough deal it will accelerate the end of US control. The mechanisms are in place to create new TLDs. The powers that be could create a .ddns top level domain in a day. no-ip.ddns would be outside the immediate jurisdiction of US laws (like the DMCA) and more insulated from US judge’s demands

    • Art Stone says:

      Microsoft may have control of the domain, but they don’t have control of the customer database to authenticate the “dynamic” IP addresses as they happen. Microsoft also does not have a contractural relationship with the legitimate no-IP customers.

      Microsoft maybe can shut the system down, but they are going to get their ass reamed if they intercept login requests. Since when is Microsoft a law enforcement agency? Maybe the US Marshall’s service deputized them.

  4. Art Stone says:

    As an aside, the “disabled” drop down doesn’t have a list of known DDNS companies. My suspicion is TWC has remotely disabled this functionality to prevent residential customers from running servers. AT&T uVerse in CT had no issues with that – this is not 1996. If I’m strong armed by TWC, the web site could vanish in the blink of an eye..

    • Nidster says:

      SHTF if you shut this down. Hells Bells, its the only oasis of sanity and reasonable thought that I’m able to take refuge.

    • Art Stone says:

      I control the domain. If my Internet provider blocked the server or terminated my service or my condo burns down, my cell phone still will work and I would redirect the domain to the temporary page I created on Google when I was in transit from Chicago to Charlotte with the server. I would keep people informed from there of whatever plans I have.

  5. CC1s121LrBGT says:

    You can probably flash the firmware with the stock firmware for the device.

    Even better, in terms of locking out external control, you may be able to flash it with firmware from http://www.dd-wrt.com/site/content/heartbleed-dd-wrtdd-wrt-online-services if your device is supported.

    • Art Stone says:

      Since I don’t need dynamic DNS, I’m not going to pick a fight.

      Comcast customers are having their residential routers turned into xfinity public wifi hot spots. I can’t wait to see how aggressive they become running over their customers once they merge.

  6. Art Stone says:

    As of Thursday, the company has all of their seized domains back. The .org registrar took them back from Microsoft’s control

    Without the ability to authenticate DNS changes as they expired, the 4,00,000 web sites all around the world became unreachable. If Microsoft faked authentication, those evil hackers in Kuwait would have 4,000,000 sub domains to hit Microsoft with. The alternative would be a “man in the middle” attack with Microsoft passing through the updates to the real servers. That’s got to be blatantly illegal. A little more technical research is needed…

    • Art Stone says:

      Here are the details
      http://www.noip.com/integrate/request/

      They made a curious design choice – embedding the userid and password in the URI itself when your router sends an update message. If the request is sent using http://username:password@…//, that would expose your credentials to anyone with ability to snoop on the message traffic. Even if you used https://, the DNS server doing the request would see your password

      I can’t imagine any equipment manufacturer doing that. If they used https:// and pass the user:password as a GET or POST variable, Microsoft would be unable to process the request as they don’t own the site certificate used to authenticate and encrypt the message. Hence the “technical error”

      Who decided that Microsoft has the standing to decide which certificate authorities can be trusted? Could/did they take over the certificates of those domains and say that they are not just the domain, but the actual business?

      The noip folks are no fly by night shady company. This interface is Integrated into gear from linksys, Cisco and netgear, among others. Those companies have scary lawyers, too.

      • Art Stone says:

        Making it even worse, telling DDNS your new myip is optional and probably rarely done – the IP of the address where the request came from is used.

        If Microsoft put itself in the middle as a “filter”, not only would the DNS update messages come to them, but a large portion of all the web traffic headed toward 4 million web sites

  7. Art Stone says:

    Has anyone ever committed criminal acts using hotmail email accounts?

Leave a Reply