This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
Where are you going to run off to? How is their security better over there? How many hours of work does that involve?
I think you're looking more kindly on their security practices than most folks in the security world would.
DO knows people can do this, but they don't want people to do it.
Remembering 2 recurring DNS servers is easier for bulk management than a bunch of different ones.
You don't test services like that, it can negatively affect other users.
Response wasn't perfect but it was reasonable.
I'm sorry, "We aware that we make it easy for about 20k domains to be directed to a malicious host, but we're not going to do anything about it" is reasonable?
But of course, it's because Matt "was messing around with things he shouldn't be". It's all solved - we just need everyone to stop doing things that DO "don't want people to do".
If the domain is added to the account there is no PoC, it's only for domains that have been removed from accounts but still have the nameserver values(meaning the domain is not being used at this point, there's no zone file if it isn't added to an account).
So this is mostly only going to affect currently derelict domains. I'm not saying it isn't something to worry about, but I do think it's a reasonable solution.
(Obviously when I say somebody else's NS I mean a NS they have zero reason to think would respond with correct records. Obviously not talking about outsourcing DNS hosting.)
If I remove my domain from Digital Ocean, it's my responsibility to then go to the registrar and point the registrar away from DigitalOcean's nameservers. (I own the domain, so I'm the only one the registrar allows to do this. Digital Ocean cannot do this.)
Now, your suggestion is that Digital Ocean goes and verifies that I'm the one who owns that domain. But how would they do this (legitimate question)? I imagine manual verification of ownership of every domain upon creation isn't feasible for their scale. Digital Ocean could query DNS, and see NS records pointing to Digital Ocean, but this only tells them someone configured the nameservers for that domain - it doesn't imply ownership. Digital Ocean can check Whois for the owner of the domain. Checking Whois might work for many cases, but at least some registrars have the option of obscuring Whois data.
It seems simpler to put the onus of security on the owner of the domain. I should cleanup my registrar's NS records before removing my domain from Digital Ocean to ensure nobody hijacks it. I would be satisfied as long as Digital Ocean maintained a simple eviction policy (I don't know if they do) as a way for legitimate owners to add their domains to Digital Ocean's nameservers.
I'd much rather know about this vulnerability via a researcher than when a high profile company loses control of their accounts / domains.
Those aren't mutually exclusive. It's certainly possible to be broken by design.
> This would only happen if it's something you're not using anymore
From the writeup it seems like it would also happen if you registered a new domain and assigned the DO name-servers but didn't immediately point it to something.
However it's the way I've always done it, because otherwise somebody else could add the domain first... it just made sense to me I guess.
[1] https://serverpilot.io/community/articles/how-to-configure-d...