The Hijacking of Perl.com
perl.com
perl.com
Couple of other issues: "It’s important to have one face (mouth?) to represent the diligent work everyone was doing." From the registar article: "the Perl team has yet to respond to our request for a comment"
And, I've fixed the broken image. Thanks for noticing that.
If the attack was mounted via faked documents which is what I think the article implied then 2FA would not have helped as it was attack on a procedure of replacing contact info.
[0] https://slashdot.org/comments.pl?sid=475216&cid=22665150
They tend to be complicated "nothing's easy about Unicode" type answers, which some users call out as pedantic. But I much prefer getting the full picture from an expert like him and then making pragmatic compromises myself where needed, instead of the usual quick and easy answers that end up being full of hidden traps.
[1] https://stackoverflow.com/users/471272/tchrist?tab=answers
- The Duct Tape Holding the Internet Together: https://medium.com/thisiscala/the-duct-tape-holding-the-inte...
- Sinkholed: https://susam.in/blog/sinkholed/
Disclosure: I am the author of the second story.
I also wondered if a domain name under a country code top-level domain (ccTLD) like .in is more susceptible to this kind of sinkholing than a domain name under a generic top-level domain (gTLD) like .com.
> I asked Benedict if it is worth migrating my website from .in to .com. He replied that in his personal opinion, NIXI runs an excellent, clean registry, and are very responsive in resolving issues when they arise. He also added that domain generation algorithms (DGAs) of malware are equally, and possibly more, problematic for .com domains. He advised against migrating my website.
You can check the status of a domain by looking for "Status: server{Delete,Transfer,Update}Prohibited" in the whois response for that domain [2].
[1] https://krebsonsecurity.com/2020/01/does-your-domain-have-a-...
[2] https://www.verisign.com/en_US/channel-resources/domain-regi...
But…be absolutely, 100%, certain that the information contained in the registry record is 100% accurate for name of registering organization and contact information. Because the process to unlock can be quite…difficult if the information is slightly off.
Seriously, transfer your domains to almost literally any other registrar. They'll be better than NetSol.
Off the top of my head: NetSol, MarkMonitor, CSC, maybe Cloudflare. There are more that will do it for specific ccTLDS (.ca has lots, for example).
https://fastmail.blog/2014/04/10/when-two-factor-authenticat...
Scary stuff. Basically we had 24 hours to dispute via email when a fax was sent to our registrar with a faked up Australian company registration and a fake passport asking to remove 2FA and change the owner email to an address @qq.com.
At the same time, our hostmaster email address had been signed up to hundreds of non-double-opt-in mailing lists, so that there was lots of noise for this email to be lost in.
We had to fight very hard to be allowed to see the fax that was allegedly from us, so that we could see what they had done.
But to the primary content - I've been surprised at just how ad-hoc much of the internet backbone infrastructure is as I've learned more about it. The same could be said about the payments processing industry! Beneath all the complexity and sleekness underlying the tools we use every day seems to eventually lie a system of IOUs, with an honor-based resolution mechanism between sufficiently trustworthy entities.
This is how societies - in the end - work. It is all about trust, I think.
And although there are forces to undermine that fundamental trust, it does still work.
Society is made out of string at best
I don't know what specifically would've tipped it the other way but I think there were several large players able to extend effort that ended up not doing so simply due to a lack of need (i.e. the military in a non-show manner).
Unanticipated in the Constitution was that a group of violent people would attempt to force Congress and the Senate to overturn the results. Had the protestors succeeded in that goal, it would have effectively ended the Republic. We would continue to be a Republic in name, just as Rome was after Julius Caesar crossed the Rubicon in 49 BC. But not in reality. And not too many years would pass before even that charade ended. As happened in Rome when Augustus Caesar became the first real emperor.
That layer of defense can't be taken for granted, especially given how aggressively hostile towards reality itself many local GOP officials are becoming.
Isn't this preventable with "clientTransferProhibited"[1]?
> This status indicates that it is not possible to transfer the domain name registration, which will help prevent unauthorized transfers resulting from hijacking and/or fraud. If you do want to transfer your domain, you must first contact your registrar and request that they remove this status code.
If nothing else, you'd think that some simple monitoring would be warranted if you own an important domain, like checking the exit code of:
# whois -h whois.verisign-grs.com google.com | grep "Registrar: MarkMonitor, Inc."
[1]: https://www.icann.org/resources/pages/epp-status-codes-2014-...
There are more secure registrars than network solutions that require much more to transfer, like others have executive lock. You can specify certain terms that must be done before a change. Like the registrar must call you on a certain phone number and get a password verbally.
At DnProtect, we are aware of at least 20 domains that have been stolen since the beginning of the year. Most from network solutions.
The hijacking of perl.com was front page news for the technical community. Did the thief really think they'd just be able to drop it on Sedo or Afternic and be done with it?
I’m aware of at least half a dozen or so domains that were stolen at the same time, by the same domain thief.
This was not an attack or hijacking. It was the stealing of domain names.
What these domain thieves do is steal the domain, transfer it to another registrar, then attempt to sell them.
In this case, Perl.com just got caught up in a list of domains that were stolen at the same time. Others stolen at the same time also start with the letter P.
Look, if your domain is with Network Solutions, and you missed the other wakeup call[1] to get off of them; let this be the wakeup call.
Network Solutions was the right (only) choice for domains in the 90s, but it hasn't been the right choice for domains in probably two decades.
[1] https://www.theguardian.com/technology/2013/oct/08/whatsapp-...
That said I've seen registrars make some glaring mistakes in the past and many still rely on faxed documents to authorize domain transfers, so it's not a surprise that stuff like this happens. Often, all it takes is finding out who's the registrar (easy), obtaining a blank transfer authorization form from that registrar (easy again), obtaining the personal or company data of the domain owner (a bit more difficult but still doable), fill out the form and fax it in. Some providers won't even bother to send you a notification when transferring the domain, so like here the legitimate owner won't notice it's gone before it's way too late.
Since the domain is that old ("This domain was registered in the early 90s" according to the article), was there really a choice? IIRC, back then the only domain name registrar available was Network Solutions.
Creation Date: 1994-08-16T04:00:00Z(There's a joke somewhere in here about how readable Perl is.)
Essentially, someone took over the Network Solutions domain management account for the domain and transferred it to a different registrar.
It's not clear if that was due to a weak password, compromised contact email account, someone social engineering the Network Solutions staff, or something else.
We probably will never know how it was done, as network solutions won’t say, and they shouldn’t.
It would be nice if, you know, people just did their jobs impartially regardless of whether they know or like you. But the reality is that not knowing the "right people" does indeed make things much harder, as we hear often here on HN from small businesses trying to deal with the tech giants.
People forget passwords, lose 2FA devices, etc all the time. Many of the usual methods can be hijacked much more easily than you might think. It's tough to make the right call for legitimate user who messed something up versus a particularly sly attacker every time without some out-of-band personal knowledge about the person in question.
All of the fancy tech in the world can't beat "Hey, I know Tom pretty well, this doesn't seem like something he would want to do. Maybe I better ring him up through a medium I trust to confirm this before I do it."
The website for Perl is perl.org and was not affected at all by the perl.com hijack.
> Since 1997 Perl.com has been the home for quality articles about Perl programming, news and culture. The website is managed by the The Perl Foundation.
They might want to update this if it isn't the case.
He bought the domain, set up the email admin@suchandsuch.com and reset the debt collectors main domain by requesting a transfer to another domain provider, it then sent an email to the domain record holder and he took over their domain.
Never use the same domain or another domain for registrant emails and buy privacy. use a gmail or your isp provided email.
Which is ironic as that is literally the opposite of the Perl programming language itself.
I wrote in Perl, Python, and Julia this month (yeah, 1st day). Probably will have some C++ and R as well later. We'll see.
It's lightning fast, it's mature, every problem is solved, it still works great out of the box, and compatible with just about every web server out there.
By "mature" I mean that any question I google there is real content, and not just StackOverflow. Real web-based knowledgebases which also happen to be lightweight HTML, without JS required, and with real solutions to the problem.
It helps that I try to build and maintain two versions of the same codebase, so I tend to write in a language which is the lowest common denominator of PHP and Perl.
I'm at a modest 14K lines now, and still find that I can find what I'm looking for with just a global text search...
This would make the situation better in two ways:
1: A normal domain move can only happen when the domain owner signs the transaction. If the domain owner claims to have lost their key, this would raise a red flag and result in an in-depth analysis which the domain owner has to pay.
2: The movement of the domain would be announced on the block chain. So in case the in-depth analysis has been tricked by an attacker, the righteous owner would be alarmed immediately. For this they would use some service that monitors the blockchain for them. They could then reverse the transaction with their key.
You can't move most domains without written consent of the domain owner and you'll have to properly identify yourself before requesting that.
In the end it's about how the registrar handles those things.
This is how DENIC handles those things at least.
I actually can't tell if you're being serious, or if this is satire about the fact that people think "the blockchain" can just be sprinkled and solve any problem.
I'd certainly pay for this service.
Imagine domain names actually being secure, like bitcoin is secure.
I've posted this idea here before and also got shat on and downvoted to oblivion.