Dangerous Gift
tbray.org
tbray.org
Undergrads sent emails like that for the lols. Recipients got freaked out they'd end up on some government watch list.
https://www.gawker.com/the-words-that-will-get-you-in-troubl...
Unfortunately, re: swatting via an non-tech-savy LEA and domain registrars: you could likely just update the contact details on a domain you own to the intended target and that'd probably be enough.
[1] https://www.coindesk.com/markets/2021/10/20/vitalik-buterin-...
The problem with NFT wallets is that you can send someone something which will then be publicly visible and associated with them, without their consent.
Domain ownership does not have this property. "WhoUsedToBe" is not a well-known database.
Realistically, lots of people would do this because the complexity of blockchain tech is beyond most peoples' grasp, but there is a reasonable failsafe at least.
This is light on details, but as I said, the only way another address can spend a users tokens is if the victim address approves it (or if the token is not ERC20 conforming). This approval might be what the article refers to here as signatures.
Alternately, this attack could somehow get a user to reveal their private key, in which case, of course an attacker has access to their funds.
Yes. Someone owns the location that's the "center of the United States" for broken IP address lookups. MaxMind gave 38 north, 97 west as the default location for 600 million IP addresses. It's a farm in Kansas.[1] MaxMind did that for 14 years. The farm was regularly visited by law enforcement, looking for various people.
[1] https://web.archive.org/web/20160817013603/http://fusion.net...
edit:
>Following Hill’s extraordinary piece in Fusion, MaxMind shifted its default “United States” location to the center of a lake, west of Wichita.
'Uncle Milton Industries has been selling ant farms to children since 1956. Some years ago, I remember opening one up with a friend. There were no actual ants included in the box. Instead, there was a card that you filled in with your address, and the company would mail you some ants. My friend expressed surprise that you could get ants sent to you in the mail.
I replied: “What’s really interesting is that these people will send a tube of live ants to anyone you tell them to.”'
(A collection of musings on the difference in mindset between "Moving the domain to a friend is okay" and "Wait, you can move the domain to anyone? How do you not see the issue with that?")
Having to registrar a domain, come up with some content, or just point the domain at some content ... then transfer it ... and then make a big deal out of it (getting attention is hard) and hoping nobody notices the easy to prove explanation that "someone transferred this to me" ... and avoiding getting caught seems like a big ordeal.
The story here is "hey random guy also hosts horrible stuff at his domain that he registered in his own name ... well he did". Maybe some folks run with that, but I'm not so so sure.
The mechanism here seems "easy" on the surface, but actually rather complicated, and odds of success seems low.
ADDED: While this process should probably be fixed in this case, at the end of the day, there's probably no foolproof way to keep people from sending you illegal stuff in either the physical or digital world in general.
1. Somehow you get the IP address of the target maybe by playing a game with them (which can be p2p) or some other way of getting the IP address and then geolocating (this can partially be avoided by using a VPN 2. If someone is live-streaming outside in the real world you recognize where the person is.
I haven't heard of someone being SWATed by a nefarious actor inside a company and never really a domain probably because you either purchased some protection plan to avoid spam so that if someone looks you up on the domain they won't find any information and also most people don't self host things using their own domain.
With that said that doesn't mean it is impossible to occur. For example Krebs on security has had SWATing attempts due to the content he posts. If you aren't live-streaming video games or doing IRL posts and or not reporting on bad actors you should consider other things to worry about.
A third requirement is living in a country with an overaggressive police force with more guns than some they know what to do with ready to shoot your dog or anything else that moves.
Not that it doesn't make sense to consider this situation when designing systems such as domain transfers, but this is the "Real Problem"™ IMO.
IP geolocation is not anywhere near precise enough to get you an address. It can give you a best-guess as to what city you are in (and even that is a guess), but not much better. If you aim to swat someone and you only know the IP you would contact the police who would contact the ISP to get your address connected to the internet subscription.
These morons got our poor mail server blacklisted in some super-exotic way that required several days of escalations to sort out. Moreover, they did it more than once, several months apart, each time causing a week of non-deliverability problems, and it took us a damn long while to add 1 and 1 to see why it was happening. Stopped reporting the abuse to them after that and all is good now.
> 1.2 "Designated Agent" means an individual or entity that the Prior Registrant or New Registrant explicitly authorizes to approve a Change of Registrant on its behalf.
Unless there is some other mechanism for preventing the Registrar from also being Designated Agent, it might be that R has terms in its EULA where registrants agree that R is also Designated Agent.
Spam email is the most common, but the same problem exists for people sharing things in Google Drive.
I had a password manager application that allowed you to share password entries to anyone else who has an account with that password manager company. The app/site actually did require you to approve the incoming entries, but didn't let you know what was in them, how many there were, etc.
Because if you look at GoDaddy (probably R) domains that are "privacy protected" you see the registrant is actually "Domains By Proxy, LLC" and switching that domain to another GoDaddy account would be invisible on the whois system.
It's still a silly setup - but then again, we have the same thing in banking - I could send you funds if I know your routing and ACH number (which is available on any of your checks, etc). So if I were a big crime lord I could randomly send money directly to people I didn't like so they'd go down with me.
There are available for $5 per year but need to publicly show your details
What's more frustrating is when software designers / product managers / business-ey people forget that "we can't trust people."
That depends…. with the right R I could see it. The tech person I interact with (rarely) at nearlyfreespeech.net deeply gets it — tech, business, legal. I doubt he’s a lawyer of course, but expect he knows when to get them involved. Probably the owner of the whole operation, if I had to guess.
And yes I realize they are probably just front ending for the real registrar, but to me they are effectively the registrar; not here to argue about that.
Here's a common one: a platform allows you to create teams and invite other users to be members of those teams. The teams that a user is a member of are shown on their profile.
Someone could create a team called "Paid up members of the Nazi party" and add people as members!
That's why it's crucial to have a "accept invitation" step if you build anything like this.
Getting a lot of press these days is the similar thing where you can transfer an NFT to someone's wallet without their permission.
Did they reset the DNS information? Because that's all that's really needed to prevent the sort of weird malicious behavior he's describing.
I believe for example, that it is extremely rare to have your door knocked down here in the UK. The police will generally politely knock and or ring the doorbell, and only knock your door down if you refuse to let them in.
I highly doubt that this is going to be the case if the warrant says that you’re wanted for child abuse imagery or human trafficking. I’m sure they’re lovely for small infractions, though.
There’s no need to send the swat team for a non-violent non-organised criminal, monster though they may be.
> I highly doubt
At least on paper UK police aim to take a more evidence-based light-touch community-building approach to policing, so I'd be curious what reasons you have to doubt this claim?
The assumption that US morality and culture applies globally is tiring and misses out on an opportunity for learning through comparison.
It is a problem with the justice system.
It is also a problem with the registrar. The registrar operates in this environment and is seemingly breaking official ICANN rules.
If that happens, you'll get arrested in front of at least some of your neighbors, who might also find out why you were arrested. (Even some of the local cops might think you're just getting away on a technicality.) Eventually being found innocent or not charged may not matter to some of them.
You will be in jail, at least for a while. You now have an arrest record. When people ask, "Have you ever been arrested," the answer will be "Yes." You might lose your job.
Your computer equipment will be seized and police will go through it. It'll be used against you in and out of court—even things that are legal—if they think it makes you look bad or will get you to talk. Getting that equipment back after charges are dropped or you are found innocent in court may or may not be slow and byzantine.
You will need to pay a lawyer, both to defend yourself, and to help you get your equipment back.
...
Yes, this is all fixable... if you are not poor and not rather unlucky. But it will take time and money. Even if you don't lose your job, I'd estimate that it would cost you $20K on the low end for legal fees.
Also, if you've done anything else even slightly illegal, and the LEA finds evidence of that when searching your stuff, even though you've been careful and haven't had cause to attract their attention previously... well... that's another whole bunch of trouble.
The class issues are enormous; if you’re wealthy enough to be able to defend yourself, you’ll still only be treated with something only loosely approximating fairness at absolutely best.
However, if you can’t afford tens of thousands for an attorney, experts, etc, you’re pretty much fucked.
We need to seriously rethink how we treat the accused in this country, from automatic sanctions that are applied to any accused, to how much leeway the police and justice system have to destroy people’s lives before there’s even been any evidence presented of an actual crime.
Among the ones who have partial bans they range from "No, unless you run a bank and the arrest was for alleged fraud or bank robbery" to "Basically yes, unless it's a really old arrest and the salary is below a threshold."
I can see it making a sort of sense in some edges cases. Would you hire a bartender who had been arrested six times on suspicion of DUI just because he was never convicted? I think that would be hard to justify, if my insurance company would even allow it. (So, in my opinion, it's better if I never found out!) However, in general I find the idea distasteful, uncharitable, and un-American.
That said, I suspect most employers just like to have as many legal reasons to reject an applicant as possible to make it harder to be sued (irrespective of whether those employers are racists). In Michigan they were more or less explicit that they put their ban in place because black people are being arrested and charged at rates disproportional to eventual convictions versus other groups.
The way you say it, it's like you think that more and more acquittals is evidence of guilt, but that doesn't make any sense to me.
Repeated arrests would be no accident of chance, but those repeated acquittals would even call into question a conviction in the future. Something is going on to generate false accusations.
You can't be forced to take (or, even, given additional punishment based on an advance-consent licensing provision, as California has and used to enforce) a blood alcohol test without a warrant under Supreme Court case law, and warrants take time.
https://www.mtvlaw.com/blog/2019/august/what-are-pennsylvani...
And that's hoping you are a citizen. Because visa renewals (and permanent residency applications, etc) also ask the exact same question. Depending on the reason for the arrest, you can also be denied naturalization or be placed in deportation proceedings without an actual conviction being required. On the basis of your "moral character".
Unless the starts align the wrong way, generally the way its gonna go is first they will pull your background, and see that there is no criminal record, good credit and a tech job. So the first thing that is going to happen is that you will get a couple of FBI agents probably show up to your door and ask you questions. At which point you could sit down in front of your computer with them, pull up your accounts, and see the evidence of the transfer, all without answering questions with a chance to self incriminate.
The advice of "not answering questions" applies mostly for situations where cops are looking for the guilty party, and you don't want to accidentally self incriminate (or if you are guilty, you have a higher chance of getting off)
FBI having records of you specifically in relation to a shady website is already past the point of looking for a guilty party - the people they send are specialized in cyber crime, are there to investigate the entirety of the situation with enough information about you already collected from all the sources like ISP logs, background check, and so on, all indicating that you are probably not guilty, as people who actually run sites like that statistically lead very different lives
You can refuse to answer questions and let them in, however that has a higher rate of a search warrant, seizure and possibly arrest. Or you could just show them your domain registrars, tell them that you have no idea where it came from, and then look up history that shows the transfer, and that could be the end of your trouble, without any self incriminating statements.
But let me tell you, I have had a couple of FBI agents show up at my door. And when I saw those badges, even though I know I've not done anything, I was nervous. Had a legit adrenaline dump. All because my address was the last known address of someone they wanted to speak with. This someone was male, brown hair, about the same height and build as me, etc. As soon as they noticed the similarities, it was not a "sit down in front of your computer and straighten this out" kind of situation. They are there for a reason - to find a criminal. They aren't there to shoot the shit with you and explain "it's all just a big misunderstanding".
If the FBI shows up at your door without a warrant, don't let them in and don't speak to them. If they insist, insist on having a lawyer present.
Luckily my situation ended up OK. I got a lawyer who specifically had experience with federal law enforcement and had them do all the "straightening up of the situation". But it cost me money and took weeks of what should have been "here is my driver's license, passport, and deed. I am me, not the other guy".
That is not at all how the FBI operates. If they suspect you of operating a child porn ring they aren't going to just show up and ask questions, because if you are operating a child porn ring you will have nuked the evidence before they return with a warrant. They show up with a warrant. They will not allow you to touch the computer, because they won't want you to have a chance to nuke the evidence.
In any case, you don't need a clean record, good credit, or a tech job—which would actually be a liability here—to have an account with a domain registrar.
If the only thing that shows up from all the data is literally a public DNS that points to a public ip address with questionable content, while you are leading a relatively normal life with all your other income accounted for, the agency (given that they have enough tech experience in cybercrime here) will most likely assume that you are a victim, and will go talk to you. Now of course, nothing is for certain, but statistically speaking, FBI doesn't go busting doors without prior investigation.
It's also worth noting that the author specifically called out in the article that the concern here is SWATing which has become such a notorious problem in some circles that the concept has made it into mainstream TV shows covering the practice.
Due process only counts when it's uniformly available, and there is ample evidence in the United States, and other countries that have similar policy, that the effectiveness of civil rights protections varies widely by economic status and ethnicity.
Good luck with that.
Even on completely spurious charges, you’ll spend time in jail, spend tens of thousands on legal fees, and spend months of your life sweating bullets.
Afterwards, you won’t even be able to sue the police thanks to qualified immunity.
Have you ever seen a no-knock raid? It happened to a house 5 houses down from where I live. They broke down the door and threw a couple of flash-bangs inside. Even from 5 houses away with all doors and windows closed, I could have sworn someone just fired off a cannon. Pretty sure they won't be fixing or paying for any damages either.
There was a somewhat-well-publicized incident a couple years(?) back when IIRC a shoplifting suspect (who was armed, I think) was chased by the cops, hid in a stranger's house, the police wrecked the house getting the guy out, and then didn't pay a dime to fix it, let alone anything to compensate for the significant inconvenience of having a messed-up house and having to have a lot of work done to repair it. Can't recall whether there were any successful lawsuits after, but the default was definitely, "nope, that's entirely your problem, we just break stuff, we don't fix it".
And that's for someone who wasn't even any kind of target for the police, but an innocent bystander.
I started to write a comment about how horribly optimistic this is but then I thought about it some more.
If it is indeed "Local" police you are probably screwed. They have zero understanding of the internet/tech and even people in positions with titles like "Cyber security" at your local station are probably just cops that got promoted into that role and have very little to zero understanding. Every interaction with my local cops w.r.t. technology has been painful and fruitless.
Of course this assumes they would follow up on it in the first place. My LEA outright refused to lift a finger with a harassment case even when provided step by step instructions (and we knew who was behind it) on how to request information from the company the harasser was using (throwaway phone numbers). That said, maybe an instance like the author describes would get them off their butts.
If it goes up to a federal level then maybe they would understand the nuance of domain transfers but not before kicking in you door.
2. Do law enforcement, as standard practice, have access to the history of domain ownership? Would they see that it was recently transferred, or not?
A. The Proper Way: Find the right person at ICANN, send letters, follow-up, and hope they understand and prioritize the issue so it's addressed in some number of years.
or
B. The Fast Way: Register a funny yet embarrassing domain name, transfer it to a senior ICANN official, tweet to some journalists idle speculation wondering why this person has such a domain name. The vulnerability will be addressed ASAP. :-)
EDIT: Being downvoted because I'm against public shaming, way to go HN! Go on, downvote me.
No, nobody deserves "reputation damage" for the misbehavior of their company (and here, the one at fault is another company).
Is there really no legal basis to sue someone because of this? Is that clearly not malicious behavior from the one who transferred the domain?
The domain could be haha.com it would not matter.
* WhatsApp will accept incoming messages from accounts not in your contacts
* WhatsApp will save all incoming photos to your library
* iCloud will upload all photos in your library to the cloud
Scary stuff.
Nothing significant has changed.
^ THAT is why the police shot. Not because someone had registered a domain name called "imakechildporn.com". They need a credible and imminent threat of violence. You can't just roll up on someone who might be hosting a "illegal website" and use that as a pretext to shoot first ask questions later.