The Internet Kill Switch; With Global Wiretapping Capability?
pastebay.net
pastebay.net
(please don't go there and feed the spammers, thank you :-))
$ whois facebook.com
FACEBOOK.COM.ZZZZZ.GET.LAID.AT.WWW.SWINGINGCOMMUNITY.COM from whois Server: whois.tucows.com
FACEBOOK.COM.MORE.INFO.AT.WWW.BEYONDWHOIS.COM from whois Server: whois.instra.net
FACEBOOK.COM.LOVED.BY.WWW.SHQIPHOST.COM from Whois Server: whois.onlinenic.com
FACEBOOK.COM.KNOWS.THAT.THE.BEST.WEB.HOSTING.IS.NASHHOST.NET from Whois Server: whois.your-server.de
FACEBOOK.COM.GET.ONE.MILLION.DOLLARS.AT.WWW.UNIMUNDI.COM from Whois Server: whois.PublicDomainRegistry.com MICROSOFT.COM.WILL.BE.BEATEN.WITH.MY.SPANNER.NET
MICROSOFT.COM.SHOULD.GIVE.UP.BECAUSE.LINUXISGOD.COM
MICROSOFT.COM.OHMYGODITBURNS.COM
MICROSOFT.COM.IS.A.STEAMING.HEAP.OF.FUCKING-BULLSHIT.NETThat's been around for more than 10 years, the reason is that whois is doing subtring matches.
Blackhat SEO stuff. Easy to fool google suggest also.
If there is a single shred of evidence other than "isn't it weiirdd...." then perhaps we can discuss this.
Perhaps I like my tinfoil hat more than the average Joe, but this sounds like an excellent way to execute wiretaps. I can only imagine that http://news.ycombinator.com/item?id=3929507 reminded the submitter of this old (Feb 17th) paste.
If true, the fact that they have a CA is what allows them to wiretap. But they don't need control of DNS to do that - just cooperation of an ISP.
As the registrar, you specify which DNS servers are authoritative for the domain. It is much easier for the registrar to quietly change a domain than any other 3rd party in the system.
That in itself isn't scary. Lots of people use(d) GoDaddy, eNom, etc. Another commenter pointed out that Last.fm likes the service because it abstracts the pain of domain registration.
But does Google care about the pain of registering Google in new TLDs? Does Facebook worry that their domain will expire due to an out of date credit card? Using a third party service introduces risk of failures out of your control. Any interruption to these major providers will cause damage far in excess of them not having to deal with spam domains.
Consolidation when consolidation is unnecessary should raise questions.
And that's the beauty. Herding the cats in engineering at Google and Facebook to spy on everyone is difficult. Many of them might even quit their jobs before doing such a thing. Best to wedge a soulless anti-spam group between the happy consumer company and the Internet and get the blessing of a couple of CEOs who have been told that compliance is not optional.
Verisign has the ability to alter DNS glue records for .com and they have the ability to issue browser-trusted certificates, except in cases of browser cert pinning functionality or extensions (like CertPatrol) that check for certs being altered before they're nearly expired.
Registrars can instruct Verisign to alter the glue records for .com domains. Are you saying Verisign has special policies in place to double check with major companies before changing their respective glue records?
{accounts, mail, docs}.google.com (at least) have HSTS forced and preloaded in Chrome, but www.google.com does not.
http://blog.chromium.org/2011/06/new-chromium-security-featu...
as well as empirical Chrome behavior.
Last.fm also uses MarkMonitor and they explained why here: http://news.ycombinator.com/item?id=3687600
Some local services: yandex.com, mail.ru, vk.com, ozon.ru, rutracker.org, lenta.ru, ok.ru - are all unaffected. I bet Chinese resources are unaffected too.
Does anyone have more information on this?