No-IP's Formal Statement on Microsoft Takedown
noip.com
noip.com
While I do take issue to the actions of Microsoft and the courts I also think No-IP hasn't done themselves any favours and are at least partially to blame for this coming to pass.
It stands to reason that it's close to impossible to create a free service that is impervious to abuse however it's still their responsibility to avoid mass abuse of their platform to orchestrate botnets.
Ethically, I think you're correct that it's their responsibility to do what they can.
Legally, the court in this situation thought it was somehow Microsoft's responsibility to fix it.
Economically, I'd say being held liable to what users do on your platform will hurt innovation and competition.
In terms of liberty, botnets and spam don't seem like they compare to an attack on someone's business, their users, and their freedom to operate independently.
I guess you can choose which perspective makes the most sense to you, personally.
That is a strange perspective I have to say.
If one accepts the idea that courts should be seizing entire swaths of domains just to fight malware, it's still absolutely bizarre that Microsoft themselves should be given control of them, rather than an independent policing body. If there are to be Internet police, they should be independent of any one corporation, industry group, or government.
Except it is not a crime if it's done under lawful authority (by definition) or in self-defense. Otherwise you'd argue imprisoning a murderer or using force to defend your life is a crime, because outside of these circumstances limiting one's freedom of movement or using force on somebody is a crime.
>>> If someone uses YouTube to upload copyrighted things, should YouTube have its domain stolen and its users unable to use the site any more?
If that's the only thing his domain is used for, it very well may happen, and similar things already happened. Seizures of domains used for illegal activities are commonplace.
However, safe harbour does atleast imply reasonable effort to curb mass abuse.
Responding case by case is nice but it's not the same. As it leaves open the proverbial DDoS attack where botnets just create so many domains that the process put in place to resolve them is too burdensome for companies like Microsoft (or even law enforcement) to reasonably utilize.
Hence if you have a platform that is vulnerable to such abuses you should have systems in place to handle this at a bigger scale than single case by case means.
From what Cisco and Microsoft are reporting NoIP is (was?) a hotspot of botnet activity. If NoIP was not doing anything against that Microsoft's lawsuit doesn't sound that unreasonable.
How this was actually implemented in the end (MS just taking over the DNS) does seem a bit strange to me though. They should at least have been taking over by a government agent.
Turning over IANA or Ford over to Microsoft would not prevent malware or robberies. Turning over NoIP to Microsoft will prevent malware (at least in the short term).
In short, it is neither obvious that turning over NoIP's domains to Microsoft will prevent malware, nor clear what should happen if it doesn't, and it is certainly not clear that Microsoft will not cause more damage than they repair by acting in this way or what should happen if they do.
Really? Not according to anyone with anything resembling a passing familiarity with malware and it's distribution...
Malware authors anticipate their communication channels to fail and usually account for it with a whole series of fallbacks.
Quite unlike your NetGear or LinkSys home router, which many people suddenly can't reach anymore from e.g. their vacation home...
It's not like this motion has created some insurmountable wall that malware creators can't possibly work around.
Using the same logic, let's just prevent malware altogether by blackholing all of the Internet traffic - problem solved!
The article of this thread (that is the blog post of NoIP in response to MS's actions) which I'm sure we all read, says that NoIP themselves DID act to prevent abuse. They were not informed of this action by Microsoft.
I'm not a lawyer, but I think I've got at least a basic idea of the circumstances under which the government can take someone's property. This doesn't seem to coincide with any of those potential circumstances, especially when the seizure transfers the property to another non-governmental entity.
What's more, where's the due process? No-IP seems to be saying that they didn't even know about the court case until being served with the order. Did they really not have the opportunity to contest this?
EDIT: To summarize some of the documents people have linked to and analyzed below, it looks like Microsoft was granted a temporary restraining order under "Federal Rule of Civil Procedure 65(b)", which allows for such orders to be granted without providing notice as long as certain requirements are met.
Microsoft was required to post a $200,000.00 bond, which is supposed to pay for any damages incurred by No-IP, and No-IP will be granted the ability to contest the order in court on July 10, and maybe earlier. However, it is clear that No-IP knew nothing about even the lawsuit until they lost control of their domains, as this was specifically ordered by the court.
Also, there is no answer as to whether transferring control over domain names from a defendant to a plaintiff is something that courts should be empowered to do as part of a temporary restraining order. I hope a lawyer with some knowledge in this area can chime in to answer that question.
IT IS FURTHER ORDERED that the Registry Operators must:
...
d. Shall completely refrain from providing any notice or warning to, or communicating in any way with Defendants or Defendants’ representatives and shall refrain from publicizing this Order until this Order is executed in full, except as necessary to propagate the changes ordered herein to all parts of the Domain Name System;
http://www.noticeoflawsuit.com/docs/Second%20Amended%20Order...
I haven't yet found Microsoft's justification for the seizure without notice.
Presumably you have a link where we can see the notarised documentation and proof of delivery of that which was sent to No-IP that they failed to respond to?
http://www.noticeoflawsuit.com/docs/Revised_Final%20No-IP%20...
...is dated June 19, 2014.
And from the order itself...
http://www.noticeoflawsuit.com/docs/Second%20Amended%20Order...
...we see the following instruction:
"IT IS FURTHER ORDERED, pursuant to Federal Rule of Civil Procedure 65(b) that the Defendants shall appear before this Court on July 10, 2014, at 3:00 p.m., in LV Courtroom 7D to show cause, if there is any, why this Court should not enter a Preliminary Injunction, pending final ruling on the Complaint against the Defendants, enjoining them from the conduct temporarily restrained by the preceding provisions of this Order."
Of course, July 1 is tomorrow.
In this document, Microsoft seems to be requesting that all of this stuff be sealed until it is ready to disclose the existence of the lawsuit to the defendant, presumably after it has completed its seizure the domains:
http://www.noticeoflawsuit.com/docs/Final%20Motion%20to%20Se...
The facts of this seem pretty clear from your link. What I am wondering is if there is any precedence for this, and if this is really considered due process?
If the stated goal is to defeat malware then windowsupdate.microsoft.com should be seized and routed to a non-interactive Windows Uninstaller.
https://www.google.com/search?&q=android+malware&ie=UTF-8&oe...
So yes, while malware exists on android, I doubt the total damages caused by it are more than a drop in the bucket when compared to windows malware.
>Practically every instance of malware runs on Microsoft Windows.
Even according to Google, about 5 million Android devices are infected with malware. http://bgr.com/2014/06/26/google-on-android-malware-and-secu...
I would suppose that your statements aren't support by fact, but the HN downvotes have got me thinking.
The bandwidth constraints imposed by most users draconic data plans and the realities of limited battery life further put a fairly low cap on what a mobile botnet can do in this day and age. (both of which admittedly will hopefully change sooner rather than later...)
http://www.noticeoflawsuit.com/docs/Second%20Amended%20Order...
Also this is No-IPs response to Cisco's previous accusations. http://www.noip.com/blog/2014/02/12/cisco-malware-report/
They did have lot of chances to contest. Apart from Microsoft's notices, the court sent a notice to No-IP which they didn't respond to. They cleary state that ex-parte decision will be taken if they don't respond. Maybe federal courts don't like it very much if you act like they don't exist.
http://www.noticeoflawsuit.com/docs/Summons%20for%20Vitalwer...
That summons also says they have 21 days to respond, which, even if they were served on 6/19, hasn't elapsed yet.
EDIT: mikeryan's post above mine is even more clear - it looks like as soon as they opened the suit, they petitioned for the TRO without notifying NoIP and the court specifically granted them the right to not notify until after the TRO was served.
- First, it says "Within 21 days after service of this summons on you...you must serve on the plaintiff an answer.."
- Second, it is dated 06/19/2014
21 days from 06/19/2014 is July 10, 2014, a date which is still in the future. Do you have any other evidence that they didn't respond? Because the document you linked to is anything but evidence that they didn't respond.
but signed on 6/26.
8. Microsoft’s request for this emergency ex parte relief is not the result of any lack of diligence on Microsoft’s part, but instead based upon the nature of Defendants’ unlawful conduct. Therefore, in accordance with Federal Rule of Civil Procedure 65(b) and Civil Local Rule 7-5, good cause and the interest of justice require that this Order be Granted without prior notice to Defendants, and accordingly, Microsoft is relieved of the duty to provide Defendants with prior notice of Microsoft’s motion.
I should note my laymans reading is that Microsoft proved exigent circumstances that negated the need for prior notice.
http://www.law.cornell.edu/rules/frcp/rule_65
(1) Issuing Without Notice. The court may issue a temporary restraining order without written or oral notice to the adverse party or its attorney only if:
(A) specific facts in an affidavit or a verified complaint clearly show that immediate and irreparable injury, loss, or damage will result to the movant before the adverse party can be heard in opposition; and
(B) the movant's attorney certifies in writing any efforts made to give notice and the reasons why it should not be required.
So, if all of this is considered a "temporary restraining order", then it must be based on these rules, which also seem to provide certain protections to the affected party, including requiring the plaintiff to put up security to reimburse the affected party for any damages they may suffer as a result of the order.
I hope that a lawyer can chime in here and give a decent opinion as to whether this is kosher, and also to answer whether it seems correct to effectively transfer control over property such as domain names through this mechanism.
The TRO actually says: “...good cause and the interest of justice require that this Order be Granted without prior notice to Defendants, and accordingly, Microsoft is relieved of the duty to provide Defendants with prior notice of Microsoft’s motion.”
It says that because Microsoft wanted it to say that; Microsoft used that language in their proposed TRO for the judge to sign, and the judge apparently agreed.
The Summons has nothing to do with this. The court issued the Summons, but the court doesn't do anything with it. It's the plaintiff's obligation to serve a summons on a defendant, and they have 120 days to do so before the Court would require the plaintiff dismiss the case without prejudice. The plaintiff could serve them the same day, or they could take their time. Corporations with registered agents are much easier to serve than an individual that dodges a process server.
There's often a good chance a defendant will receive a solicitation from an attorney (who searches court records for new cases) to represent them before they actually get served with the summons and complaint. However, nothing would come up in court records in this case because the entire docket is sealed.
There's no way Vitalwerks/No-IP would have known about this, and it sounds like they weren't served until today, after Microsoft's action.
I think it's pretty clear that Microsoft wanted to ensure that nobody, including No-IP, knew about the case until they were able to strike.
no-ip and such are a required service for people to host their own "cloud" solutions from their home connections.
Microsoft makes money with their own "cloud" offering. which does not require such services. So by closing down on those services (or using the redirect to collect data) they are making their offering more attractive.
Obligatory car analogy: This is very well like Ford closing down all of Teslas charging stations because someone sold weed on one of them.
The competition from no-ip to Microsoft from this is virtually zero. Any serious hoster will have a static IP, or own their own domain.
Ford shutting down all of Tesla's charging stations because the original chargers were replaced by mean people with new ones that had a nasty habit of attempting to bazooka any Ford charging station that were withing shooting distance. Those charger were installed by any customers who happened to be within earshot of a sleazy sales guy that had a solution to cure their cars for non-existent problems by smooth talking them about "did you know internet explorer could run 200% faster" even though their car ran firefox or chrome.This is nothing new. Here is one a porn company got against a file locker service: http://www.xbiz.com/docs/xbiz/news/150302_oron062212.pdf. They eventually parlayed this into an asset freeze in Hong Kong.
http://www.noip.com/blog/2014/02/12/cisco-malware-report/
It doesn't compute that Cisco is casting blame on them and Microsoft got a court order when all they had to do is send an email.
It's kind of strange, they're probably unable to keep up with the abuse reports and validating them or something. There are a lot of dynamic DNS providers so why do the bad guys pick them for the most part for their DNS needs?
EDIT: Looks like DynDNS recently got rid of their free offering. I wonder if that was related to this?
It offers a DNS service for your domain and the ability to share your domain with others.
You can't seize the 100.000 domains being shared and used by bot nets so the only easy target was no-ip.
What i find extremely troubling is the domains being handed over to another corporate entity this mechanism is just ripe for abuse.
Mine doesn't use the same dyn update API, just curl, and you can self-host if you have an Amazon Route53 account.
Microsoft does not have the power to seize domains. A federal court order made that happen. This order is (apparently) the responsibility of the U.S. District Court of Nevada. If you want to blame someone, then blame the court.
Obnoxious people ask courts to do obnoxious things every day. Good courts do not comply.
> Microsoft has no obligation to you. Your judicial system does.
In any case, there is no "hating the game" here. The fault -- if one has a problem with this action -- is not with "the system", but with a very specific player: the federal judge who issued the order. (I don't feel like going through the trouble of finding his/her name, but I doubt it would be difficult.)
Problem is, there is no good court. It's always vary case by case. Is the Supreme Court good court? It did rule in favor of gay married couples entitled to federal benefits but not so on some other issues. Laws are meant to be interpreted differently and handled differently by different judges at different time.
What you (and I and everyone is doing) is expressing our own opinion of how the complaint should be handle based on our interpretation of the law, responsibility, and society.
Later edit: Isn't this ironic, how most botnet members are running Microsoft's software, yet they get to do this?
E.g. one might reasonably disrupt a farmer's market known to be selling beef infected with salmonella without banning cows of the same breed across the world.
Yep totally the same...
Thanks Microsoft.
See also my root-level comment:
Actual detail here: http://www.noticeoflawsuit.com/index.htm
Others will see it as Microsoft proactively removing bots and spam.
This has been going on for years. You don't own a domain name you just rent it.
Especially this quote: "Apparently, the Microsoft infrastructure is not able to handle the billions of queries from our customers."
Azure DNS, Microsoft.com, Bing. Yeah, all of those already require billions of DNS queries. I don't doubt things are not working correctly, but insinuating Microsoft can't handle the load just makes their case smell even worse.
I am not in love with what Microsoft did here but No-IP is not doing the best job of defending their position.
$ host ns1.microsoftinternetsafety.net
ns1.microsoftinternetsafety.net has address 199.2.137.250
$ host ns1.msft.net
ns1.msft.net has address 65.55.37.62
ns1.msft.net has IPv6 address 2a01:111:2005::1:1
$
Those of us working defense at large organizations have known for a while that No-IP domains are wretched hives of scum and villainy. Any company with a threat model that includes at least one of a diverse set of characters ranging from malware authors to organized crime to nation state teams should be logging all DNS requests and treating any request to a No-IP domain as an indicator of compromise.
Microsoft has a successful history of disrupting botnet C&C and distribution channels via domain seizures, which is why this request probably sailed through Federal Court. The only difference in this situation is that there are innocent bystanders affected, which generally doesn't happen since the other domains they have seized have been 100% used for fraud.
I feel bad for those folks and the people at No-IP who maybe meant well, but the truth is that the fight to keep normal people safe is bigger than just technological, and needs to include civil legal actions like this.
Is that rather like saying "Bing domains are full of malware". You appear to be claiming that No-IP are complicit in the actual hosting of content that gets pointed to with No-IP domains. MS facilitates a ton of illegal activity, I could spin up a Windows box and break 5 laws before bedtime. Of course shutting down MS would harm some innocent bystanders but handing their windowsupdate domains over to Google will lead to less malware, less spam, less successful scamming.
If, as a car company, i sell cars with potentially lethal flaws, i am required/told to recall and fix those vehicles. Other companies who sell cars are NOT allowed to have a court order the seizure of my phone numbers and have them direct to competitive business, so they can figure out who is driving safe cars and who isn't.
Secondly, the idea that private companies can be labeled "wretched hives of scum and villainy" by other private employees and have that permissible as anything other than meaningless hearsay is itself, nonsense.
I have read many documents on this today and every HN comment and I have yet to find someone present a case as to why on earth this is a good and sustainable precedent.
Microsoft presented evidence to the court that No-IP domains were being used to facilitate real crimes against real people, and the court acted. I think there is an interesting debate to be had on venue and the level of malicious activity that needs to happen before a domain is seized, but instead all I see is standard HN smashing of the keyboard and "Microsoft Bad!"
But indeed, if you feel you have sufficient evidence that MSFT is downright neglectful and turning a blind eye to spam accounts, feel free to file a motion and post a $200k+ bond.
Is there any reason why you're not serving via HTTPS? Without encryption, credentials are completely open to the network.
(It was initially going to be commercialized, but in the end I found people pretended they'd pay, rather than actually wanted to do so for extras like more hostnames, MX records, etc. So in the end I went with a different project https://dns-api.com/)
I could pretend I regard DNS data as public, but sniffing the update token could allow malicious users to change things in surprising fashions so it really does deserve SSL, but I'm not going to pay for it. I would hope that if users cared about security they'd deploy their own instance - and pay for the resulting Amazon traffic.
>...United States, including those located in the state of Nevada and the city of Las Vegas. Defendant has a contractual obligation to take reasonable and prompt steps to investigate and respond to reports of Internet or computer abuse, and the company has also made representations to the public that it has an “abuse team” to police and take action against such malicious activity. Yet Defèndant has failed to take sufficient action to stop, prevent, or effectively control this malicious conduct in breach of its contractual obligations and best practices of the industry, causing further harm to Nevada and Las Vegas residents.
Someone sends a court order to essentially handicap your business, putting it at risk for the sake of malevolent users. This was a situation where No-IP's "resolution" process should have been reported (ie they cater to criminals for profit), and not man-handled by a separate law and business body.
"Someone" in this is case is a federal district court which did that because there was no communication from No-IP. MS does not have the power to send court orders. The court ordered No-IP to send a response and looks like there was no response.
>If I was No-IP, I'd be out for blood.
Who's blood?
That's absolutely false. Microsoft explicitly asked the court to allow them to file the entire case under seal, and to obtain ex parte emergency relief without notifying the defendants.
The TRO states: “...good cause and the interest of justice require that this Order be Granted without prior notice to Defendants, and accordingly, Microsoft is relieved of the duty to provide Defendants with prior notice of Microsoft’s motion.”
The judge signed that. No-IP did not receive any advance warning or service by Microsoft's own admission, and No-IP's blog post confirms they weren't served until today.