DNS abuse and criminal infrastructure

(labs.ripe.net)

69 points | by jruohonen 1 day ago

15 comments

  • SpaceLawnmower 6 hours ago
    This article is pretty light on details. The linked presentation goes into a lot more detail with statistics about which registrars and organizations are the worst offenders etc.

    https://view.officeapps.live.com/op/view.aspx?src=https%3A%2...

    • ohashi 2 hours ago
      That presentation is... weird.

      For example, claiming 4 registry families having over a million blocker domains. But there aren't that many registries... and the domains under management by registry is... skewed. .com (verisign) is 37% of all domain registrations. Not to mention .net and other TLDs they manage. So the fact they come in below that number seems meaningless and skewed? I say this as someone who hates Verisign because they're a terrible monopolist.

      Then the registrar families with highest domains blocked.

      NameCheap registered 14m and had 1.1m abuse domains (~8%) gname had 3.1m with 1m abuse (~32%), dynadot (~20%), namesilo (~20%), godaddy (~5%). That feels pretty unfair calling out NameCheap and GoDaddy who have a fraction of the abuse the other 3 have but show up simply because of their scale?

      The registrars with 50%+ of domains blacklisted and top one being 87% screams for an investigation though.

      It seems to highlight some potentially suspect actors but also throwing some large companies under the bus simply because they're big?

    • dang 4 hours ago
      We'll put that link in the toptext as well. Thanks!
  • TLDRisk 5 hours ago
    > Any additional measures should not require ICANN to assume the role of a global content regulator or criminal-law authority.

    > The community should instead consider whether contractual and operational arrangements adequately enable registries and registrars...

    Those are things that are easy to say and hard to do. From the perspective of a good faith registrant, the enforcement is already too complex. There are hundreds of registries and thousands of registrars, all enforcing their own interpretation of the rules, so you end up with massive inconsistency.

    No one wants their 10+ year old domain revoked for DNS abuse if they've been the victim of a security incident and it got misused, but dealing with that is hard and the economic structure of the industry isn't conducive to "intelligent" handling of complaints. Any solutions will scale the same as big tech with massive, automated systems that turn good faith participants into collateral damage.

    A big problem for the domain industry is the way registries are shielded from liability and registrants. The registrars operate on thin margins and take on all the liability and customer support.

    I don't think the registries will be given more responsibility. That's based on a personal bias though. I think the industry is set up to benefit the registries at the expense of registrars and registrants.

    The registrars are the most likely party to be saddled with extra responsibility and I don't think that's a good solution because they have an economic incentive to look the other way. It's also a weakest link industry so, even if Porkbun, etc. are working overtime to keep bad actors off their platform, there's always someone willing to onboard a scammer for a few dollars.

    In my opinion, there should be more talk about a centralized system funded by fees that ICANN collects. As a good faith registrant I want consistent, well defined rules with an appeals process, transparency etc.. I also don't care if I have to pay an extra dollar or two a year for my domains if it improves the industry overall.

    Semi-related, does anyone know if there are any lists or decent sources for finding domains that have previously been suspended or put on block lists? That would be useful info for would-be registrants. No one wants to get surprised with a tainted domain.

  • xp84 3 hours ago
    While I'm definitely not inclined to trust whoever wants to introduce new barriers, part of me actually thinks that the availability of second-level names (e.g. example.com), instantly, for trivially-low prices... maybe you could make a case that we get more harm than good from it.

    If you're starting a new commercial venture, something that cost $1000 and took a week would still be one of the cheapest and fastest parts of that process. If you're doing a hobby project or a speculative startup, using a subdomain would be fine. It worked for Altavista.digital.com and Google.stanford.edu.

    The argument for shifting (back) to a model like that would be that the hierarchial DNS served as a chain of responsibility. Today a lot of companies irresponsibly use dozens of domains, presumably either because they think people are too stupid to learn to type an additional period in a name, or because their internal dysfunction makes provisioning a subdomain an 11-month project. It's terrible that citibankonline.com, citibank.com, citicards.com, citientertainment.com, citi.com, and citigroup.com are all official domains that Citigroup uses. A user seeing a link to, say, 'citicardbenefits dot com' has zero methods of establishing provenance.

    And of course, under conditions where 2LDs were expensive again, 'free subdomains' would certainly still be a thing, as they even back were when .coms were $50 or whatever. We had cjb.net, a bunch of clever '.to' domains, afraid.org, etc.

    Under the 'modern' system, the problem of "who do we need to contact about an obvious scam site" has been pushed up to the largest possible scale - the GTLD registries, whereas a scammer abusing a "free subdomain" would be shut down by the admins at that second level.

    In the end though, I admit we're stuck with the current way, or, (possibly) some hare-brained KYC scheme that will subject everyone to a high level of government censorship and make anonymity unavailable to good actors who really deserve it.

    • QuantumNomad_ 2 hours ago
      I find that the ccTLD for my country strikes a pretty good balance.

      It’s still cheap to register and renew, but requires a traceable real connection to a company or a person:

      > 5. Requirements for the applicant - who can apply?

      > Organisations

      > 5.1 The applicant must be an organisation that is registered in the Norwegian Central Coordinating Register for Legal Entities, see the list of which types of organisations can apply (Appendix E). The organisation must in fact conduct business and/or have activities and a presence according to information specified in the Central Coordinating Register, and it must document its actual existence if Norid requests such documentation. The organisation must have a Norwegian postal address.

      > 5.2 Each organisation may at any time subscribe to up to 100 domain names directly under .no. In addition, an organisation may subscribe to up to 5 domain names under each geographic domain to which the organisation belongs, as well as 5 domain names under each category domain to which the organisation belongs.

      > Private individuals

      > 5.3 The applicant must be over age 18, registered in the Norwegian National Population Register with a Norwegian national identity number and have a Norwegian postal address.

      > 5.4 Each private individual may at any time subscribe to up to 5 domain names directly under .no. In addition, a private individual may subscribe to up to 5 domain names under each geographic domain to which the person in question belongs, as well as 5 domain names under priv.no.

      https://www.norid.no/en/om-domenenavn/regelverk-for-no/#5.-R...

      It works well, and on top of that it is still possible for someone to host content on behalf of someone else to protect the anonymity of that other person, for example by as you said handing out free subdomains to others and handling complaints about scams and other undesirable or illegal things. With all the responsibility and legal liability that doing so incurs.

    • TLDRisk 2 hours ago
      > If you're starting a new commercial venture, something that cost $1000 and took a week would still be one of the cheapest and fastest parts of that process.

      That's highly dependent on where you live.

      I don't agree with the 3rd level domain structure. In fact, I don't think ICANN should allow registrars to sell those without clear disclosure informing registrants they're not ICANN domains. At the very least, registrars shouldn't be doing that to their customers.

      In terms of abuse handling, you don't want to be a sibling to some unknown person or entity.

      > Under the 'modern' system, the problem of "who do we need to contact about an obvious scam site" has been pushed up to the largest possible scale - the GTLD registries, whereas a scammer abusing a "free subdomain" would be shut down by the admins at that second level.

      But I want my legitimate domain pushed up to the largest possible scale with a clear set of rules and independence from other registrants. In terms of governance, the average registrant couldn't tell you the difference between a 2nd level domain and a 3rd level domain and the 3rd level domain comes along with additional risk.

      As soon as you add 3rd level domains, that's an extra party that can drop your domain. The 3rd level domain providers don't have a standard abuse handling mechanism. I think most of them try to defer to ICANN's rules, but there's nothing that says they must do that. As far as I know, ICANN only deals in TLDs [1].

      What happens if you're on a 3rd level domain, there's an influx of abusive behavior by sibling domains, and the 2nd level owner doesn't do a good job of handling it? Does the 2nd level domain get banned by the gTLD? What kind of collateral damage does that cause?

      Maybe you create something like the public suffix list, but then it's the same problem with more complexity regarding responsibilities.

      I do agree with the general sentiment of letting people pay to prove trust. I think it's really hard to come up with a number that makes sense, but I'd be willing to pay $X into an abuse handling fund if it bought me extra trust for my domain(s).

      1. https://www.icann.org/en/contracted-parties/registry-operato...

  • azeemba 6 hours ago
    I agree with the premise but this article doesn't really provide a strong argument. It mentions stats about child exploitation but doesn't show how that's related to gtlds.

    Stats about the block list are good (10% of gtld domains are blocked) but thay requires comparing it with a baseline. How many of non gtld domains are blocked?

    • donmcronald 5 hours ago
      > It mentions stats about child exploitation but doesn't show how that's related to gtlds.

      Yeah, I wondered about that too. Any young people I know can barely tell you what a domain is. They're not directly visiting websites AFAIK and I don't think any of the platforms require a domain to participate.

      > 9% experience online sexual extortion before the age of 18

      That's an astronomical number and I'd assume it has to be an overall total. I hate those kinds of statistics because they're not telling you what you really need to know to make an informed decision. What's the percentage that involved a gTLD?

      To me, this smells a bit like another effort at usurping control of the flow of information. Domains are an incredible tool for independence and the fact they've been co-opted by bad actors provides a great opportunity for a select few to seize control over what we're allowed to do with them :-(

      They've made no effort to give normal participants an edge over the scammers and jump straight to censorship / control.

      For example, consider that person on here with 'web.one' the other day. Why doesn't their expensive, premium domain include an increased level of trust and reputation?

      If they want to do KYC, I think that's fine, but it should be an opt in system like the old EV certificates used to be. I don't need KYC and a bunch of controls to self-host things that no one else uses.

      The problem with EV certificates is they became a money printing scam for the CAs. Plus, and this is an opinion, I think the platforms like Google and Facebook went out of their way to kill EV because damaging a trust indicator for domains benefits them when there are scams everywhere (as we're seeing now) and people need the platforms to "protect them" rather than having a fundamental understanding of how to evaluate risks on their own.

      • xp84 3 hours ago
        I'm no domain registry expert but I'm inclined to agree with you on 100% of this. Who needs a domain registration to cyber extort? Pretty sure they just DM that type of material to the victim and threaten to DM it to others. Simple. Same for distributing illicit materials. Pretty sure it's either dark web or private groups on platforms.

        These days especially it seems like nearly every measure relating to "cybersecurity" or regulation in the online space in any way is always hitching itself loudly to some form of child sex abuse - I don't blame these various lobbyists for trying, since it's obviously a winning formula. Bring up a universally loathed offense, explain that your new scheme is somehow "needed" to cut down on it, then shout down your opposition as "soft on child abuse."

        It's the playbook used in 2001 when it was The Terrorists. I suspect that since moral relativism has resulted in many people being unsure if even the sickest terrorists, who behead their prisoners on camera with a dull sword, might actually just be misunderstood freedom-fighters, now there's a new favorite bogeyman, this one more resistant to political reframing.

        • donmcronald 3 hours ago
          I think part of the problem is a lack of explanation and education. 10% of kids are being exploited and no one can tell us how it's happening, but everyone has a plan to fix it?

          Is there money to invest in resources for kids that need help? Nope. Is there money to implement a global surveillance system that tracks and logs everything for AI analysis while attributing it to verified identities? You betcha!

          When I was a kid deleting your account and creating a new one was a good solution if someone started harassing you. That's been taken away and, even worse, normalizing verified IDs is eliminating the last tiny bit of privacy everyone has, including kids. The bad actors are going to be able to follow people around forever IMO.

  • edent 6 hours ago
    I have some experience of dealing with this when working for .gov.uk

    A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims.

    By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists.

    At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?

    I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless.

    • FromOmelas 4 hours ago
      How would you decide what is legitimate ?

      Better would be a "this site is suspiciously new" warning in browsers.

      At $WORK, newly registered sites are blocked by default by the network appliance.

    • tremon 6 hours ago
      On the other hand, I struggle to think of a reason how harm could come from delayed activation of a registered public name. Can you describe a use case that cannot be solved by opting for a subdomain of an already-existing domain?
      • edent 6 hours ago
        England have just scored the winning goal in the world cup and I want to celebrate by launching my personal tribute on Lionesses.rock

        Why shouldn't that go live instantly?

        A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.

        I've had a brilliant idea for an eCommerce website but it is 1705 on a Friday night and, because no one works weekends, I have to wait until next week before the domain is agreed.

        I agree that there's no great harm in having to wait a day, or a week, for registration to complete. But in a world of instant gratification, it feels old fashioned.

        • skrebbel 5 hours ago
          None of these require a domain to work. There’s plenty precedent of things taking off without having a domain, eg Wordle, all Neal.fun sites, Hacker News, and I’m probably forgetting a few obvious ones.

          I know that “mystupidvibecodedidea.com” is all the rage but nobody cares if that’s instead on yourname.com/mystupidvibecoded idea except you.

          • edoceo 5 hours ago
            Back in the day (~2003) it was popular to get a domain name for every project. Loads of people I knew where holding a domain name for every idea they had. I even had a few (~40). But in like 2008 I think I switched over to using just sub-domains of my primary. If anything took off I could then find and buy the cool name. And if it dies (likely outcome) I've saved $30.
          • edent 2 hours ago
            OK, so I have a legitimate domain. I can add any subdomain I want without recourse.

            projects.example.com or new.cool.thing.example.com

            So nothing stops me from registering a legitimate domain, using it for a bit, then launching the subdomain `pay-your-tax.gov.uk.official.example.com`

            It must be legit - it has the .gov.uk in it!

        • IAmBroom 4 hours ago
          In the world of spammers with zero accountability, it seems needed.
        • cucumber3732842 5 hours ago
          >A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.

          More likely:

          Some flavor of shit has hit the fan. I need to register some viable short and to the point domain names to get the word out faster than BigCo or the government and their army of lawyers can buy those domains.

          Would we have stuff like DeFlock if there was an objection period?

          What about if some advocacy firm was trying to create a website for people harmed by a drug. The drug company would just object to all their attempted registrations and bog them down.

          • amluto 5 hours ago
            A delay doesn’t even really hurt this use case. The first person to register the domain would still get it, 24 hours later, unless there’s an actual objection.
            • edent 5 hours ago
              I think the "actual objection" is the hardest part.

              The UK Government might legitimately object to the registration of `dwpgov-uk-payments.pizza` but should they be allowed to object to `dwp-gov-uk-stole-my-payments.fart`?

              One might be obviously dodgy, the other is someone ranting about their experience. Do you think Governments should be able to object to domains complaining about them?

              • amluto 3 hours ago
                I'm not entirely sure. But we have have mechanisms like Google Safe Browsing, and I can imagine that a similar mechanism could be used. Or there could even be a new classification in Safe Browsing and similar databases for newly registered domains that look like they are misleaing, and this could actually be fast enough if there was a 24-hour hold on new domains.
            • cucumber3732842 5 hours ago
              Who defines "actual objection"? The entrenched interests are really good at tilting such processes in their favor.
              • pessimizer 4 hours ago
                A delay wouldn't change that. You're talking about the difference of the site being up for a half day or not at all, which is admittedly infinity times longer, but not enough to make any sort of difference (as opposed to putting the anti-entrenched interests info up without its own domain name.)
    • TLDRisk 4 hours ago
      > At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?

      I'd say "legitimate objections" is doing a lot of heavy lifting there and I don't like the idea. Having the time and resources to monitor registrations becomes a barrier and that makes it a time and resource based system. IE: Rich individuals and companies can pay a monitoring service that objects very broadly.

      I've always been frustrated by systems like that and it seems like a lot of the tech industry is set up that way. I've had my personal, family name, 25 year old domain put on Google's safe browsing block list and being the collateral damage in a hugely scaled system isn't fun. Spending the time and resources needed to deal with it are far more of a burden for me than for a big company. I was able to get it removed, but why should I be forced to pay for their mistake?

      Ultimately though, any system is going to cost money no matter how it's structured. If you're not paying directly, you're spending time or resources of some kind. I'd rather pay directly because it's easier to understand.

      I don't think you can build an all or none system for handling abuse because so much of it is subjective. Even using what's legal vs illegal is difficult because a global system is going to have contradictions. Online gambling is a good example. Some countries would want the related domains banned for being illegal while others don't have a problem with it.

      Domains are one of the core building blocks that makes a decentralized internet work. Adding strong moderation tools to that is a huge risk because moderation and censorship are closely related. Who determines what's trustworthy or legitimate or abuse or anything else? What happens if a newly appointed authority claims transparency will enable bad actors?

      Highly transparent systems with independent trust ranking make the most sense to me. Any solutions need to be opt-in, or, at the very least, opt-out.

  • inigyou 4 hours ago
    My opinion is that as long as criminal organisations exist, there's no reason they shouldn't be allowed DNS names. That will just help the police track the actual organisation.
  • thataccount 6 hours ago
    The internet DNS system is broken in multiple ways. We would do better to have a shared DHT table with unique keys addressable to names.
    • edoceo 4 hours ago
      How can we start today? How are name conflicts resolved?
  • m3047 20 minutes ago
    "The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis."

    I don't disagree with the general assertion / hypothesis that bad actors register a lot of domains. But the data comes from an industry which does a poor job of categorization, doesn't agree on categories, and absolutely does not publish statistics on corrections. Nor is it easy to request corrections. Nor does it seem that corrections are felt to be necessary absent customer complaints. There is too little basic science and integrity in the process.

    This is not new, the industry has quite frankly always been like this.

    "Any industry confronted with evidence that a material share of its output may be controlled by bad actors should be seriously concerned." Too much category confusion to go through it all, for this statement, in this context. But yes. The domain sector isn't just people selling domains, it is also people who make money preventing you from being able to use a domain, and people doing arbitrage on your domain before you can even put it on-line. So I ask: are these "good" actors? How do we know? What's the standard?

    It's too hard to get a response from most parts of this sector, and a lot of it is corrupt.

    Let's start with registrars, because nobody starts there: I had a registrar literally catch fire. Basically out of business at that point. Because their systems were down they couldn't transfer the domains. I had to file a formal dispute with ICANN, six weeks of back and forth and waiting later, they handed the domains to some registrar I'd never heard of and had no existing business relationship with. (Not a great registrar.) This happened in 2017, don't tell yourself that things have improved since then.,

    Then we have the email reputation services which spam on their own account: http://athena.m3047/pub/soe/abusix-spam-backstory.html

    As well as reputation services spamming because someone paid them to do it (they send email to domains which they block, with their own servers): http://athena.m3047/pub/soe/pphosted-vmed.png I'd originally put this down to a three body problem: https://consulting.m3047.net/dubai-letters/blocking-esps-pla... (technically what you're seeing in the screenshot is me blocking them as a favor since they can't seem to manage it on their own).

    The industry is rotten. https://consulting.m3047.net/dubai-letters/ptn-industry-trus...

  • jeffbee 3 hours ago
    Slide 17 is the one people should read before they get on their blog complaining that their emails are rejected by Google and Microsoft. The entities associated with your domain and network, the DNS hosts, registrars, network blocks, and all that each have their own reputation. It is easy for the unwitting to fall in with criminals.
  • seany 4 hours ago
    Just just seems like a reason to have a truely distributed DNS system that is censorship resistant. The complaints presented should be _unfixable_ since they are a feature, not a bug.
    • peanut-walrus 2 hours ago
      There is no such thing as unfixable. It's just kicking the can down the road. Look at how email devolved because of the features that made spam "unfixable". I would like dns not to go down the same path, which seems all too likely if nothing is done. Already most corporate networks are blocking most "new" domains. It's only a matter of time before new domains you buy are essentially unusable.
    • teravor 3 hours ago
      such decentralized systems would have to rely on a DHT and the domains would be public keys, somewhat defeating the purpose of a domain.

      an effort to do this: https://github.com/pubky/pkarr

  • jonathanstrange 4 hours ago
    Why should alleged "cybercriminals" not be be allowed to register domain names? There are procedures of seizing domain names in various countries, and these are in my opinion already somewhat questionable, but the premise of this article seems to go far beyond that and suggest that what they call "malicious actors" should somehow be deprived of infrastructure because they are suspected criminals. The rationale for that is that they later show up on blocking lists...?

    That seems beyond any reasonable due process and legal standards. Or am I missing some international legal standard and judicial oversight that would play a role here? I'm genuinely confused.

    • IAmBroom 4 hours ago
      This is exactly what a delay accomplishes: a trivial annoyance to legit users, but a real overhead to bots trying to hit-and-run users.

      Much like micropayments could solve the text spam problem.

  • TZubiri 5 hours ago
    If you are thinking of launching your own TLD, or second level tld, or effective TLD (like vercel.app). I suggest being creative instead of making yet another TLD with the standard checkbox rules.

    If your TLD is location based for example, consider verifying and linking the TLD to an identity, by local means, like a national ID.

  • inigyou 4 hours ago
    gTLDs themselves are a scam, but because it's rich people running that scam it gets a pass
  • fenestella 5 hours ago
    [dead]
  • thinkafter 6 hours ago
    [flagged]