DNS Abuse and Criminal Infrastructure

(labs.ripe.net)

19 points | by jruohonen 1 day ago

6 comments

  • SpaceLawnmower 20 minutes ago
    This article is pretty light on details. The linked presentation goes into a lot more detail with statistics about which registrars and organizations are the worst offenders etc.

    https://view.officeapps.live.com/op/view.aspx?src=https%3A%2...

  • edent 57 minutes ago
    I have some experience of dealing with this when working for .gov.uk

    A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims.

    By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists.

    At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?

    I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless.

    • tremon 46 minutes ago
      On the other hand, I struggle to think of a reason how harm could come from delayed activation of a registered public name. Can you describe a use case that cannot be solved by opting for a subdomain of an already-existing domain?
      • edent 39 minutes ago
        England have just scored the winning goal in the world cup and I want to celebrate by launching my personal tribute on Lionesses.rock

        Why shouldn't that go live instantly?

        A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.

        I've had a brilliant idea for an eCommerce website but it is 1705 on a Friday night and, because no one works weekends, I have to wait until next week before the domain is agreed.

        I agree that there's no great harm in having to wait a day, or a week, for registration to complete. But in a world of instant gratification, it feels old fashioned.

  • azeemba 50 minutes ago
    I agree with the premise but this article doesn't really provide a strong argument. It mentions stats about child exploitation but doesn't show how that's related to gtlds.

    Stats about the block list are good (10% of gtld domains are blocked) but thay requires comparing it with a baseline. How many of non gtld domains are blocked?

  • thataccount 48 minutes ago
    The internet DNS system is broken in multiple ways. We would do better to have a shared DHT table with unique keys addressable to names.
  • TZubiri 11 minutes ago
    If you are thinking of launching your own TLD, or second level tld, or effective TLD (like vercel.app). I suggest being creative instead of making yet another TLD with the standard checkbox rules.

    If your TLD is location based for example, consider verifying and linking the TLD to an identity, by local means, like a national ID.

  • thinkafter 36 minutes ago
    [flagged]