So it seems, as ALWAYS, we're going to have to wait for state sponsored actors to buy the things, embarrass the shit out of a couple CEOs by posting their dick pics they're inexplicably sending over company mail, and THEN corps will start doing something about it.
Why we have to get on and off this merry go round every time is beyond me. Short-sightedness of those with decision making power boggles my mind daily.
And that statement, while obvious, is darker than it seems. Companies going under aren't sufficient consequences (many ransomware cases). Universities going offline isn't enough (look for the uni giessen). The bureaucracy of cities going offline isn't enough (e.g. New Orleans).
This is just going to continue to escalate until something really really ugly happens and kills many people. And then we'll be presented with some grand legislation that I don't look forward to.
Frankly that doesn't sound to expensive given the context, it's probably less than Microsoft's existing bug bounty budget anyway. I don't know why they couldn't work this out, or why they never bothered to try to address the issue over the multiple decades this guy has been keeping this domain out of dangerous hands.
Just write the check, Satya.
Still, this is the funniest thing that I've seen in months.
If there's credible reason to believe Microsoft is responsible for the liability, take them to court over it, but don't keep innocents at risk for the sake of trying to get Microsoft to own up to a mistake.
I can't even take that type of statement (in the article) with a straight face. You have an ordinary person presumably of typical wealth let's say average and he should just give something away for free 'for the good of security'.
Microsoft should buy it for the good of security. Why gift anything to a Trillion dollar company?
Because someone will have to cut a 7 digit check. And nobody is going to volunteer their budget for that.
Until the bigwigs gets pantsed and command someone to cut the check, it simply won't happen.
> That experience, portions of which are still indexed by the indispensable Internet Archive, saw O’Connor briefly redirecting queries for the domain to the Web site of a local adult sex toy shop as a joke. He soon got angry emails from confused people who’d also CC’d Microsoft co-founder Bill Gates.
If only Gates had gotten more annoyed back then and bought the domain just to stop the emails...
This is a guy who, by his own admission, wants it to go to Microsoft, but is also holding an auction. He could just quote Microsoft $2M and be done with this whole thing.
Instead, he and this "security firm" publish a big article on one of the internet's most lauded security blogs where they outline how blown away they were with how much data was being sent to this domain. They left it open for 15 minutes and got millions of emails, passwords, etc. "Wow, bad people reading this, look at how much data you could get. You better join in on the auction. Microsoft, you seeing this? You better get in on this too. Bid often and bid well, friends."
I wonder what kind of authority ICANN has in revoking domain name registrations in extreme circumstances. Microsoft fucked up here, but we're long past that being a relevant component in this discussion. This registration should be pulled out from under O’Connor and blocked from registration for 100 years.
Perhaps the fallout would be good for computer security, as it would stop corporations from making boneheaded security decisions. Pain seems to be the only way to make corporations evolve anyways.
Why should everyone in the world not get to use a thing because Microsoft has some naming scheme? These places have been shouting whatever data at a random (edit: unintentional and uncontrolled rather than random) spot on the internet for years and that's a huge problem.
Opening up an auction is a nice way to draw attention to the problem, get MS to literally&figuratively pay for it (even if the price 10x'd it's not like M$ couldn't handle $17MM), and make it no longer the seller's problem.
Brian did contact Microsoft for comment, and their response doesn't mention that they want to buy it.
I consider it bad reporting that Brian doesn't mention whether Mike already contacted Microsoft or not.
Not even close to the way this works ICANN does not 'revoke' domain names. There are ways to take possession of a domain name but that would not be the process (nor should it be).
> He could just quote Microsoft $2M and be done with this whole thing.
If you think selling anything and in particular a domain name is that easy you should try to sell a domain name to a large corporation and report back the results. It's not trivial and to a large corporation in particular and further for any amount (much less way less) not assured in any way.
He could but MS would laugh in his face. The auction and publicity are the only way to establish the domain's actual market value and to pressure MS to pay it.
What a persona this paints of the seller.
Would like to add that I also share your wonder. To me, this needs to evolve to anecessity for them (ICANN, in terms of ability) rather than just an “if”.
Please forgive me my lack of context surrounding this, but would love to learn more about why Corp.com is being sent various data (some sensitive, as mentioned in the article) from various parties in the first place. Did it use to serve a purpose for MS or other?
Obviously all these suggestions are equally ludicrous.
If everyone would do that the domain would be worthless.
127.0.0.1 corp.com
::1 corp.comI bet many IT admins would find this “quick fix” that would “make it work again” by effectively removing that /etc/hosts entry.
Perhaps a better patch would be to remove the [TLD] => [TLD].com DNS failover resolution feature.
I have a small bit of sympathy for them, because when Active Directory was first learning how to do domain names, they cost $100 per year and required a huge amount of bureaucratic nonsense. MS wanted to be able to sell their software to businesses that might never connect to the Internet. But they could have done a much better job.
2) what are likely the most risky applications tend to ignore the libc resolver and its configuration.
It should be handled as such. Not an auction to the highest (perhaps even foreign) bidder.
But where does the .com part come in to the picture?
Does corp.net or corp.ninja have the same type of issue?
https://www.networkworld.com/article/2289705/windows-flaw-co...
I would; but sadly...I haven't hit yet.
I am entirely on board with just killing this domain out from under him.