back
290 comments
The end of the article the owner talks about why he doesn't just give the domain name to Microsoft for the good of security, and he has imo a good reason - Microsoft fucked up and should shoulder the responsibility. Even more incredibly is it seems some requests were coming from Microsoft owned machines. He talks about how massive fortune 500 companies may be aware of the issue but unwilling to do anything about it.

So it seems, as ALWAYS, we're going to have to wait for state sponsored actors to buy the things, embarrass the shit out of a couple CEOs by posting their dick pics they're inexplicably sending over company mail, and THEN corps will start doing something about it.

Why we have to get on and off this merry go round every time is beyond me. Short-sightedness of those with decision making power boggles my mind daily.

As cynical as I may sound, but cybersecurity threats like this will continue to be ignored until they sufficiently escalate into consequences.

And that statement, while obvious, is darker than it seems. Companies going under aren't sufficient consequences (many ransomware cases). Universities going offline isn't enough (look for the uni giessen). The bureaucracy of cities going offline isn't enough (e.g. New Orleans).

This is just going to continue to escalate until something really really ugly happens and kills many people. And then we'll be presented with some grand legislation that I don't look forward to.

A more cynical interpretation is that he almost certainly tried to sell this to MS privately, and they didn't bite at the price he was asking. The public offering at $1.7M is likely an attempt to force their hand.

Frankly that doesn't sound to expensive given the context, it's probably less than Microsoft's existing bug bounty budget anyway. I don't know why they couldn't work this out, or why they never bothered to try to address the issue over the multiple decades this guy has been keeping this domain out of dangerous hands.

Just write the check, Satya.

Indeed, one could argue that Microsoft has been encouraging its customers to effectively spoof the domain. So it's totally obvious that it ought to buy it.

Still, this is the funniest thing that I've seen in months.

Is just invalidating the domain an problem? DNS exists to serve as a useful tool to society. If a particular domain becomes a public liability, just shut it down.

If there's credible reason to believe Microsoft is responsible for the liability, take them to court over it, but don't keep innocents at risk for the sake of trying to get Microsoft to own up to a mistake.

> The end of the article the owner talks about why he doesn't just give the domain name to Microsoft for the good of security

I can't even take that type of statement (in the article) with a straight face. You have an ordinary person presumably of typical wealth let's say average and he should just give something away for free 'for the good of security'.

Pain is required in order for people to make change.
As a Joe Shmoe I honestly think I would do the same thing as this guy, and I'd sleep OK about it. Should I forgo an 'exit' for me and my loved ones based on feeling some responsibility for the errors in cyber security of various profit seeking corporations owned by someone else?
>>The end of the article the owner talks about why he doesn't just give the domain name to Microsoft for the good of security,

Microsoft should buy it for the good of security. Why gift anything to a Trillion dollar company?

> Why we have to get on and off this merry go round every time is beyond me. Short-sightedness of those with decision making power boggles my mind daily.

Because someone will have to cut a 7 digit check. And nobody is going to volunteer their budget for that.

Until the bigwigs gets pantsed and command someone to cut the check, it simply won't happen.

> Schmidt’s findings closely mirror what O’Connor discovered in the few years corp.com was live on the Internet after he initially registered it back in 1994. O’Connor said early versions of a now-defunct Web site building tool called Microsoft FrontPage suggested corporation.com (another domain registered early on by O’Connor) as an example domain in its setup wizard.

> That experience, portions of which are still indexed by the indispensable Internet Archive, saw O’Connor briefly redirecting queries for the domain to the Web site of a local adult sex toy shop as a joke. He soon got angry emails from confused people who’d also CC’d Microsoft co-founder Bill Gates.

If only Gates had gotten more annoyed back then and bought the domain just to stop the emails...

I love how GoDaddy lets you add the corp.com domain, has a checkout page showing the $1690000.00 and a buy now button. It even has a promo code field, so I wonder if I can get a discount?
That sounds cheap.. Seriously, the potential to make a far bigger business out of *.corp.com is better than whatever current startups that VCs have been smoking.
You're funny, but I tried that with a GoDaddy account and I see no such thing. Screenshot?
I can't believe this situation.

This is a guy who, by his own admission, wants it to go to Microsoft, but is also holding an auction. He could just quote Microsoft $2M and be done with this whole thing.

Instead, he and this "security firm" publish a big article on one of the internet's most lauded security blogs where they outline how blown away they were with how much data was being sent to this domain. They left it open for 15 minutes and got millions of emails, passwords, etc. "Wow, bad people reading this, look at how much data you could get. You better join in on the auction. Microsoft, you seeing this? You better get in on this too. Bid often and bid well, friends."

I wonder what kind of authority ICANN has in revoking domain name registrations in extreme circumstances. Microsoft fucked up here, but we're long past that being a relevant component in this discussion. This registration should be pulled out from under O’Connor and blocked from registration for 100 years.

I am totally OK with the sale of this domain to anyone. He owns the domain and he has the right to sell it.

Perhaps the fallout would be good for computer security, as it would stop corporations from making boneheaded security decisions. Pain seems to be the only way to make corporations evolve anyways.

You're saying a domain ownership should be revoked based on a third party having bad defaults and the owner talking up the value of the domain?
I think an extreme circumstance would be someone hijacking microsoft.com and trying to ransom it off but I'm not really familiar with ICANN's specific powers.

Why should everyone in the world not get to use a thing because Microsoft has some naming scheme? These places have been shouting whatever data at a random (edit: unintentional and uncontrolled rather than random) spot on the internet for years and that's a huge problem.

Opening up an auction is a nice way to draw attention to the problem, get MS to literally&figuratively pay for it (even if the price 10x'd it's not like M$ couldn't handle $17MM), and make it no longer the seller's problem.

The story is not fully clear. It's possible he already tried to contact Microsoft and tried to sell it to them. They might have refused. But the idea of it going on an auction might pressure them into buying it.

Brian did contact Microsoft for comment, and their response doesn't mention that they want to buy it.

I consider it bad reporting that Brian doesn't mention whether Mike already contacted Microsoft or not.

> I wonder what kind of authority ICANN has in revoking domain name registrations in extreme circumstances.

Not even close to the way this works ICANN does not 'revoke' domain names. There are ways to take possession of a domain name but that would not be the process (nor should it be).

> He could just quote Microsoft $2M and be done with this whole thing.

If you think selling anything and in particular a domain name is that easy you should try to sell a domain name to a large corporation and report back the results. It's not trivial and to a large corporation in particular and further for any amount (much less way less) not assured in any way.

Because if he'd have done that, this wouldn't be news, it wouldn't be on HN, and this somewhat invisible security hole would remain in the shadows. Perhaps O'connor would be just fine with ICANN ripping this away from him, but perhaps that bluff needs calling.
> He could just quote Microsoft $2M and be done with this whole thing.

He could but MS would laugh in his face. The auction and publicity are the only way to establish the domain's actual market value and to pressure MS to pay it.

Am I wrong, or does one update from Microsoft make this whole drama go away and the "problem" a moot point?
Why bring up ICANN? They don’t control .com, verisign does.
Perspectives like this and others are one of the many reasons I greatly enjoy HN. I didn’t even consider the situation in this way, yet is makes much more sense than what I constructed in my head. Thank you for that.

What a persona this paints of the seller.

Would like to add that I also share your wonder. To me, this needs to evolve to anecessity for them (ICANN, in terms of ability) rather than just an “if”.

Please forgive me my lack of context surrounding this, but would love to learn more about why Corp.com is being sent various data (some sensitive, as mentioned in the article) from various parties in the first place. Did it use to serve a purpose for MS or other?

Why not take microsoft.com then in the same way. One could argue the software there has led to a ton of criminal activity. Since we've now decided that private property laws don't matter anymore, then this domain should be blocked from registration for 100 years. Let's throw in google.com. That has led to tons of crimes too, just from the malware ads, let alone everything else.

Obviously all these suggestions are equally ludicrous.

Also if this is such a big issue, you can simply configure your local DNS server to point that domain to whatever you want and ignore its original SOA.

If everyone would do that the domain would be worthless.

The easy resolution here would be for microsoft to push an update that does the moral equivalent of adding hosts file lines

    127.0.0.1 corp.com
    ::1 corp.com
That would break internal workflows for a lot of companies—they’re relying on “corp” as a bare TLD to resolve to an internal network endpoint.

I bet many IT admins would find this “quick fix” that would “make it work again” by effectively removing that /etc/hosts entry.

Perhaps a better patch would be to remove the [TLD] => [TLD].com DNS failover resolution feature.

What Microsoft should have done was read and implement https://tools.ietf.org/html/rfc1535 and apply a bit more learning from others and a bit more foresight when they were setting up this disaster in the 1990s.

I have a small bit of sympathy for them, because when Active Directory was first learning how to do domain names, they cost $100 per year and required a huge amount of bureaucratic nonsense. MS wanted to be able to sell their software to businesses that might never connect to the Internet. But they could have done a much better job.

1) windows has a hosts and resolve.conf file (don’t ask me where it is but I’ve seen it and it works)

2) what are likely the most risky applications tend to ignore the libc resolver and its configuration.

And, of course, a great many internal computers will _never_ get an update from Microsoft. https://gs.statcounter.com/os-version-market-share/windows/d... Windows 7 still has a quarter of the market...
That's hardly a resolution, because it assumes such an update would actually be applied to all the machines in question.
This may be, if as stated in the article, a national-security-level threat.

It should be handled as such. Not an auction to the highest (perhaps even foreign) bidder.

I wonder if buying it and participating in bug bounties en masse would be profitable in the long run.
OK, so a bunch of years ago, Microsoft suggested that AD domains/hosts should end in ".corp".

But where does the .com part come in to the picture?

Does corp.net or corp.ninja have the same type of issue?

Oh wow, this is fun. Legitimate question: Where can I bid on this? There's no link in the article and a Google search doesn't yield anything but spam.
Makes me wonder what's happening over at example.com, prod.com, dev.com, ad.com, and whatever other common similar names are out there.
Wait, so if Microsoft or done legitimate company doesn't buy it then it will automatically go to cybercriminals?
$1.7MM. cheap, considering. honestly if I had the money I’d snatch it up
Fwiw the correct way for Microsoft should they decide to bid on this domain to win this auction would be for them to make initial overbids that drive the price up to prevent others simply playing a game of chicken from taking hold and getting sucked into driving the price up even more.
He's known since 1997 (earlier?) that he has a dangerous domain. He had an offer from Microsoft "several years back" (curious how long ago) but he's holding out for something closer to "market"? I doubt he spent much money purchasing and maintaining the site over the years. Yes, Microsoft should get the purchase done at $1.7m. But O'Connor doesn't exactly come across as a saint here. Pay a "market price" for my sui generis dangerous domain or I'll sell it to the highest bidder...
Amazing this sort of thing is still around. I remember there was a similar sort of problem with WPAD (Web Proxy Auto-Discovery) domains like wpad.co.uk and wpad.co.nz that was publicised back in 2007

https://www.networkworld.com/article/2289705/windows-flaw-co...

Couldn't some organization buy it and let the IETF control it, like .local (not really a TLD, but the idea is what counts)
These days its .local - we should keep an eye on that
If it is such a bad risk, why doesn't one of the gazillionairs on here, or even YComb itself just write a check and park it. End of story.

I would; but sadly...I haven't hit yet.

A domain isn't property that anyone has to respect. I trust my domain resolver to point me at reasonable IP addresses. Not to criminals, people trying to entice criminals, or people trying to extort corporations. I appreciate the fact that the third is likely redundant with the first in most places.

I am entirely on board with just killing this domain out from under him.

Just wondering, IANAL, if Microsoft would be afraid of some type of class action lawsuit if buying the domain. Buying it could maybe be seen as taking responsibility for the error earlier committed and could open up a can of worms for Microsoft. In any case, I am sure Microsoft have their reasons for being quiet; it would be an easy problem to solve after all.