• Lammy 9 hours ago

    To avoid my comment being entirely a terminology nitpick I will say this is very cool work that I would be too afraid of CFAA to ever attempt. Especially funny to see four parasites on one government domain. Do skiddies not excise other skiddies' backdoors when pwning systems so they can have them all to themselves?

    > We then hooked that up to the AWS Route53 API, and just bought them en-masse. Honestly, it’s $20, and we’ve done worse with more.

    > We’re incredibly grateful for the support of The Shadowserver Foundation, who have agreed yet again to save us from our own adventures and to take ownership of the domains implicated in this research and sinkhole them.

    I wish we could collectively stop using the terms “buy” and “own” with regard to domains. Try “leased” or “rented”. If they could be bought then they wouldn't have been available again for this exercise.

    • judge2020 an hour ago

      What would buying even mean in this sense? Even countries don't "own" their ccTLDs, but ICANN has made considerable efforts to outline policies that go "we really need to treat ccTLDs like the countries own them to avoid tensions over internet namespaces". That's why most gTLD rules don't apply to ccTLDs.

      Countries "own" their ccTLD in the sense that they (or most) have the military prowess to defend their usage of their ccTLD if ICANN, or the servers at root-servers.net, were to stop resolving TLDs appropriately.

      • awwaiid an hour ago

        All property, physical and digital, is rented if you squint just right.

        • noduerme 24 minutes ago

          I'm curious if this is a socialist lament about landlords or a libertarian complaint about governments.

      • fn-mote 5 hours ago

        I loved this write up. Light-hearted. Conscious of the impact of any disclosure. Everything substantiated, but not taking themselves too seriously. Enjoying read, and at the same time talking about a serious issue.

        • ipdashc 39 minutes ago

          Thank you for putting it in words. I felt the same way, both about this and the writeup for their previous .mobi thing. Well explained with plenty of context, no buzzwords, light hearted and cool (while not trying too hard to make themselves sound cool), and plenty of substance with no fluff. A lot of blog posts or security write-ups violate some of these; this is a breath of fresh air.

          • taspeotis 2 hours ago

            I also loved the appearance of WordArt, shame they did not do the rainbow one.

          • pea 43 minutes ago

            Blast from the past seeing h0no mentioned.. Brings me back to days of darpanet/m00/#darknet/dikline

            • Thorrez 7 hours ago

              I wonder what would happen if they exploited these webshells' backdoors to delete the webshells...

            • busymom0 5 hours ago

              Slightly off topic but what's going on with the font for the "y" character in this article? It sticks out like a sore thumb.

              • 8organicbits 4 hours ago

                I find this sort of thing bothers me often enough that I've disabled downloadable_fonts. I think of the web as a place where I read things, so custom fonts that hurt readability are undesirable. I get why designers want a unique style, but I rarely want that as an end user.

                • npteljes 4 hours ago

                  I think some fonts do this so that they have a distinguishing feature. Fonts seem to be a very saturated market, so this might help being noticed in a crowd of sameness and copycats, and many people don't look at a font otherwise either, even people who use them in designs.

                  I think the sticking out part is supposed to irritate somewhat, but it still needs to make some sense, like a hot take. I noticed some online personalities use the same strategy with pronunciation, consciously and consistently mispronouncing specific words, play up their accent. Media analysts also recognize verbal tics as a trope, for similar effect.

                  Back to fonts, another site that I remember using a similar thing is the Genius lyrics site. For a long time, while establishing their presence, they used the square character forms from the Programme font, which you can see on my link. They still use Programme, but use the normal forms for some time now though, presumably, because it was indeed irritating, and it hurt legibility.

                  https://www.typewolf.com/programme

                  • sosborn 5 hours ago
                    • roygbiv2 2 hours ago

                      Wow what is going on with that website.

                      • busymom0 5 hours ago

                        Looks like the font provides an "alternative y" which looks normal. But the default one has that ugly broken look.

                    • Its_Padar 9 hours ago

                      Technically this is a dupe as this has been submitted twice before in the last week

                      https://news.ycombinator.com/item?id=42658405

                      https://news.ycombinator.com/item?id=42633273

                      • blendergeek 9 hours ago

                        It only counts as a dupe if it received discussion/upvotes last time.

                        • catoc 7 hours ago

                          The first link is also watchtwr, but a different post