9 ms·
It's Way Too Easy to Get a .gov Domain Name
- forgingahead 7y agoGood reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs had gone off at polling stations in Democrat-leaning districts. Such a hoax could well decide the fate of a close national election. Why the need to specify "Democrat" strongholds? Doesn't this attack work for any other political-party strongholds as well? Seems like an unnecessarily partisan position to take.
- aspaceman 7y agoDue to differences in Democrat and Republican voter demographics, one is more heavily affected than the other.
- katet 7y agoI see what you mean, but I suspect the author might be referring to the Russian disinformation campaign to favour Republicans. I see it just as an example - obviously it can be adapted in either direction, or both just to deter voter participation altogether.
- larnmar 7y agoIt would be shocking, though, if it turned out that Russia was the only country trying to influence US elections, though, instead of the only one that has been publically exposed.
- krn 7y agoYet, with an exception of Iran, the countries with most aggressive foreign policies (Russia, China, North Korea, Saudi Arabia, and Turkey) seem to currently support the election of Republican nominees.
- C1sc0cat 7y agoOnly certain republicans though
- deleted 7y ago[deleted]
- Iv 7y agoI think many countries assessed that they were capable of it, but many would think this was a casus belli. Had Clinton been elected instead, she probably would have sought additional sanctions and a firmer stance against Russia because of this.
- paggle 7y agoI don’t think the Russian agenda favors Republicans — it favors sowing chaos. Trump was certainly that candidate in 2016 but that could change.
- deleted 7y ago[deleted]
- microcolonel 7y agoIt's a figure, not every sentence needs to have stand-in characters written in to appeal to sensitivities like this. Also, maybe if he chose “Republican” it wouldn't hit home, and it'd sound like he's threatening his audience with a good time. ;- ) It could be criticized regardless of the characters chosen.
- walrus01 7y agoThat specific paragraph is a lot of weirdness. But once you have the domain, somebody who knows what they're doing with DNS and SMTP absolutely could set up proper email services on it (forward-confirmed rDNS, SPF, DKIM signing, DMARC), and send spam with it. It's functionally equivalent to any other domain. Particularly if the intention was to be a one-shot approach that would "burn" both the domain and the hosting services, such as in the days leading up to an election. A really smart bad actor would use some IP space from an ISP that traditionally has not been a source of spam. Eg: Not an ISP with a lot of low-dollar-value VPS/VM/hosting customers. There's still some totally "clean" /24 IP blocks out there in the various RBLs and spam listing services if you go searching. If I were an evil person and did this, I'd try to get the domain at least a few weeks in advance and try to generate a moderate volume of totally legit looking emails, destined for the top 20 major destinations (office365, gmail, etc) and verify from a bunch of sockpuppet accounts that the mail was actually getting delivered. Then I'd turn loose the fire hose. Should a person want to be really evil, they'd do something like the reverse of what happened to the City of Baltimore with the cryptolocker trojan. Find a list of municipal (water, sewer, gas, electrical, property tax) bill payers and email each of them a plausible looking invoice, with cryptolocker attached. The likelihood of people opening it would be high.
- ekimekim 7y agoLarge cities tend to be blue, and you want to pick a recognizable large city name to get the point across. Politics aside, the example would've had less impact for a republican stronghold just because it wouldn't be as recognizable a city name.
- OrgNet 7y agodid he name any cities?
- quantum_magpie 7y agoYes, Miami.
- xwowsersx 7y agoAgreed, that was totally gratuitous and it detracts from the article.
- MereInterest 7y agoOne of the major political parties in the US has been repeatedly engaging in voter suppression. Is it partisan to observe repeated behavior on one side of the political spectrum, and to extrapolate accordingly? https://en.wikipedia.org/wiki/Voter_suppression_in_the_United_States https://en.wikipedia.org/wiki/Voter_suppression_in_the_Unite...
- judge2020 7y agoSpecifying "democrat" in this particular example of how an adversary having a .gov domain could be bad adds nothing to the example.
- soperj 7y agoFrom an outsiders perspective, there's very little difference between both your political parties.
- bsder 7y agoThen you haven't been paying attention very much. One party appears to be on the Russian payroll, the other isn't. And while you may not wish to pay attention to US or UK party politics, you might want to check which parties from your government might be on the Russian payroll.
- bcrosby95 7y agoOne party asked for voter data by race, then got rid of voting methods disproportionately used by black people. The same party also passed voter ID laws, and allowed NRA membership cards but not college ID cards. Your comment amounts to "I'm ignorant, but to me both parties are the same".
- soperj 7y agoAnd the other party is guilty of nothing?
- dependenttypes 7y agoI don't know about NRA membership cards but I know for a fact that college ID cards tend to be quite easily to forge. Regardless, it seems very weird to me that they would accept non-government issued IDs for elections.
- GeneralMayhem 7y ago>Why the need to specify "Democrat" strongholds? Because that's what's been observed in the past few decades. Republicans in power attempt to suppress votes, especially in inner cities. Democrats do not. Moreover, the hypothetical is referencing misinformation campaigns carried out by Russian intelligence agents in 2016, which were specifically designed to benefit the Republican party. >Doesn't this attack work for any other political-party strongholds as well? Since large, dense cities tend to vote left-wing, right-wing parties don't really have as many "strongholds" in the same way. This kind of attack on miami.gov would likely have a lot more impact than jacksonville.gov.
- SlowRobotAhead 7y ago> Republicans in power attempt to suppress votes, especially in inner cities. Democrats do not. Citation?
- GeneralMayhem 7y agoHere's about a hundred: https://www.americanprogress.org/issues/democracy/reports/2018/11/20/461296/voter-suppression-2018-midterm-elections/ https://www.americanprogress.org/issues/democracy/reports/20....
- SlowRobotAhead 7y agoGreat link! It would be a lot greater if it wasn’t Hillary Clinton’s campaign manager John Podesta and George Soros saying Republicans are just evil. Seriously, did you take even 1/2 a second to look at who the organization was? Or were you just hoping I wouldn’t? Yea that’s ok, just downvote with a different account and ignore the point that your source was absolutely as biased as possible.
- save_ferris 7y agoThe Houston Chronicle reported today that the Texas GOP plans to purchase several domains resembling democratic candidates and run active disinformation campaigns against them using fake campaign sites[0]. Might’ve had something to do with it. 0: https://www.houstonchronicle.com/news/politics/texas/article/Texas-Republican-Party-plans-to-build-phony-14863988.php https://www.houstonchronicle.com/news/politics/texas/article...
- drak0n1c 7y agoAnother news story today is the lawsuit against the "Devin Nunes' Cow/Mother" Twitter accounts run by anonymous DNC personnel. In each of these incidents the "disinformation" label is used by partisan officials and obsessively repeated by the media (because the creator's identity is not placed in large font at the top), but anyone who looks at it themselves can clearly see that such is satire and opposition material. This one is particularly great. Made by an enterprising private individual. https://joebiden.info/ https://joebiden.info/
- kevingadd 7y agoWhen was it confirmed that those twitter accounts were run by the DNC and not just ordinary people? Did the owners break anonymity to the press to prove ownership even though a lawsuit is trying to reveal their identity? That's wild.
- lightbyte 7y ago"Devin Nunes' Cow" is obviously a satire account. As the judge ruled, a cow clearly can not tweet so nobody reasonably can believe that is actually his cow. "ZweinerforTexas.com", "ZweinerforTx.com" are not obviously satire, they look like normal campaign urls and are clearly made to deceive.
- smcl 7y agoWell, yes and no. Yes - he could've chosen not to name a party at all and the point would have stood. However it's not simply a matter of opinion to suggest that the Republican party attempt nefarious electoral tricks to discourage (or outright ban) people from voting. It's now pretty much party policy.
- minikites 7y agoExactly. The problem with "both sides" reasoning is that often times it really is only one side to any meaningful degree.
- Iv 7y agoI'd say it is an unnecessary position to take but would not call it especially partisan. There is no symmetry in the amount of election meddling that has been done by both parties. Saying the GOP may be a party interested in election meddling is like saying Iran may be interested in funding islamist terror groups. An unnecessary accusation, but hardly a partisan one.
- ptah 7y agorelated: https://news.ycombinator.com/item?id=21110318 https://news.ycombinator.com/item?id=21110318 tldr; republicans tend to win by slimmer margins compared to democrats
- minikites 7y agoDemocrats _want_ people to vote, most voter registration drives and voter services (offering transportation to a polling place, etc) are run by Democrats or aligned organizations.
- green1 7y agoIt's a fairly ridiculous scenario in any case. 1. Attacker needs a .gov from a swing state 2. No they don't, because nobody who'd fall for this would analyze the sender address/website URL, let alone for .gov instead of .org/.net/.com, and there's zero need to emulate a gov website anyway, when emulating a news site would be at least as effective 3. It relies on people reading an email on election day before voting and then not bothering to verify what it says anywhere, not having someone tell them it's fake and not hearing about the scam on the news they're watching for the bomb story
- njharman 7y agoThat is such a complicate movie plot threat. Far more direct to just spread those rumors through social media. Which more people pay attention to and believe than .gov. Or just make actual bomb threats.
- RandomBacon 7y agoThe title reminds me when someone reported that it was just as easy to get fully-automatic firearms and other military gear from homeland security for free by pretending to be a police department (fake website) and a simple form.
- microcolonel 7y agoThere are other more straightforward ways to illegally purchase post-hughes machine guns. This is an extremely high risk scheme.
- npo9 7y agoYeah but A) military gear is more than automatic weapons. Sometimes they send out things harder to come by than guns to police departments. B) This scheme costs less than pennies on the dollar.
- catalogia 7y agoThis scheme only makes economic sense if you neglect to factor in the cost of being sent to federal prison for many years.
- girvo 7y agoThough that's still a risk even if you're getting them on the black market, or manufacturing modifications for legally bought AR-15s et al. yourself
- manigandham 7y agoIsn't that part of the cost with all the schemes?
- microcolonel 7y agoYeah, but anyone with access to a machine shop can make good machine guns, it is very easy. This is one of the lower risk approaches.
- nodesocket 7y ago> who said he got a .gov domain simply by filling out and emailing an online form, grabbing some letterhead off the homepage of a small U.S. town that only has a “.us” domain name, and impersonating the town’s mayor in the application. He also can get prosecuted and potentially jail time for such a gamble.
- Nextgrid 7y ago> He also can get prosecuted and potentially jail time for such a gamble. I'm sure such a threat is definitely going to stop the bad guys, so let's not worry about actual security. /s The people that should be prosecuted are the ones falling for such an obvious fraud. If you're in control of the .gov TLD and explicitly tell people to use the domain as a sign of legitimacy you are expected to know what you're doing and not be an idiot like the people currently running it.
- sb057 7y agoIf you want some irony, from the "dotgov.gov" website linked in the post: >An official website of the United States government. Here's how you know: >The .gov means it's official. Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site.
- bonyt 7y ago> A review of the Top 10 most populous U.S. cities indicates only half of them have obtained .gov domains, including Chicago, Dallas, Phoenix, San Antonio, and San Diego. > Yes, you read that right: houston.gov, losangeles.gov, newyorkcity.gov, and philadelphia.gov are all still available. As is the .gov for San Jose, Calif., the economic, cultural and political center of Silicon Valley. A minor nit: Many of these cities do have a .gov domain. For example, NYC has nyc.gov. So, I would suspect (or I’d hope) the GSA wouldn’t issue newyorkcity.gov to a random fraudster as easily. Houston has houstontx.gov. Philadelphia has phila.gov. San Jose has sanjoseca.gov. LA has .. lacity.org? That’s a bit unexpected. Some cities may also use a subdomain of their states domain, which may or may not be a .gov.
- profmonocle 7y ago> Some cities may also use a subdomain of their states domain, which may or may not be a .gov. This reminds me of how longwinded the domain hierarchy for .us originally was. In MN (not sure if it's the same for every state), city domains were "www.ci.cityname.mn.us". Then the school district's web site was "www.cityname.k12.mn.us". Not only was the order inconsistent (why not www.k12.cityname etc.?) but sometimes the city might be typed differently - i.e. the main Minneapolis site had "minneapolis" in the domain, but the school district had "mpls". In the primordial days of the web, back before good search engines, this didn't make it very easy to find the school's web site. Fortunately many governments realized this and moved once .gov became available to cities & states. (or they just used .org). For instance Minneapolis uses minneapolismn.gov, but many are still on the old style domains. The school district uses mpls.k12.mn.us, but at least they've dropped the "www."
- markovbot 7y agothose are called .us locality domains. ci.<locality name>.<state>.us is assigned to the city, there are several other similarly non-obvious assignments, anyone is permitted to register one. I found this page that talks about it more: http://telecafe.org/smw/.US_Locality_Domains http://telecafe.org/smw/.US_Locality_Domains
- semi-extrinsic 7y ago
- kitteh 7y agoI remember when it was easy to get edus. Recall someone who had irc.edu until they got caught.
- iamleppert 7y agoSounds to me like this researcher is going to be brought up on charges. Well deserved charges. We don’t know what he did with this domain before he contacted krebs. He very well could be covering his tracks and creating plausible deniability. You break the law, you go to jail. Simple as that. They aught to make an example out of him.
- saagarjha 7y agoSurely everyone already knows what happens if you maliciously create a .gov domain? What would making an example of this security researcher do, other than have a chilling effect on the field as a whole?
- dependenttypes 7y ago> Well deserved charges Who was the victim?
- Biganon 7y ago"You break the law, you go to jail. Simple as that." This is laughably ignorant. It's absolutely not simple as that, by chance.
- ryanlol 7y agoIs there a point you’re trying to make with this weird tirade?
- Thorentis 7y ago> “I used a fake Google Voice number and fake Gmail address,” said the source, who asked to remain anonymous for this story but who said he did it mainly as a thought experiment. I don't think "thought experiment" applies to actually carrying out what you were thinking about.
- yoaviram 7y agoCame here to say the same thing. I'm surprised how often people misuse the term. Here's my attempt at explaining what are thought experiments: https://thoughtexperiments.net/pages/on-thought-experiments/ https://thoughtexperiments.net/pages/on-thought-experiments/
- Eiriksmal 7y ago>Technically, what my source did was wire fraud (obtaining something of value via the Internet/telephone/fax through false pretenses); had he done it through the U.S. mail, he could be facing mail fraud charges if caught. Yeah, I'm pretty confident that a true thought experiment can't lead to wire fraud charges. "Security research" seems like a more popular, and reasonable, umbrella to hide behind.
- deleted 7y ago[deleted]
- KingMachiavelli 7y agoIsn't the main issue that TLDs are a poor way of establishing trust? Otherwiae does every company and government need to get specialized TLDs to prevent impersonation? Even then it only works is users know and always notice the domain. EV certs are dead for good reason but nothing seems to have replaced them. I guess the only option is to verify each site once and then bookmark it and always make sure it's https. But on the first visit, how do I know chase.com is Chase Bank?
- frei 7y agoWell the back of my Chase card says chase.com. If you tend to use search engines to find websites, you are trusting the search engine to give you the website for Chase Bank.
- why_only_15 7y agoI feel like google is less likely to give me something fraudulent than e.g. the risk of me misspelling chase or the like
- laken 7y agoan attacker could purchase google ads for "chɑse.com" (note the unicode "s" instead of "s"
- knolax 7y agoIsn't the homoglyph the IPA "ɑ" character used in place of Basic Latin "a"? The homoglyph URL attack also has some downsides because Unicode is only supported for domains through an extension system, most browsers will convert the above to "xn--chse-r5b.com" after you visit the link.
- deleted 7y ago[deleted]
- why_only_15 7y agoSeems unlikely google would let scammers with fake domains purchase ads, though maybe they have in the past.
- rshnotsecure 7y agoI would also like to add signing up for an AWS Gov account was at least 12 months ago...a completely automated process where I was approved in no more than 15 mins. The account had a credit card but otherwise was 100% still in free tier mode, and in fact was being used by an open source team so it included ppl from around the world. The CIA has stated multiple times in court documents (typically they have emerged in cases where the FBI attaché that all embassies have post-911 or someone similar is testifying) concerns about this and why they demanded and got “AWS secret”, a level higher than gov, that was opened in 2017. Keep in mind though that many governments at state and local still use the TLD of “.us”. For instance Texas has widely used, until within the last year, “https:<subdomain>state.tx.us”. Many states have this legacy naming convention left over, and of course the restrictions are about as somewhat paper thin and avoided on .us as they are on .gov but more. There are changes in the works for this though. More concerningly though is that the recent issue with the .org TLD clearly, and this can be proven in a straightforward manner, involves a group with unlimited funding by the People’s Liberation Army making this purchase. Ethol Capital is a joke of a firm. They’ve already sanitized the Google Search Results about them, which lol should be obvious when you realize they have taken out a Google Ad for “keypointsabout.org” when you Google them. The proof though is that if you look at court documents from 2015 you will find mention of a firm...SharkTech. Another front company that the PLA loans out from time to time to the Middle East and even as I recall Israel. Anyway as I’ve stated before in comments if you do the reverse Whois searches and dns subdomain enumeration you can find the trail back to No 31 Jin-rong Street. I’ve been asked before to write a post about this always elaborating and Christ I finally took out a domain https://blog.12security.com https://blog.12security.com ... it has nothing on it but Jesus just look at the DNS records it took forever to get that DMARC record to the strictest level involving no 3rd parties and also to split that DKIM key across 3 txt records...which you have to do sometimes for the 2048 keys. EDIT: forgot to mention there is obviously a connection between SharkTech and Ethol Capital. That will be proven in the blog and it is on me and my very tardy credibility to do it :) look at http://dcsmanage.com http://dcsmanage.com out of Los Angeles though if you want to get a head start, and if anyone claims that’s a real IT firm...
- justinclift 7y agoIf all the above is reasonably easy to verify, you might like to email Krebs about it for wider dissemination. ;)
- HNLurker2 7y agoThis is what I used to do back in the day, to get high pagerank(remember that?) In Google
- frei 7y agoYou used to defraud the US Government back in the day? For pagerank? Did you get in trouble?
- C1sc0cat 7y agoIt was more .edu's back then, I came across more than one (presumably hacked) professors personal sites that where hosting link spam directories
- Thorrez 7y agoIf we go back to the original PageRank algorithm, I don't think it would be affected by this attack. The original algorithm just counts the number of links (or number of sites making links), not the TLDs. So a .com site would be just as good as a .gov site.
- HNLurker2 7y agoYes but they used to had, I remember correctly higher PR. Back in the day (Twitter had 10, Google had 9 and any gov had 7 atleast) I used to buy those and link to my directory webs.
- Thorrez 7y agoInteresting that this was done very shortly after the DOTGOV bill was introduced. It's possible that this attack was done by a supporter of the DOTGOV bill in order to provide evidence to help the bill pass.
- xyz-x 7y agoDoes anybody know why the USA hogs the toplevel domain? It's not the only government in the world. It would seem more just to make it more like .com than .edu.
- zokier 7y agoIt's a perk from building the internet. Early bird gets the worm etc
- avocado4 7y agoBecause they came up with it.
- ptaipale 7y agoObviously, because of history of Internet deriving from Arpanet. The whole domain name structure grew out of the needs of the US government, even if the .com domain was largest TLD from the start.
- astura 7y agoNope, .gov belongs to the US, so they get to hog it. It's a historical vestige, the Internet started out as a U.S. government-sponsored research network, so they built it for their own needs. There's absolutely no reason to them to give that up.
- velosol 7y agoIn addition to all the siblings, government isn't always spelled with 'gov' so it would be useful to the subset of countries where those letters make sense. Compared to say Mexico with http://gob.mx http://gob.mx .
- curiousgal 7y agoTangent. This guy has the best and probably most read blog on cybersecurity incidents. He's smart enough to serve ads from his own domain but can't even bother to make his site mobile friendly? I've seen people pick on the sites of free tools and side projects for the same reason but somehow this gets a pass.
- tsukurimashou 7y agohe does whatever he wants
- curiousgal 7y agoSo do I, which is why I blocked all images on his site.
- Biganon 7y ago...yeah? And? Everyone does whatever they want, not even criminal law makes it impossible to act a certain way. What's your point? It's still a terrible design choice, and it alienates a great number of potential readers.
- tsukurimashou 7y agonot everything is a business, maybe he just writes blog posts for fun / himself
- frozenport 7y agoLooks fine on mobile Firefox
- astura 7y agoWell, it loads instantly and I can read it just fine on my mobile device, which is more than I can say for half of "mobile friendly" sites out there, so there's that... Anyway, he mentioned about a year ago that he knows the design of his blog is outdated, and he was looking at making it more modern.
- 7y ago
- aaron695 7y agoThis is dumb. If someone is doing this, then link? Else it's obviously to much bother, you're domain will get axed. Compare to all the domains that won't get axed. Do they real expect us to believe the population will get fooled on a losangeles.gov but not losangelesgovernment.ws, the difference will be a small percent. > then on Election Day send out emails signed by .gov Why the hell won't these be junked like any spam? New domain. Sudden flood. People marking as spam. What, are we in 2010?
- neiman 7y agoTogether with selling .org to Ethos Capital, we're getting a worrying picture of problems with the current model of managing TLDs. Managing TLDs is a lot of power in 2019, since the Internet is such a powerful player now. I'm not sure what's the best way to manage it, but I am sure that if we leave it as is, we'll see more and more deal with dodgy commercial entities or more entities getting domain names they should not own.
- Jaruzel 7y agoCo-incidently, I just watched a Family Guy episode where Peter and Tom Tucker shoot a skateboarding video, which ends up with Peter being attacked by a bear. The skit ends with a fake advert for www.shirt.gov Obviously, they thought that there was no way someone could register shirt.gov... how wrong they were ;)
- Chancellorrr 7y ago<script>test</script>
- zurn 7y agoOr too hard - why are they US only?
- anoncake 7y agoWhat would be the point? How often do you want to make sure you are on a government website without even caring of which country?
- delfinom 7y agoIt's the legacy of the internet starting off in the US. The US Government laid claim to .gov. Other countries instead operate .gov.countrytld
- zurn 7y agoOnly a handful of countries operate .gov.countrytld, they are mostly named like someoofficename.countrytld.
- astura 7y agoBecause they created it as one of the original TLDs (along with .arpa, .com, .org, .net, .int, .edu, and .mil) for their research network, ARPANET. Later on the Internet was built from ARPANET.
- zurn 7y agoBut those others are not US-only, except .mil
- deleted 7y ago[deleted]
- walterkrankheit 7y agoI wonder if anyone's done any sort of research on how many possible fraudulant .gov sites there could be. Definitely seems like a tool disseminators of fake news and hate campaigns would do.