news.volyx.in

We spent $20 to achieve RCE and accidentally became the admins of .mobi (labs.watchtowr.com)

1624 points by notmine1337 · 696 days ago · 367 comments on HN

Article summary

Researchers spent $20 to acquire an expired domain of an old WHOIS server, which allowed them to gain control over the .mobi top-level domain and potentially undermine the security of the internet. They discovered that many organizations, including certificate authorities, were still using the old WHOIS server, making them vulnerable to attacks. The researchers were able to demonstrate a proof-of-concept attack, highlighting the fragility of the internet's infrastructure. This incident raises concerns about the security and integrity of online communications.

Main themes

  • WHOIS server vulnerability
  • Internet infrastructure security
  • Certificate authority trust
  • Domain name system
  • Security protocols

What commenters say

  • The internet's reliance on outdated protocols and lack of standardization is a major security concern.
  • The use of DNSSEC and other security extensions is not a silver bullet and may not be sufficient to address all security concerns.
  • The security of the internet is only as strong as its weakest link, and DNS is a systemic weak link in the chain of trust.
  • Certificate pinning is not a common practice and may not be an effective solution to mitigate DNS compromise risks.
  • The evolution of standards and protocols is necessary, but it is a complex process that involves politics, investment, and coordination among multiple stakeholders.
  • The dominance of a few major tech companies may actually make it easier to address security issues, but it also raises concerns about centralization and control.
  • The state of IPv6 support is still lacking in many areas, including cloud services and networking gear, which hinders the adoption of more secure protocols.
  • Human relationships and trust are essential in verifying identities and securing online transactions, but they can also be vulnerable to social engineering attacks.