> don't want to serve as an oracle for the people whose malware they are trying to block
Those people don't have a registered business; The people contacting Microsoft do.
There are probably a bunch of excuses we can come up with that would make sense... but I think most people know the real reason, it's the same as with Google and Apple... they don't do customer support, and they don't take responsibility for any negative effects their services might have on others, at least not until someone big enough makes a fuss or lawyers get involved.
He's not saying there is. He's saying that it's pretty unlikely that the malware authors are going to phone Microsoft and ask why their site is flagged, so putting in some reasonable road blocks that a legitimate business would definitely jump over (e.g. talking to real people) would be plenty to remove the oracle issue.
Sure, maybe not display it in the publicly visible warnings, but if the admins of a domain email you from the same domain as the flagged site, then maybe providing more detail at that point is an acceptable method of fixing the issue.
Saying "we know you are compromised and know exactly where, but we're not going to tell" is very childish. Now, if they said for a nomial fee, we'd be happy to share the results of our work, would be another thing totally.
Not sure what you are saying here. I've only ever used TXT DNS records by copying&pasting whatever the original certbot told me to do or when setting up custom domain with 3rd party email. I have no idea what they do, who can read them, when, where, why, etc.
Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance? What does law enforcement do with this info?
> but if the admins of a domain email you from the same domain as the flagged site
Email domains aren't always match with domains running the web-site (don't forget only ten years ago www. was still expected and people redirected you there from non-www. name).
But having access to DNS zone you can prove 'ownership' (at least technical) of the domain (even if it doesn't have the associated MX records for e-mail), precisely why LE is doing it.
> by copying&pasting whatever the original certbot
> I have no idea what they do, who can read them, when, where, why, etc
Oh my...
> Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance?
More like "to prove you are the one responsible for tailspintoys.com - create a TXT record under that domain with 'dylan604 is admin here'".
> I have no idea what they do
TXT records are just plain text strings (in ASCII), nothing more, nothing less.
> who can read them, when, where, why
Everyone, anytime, anywhere, because it is you who placed it there in a system of Public DNS servers
Except that it could help attackers beefen up their tools. A certain amount of obscurity is good to keep the attackers from having too much information.
I've been in the situation where a company kinda 'ghosts' me before. And found out I was indeed the bad player (unintentionally, of course).
Those people don't have a registered business; The people contacting Microsoft do.
There are probably a bunch of excuses we can come up with that would make sense... but I think most people know the real reason, it's the same as with Google and Apple... they don't do customer support, and they don't take responsibility for any negative effects their services might have on others, at least not until someone big enough makes a fuss or lawyers get involved.