Hacker News new | ask | show | jobs
by Dylan16807 1401 days ago
Saying they detected malware already does that.

Being slightly more specific shouldn't be a problem.

2 comments

Sure, maybe not display it in the publicly visible warnings, but if the admins of a domain email you from the same domain as the flagged site, then maybe providing more detail at that point is an acceptable method of fixing the issue.

Saying "we know you are compromised and know exactly where, but we're not going to tell" is very childish. Now, if they said for a nomial fee, we'd be happy to share the results of our work, would be another thing totally.

"we know you are compromised and know exactly where, but we're not going to tell"

The sad think is they didn't even tell that, they gave the admins no ways to be able to differentiate between:

- we don't care if we destroy your company with a false positive and

- we are sure we are right, if you didn't do it intentionally you are probably compromised

TXT DNS records are used by Google, Microsoft and LE exactly for this purpose.
Not sure what you are saying here. I've only ever used TXT DNS records by copying&pasting whatever the original certbot told me to do or when setting up custom domain with 3rd party email. I have no idea what they do, who can read them, when, where, why, etc.

Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance? What does law enforcement do with this info?

> but if the admins of a domain email you from the same domain as the flagged site

Email domains aren't always match with domains running the web-site (don't forget only ten years ago www. was still expected and people redirected you there from non-www. name).

But having access to DNS zone you can prove 'ownership' (at least technical) of the domain (even if it doesn't have the associated MX records for e-mail), precisely why LE is doing it.

> by copying&pasting whatever the original certbot

> I have no idea what they do, who can read them, when, where, why, etc

Oh my...

> Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance?

More like "to prove you are the one responsible for tailspintoys.com - create a TXT record under that domain with 'dylan604 is admin here'".

> I have no idea what they do

TXT records are just plain text strings (in ASCII), nothing more, nothing less.

> who can read them, when, where, why

Everyone, anytime, anywhere, because it is you who placed it there in a system of Public DNS servers

Except that it could help attackers beefen up their tools. A certain amount of obscurity is good to keep the attackers from having too much information.

I've been in the situation where a company kinda 'ghosts' me before. And found out I was indeed the bad player (unintentionally, of course).