Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Microsoft is only sending traffic from computers that are infected to Microsoft instead of No-IP.

Unfortunately that's false. See below:

dig -t ns no-ip.biz

; <<>> DiG 9.9.2-P2 <<>> -t ns no-ip.biz ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 7020 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 2

;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4000 ;; QUESTION SECTION: ;no-ip.biz. IN NS

;; ANSWER SECTION: no-ip.biz. 7154 IN NS ns8.microsoftinternetsafety.net. no-ip.biz. 7154 IN NS ns7.microsoftinternetsafety.net.

;; ADDITIONAL SECTION: ns8.microsoftinternetsafety.net. 3560 IN A 157.56.78.93

;; Query time: 3 msec ;; SERVER: 10.1.1.3#53(10.1.1.3) ;; WHEN: Mon Jun 30 14:14:47 2014 ;; MSG SIZE rcvd: 117



The funny thing is that "microsoftinternetsafety.net" sounds just like a domain that a fake antivirus software would use.


so true, I would not trust that domain at all.


What DNS are you using?

On Google (8.8.8.8) or Comcast DNS I'm not seeing this for their top domains (no-ip.org, no-ip.biz, no-ip.info).

I wonder if your ISP is working with Microsoft.


This is simply a side-effect of how DNS updates. The data is propagating right now, as the root nameservers for the .biz tld are already returning the Microsoft DNS servers as the correct response. The TTL for the root appears to be a day, so you should see this everywhere in 14 hours from this post.

Source: 'whois' and 'dig +trace'


Ha. Good point. This was done at work, where we use MS Server's DNS.

<strike>I'm not sure if this is an artifact of our longer TTL, if MS is updating MS server DNS entries, or something else. Either way, at some point in time or in certain places, traffic resolved by no-ip was/is under Microsoft control.</strike>

EDIT: Looks like it may actually be a result of our shorter TTL, since google DNS appears to have 5.7 hours left on their records for no-ip.

Confirmed by a couple queries to the {a..k}.gtld.biz nameservers.


It's strange, I've yet to see it too, in Canada. Must be within a limited area for the ISP, or thanks to the collaboration with A10 Networks.

E.g. https://www.whatsmydns.net/#NS/no-ip.com




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: