Cloudflare Scrubs Aisuru Botnet from Top Domains List

jtbayly | 50 points

If an automated service is pulling the top 100 domains from CF and naively trusting them, why can't it also pull the categorization information that's right there and make sure none of the categories are "Malware"??? Who would write something like that? It's absolutely believable that the top 100 domains could contain malware domains...because of the nature of botnets and malware.

That's PEBCAK.

arcfour | 26 minutes ago

> We should have two rankings: one representing trust and real human use, and another derived from raw DNS volume.

Isn't identifying real humans an unsolved problem? I'm not sure efforts to hide the truth that these domain are actually the most requested domains does anyone any favors. Is there something using these rankings as an authoritative list or are they just vanity metrics similar to the Alexa Top Site rankings of yore? If they are authoritative, then Cloudflare defining "trusted" is going to be problematic as I would expect them to hide that logic to avoid gaming.

bradly | 38 minutes ago

> Aisuru switched to invoking Cloudflare’s main DNS server — 1.1.1.1

I don’t suppose they use DNS to find their command-and-control servers? It’d be funny if Cloudflare could steal the botnet that way. (For the public good. I know that actually doing such a thing would raise serious concerns. Never know, maybe there would be a revival of interest in DNSSEC.) I remember reading a case within the last few years of finding expired domains in some malware’s list of C2 servers, and registering them in order to administer disinfectant. Sadly, IoT nonsense probably can’t be properly fixed, so they could probably reinfect it even if you disinfected it.

chrismorgan | 36 minutes ago

given the anti-user behaviour of modern Windows, shouldn't microsoft.com be down as malware too?

after yesterday's reveal[1]: facebook should certainly be down as "scams"

[1]: https://news.ycombinator.com/item?id=45845772

blibble | 37 minutes ago