HN user

StuntPope

3,168 karma
Posts143
Comments108
View on HN
dnsskills.md 16d ago

Show HN: DNSskills.md – agentic skills for certain DNS utilities

StuntPope
3pts1
easydns.com 19d ago

Bought an expired domain. Then I inherited their AWS Root account

StuntPope
9pts3
tunnel.to 1mo ago

Show HN: Tunnel.to – dead simple localhost reverse tunnels

StuntPope
7pts1
easydns.com 1mo ago

GPG-encrypted email forwarding is back, and the mxcrypt relay is now open source

StuntPope
8pts0
axisofeasy.com 3mo ago

Internet Content Regulation Is Coming to Canada

StuntPope
7pts0
easydns.com 3mo ago

Age verification now required for DNS resolution

StuntPope
47pts17
bombthrower.com 5mo ago

Repricing Sovereignty: Personal Freedom in the Age of Mass Compliance

StuntPope
3pts0
easydns.com 6mo ago

Can x402 save the Open Source Software movement?

StuntPope
8pts1
domainsure.com 1y ago

No, Your chatbot can't be hacked via DNS (at least not on its own)

StuntPope
6pts0
easydns.com 1y ago

Grappling with the Existential Panic over AI

StuntPope
4pts0
bombthrower.com 1y ago

Is ChatGPT Intentionally Driving You into Psychosis?

StuntPope
8pts2
easydns.com 1y ago

Canada's "Strong Borders Act" (Bill C-2) Contains Four Surveillance Provisions

StuntPope
14pts1
easydns.com 1y ago

EasyDNS First to Use AI to Answer All DNS Queries

StuntPope
7pts0
bombthrower.com 1y ago

"It's the denominator, stupid" (Groking Bitcoin's inexorable rise)

StuntPope
3pts1
cronly.app 1y ago

Crontab.ninja: natural language in, cron expression out

StuntPope
6pts0
axisofeasy.com 2y ago

The Google Algorithm Leak: The TL;DR on what you need to know

StuntPope
1pts0
bombthrower.com 2y ago

Private Equity "Adds Value" in a Fiat-Financed World

StuntPope
1pts0
twitter.com 2y ago

No, Apple did not launch their own crypto, it's a wallet drainer (thread)

StuntPope
2pts0
easydns.com 2y ago

Everybody's aware that Google will start enforcing DMARC Feb 1st, right?

StuntPope
35pts18
old.reddit.com 2y ago

Everybody's aware that Google will start enforcing DMARC Feb first, right?

StuntPope
1pts0
www.darkreading.com 2y ago

Critical bug in WS_FTP (40M users) allows for RCE

StuntPope
4pts1
easydns.com 2y ago

UK version of “Online Harms Bill” wants to prefilter content without due process

StuntPope
169pts105
decrypt.co 3y ago

Phishing attack leaks 100K ChatGPT logins on Darkweb

StuntPope
3pts1
www.fox5dc.com 3y ago

State of Maryland lets domain expire, hilarity ensues

StuntPope
1pts3
easydns.com 3y ago

Canada’s cyber-security Bill C-26: Yet Another Government Power Grab

StuntPope
39pts5
easydns.com 3y ago

Move over Mastodon, here comes Nostr (and to set up your NIP-05 id)

StuntPope
8pts1
bombthrower.com 3y ago

Why Proof-of-Work Is Superior to Proof-of-Stake

StuntPope
6pts1
easydns.com 3y ago

Added Native Support for Ethereum Name Service (ENS) .ETH Domains

StuntPope
3pts0
easydns.com 3y ago

Solving the “Fake Twitter Profile” Problem Using DNS

StuntPope
8pts0
bitcoinmagazine.com 3y ago

Simplifying Bitcoin Addressing Using DNS

StuntPope
7pts1

We've added agentic skills for five DNS utils we've had on the Domainhelp site for awhile (formerly easyWhois)

These ones are handy:

1. What is my public IP

2. What is my DNS resolver (handy)

3. Is this a homoglyph (have your openclaw check this before blindly following a link)

4. SPF Flattener

5. DNS Twister

More to come.

I run a DNS company (some of you can probably guess which one), and a few weeks ago one of my nephews was showing me his home setup and asking about local tunnels.

He already knew about Cloudflare Tunnels. I mentioned ngrok, localtunnel, etc., and then I started thinking about what a super-lightweight tunneling client might look like if it were optimized for clawbots, MCP servers, dashboards, and random services people are increasingly running on home networks and minis.

And then I remembered I owned the tunnel.to domain name.

At that point the idea kind of lodged in my brain and refused to leave until I built the thing.

Current state:

- lightweight relay-based tunnel service

- CLI-first

- public relay nodes in North America + Europe

- TLS

- no account required for basic usage

- intended to be dead simple to expose localhost services

Right now it’s centralized. Early days, but it's entirely doable to add:

- self-hosted relays

- private relays

- agent-oriented workflows

- lightweight auth/access controls

- better relay selection/failover

Given my background I'm also in a good position to preempt abuse, so it doesn't become a timesuck. The no-registration level assigns sub-hostnames so people can't set up obvious phishing sites.

(And yes, I told my nephew about it after it was finished. He said “cool”. Hasn’t used it yet.)

easyDNS here. Our ears were burning as multiple people have mentioned us in this thread.

If you want to get with a registrar who is actually clueful about takedowns, we can help you out.

The Gell-Mann Amnesia is strong in this story and thead.

As I posted on Krebs' article:

This is neither news nor new. There have been prior panics around this “water is wet” type issue going back at least a decade.

(Search up “Floating Domains – Taking Over 20K DigitalOcean Domains via a Lax Domain Import System” – and others).

I also wrote about this on CircleID from the DNS operator’s perspective (“Nameserver Operators Need the Ability to “Disavow” Domains”) – after this same issue was used to DDoS attack another DNS provider by delegating a domain to their DNS servers without having setup an account there, and then doing a DNS reflection attack on that domain. That was over ten years ago.

The fact that people can delegate their own domains to somebody else’s nameservers without ever properly setting up a zone on those nameservers, or ever keeping track of where THEIR OWN DOMAINS point is 100% the responsibility of the domain owner – and to varying degrees a function of their REGISTRAR – who is the only entity that has any control over it.

It’s a weird flex for corporate registrars who purport to be “high touch” and exclusive, to simply shrug their shoulders and turn a blind eye to their own clients’ obviously broken and vulnerable nameserver delegations.

For our part this is specifically one of things we actively monitor and alert our clients about.

Beware of EuroDNS 2 years ago

Default behaviour in a registrar transfer is to leave the nameservers as is - the rar has to explicitly send a new ns set in the transfer call to effect a change.

Are you positive you didn't accidentally tick a checkbox or anything to use their nameservers?

Great story.

I was a huge HHGTTG fan (counting Disaster Area among my top musical influences)

When I was at UWO in the early 90's Douglas Adams came on campus for a book signing - it was to last about 45 minutes, and it was scheduled right in the middle of one of my exams.

So I decided to sit the exam, thinking "I'll catch up with him at a future book signing", alas he died before I ever got the chance.

I would recommend ponying up a few sats and using paid relays.

If you're just using free relays you will get inundated with spam.

I was running an open relay for awhile and closed it up because of this.

(Lightning is the magic lubricant that makes Nostr so promising).

Are you asking for a source on "ivermectin is not a horse de-wormer" Other than that it has been an FDA approved drug for over thirty years?

Or are you asking for a source on somebody getting deplatformed for saying that, and Dr. Peter McCullough comes to mind there.

The Great Barrington Declaration was also de-indexed from Google for disputing lockdowns.

I've seen people say this, but I've not actually observed that at all. What got censored exactly?

Zerohedge was kicked off Twitter for suggesting that the Wuhan Institute of Virology was a likely candidate for the origin.

We're seeing that Fauci & Ecohealth co-ordinated the paper to "debunk" the lab leak theory and now the lab leak is looking to be the most likely culprit (it is not without precedent, the 1977 Russian Flu turned out to be a lab leak from gain-on-function research).

Ivermectin, was another. Complete with "horse de-wormer" smears and deplatforming campaigns all over the place.

If you don't know of any instances where this has happened, you either did a masterful job tuning it all out, or still believe 99% of the b/s.

I've been thinking for some time about a mechanism that could be used to assert control over a domain that has a lot of third-party backlinks to it, as in widgets, ad networks, javascript etc.

Because when those domains become defunct or expire, anybody recognizing what they were could grab them and inject malicious code into all the websites with the broken widgets embedded (we've seen this happen with crypto miners, etc)

This kind of a mechanism (along with domainconnect) could work - but it would also need the browsers (perhaps with a plugin?) to verify a domain on embedded components before rendering them.

That would add a lot of DNS lookups though.

Overall a good effort. Would be good to see something along these lines gather some traction.

EasyDNS has a history of being decent but has had an openly right wing slant for the last few years, which could translate into how they handle complaints for domains owned by the "other side".

easyDNS spokesbot here.

We take the same attitude toward our client domains regardless of political affiliation or orientation.

In the past we were the DNS provider for both BLM and Antifa, who brought in their fair share of takedown requests and are arguably left-of-centre.

When we were added as a defendant in a defamation suit because we wouldn't take the website down ahead of a court ruling, that was a legal battle between two different factions of socialists - which we're not a fan of - we still fought the lawsuit at our own expense.

Everybody seeking to deplatform an easyDNS customer because of their political ideology gets the same answer: "GFY".

That is precisely the concern. Listen to the Law Bytes podcast with Michael Geist and Brenda McPhail - Geist is a University of Ottawa law professor and undisputed privacy expert - and they talk about exactly this.

(Or you could read the legislation itself, but Canadian bills are hard to read because they are these kind of Frankenstein concoctions of lines that are stricken from other acts and new lines that are added).

I loved Dr Dobbs Journal. Used to buy it every month when I was in college and barely understood any of it.