Live data from Hacker News

Introducing Cloudflare Registrar

blog.cloudflare.com

31–40 of 257 posts

Re: Introducing Cloudflare Registrar

#32
Do cloudflare want to be registrar for other foreign TLDs in the future?

I would love to see them support TLDs such as .dk, .de, .it etc. That way both me and my clients could begin consolidating domain registration in one place, instead of using expensive and shitty domain registration management services. Harder ones, like Tonga (.to) or Greenland (.gl) would be nice to have as well, but I don't think it's feasible (or possible even) to integrate with all countries.

Re: Introducing Cloudflare Registrar

#33
post #5

Earlier quoted context omitted.

I currently use NameSilo. Don't forget they also offer free whois privacy for life. My only complaint with them is their DNS records are only updated once every 15 minutes. This makes doing automated API based DNS based LE challenges annoying because you need to sleep your script for 15 minutes to ensure the update got pushed. Also, I'm surprised Cloudflare omit talking about whois privacy in the blog post. Makes me…

We actually didn't talk about WHOIS Privacy because it's becoming less and less of a relevant feature in the post-GDPR world. We do support it, free of charge. Cloudflare is also the largest authoritative DNS deployment in the world, and changes propagate in closer to 15 seconds than 15 minutes.

Still got to factor in the minimum allowed TTL of 120 seconds, thought. I wish the API would allow less.

Re: Introducing Cloudflare Registrar

#34
I have used dozens of different registrars over the past two decades and found Fabulous.com to be by far the best on price and technology. Unfortunately, they now have no plans to support the new CDS and CDNSKEY protocols which would be handy for anyone managing a large number of domains.

What Fabulous do have, however, is an "Executive Lock" feature, which is an optional additional layer of verification that the domain owner must go through before a domain can be transferred away from his account. They also support U2F, which allows the use of hardware tokens such as Yubikeys.

Domain protection features such as these are vital if a registrar does not want to be swamped with jacking attempts and the PR disaster of actually losing domains.

I am surprised that Cloudflare has not already followed the fine example of companies such as Dropbox, Github, and Google by supporting U2F. A quick search shows that Cloudflare customers have been publicly asking for this for at least 3 years. When they introduced TOTP 2.5 years ago, they stated that they would support U2F "shortly".

In the context of being a domain registrar, supporting U2F would be even more useful, dramatically reducing the number of domain jacking attempts. Proper support would encourage customers to associate TWO hardware tokens with their account, each stored in a different location. Supporting only one, as AWS have recently done, leaves them wide open to social engineering, with impersonators claiming to have lost their one key.

Re: Introducing Cloudflare Registrar

#36

I have used dozens of different registrars over the past two decades and found Fabulous.com to be by far the best on price and technology. Unfortunately, they now have no plans to support the new CDS and CDNSKEY protocols which would be handy for anyone managing a large number of domains. What Fabulous do have, however, is an "Executive Lock" feature, which is an optional additional layer of verification that the dom…

Wow, it's hard to believe they don't support U2F yet. Even smaller providers such as OVH have U2F for a long time.

Re: Introducing Cloudflare Registrar

#37
post #36

I have used dozens of different registrars over the past two decades and found Fabulous.com to be by far the best on price and technology. Unfortunately, they now have no plans to support the new CDS and CDNSKEY protocols which would be handy for anyone managing a large number of domains. What Fabulous do have, however, is an "Executive Lock" feature, which is an optional additional layer of verification that the dom…

Wow, it's hard to believe they don't support U2F yet. Even smaller providers such as OVH have U2F for a long time.

Yeah, very surprising. Perhaps companies lose the ability to get this stuff done as they grow larger.

An even more shocking example is Transferwise, supposedly a cutting-edge star of the "fintech" scene. They use SMS-based codes, a wildly insecure form of OTP. Over a thousand employees and they cannot even implement some sort of app-based TOTP (such as Google Authenticator) to protect their clients' money.

Re: Introducing Cloudflare Registrar

#38
post #4

This sounds great. Hopefully the TLD coverage is extensive, I dislike having my domains split across multiple registrars based on their supported extensions.

We want to help you consolidate those! Full list here for TLDs supported at launch, but we're busy working to add more before then. https://www.cloudflare.com/tld-policies/

I second the request for the .UK TLDs.

Re: Introducing Cloudflare Registrar

#39
post #22

Earlier quoted context omitted.

When you say real inboxes, are you thinking webmail of some sort? Don't most people prefer to use Google Apps or the like these days?

I mean being able to set up zackbloom@cloudflare.com as a proper inbox that can send and receive mail without forwarding to another email. Having a web interface for it would be cool but I think a lot of people could also configure existing email clients to access it (at least at the start). Google Suite is something like $5 / month per domain name so offering that as a free feature would be a pretty big deal.

Google Suite starts at $5 per email address per month; I think asking for free email accounts is beyond the product offering of domain registration/renewal.

And they probably want to reserve usage of their domain for email so you know it's a staff member you're dealing with, which is why google gives away gmail.com addresses, not google.com addresses.

Here are three less expensive email options for you:

1. get a VM and install exim/postfix 2. OpenSRS https://opensrs.com/services/hosted-email/ 3. AWS workmail https://aws.amazon.com/workmail/

Re: Introducing Cloudflare Registrar

#40

Do cloudflare want to be registrar for other foreign TLDs in the future? I would love to see them support TLDs such as .dk, .de, .it etc. That way both me and my clients could begin consolidating domain registration in one place, instead of using expensive and shitty domain registration management services. Harder ones, like Tonga (.to) or Greenland (.gl) would be nice to have as well, but I don't think it's feasible…

Yes, we do.
Post reply on HN