Live data from Hacker News

Introducing Cloudflare Registrar

blog.cloudflare.com

111–120 of 257 posts

Re: Introducing Cloudflare Registrar

#111

I would never use Cloudflare. They hide spammers and refuse to do anything about them. The same mass spammer will register site after site for months, sending snowshoe spam, and cloudflare refuses to do anything. At one point this was taking up about 80% of our incoming spam, and most of it was getting through spam filters due to the snowshoeing. You could see the same registration info for hundreds of domains over m…

How do you have your MTA check if a domain is hosted through Cloudflare, and what blacklists do you use? I think I'd like to do this, too.

Re: Introducing Cloudflare Registrar

#112
post #62

Earlier quoted context omitted.

Hell, yeah. Get into hosting next. Destroy the whole internet. It's what the 'competition' deserves.

Is this sarcasm?

Presumably, but they have a poorly-articulated point -- Cloudflare has an incredible potential for (even unintentional) destructive effect based on their extreme consolidation and centralization of internet technologies. I think a terrific example of this is when they put a DNS server on 1.1.1.1 (in historically unused address space which was assigned to APNIC for research purposes), got a certificate for the IP address, then added that certificate to the Chrome HSTS preload list, meaning people who ended up on captive portals on 1.1.1.1 (and there are a _lot_ of them) couldn't access the internet, because instead of observing what people _actually_ do and paving the cowpaths, they took the point of view that acting against the standards was punishable, and the people being punished are nontechnical folks visiting hotels and airports who are using a modern browser (it has since been removed from the preload list, but if you're foolish enough to visit the site you'll still get HSTS-poisoned).

An even better example, of course, is Cloudbleed, but I guess we've all agreed to pretend that never happened?

Re: Introducing Cloudflare Registrar

#113
post #96
post #67

Earlier quoted context omitted.

It seems like it was just a handful of users who posted their story multiple times. The users highclass, ethanwillis, kweks all had multiple comments only about namecheap on a thread that wasn't directly about namecheap. Can I get more horror stories to confirm those are real? It's unfortunate because namecheap used to have the exact opposite reputation: https://news.ycombinator.com/item?id=3396606

I was one of the upvoted posters there. TLDR: I was issued couriered C&Ds to a postal and email address only used on Namecheap. The attacking party had no court order, subpoena, judgement, etc. Ted from namecheap asked me to email him. He confirmed legal had received the complaints, but said they hadn't replied. He hasn't replied to my email since (3 days ago) to offer any explanation how the attacking lawyers got de…

Just curious, where are you going to move to?

If someone really wanted to sue you, it's pretty cheap to issue subpoenas ([1] https://en.wikipedia.org/wiki/Doe_subpoena

Re: Introducing Cloudflare Registrar

#114

Earlier quoted context omitted.

We want to help you consolidate those! Full list here for TLDs supported at launch, but we're busy working to add more before then. https://www.cloudflare.com/tld-policies/

Gah, you don't have .je domains. I have a charity one there which I have to use gandi.net for and it's driving me nuts...

Likewise, .sh domains are pretty popular but an incredible pain to deal with. I managed to transfer mine to Hover, but it's expensive and buggy (you can't update your registration address, for example; you get an "internal server error").

Re: Introducing Cloudflare Registrar

#115

The registration cost for domains is trivial (for most common TLDs): $8/year or $35/year - how much is $27/year worth to you and your company? The primary cost for domains is potential downtime. How much does a day of downtime cost you and your company? I don't want to think about it either. The next most significant cost is labor - your time and your business' delays when dealing with the registrar over service and…

We provide email support to all of our customers. I believe free customers see a response within 8 hours on average (we have teams in SF, Austin, London, and Singapore, to cover every timezone). That 8 hours can become as little as 30 minutes for customers who also subscribe to our Pro or Business plans, or use our Custom Domain Security product.

Re: Introducing Cloudflare Registrar

#116
post #96
post #67

Earlier quoted context omitted.

It seems like it was just a handful of users who posted their story multiple times. The users highclass, ethanwillis, kweks all had multiple comments only about namecheap on a thread that wasn't directly about namecheap. Can I get more horror stories to confirm those are real? It's unfortunate because namecheap used to have the exact opposite reputation: https://news.ycombinator.com/item?id=3396606

I was one of the upvoted posters there. TLDR: I was issued couriered C&Ds to a postal and email address only used on Namecheap. The attacking party had no court order, subpoena, judgement, etc. Ted from namecheap asked me to email him. He confirmed legal had received the complaints, but said they hadn't replied. He hasn't replied to my email since (3 days ago) to offer any explanation how the attacking lawyers got de…

Just had a follow up from Ted. He says that legal received a complaint but ignored it, and perhaps the leak vector was via historical whois data. Historical whois data says otherwise. Hard to draw a firm conclusion apart from the facts.

Re: Introducing Cloudflare Registrar

#117
post #77

While I'm sure few of us would have controversial domains, let's remember that Cloudflare have removed the DNS records of sites that they didn't like in the past[0]. [0] - https://blog.cloudflare.com/why-we-terminated-daily-stormer/

That's misleading. They removed the records of one site. Not "sites". And they did it because that site was claiming that CloudFlare providing them services meant that CloudFlare secretly supported their (hate-based) ideology. And it's also worth pointing out that CloudFlare wasn't the only company terminating services for Storm Front. GoDaddy dropped them, then Google dropped them (and their YouTube account), then T…

And, perhaps more importantly, Cloudflare admitted that was a mistake and promised that it wouldn't happen again. (IIRC.)

Re: Introducing Cloudflare Registrar

#118
I really wish I could find a good solution for generic wildcard forwarding of email my registrar provides

I'd move everything to CloudFlare instantly if I could find a way to get *@mydomain.com for all mess of domains without having to run my own email server or pay a bunch of money per domain.

Re: Introducing Cloudflare Registrar

#119
post #77

While I'm sure few of us would have controversial domains, let's remember that Cloudflare have removed the DNS records of sites that they didn't like in the past[0]. [0] - https://blog.cloudflare.com/why-we-terminated-daily-stormer/

That's misleading. They removed the records of one site. Not "sites". And they did it because that site was claiming that CloudFlare providing them services meant that CloudFlare secretly supported their (hate-based) ideology. And it's also worth pointing out that CloudFlare wasn't the only company terminating services for Storm Front. GoDaddy dropped them, then Google dropped them (and their YouTube account), then T…

You failed to mention that the decision to drop them was made unilaterally by the CEO, and he said it was because he woke up in a bad mood that day. That was why people were talking about it; all you have to do is get on the bad side of someone at the company and they'll try to effectively erase you from the internet, and people will defend it by saying "it's a private business, they can't be forced to host anyone". It was a very visible case of a gatekeeper to a large portion of the internet showing that they're willing to decide what information people can see.

Re: Introducing Cloudflare Registrar

#120
post #118

I really wish I could find a good solution for generic wildcard forwarding of email my registrar provides I'd move everything to CloudFlare instantly if I could find a way to get *@mydomain.com for all mess of domains without having to run my own email server or pay a bunch of money per domain.

You could probably use Mailgun with a routing rule to map *@yourdomain.com to a single email address.
Post reply on HN