Live data from Hacker News

Introducing Cloudflare Registrar

blog.cloudflare.com

231–240 of 257 posts

Re: Introducing Cloudflare Registrar

#231

Earlier quoted context omitted.

Email verification isn't a Namecheap thing, it was an ICANN thing, it happened to every domain provider.

I neglected to mention this happened only a few months ago, after the domain had been quietly and happily registered for several years. Unless you're saying ICANN changed the rules recently, but I'm having trouble finding a record of that.

> namecheap

I got a free domain with Github student pack from Namecheap. Just my personal experience, the person I talked to seemed very helpful and kind. However, the multiple rounds of talking to a real person to register a domain makes me think they don't have nearly enough automation which is a red flag.

Re: Introducing Cloudflare Registrar

#232

Security wise, are you on par with MarkMonitor?

MarkMonitor supports UF2, Cloudflare does not.

U2F allows you to secure your account with hardware tokens, such as Yubikeys.

Cloudflare does support "soft 2FA", which is two-factor authentication using apps, which is good, but could be vulnerable if a remote hacker gets hold of your 2FA secret by, for instance, compromising your password manager.

If you are keeping it only in the app but lose or break your phone, you will have to go through a verification process to regain access to your account. This process is, itself, a huge target for hackers.

For protecting domains that are important to your business - and, indeed, protecting your Cloudflare settings - nothing beats having two hardware tokens associated with your account, each located in a separate, secure location. They are inexpensive, do not need to be recharged, are almost impossible to break, are easily hidden and, if you lose one, you can use the other until your replacement arrives.

Re: Introducing Cloudflare Registrar

#233
post #226

Earlier quoted context omitted.

From Tophost: "solo 1 euro in più per .com". So it's 6.99€ ~= $8.10; seven cents more than Cloudflare. In any case, the Verisign fee is not hard to confirm; it would be weird for them to lie about it: https://investor.verisign.com/news-releases/news-release-det...

Indeed, only seven cents more: do you really think Tophost and similar (including Coudflare) are living off those seven cents per domain?

I think they are living off upsales. I mean, CL already has free plans. Why would an at-cost plan be unbelievable?

Re: Introducing Cloudflare Registrar

#234
post #141

Earlier quoted context omitted.

Note that if you're cnaming to some thing that is doing dns based load balancing or Geo targeting, introducing flattening in the middle may reduce the ability of your provider to do those things.

What is the alternative for a root domain A record? You are saying use a direct ip to the load balancer instead?

If you want dns based load balancing on the root domain, you really have to delegate that domain to your DNS based load balancing service.

Otherwise, set up a couple stable IPs to redirect to a subdomain and nothing else. (I'm comfortable putting two quality machines in different data centers for this, but you can use a load balancer it you have access to quality load balancer). If all of your published urls have www (or m) and all of your inbound links have it too, it's not really a big deal if the root domain is unreachable for some time in the event of a server/load balancer/datacenter failure.

Re: Introducing Cloudflare Registrar

#235

Earlier quoted context omitted.

Interesting that no one here has mentioned Google Domains: - It has no up-sells - I trust Google's security more than Cloudflare's - It has decent customer support, unlike some of Google's other products

Last time I looked at their Terms of Service it appeared that losing your Google account would cause you to lose access to all services. It's not good to put all your eggs in one basket. With that being said, I've used Google Domains as well and haven't had any issues with it.

This. I lost access to an email address and when Google asked me to check email for accessing it from a new device, I could no longer get in. It asked me when I signed up but of course I couldn't answer it properly.

And it's another step to showing what you're related to, to Google. It would be better if you want Google to build up your online figure on behalf of you.

Re: Introducing Cloudflare Registrar

#236

Earlier quoted context omitted.

Aside from the price, one very good reason to be interested in CloudFlare as a registrar compared to Google Domains is that CloudFlare supports CNAME flattening [1] so that you can use a CNAME instead of an IP address for an A record (AKA "ALIAS" on DNSimple or Route53). I'm using Google Domains right now, but have been using CloudFlare to host my DNS for ages for this reason alone. I'll think about transferring my d…

I second this. I have my domain instantfloppy.net hosted on GDomains and use Cloudflare for DNS but I'm going to transfer "mid-November" for sure. I wholeheartedly trust Cloudflare. They've shown their commitment to privacy and I don't understand what their endgame is but I want to believe they support a better Web.

I believe when 90% people feel it this way, they turn bad.

Re: Introducing Cloudflare Registrar

#237
post #41

Earlier quoted context omitted.

I though namecheap was one of the better ones around? I'm looking for a domain registrar. Could share the link with namecheap horror stories? Thanks

If you are using PrivateInternetAccess, you can't login to your NameCheap account. As in, your valid username and password will be rejected. This happens even if you have 2fa enabled. I reset my password twice (even though I _knew_ the original because I use a password manager) before I opened a support case, and they confirmed that they block legitimate logins if they detect you're using a VPN. I wanted to move off…

Gandi's "No bullshit" slogan is far from correct. I had someone harassing ICANN on me with a domain they wanted, and Gandi kept requesting identity verification every other day. They wouldn't keep it on file, and locked my account.

Stay far, far away.

Re: Introducing Cloudflare Registrar

#238

Earlier quoted context omitted.

If you are using PrivateInternetAccess, you can't login to your NameCheap account. As in, your valid username and password will be rejected. This happens even if you have 2fa enabled. I reset my password twice (even though I _knew_ the original because I use a password manager) before I opened a support case, and they confirmed that they block legitimate logins if they detect you're using a VPN. I wanted to move off…

Gandi is good, I think the site upgrade is done now so there won't be much clunkiness for new domains. They're more expensive than most, but I've had no problems. I only use their DNS though, I can't comment on mail, mail forwarding or hosting.

It's sad domains are stupidly expensive. They don't need $10+/year to maintain a domain. The sad reality when such an infrastructure is governed by a tree structure with no one to override.

Re: Introducing Cloudflare Registrar

#239
post #62

Earlier quoted context omitted.

Is this sarcasm?

Presumably, but they have a poorly-articulated point -- Cloudflare has an incredible potential for (even unintentional) destructive effect based on their extreme consolidation and centralization of internet technologies. I think a terrific example of this is when they put a DNS server on 1.1.1.1 (in historically unused address space which was assigned to APNIC for research purposes), got a certificate for the IP addr…

On the other hand, 1.0.0.0/8 is routable ip space on the internet. I get that it sucked, but, would people have stopped "squatting" for lack of a better way to say it had they not added 1.1.1.1 to the preloaded list?

Re: Introducing Cloudflare Registrar

#240

Earlier quoted context omitted.

Email verification isn't a Namecheap thing, it was an ICANN thing, it happened to every domain provider.

I neglected to mention this happened only a few months ago, after the domain had been quietly and happily registered for several years. Unless you're saying ICANN changed the rules recently, but I'm having trouble finding a record of that.

There was a requirement in 2014 (I think?) and recently they updated it in 2017. I think people that weren't meeting guidelines started getting notices from registrars around that time. A few clients of our had this happen to them from everyone from GoDaddy to Network Solutions to NameCheap. Some organizations that had their emails set to go to a person that no longer worked at the company were having their domains suspended...but it was all because of ICANN.
Post reply on HN