Live data from Hacker News

Introducing Cloudflare Registrar

blog.cloudflare.com

251–257 of 257 posts

Re: Introducing Cloudflare Registrar

#251
post #246

Earlier quoted context omitted.

As a big company, they pay their processor(s) far less than you or I pay Stripe or Ayden. For the marketing dynamite of being the only $8.03 "at-cost" registrar, they are going to take a payment processing hit of around ten to fifteen cents per domain. They could shift that cost to the price, but then they would lose those invaluable bragging rights. The point is not that customers save a few cents, but the absolute…

This is actually incredible from a standpoint that most people and businesses have a very limited number of domains, making margins of say $2 a year on 5 domains moot.

Yeah, it is not about the $10 that the 5-domain company might save, it is about trust, about Cloudflare positioning itself as a fair dealer that is not out to nickel and dime you.

Of course, once that relationship has been established, Cloudflare is in prime position to eventually make hundreds or thousands of dollars per year from that company.

Re: Introducing Cloudflare Registrar

#252
post #41
post #24

I wouldn't have cared much about Domain Name Register just a week ago, but after what happen at Zoho, and all the horror story in the comments section from namecheap and others, Cloudflare Registar couldn't come at a better time. I really wish Cloudflare at least made $1 or $2 Gross Profits per domain. Who paids for Domain Register Support? I would much rather be a "customer" than I am not sure where they are making…

I though namecheap was one of the better ones around? I'm looking for a domain registrar. Could share the link with namecheap horror stories? Thanks

Some things off the top of my head (personal experiences):

1. Have had them turn off private WHOIS for all (hundreds of) domains "by accident".

2. I haven't figured out a way to export a list of domains after their UI revamp some years ago.

3. At some point they started setting DNS records for newly purchased domains to their landing page with a 30 minute TTL, which makes setting up something on the fly impossible, unless you use their API:

4. Their API is flaky at best. I wrote a script to register domains and set NS records and was forced to write a loop to set NS records up to 10 times until they got set properly.

Re: Introducing Cloudflare Registrar

#253
post #39
post #22

Earlier quoted context omitted.

I mean being able to set up zackbloom@cloudflare.com as a proper inbox that can send and receive mail without forwarding to another email. Having a web interface for it would be cool but I think a lot of people could also configure existing email clients to access it (at least at the start). Google Suite is something like $5 / month per domain name so offering that as a free feature would be a pretty big deal.

Google Suite starts at $5 per email address per month; I think asking for free email accounts is beyond the product offering of domain registration/renewal. And they probably want to reserve usage of their domain for email so you know it's a staff member you're dealing with, which is why google gives away gmail.com addresses, not google.com addresses. Here are three less expensive email options for you: 1. get a VM a…

Looks like opensrs requires to pay a one-time $95 fee. Can one use just hosted email on their domains at $0.5/mo?

Re: Introducing Cloudflare Registrar

#254

Earlier quoted context omitted.

Why use a homebrew Perl script for this when Postfix (and likely most other MTAs) has features available that can do this for you? Want to block all mail from any domain name that's hosted by Cloudflare? That's simple enough (and doesn't require taking a shower afterwards, unlike when writing Perl). Just grab the plain-text version of the file that contains the list of Cloudflare's IP address ranges [0], create a CID…

Well, I definitely don't want to block any mail from cloudflare hosted domains, as I have many customers using cloudflare dns. I just want to delay it 15 minutes so that I can then do a second blacklist check. Does postfix do that? >and doesn't require taking a shower afterwards, unlike when writing Perl). I wouldn't say that. perl is about the best scripting language IMO, and is available on all systems. I wrote my…

Postfix's "zombie blocker", postscreen [0] (which ships with Postfix), offers that functionality -- and more [1] -- out of the box.

In the worst case, where you have some unusual, specific need that hasn't been designed for, you can -- quite easily -- easily create your own policy daemon [2] (even in Perl; see the example) and/or milters [3].

> I wouldn't say that. perl is about the best scripting language IMO, and is available on all systems.

Oh, I agree; I was mostly teasing. I first started using Perl c. 1995 (and later, for writing CGI scripts, when CGI became a thing) and it is still the scripting language I reach for 95% of the time for basic sysadmin stuff.

> I wrote my own spam filter because I want to have full control over how I deal with spam, and generally it works very well.

I certainly can't fault you for that. Take a look at the greylist.pl script that ships with Postfix. It is an example of a policy daemon that implements greylisting (not meant for production; for greylisting, use postscreen instead). It's been several years ago but, after looking at that, I was able to implement my first policy daemon (which reached out to a MySQL server) in about 20 minutes and, after some testing, put it into production shortly after that. It's amazingly simple.

I'm not sure what MTA you are currently using but I would certainly recommend looking into Postfix. Back in the 90s, I was a hardcore, bigoted sendmail guy ("Give me sendmail or give me death!") but at some point I started looking into Postfix and have never looked back. Among other things, I manage mail systems at $work (an ISP) and I'm "very anti-spam". I occasionally need/want to do some unusual things policy-wise (WRT accepting or rejecting mail) and Postfix can itself handle 95% of it. For the other 5%, I tweak AMaViS or write my own policy daemons.

N.B.: My personal mail server (currently) runs on FreeBSD, where I use OpenBSD's "spamd" [4] for greylisting. Personally, I prefer and use that over postscreen (it stops upwards of 90% of remote mail systems from even getting to talk to the "real" MTA!) but on my (CentOS) Linux-based mail systems, I now just use postscreen (previously, I had a "standalone" OpenBSD box running "spamd" sitting in front of Barracuda appliances (as a transparent SMTP proxy). postscreen is really simple to get up and running -- and even more so if you're already using Postfix! -- and a very minimal, basic postscreen configyration will stop the majority of "zombies", hijacked PCs, blacklisted hosts, etc., from getting through to your actual SMTP server.

[0]: http://www.postfix.org/postscreen.8.html

[1]: http://www.postfix.org/POSTSCREEN_README.html

[2]: http://www.postfix.org/SMTPD_POLICY_README.html

[3]: http://www.postfix.org/MILTER_README.html

[4]: https://www.openbsd.org/spamd/index.html

Re: Introducing Cloudflare Registrar

#255

The registration cost for domains is trivial (for most common TLDs): $8/year or $35/year - how much is $27/year worth to you and your company? The primary cost for domains is potential downtime. How much does a day of downtime cost you and your company? I don't want to think about it either. The next most significant cost is labor - your time and your business' delays when dealing with the registrar over service and…

We provide email support to all of our customers. I believe free customers see a response within 8 hours on average (we have teams in SF, Austin, London, and Singapore, to cover every timezone). That 8 hours can become as little as 30 minutes for customers who also subscribe to our Pro or Business plans, or use our Custom Domain Security product.

Thanks for the update. For comparison, I pay ~$35/year and get skilled, empowered, responsive phone support within maybe five minutes of calling. I've never needed them to pull off a miracle so I don't know how truly empowered they are.

Re: Introducing Cloudflare Registrar

#256

Earlier quoted context omitted.

And, perhaps more importantly, Cloudflare admitted that was a mistake and promised that it wouldn't happen again. (IIRC.)

I've been trying to watch these issues and not seen anything that suggests they won't do it again. If you have some evidence of this, please post it. In fact I think it more important to point out that the incident proved they can and will do such a thing, and will have less of an argument should someone stick a piece of paper to their head and tell them to do it more often. I like cloudflare and appreciate all these…

Days after posting about the need for cloudflare (and others) to decentralize / split up; and there is this article in the Guardian for the UK: https://www.theguardian.com/commentisfree/2018/sep/30/we-can...

Equating cloudflare tech with nazi bouncers, and killing. Needing to be used to shutdown sites.

with things like this: >> Cloudflare has built “edge servers” – data centres that store content locally. There are 30 in Europe, including one in London and one in Manchester. The British government cannot regulate the worldwide web, but it could enforce the law in Britain. The anti-fascists at Hope not Hate begged ministers to make Cloudflare’s British operations comply with anti-Nazi legislation.

>> Cloudflare, by contrast, is enabling men who want to kill, not argue.

There was a time when the tech was not easily understood, and the argument of dumb pipes was kind of legit. It seems that time is over, in no small part because tech has not been sticking to their principals (imho).

Re: Introducing Cloudflare Registrar

#257
post #236

Earlier quoted context omitted.

I second this. I have my domain instantfloppy.net hosted on GDomains and use Cloudflare for DNS but I'm going to transfer "mid-November" for sure. I wholeheartedly trust Cloudflare. They've shown their commitment to privacy and I don't understand what their endgame is but I want to believe they support a better Web.

I believe when 90% people feel it this way, they turn bad.

Yeah, it's naive, but it's the best solution there's been for quite a while. I just really hope this is good.
Post reply on HN