Live data from Hacker News

Cloudflare Registrar

cloudflare.com

91–100 of 111 posts

Re: Cloudflare Registrar

#91
post #70
post #64

Does Cloudflare Registrar support U2F authentication yet? I don't trust any service with mission-critical stuff that doesn't have U2F. Domains are way too valuable to keep them in registrars without U2F.

Just curious, what are the domain registrars currently support U2F? Also, just to be sure U2F is an additional methods of 2FA, not the only method of 2-step, so to me having U2F is not necessarily making accessing your account securer.

Namecheap support U2F as well.

Re: Cloudflare Registrar

#92
post #74
post #70

Earlier quoted context omitted.

Just curious, what are the domain registrars currently support U2F? Also, just to be sure U2F is an additional methods of 2FA, not the only method of 2-step, so to me having U2F is not necessarily making accessing your account securer.

> Just curious, what are the domain registrars currently support U2F? Google, Amazon, Gandi (and some others I can't remember off the top of my head) support U2F. > having U2F is not necessarily making accessing your account securer. I don't agree with that at all. There are numerous cases of various 2FA methods being taken advantage of. No one has yet managed to crack U2F.

I think devy means that you usually cannot add a U2F as the only second factor - you usually need to first add TOTP or phone number as backup.

So, an attacker can just target the weaker factor and ignore U2F.

I certainly had the same thought.

Re: Cloudflare Registrar

#93
post #35

New GTLDs may cost considerably more at Cloudflare Registrar. For example, the annual cost of a .space domain during transfer is $15.18 (it was $17 two months ago), while renewal for the same domain at Namecheap costs $9.06. To be fair Namecheap lists it as a discounted offer, but that appears to be always the case for the .space TLD renewals.

If you can find it for $15.18 without having to buy other services, that's a deal and you should take it. Most discounts like that are offered as loss leaders in the hopes that you'll buy other add-ons.

Understood... personally, I'd rather pay the extra dollar or two in order to NOT have to click through promotional crap during registration. I don't know about cloudflare's process, but I'm assuming it'll likely be as clean as google's (by comparison).

Re: Cloudflare Registrar

#94
post #77

Before you register your domain with Cloudflare, please consider who their other customers are. Cloudflare today provides services for many white supremacist websites; they kicked off the Daily Stormer in 2017 after widespread criticism, but still receive money from many others. From what I can see, their senior leadership genuinely believes that, morally, they have an obligation to provide services for horrible peop…

You don't change peoples opinions by shutting them out, all that does is drive them deeper into their own echo chambers. It's usually a bad idea in practice.

Freedom of speech means freedom of speech you don't agree with. There is no need to protect speech most people disagree with. FYI, the ACLU has also protected the same people you refer to. The problem with taking away civil liberties, is that eventually it will come down to losing your own.

For example, if you want the government to shut down speech it doesn't like, what happens when opposing views are in power, and Donald Trump decides he doesn't like what YOU are saying. Do you really want to go there?

Re: Cloudflare Registrar

#95
post #24

Meta: "support for hundreds of TLDs" * https://www.cloudflare.com/tld-policies/ Crikey there's a lot of stuff out there. Seems that ICANN has approved just about any random word in the English language.

But they still haven't got .dev :(

no .biz either

Re: Cloudflare Registrar

#96
post #91
post #70

Earlier quoted context omitted.

Just curious, what are the domain registrars currently support U2F? Also, just to be sure U2F is an additional methods of 2FA, not the only method of 2-step, so to me having U2F is not necessarily making accessing your account securer.

Namecheap support U2F as well.

>Namecheap support U2F as well.

They do not. They support 2FA through TOTP only.

Re: Cloudflare Registrar

#97
post #77

Before you register your domain with Cloudflare, please consider who their other customers are. Cloudflare today provides services for many white supremacist websites; they kicked off the Daily Stormer in 2017 after widespread criticism, but still receive money from many others. From what I can see, their senior leadership genuinely believes that, morally, they have an obligation to provide services for horrible peop…

You don't change peoples opinions by shutting them out, all that does is drive them deeper into their own echo chambers. It's usually a bad idea in practice. Freedom of speech means freedom of speech you don't agree with. There is no need to protect speech most people disagree with. FYI, the ACLU has also protected the same people you refer to. The problem with taking away civil liberties, is that eventually it will…

I support the First Amendment wholeheartedly, and believe it's important that the government refrain from shutting down speech it doesn't like.

You may note that Cloudflare is not a government.

Re: Cloudflare Registrar

#98
post #92
post #74

Earlier quoted context omitted.

> Just curious, what are the domain registrars currently support U2F? Google, Amazon, Gandi (and some others I can't remember off the top of my head) support U2F. > having U2F is not necessarily making accessing your account securer. I don't agree with that at all. There are numerous cases of various 2FA methods being taken advantage of. No one has yet managed to crack U2F.

I think devy means that you usually cannot add a U2F as the only second factor - you usually need to first add TOTP or phone number as backup. So, an attacker can just target the weaker factor and ignore U2F. I certainly had the same thought.

The prime thing U2F mitigates is phishing attacks. You literally cannot be phished with U2F, you try to auth against the wrong domain and you get a different secret - so they can't then pass that on the backend (i.e. the real site) and login as you.

Sure your TOTP might remain, but you're not using it, so it's not liable to be taken.

Post reply on HN