Live data from Hacker News

Does Your Domain Have a Registry Lock?

krebsonsecurity.com

21–30 of 73 posts

Re: Does Your Domain Have a Registry Lock?

#21
post #17

Earlier quoted context omitted.

Probably because the manual management of these requests is relatively expensive.

Yeah, CloudFlare is one that offers it, but it seems firmly in "Request Quote/Call Sales" territory for pricing. It dates from when they first intro'd their original registrar offering [1] a few years ago, and they said right out: > "CloudFlare Registrar is not designed for the masses. There are plenty of great mass-market registrars. However, if you’re an organization where losing your domains would be a front-page…

[deleted]

Re: Does Your Domain Have a Registry Lock?

#22
post #5

I'm not able to find a registry lock on google domains. There is a lock feature but i'm assuming that is a registrar lock

You mostly see registry lock offered by corporate registrars that have a high touch customer service flow, e.g. you have a dedicated person servicing your account.

Re: Does Your Domain Have a Registry Lock?

#23

Wow. Some random person was able to move a domain to their own account simply by whatsapp ing the registrar, telling them that they had bought the domain and were having trouble moving it. That's it. It makes me realize that Google's no humans policy -- is it a policy? -- is actually a strength here. My domains purchased through Google are safe from social engineering because, well, there are no humans to contact to…

The no humans thing also just closes off any path for exceptions that occur outside of what is coded.

I bought a domain for a blogger blog ages ago. At the time google had no domain registry so they partnered with some company.

Years later and google starts hammering me with "hey your credit card is expired we're not going to renew your domain" ...

Fine right?

"Hey go update your payment information on admin.google.com"

Wait. I don't have a g-suite account... and on my personal account my payment info is up to date, so I figure maybe they migrated my email address or emailed me about it but nope.

Then comes circular system where if you forgot X you need Y and if you don't have Y you need X and links on pages that always lead to admin.google.com...

There was no place to find / get help from google. Blogger seems like the information there is wrong / hasn't been updated / abandoned. Just links that ran in circles.

I found the old registrar they partnered with and got them to help.

With Google as far as I could tell there was no way to resolve the issue in a situation where I"m even trying to give them money (granted a nominal amount).

Re: Does Your Domain Have a Registry Lock?

#24
post #7

Confused, how do you get a registry lock then? Do you have to email your registrar? Why is there so little info on this? Or is this the same thing as clientTransferProhibited that is often provided?

You have to deal with the registry directly. Otherwise it's kind of pointless if registrar itself can lock/unlock it.

I have registry lock. I just asked my national domain registry to lock the domain. All that was needed was a strong proof of identity. (not just a photo of an ID, but doing a physical verification in person somewhere, like on the post office or sending a notarized letter) It was free.

But this is a national domain, where I have a high trust in the registry itself (registry manager makes the Turris router, btw, and some key software like knot dns server, etc), and that's also the reason why all my important stuff is linked to this domain.

Re: Does Your Domain Have a Registry Lock?

#25

Wow. Some random person was able to move a domain to their own account simply by whatsapp ing the registrar, telling them that they had bought the domain and were having trouble moving it. That's it. It makes me realize that Google's no humans policy -- is it a policy? -- is actually a strength here. My domains purchased through Google are safe from social engineering because, well, there are no humans to contact to…

> It makes me realize that Google's no humans policy -- is it a policy? -- is actually a strength here. My domains purchased through Google are safe from social engineering because, well, there are no humans to contact to ask them to manually move domains.

I'd suppose that goes both ways. If someone does find a way to steal a domain that's managed by Google, who are you going to contact to get it back?

Re: Does Your Domain Have a Registry Lock?

#26

The usual "registrar lock" is the clientTransferProhibited status you see on domains... that's easily removed by social engineering the registrar. "Registry lock" is serverTransferProhibited, the kind where both your registrar and the main registry need to agree to transfer the domain to another registrar. For instance, you can buy a .ca domain from any registrar, but you need CIRA's compliance (the issuing body for…

A.k.a. the serverTransferProhibited status.

Re: Does Your Domain Have a Registry Lock?

#27
For really important domains, there was MarkMonitor, the high-end registrar. But they've been acquired by an analytics company, so now it's necessary to wait a few years to see if they are still trustworthy.

It's useful to trademark your domain name. That gives you a very likely win if things ever get to the ICANN dispute process.

Re: Does Your Domain Have a Registry Lock?

#28
PM at a large, retail domain registrar here.

Registry Lock isn't something most retail registrars will offer, because generally, the vast majority of registrants don't really need it. It's not something you can just put into your domain management panel and roll out to everyone because of all the hoops required once enabled.

That said, Brian Krebs does need it on his domain(s) for obvious reasons - his domain is a massive target for hacking - and so it's enabled on his domain with specific procedures around how updates happen when required which I won't get into.

Beyond Registry Lock, the best way to secure your domains is to have them in an account with a random username (prevents guessing to aid in social engineering vs. "firstlast" or "flast"), a strong password and 2FA. Perhaps consider a unique account email address that you only use for that registrar account since losing control of that could result in losing control of your entire domains account and all the domains in it (assuming you didn't use 2FA).

On the Registrar side, look for one with good protections to ward off social engineering against the account and domains. In our case, we have a system that requires the account holder's specific consent (obtained via account email) to have a support person view personal information or access the account.

Re: Does Your Domain Have a Registry Lock?

#29

The usual "registrar lock" is the clientTransferProhibited status you see on domains... that's easily removed by social engineering the registrar. "Registry lock" is serverTransferProhibited, the kind where both your registrar and the main registry need to agree to transfer the domain to another registrar. For instance, you can buy a .ca domain from any registrar, but you need CIRA's compliance (the issuing body for…

So what actually makes the "registry lock" robust against social engineering.

Reading CIRA's page it just says that to make changes the Registrar will talk to CIRA to have to lock removed on their behalf. Doesn't sound like there's any mandatory OOB check from CIRA back to the actual client.

Re: Does Your Domain Have a Registry Lock?

#30
post #23

Wow. Some random person was able to move a domain to their own account simply by whatsapp ing the registrar, telling them that they had bought the domain and were having trouble moving it. That's it. It makes me realize that Google's no humans policy -- is it a policy? -- is actually a strength here. My domains purchased through Google are safe from social engineering because, well, there are no humans to contact to…

The no humans thing also just closes off any path for exceptions that occur outside of what is coded. I bought a domain for a blogger blog ages ago. At the time google had no domain registry so they partnered with some company. Years later and google starts hammering me with "hey your credit card is expired we're not going to renew your domain" ... Fine right? "Hey go update your payment information on admin.google.c…

Yep, similarly here. eNom successfully "extorted" $300 from me due to it. My fault ultimately in the end though. But it was a stressful couple days, and eNom and Google partnership soured my view of both of them. I no longer do business with eNom.
Post reply on HN