Earlier quoted context omitted.
Probably because the manual management of these requests is relatively expensive.
Yeah, CloudFlare is one that offers it, but it seems firmly in "Request Quote/Call Sales" territory for pricing. It dates from when they first intro'd their original registrar offering [1] a few years ago, and they said right out: > "CloudFlare Registrar is not designed for the masses. There are plenty of great mass-market registrars. However, if you’re an organization where losing your domains would be a front-page…
Does Your Domain Have a Registry Lock?
61–70 of 73 posts
Re: Does Your Domain Have a Registry Lock?
#62Earlier quoted context omitted.
This does not seem like a sound philosophical security posture -- that only domains who are "massive targets for hacking" should use Registry Lock.
Security and usability is always a compromise. Otherwise we'd all use one-time pads for everything on the internet.
Re: Does Your Domain Have a Registry Lock?
#63Earlier quoted context omitted.
AWS Route53 user chiming in here. I have IAM accounts and soft-token 2FA, and I like how minimal the R53 panel is. This makes me feel like I have a handle on things because there are so few paths to make changes. It also makes me worried I'm missing something. 7 years and no hacks (that I've detected). Knock on wood.
I'm guessing your domain wasn't a huge target then. There was a dns hijacking bug in r53 like 3-4 years ago that was fairly trivial to use. It allowed an arbitrary attacker to register new records to redirect your traffic and take a higher priority in the routing table. I probably shouldn't say much more about it because I don't think it was publicized after they fixed it.
https://blog.thousandeyes.com/amazon-route-53-dns-and-bgp-hi...
That wasn't reaaaaly an AWS hack. BGP hacks are still an issue since it is mostly an honor system! There are no safeguards against this except fast admin.
Re: Does Your Domain Have a Registry Lock?
#64Earlier quoted context omitted.
I'm guessing your domain wasn't a huge target then. There was a dns hijacking bug in r53 like 3-4 years ago that was fairly trivial to use. It allowed an arbitrary attacker to register new records to redirect your traffic and take a higher priority in the routing table. I probably shouldn't say much more about it because I don't think it was publicized after they fixed it.
I think you mean the BGP hack. https://blog.thousandeyes.com/amazon-route-53-dns-and-bgp-hi... That wasn't reaaaaly an AWS hack. BGP hacks are still an issue since it is mostly an honor system! There are no safeguards against this except fast admin.
Re: Does Your Domain Have a Registry Lock?
#65Re: Does Your Domain Have a Registry Lock?
#66Re: Does Your Domain Have a Registry Lock?
#67Earlier quoted context omitted.
This does not seem like a sound philosophical security posture -- that only domains who are "massive targets for hacking" should use Registry Lock.
Why? It's about threat models.
Re: Does Your Domain Have a Registry Lock?
#68Earlier quoted context omitted.
> that's easily removed by social engineering the registrar. I decided to eliminate that one by becoming my own registrar. And that's one less man in the middle siphoning money off of me.
Quite interesting. How did you do that and what did it take (cost, time, effort)? NearlyFreeSpeech.net started off on this a couple of years ago, and it seems like this is a very costly proposition (something like $80K for accreditation?) that also takes a lot of time.
Re: Does Your Domain Have a Registry Lock?
#69The usual "registrar lock" is the clientTransferProhibited status you see on domains... that's easily removed by social engineering the registrar. "Registry lock" is serverTransferProhibited, the kind where both your registrar and the main registry need to agree to transfer the domain to another registrar. For instance, you can buy a .ca domain from any registrar, but you need CIRA's compliance (the issuing body for…
> that's easily removed by social engineering the registrar. I decided to eliminate that one by becoming my own registrar. And that's one less man in the middle siphoning money off of me.
Re: Does Your Domain Have a Registry Lock?
#70Earlier quoted context omitted.
> that's easily removed by social engineering the registrar. I decided to eliminate that one by becoming my own registrar. And that's one less man in the middle siphoning money off of me.
How's that even possible? I cannot imagine how you could convince a registry to do this. Maybe a gTLD registry?