Live data from Hacker News

Google Domains blocking all Gitbook URLS: post-mortem

blog.gitbook.com

161–170 of 189 posts

Re: Google Domains blocking all Gitbook URLS: post-mortem

#161

Just out of curiosity- when Google is infamous for hard-to-reach human support, what in the Internet would make anyone interested to register their domain with them? Do they provide some sort of security or insurance that I am unaware of? All the popular dedicated domain registrars I have used so far have excellent human support. Godaddy, namecheap, namesilo to name a few. I don't know if big companies or corporate u…

I moved/consolidated from GoDaddy and 101domain to Google Domains because of the support I've gotten from Google in the past (on Nexus/Pixel devices, Apps, Fiber, Fi, Stadia, etc). I always assume the people complaining about nonexistent support from Google are trying to get support for something they aren't paying for. You pay for Domains, and the support reflects that. You probably can't get support for getting loc…

As a paying G Suite customer, all of my support experiences have been horrendous, including trying to unlock an employee’s account that was locked for “spam”.

The support agent couldn’t do a single thing but tell me to wait for the possibly robotic appeals process.

Re: Google Domains blocking all Gitbook URLS: post-mortem

#162
post #129

Earlier quoted context omitted.

We've just published a postmortem: https://blog.gitbook.com/tech/post-mortems/06-20-gitbook-dom... let us know if you have any questions!

I'm curious how you feel about CloudFlare as a registrar not allowing GitBook to use an external root nameserver. Being forcibly stuck on CloudFlare's own nameservers only sounds very nefarious, and isn't a limitation I've ever heard of with any other registrar. For instance, it would break my tooling that uses my host's APIs to control DNS records through their nameserver. I'd be very appreciative if eastdakota or j…

Cloudflare sells the domain at cost. I think the idea is that its an extra service meant for their customers, not a service for the general public. As they are a DNS provider, their customers will use cloudflare nameservers. If they didn't, they would no longer be customers.

Re: Google Domains blocking all Gitbook URLS: post-mortem

#163
post #27

Earlier quoted context omitted.

Namecheap have been solid for me for several years now.

Namecheap dumping personal info without informing their customer ( https://news.ycombinator.com/item?id=18063667 ), Namecheap threatening to shut down a site if the customer doesn’t delete two images posted there within 24 hours ( https://news.ycombinator.com/item?id=14139288 )

> Namecheap dumping personal info without informing their customer

Something similar happened to me – Namecheap dumped the wrong (private) information into WHOIS immediately after a redesign of their systems. It definitely was not user error.

Dealing with Namecheap's customer support to try to resolve this was possibly the worst customer support experience I've had in 20+ years in the tech industry. Lots of lies about getting back to me the next day, passing the buck, blaming everybody but themselves, extended periods of flat-out ignoring me, and eventually a complete inability to fix it.

I've been a happy user of Hover ever since, but I'm unable to recommend them – ironically because nothing has ever gone wrong with them. I used to recommend Namecheap until that nightmare happened, then I found out just how shockingly useless they are when it comes to customer support and privacy. Ever since, I only recommend services where something has gone wrong so that I know they are capable of resolving problems well. I regret ever recommending Namecheap and don't want to make the same mistake again.

Some more Namecheap horror stories here: https://news.ycombinator.com/item?id=18087862

Re: Google Domains blocking all Gitbook URLS: post-mortem

#164
post #69
post #65

Earlier quoted context omitted.

I'm going through issues with G Suite as an admin. They randomly blocked my account falsely accusing me of sending spam. I can't even access the help support team sicne I can't login to the system.

This is completely insane - there's absolutely no legitimate reason for Google to lock you out of your account , even if you were sending spam emails. Disable your ability to send new emails, maybe. Lock you out of your email inbox, maybe. But completely prevent you from accessing your account, and therefore even appealing? Inexcusable.

Come on bear with them. They're not a very big or technically sophisticated company, so they only have one big on/off button per account.

Re: Google Domains blocking all Gitbook URLS: post-mortem

#165

Aside from the Google domain issue (which is obviously a problem) -- why on earth would GitBook be hosting user-generated content under their corporate gitbook.com domain? The registrar issue is one problem here -- but I don't see this addressed in their post-mortem. I thought this was a well-known issue. You don't host user-generated content on the same domain that handles your corporate email. Because things like t…

It most often has to do with browser sandboxing. See CORS, cookies, etc. It was a security flaw that began being addressed circa 2010.

Re: Google Domains blocking all Gitbook URLS: post-mortem

#167
post #116

Earlier quoted context omitted.

Where do you draw the line? I mean github.com is the corporate email domain of the GitHub company, it also hosts repositories (user generated content)

But it isn't... directly. Github.com is their corporate site, hosts their application, and is how we all interact with repositories (via https or git://). But, the only data you get from that site has been processed through their application and sanitized. The only way to get access to the raw user-generated data is through raw.githubusercontent.com or Github Pages which hosted on github.io. And the data from raw.git…

Nevertheless some countries blocked github.com, not (only?) githubusercontent.com or github.io

https://en.wikipedia.org/wiki/Censorship_of_GitHub

Probably they think that GitHub didn't sanitize the content on github.com well enough.

Re: Google Domains blocking all Gitbook URLS: post-mortem

#168
post #154

Earlier quoted context omitted.

Does it really make it less of a problem if they had a separate domain for corporate and it was only the user content going down? Serving user content can as well be part of a service’s core product and registrar induced downtime is a big enough problem. Building and running anti-abuse tech works in proportion to the money put in. Can a small player really compete with Google’s anti-abuse investments? No. Save for a…

> Does it really make it less of a problem if they had a separate domain for corporate and it was only the user content going down? Serving user content can as well be part of a service’s core product and registrar induced downtime is a big enough problem. Yes, it really does. Not losing your ability to receive email will help resolve the problem. > Serving user content can as well be part of a service’s core product…

> Not losing your ability to receive email will help resolve the problem.

Sure, I'm trying to prevent this stealing focus from the fact that this shouldn't have been a problem to begin with. The argument for separation is not made for defending against a SLA limitation or some other technical reason. It is made to accommodate a faulty policy problem. It is equal to saying "best practice: all big-co domains users should have corporate and production domain separation in case big-co's policy layer messes up. oh well". I'd rather see big-co held accountable not to mess up.

> If that is the case, then choosing a registrar that provides quality, timely and responsive support when dealing abusive content complaints should be on the top of your priorities.

Hindsight is perfect, while those qualities are rarely perfectly symmetrical information. "They should have known this could have happened" sounds like victim blaming to me. They were entitled to reasonable policies and reasonable application of those policies.

> I'm not sure how this become anti-competitive

Monopoly is not the only machinery of anti-competition. Creating a landscape demanding anti-abuse parity is essentially creating a barrier of entry. They are going to cloudflare next but there is no telling a similar scenario won't happen. It is important to call out the potential of big-co's putting capital-intensive demands on little players to participate in the web.

Re: Google Domains blocking all Gitbook URLS: post-mortem

#169

Aside from the Google domain issue (which is obviously a problem) -- why on earth would GitBook be hosting user-generated content under their corporate gitbook.com domain? The registrar issue is one problem here -- but I don't see this addressed in their post-mortem. I thought this was a well-known issue. You don't host user-generated content on the same domain that handles your corporate email. Because things like t…

We don't host user content under the gitbook.com, or at least we've stopped doing it a few years ago.

User content is stored under *.gitbook.io, similar to GitHub.

Google blocked all domains that contained "gitbook" in our account, even ones that are used for some infrastructure and are not accessible by the public. We don't know the exact reason for this, maybe they've blocked gitbook.com because we still have some redirect for content that was hosted under it years ago.

And yes we are going to make changes to host our status page under another domain.

Re: Google Domains blocking all Gitbook URLS: post-mortem

#170

GitBook CTO here: Our production domains (gitbook.com and gitbook.io) have been blocked and locked by our registrar (Google Domains). None of our infrastructure is impacted, all user content and databases are safe; our domains simply blocked by a heavy handed policy. As mentioned on Twitter, we are all hands working with Google to fix this issues ASAP. We'll then share an in-depth post-mortem https://twitter.com/GitB…

We've just published a postmortem: https://blog.gitbook.com/tech/post-mortems/06-20-gitbook-dom... let us know if you have any questions!

How did you arrive at choosing Cloudflare? It's clear Google Domains has broken processes not conducive to running a business centered on user content. How do you know Cloudflare does not suffer from similar broken processes?
Post reply on HN