Live data from Hacker News

How I hijacked the top-level domain of a sovereign state

labs.detectify.com

41–50 of 65 posts

Re: How I hijacked the top-level domain of a sovereign state

#41
post #8
post #3

It pisses me off that for something of this magnitude this guy will probably only be paid no more than a couple thousand dollars, if at all. He still has no response.

If rich countries and private charities were serious about foreign aid, they'd consider helping fund things like this.

Paying developers outside the DRC? I’d imagine that most who wanted to help would prefer something more direct.

Re: How I hijacked the top-level domain of a sovereign state

#42
post #30
post #17

I had a gut feeling it will be '.cd' before clicking on the article and I was right. Dealing with the state entity (SCPT) that manages this TLD is quite a pain. It's so painful that I've given up managing all the .cd domains I used to own. .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously.

> .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously. I bought one a few years ago for 80 Euros / year. Aren't there a lot of TLDs that are way more expensive?

Kiribati (.ki) comes to mind - 900€ per year via ghandi.net or 1350€ at eurodns...

Re: How I hijacked the top-level domain of a sovereign state

#43
post #17

I had a gut feeling it will be '.cd' before clicking on the article and I was right. Dealing with the state entity (SCPT) that manages this TLD is quite a pain. It's so painful that I've given up managing all the .cd domains I used to own. .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously.

You can register/renew it for $59, see https://tld-list.com/tld/cd

Re: How I hijacked the top-level domain of a sovereign state

#44
post #42
post #30

Earlier quoted context omitted.

> .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously. I bought one a few years ago for 80 Euros / year. Aren't there a lot of TLDs that are way more expensive?

Kiribati (.ki) comes to mind - 900€ per year via ghandi.net or 1350€ at eurodns...

According to tld-list.com, the .th TLD is the most expensive ccTLD at $5000 and .ru is the cheapest at $2.99

Re: How I hijacked the top-level domain of a sovereign state

#45

> Although one of the contacts replied and delegated to their colleague, as of this writing, I haven’t received any follow-up confirmation that they fixed the issue. Wonder if that means they're investigating a "legal response" to his report? eg the old "shoot the messenger" approach :/

Many countries would do that, unfortunately

Re: How I hijacked the top-level domain of a sovereign state

#46
post #20

The most ethical move would have been to write to people listed at https://www.iana.org/domains/root/db/cd.html and put IANA in copy (likely ROOT-MGMT@IANA.ORG as listed in the public document: 24x7 Emergency Process Step-by-Step Description).

And if he wasn't going to contact anyone, watching for the domain name to drop, and manually registering it at that point, is a recipe for disaster. It may not have been feasible for him to set up an automatic registration script (although I see he was using Route 53, so maybe it would have been?), but being first in line to drop-catch a domain name is the exact purpose of services such as SnapNames. Took a terrible and unnecessary risk on top of not doing the "most ethical" thing.

Re: How I hijacked the top-level domain of a sovereign state

#47
post #29
post #20

The most ethical move would have been to write to people listed at https://www.iana.org/domains/root/db/cd.html and put IANA in copy (likely ROOT-MGMT@IANA.ORG as listed in the public document: 24x7 Emergency Process Step-by-Step Description).

Quoting the article: >On January 7th, I reached out to the Administrative and Technical contacts listed for .cd on [ https://www.iana.org/domains/root/db/cd.html ].

A week after he registered the domain name. That's not the same thing as "before," which I believe the top comment in this thread was implying about what he should have done instead of what he did do.

Re: How I hijacked the top-level domain of a sovereign state

#48
post #11
post #3

It pisses me off that for something of this magnitude this guy will probably only be paid no more than a couple thousand dollars, if at all. He still has no response.

I work for a few a cities in Europe, and happen to know one of the cities had a site with an sql injection issue. An external person found and let the city know but didn't want to reveal the specifics before getting money. The city has no bounty program and for some people in the City it came across as if the guy was distorting them. The guy probably felt like he didn't get money for his work. Probably both have a po…

  s/distort/extort/

Re: How I hijacked the top-level domain of a sovereign state

#50
post #11

Earlier quoted context omitted.

I work for a few a cities in Europe, and happen to know one of the cities had a site with an sql injection issue. An external person found and let the city know but didn't want to reveal the specifics before getting money. The city has no bounty program and for some people in the City it came across as if the guy was distorting them. The guy probably felt like he didn't get money for his work. Probably both have a po…

s/distort/extort/

Yes right. Apologies.
Post reply on HN