Live data from Hacker News

Perl.com Taken over by Domain Squatters

twitter.com

51–60 of 82 posts

Re: Perl.com Taken over by Domain Squatters

#51
post #42

Earlier quoted context omitted.

Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.

Agreed, definitely use 2fa if it’s offered. What many people don’t realize is that there are a lot of registrars still using less secure platforms. So moving to a more secure registrar can help as well. I mention registering for 5 years in the future because if something like this happens, there will be no question as to whether or not you lost the domain because it expired.

Any recommendations on a good registrar?

Re: Perl.com Taken over by Domain Squatters

#52
post #42

Let’s call it what it is. It’s not a domain taken over by squatters. The domain was stolen. I’ve seen other domains get stolen recently, it seems to be about the same time. Patterns dot com Piracy dot com Perl dot com All stolen at around the same time. With patterns, the thief hacked the network solutions account, put the domain under privacy, transferred it to a Chinese registrar, and then put the old whois data ba…

Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.

I'm actually not sure for this type of attack how much I'd value OTP authenticators over SMS. They are both vulnerable to phishing in the same way.

What I'd like to see a lot more of is WebAuthn specifically, rather than "hardware keys" generally. It's frustrating to me that the outfits I deal with only have OTP and not WebAuthn.

Re: Perl.com Taken over by Domain Squatters

#53
post #51

Earlier quoted context omitted.

Agreed, definitely use 2fa if it’s offered. What many people don’t realize is that there are a lot of registrars still using less secure platforms. So moving to a more secure registrar can help as well. I mention registering for 5 years in the future because if something like this happens, there will be no question as to whether or not you lost the domain because it expired.

Any recommendations on a good registrar?

Gandi.net is awesome. (not affiliated, just a happy user)

Re: Perl.com Taken over by Domain Squatters

#55
post #51

Earlier quoted context omitted.

Agreed, definitely use 2fa if it’s offered. What many people don’t realize is that there are a lot of registrars still using less secure platforms. So moving to a more secure registrar can help as well. I mention registering for 5 years in the future because if something like this happens, there will be no question as to whether or not you lost the domain because it expired.

Any recommendations on a good registrar?

namecheap.com is great (always good prices). Obviously, never go with Godaddy.com (rip offs)

Re: Perl.com Taken over by Domain Squatters

#56
post #51

Earlier quoted context omitted.

Agreed, definitely use 2fa if it’s offered. What many people don’t realize is that there are a lot of registrars still using less secure platforms. So moving to a more secure registrar can help as well. I mention registering for 5 years in the future because if something like this happens, there will be no question as to whether or not you lost the domain because it expired.

Any recommendations on a good registrar?

Gandi.net

Re: Perl.com Taken over by Domain Squatters

#58
Thanks to everyone who has given advice and helped us develop a timeline of the incident. I'm not part of the network and asset management: I'm a mere editor of the website.

The current registrar has contacted me. They've locked the domain and we need to submit some paperwork. It shouldn't be that big of a deal even though it's annoying. All of this was handled quickly (12 hours) because of the attention to the internet in general.

Re: Perl.com Taken over by Domain Squatters

#59

Thanks to everyone who has given advice and helped us develop a timeline of the incident. I'm not part of the network and asset management: I'm a mere editor of the website. The current registrar has contacted me. They've locked the domain and we need to submit some paperwork. It shouldn't be that big of a deal even though it's annoying. All of this was handled quickly (12 hours) because of the attention to the inter…

That's great news, Brian. The key here is that it was handled quickly. The longer it goes on unnoticed, the more difficult it becomes to unravel, as a domain gets transferred from registrar to registrar and from owner to owner.

I can confirm that Neurologist dot com and Chip dot com were also stolen at the same time. There may be others.

Re: Perl.com Taken over by Domain Squatters

#60
Honest question: Was this an important host name?

From what I can see Perl the programming language has its home at perl.org, which is running fine. The .com does not show up prominently when googling for perl. Based on Google's cache it seems it was some kind of programming-related news page. Was it relevant/popular in the Perl community?

Post reply on HN