Live data from Hacker News

Perl.com Taken over by Domain Squatters

twitter.com

61–70 of 82 posts

Re: Perl.com Taken over by Domain Squatters

#61
post #42

Earlier quoted context omitted.

Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.

I'm actually not sure for this type of attack how much I'd value OTP authenticators over SMS. They are both vulnerable to phishing in the same way. What I'd like to see a lot more of is WebAuthn specifically, rather than "hardware keys" generally. It's frustrating to me that the outfits I deal with only have OTP and not WebAuthn.

Anyone have a short list of registrars who support Yubikey (or competitors)?

Re: Perl.com Taken over by Domain Squatters

#62
post #60

Honest question: Was this an important host name? From what I can see Perl the programming language has its home at perl.org, which is running fine. The .com does not show up prominently when googling for perl. Based on Google's cache it seems it was some kind of programming-related news page. Was it relevant/popular in the Perl community?

Historically, it was the Perl web site for a long time. It was registered by Tom Christiansen in 1994 and soon afterwards, he let O'Reilly run it - and they used it to post useful Perl news and articles for a long time.

But O'Reilly's interest in Perl waned and it sat, moribund, for several years (which probably explains its lack of Googlejuice).

A few years ago, the Perl community approached Tom and he let them take over running it. The team behind the PerlTricks web site ported over all the old articles and had been posting new ones. It had become a pretty useful resource again.

So, yes, it would be a shame to lose it. But from what brian has posted elsewhere on this thread, that seems unlikely to happen.

Re: Perl.com Taken over by Domain Squatters

#63
post #42

Earlier quoted context omitted.

Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.

I'm actually not sure for this type of attack how much I'd value OTP authenticators over SMS. They are both vulnerable to phishing in the same way. What I'd like to see a lot more of is WebAuthn specifically, rather than "hardware keys" generally. It's frustrating to me that the outfits I deal with only have OTP and not WebAuthn.

To phishing, yes, but not to SIM card cloning/social engineering your cell phone provider shenanigans.

Re: Perl.com Taken over by Domain Squatters

#64

Let’s call it what it is. It’s not a domain taken over by squatters. The domain was stolen. I’ve seen other domains get stolen recently, it seems to be about the same time. Patterns dot com Piracy dot com Perl dot com All stolen at around the same time. With patterns, the thief hacked the network solutions account, put the domain under privacy, transferred it to a Chinese registrar, and then put the old whois data ba…

> The domain was stolen.

Yes. At the time, and with the information available, it looked like an isolated incident. It now appears that this affects several, dozens maybe, or potentially many more domains after what appears to be a social engineering attack at a registrar. Check your domains!

Re: Perl.com Taken over by Domain Squatters

#66

Earlier quoted context omitted.

I'm actually not sure for this type of attack how much I'd value OTP authenticators over SMS. They are both vulnerable to phishing in the same way. What I'd like to see a lot more of is WebAuthn specifically, rather than "hardware keys" generally. It's frustrating to me that the outfits I deal with only have OTP and not WebAuthn.

Anyone have a short list of registrars who support Yubikey (or competitors)?

Gandi.net seems to support it https://www.yubico.com/works-with-yubikey/catalog/gandi-net/ There’s a short list found here with supported sites including registrars https://www.yubico.com/works-with-yubikey/catalog/

Re: Perl.com Taken over by Domain Squatters

#67
post #39
post #31

Earlier quoted context omitted.

It hosted cperl and rperl, which are important. Perl5, as you might not know is not developed anymore, it's only maintained into oblivion, getting worse and worse over time. 20 years no new features, only design mistakes over mistakes piling up. perl11 provided the continuation of Perl development, but the maintainers in their tunnel vision do not agree (yet). Almost everything they did in the last 6 years came from…

Uh Perl 5 is in ACTIVE development and has gotten new features. Everything you said about Perl 5 is wrong. Perl 7 (skipping Perl 6 obviously) is on the table and being talked about and Perl 5.34.0 is going to be released in a couple months setting the stage for Perl 7.

reini has a ... unique ... perspective on perl development, which is probably related to how he got banned from the p5p mailing list for repeatedly calling people incompetent without giving actual technical reasons against the patches.

cperl is an interesting fork with a lot of good ideas, but his tendency to submit patches to core modules to work around cperl bugs without full explanation and then yell at the people asking for justification and actual tests for those changes meant that such patches don't tend to actually end up applied.

Given reini is undeniably brilliant when at his best, I consider this deeply unfortunate, but I've tried to explain the concept of "even if you're sure you're right, you need to actually convince people of that" multiple times both online and in person and apparently not got through, so at this point I can only suggest that people who're interested in his brilliance follow their code for themselves and submit the interesting stuff as patches.

A great shame, but things are what they are.

Re: Perl.com Taken over by Domain Squatters

#68
post #42

Let’s call it what it is. It’s not a domain taken over by squatters. The domain was stolen. I’ve seen other domains get stolen recently, it seems to be about the same time. Patterns dot com Piracy dot com Perl dot com All stolen at around the same time. With patterns, the thief hacked the network solutions account, put the domain under privacy, transferred it to a Chinese registrar, and then put the old whois data ba…

Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.

I use Gandi which supports 2FA, but annoyingly they do not let you disable TOTP if you want to use U2F.

Re: Perl.com Taken over by Domain Squatters

#70

Earlier quoted context omitted.

Anyone have a short list of registrars who support Yubikey (or competitors)?

Gandi.net seems to support it https://www.yubico.com/works-with-yubikey/catalog/gandi-net/ There’s a short list found here with supported sites including registrars https://www.yubico.com/works-with-yubikey/catalog/

When 2FA is not enough... https://fastmail.blog/2014/04/10/when-two-factor-authenticat...
Post reply on HN