Live data from Hacker News

Perl.com Taken over by Domain Squatters

twitter.com

71–80 of 82 posts

Re: Perl.com Taken over by Domain Squatters

#71
post #42

Let’s call it what it is. It’s not a domain taken over by squatters. The domain was stolen. I’ve seen other domains get stolen recently, it seems to be about the same time. Patterns dot com Piracy dot com Perl dot com All stolen at around the same time. With patterns, the thief hacked the network solutions account, put the domain under privacy, transferred it to a Chinese registrar, and then put the old whois data ba…

Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.

This actually rules out a substantive number of registrars. I have a statement from an account manager at our wholesale supplier arguing that the requirement to know both the email address and password is considered "two factor" in the industry.

I don't see why offering MFA hasn't been made a requirement in order to be an accredited domain registrar.

Re: Perl.com Taken over by Domain Squatters

#72

Earlier quoted context omitted.

Anyone have a short list of registrars who support Yubikey (or competitors)?

Gandi.net seems to support it https://www.yubico.com/works-with-yubikey/catalog/gandi-net/ There’s a short list found here with supported sites including registrars https://www.yubico.com/works-with-yubikey/catalog/

They do, I use it.

Re: Perl.com Taken over by Domain Squatters

#73
post #68
post #42

Earlier quoted context omitted.

Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.

I use Gandi which supports 2FA, but annoyingly they do not let you disable TOTP if you want to use U2F.

I've found that to be pretty common. I guess sites don't want to risk you losing your hardware and then not having a backup method.

Re: Perl.com Taken over by Domain Squatters

#74
post #51

Earlier quoted context omitted.

Agreed, definitely use 2fa if it’s offered. What many people don’t realize is that there are a lot of registrars still using less secure platforms. So moving to a more secure registrar can help as well. I mention registering for 5 years in the future because if something like this happens, there will be no question as to whether or not you lost the domain because it expired.

Any recommendations on a good registrar?

We've been using joker.com for years.

Re: Perl.com Taken over by Domain Squatters

#75
post #42

Let’s call it what it is. It’s not a domain taken over by squatters. The domain was stolen. I’ve seen other domains get stolen recently, it seems to be about the same time. Patterns dot com Piracy dot com Perl dot com All stolen at around the same time. With patterns, the thief hacked the network solutions account, put the domain under privacy, transferred it to a Chinese registrar, and then put the old whois data ba…

Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.

Which registrars do you recommend that have 2FA?

Re: Perl.com Taken over by Domain Squatters

#76

Earlier quoted context omitted.

How would you prevent a group from trolling or performing a hostile takeover of a small domain? How would someone acquire a domain? How do you determine consensus? In this case, as someone who doesn't follow Perl, how would I make an informed decision on which perl.com domain I really want?

> How would you prevent a group from trolling or performing a hostile takeover of a small domain? Several ways. If you are accessing the domain locally, you'd normally be looking for entries that match the private key you have stored. So if you ever went to that domain, you'll get the same remote again. If this is your first time accessing the domain, you'd ask your peers what version of the domain they have stored.…

I just thought of a way to improve the privacy of the DNS lookup. Instead of asking for the domain name, ask for a prefix of the hash of the domain name chosen so you get maybe 20 domains back.

The point is - I got all of the above by thinking about the problem for maybe ten minutes. This is far from unsolvable. We as a community are just terminally lazy.

Re: Perl.com Taken over by Domain Squatters

#77

Let’s call it what it is. It’s not a domain taken over by squatters. The domain was stolen. I’ve seen other domains get stolen recently, it seems to be about the same time. Patterns dot com Piracy dot com Perl dot com All stolen at around the same time. With patterns, the thief hacked the network solutions account, put the domain under privacy, transferred it to a Chinese registrar, and then put the old whois data ba…

Why did you spell it out “dot com”?

Re: Perl.com Taken over by Domain Squatters

#78
I was wondering why none of the links were working. I was trying to read on the beginnings of Perl6 (now Raku) design (such as in https://www.perl.com/pub/2000/11/perl6rfc.html/) and also check some States of the Onion. At least everything is currently accessible either through the Wayback Machine or here: https://perldotcom.perl.org/

Re: Perl.com Taken over by Domain Squatters

#79

Let’s call it what it is. It’s not a domain taken over by squatters. The domain was stolen. I’ve seen other domains get stolen recently, it seems to be about the same time. Patterns dot com Piracy dot com Perl dot com All stolen at around the same time. With patterns, the thief hacked the network solutions account, put the domain under privacy, transferred it to a Chinese registrar, and then put the old whois data ba…

for How much was it on sale?
Post reply on HN