Live data from Hacker News

Cloudflare loses 22% of its domains in Freenom .tk shutdown

netcraft.com

171–180 of 236 posts

Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown

#172

Earlier quoted context omitted.

1) not using DoS / DDoS protection, or using any number of hosting services that have this built in, or using a service that doesn't marginalize large parts of the world in the name of "security". DoS / DDoS attacks are not as common as Cloudflare would want you to believe. 2) use literally any other registrar / DNS service / hosting platform. You then won't need to worry about whether people all over the world will…

They don’t only offer DDoS protection, but also a WAF (Web Application Firewall), and if you run commodity software, attacks are very common. I know this because I manage a WordPress site fronted by a different WAF, and I can see in the logs that malicious bots are trying to pwn the site basically 24/7. (and before you say ‘patches’ – yes, but defense in depth is a thing, and you don’t always have the luxury of vendo…

Yes, Wordpress is attacked incessantly. It's designed to be actively hostile to security, so yes, a firewall that helps ameliorate is a good thing.

However, if you really care about Wordpress security, a WAF is just covering things up, and yes, you need to patch (but that's not really the fix). The proper fix is to reconfigure things to not follow Wordpress' absolutely ridiculous security. While patching depends on vendors, securing Wordpress from its own hubris doesn't depend on vendors.

But even where Cloudflare's products are arguably good, they still do too much in my opinion to marginalize non-mainstream visitors and to re-centralize the Internet around one big company. Every time they have issues, huge parts of the Internet are affected. If I wanted a WAF, I'd get it from elsewhere.

Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown

#173

Earlier quoted context omitted.

Cloudflare shields criminals from cops. They do so because of "free speech" or whatever. There was recently a story about a swatting victim, who tried to get the forum the swatters use to shut down. Cloud flare refused to give the identity of the criminals, the case even went to court and the victim lost and now apparently has to pay court costs. Our legal system is unfortunately not perfect, which is why it matters…

wait, are you mad cloudflare decided not to be an active participant in a doxxing campaign? Swatting is awful but I'm inclined to side with cloudflare here.

I'm mad that they offer anonymity to criminals. If you offer a service that lets people hide their identity, you ought to perform a bit of due diligence.

Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown

#174

Earlier quoted context omitted.

> if this is about not-illegal-but-objectionable content, I'm actually glad that as an infrastructure company, they're choosing to not get into the business of content moderation. Agreed. There's one other subset you didn't mention: "Clearly illegal but not yet handled in the court of law". Cloudflare again has a pretty hardline stance that "the courts need to come to us and force us to take it down"

> Cloudflare again has a pretty hardline stance that "the courts need to come to us and force us to take it down" "Hardline"? To me it seems like quite reasonable approach as opposed to "we will just take down anything someone on Twitter didn't like".

It's not reasonable. 99% of scams, frauds and harassment will never be subject of legal action, because there just aren't enough prosecutors out there to charge every fraud attempt.

If you require a court ruling before blocking a fraud, it means you will keep hosting 99% of frauds.

Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown

#176
post #10

Another prominent .tk domain is for the Tcl programming language (tcl.tk) and I just checked, that is one of the paid .tk domains that are still up.

Why do orgs feel the need to use these whacky TLDs I’m still of the fence with rust using .rs in important places which is fundamentally in control of the Serbian government. You’re going to have to trust the Serbian government with signing .rs DNSSSEC at minimum and I don’t.

To be perfectly fair, the list of DNSSEC cock-ups is staggering. .nz ccTLD was taken down, IIRC, for 4 days after a bad KSK rollover just last year. I’ve seen prominent registrars with ‘automated’ DNSSEC fail to upload correct NSEC and RRSIGs. It’s not uncommon to see .gov domains go down because of DNSSEC. You’d think all these entities should get it right, but they don’t. Probably why many major tech domains such as google.com don’t use DNSSEC.

But to your point, using a ‘off-brand’ can really hurt sometimes. `.af` might be a cute marketing tactic, but it’s actually Afghanistan, and the Taliban play by a different rulebook. I believe it was `gay.af` that found that out the hard way. Tons of other stories.

Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown

#177
post #22

Earlier quoted context omitted.

> You are sort of borrowing it without explicit (or lasting) permission. To be fair, this is true of all domains. The broader concern with ccTLDs is this borrowing dynamic layered with whatever geopolitical situation the country is in, how stable the administering authority is with respect to the current regime, or just the political forces at work within the country that may lead to changes or requirements for the c…

It's not true of gTLDs though. You actually own those domains, and they can't be taken away from you (barring extreme circumstances) so long as you pay the registration fees every year. But domains on ccTLDs can be taken away from you by the government at any time for any reason.

I gotta say i find it extremely hard to believe that one can "own" a domain. This sounds like hand-waving. We don't own software, we barely own computers (to do with what we want), we don't own media.

Is this like "one can own land" but really that's asterisked with Eminent Domain (no pun intended)?

Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown

#178
post #160

Earlier quoted context omitted.

Who you going to send to an online pharmacy hosted say in Egypt?

Why do you need to take down Egyptian pharmacy in the first place?

Because they send controlled substances to the US and falsely label them as "supplements"

I know, because I bought RX stuff from India and it did not get labelled as medication

Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown

#179
post #9

Oh, that is why I wasn't able to renew some domains I have used for 10+ years. I'm not even able to upgrade to paid domain. I don't think it will help reducing malware/scams/phishing. But it will hurt students and young people that want to start in en development and aren't able to pay for a domain.

We still have https://nic.eu.org/ and https://freedns.afraid.org/ .

I applied for a domain at nic.eu.org in 2023 and I have never gotten a response

Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown

#180

Earlier quoted context omitted.

Im trying to remember I think it was 8m.com or something like that? Which also let you have stuff like username.8m.com its probably gone now. I also miss tripod, not sure if its still around how it used to be. Angelfire comes to mind too.

Those sites are still up, the control panel is at freeservers.com my Site davinder.8m.net is still up after 22 years. I chose .net because it was cooler than .com :)

Hah! Thats awesome, I don’t recall any of the names I used to be honest, its been too many years.
Post reply on HN