Live data from Hacker News

Never buy a .online domain

0xsid.com

241–250 of 513 posts

Re: Never buy a .online domain

#241

> The domain ... has been suspended due to its blacklisting on Google Safe Browsing Et voilà ... ! this is precisely the slippery slope I warned about a decade ago. The indirect censorship becomes direct censorship, defeating all the arguments about the morality of such a list. And: > Not adding the domain to Google Search Console immediately. I don't need their analytics and wasn't really planning on having any cont…

This is 100% on Radix, not on Google. Google and Microsoft can (and probably should) have a registry of known-abusive websites. False positives are inevitable, so these should be taken with a grain of salt, but in most cases they're correct. Their lists are a lot more reliable than those from the "traditional" antivirus/anti-scam vendors that will list anything remotely strange to pump up their numbers. The external…

Exactly what we predicted would happen (someone would eventually put "too much faith" on this list) has literally happened, and your defense is still "well it's not Google's fault, it's a 3rd party's!". Obviously the point is not that Google was going to do it, but that others would , analogue to the process known as "self-censorship".

Re: Never buy a .online domain

#244

The registrar relying on Google Safe Browsing as a “trigger” for suspension is the most horrifying thing I’ve seen in a while. This basically makes the entire TLD unviable for serious use.

This is the real story. This is 100% a problem with Radix. Safe browsing targets the website not the domain. No reason a registrar should be suspending an entire account over something a company reports. Black-holing the A and CNAMEs on a subdomain? Maybe..... But even then I don't think it's the registrars place to do that. Freezing the entire account? Absolutely not.

Blackholing the a and cnames would prevent getting off the safe browsing list, as mentioned in the blog post.

Re: Never buy a .online domain

#245

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

Ah the old "reverse identity theft".

Relevant xkcd:

https://xkcd.com/1279/

Yeah, I get the same regularly.

Re: Never buy a .online domain

#246
post #73

Earlier quoted context omitted.

No need to look for malicious intentions, this is just a feature that costs money so it's very low (or zero) priority for profit driven organisations. I wonder if finding people responsible and spamming then with their own service emails would make the team care enough to fix this. But of course that's mostly dubious, probably illegal, and shouldn't be a responsibility of some vigilante hacker

If bartenders are legally (including criminally!) liable in some jurisdictions for their customers, then certainly a chain of legal liability can exist in other industries.

Yes but bartenders overserving is a crime done by a working-class person and not a wealthy business.

Re: Never buy a .online domain

#247

Earlier quoted context omitted.

Google should not be allowed to make libelous statements without consequences.

(IAAL but this is not legal advice.) It’s not libel. Defamation requires a false statement of fact . Marking a website as “unsafe” is an opinion .

As someone who has also been bit by this, and with the only possible resolution being that I sign up for google services and register my site with them in the google search dashboard...

Fuck Google.

This is absolutely libel. They put a big fucking red banner on top of my site, telling the world that it's unsafe, using all the authority they have as one of the largest tech companies in the world.

In my case - it was a jellyfin instance I'd stood up to host family videos of my kids for my parents.

It was not compromised, and showed only a login page. I reported it as a false flag repeatedly, for weeks, with Google doing jack fucking shit.

Only after signing up in their search console and registering the site did the warning disappear.

They are abusively forcing people into their products. Fuck Google.

In case it wasn't entirely clear - Google can get fucked. Fuck Google.

Re: Never buy a .online domain

#248

Earlier quoted context omitted.

I logged in several times to other people's accounts and reset their passwords. But it's too tiring, people keep adding my email. I hope it's because I have small simple email and not because they want to steal it.

You’re confessing to several actual felonies here, may want to change strategies.

I'm curious if this would really be considered unlawful access, since only pure idiocy and no hacking/scamming/etc were involved.

Re: Never buy a .online domain

#249

> The domain ... has been suspended due to its blacklisting on Google Safe Browsing Et voilà ... ! this is precisely the slippery slope I warned about a decade ago. The indirect censorship becomes direct censorship, defeating all the arguments about the morality of such a list. And: > Not adding the domain to Google Search Console immediately. I don't need their analytics and wasn't really planning on having any cont…

This is 100% on Radix, not on Google. Google and Microsoft can (and probably should) have a registry of known-abusive websites. False positives are inevitable, so these should be taken with a grain of salt, but in most cases they're correct. Their lists are a lot more reliable than those from the "traditional" antivirus/anti-scam vendors that will list anything remotely strange to pump up their numbers. The external…

Wym mean external people aren't these lists integrated to the browsers? I'm sure if you try to open a website from this list your browser won't let you and I'll put a big warning sign

Re: Never buy a .online domain

#250

Earlier quoted context omitted.

> Marking a website as “unsafe” is an opinion. No, it's not. You're welcome to cite case law if you want to insist. Otherwise, unsafe (in the context of infosec) has a definition of likely or able to cause harm or malfunction. Something that is provable or falsifiable with evidence.

Isn't "oops we made a mistake" actually a valid defense to libel in most US states? I thought you had to prove it was intentional to some extent? Or reckless/negligent IANAL

Google takes no action to review the reports that their warnings are false until you sign up for Google products (namely - registering the site in their search console).

I reported a falsely flagged site repeatedly for weeks with absolutely no action from them.

Mozilla and Microsoft both did actually remove the warnings after the reports (Edge and Firefox stopped displaying the warning). Google did not. Google strong armed me into registering for google products, like a fucking bastard of a company.

This was the moment I went from "I don't love google anymore" to "Google can get fucked".

I wish them bankruptcy and every damn legal consequence that is possible to enforce.

Post reply on HN