DNS abuse and criminal infrastructure
1–10 of 51 posts
Re: DNS abuse and criminal infrastructure
#2A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims.
By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists.
At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?
I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless.
Re: DNS abuse and criminal infrastructure
#3Stats about the block list are good (10% of gtld domains are blocked) but thay requires comparing it with a baseline. How many of non gtld domains are blocked?
Re: DNS abuse and criminal infrastructure
#4Re: DNS abuse and criminal infrastructure
#5I have some experience of dealing with this when working for .gov.uk A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims. By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on w…
Re: DNS abuse and criminal infrastructure
#6I have some experience of dealing with this when working for .gov.uk A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims. By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on w…
On the other hand, I struggle to think of a reason how harm could come from delayed activation of a registered public name. Can you describe a use case that cannot be solved by opting for a subdomain of an already-existing domain?
Why shouldn't that go live instantly?
A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.
I've had a brilliant idea for an eCommerce website but it is 1705 on a Friday night and, because no one works weekends, I have to wait until next week before the domain is agreed.
I agree that there's no great harm in having to wait a day, or a week, for registration to complete. But in a world of instant gratification, it feels old fashioned.
Re: DNS abuse and criminal infrastructure
#7Re: DNS abuse and criminal infrastructure
#8https://view.officeapps.live.com/op/view.aspx?src=https%3A%2...
Re: DNS abuse and criminal infrastructure
#9If your TLD is location based for example, consider verifying and linking the TLD to an identity, by local means, like a national ID.