Live data from Hacker News

Name.com hijacks non-existent subdomains and redirects to their servers

destructuring.net

1–10 of 93 posts

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#4
post #3

Can't you just do a CNAME entry with a wildcard pointing to your primary domain?

yes, you can enter a wildcard record yourself, and that will override the name.com wildcard. Is it irritating that they do that? Sure. Should they be doing? probably not. But it does have a pretty simple fix.

Personally, I use a third-party dns service. Seen too many registrars play with DNS. Don't know why anyone would trust them.

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#5
post #3

Can't you just do a CNAME entry with a wildcard pointing to your primary domain?

yes, you can enter a wildcard record yourself, and that will override the name.com wildcard. Is it irritating that they do that? Sure. Should they be doing? probably not. But it does have a pretty simple fix. Personally, I use a third-party dns service. Seen too many registrars play with DNS. Don't know why anyone would trust them.

>> Don't know why anyone would trust them.

I don't know about you, but i give everyone the benefit of doubt and unless someone violates this trust, i'd think most people do too.

Also, at least i tend to think of registrars as some kind of neutral entity that i, indeed, can trust - guess there are some exceptions to the rule.

How many years and years of abuse has it taken for people to notice what GoD*ddy has been doing all that time and finally cause some sort of mass-defect to other registrars..

Hopefully, the level of tolerance for this behavior is of an all-time low so registrars simply can't afford to abuse the trust of their customers any longer.

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#7
I caught Hover.com doing something similar[1] a couple of years ago. They were adding forwards not for subdomains but paths of the root domain. I actually switched to Name.com for this very reason, troubling to see another pulling this stuff.

[1]http://matthewphillips.info/posts/no-thanks-hover.html

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#9
post #3

Can't you just do a CNAME entry with a wildcard pointing to your primary domain?

The wildcard fix is annoying when you have everything on SSL but don't want to handle a wildcard cert[1]. When someone typos https://foo.example.com I'd like the UX to be a browser's "could not connect to server" error, not "this site is untrusted, run away as fast as you can".

--

[1] IMO, the use of wildcard certs is a dangerous practice[2] made obsolete by SNI.

[2] If the cert gets stolen from one server, the thief can impersonate any server on that domain.

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#10
post #5

Earlier quoted context omitted.

yes, you can enter a wildcard record yourself, and that will override the name.com wildcard. Is it irritating that they do that? Sure. Should they be doing? probably not. But it does have a pretty simple fix. Personally, I use a third-party dns service. Seen too many registrars play with DNS. Don't know why anyone would trust them.

>> Don't know why anyone would trust them. I don't know about you, but i give everyone the benefit of doubt and unless someone violates this trust, i'd think most people do too. Also, at least i tend to think of registrars as some kind of neutral entity that i, indeed, can trust - guess there are some exceptions to the rule. How many years and years of abuse has it taken for people to notice what GoD*ddy has been doi…

"I don't know about you, but i give everyone the benefit of doubt and unless someone violates this trust, i'd think most people do too."

True.. and I used to trust registrars to manage my DNS.. but over the years, this is at least the 3rd or 4th time this has happened with a registrar I am on (yes, I have domains at name.com).

Since I don't have time to interrogate every registrars DNS server when I sign up, I just assume it's useless these days. + I end up having to pay for a DNS service anyway, to avoid the bad registrars DNS.. so it's easier to use a single DNS service for all of the domains.

Post reply on HN