Live data from Hacker News

Name.com hijacks non-existent subdomains and redirects to their servers

destructuring.net

61–70 of 93 posts

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#61
post #13

Some previous discussion on this issue (almost 2 years ago): http://news.ycombinator.com/item?id=2443710 I'll say the same thing I said then: As an anecdotal counterpoint, I'm an extremely happy Name.com customer. I transfered several domains to them a year or so ago from GoDaddy. They support two-factor authentication, their interface is uncluttered, I pay them less money than I paid GoDaddy, and I haven't had a sin…

May I ask where do you do your DNS hosting ? Do you host it yourself ? Or do you use a third party ?

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#64

Earlier quoted context omitted.

Why bother? ZoneEdit works great. I've been using them for, geez, over 15 years I think.

ZoneEdit now charge. They grandfathered old users in at a free tier (first 5?) but now all new users have to pay either $1/month/domain or less if you buy a lot of "credits."

I'm still sad that they discontinued their free tier. It was awesome..just like google apps was awesome.

:(

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#66

Earlier quoted context omitted.

The irony is that their actions can in fact make cookies their customers are using for their sites invulnerable.

I don't understand what you are saying ? Is it that there is a security issue arising from the DNS hijacking ? If so what's the issue ?

Say you set a session cookie that spans multiple subdomains (cookie domain = `.example.com`).

Now, if one of your authenticated users visits the wrong subdomain, they are directed to a server of name.com's choice.

That server now has access to your user's session ID (using Javascript or PHP or whatever to read the cookie).

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#67
post #13

Some previous discussion on this issue (almost 2 years ago): http://news.ycombinator.com/item?id=2443710 I'll say the same thing I said then: As an anecdotal counterpoint, I'm an extremely happy Name.com customer. I transfered several domains to them a year or so ago from GoDaddy. They support two-factor authentication, their interface is uncluttered, I pay them less money than I paid GoDaddy, and I haven't had a sin…

May I ask where do you do your DNS hosting ? Do you host it yourself ? Or do you use a third party ?

for domains I'm actively using, I use Route53. For domains I'm not actively using, I don't mind name.com is parking.

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#68
post #13

Some previous discussion on this issue (almost 2 years ago): http://news.ycombinator.com/item?id=2443710 I'll say the same thing I said then: As an anecdotal counterpoint, I'm an extremely happy Name.com customer. I transfered several domains to them a year or so ago from GoDaddy. They support two-factor authentication, their interface is uncluttered, I pay them less money than I paid GoDaddy, and I haven't had a sin…

May I ask where do you do your DNS hosting ? Do you host it yourself ? Or do you use a third party ?

The hosting companies I've used (eg: Linode, Dreamhost for smaller projects) all provide DNS services. I trust them to manage a DNS infrastructure more than I trust myself.

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#69
post #48

Earlier quoted context omitted.

DNS aside, Name.com is one of the only registrars I know of with reasonable security practices. They support two-factor auth (almost no one else does), and have nicely scoped cookies (HTTP only, Secure flag, etc.).

The irony is that their actions can in fact make cookies their customers are using for their sites invulnerable.

invulnerable? You mean "vulnerable", right?

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#70
21. Parked domain service

All domain names registered via Name.com will automatically be provided a Parked Domain Service. All domains will default to our name servers unless and until you modify your default settings. At any time, you may disable the placeholder page by updating, modifying or otherwise changing the name servers for the relevant domain name.

Domain names using our Parked Domain Service may display a placeholder page for your future website. These placeholder pages may include contextual and/or other advertisements for products or services. Name.com will collect and retain any and all revenue acquired from these advertisements, and you will have no right to any information or funds generated via the Parked Domain Service.

You agree that we may display our logo and links to our website(s) on pages using the Parked Domain Service.

Name.com will make no effort to edit, control, monitor, or restrict the content displayed by the Parked Page Service. Any advertising displayed on your parked page may be based on the content of your domain name and may include advertisements of you and/or your competitors. It is your responsibility to ensure that all content placed on the parked page conforms to all local, state, federal, and international laws and regulations.

It is your obligation to ensure that no third party intellectual or proprietary rights are being violated or infringed due to the content placed on your parked page. Neither Name.com nor our advertising partners will be liable to you for any criminal or civil sanctions imposed as a direct or indirect result of the content or links (or the content of the websites to which the links resolve) displayed on your parked pages.

As further set forth above, you agree to indemnify and hold Name.com and its affiliated parties harmless for any harm or damages arising from your use of the Parked Domain Service.

Post reply on HN