Live data from Hacker News

As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

blog.easydns.org

11–20 of 71 posts

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#11
post #6

The title is pretty much linkbait. If you change registrar-level things about your domain, they're now required to confirm your contact info with you. This isn't a "DDoS", or "deadly", or any of that nonsense: it's a new strategy to ensure whois data stays updated. Whether or not it's an effective strategy for keeping whois data accurate is another debate (I don't think it is), but talking about it like some maliciou…

The end of the article raised a good point though: this is going to train people to click on links in emails that look like they came from their registrar.

That's bad.

The registrar is public information. The registrant's contact information is public (or at least publicly accessible). So, wait a year for people to get accustomed to clicking on links in emails from their registrar, pick a target domain, forge an email from the registrar, send it to owner contact with a link to a phishing page. Congratulations, enjoy your new domain.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#12
post #8
post #4

Earlier quoted context omitted.

I got such an email from Namecheap yesterday, and confirmed it with one click. And unlike the intended trigger for verification ("changes to contact information"), I didn't make any changes to my domain. Either a WHOIS cloak expired, or some other action by Namecheap triggered the verification step.

What exactly is the verification step? Do they mail you a verification token? Because it sounds like you simply clicked a link to verify your address.

Yes, I just clicked a link that went to http://raa.name-services.com/raaverification/verification.as...

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#13
This bit me kind of bad yesterday.

I was about to drive out of cell range and got a text that client's site had some strange page displaying.

Unfortunately, they repoint the dns servers of the domain, and the client had the contact email mx records associated with same domain.

The actual site gets 'dns hikacked' by icann until you fill out a captcha on your site's new page and it emails the whois email account on record with the link.

Had to log into the registrar, luckily had the client's account info, changed the email, and got it verified.

That was 3am yesterday.

Says it takes 24 to 48 hours to updated, but it was only like 8.

Still, if you had an ecommerce site or conduct time-sensitive business via email, be careful.

Because, if you do not see the email, your site will be hijacked by ICANN.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#14
post #4

Can this be done via a "click here to confirm" email, or does this require phone conversations with the registrar? I don't like registering domains using my real name.

I got such an email from Namecheap yesterday, and confirmed it with one click. And unlike the intended trigger for verification ("changes to contact information"), I didn't make any changes to my domain. Either a WHOIS cloak expired, or some other action by Namecheap triggered the verification step.

The email Namecheap sends out is very shady looking. I had to google around quite a bit before concluding it was genuine. The verification link leads to the domain raa.name-services.com and is not delivered over https. It looks exactly like I imagine a targeted phishing email to look.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#15
post #6

The title is pretty much linkbait. If you change registrar-level things about your domain, they're now required to confirm your contact info with you. This isn't a "DDoS", or "deadly", or any of that nonsense: it's a new strategy to ensure whois data stays updated. Whether or not it's an effective strategy for keeping whois data accurate is another debate (I don't think it is), but talking about it like some maliciou…

The end of the article raised a good point though: this is going to train people to click on links in emails that look like they came from their registrar. That's bad. The registrar is public information. The registrant's contact information is public (or at least publicly accessible). So, wait a year for people to get accustomed to clicking on links in emails from their registrar, pick a target domain, forge an emai…

The email address doesn't seem to be the thing registrars should be "validating" about contact information, anyway. Shouldn't my registrar be calling/texting a code to the included phone number, and sending a letter with another code to the included mailing address?

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#18
post #7

Can this be done via a "click here to confirm" email, or does this require phone conversations with the registrar? I don't like registering domains using my real name.

Isn't there some rule that a domain must be registered with a real name, or it doesn't really belong to you (and all anonymization services for domains are therefore suspect)?

[deleted]

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#19
post #7

Can this be done via a "click here to confirm" email, or does this require phone conversations with the registrar? I don't like registering domains using my real name.

Isn't there some rule that a domain must be registered with a real name, or it doesn't really belong to you (and all anonymization services for domains are therefore suspect)?

[deleted]
Post reply on HN