Live data from Hacker News

As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

blog.easydns.org

21–30 of 71 posts

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#21
post #4

Earlier quoted context omitted.

I got such an email from Namecheap yesterday, and confirmed it with one click. And unlike the intended trigger for verification ("changes to contact information"), I didn't make any changes to my domain. Either a WHOIS cloak expired, or some other action by Namecheap triggered the verification step.

The email Namecheap sends out is very shady looking. I had to google around quite a bit before concluding it was genuine. The verification link leads to the domain raa.name-services.com and is not delivered over https. It looks exactly like I imagine a targeted phishing email to look.

That's the same domain they use in the e-mail you get asking you to review the accuracy of your WHOIS data. They send that e-mail for every domain you own, every year, as required by ICANN. For Namecheap customers, the domain should be familiar, after the first mail at least.

The subject line of those mails is: Important Notice Regarding Your Domain Name(s)

The new mails have a stronger subject line: IMMEDIATE VERIFICATION required for [domain]

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#22

This bit me kind of bad yesterday. I was about to drive out of cell range and got a text that client's site had some strange page displaying. Unfortunately, they repoint the dns servers of the domain, and the client had the contact email mx records associated with same domain. The actual site gets 'dns hikacked' by icann until you fill out a captcha on your site's new page and it emails the whois email account on rec…

How do they email you if your contact email is on the domain they just suspended? Time to set a TTL of 100 years, or something, I guess.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#23

This is apparently so the physical mail spammers can send me more physical mail along the lines of "This is the Domain Registry of America! Pay us $1000 to keep your domain!" Uh, no. Where's the FTC when I need it...

Is that what they say?

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#24
Okay why are we still using a centralized domain name system with authorities? Do we enjoy the crazy keyholders from various countries meeting in secret thing?

We can have many decentralized ways of registering and transferring domains. Namecoin is one, but how hard is it to decentralize the DNS database?

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#25
post #24

Okay why are we still using a centralized domain name system with authorities? Do we enjoy the crazy keyholders from various countries meeting in secret thing? We can have many decentralized ways of registering and transferring domains. Namecoin is one, but how hard is it to decentralize the DNS database?

> but how hard is it to decentralize the DNS database

Its an interesting question; how do you decide who to trust?

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#26
post #23

This is apparently so the physical mail spammers can send me more physical mail along the lines of "This is the Domain Registry of America! Pay us $1000 to keep your domain!" Uh, no. Where's the FTC when I need it...

Is that what they say?

Yes, I have gotten physical mail with exactly that pitch.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#27
post #23

Earlier quoted context omitted.

Is that what they say?

Yes, I have gotten physical mail with exactly that pitch.

Hopefully not since 2003 when the FTC had a court enjoin that specific company from making misleading statements about renewals in their postal mail.

The mails they send out now look like this:

"As a courtesy to domain name holders, we are sending you this notification of the domain name registration that is due to expire in the next few months. When you switch to Domain Registry of America, you can take advantage of our best savings. Your registration for _______ will expire on _____.

You must renew your domain to retain exclusive rights to it on the web, and now is the time to transfer and renew your domain from your current registrar to the Domain Registry of America.

...

This notice is not a bill. (bold) It is rather an easy means of payment should you decide to switch your domain name registration to Domain Registry of America."

Followed by the pricing table and write-in order form. Still junk mail, but not falsely representing themselves as your current registrar.

I get these mails all the time too, and unfortunately I actually have to pay one of them. Some 12 years ago or so, I helped a neighbor who runs a local charity by creating a website for her annual event, pro bono. Even though she paid for the domain, the billing contact info was changed to my address (perhaps by her, when someone asked for a technical contact), and transferred to DROA. I don't live in that area anymore or have contact with this neighbor, and I'd rather not track her down with a bill nor let the domain of her charity expire, so I've been dutifully paying the marked-up DROA renewal every year.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#28
How is this different from all the other online services that require you to click a link in an email in order to verify it, and refuse to give you full membership until you do so?

Some of the registrars I use have implemented this policy lately. Turns out it's a non-issue as long as your contact info is valid and up to date (which it should already be).

It doesn't conflict with whois privacy, either, contrary to all the FUD that gets spread around. Any whois privacy service that is worth the cost will forward the verification request to your real email address, and if it doesn't, you should switch to a better service. Using a crappy whois privacy service with no email forwarding is a surefire way to lose your domain anyway.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#29

This bit me kind of bad yesterday. I was about to drive out of cell range and got a text that client's site had some strange page displaying. Unfortunately, they repoint the dns servers of the domain, and the client had the contact email mx records associated with same domain. The actual site gets 'dns hikacked' by icann until you fill out a captcha on your site's new page and it emails the whois email account on rec…

How do they email you if your contact email is on the domain they just suspended? Time to set a TTL of 100 years, or something, I guess.

You should never use a contact email that is on the domain for the DNS record in question. Only bad things can result. I use my most basic fastmail.fm email for that purpose.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#30
post #24

Okay why are we still using a centralized domain name system with authorities? Do we enjoy the crazy keyholders from various countries meeting in secret thing? We can have many decentralized ways of registering and transferring domains. Namecoin is one, but how hard is it to decentralize the DNS database?

To honestly answer your question: the we you refer to isn't in control / power.

The system is centralized because the control over nations is centralized. It will remain that way so long as political power remains centralized. Particularly given the immense importance of the internet economy now to most major nations. The political powers that be are not about to let go of something so important. The domain name system is a huge point of control over national and global economics. If I were a standard issue politician, I'd make you pry it from my cold dead hands.

Post reply on HN