Live data from Hacker News

The Perils of an .xyz Domain

spotvirtual.com

151–160 of 282 posts

Re: The Perils of an .xyz Domain

#151
post #119

Just get the dotcom. [0,1] [0] http://www.paulgraham.com/name.html [1] https://zlipa.com

Gee, I wonder who made zlipa?

> Bootstrapped with > Our goal is to help makers find an awesome home for their project and not to help you flip. We reserve the right to refuse, or cancel membership to anyone without explanation.

Nice, so only you're allowed to flip your parked domains.

Re: The Perils of an .xyz Domain

#152
post #11

These are also good reasons to avoid using .so domains. You can also expect mail delivery issues and blanket corporate firewall blocks on .so. The rising prominence of https://notion.so is changing the cultural situation somewhat, but very slowly. (Edit: I work at Notion)

A potential issue with ccTLDs in general is they aren't subject to ICANN policies at all. Countries can do whatever they want with their TLD, ICANN's only involvement is keeping their root zone entries up to date.

This means you're subject to the politics of whatever country's TLD you're using. If the country's lawmakers suddenly decide that their TLD should only be for use by local entities, or that owners of popular domains should pay more, or that certain types of content is banned, you have no recourse.

(Not that ICANN policies always help you. Some of the new TLDs have contracts with ICANN that allow them to arbitrarily jack up prices, which they've done: https://domainnamewire.com/2017/03/07/yikes-death-spiral-new...)

Re: The Perils of an .xyz Domain

#153
post #144

Earlier quoted context omitted.

I wish the Telco's did MORE filtering given the huge amount of SMS spam I get since Twilio has turned this channel into a positive ROI for spammers. (1st biggest spam channel being email, which surprise/surprise - Twilio also dominates via SendGrid)

I have no knowledge of the ROI involved here, but would love to understand this: Twilio is 0.75c to send a text. Is it possible for a spammer to generate >$75 per 10,000 people spammed? I've no idea were the SMS spams I've got link to (not about to find out) but they are so obviously spam. We use SMS for communicating with users and would be happy to more a lot more per text to escape the 'positive ROI for spammers'…

Probably decent ROI which is why it keeps on happening!

They just need one person in each 10k spammed on average, to click the phishing url asking them to pay a fake bill and then charge them $328 instead of the $3.28 displayed o the page.

I received (and reported to their scam Dept) a phishing SMS yesterday pretending to be from Australia Post asking for $3.28 to release a delivery package I'm waiting for, which is most people in Australia nowadays with the current slowdown in mail delivery speed.

I am only guessing that the $3.28 phishing purchase would have attempted a $328 charge on my card... but that would be wildly profitable if the input costs per successful fraud were under $100...

Re: The Perils of an .xyz Domain

#154

Earlier quoted context omitted.

So put it in a spam folder. If I had a spam texts folder that showed me everything I was being blocked from, I'd both appreciate it and not feel this massive breach of trust that things being sent to me are being completely ignored by a third party system. The system that does this is absolutely primed for censorship, and we have no way to know it's not being used.

> So put it in a spam folder. 1) Neither the SMS protocol nor any phone I've ever seen has any mechanism to file messages in "folders". 2) Processing SMS messages and delivering them to subscribers has a cost. Doing so for high-volume junk messages would place a significant burden on carriers. 3) Most carriers used to charge subscribers for receiving SMS messages. Some still do! Charging subscribers to receive spam S…

Then put it behind a config setting.

Or let me view it through some other means.

I'm not opposed to spam filtration as a user default, but doing so silently without any indication of what is being filtered or ability to verify it is working is not acceptable for such a vital messaging system.

Re: The Perils of an .xyz Domain

#155
post #46
post #9

What about .app domains?

The .app TLD is owned by Google, requires HTTPS, and I haven't run into any issues in practice. Whereas my corporate VPN blocks all .xyz domains.

> requires HTTPS

I've always felt conflicted about this. I generally support moving everything to HTTPS, and requiring it for new TLDs isn't a terrible idea because there's no chance of breaking anything legacy.[1]

On the other hand, Google owns the TLD, controls the HSTS preload list, controls the most popular browser. The idea that an entire TLD could be added to the HSTS preload list was a completely unilateral decision by Google. It makes me uneasy.

[1] ...unless you were using the domain internally assuming it would never be added to the root zone, which bit some people when they did this with .dev

Re: The Perils of an .xyz Domain

#156

Earlier quoted context omitted.

Email providers absolutely block email, its the edge cases that make your spam folder.

> its the edge cases that make your spam folder. Well, from their perspective. Not from any reasonable perspective; I have a few obviously-spam emails in my gmail spam folder right now, but I've had plenty of problems with gmail refusing to deliver completely legitimate email to me.

If there was no filtering how many spammessages would you receive?

I suspect any more than you see

Re: The Perils of an .xyz Domain

#158
Whoa. I use an xyz domain daily. This thread is eye-opening. Here's the reply from a SpamAssassin validator.

My domain is almost marked as spam solely on TLD grounds. What's the point of a TLD if it isn't a first-party domain on the internet?

  SpamAssassin Score: -0.599
  Message is NOT marked as spam
  Points breakdown: 
  -5.0 RCVD_IN_DNSWL_HI       RBL: Sender listed at https://www.dnswl.org/,
                              high trust
                              [***.***.***.*** listed in list.dnswl.org]
   0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was
                              blocked.  See
                              http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                               for more information.
                              [URIs: ***.xyz]
  -0.0 RCVD_IN_MSPIKE_H2      RBL: Average reputation (+2)
                              [***.***.***.*** listed in wl.mailspike.net]
   0.0 SPF_HELO_NONE          SPF: HELO does not publish an SPF Record
   2.0 PDS_OTHER_BAD_TLD      Untrustworthy TLDs
                              [URI: ***.xyz (xyz)]
   0.0 HTML_MESSAGE           BODY: HTML included in message
   0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily
                              valid
  -0.1 DKIM_VALID_AU          Message has a valid DKIM or DK signature from
                              author's domain
  -0.1 DKIM_VALID             Message has at least one valid DKIM or DK signature
   2.0 FROM_SUSPICIOUS_NTLD_FP From abused NTLD
   0.5 FROM_SUSPICIOUS_NTLD   From abused NTLD
   0.0 TVD_SPACE_RATIO        No description available.

Re: The Perils of an .xyz Domain

#159
post #27

I was pretty excited when ICANN opened up a bunch of new domain extensions, but it does sometimes feel like "all these extensions are great if you don't plan on using them". It was pretty cool that I managed to buy a bunch of domains like . , but to be honest I really don't see myself using my .blackfriday domain for anything. For that matter, I think that (somewhat ironically) `my-last-name.email` would not be taken…

crypto space is making use of the new ICANN approved TLDs pretty rapidly

their customers are on discord, twitter, telegram and wechat so email delivery is not a factor

the entire sites and revenue drivers are entirely client side (with the "servers" being the smart contract methods stored on the nearest blockchain nodes, this has only one initial upload cost but functions similarly to lambda functions except the users pay for the computations), when the domain is down or blocked, the user can interact directly with the nearest node hosting the website's associated smart contracts, if they are interested enough

this is working really well for a lot of organizations, and it has been this way for several years now

makes lean SaaS services even leaner, and allows them to grow even faster - as long as their customer base is already a crypto native. I haven't seen any organization succeed if they have to sell their customer on some crypto browser extension.

Re: The Perils of an .xyz Domain

#160

Earlier quoted context omitted.

Disable auto-image loading, and it will cut down the ability for companies to do this. Unfortunately, this often times leads to direct phone calls along the lines of, "Hey taftster, did you get my email? It shows that you haven't opened it yet." This side-effect is also very annoying.

Who gives companies their personal phone number?

I get unenrolled from electronic statements from Capital One and a local credit union if I go 12 months without “opening” an e-mail from them. I do open and read their e-mails but since I don’t have image loading enabled, they don’t know that so they “helpfully” start sending me paper bills again, and stop sending me the e-mails to say that the bills are ready. It’s incredibly annoying.
Post reply on HN