Live data from Hacker News

The Passport Payment (2000)

web.archive.org

21–30 of 55 posts

Re: The Passport Payment (2000)

#21
post #16

perhaps the most surprising to me is the apparent willingness to enter credit card info online in 1999. I wasn't around for this period but wasn't the conventional wisdom back then that this was insecure? hence PayPal?

The general wisdom was (as it still is) that you couldn't trust that anyone with a credit card form on their website would honor your trust. In this case the recipient wasn't just anyone with a credit card form on their website, but Network Solutions.

Re: The Passport Payment (2000)

#22
post #16

perhaps the most surprising to me is the apparent willingness to enter credit card info online in 1999. I wasn't around for this period but wasn't the conventional wisdom back then that this was insecure? hence PayPal?

Well we had https ("check for the lock icon") back then, you could pay for plenty of things with credit cards online. Of course there was some fear of it among the general public. PayPal by no means invented online payments they just popularised it.

Re: The Passport Payment (2000)

#24
post #9

Could you imagine doing this today? You'd probably get lawyers making you sign agreements saying your payment of the domain renewal is not a ownership interest in the domain and threatening to take you to court for renewing their domain.

I actually think it would be the opposite now. Things like bug bounties or a huge PR problem by the affected problem posting it on Twitter are new things. It was more prevalent to send lawyers for accessing public but not meant to be public URLs back in the days than it's now.

Re: The Passport Payment (2000)

#25
post #17

I'm confused, how did he pay for someone else's domain? Was there no authentication?

Back then, control was authenticated as necessary for the proper functioning, but even today I see no reason why renewal should have to be gated behind login walls. Actually, I'd even prefer it not to be, because you might, in a pinch, be prevented from paying for them yourself electronically, having to call in a favor and promise to pay back as soon as you see that friend. Or you just prefer to pay someone cash for…

yup, i use gandi for that reason. they support payment from anyone. it's especially convenient for volunteer community sites. we don't depend on the person who registered the domain and forgot to give access to others.

Re: The Passport Payment (2000)

#26
post #16

perhaps the most surprising to me is the apparent willingness to enter credit card info online in 1999. I wasn't around for this period but wasn't the conventional wisdom back then that this was insecure? hence PayPal?

I regularly made normal payments for normal products such as movies and nothing. It generally was considered safe.

Re: The Passport Payment (2000)

#27
post #8

Earlier quoted context omitted.

It used to be that nameserver changes with TLDs were measured in days, not minutes. Even today some TLDs continue to operate this way.

What are reasonable timeframe expectations for nameserver changes now?

That depends on the TTL of your DNS records. But if it’s a brand-new registration for a dot-com then I’ve found DNS queries work within 3 minutes of me completing GoDaddy’s regustration (and using GoDaddy’s DNS zone hosting) even through my ISP’s DNS servers (provided there’s no cached NXDOMAIN results).

Re: The Passport Payment (2000)

#28
post #3
post #2

According to the story, it took somewhere between 13 and 19 hours for passport.com to resolve properly after he renewed it for Microsoft. Is that normally how long it takes to reactivate a domain name that has gone into a renewal grace period, or was something different back then? Perhaps the NXDOMAIN response was cached by ISPs for an especially long time because it was such a frequently visited hostname?

NXDOMAIN is often cached for much longer because it's assumed not to change soon. Sometimes, as in this case, that's a wrong assumption.

I thought NXDOMAIN results were cached for as long as the TTL in the parent SOA record?

Re: The Passport Payment (2000)

#29
post #16

perhaps the most surprising to me is the apparent willingness to enter credit card info online in 1999. I wasn't around for this period but wasn't the conventional wisdom back then that this was insecure? hence PayPal?

In 1999 Amazon (for example) was already 5 years old and plenty of people were using credit cards online.

People who used mail orders before the internet might remember that the options included sending a cheque along with the order form or filling in your credit card details on the order form (that's a paper form that you send in the post), and I think that this is still the case. So I don't think that average people really saw sending card details online any differently. I even remember being asked for my card details by email!

Re: The Passport Payment (2000)

#30
post #3

Earlier quoted context omitted.

NXDOMAIN is often cached for much longer because it's assumed not to change soon. Sometimes, as in this case, that's a wrong assumption.

I thought NXDOMAIN results were cached for as long as the TTL in the parent SOA record?

For com. that's currently 24 hours!
Post reply on HN