Live data from Hacker News

Never buy a .online domain

0xsid.com

211–220 of 513 posts

Re: Never buy a .online domain

#211
post #180

Earlier quoted context omitted.

Cute. That is the commenter’s whole point about monopolies. Google is on record making their product worse to squeeze revenue. We’ve been living in the enshitification economy.

There is a financial incentive to make the search results worse. (More searches, more ads, more money.) There is no incentive for adding false positives to lists of malicious websites.

Sure, until their "smart filters" start considering GCP-hosted websites as pre-verified and small self-hosted websites as malicious. You know, like they have been doing with email?

Chrome is big enough that a website owner can't afford a false positive on their malware list, just like they can't afford to have all their email end up in spam for all Gmail users.

Due to their near-monopoly Google also has no incentive to avoid adding false positives to their blocklist - provided they don't accidentally block high-profile targets. And if a CxO is screaming over your shoulder that your website has been blocked, arguments about "false positives" aren't very compelling: they'll just demand you move off the "shitty basement provider" and switch to "proper hosting, like the Google Cloud"...

Re: Never buy a .online domain

#212

Earlier quoted context omitted.

Google should not be allowed to make libelous statements without consequences.

How is any kind of antivirus or threat detection software supposed to operate on this standard? Libel suits can be financially catastrophic, so even a tiny false positive rate could present risk that disincentivizes producing such software at all. And a threat detection mechanism that has a 0.0% false positive rate is conservative to the point of being nearly useless.

I think that is the idea. They shouldn't exist without a prompt mitigation path.

In other words, if you can't deal with the false positives in a timely manner. You SHOULD be liable for the damages.

I can't build a budget car put together in an unsafe manner. Then complain I can't compete due to all the peoples cars crashing and blowing up and suing me.

Re: Never buy a .online domain

#213
post #60

Earlier quoted context omitted.

They seem to be almost always associated with scam sites. So, might as well to block entire TLDs and never buy a domain under those TLDs

Because they are very cheap. If you are a scammer, why pay $5 for a domain when you can buy one of these for $1. I use them when I need a random domain.

> Because they are very cheap.

When I first bought an .online, it was not cheap

Re: Never buy a .online domain

#214

Side note: My empirical experience is that vanity domains are disliked by some enterprise security systems. I have a friend who owns a .homes domain which ended up being blocked by quad9 as well as the enterprise security system of a friend's work for ~half a year. The block cleared by itself. I had the same experience while buying another TLD. For ~1 month, certain people whose ISP "helpfully" had "safe browsing" fe…

Because the entire security mechanism of the www today is "look at the domain name to make sure it matches." And the TLD is at the end where people might miss it.

[deleted]

Re: Never buy a .online domain

#215

Earlier quoted context omitted.

I logged in several times to other people's accounts and reset their passwords. But it's too tiring, people keep adding my email. I hope it's because I have small simple email and not because they want to steal it.

Have you tried sending them emails asking/telling them to stop?

That may be what they're hoping for, using a similar modus operandi as those WhatsApp/IM messages from strangers who text you with things in the vein of ‘Hey, it was great meeting you at the conference’ or ‘Did Martha like your flowers?’ etc.

They may well be looking for targets.

Re: Never buy a .online domain

#216

Never use a “free” domain is a better rule. Even if there were no technical or administrative issues, nobody trusts them.

I could also buy that the free domains were ran up by scammers which could have caused some of the hair trigger Safe Browsing denylisting.

Re: Never buy a .online domain

#217
post #198

The logic doesn't automatically extend to other TLDs unless they too are owned by the same firm. Alternative TLDs are often preferable because they're so much cheaper than wasting money on a .com, etc.

Most alternative tlds are more expensive than .com after first year teaser rates expire though

There are various gTLD that are cheaper. For example, .top is great and among the cheapest. It however is falsely maligned by those with small brains who stereotype things.

Re: Never buy a .online domain

#218

> The domain ... has been suspended due to its blacklisting on Google Safe Browsing Et voilà ... ! this is precisely the slippery slope I warned about a decade ago. The indirect censorship becomes direct censorship, defeating all the arguments about the morality of such a list. And: > Not adding the domain to Google Search Console immediately. I don't need their analytics and wasn't really planning on having any cont…

Where did you do the warning?

Re: Never buy a .online domain

#219

tried to roll my own email server on a .xyz domain...basically a big no go, couple of emails went through, then nothing, just a black hole. Thanks corpos and the safety theatre.

Call me a luddite but if it isn't one of the original big TLDs, a country TLD, or similar, I just don't trust it for anything serious.

I believe that .de domains are pretty cool (written another comment about it) but .de are $3.25 for registration and .de is the second most common after .com so from webatla, I see approx 16 million domains.

I don't think that they could ban emails from .de for what its worth.

Personally I like .in domains too. Makes more sense to me because I am well Indian and we all use it quite frequently/sort of intutitively know fwiw but if I just want a domain for email purposes for cheap. Honestly, .de could be good.

https://tld-list.com/ [Try seeing the cheapest renewal rate with top level TLD and ignore .storage which costs 465$ for registration smh]

Some other domains like .top exist as well in this league imo but .de is one of the best if you can find a relevant domain in .de

Re: Never buy a .online domain

#220

Earlier quoted context omitted.

(IAAL but this is not legal advice.) It’s not libel. Defamation requires a false statement of fact . Marking a website as “unsafe” is an opinion .

> Marking a website as “unsafe” is an opinion. No, it's not. You're welcome to cite case law if you want to insist. Otherwise, unsafe (in the context of infosec) has a definition of likely or able to cause harm or malfunction. Something that is provable or falsifiable with evidence.

Isn't "oops we made a mistake" actually a valid defense to libel in most US states? I thought you had to prove it was intentional to some extent? Or reckless/negligent IANAL
Post reply on HN