Live data from Hacker News

Never buy a .online domain

0xsid.com

251–260 of 513 posts

Re: Never buy a .online domain

#251
It's not about the .online TLD being "weird". The problem is that it was free. That's going to attract a swarm of fraudsters, spammers, etc, and then turn into a strong "this is probably fraud" signal in all kinds of fraud scoring systems.

There are lots of domains out there other than .com that are just fine.

Re: Never buy a .online domain

#252

> The domain ... has been suspended due to its blacklisting on Google Safe Browsing Et voilà ... ! this is precisely the slippery slope I warned about a decade ago. The indirect censorship becomes direct censorship, defeating all the arguments about the morality of such a list. And: > Not adding the domain to Google Search Console immediately. I don't need their analytics and wasn't really planning on having any cont…

That's like a business being dissolved because it got a bad rating from BBB. Absolutely insane.

Re: Never buy a .online domain

#253
post #61

Earlier quoted context omitted.

But if Google decides to nuke me from orbit, and my domain is registered there, the nuke can cross between my domain and my Google account.

Well, yeah, that's digital monopolies for you. I guess one can always create a dedicated google account to register each site with

It doesn't work, there was a Google employee here mentioning they assign a degree of separation to each account, any accounts that are deemed "close", are included when the ban hammer falls.

Re: Never buy a .online domain

#254
post #60
post #11

The TLD owner in this case was Radix, which also owns .store .online .tech .site .fun .pw .host .press .space .uno .website https://radix.website/

They seem to be almost always associated with scam sites. So, might as well to block entire TLDs and never buy a domain under those TLDs

funnily enough, good.store which sounds like a made up example of a scam is actually a nonprofit ran by john green and his brother hank green

Re: Never buy a .online domain

#255

But was this because it's .online? I got one and it was fine. The only issue was the usual trap with all Namecheap domains: They tell you it's all set, and it works, until they randomly email you a week later asking for email verification. If you don't do that promptly, they suspend your domain until you trigger a resend. Which is easy to fix but also strange.

The blog post details that the TLD registry, Radix, decided that getting put on Google's safe browsing list means they put a serverhold on your domain, which prevents you from getting off the safe browsing list.

So yes, this appears to be a TLD- (or at least registry-) specific issue.

Re: Never buy a .online domain

#256

Side note: My empirical experience is that vanity domains are disliked by some enterprise security systems. I have a friend who owns a .homes domain which ended up being blocked by quad9 as well as the enterprise security system of a friend's work for ~half a year. The block cleared by itself. I had the same experience while buying another TLD. For ~1 month, certain people whose ISP "helpfully" had "safe browsing" fe…

Fortinet blocks new domains by default so I can never check out cool new projects on the front page when I'm procrastinating nowadays :(

Re: Never buy a .online domain

#257
post #6

Are there any other TLDs that are of this ilk or are we saying nothing but .com will ever do? Or .org, perhaps?

It's not exactly the same, but a lot of owners of weird TLDs have got hit with insane renewal fees,.hosting went from $20/y to $300/y overnight. Also, some TLDs directly speculate on having very low prices for the first year or two, then 10x it on year 2 or 3.

Buy all 10 years you can when you get the domain. Renew yearly. When they pull silliness like this you have at least 9 years to migrate.

Re: Never buy a .online domain

#258

Earlier quoted context omitted.

Have you tried sending them emails asking/telling them to stop?

I’m a different person, but this happens to me, too. I have the kstrauser@yahoo.com email address because I signed up for it like 25 years ago. I log in every 6 months to see what the few other kstrausers in the world have signed me up for. Not jsmith, but kstrauser. Not Gmail, but Yahoo. And I still get banking docs, and HOA meeting minutes, and birthday party invitations, and Facebook logins, and other bizarre rand…

I had one that person seemed to think their @twitter name was the same thing as my gmail address. Haven't seen it in a while, maybe they figured it out after I told their kid's teacher they had the wrong person...

Re: Never buy a .online domain

#259

Earlier quoted context omitted.

How is any kind of antivirus or threat detection software supposed to operate on this standard? Libel suits can be financially catastrophic, so even a tiny false positive rate could present risk that disincentivizes producing such software at all. And a threat detection mechanism that has a 0.0% false positive rate is conservative to the point of being nearly useless.

You document your claims with concrete evidence of fraud. That will be your libel defense. No evidence means you bear the full responsibility of a fuckup.

At internet scale, this would roughly be equivalent to not doing any warning or detection at all.

Scalable systems need to use heuristics to catch threats. Needing concrete evidence in every case means that an enormously higher amount of malicious resources will not be flagged.

There is a policy argument as to the right balance of concerns here. But there is a clear trade-off to make.

Re: Never buy a .online domain

#260
It sucks so much that there is no standard way of linking additional domains to your main one and inheriting the reputation.

Want to set up a new domain for whatever purposes (conference, new product, etc)? Be prepared to spend the first half a year fighting the various blacklists before people can actually reliably connect.

Would make so much sense if you could just have a .well-known/other-domains.txt (or something something DNS) with a list of domain names that should be considered just as trustworthy as your main domain.

It's not even about .online or other weird TLDs, it's just that the domain is new and therefore "not trustworthy". Even worse if you need to use your existing branding on the new domain - instantly flagged as a phishing site everywhere.

Post reply on HN