Live data from Hacker News

Never buy a .online domain

0xsid.com

301–310 of 513 posts

Re: Never buy a .online domain

#301

Earlier quoted context omitted.

These alternative domains are quite popular with the fediverse and other hobbyist-run groups. Affordable domains with somewhat recognisable names still available. Scam websites will use any TLD in my experience. Based on the ones that made it to my Google search results, .it and .info are the TLDs I should be blocking. When I search for "free roblox cash", most websites are .com. "Free robux" also brings forth a few…

My all time favorite Fediverse domain is jorts.horse. That’s the most delightfully random thing.

this looks exactly like every mastodon instance I ever saw.

Re: Never buy a .online domain

#302

Earlier quoted context omitted.

I logged in several times to other people's accounts and reset their passwords. But it's too tiring, people keep adding my email. I hope it's because I have small simple email and not because they want to steal it.

You’re confessing to several actual felonies here, may want to change strategies.

In what jurisdiction? He's in Russia

Re: Never buy a .online domain

#303

Are you 100 percent certain that the domain name wasn't registered before and then got on the blacklist because of prior misuse? It's quite possible that the domain you chose was registered previously and dropped because the previous owner misused it and burned that domain. The .ONLINE extension has been around for several years now.

I feel like google should be sophisticated enough to tell when a domain has expired and gone up for auction/resale?

Re: Never buy a .online domain

#304

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

> Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine.

I got hit by this from google.

1. Gmail added requirement for 2FA on my primary email address. Since I had no phone number on file, it instead used my recovery email address. Thankfully, I still had the password for my recovery email address, and could continue to (2).

2. Gmail added requirement for 2FA on my recovery email address. Since I had no phone number on file, it instead used by recovery's recovery email address. Thankfully, I still had the password for my recovery's recovery email address, and could continue to (3).

3. SBC Communications no longer exists, as it merged with AT&T in 2005. Email addresses at `sbcglobal.net` were maintained up until around 2021-ish, when they started purging any mailboxes that had been idle for more than 12 months.

Fundamentally, this was google's fault for misusing a recovery email for 2FA. Unfortunately, the only way to fix it would be to contact AT&T, asking them to pretty please update the email settings for somebody who hadn't been a paying customer for two decades.

Re: Never buy a .online domain

#305

Earlier quoted context omitted.

The problem isn't Google Safe Search backlisting the side (I mean that also is a problem, but a very different one). The problem is the vanity domain registrar Radix using that as a reason to _put the whole domain on hold, including all subdomains, email entries etc._ This means: - no way to fix accidental wrong "safe search" blacklisting - if it was your main domain no mails with all the things it entails - no way t…

At the same time given the already terrible reputation of such vanity TLDs, being this hard on abuse might be the only survivable way. That's not me saying there shouldn't be a warning and a recourse, but the time-to-profit for domain abuse is really short so anti-abuse actions have to be quick.

This isn't being hard on abuse though, this is being lazy and incompetent.

Re: Never buy a .online domain

#306
post #73

Earlier quoted context omitted.

If bartenders are legally (including criminally!) liable in some jurisdictions for their customers, then certainly a chain of legal liability can exist in other industries.

What are you envisioning exactly?

Am I supposed to envision something?

When pointing out that legal parallels exist, to enact a solution, must I envision that solution?

Re: Never buy a .online domain

#307

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

Oh man we had a person leave unexpectedly who controls our Apple organization for our dev accounts. I'm several months into me making requests, getting responses at least a week later for each email where the responder ... didn't really read my message. Then they ask for documents ... but they forgot to send me the secure link ... another week+ for them to do what they said they were going to do. Now one of my documents didn't include a sentence they needed ...

One of the requests was for a business card ... I haven't had a business card made with my name on it in 20 years.

The amazing thing is that I bet scammers working this system can get through this faster than I can.

At this point they should just give me control because no way would some scammer fail this much at this ungodly process.

Re: Never buy a .online domain

#308

Are you 100 percent certain that the domain name wasn't registered before and then got on the blacklist because of prior misuse? It's quite possible that the domain you chose was registered previously and dropped because the previous owner misused it and burned that domain. The .ONLINE extension has been around for several years now.

I can't be 100% sure but googling showed nothing. My site was up for almost 6 weeks with no issues. I used the domain for Apple's review process too. No issues at all.

Re: Never buy a .online domain

#309
post #293

Earlier quoted context omitted.

It does. "Unsafe" is not a fact, it's an opinion.

"When Google marks a site as "unsafe" or "dangerous" in Chrome or search results, it is a factual finding based on automated detection of specific, technical security threats, rather than a subjective opinion. These warnings are triggered by Google’s Safe Browsing technology, which scans billions of URLs daily to protect users from malicious content" Opinions and facts in a legal context usually comes down to who is…

Nope. Not correct. Companies have the same 1A rights, too.

In the US, it really doesn't matter who says it, the only thing that matters is who it's being said about.

If you are a "public figure" -- which is a much broader category in 1A law than you think -- then in order to prove defamation, you have to prove the thing was false _and_ that the person saying it knew it was false at the time. Not that they were mistaken, not that they were careless, not that they knew later, they deliberately lied and knew they lied as they said it.

If your next question is "how do you prove what someone was thinking", then yes. That is the reason it's nearly impossible.

Re: Never buy a .online domain

#310

Earlier quoted context omitted.

“…and so I made him the owner of my account, and he used that to remove himself from it!” “We’ll be right over.”

You forgot the part where he reset their email he didn't own and change their passwords so they couldn't get back into it

I think you’re misreading this. OP has an email account. Someone else signed up for some website that doesn’t verify that you own the address before allowing you to log in and use the service. If the site did verify it, the user wouldn’t have been able to log in because OP would have been getting the verification emails, and not the user.

Later, after OP told the user and they failed to change their address, OP logged into the site and changed their password, putting an end to the spam they were receiving from the user’s actions.

I don’t have an ethical qualm with this. He didn’t want to sign up for the service. Someone else signed his email address up for it. Legally, I can’t imagine that being prosecutable.

Post reply on HN