Live data from Hacker News

Never buy a .online domain

0xsid.com

321–330 of 513 posts

Re: Never buy a .online domain

#321
post #11

The TLD owner in this case was Radix, which also owns .store .online .tech .site .fun .pw .host .press .space .uno .website https://radix.website/

Well, dang. I've used a .tech as my personal domain and email for some years now, and didn't know this was owned by an obnoxious registry.

Re: Never buy a .online domain

#322
post #293

Earlier quoted context omitted.

"When Google marks a site as "unsafe" or "dangerous" in Chrome or search results, it is a factual finding based on automated detection of specific, technical security threats, rather than a subjective opinion. These warnings are triggered by Google’s Safe Browsing technology, which scans billions of URLs daily to protect users from malicious content" Opinions and facts in a legal context usually comes down to who is…

Nope. Not correct. Companies have the same 1A rights, too. In the US, it really doesn't matter who says it, the only thing that matters is who it's being said about. If you are a "public figure" -- which is a much broader category in 1A law than you think -- then in order to prove defamation, you have to prove the thing was false _and_ that the person saying it knew it was false at the time. Not that they were mistak…

Not talking about 1A rights or public figures. We are talking about

Opinions (Protected) vs Facts (Not Protected)

Defamation cases where individuals say something are usually considered opinions and companies are usually considered facts in the eyes of the courts. I say "Usually"

Defamation also DOES NOT require intent, but it requires a minimum level of fault (negligence)

Google saying something is unsafe in the web search or browser would not be considered an opinion because of their position of authority. It would not even be a debate since Google has already said they make decisions based on facts and data presented to them.

The only question is are they negligent in their assessment or response to a false report. And what would be the damages. In the case of a phishing report that is false courts would already consider it defamation per se (damages presumed)

Re: Never buy a .online domain

#323

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

> Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. I got hit by this from google. 1. Gmail added requirement for 2FA on my primary email address. Since I had no phone number on file, it instead used my recovery email address. Thankfully, I still had the password for my recovery email address, and could continue to (2). 2. Gmail added requ…

> Fundamentally, this was google's fault

Or yours, for not caring about 2FA. It's been a common practice for many years, and strongly recommended by most identity services, as well as OWASP and NIST recommendations.

What would you do in Google's place?

Re: Never buy a .online domain

#324

Earlier quoted context omitted.

You forgot the part where he reset their email he didn't own and change their passwords so they couldn't get back into it

I think you’re misreading this. OP has an email account. Someone else signed up for some website that doesn’t verify that you own the address before allowing you to log in and use the service. If the site did verify it, the user wouldn’t have been able to log in because OP would have been getting the verification emails, and not the user. Later, after OP told the user and they failed to change their address, OP logge…

One thing I've found, occasionally the hard way, is that helpful bystanders are always offering advice based on "ethical", "intuitive", "logical" and "common sense", usually without any aspect of "legal".

I got divorced a decade ago, and every well-wishing person in my life was strongly urging me to do things which were shockingly counter-productive / dangerous / wrong, based on their confident understanding (assumption, really) of the law which was completely and dangerously inaccurate.

Hacker News audience is global. People start accounts for various purposes. Yet people still freely share the notion that logging in to some unknown website run by an unknown company from a hard to spell country and then touching things is universally safe.

I miss the old "IANAL" tag which at least provided basic warning and self-awareness :-).

Re: Never buy a .online domain

#325
The first mistake anyone makes is thinking they are “buying” anything with a domain. You’re renting it. And the company you are renting from can arbitrarily push up the price above inflation. NameCheap is good for the basics. But a .site or .online domain is a no-go beyond an MVP/test.

Re: Never buy a .online domain

#326

Earlier quoted context omitted.

At the same time given the already terrible reputation of such vanity TLDs, being this hard on abuse might be the only survivable way. That's not me saying there shouldn't be a warning and a recourse, but the time-to-profit for domain abuse is really short so anti-abuse actions have to be quick.

This isn't being hard on abuse though, this is being lazy and incompetent.

I'm fairly sure that Safe Browsing's false-positive rate is extremely low otherwise it'd be unusable in Chrome. Which also means that acting on positive results is very likely a correct approach.

Re: Never buy a .online domain

#327

Side note: My empirical experience is that vanity domains are disliked by some enterprise security systems. I have a friend who owns a .homes domain which ended up being blocked by quad9 as well as the enterprise security system of a friend's work for ~half a year. The block cleared by itself. I had the same experience while buying another TLD. For ~1 month, certain people whose ISP "helpfully" had "safe browsing" fe…

This does unfortunately actually work pretty well as a security measure. The new domains that are cheap and good for fun side projects, are also cheap for scammers.

For a while I noticed all the scam links my grandmother was getting were from ‘.top’ domains. I fully blocked it at the DNS level. Her DNS settings also block all newly registered sites for 90 days. She hasn’t ever had issues with it. But these have actively prevented her from clicking on scam links multiple times.

Facebook, google, and all the popular sites are all older than 90 days, on popular well known TLDs. My grandmother doesn’t seek out new trendy sites.

It was definitely something I considered when buying a new domain. I sorted by price, and then immediately ignored all the cheapest domains that were ~$1 because I’ve seen them being used for scams. They may be cheap but good luck using them.

Re: Never buy a .online domain

#328
post #245

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

Ah the old "reverse identity theft". Relevant xkcd: https://xkcd.com/1279/ Yeah, I get the same regularly.

Smartly, I got firstnamemiddleinitiallastname@gmail.com. I never get anybody else' details.

On the other hand... Occasionally someone gets my info because some careless person entered my email address into their system incorrectly. You'd think this problem would be solved by moving to a custom domain, but I still once in a while find someone completely ignore what I put into the form and sign me up as firstnamelastname@gmail.com.

Re: Never buy a .online domain

#329

Earlier quoted context omitted.

I think you’re misreading this. OP has an email account. Someone else signed up for some website that doesn’t verify that you own the address before allowing you to log in and use the service. If the site did verify it, the user wouldn’t have been able to log in because OP would have been getting the verification emails, and not the user. Later, after OP told the user and they failed to change their address, OP logge…

One thing I've found, occasionally the hard way, is that helpful bystanders are always offering advice based on "ethical", "intuitive", "logical" and "common sense", usually without any aspect of "legal". I got divorced a decade ago, and every well-wishing person in my life was strongly urging me to do things which were shockingly counter-productive / dangerous / wrong, based on their confident understanding (assumpt…

IANYL, though! Offering legal advice with the disclaimer “I am not a lawyer” could be prosecuted as practicing law if a reasonably party could still infer a potential lawyer-client relationship from your message and/or intent. Instead, “I am not your lawyer” explicitly denies the lawyer-client relationship, which closes the door on both being accused of practicing law illegally and on being found as party to a lawyer-client relationship whether or not you have the appropriate certifications.

Re: Never buy a .online domain

#330

Earlier quoted context omitted.

Even (uncommon) country TLD's too. I own a .vg domain which is a perfect match with the initials of my last name. My mails end up in spam quite often too, despite having set up SPF, DKIM, DMARC and all that stuff correctly. It's just not common so some security systems block it.

It's not just about being common, it's also about the share of abuse coming from such domains.

Or just incompetence, I had to lobby to get .org unblocked for mail at some CS faculty of a (not my) university, 20 years ago.
Post reply on HN