Live data from Hacker News

Never buy a .online domain

0xsid.com

331–340 of 513 posts

Re: Never buy a .online domain

#331

Earlier quoted context omitted.

That sounds like a spurious distinction. Pretty sure you can’t say “Person X is a murderer” and then say “well I’m only expressing my opinion, and in my opinion if you do something that annoys me that qualifies as murder.”

Nope, not in the US. It is perfectly legal to say, for example, "Kyle Rittenhouse is a murderer" despite him being acquitted. You're entirely free to disagree with the result, that is an opinion. Any opinion based on public knowledge is ok. It doesn't even have to be reasonable or rational. What you can't do is imply non-public knowledge, aka "I heard from my cousin who works in law enforcement that Kyle murdered a h…

> It is perfectly legal to say, for example, "Kyle Rittenhouse is a murderer" despite him being acquitted.

That's ... not quite true. I wouldn't go that far.

Re: Never buy a .online domain

#332

Earlier quoted context omitted.

> Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. I got hit by this from google. 1. Gmail added requirement for 2FA on my primary email address. Since I had no phone number on file, it instead used my recovery email address. Thankfully, I still had the password for my recovery email address, and could continue to (2). 2. Gmail added requ…

> Fundamentally, this was google's fault Or yours, for not caring about 2FA. It's been a common practice for many years, and strongly recommended by most identity services, as well as OWASP and NIST recommendations. What would you do in Google's place?

Not add 2fa automatically, but instead prompt with options to add it.

This probably doesn't comply with the relevant recommendations, but cutting a user of from their email is worse in my opinion.

Re: Never buy a .online domain

#333
post #322

Earlier quoted context omitted.

Nope. Not correct. Companies have the same 1A rights, too. In the US, it really doesn't matter who says it, the only thing that matters is who it's being said about. If you are a "public figure" -- which is a much broader category in 1A law than you think -- then in order to prove defamation, you have to prove the thing was false _and_ that the person saying it knew it was false at the time. Not that they were mistak…

Not talking about 1A rights or public figures. We are talking about Opinions (Protected) vs Facts (Not Protected) Defamation cases where individuals say something are usually considered opinions and companies are usually considered facts in the eyes of the courts. I say "Usually" Defamation also DOES NOT require intent, but it requires a minimum level of fault (negligence) Google saying something is unsafe in the web…

> Google saying something is unsafe in the web search or browser would not be considered an opinion because of their position of authority.

Everything the Supreme Court rules is an "opinion." And they're the ultimate arbiter of legal questions in the U.S.

Whether a statement is a fact and whether the person who said it is considered an "authority" or not are independent concerns.

Re: Never buy a .online domain

#334

Earlier quoted context omitted.

My understanding from the article is that because the registrar for this domain is using Google safe browsing for their domain suspension, something that a) shouldn't be the case and b) isn't the case for other, perhaps more mainstream TLDs

Right. Sounds more like a registrar problem than a TLD problem. They should change the article title to "Never buy a domain from Radix"

Radix is the registry for .online, not the registrar they bought the domain from.

Re: Never buy a .online domain

#335

Earlier quoted context omitted.

> Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. I got hit by this from google. 1. Gmail added requirement for 2FA on my primary email address. Since I had no phone number on file, it instead used my recovery email address. Thankfully, I still had the password for my recovery email address, and could continue to (2). 2. Gmail added requ…

> Fundamentally, this was google's fault Or yours, for not caring about 2FA. It's been a common practice for many years, and strongly recommended by most identity services, as well as OWASP and NIST recommendations. What would you do in Google's place?

I have the same issue. At the time I created the account that I'm locked out of, Google said nothing about these "recovery" email addresses as 2FA. Years passed without any notice that maybe they were going to lock me out of an account I have the password for. No notice that I had better have access to that "recovery" email address that I hadn't bothered to keep up to date because I never thought I'd need to "recover" the account from Google. (In my case, it's an old .edu email address that I was promised "for life".)

If Google wanted to lock me out of my account for my own good until I enabled 2FA, fine. But as GP stated, they abused the recovery email addresses to force 2FA on people and ended up locking some people out of their accounts.

Re: Never buy a .online domain

#336

Earlier quoted context omitted.

> If the opinion is meant to be just another opinion, then it shouldn't cause any blacklisting of any sorts anywhere. I agree with this! The registrar should not have triggered a suspension because of this. They're not obligated to, and the two processes should be decoupled.

The registrar should ignore reports of abuse, especially if coming from an authoritative source with vast resources that's been collecting reports on its own? No. The source should be more careful. It's the equivalent of a renowned newspaper printing warning a restaurant being unsafe to visit. Should the customers' willingness to visit be magically decoupled from this opinion?

> The registrar should ignore reports of abuse, especially if coming from an authoritative source with vast resources that's been collecting reports on its own?

I'm not saying they should "ignore" reports of abuse but treat them as they are -- reports. They can then perform their own independent investigation.

That may well have happened here. I suspect the author isn't telling us something.

Re: Never buy a .online domain

#337
post #330

Earlier quoted context omitted.

It's not just about being common, it's also about the share of abuse coming from such domains.

Or just incompetence, I had to lobby to get .org unblocked for mail at some CS faculty of a (not my) university, 20 years ago.

Usually not, just look at for example SpamHaus's top abusive TLDs. New TLDs dominate.

Re: Never buy a .online domain

#338

Earlier quoted context omitted.

> If the opinion is meant to be just another opinion, then it shouldn't cause any blacklisting of any sorts anywhere. I agree with this! The registrar should not have triggered a suspension because of this. They're not obligated to, and the two processes should be decoupled.

The registrar should ignore reports of abuse, especially if coming from an authoritative source with vast resources that's been collecting reports on its own? No. The source should be more careful. It's the equivalent of a renowned newspaper printing warning a restaurant being unsafe to visit. Should the customers' willingness to visit be magically decoupled from this opinion?

[deleted]

Re: Never buy a .online domain

#339

Earlier quoted context omitted.

> Marking a website as “unsafe” is an opinion. No, it's not. You're welcome to cite case law if you want to insist. Otherwise, unsafe (in the context of infosec) has a definition of likely or able to cause harm or malfunction. Something that is provable or falsifiable with evidence.

Isn't "oops we made a mistake" actually a valid defense to libel in most US states? I thought you had to prove it was intentional to some extent? Or reckless/negligent IANAL

Negligence is an element of the tort of defamation.

Re: Never buy a .online domain

#340
post #293

Earlier quoted context omitted.

It does. "Unsafe" is not a fact, it's an opinion.

"When Google marks a site as "unsafe" or "dangerous" in Chrome or search results, it is a factual finding based on automated detection of specific, technical security threats, rather than a subjective opinion. These warnings are triggered by Google’s Safe Browsing technology, which scans billions of URLs daily to protect users from malicious content" Opinions and facts in a legal context usually comes down to who is…

> "When Google marks a site as "unsafe" or "dangerous" in Chrome or search results, it is a factual finding based on automated detection of specific, technical security threats, rather than a subjective opinion. These warnings are triggered by Google’s Safe Browsing technology, which scans billions of URLs daily to protect users from malicious content"

Whom are you quoting here? A court opinion?

Post reply on HN