Live data from Hacker News

Never buy a .online domain

0xsid.com

371–380 of 513 posts

Re: Never buy a .online domain

#371
post #322

Earlier quoted context omitted.

Nope. Not correct. Companies have the same 1A rights, too. In the US, it really doesn't matter who says it, the only thing that matters is who it's being said about. If you are a "public figure" -- which is a much broader category in 1A law than you think -- then in order to prove defamation, you have to prove the thing was false _and_ that the person saying it knew it was false at the time. Not that they were mistak…

Not talking about 1A rights or public figures. We are talking about Opinions (Protected) vs Facts (Not Protected) Defamation cases where individuals say something are usually considered opinions and companies are usually considered facts in the eyes of the courts. I say "Usually" Defamation also DOES NOT require intent, but it requires a minimum level of fault (negligence) Google saying something is unsafe in the web…

We are absolutely talking about the 1A lol. Defamation is 1A law. It is one of the few recognized exceptions to the 1A.

And we are also 100% talking about public figures. "Public figures" include companies and it's a critical part of 1A since Times v Sullivan.

Google is a US company and has 1A rights. That's how it works. The rest of what you said is nonsense and is your idea of how it should work, but has nothing to do with how it actually works.

Re: Never buy a .online domain

#372

Earlier quoted context omitted.

IAN Y L, though! Offering legal advice with the disclaimer “I am not a lawyer” could be prosecuted as practicing law if a reasonably party could still infer a potential lawyer-client relationship from your message and/or intent. Instead, “I am not your lawyer” explicitly denies the lawyer-client relationship, which closes the door on both being accused of practicing law illegally and on being found as party to a lawy…

> closes the door on [...] being accused of practicing law illegally Does it? So I can say, "I'm not your lawyer, but I'm happy to go ahead and give you specific legal advice on your case." and I can't be accused of illegally practicing law? I was under the impression that this could still get you into hot water. But not being your lawyer, due to the fact that I am not a lawyer at all, I don't know if it is true or n…

IANAL, so take this with a grain of salt, but:

As with all things, who are you going to get in trouble with? And what's so magical about legal practice as opposed to, say, giving shitty medical advice or telling someone how to build porch? Asking genuinely. No one falls all over themselves to say "I am not a doctor, but...", even though their next words could kill someone. The implication is that they don't have formal training but they saw something on Facebook that you should try. What happens next is on you, not on them.

Re: Never buy a .online domain

#373

Earlier quoted context omitted.

> Fundamentally, this was google's fault Or yours, for not caring about 2FA. It's been a common practice for many years, and strongly recommended by most identity services, as well as OWASP and NIST recommendations. What would you do in Google's place?

Not force nonconsensual authentication methods onto users. Google is one of the rare places I actually see positive value to 2FA. Compare with say banks, where it being demanded actually decreases my security. But regardless, it should not be forced.

As for the banks I doubt it decreases security. Even SMS 2FA actually reduces fraud by 90%+ percent.

Yes, some banks implement it silly, like SVB requiring biometric login in order to scan one-time QR 2FA code from their app (biometric login is less secure), but you don't have to use the QR code, can use regular 2FA without biometrics.

But even then having 2FA is 42 times better than not having it.

Re: Never buy a .online domain

#374

Earlier quoted context omitted.

Not add 2fa automatically, but instead prompt with options to add it. This probably doesn't comply with the relevant recommendations, but cutting a user of from their email is worse in my opinion.

I'm sure Google prompted author for years begging to turn the 2FA on, as well as warning that they will enforce it on day X. Author ignored them all.

That doesn't make forcing it any less wrong.

Re: Never buy a .online domain

#375

Earlier quoted context omitted.

Nope, not in the US. It is perfectly legal to say, for example, "Kyle Rittenhouse is a murderer" despite him being acquitted. You're entirely free to disagree with the result, that is an opinion. Any opinion based on public knowledge is ok. It doesn't even have to be reasonable or rational. What you can't do is imply non-public knowledge, aka "I heard from my cousin who works in law enforcement that Kyle murdered a h…

> It is perfectly legal to say, for example, "Kyle Rittenhouse is a murderer" despite him being acquitted. That's ... not quite true. I wouldn't go that far.

Sure it is, that's how the 1A works. Saying he was convicted of murder is not true, but calling him a murderer is an opinion. Your opinion doesn't even have to be reasonable. It just has to be based on facts that both you and I have.

1A rights are construed really broadly. The courts don't do the 'he wasn't legally convicted therefore it's illegal to call him one' thing.

Re: Never buy a .online domain

#377

Earlier quoted context omitted.

Self censorship requires a threat or risk of detriment if the party doesn't self censor, right? Where is that here? What Radix does has no impact on Google, and I don't see how Google would be incentivized to pressure Radix. So I don't see how to make the leap blaming Google for Radix's incompetence. Yes, Google should recognize the risk of this happening, but they'd have to balance that against the rewards (or at le…

Google is making false statements about the safety of a domain and it has significant collateral damage. Google is the cause. They should be liable for losses. I had my main family domain put on Google's safe browsing block list and it has a massive impact. No one can visit the site. I think apps using system browser runtimes (ie: mobile) may stop working. I've seen reports that it can impact email deliver-ability. A…

That's fair, if your domain is erroneously put on the block list, Google should be liable for the consequences.

But my point is that any knock on effects like domain suspension, email deliver-ability, etc. stem from 3rd parties misusing the safe browsing list outside the scope of safe browsing.

I don't see how Google can be blamed for other companies erroneously treating the safe browsing list as a source of truth for generally malicious domains

Re: Never buy a .online domain

#378

Earlier quoted context omitted.

nonsense. any feature should have acceptable failure modes. blaming the customer for a fault they have no control over is not acceptable. many people know nothing about 2FA. it is not their responsibility. 2FA is a symptom of shitty designed systems which are inherently insecure and companies who dont give a shit about that and let their customers shoulder the burden by shoving complexity down their throats. if you m…

> many people know nothing about 2FA That's why Google sent them multiple emails explaining what it is and recommending to turn it on. What else could Google do?

Not just turn it on without their approval.

Re: Never buy a .online domain

#379

.com is definitely the gold standard, I got an .io more than a decade ago and if I would go back in time, I would just use .com, the pricing for .io been increasing for no apparent reason.

People often make the mistake of treating .io like a gTLD, when it's actually a ccTLD for the "British Indian Ocean Territory" etc. ccTLDs have always had risks, especially when they are for a really tiny region.

Similar issues to .io happened with the popularity of .tv domains, which again is a ccTLD. The government of Tuvalu sought to increase income from sales of their ccTLD and prices went up. Tuvalu is such a small nation .tv domain sales ended up making a significant part of the State's income.

Another fun example of the mess you can get into with ccTLDs was when the UK left the EU. All UK registered .eu domain names were cancelled following the UK exit from the bloc.

gTLDs generally have some degree of insulation from State-level politics. ccTLDs permit the nation or territory they represent much more say in how they are priced and who they are sold to.

Re: Never buy a .online domain

#380
post #60
post #11

The TLD owner in this case was Radix, which also owns .store .online .tech .site .fun .pw .host .press .space .uno .website https://radix.website/

They seem to be almost always associated with scam sites. So, might as well to block entire TLDs and never buy a domain under those TLDs

That's just because they're relatively inexpensive
Post reply on HN