Live data from Hacker News

Never buy a .online domain

0xsid.com

391–400 of 513 posts

Re: Never buy a .online domain

#391

Earlier quoted context omitted.

Google is making false statements about the safety of a domain and it has significant collateral damage. Google is the cause. They should be liable for losses. I had my main family domain put on Google's safe browsing block list and it has a massive impact. No one can visit the site. I think apps using system browser runtimes (ie: mobile) may stop working. I've seen reports that it can impact email deliver-ability. A…

That's fair, if your domain is erroneously put on the block list, Google should be liable for the consequences. But my point is that any knock on effects like domain suspension, email deliver-ability, etc. stem from 3rd parties misusing the safe browsing list outside the scope of safe browsing . I don't see how Google can be blamed for other companies erroneously treating the safe browsing list as a source of truth f…

A lot of laws use the phrase "known, or should have known"

Google should not have known that someone would misuse their block list to block domains. But now that someone is misusing their block list to block domains, if someone brings it to their attention, the next time this happens, they will have known it.

I am not a lawyer, I am not your lawyer, and this is not legal advice.

Re: Never buy a .online domain

#392

Earlier quoted context omitted.

You document your claims with concrete evidence of fraud. That will be your libel defense. No evidence means you bear the full responsibility of a fuckup.

At internet scale, this would roughly be equivalent to not doing any warning or detection at all. Scalable systems need to use heuristics to catch threats. Needing concrete evidence in every case means that an enormously higher amount of malicious resources will not be flagged. There is a policy argument as to the right balance of concerns here. But there is a clear trade-off to make.

Then that heuristic is your evidence in court. If it's a good heuristic, you win the case. If it's a bad heuristic, you lose the case.

"Your Honor, we banned this person's website because his web page contained the word 'bitcoin' more than 5 times" will not hold up.

"Your Honor, we banned this person's website because it contains a bitcoin miner script. See, here is the script, and it matches the hash value found in these other attacks" hopefully holds up.

Re: Never buy a .online domain

#393

Earlier quoted context omitted.

> Marking a website as “unsafe” is an opinion. No, it's not. You're welcome to cite case law if you want to insist. Otherwise, unsafe (in the context of infosec) has a definition of likely or able to cause harm or malfunction. Something that is provable or falsifiable with evidence.

I'm curious as to how you would prove that it would be impossible for any resource accessible under a given DNS domain to ever cause harm to anyone else.

You don't. Google has to prove that something on that domain can cause harm.

Re: Never buy a .online domain

#395

Earlier quoted context omitted.

As someone who has also been bit by this, and with the only possible resolution being that I sign up for google services and register my site with them in the google search dashboard... Fuck Google. This is absolutely libel. They put a big fucking red banner on top of my site, telling the world that it's unsafe, using all the authority they have as one of the largest tech companies in the world. In my case - it was a…

There’s nothing wrong with your dislike of Google. No matter how much you dislike them, though, the word “libel” has a meaning that should be respected. To opine that a site is unsafe is simply not libelous.

It's libelous in Germany unless you can prove it's true. In fact people regularly get punished in Germany for things like calling politicians idiots, because they can't prove they are idiots. https://www.ft.com/content/27626fa8-3379-4b69-891d-379401675...

Re: Never buy a .online domain

#396
post #142

Earlier quoted context omitted.

I always wonder what the settlement and damages would be if google marked Amazon as a phishing site for even a few minutes. The problem is that these gatekeepers of the internet respond to false statements of facts/opinions by so called professionals. I had cloudflare mark a worker as phishing because a AI "security company" thought my 301 redirect to their clients website was somehow malicious. (url redirects are no…

There is a potentially different cause of action, tortious interference with business relationships. It does require that the defendant intended to interfere in a way that would cause harm to the plaintiff, though. Proving Google intended such harm would be difficult and expensive.

Google intends harm to everyone on that list. That's the point of the list. Google is unlikely to have intended this specific harm, but they don't have to.

Re: Never buy a .online domain

#397
post #17

I still remember how Google banned my entire account without providing a reason for a small Android app (more than 12 years ago). To this day I have no idea why, it was absolutely green-area fit tracker or something. There was absolutely no way to know the reason or unblock my account. Turned me away from Android development forever.

A relative’s business has had Google reviews frozen for years. Search results show the bad rating after some former customer and spouse left bad reviews several years ago. Appeal went into a black hole. Running a small business is at the pleasure of Silicon Valley.

Check with a lawyer if this counts as tortious interference. You could potentially win quite a large sum from Google.

Re: Never buy a .online domain

#398
post #360

Earlier quoted context omitted.

cloudflare is the cheapest - they do it at cost.

Wow, thanks. You were right. I Googled and it says Cloudflare is cheaper by twenty-five to fifty percent on renewals. I'm really sick of namecheap. They seem to never stop raising prices. but I'm also I'm kinda wary and afraid of moving domains and losing it.

Cloudflare is doing the enshittification strategy, enticing you now, and then extracting value later. You don't want your domains to be in Cloudflare when they lock the gates. If it's a temporary domain, go ahead I suppose.

Re: Never buy a .online domain

#399
post #307

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

Oh man we had a person leave unexpectedly who controls our Apple organization for our dev accounts. I'm several months into me making requests, getting responses at least a week later for each email where the responder ... didn't really read my message. Then they ask for documents ... but they forgot to send me the secure link ... another week+ for them to do what they said they were going to do. Now one of my docume…

Scammers can definitely get through it faster than you can. Whenever you attempt to address abuse in a system by increasing the complexity of that system, you implicitly bias it towards those with the time and inclination to study it, which always includes those with intent to abuse it, and generally does not include your users.

Re: Never buy a .online domain

#400

Earlier quoted context omitted.

There is a potentially different cause of action, tortious interference with business relationships. It does require that the defendant intended to interfere in a way that would cause harm to the plaintiff, though. Proving Google intended such harm would be difficult and expensive.

Google intends harm to everyone on that list. That's the point of the list. Google is unlikely to have intended this specific harm, but they don't have to.

That won’t cut it in court.
Post reply on HN