Morale of the story: never ever use a registry that bases its decisions on Google Safe Browsing. Radix in this case. A very modern looking website for a really caveman support.
Never buy a .online domain
401–410 of 513 posts
Re: Never buy a .online domain
#402Earlier quoted context omitted.
Not add 2fa automatically, but instead prompt with options to add it. This probably doesn't comply with the relevant recommendations, but cutting a user of from their email is worse in my opinion.
I'm sure Google prompted author for years begging to turn the 2FA on, as well as warning that they will enforce it on day X. Author ignored them all.
Re: Never buy a .online domain
#403“never buy a non-.(com|net|org) domain” ftfy
I agree, but if I ever get a chance at .edu, .mil, or .gov I'm gonna take it.
.mil and .gov have always been too strict for ordinary folks though.
Re: Never buy a .online domain
#404The registrar relying on Google Safe Browsing as a “trigger” for suspension is the most horrifying thing I’ve seen in a while. This basically makes the entire TLD unviable for serious use.
https://tldrisk.com/beyond-basics/reclassification/
> This basically makes the entire TLD unviable for serious use.
It doesn't just make the TLD in question unusable. I think it makes most of the new gTLDs unusable. Registries can enact policies and systems like this, regardless of the detriment to registrants, due to a lack of oversight and registrant consideration by ICANN. That creates uncertainty and makes it pragmatic for registrants to simply choose the gTLDs with lots of history and precedence; .com, .org, etc..
The only two TLDs I'd personally rely on are .com (gTLD) and .ca (ccTLD).
Re: Never buy a .online domain
#405Earlier quoted context omitted.
The point of the system is what it does. They can't just say "we don't want to deal with small timers who will not pay us big bucks doing nonstandard things" without pushback but they can write the policy so that a huge fraction of those use cases fall into some crack that can only be got out of by incurring the kind of expense that's a non-starter for those users. Your municipal code is rife with examples of this.
This is a catchy aphorism, but not really true. Things can be badly implemented so that they fail to achieve their purpose.
The people who create a system have some intent for it. The system may or may not effectively achieve that intent, may or may not outlive the initial conditions that surrounded its creation, and may or may not have side effects.
Purpose is something humans assign. It is sometimes linked to intent. A carpenter's hammer is intended to drive and pull nails, and that is often also its purpose. The purpose of the hammer I keep in my basement is breaking open walnuts.
The phrase is stating that the purpose we should assign to systems when judging them is their outcome, and not the intent behind them.
Re: Never buy a .online domain
#406Earlier quoted context omitted.
I prefer "please verify your account" to "thanks for joining" by a lot. The former presumably does not verify when I ignore it. The latter should be illegal but somehow isn't. I do wish there was a requirement for some sort of "no" button that would stop sending sign up requests entirely.
Any idea what the incentive is for them to put in an email address they can't access? I run a few websites that accept an email address (all noncommercial, I have no interest in spamming anyone). One of them is the "contact me" feature on my personal website. To prevent spam, I had people just put in their email address and it'll automatically email them my email address. This works perfectly to this day, haven't got…
Re: Never buy a .online domain
#407Earlier quoted context omitted.
> closes the door on [...] being accused of practicing law illegally Does it? So I can say, "I'm not your lawyer, but I'm happy to go ahead and give you specific legal advice on your case." and I can't be accused of illegally practicing law? I was under the impression that this could still get you into hot water. But not being your lawyer, due to the fact that I am not a lawyer at all, I don't know if it is true or n…
IANAL, so take this with a grain of salt, but: As with all things, who are you going to get in trouble with ? And what's so magical about legal practice as opposed to, say, giving shitty medical advice or telling someone how to build porch? Asking genuinely. No one falls all over themselves to say "I am not a doctor, but...", even though their next words could kill someone. The implication is that they don't have for…
This is precisely why I’m pointing this out: IANAL is a very curious case of people self-labeling their statements as “not trustworthy for the topic”. I can think of perhaps no other cases where it is so popular to claim to not be a professional in the relevant field, which suggests that IANAL is a ‘badge of honor’ rather than a proper legal disclaimer. Certainly few (if any) claim IANAD before writing about their experiences with medical issues, body things, or nutritional supplements here, even though those topics are (as you correctly indicate) potentially lethal.
Thus, IANYL: if your goal is to ensure that the recipient of your advice / opinion / whatever does not have grounds to claim that you provided legal advice, and therefore are their lawyer, then you can either do so weakly with TINLA (“this is not legal advice”), which still leaves the door open for awkward claims by some desperate grifter-rando to reach a bench, or you can do so strongly with IANYL (“I am not your lawyer”), which closes that vulnerability in full.
Not once in years of using IANYL have I seen anyone else properly protect themselves from this vulnerability; meanwhile, “IANAL but” remains in use as a badge of honor. So, yeah, I don’t think anyone considers the particular avenue of vulnerability a serious threat, and yeah, the general context of IANAL here is prideful rather than protective. But after twenty years of dealing with a stalker who was adept at internet and tried to fuck with my job at one point, I do now tend to value closing off legal vulnerabilities with certainty, and as a bonus it doesn’t imply insult to the professions of law.
IANYL, YMMV :)
Re: Never buy a .online domain
#408Earlier quoted context omitted.
Google is making false statements about the safety of a domain and it has significant collateral damage. Google is the cause. They should be liable for losses. I had my main family domain put on Google's safe browsing block list and it has a massive impact. No one can visit the site. I think apps using system browser runtimes (ie: mobile) may stop working. I've seen reports that it can impact email deliver-ability. A…
That's fair, if your domain is erroneously put on the block list, Google should be liable for the consequences. But my point is that any knock on effects like domain suspension, email deliver-ability, etc. stem from 3rd parties misusing the safe browsing list outside the scope of safe browsing . I don't see how Google can be blamed for other companies erroneously treating the safe browsing list as a source of truth f…
That's fair and I agree. My opinion is that both should be liable in a case like this. If I had to attribute it, my starting point would be that Google is liable for the loss of website traffic and the registry is liable for the loss of email and all other lost services due to the domain suspension.
It spirals though because, like you pointed out, no one forced (ex:) Mozilla or Apple to adopt the blacklist. They did that voluntarily, so they should be responsible for their share. That's why nothing ever gets fixed. It's broken, but there's so much potential for finger pointing that no one gets pinned down and held responsible.
The answer is always the same IMO. Break up big tech companies into a million little pieces.
Re: Never buy a .online domain
#409That should be enough to trigger an antitrust case against Google and a split of its activities. When despite unrelated, it becomes the gatekeeper of your presence in internet.
Re: Never buy a .online domain
#410https://www.spamhaus.org/reputation-statistics/gtlds/malware...