Live data from Hacker News

Never buy a .online domain

0xsid.com

411–420 of 513 posts

Re: Never buy a .online domain

#412
post #402

Earlier quoted context omitted.

I'm sure Google prompted author for years begging to turn the 2FA on, as well as warning that they will enforce it on day X. Author ignored them all.

Why is 2FA so critical it’s worth proactively breaking the user? What’s the even more bad thing that would (not could) happen to the user if 2FA was not enabled?

Password database leaks turning into spam/proxy farms of very well aged accounts.

Re: Never buy a .online domain

#413

Earlier quoted context omitted.

Have you tried sending them emails asking/telling them to stop?

I’m a different person, but this happens to me, too. I have the kstrauser@yahoo.com email address because I signed up for it like 25 years ago. I log in every 6 months to see what the few other kstrausers in the world have signed me up for. Not jsmith, but kstrauser. Not Gmail, but Yahoo. And I still get banking docs, and HOA meeting minutes, and birthday party invitations, and Facebook logins, and other bizarre rand…

I have a catch-all on a .com.au domain where there exists a later 1000+ people organisation with the equivalent .gov.au. I get what you described but from many, many people - divorce proceedings, legal discussions, financial documents, health things, etc.

Re: Never buy a .online domain

#414

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

> along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email"

What would you expect clicking that "wasn't me" link to do?

In 99% of cases, the user who signed up with your address already can't do any more with that account unless you positively confirm it was you; and the site also won't send you any more email because they don't consider the email verified (and so sending to it might result in their emails getting sent to spam -> their email-sending reputation score going down.) So things are already in the state you'd want them to be in, no?

The only problem I can think of with that state is that now you can't sign up "fresh" for an account with the same provider, because now there's already an account associated with your email address sitting there in their DB in the pending-email-verification state. (But you still can acquire that account, by clicking "forgot/reset password" and going through that flow, which will inevitably go through your email, as anything like a 2FA setup flow always waits behind email verification.)

Re: Never buy a .online domain

#415

Earlier quoted context omitted.

Yeah. Everyone uses their list and being blocked by all web browsers is like having someone cover the doorway with a massive DANGER sign. It's insane that people are roaming around here arguing that it's ok because the damage caused is a necessity for "internet scale".

Right now, any damages are completely speculative at this point. I would suspect in this case, the damages are minimal, and taken in the broader context, the good outweighs the harm. Do you have evidence to the contrary?

The good outweighs the harm until it happens to you. The problem is that even if the failure rate is low, the failure can be catastrophic for the people suffering from it.

I use Ubiquiti as an example for an update they pushed to their UniFi systems a long time ago (5+ years). Some people were configuring their devices to use an https URL to connect to a management console when it was supposed to be http. Before the update, the console accepted http on the https port. After it didn't. That caused devices to disconnect from the management portal and remain offline.

When people complained, Ubiquiti said they realized it would happen, but it "would only affect a tiny percentage of customers." However, most customers that were affected had a 100% rate of failure. One person had something like 600-700 devices that got disconnected and required manual reconfiguration.

A 1% failure rate might be ok for the company, but it shouldn't be if the 1% of people affected suffer 100% failure. The distribution of the failures needs to be considered.

I had my primary domain that my entire family has used for 25 years put on that blacklist. If I hadn't been able to get it removed it would have had a massive negative impact on my life. Had it been suspended by the registry the way the OP of this article describes, I'm not sure how it would have worked out.

So it may be a false positive of .0000000001%, but would have ruined my life. I have 900 entries in my password manager and probably half of them are tied to that domain. Is my entire digital life acceptable collateral damage? Is yours?

Re: Never buy a .online domain

#416
post #335

Earlier quoted context omitted.

> Fundamentally, this was google's fault Or yours, for not caring about 2FA. It's been a common practice for many years, and strongly recommended by most identity services, as well as OWASP and NIST recommendations. What would you do in Google's place?

I have the same issue. At the time I created the account that I'm locked out of, Google said nothing about these "recovery" email addresses as 2FA. Years passed without any notice that maybe they were going to lock me out of an account I have the password for. No notice that I had better have access to that "recovery" email address that I hadn't bothered to keep up to date because I never thought I'd need to "recover…

> No notice that I had better have access to that "recovery" email address that I hadn't bothered to keep up to date

The rest of your complaints make sense but this one is bizarre. It's a recovery email, isn't having access to it the entire point? Like what else did you think it was supposed to be there for beside being accessible?

Google clearly misused it for something else, and you have a strong argument they shouldn't have. This one sentence just needlessly weakens the argument.

Re: Never buy a .online domain

#417
post #307

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

Oh man we had a person leave unexpectedly who controls our Apple organization for our dev accounts. I'm several months into me making requests, getting responses at least a week later for each email where the responder ... didn't really read my message. Then they ask for documents ... but they forgot to send me the secure link ... another week+ for them to do what they said they were going to do. Now one of my docume…

I'm in a similar boat...and over the weeks where i have been sending the requested docs/files...Apple reps come back and state that one of docs i sent them was not valid...so i ask them to clarify their "definition" of the doc..and they just either reply with unhelpful comments, or delay a little and delay things further. When someone asks for a copy of a payslip and you send it...but then Apple says its not a payslip, i genuinely am sad about the overall state of the world...I dislike apple and all these big tech providers for their abusive control/power and at the same time vast layers and levels of incompetence. :-(

Re: Never buy a .online domain

#418
Google loves doing stuff like this. At my last company, before we sold it, I had to reverify our Google Business page about once a week because it would constantly just remove the verification for seemingly no reason.

Re: Never buy a .online domain

#420
post #335

Earlier quoted context omitted.

I have the same issue. At the time I created the account that I'm locked out of, Google said nothing about these "recovery" email addresses as 2FA. Years passed without any notice that maybe they were going to lock me out of an account I have the password for. No notice that I had better have access to that "recovery" email address that I hadn't bothered to keep up to date because I never thought I'd need to "recover…

> No notice that I had better have access to that "recovery" email address that I hadn't bothered to keep up to date The rest of your complaints make sense but this one is bizarre. It's a recovery email, isn't having access to it the entire point? Like what else did you think it was supposed to be there for beside being accessible? Google clearly misused it for something else, and you have a strong argument they shou…

The point is that an or relationship was silently converted into an and relationship, which is a _very_ different relationship between two factors.
Post reply on HN