Live data from Hacker News

Never buy a .online domain

0xsid.com

421–430 of 513 posts

Re: Never buy a .online domain

#421
post #335

Earlier quoted context omitted.

> Fundamentally, this was google's fault Or yours, for not caring about 2FA. It's been a common practice for many years, and strongly recommended by most identity services, as well as OWASP and NIST recommendations. What would you do in Google's place?

I have the same issue. At the time I created the account that I'm locked out of, Google said nothing about these "recovery" email addresses as 2FA. Years passed without any notice that maybe they were going to lock me out of an account I have the password for. No notice that I had better have access to that "recovery" email address that I hadn't bothered to keep up to date because I never thought I'd need to "recover…

> old .edu email address that I was promised "for life"

Best treat all org controlled email address as temporary.

Re: Never buy a .online domain

#422

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

> Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. I got hit by this from google. 1. Gmail added requirement for 2FA on my primary email address. Since I had no phone number on file, it instead used my recovery email address. Thankfully, I still had the password for my recovery email address, and could continue to (2). 2. Gmail added requ…

> Fundamentally, this was google's fault for misusing a recovery email for 2FA.

While this would absolutely suck and I sympathise with anyone getting hit by this out of the blue, it's pretty clearly your fault, not Google's. What should they have done? Just permit everyone to avoid upgrading to 2FA indefinitely? That would result in relatively more account hacks overall, for which they would inevitably be roasted in the court of public opinion.

Re: Never buy a .online domain

#423

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

Once got one of those with a disclaimer that clicking any link was giving permission to subscribe me…

I believe they included the “unsubscribe” link too…

Re: Never buy a .online domain

#424
post #354

Earlier quoted context omitted.

This is a catchy aphorism, but not really true. Things can be badly implemented so that they fail to achieve their purpose.

People often have trouble with this saying, and that trouble often boils down to the difference between intent and purpose. The people who create a system have some intent for it. The system may or may not effectively achieve that intent, may or may not outlive the initial conditions that surrounded its creation, and may or may not have side effects. Purpose is something humans assign. It is sometimes linked to inten…

Sometimes intent and outcomes matter, but the aphorism is simply not a good guide to understanding reality. It should be discarded.

The classic example is a hospital for treating cancer patients. Suppose that one third of the patients are successfully treated, while the other two thirds die of their cancer. Is the purpose of the hospital to kill two thirds of the patients? Clearly not, but that is the outcome.

Re: Never buy a .online domain

#425

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

I'm currently in the endless email loop because someone named Raymond used one of my Gmail names to register with State Farm. One of their agents even emails me directly when he gets really behind on his payments but won't do anything when I tell them it's the wrong email. In the past when this happens I usually reset the password and change the email to some anon throwaway but I can't do that without Raymonds DOB (d…

This exact thing happened to me with a State Farm agent.

After a few months, I told them I was concerned about the privacy ramifications and would have to report it to their state insurance regulator, and it was very quickly fixed.

Re: Never buy a .online domain

#426

So, how is this not libel by Google? The claim was that you were running an "unsafe site". Its their job to prove that, and not just "black box says so". And you have system and reputational damages. Go for small claims suit, $5000. It'll cost more than that for their attorney to go to your jurisdiction.

It’s not libel. Defamation requires a false statement of fact. Claiming a website is “unsafe” is an opinion. (IAAL, but this is not legal advice. Consult a licensed attorney for legal advice.)

The warning says something along the lines of "Dangerous Site Ahead. Attackers on [site] may trick you into doing something dangerous..."

If I'm the only one with access to the site, they're calling me an attacker and saying that I might try to steal passwords, credit card info, etc.. If they're calling me an attacker, that seems like more than an opinion. Wouldn't they have to prove I'm a bad guy if they're asserting I'm a bad guy?

Re: Never buy a .online domain

#427

Earlier quoted context omitted.

Have you tried sending them emails asking/telling them to stop?

I’m a different person, but this happens to me, too. I have the kstrauser@yahoo.com email address because I signed up for it like 25 years ago. I log in every 6 months to see what the few other kstrausers in the world have signed me up for. Not jsmith, but kstrauser. Not Gmail, but Yahoo. And I still get banking docs, and HOA meeting minutes, and birthday party invitations, and Facebook logins, and other bizarre rand…

I have very weird and rare @gmail.com and I Still get other peoples mail sometimes.

Re: Never buy a .online domain

#428
post #228

Earlier quoted context omitted.

I am in Canada, but I think it is the same in the US? A newspaper can be responsible here. For example, if they say "people should riot" and a riot happens, the newspaper could be responsible for all actions that resulted the same as if they were the ones doing the crime. Same with if they become aware of defamation and fail to retract and make a statement. But newspapers will generally also thoroughly investigate th…

It is not the same in the U.S. (And, to be honest, I'm quite doubtful this is true in Canada, though I could be persuaded through legal citations that it is.)

"Under the Criminal Code of Canada (Section 21), you can be charged as a "party" to an offence if you were involved in planning, "encouraging", or aiding in its commission" Criminal Code (R.S.C., 1985, c. C-46)

"21(1) Parties to Offence: Anyone who actually commits the offense, aids in committing it, or abets (encourages) someone in committing it is a party to the offense."

I work in a law firm but NAL. I could probably find some cases if I had time. Most of the responses from people saying defamation is not very successful and "good luck" in the us because of 1A seem strange to me also.

Re: Never buy a .online domain

#429

Earlier quoted context omitted.

In my opinion, a .online domain is unsafe. 99% of people only visit ".com"s unless they clicked a scam link. Completely blocking the site is overkill, but the browser should warn you about it like it does with non-SSL sites.

What? I find myself on .net-s and .org-s all the time. For example... Wikipedia is .org. Do 99% of people not visit Wikipedia?

I mean .org or .gov is fine, just not stuff like .online or .info.

Re: Never buy a .online domain

#430
The product[1] looks super cool! I can immediately think of my use case, though not for gamin. I am using LibreChat to call LLMs, installed on my home server. But when I open a webtab, it has all these browser tabs I don't want to see. I am sure there are many cases where this product can shine.

[1] https://getwisp.online/

Post reply on HN