Live data from Hacker News

Never buy a .online domain

0xsid.com

431–440 of 513 posts

Re: Never buy a .online domain

#431

Earlier quoted context omitted.

I'm fairly sure that Safe Browsing's false-positive rate is extremely low otherwise it'd be unusable in Chrome. Which also means that acting on positive results is very likely a correct approach.

Safe browsing is meant for websites, not domain names. You really want your registry acting on it and nuking your email services, intranet services, cert renewal automation, et cetera?

You think no bad actor thinks of that, using subdomains or whatnot?

Nor did I say anything about wanting a registry acting on it, it's just that the motivations and reasons are incredibly clear. At least to me.

And let me also reiterate that I clearly said that it should be a thought-out process and they haven't thought it out.

Re: Never buy a .online domain

#432

Earlier quoted context omitted.

That sounds like a spurious distinction. Pretty sure you can’t say “Person X is a murderer” and then say “well I’m only expressing my opinion, and in my opinion if you do something that annoys me that qualifies as murder.”

Nope, not in the US. It is perfectly legal to say, for example, "Kyle Rittenhouse is a murderer" despite him being acquitted. You're entirely free to disagree with the result, that is an opinion. Any opinion based on public knowledge is ok. It doesn't even have to be reasonable or rational. What you can't do is imply non-public knowledge, aka "I heard from my cousin who works in law enforcement that Kyle murdered a h…

Is “opinion versus fact” relevant to that example? My impression is that Kyle Rittenhouse wouldn’t have a strong defamation case against a random person tweeting that he’s a murderer, but the reason isn’t that “it’s a statement of opinion.” The reason is that it’s a high profile and controversial homicide case, and it would be very difficult for Rittenhouse to show that that the random Twitter user had “actual malice.”

Re: Never buy a .online domain

#433
post #346

Earlier quoted context omitted.

A couple of years ago someone associated my email with their bank account in Santander UK. I tried to get in touch with Santander but turned out that the only way to do so is to either make an international call (I don't live in UK) or send them a paper letter. I gave up and just routed these emails to separate folder.

I meticulously report every single of emails like this as spam. Every single one. If it _could_ be read as a phishing attempt, I report them as phishing. Etc.

"Wrong recipient" seems beyond the scope of what you can expect a spam filter to handle with accuracy. Wouldn't marking it as spam just degrade the signal to noise ratio of legitimate email? I'd rather get a few misses here and there than have to trawl through my spam folder which I only check once or twice a year when something doesn't show up right away.

Re: Never buy a .online domain

#434

Earlier quoted context omitted.

(IAAL but this is not legal advice.) It’s not libel. Defamation requires a false statement of fact. Marking a website as “unsafe” is an opinion.

Marking a website as "unsafe" in Chrome is equal to standing in front of the door of a small restaurant and blocking 71% of people going inside. Everyone first has to agree that they will enter the restaurant at their own risk. That is more than an opinion. Chrome has a monopoly and should act accordingly. Blocking entry to a website should be a last resort, not just because someone didn't add their website to the wh…

It isn't just chrome. Firefox, Safari, and Edge also use that list.

Re: Never buy a .online domain

#435

Earlier quoted context omitted.

> Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. I got hit by this from google. 1. Gmail added requirement for 2FA on my primary email address. Since I had no phone number on file, it instead used my recovery email address. Thankfully, I still had the password for my recovery email address, and could continue to (2). 2. Gmail added requ…

> Fundamentally, this was google's fault for misusing a recovery email for 2FA. While this would absolutely suck and I sympathise with anyone getting hit by this out of the blue, it's pretty clearly your fault, not Google's. What should they have done? Just permit everyone to avoid upgrading to 2FA indefinitely? That would result in relatively more account hacks overall, for which they would inevitably be roasted in…

I'm tired of 2FA. Absolutely the worst when setting up a new phone after losing the old one. A whole bunch of mixed methods, in 2 hours between installing all the apps again, getting text messages, installing authenticators, scanning IDs, taking selfies, receiving phone calls with spoken codes, grabbing another device that still somehow has access, twenty emails about new suspicious activity, grabbing recovery codes, or scrambling to find the Yubikey I used when registering for the simplest and most benign services that have no connections to my personal data or payment.

Google will insist on sending a notification to a phone you have no longer access to, and regaining access always feels like hacking yourself. I dread the day I lose a phone together with my SIM card and ID during travel. I will never be able to go back and will have to start a new life as an illegal immigrant, living as a hermit in some deep forest.

Re: Never buy a .online domain

#436
post #307

Earlier quoted context omitted.

Oh man we had a person leave unexpectedly who controls our Apple organization for our dev accounts. I'm several months into me making requests, getting responses at least a week later for each email where the responder ... didn't really read my message. Then they ask for documents ... but they forgot to send me the secure link ... another week+ for them to do what they said they were going to do. Now one of my docume…

I'm in a similar boat...and over the weeks where i have been sending the requested docs/files...Apple reps come back and state that one of docs i sent them was not valid...so i ask them to clarify their "definition" of the doc..and they just either reply with unhelpful comments, or delay a little and delay things further. When someone asks for a copy of a payslip and you send it...but then Apple says its not a paysli…

I’ve been shocked by the poor support.

I didn’t expect speed but what I’ve experienced has been what feels like bottom of the barrel outsourced support you get from some no name brand company….

Re: Never buy a .online domain

#437
This story (and many others like it) just goes to show that systems that rely on domains in any way can't be called decentralized.

Email isn't decentralized. Mastodon isn't decentralized. Matrix isn't decentralized. XMPP isn't decentralized. The web certainly isn't either.

All of them can be killed by Safe browsing. All of them can be killed by ICAN (which is under significant influence from the US government). All of them can be killed by their domain registrar and registry operator. All of them can be killed by Let's Encrypt adding their certificates to a CRL, and refusing to issue new ones. All of these will eventually be weaponized, when the war over who controls information truly begins.

Re: Never buy a .online domain

#438

One time I bought a .dev domain, which is/was run by Google, and after missing the renewal deadline by less than 24 hours, the renewal price jumped from less than $30, to $800.

Is this even legal?

No idea, but it would cost me more to fight it than it's worth. And other people have reported similar issues but people refused to believe them, so I doubt I would get much sympathy.

Re: Never buy a .online domain

#439
post #335

Earlier quoted context omitted.

I have the same issue. At the time I created the account that I'm locked out of, Google said nothing about these "recovery" email addresses as 2FA. Years passed without any notice that maybe they were going to lock me out of an account I have the password for. No notice that I had better have access to that "recovery" email address that I hadn't bothered to keep up to date because I never thought I'd need to "recover…

> No notice that I had better have access to that "recovery" email address that I hadn't bothered to keep up to date The rest of your complaints make sense but this one is bizarre. It's a recovery email, isn't having access to it the entire point? Like what else did you think it was supposed to be there for beside being accessible? Google clearly misused it for something else, and you have a strong argument they shou…

I never expected to need to recover the account because I used a strong password stored in a password manager that I had adequately secured and backed up.

Re: Never buy a .online domain

#440

Earlier quoted context omitted.

Not force nonconsensual authentication methods onto users. Google is one of the rare places I actually see positive value to 2FA. Compare with say banks, where it being demanded actually decreases my security. But regardless, it should not be forced.

As for the banks I doubt it decreases security. Even SMS 2FA actually reduces fraud by 90%+ percent. Yes, some banks implement it silly, like SVB requiring biometric login in order to scan one-time QR 2FA code from their app (biometric login is less secure), but you don't have to use the QR code, can use regular 2FA without biometrics. But even then having 2FA is 42 times better than not having it.

For US banks, the most important thing you can do to prevent fraud is to check your account transactions every 30 days so that you can report fraudulent transactions in a timely manner and have them reversed. Anything that increases friction of logging into your account thus decreases your security.
Post reply on HN