Live data from Hacker News

Never buy a .online domain

0xsid.com

441–450 of 513 posts

Re: Never buy a .online domain

#441

This story (and many others like it) just goes to show that systems that rely on domains in any way can't be called decentralized. Email isn't decentralized. Mastodon isn't decentralized. Matrix isn't decentralized. XMPP isn't decentralized. The web certainly isn't either. All of them can be killed by Safe browsing. All of them can be killed by ICAN (which is under significant influence from the US government). All o…

> All of them can be killed

> Anyone can be killed, my Lord!

So nothing is decentralized?

Re: Never buy a .online domain

#442

Earlier quoted context omitted.

> I don't understand. What is Google Search Console, and should I add all my domains there right now? Google's way of tying real identifies of people to domains, without making it explicit. Basically, your domain will be weirdly treated by a bunch of entities, none the less Google themselves, if you don't add your domain there (or some other Google property). Especially with less common TLDs, like .online, they reall…

Open a fake Google account under your dog's name using a VPN? It doesn't have to be tied to your own every day Goog acct. Any old account will do.

Does your dog have a phone number?

Re: Never buy a .online domain

#443

Earlier quoted context omitted.

It’s not libel. Defamation requires a false statement of fact. Claiming a website is “unsafe” is an opinion. (IAAL, but this is not legal advice. Consult a licensed attorney for legal advice.)

The warning says something along the lines of "Dangerous Site Ahead. Attackers on [site] may trick you into doing something dangerous..." If I'm the only one with access to the site, they're calling me an attacker and saying that I might try to steal passwords, credit card info, etc.. If they're calling me an attacker, that seems like more than an opinion. Wouldn't they have to prove I'm a bad guy if they're assertin…

“May” is a load bearing word here.

Re: Never buy a .online domain

#444

Earlier quoted context omitted.

Someone constantly adds my Gmail address as their Gmail account's backup address. I constantly remove it whenever Gmail sends me the notification. I can't help but think there is some method for the other person to steal my Gmail account if I never remove my email as their backup.

My Gmail account is a funny word in Spanish that I got when there was still plenty of names available. I get TONS of emails of people trying to join services that use my address as a "fake email".

We call this the Scunthorpe problem. Stupid "rude word" detectors use simple rules that fail on actual words.

Way back I was working on a loyalty card system that had the entire UK electoral roll and Post Office data and we had to validate people; names and addresses. A "comedian" decided to sign themselves up for the system using a stupid name, and when the loyalty card duly arrived at their (correct) address with their (incorrect) name, they went to the papers and it became a slow news day human interest story.

We had to implement a Scunthorpe filter, and that was really difficult. We ended up with a human looking at the data and hitting a button if they thought this was a made-up "funny" name or address.

You would be amazed at English place names and surnames. Velvet Bottom is a real place in the UK. There are many people wandering around with names that you can't say in polite company.

Re: Never buy a .online domain

#445

> Not adding the domain to Google Search Console immediately. I don't need their analytics and wasn't really planning on having any content on the domain, so I thought, why bother? Big, big mistake. That should be enough to trigger an antitrust case against Google and a split of its activities. When despite unrelated, it becomes the gatekeeper of your presence in internet.

A registrar using Google's signal to deactivate your service isn't Google's fault.

Safe Browsing itself has an appeal process so I think legally they're covered. Users and governments surely appreciate someone filtering bad actors online, even if casualties don't.

Re: Never buy a .online domain

#446

This story (and many others like it) just goes to show that systems that rely on domains in any way can't be called decentralized. Email isn't decentralized. Mastodon isn't decentralized. Matrix isn't decentralized. XMPP isn't decentralized. The web certainly isn't either. All of them can be killed by Safe browsing. All of them can be killed by ICAN (which is under significant influence from the US government). All o…

Was just thinking that our workstations should save DNS lookups for our most used domains over time.

Re: Never buy a .online domain

#447
post #272
post #251

It's not about the .online TLD being "weird". The problem is that it was free. That's going to attract a swarm of fraudsters, spammers, etc, and then turn into a strong "this is probably fraud" signal in all kinds of fraud scoring systems. There are lots of domains out there other than .com that are just fine.

.online, .top, .xyz. info and .shop are some of the top TLDs that scammers use, precisely because of their rock bottom registrar fees that make them attractive for sites that have a shelf life of a few hours or a few days before being blocked. As a result, many places have a blanket "suspicious" flag for fresh domains under these TLDs. If you plan on building a legit site, do not use any of these cheap TLDs.

Try finding a pithy domain these for under 10,000 these days. I tried a week ago and had to settle for something a lot longer than I wanted and even then it was something from outside the common three letter TLDs.

Re: Never buy a .online domain

#450

Earlier quoted context omitted.

Have you tried sending them emails asking/telling them to stop?

That may be what they're hoping for, using a similar modus operandi as those WhatsApp/IM messages from strangers who text you with things in the vein of ‘Hey, it was great meeting you at the conference’ or ‘Did Martha like your flowers?’ etc. They may well be looking for targets.

I have a story here: I deleted my Reddit account.

A few months later, the owner of the u/batman account added my mail as password reset mail.

I looked up the account. It was hardly ever used in 15 years, mostly for once in a blue moon dropping in a random comment role-playing as Batman. It was not obviously anyone I knew. It looked like they were basically inviting me to take over the account.

That was actually a bit tempting, but then the owner, whoever they were, would know who I was, and I still didn't know who they were.

(For that reason I've changed the name, it wasn't Batman, but it was equally "I can't believe you got THAT as your Reddit username" rare.)

So I clicked "this wasn't me" instead. After a few weeks the account was deleted by the owner. It seems they were willing to burn a 15+ year old account with a super-desirable (to many) name in order to get me back to Reddit, and then when I refused they just deleted it. That was VERY weird, and I wish I knew what was going on.

Post reply on HN