Live data from Hacker News

Never buy a .online domain

0xsid.com

451–460 of 513 posts

Re: Never buy a .online domain

#451

Are you 100 percent certain that the domain name wasn't registered before and then got on the blacklist because of prior misuse? It's quite possible that the domain you chose was registered previously and dropped because the previous owner misused it and burned that domain. The .ONLINE extension has been around for several years now.

I am 100 percent certain that one of my domains i registered before and now I am still looking for lawyer to help me sue my government for blocking my domain for something I never commit and refusing to remove the block - just be cause they can. short .com domain! I even paid it for 2 years because I was willing to commit.

Re: Never buy a .online domain

#452
My only adventure with off-brand TLDs has been "aether.ltd". This was for my steampunk telegraph office, "The Aetheric Message Machine Company", an elaborate setup we ran at steampunk conventions from 2011 through 2019.[1] Text in a message, and it's banged out on a restored Teletype machine from the 1930s in a brass and glass case, then delivered by a costumed messenger.[1] This got some press coverage back when steampunk was a thing.

Somehow, Zoominfo picked up the site, and rated The Aetheric Message Machine Company as having revenue of about $5 million a year and, at peak, 24 employees. We had a back story for roleplay purposes, in the operating manual for the cosplayers.[2] Someone apparently took it seriously.

That was a fun project.

[1] https://vimeo.com/124065314

[2] https://aetherltd.com/public/othermanuals/operatormanual05.p...

Re: Never buy a .online domain

#453
post #414

Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. This goes right to the top for me, along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email". Either people who do this for a living have no clue how to do their job, or, depressingly more likely, their goals are just complet…

> along the ubiquitous "please verify your account" emails with NO OPTION to click "that's NOT me, somebody misused my email" What would you expect clicking that "wasn't me" link to do? In 99% of cases, the user who signed up with your address already can't do any more with that account unless you positively confirm it was you; and the site also won't send you any more email because they don't consider the email veri…

> and the site also won't send you any more email because they don't consider the email verified

Netflix, for one, didn't do this. They kept allowing this guy to "resend his confirmation email" periodically over several months (I never had a Netflix account).

My theory is that it was an affiliate scam of some sort; someone probably got paid for everyone who signed up with his code. So he "signed up" thousands of random mails in the hope that some of them would click through on the "you're almost ready to start your Netflix journey!" mail and actually subscribe to Netflix.

Re: Never buy a .online domain

#454
post #11

The TLD owner in this case was Radix, which also owns .store .online .tech .site .fun .pw .host .press .space .uno .website https://radix.website/

Despite blocking 66 TLDs and all IDN ccTLDs on my home dns I didn’t have these blocked. Guess I’ll consider it. Once you have the hagezi rpz files including threat information feed though you really have blocked most silliness.

Which other ones do you block?

Re: Never buy a .online domain

#455

Why was the domain blacklisted though? What can we do to prevent blacklisting in the first place?

That’s my question. I’ve launched many fresh websites that have not been marked as unsafe by Google. If they were habitually doing this, there would be far more reports of it. I suspect there is something the author is not telling us.

The site is already back online after the post. You can check yourself. If I really did have malicious content on the site, this post would have had zero effect on the result.

Re: Never buy a .online domain

#456
post #135

Earlier quoted context omitted.

There is _some amount_ of justification to ban TXT. There have been a few cases of C2 servers using DNS to send instructions to malware, so letting TXT slip through the cracks would still allow for that. Now whether this downside justifies the massive problem it causes on false positives...

TXT can't be banned. There are several RFCs that require TXT records, such as DKIM configuration, DMARC configuration, and it is extensively used for verification by things like AWS SES, Microsoft Office, and all kinds of things. It's built into many standards and used by all kinds of other entities for all kinds of perfectly legitimate things.

Did you read my reply without reading the parent I was replying to? I’m talking about not allowing a blocked domain from being able to add new TXT entries as the parent was suggesting. Of course TXT shouldn’t be banned entirely…

Re: Never buy a .online domain

#457

Earlier quoted context omitted.

> Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. I got hit by this from google. 1. Gmail added requirement for 2FA on my primary email address. Since I had no phone number on file, it instead used my recovery email address. Thankfully, I still had the password for my recovery email address, and could continue to (2). 2. Gmail added requ…

> Fundamentally, this was google's fault for misusing a recovery email for 2FA. While this would absolutely suck and I sympathise with anyone getting hit by this out of the blue, it's pretty clearly your fault, not Google's. What should they have done? Just permit everyone to avoid upgrading to 2FA indefinitely? That would result in relatively more account hacks overall, for which they would inevitably be roasted in…

2FA isn't an upgrade, it's an annoyance. If your organization needs secure authentication, it's useful, but as an individual I have only ever been enraged. Making me check my email and phone to log in is a great way to ensure I never use your service again.

Re: Never buy a .online domain

#458
post #436

Earlier quoted context omitted.

I'm in a similar boat...and over the weeks where i have been sending the requested docs/files...Apple reps come back and state that one of docs i sent them was not valid...so i ask them to clarify their "definition" of the doc..and they just either reply with unhelpful comments, or delay a little and delay things further. When someone asks for a copy of a payslip and you send it...but then Apple says its not a paysli…

I’ve been shocked by the poor support. I didn’t expect speed but what I’ve experienced has been what feels like bottom of the barrel outsourced support you get from some no name brand company….

Structurally all these companies have adopted the approach that the anti-fraud team is it's own world, that should be uninfluenced. So you can't talk to them on the phone, even customer support can only email them; the only feedback paths are ones under their own control. It also seems likely that each subsequent reply is processed by a different operative; for companies of sufficient size, that's probably enforced programmatically.

This all helps make them immune from manipulation by "social engineering" or other forms of influence. But of course it also means they have virtually zero incentive to give a shit about the customer.

There are obviously many ways that they could improve customer experience, but giving them an incentive to do so, without opening the door to influence, is a hard problem.

Personally I think it should be the law that you can put up a bond to get to accelerate the process. Unfortunately the amount potentially at risk is probably larger than some customers accounts, at least at places like AWS where their services can trivially be exchanged for cash. So in many cases a bond would be over the customers means. But if any customers can afford it, it would provide a feedback path.

Re: Never buy a .online domain

#459

Earlier quoted context omitted.

> Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. I got hit by this from google. 1. Gmail added requirement for 2FA on my primary email address. Since I had no phone number on file, it instead used my recovery email address. Thankfully, I still had the password for my recovery email address, and could continue to (2). 2. Gmail added requ…

> Fundamentally, this was google's fault for misusing a recovery email for 2FA. While this would absolutely suck and I sympathise with anyone getting hit by this out of the blue, it's pretty clearly your fault, not Google's. What should they have done? Just permit everyone to avoid upgrading to 2FA indefinitely? That would result in relatively more account hacks overall, for which they would inevitably be roasted in…

> What should they have done? Just permit everyone to avoid upgrading to 2FA indefinitely?

Yes. I've had online accounts for nearly as long as there's been an "online". The only time I've ever lost control of an account was due to 2FA.

2FA should always be optional for one's personal accounts. [0] People who can securely manage passwords simply don't need it. And if Organized Crime or Mossad wants access to my accounts, 2FA is not going to stop them.

[0] Corporate accounts and hardware are a different matter. You manage those however your employer commands you to manage them.

Re: Never buy a .online domain

#460
post #439

Earlier quoted context omitted.

> No notice that I had better have access to that "recovery" email address that I hadn't bothered to keep up to date The rest of your complaints make sense but this one is bizarre. It's a recovery email, isn't having access to it the entire point? Like what else did you think it was supposed to be there for beside being accessible? Google clearly misused it for something else, and you have a strong argument they shou…

I never expected to need to recover the account because I used a strong password stored in a password manager that I had adequately secured and backed up.

Exactly.

It was pretty sobering when Google demonstrated to me a new and novel way that made them the actual threat to my account security. I thought that by carefully refusing to publish anything with their add-ons (YouTube, Docs, Android Store, etc, etc) that I'd avoid getting swept up in an autoomated account-wide bannination, but, nope. A perfectly ordinary login to the account I'd had for years from the exact same location and IP address I'd used the day before was "suspicious" and required "recovery".

Post reply on HN