Live data from Hacker News

Never buy a .online domain

0xsid.com

461–470 of 513 posts

Re: Never buy a .online domain

#461

Earlier quoted context omitted.

That's fair, if your domain is erroneously put on the block list, Google should be liable for the consequences. But my point is that any knock on effects like domain suspension, email deliver-ability, etc. stem from 3rd parties misusing the safe browsing list outside the scope of safe browsing . I don't see how Google can be blamed for other companies erroneously treating the safe browsing list as a source of truth f…

> But my point is that any knock on effects like domain suspension, email deliver-ability, etc. stem from 3rd parties misusing the safe browsing list outside the scope of safe browsing. That's fair and I agree. My opinion is that both should be liable in a case like this. If I had to attribute it, my starting point would be that Google is liable for the loss of website traffic and the registry is liable for the loss…

> My opinion is that both should be liable in a case like this.

I totally agree, but if I went after every company I felt to be incompetent to the point of criminal negligence I'd be up to my eyeballs in lawsuits just over password requirements.

> The answer is always the same IMO. Break up big tech companies into a million little pieces.

Generally I agree, but in this case I think there's an even simpler solution: 1) hold Google accountable for entries in their safe browsing lists (as an adjacent poster pointed out, the legal precedent may be there) and 2) make companies legally liable for misusing 3rd party data.

Really just the second part would suffice, and frankly it's purely good for society. The inevitable outcome is that no one exposes data they can't guarantee, and maliciously consuming 3p data would nearly disappear

Re: Never buy a .online domain

#462

Earlier quoted context omitted.

This is 100% on Radix, not on Google. Google and Microsoft can (and probably should) have a registry of known-abusive websites. False positives are inevitable, so these should be taken with a grain of salt, but in most cases they're correct. Their lists are a lot more reliable than those from the "traditional" antivirus/anti-scam vendors that will list anything remotely strange to pump up their numbers. The external…

Wym mean external people aren't these lists integrated to the browsers? I'm sure if you try to open a website from this list your browser won't let you and I'll put a big warning sign

You can check browser behaviour here: https://testsafebrowsing.appspot.com/

"See details"> "ignore the risk" works for me. Even Chrome lets you ignore the warning if you click the details button. That's not the problem, though; the problem is that the registrar decided that the browser warning ("something might be wrong") as proof of malice (took down the domain entirely).

Re: Never buy a .online domain

#463
post #194

Earlier quoted context omitted.

Google doesn't sell their list to you. They give it to you for free. Using their list costs them money. Pumping up numbers gains them nothing but the headache of PR issues when they get a false positive. Spyware filters used to boast about how many domains they filter out because they wanted you to buy their filters instead of someone else's. By the time they hit a false positive, they've already sold a year's subscr…

Step 1: Get everyone to use your free internet filter Step 2: Alter filters to mark newly-registered domains and low-traffic websites as "potentially harmful". Step 3: Charge a lot of money for "business verification" - which gives them a fancy badge somewhere and incidentally makes their website trustworthy in the eyes of your filter. Step 4: Profit! The Big Tech cartel has been doing this pretty successfully with e…

> Step 2: Alter filters to mark newly-registered domains and low-traffic websites as "potentially harmful".

Yeah, sounds like a great cartel idea, if they actually did that. None of my domains ever got marked as potentially harmful, even the one that I bought as a joke because it would be so easy to turn it into a phishing site.

Not everything is a big conspiracy to oppress the population. We hear about the cases where it goes wrong because the HN front page is the fastest way to reach the single part-time support person Google seems to employ.

Re: Never buy a .online domain

#464

Earlier quoted context omitted.

These alternative domains are quite popular with the fediverse and other hobbyist-run groups. Affordable domains with somewhat recognisable names still available. Scam websites will use any TLD in my experience. Based on the ones that made it to my Google search results, .it and .info are the TLDs I should be blocking. When I search for "free roblox cash", most websites are .com. "Free robux" also brings forth a few…

> Affordable domains with somewhat recognisable names still available. Aren't they only affordable for the first year though?

$2 per month isn't cheap for a domain per se, but compared to .ht or .ao or .ly it's still cheap.

TLDs like .stream, .click, .top, and .link are cheap in general, even compared to .com

Re: Never buy a .online domain

#465
post #261

Earlier quoted context omitted.

This is 100% on Radix, not on Google. Google and Microsoft can (and probably should) have a registry of known-abusive websites. False positives are inevitable, so these should be taken with a grain of salt, but in most cases they're correct. Their lists are a lot more reliable than those from the "traditional" antivirus/anti-scam vendors that will list anything remotely strange to pump up their numbers. The external…

I read your comment as agreeing with the article: "Never buy a .online domain". And Google has the right to publish a list, there should be more lists not less. But Google was at fault for not correcting their blacklist. Until the article appeared on Hacker News, this was not 0% on Google. A small, correctable mistake, but they deserved a tiny bit of blame.

Not just .online, also any other domain Radix hosts. At least not for anything important.

What stands out to me:

> Earlier this year, Namecheap was running a promo that let you choose one free .online or .site per account.

I wouldn't be surprised if most of Namecheap's customers who used the "register a domain for free" discount were indeed malicious. Without seeing the results of whatever analysis Google did to flag this website, it's hard to say whether Google is at fault here.

Re: Never buy a .online domain

#466

Does anybody know any good alternative to Name Cheap? It seems like they keep raising prices on all the domains. Website is very sluggish, especially for finding domains quickly.

I've heard good things about https://www.inwx.com/ I'm contemplating moving my domains from namecheap to there as they have a reputation for supporting lots of exotic domains which will make migrating easier.

Lots of good stuff in this thread I was not aware of. I have a few vanity domains with personal projects so it's not a big deal if they have low SEO but good to know going forward that I should be prioritising country domains like the Irish .ie one instead of 'fun' looking domains that are memorable.

Re: Never buy a .online domain

#467

Earlier quoted context omitted.

> Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. I got hit by this from google. 1. Gmail added requirement for 2FA on my primary email address. Since I had no phone number on file, it instead used my recovery email address. Thankfully, I still had the password for my recovery email address, and could continue to (2). 2. Gmail added requ…

> Fundamentally, this was google's fault Or yours, for not caring about 2FA. It's been a common practice for many years, and strongly recommended by most identity services, as well as OWASP and NIST recommendations. What would you do in Google's place?

2FA falls under the same criteria as mandatory password rotation, and "has to have special characters". Those were NIST recommended for a long time too.

Re: Never buy a .online domain

#468

Earlier quoted context omitted.

This is the real story. This is 100% a problem with Radix. Safe browsing targets the website not the domain. No reason a registrar should be suspending an entire account over something a company reports. Black-holing the A and CNAMEs on a subdomain? Maybe..... But even then I don't think it's the registrars place to do that. Freezing the entire account? Absolutely not.

Blackholing the a and cnames would prevent getting off the safe browsing list, as mentioned in the blog post.

Google allows you to use TXT to verify though, since this "feature" of disabling domains because of Safe Search is based only on web contents (A/AAAA/CNAME) they could disable those and allow TXT anyway since those are AFAIK harmless

Re: Never buy a .online domain

#469

Earlier quoted context omitted.

> Oh man. The infinite loops of impossible verification by large companies that should know better are massive pain peeve of mine. I got hit by this from google. 1. Gmail added requirement for 2FA on my primary email address. Since I had no phone number on file, it instead used my recovery email address. Thankfully, I still had the password for my recovery email address, and could continue to (2). 2. Gmail added requ…

> Fundamentally, this was google's fault for misusing a recovery email for 2FA. While this would absolutely suck and I sympathise with anyone getting hit by this out of the blue, it's pretty clearly your fault, not Google's. What should they have done? Just permit everyone to avoid upgrading to 2FA indefinitely? That would result in relatively more account hacks overall, for which they would inevitably be roasted in…

Personally, if their 2FA doesn't work, then they should definitely permit everyone to avoid upgrading to 2FA indefinitely.

Re: Never buy a .online domain

#470

Earlier quoted context omitted.

nonsense. any feature should have acceptable failure modes. blaming the customer for a fault they have no control over is not acceptable. many people know nothing about 2FA. it is not their responsibility. 2FA is a symptom of shitty designed systems which are inherently insecure and companies who dont give a shit about that and let their customers shoulder the burden by shoving complexity down their throats. if you m…

> many people know nothing about 2FA That's why Google sent them multiple emails explaining what it is and recommending to turn it on. What else could Google do?

Provide a way to resolve the issue in the very foreseeable situation where someone doesn't read the emails an add it.

Is it possible that you use email differently than most people? I virtually never actually check my inbox. I'm either reading an email that I knew was coming (e.g. an order confirmation with a shipping link) or I'm searching for something specific. So no matter how many emails Google sends I'm unlikely to read them.

Post reply on HN