Live data from Hacker News

The Passport Payment (2000)

web.archive.org

51–55 of 55 posts

Re: The Passport Payment (2000)

#51
post #17

I'm confused, how did he pay for someone else's domain? Was there no authentication?

Back then, control was authenticated as necessary for the proper functioning, but even today I see no reason why renewal should have to be gated behind login walls. Actually, I'd even prefer it not to be, because you might, in a pinch, be prevented from paying for them yourself electronically, having to call in a favor and promise to pay back as soon as you see that friend. Or you just prefer to pay someone cash for…

There are other registrars that support paying for an arbitrary domain without having ownership.

Re: The Passport Payment (2000)

#52
post #5

> in addition to a new copy of Visual Studio 6.0 (which I need to compile and run the decss program to decode my DVD's so that I can play them under Linux) Why would you need VS6 to compile a program for Linux?

DeCSS was a windows-only program back in those days.

Also, because it's a joke and is funny :p

Re: The Passport Payment (2000)

#53
post #35

Earlier quoted context omitted.

> even today I see no reason why renewal should have to be gated behind login walls. This actually reminds me on a somewhat interesting social engineering "vulnerability" a little while back[0]. 1. The hacker would call into Amazon and say that the website was acting up and they needed to add a card to the victim's account. It wouldn't take much effort because why would it? 2. The hacker'd call right back and say tha…

That's a useless hack at the time. You could generate your own credit card numbers back then using a formula. The name/expiry date or address were not used for verification. So ordering from a fake credit card was easy. Finding the drop shipping location was the hard part.

In context, the exfiltrated info (last for of real card, billing address, email) was used as verification to get the victim's me.com account under the hacker's control, which was the back up for the victim's primary gmail used for everything else.

Re: The Passport Payment (2000)

#54
post #51
post #17

Earlier quoted context omitted.

Back then, control was authenticated as necessary for the proper functioning, but even today I see no reason why renewal should have to be gated behind login walls. Actually, I'd even prefer it not to be, because you might, in a pinch, be prevented from paying for them yourself electronically, having to call in a favor and promise to pay back as soon as you see that friend. Or you just prefer to pay someone cash for…

There are other registrars that support paying for an arbitrary domain without having ownership.

Got an example? And could you use it to pay for my domain, which is not using "your" registrar?

Re: The Passport Payment (2000)

#55
post #54
post #51

Earlier quoted context omitted.

There are other registrars that support paying for an arbitrary domain without having ownership.

Got an example? And could you use it to pay for my domain, which is not using "your" registrar?

> Got an example?

NetSol/Web.com, (maybe) Gandi SAS, easyDNS and (maybe) Tucows

Others may support it by request

> And could you use it to pay for my domain, which is not using "your" registrar?

No

Post reply on HN