Live data from Hacker News

Name.com hijacks non-existent subdomains and redirects to their servers

destructuring.net

51–60 of 93 posts

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#51
post #45

Earlier quoted context omitted.

name.com is very usable and otherwise handy; I don't like this policy, but I wouldn't wish GoDaddy on my worst enemy. (OK, maybe I would) EDIT: I really don't understand your thinking; I am the opposite. I respect name.com for being forward about it and not acting like a politician (treating me like a child).

> I really don't understand your thinking; I am the opposite. I respect name.com for being forward about it and not acting like a politician (treating me like a child). I respect them for sharing their reasons. I think it is professional. My issue is two fold: - This kind of activity "breaks the internet" on the purest sense possible. It is against spec' for a very good reason, IT IS STUPID. Going to a null domain sh…

> - Their work-around(s) are silly. They are essentially "then use someone else" or "register every single possible sub-domain." No opt-out.

"Use someone else" is the opt-out, whether you take it to mean "use another registrar" or use "other, non-gratis DNS services.

Your other option is to use a wildcard, as I think you understand (though your "register every single possible sub-domain" is a bit misleading).

This behavior sucks, but if it's something that bothers you, you're probably the type that should be using a better DNS provider, anyways. That said, I'm a happy customer of name.com.

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#52

My workaround for this was to add a TXT record for *.mydomain.com that just returns a string like "Unused". This seems to stop them from hijacking any subdomains, and it's not an A record so undefined subdomain names do not resolve, just like if you had not defined them in the first place. (Workaround shouldn't be necessary of course, but this kind of bullshit is par for the course with cheap hosting companies.)

I typically just do a *.example.com @A record to the IP address, works just as well and would fix the specific problem in the link (unless he's worried about having to extract individual subdomains to go separate places later).

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#53

Earlier quoted context omitted.

What do you mean? I believed their explanation but wanted to leave anyways. I don't want them redirecting my domains regardless of intent.

I moved quite a few domains to Hover within the last 2 months. I went and immediately checked the forwards section after reading your comment. Thankfully, there are ZERO forwards setup. I'm guessing they stopped pre-configuring example forwards for demonstration purposes.

They did. I use Hover now, and while they still have a dumb landing page for unused subdomains (which I disable immediately on first login), they aren't doing the forwards by default.

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#54
post #48
post #42

I ran into the same issue several years ago. Now I actively recommend against name.com because of this practice, which I consider very dodgy. Their support was unable to provide any real resolution to this and so I moved elsewhere. On recollection, I should have asked for my money back. Not for the meaningful amount that it cost, but to highlight how stupid this practice is. I'd encourage anyone with name.com to do t…

DNS aside, Name.com is one of the only registrars I know of with reasonable security practices. They support two-factor auth (almost no one else does), and have nicely scoped cookies (HTTP only, Secure flag, etc.).

The irony is that their actions can in fact make cookies their customers are using for their sites invulnerable.

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#55

My workaround for this was to add a TXT record for *.mydomain.com that just returns a string like "Unused". This seems to stop them from hijacking any subdomains, and it's not an A record so undefined subdomain names do not resolve, just like if you had not defined them in the first place. (Workaround shouldn't be necessary of course, but this kind of bullshit is par for the course with cheap hosting companies.)

A workaround? As opposed to simply switching registrars with something decent?

yeah, the best workaround is namecheap.com

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#56
post #51

Earlier quoted context omitted.

> I really don't understand your thinking; I am the opposite. I respect name.com for being forward about it and not acting like a politician (treating me like a child). I respect them for sharing their reasons. I think it is professional. My issue is two fold: - This kind of activity "breaks the internet" on the purest sense possible. It is against spec' for a very good reason, IT IS STUPID. Going to a null domain sh…

> - Their work-around(s) are silly. They are essentially "then use someone else" or "register every single possible sub-domain." No opt-out. "Use someone else" is the opt-out, whether you take it to mean "use another registrar" or use "other, non-gratis DNS services. Your other option is to use a wildcard, as I think you understand (though your "register every single possible sub-domain" is a bit misleading). This be…

Using a different nameservice provider only treats the symptom. Name.com is still breaking the internet with this practice.

Re: Name.com hijacks non-existent subdomains and redirects to their servers

#60
post #48

Earlier quoted context omitted.

DNS aside, Name.com is one of the only registrars I know of with reasonable security practices. They support two-factor auth (almost no one else does), and have nicely scoped cookies (HTTP only, Secure flag, etc.).

The irony is that their actions can in fact make cookies their customers are using for their sites invulnerable.

I don't understand what you are saying ? Is it that there is a security issue arising from the DNS hijacking ? If so what's the issue ?
Post reply on HN