Live data from Hacker News

As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

blog.easydns.org

51–60 of 71 posts

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#51

The domain name industry is a dirty scummy dishonest business. There isn't a company one can deal with that at some point won't make you feel like you're forced to work with crooks just to get an online presence.

Don't tell my mom I'm a domain registrar! She thinks I'm a webmaster for a cyberporn website.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#52
A troll once tried to take one of my websites off-line by reporting to ICANN that the whois info was fake:

http://www.icann.org/en/resources/compliance/complaints/whoi...

That was... interesting.

Good timing on the troll's part as I was migrating from 123-reg to Gandi at just that moment and had to persuade both of them that I was who I said I was and that the info was correct.

If I recall correctly it involved proof that there was a company behind it (company registration documents), proof that the address for the company was correct, and proof that I worked for the company and had the right to represent it.

It's pretty scary to think that your domain might be pulled, and the web properties and email with it, based on a third party report.

At least with this proposal a 15-day window to verify details when you change info is an expected thing.

Oh, and ICANN sent the notification via the registrar to the admin email on the domain... make sure you're monitoring all of those email addresses.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#53

Earlier quoted context omitted.

google.com appears to use a google.com email address in its DNS record.

Google probably have a real live person they can call if this gets messed up, or even has the potential to get messed up a few months from now.

They are also a registrar.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#55
post #34

Earlier quoted context omitted.

To honestly answer your question: the we you refer to isn't in control / power. The system is centralized because the control over nations is centralized. It will remain that way so long as political power remains centralized. Particularly given the immense importance of the internet economy now to most major nations. The political powers that be are not about to let go of something so important. The domain name syst…

What is to prevent an open source DNS server to be deployed all around the world by various people? And browser makers would just add it to the list of servers once it gets big enough. Until then, people could download a program or instructions that would add it, similarly to Google's DNS or OpenDNS Except it would not use the regular DNS system on the back end, but supplement it with its own rules eg not taking a do…

Nothing except inertia. There are many alternative root operators. It's just that none of them have managed to convince enough people to use them.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#56
post #6

The title is pretty much linkbait. If you change registrar-level things about your domain, they're now required to confirm your contact info with you. This isn't a "DDoS", or "deadly", or any of that nonsense: it's a new strategy to ensure whois data stays updated. Whether or not it's an effective strategy for keeping whois data accurate is another debate (I don't think it is), but talking about it like some maliciou…

If you knew any of the people involved in pushing the agenda that lead to the policy, you wouldn't be so quick to discount the view that this is a malicious act.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#57

This is apparently so the physical mail spammers can send me more physical mail along the lines of "This is the Domain Registry of America! Pay us $1000 to keep your domain!" Uh, no. Where's the FTC when I need it...

I got email from the people who run .us domains demanding a photo of my driver's license to prove I'm American. They did not understand why I might think they were scammers and want them to verify their identity first, nor did they understand how to verify their identity.

I would love to hear how that played out, actually, if you don't mind.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#58
post #39

ICANN is a mafia! They did this to actually force some old domains to get back into the market. ICANN as an organization will profit little from this, but the people bribing them (domainers, auction sites, domain escrows, etc.) will vastly profit from it. Imagine what would happen if somebody sends you a letter and they get back a letter saying that you cannot receive the letter as you didn't verify your name with US…

Actually, this whole this was included under pressure from law enforcement agencies (LEAs). Registrars, registries, and ICANN themselves would much prefer we stuck with the old WDRP regime where all that happens is that the registrars periodically ask that registrants verify that the information provided is correct. This new LEA-mandated nonsense is nothing but a drain on registrars (which is a business with thin margins as it is).

Also, redemption isn't a scam, it's a fine to discourage people from making ridiculously late payment! You're given a 45 day window after a domain expires to pay for the renewal before the domain ends up in redemption, and registrars are required to send at least three separate reminder emails at specific intervals to tell you the domain is expiring or has expired. If you can't pay your bills within 45 days, ICANN, the registries, and the registrars aren't the problem: you're own incompetence is the problem.

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#59
post #16

Everyone who's already screwed themselves with domains by proxy is in for a new world of hurt.

If you're talking about the GoDaddy service, they're not. If you're talking about WHOIS privacy services in general, then possibly.

If you use a registrar's WHOIS privacy service, then the registrar still has the (supposedly) correct details and are simply masking them in WHOIS. There's no issue there. However, if you're not using the registrar's own WHOIS privacy service, then yeah, you're potentially opening yourself up to a world of pain, as (a) the domain is no longer actually registered to you in a manner verifiable to the registrar and (b) you might not be able to receive important notification emails that the registrar is required to send you (such as expiry notices).

Re: As Deadly as a DDoS: ICANN Unleashes the Whois Accuracy Program

#60
post #4

Earlier quoted context omitted.

I got such an email from Namecheap yesterday, and confirmed it with one click. And unlike the intended trigger for verification ("changes to contact information"), I didn't make any changes to my domain. Either a WHOIS cloak expired, or some other action by Namecheap triggered the verification step.

The email Namecheap sends out is very shady looking. I had to google around quite a bit before concluding it was genuine. The verification link leads to the domain raa.name-services.com and is not delivered over https. It looks exactly like I imagine a targeted phishing email to look.

It's not Namecheap sending those out: Namecheap is simply an eNom reseller and the email you received was likely directly from eNom, with some Namecheap branding attached. *.name-services.com is used for various eNom-related stuff.
Post reply on HN