Live data from Hacker News

Never buy a .online domain

0xsid.com

501–510 of 513 posts

Re: Never buy a .online domain

#502

Earlier quoted context omitted.

You document your claims with concrete evidence of fraud. That will be your libel defense. No evidence means you bear the full responsibility of a fuckup.

At internet scale, this would roughly be equivalent to not doing any warning or detection at all. Scalable systems need to use heuristics to catch threats. Needing concrete evidence in every case means that an enormously higher amount of malicious resources will not be flagged. There is a policy argument as to the right balance of concerns here. But there is a clear trade-off to make.

No one elected Google to be the internet police. Why should we legally protect vigilantism on the web any more than we do in real life?

Re: Never buy a .online domain

#503

Earlier quoted context omitted.

> Fundamentally, this was google's fault for misusing a recovery email for 2FA. While this would absolutely suck and I sympathise with anyone getting hit by this out of the blue, it's pretty clearly your fault, not Google's. What should they have done? Just permit everyone to avoid upgrading to 2FA indefinitely? That would result in relatively more account hacks overall, for which they would inevitably be roasted in…

I doubt anyone would blame google for not forcibly enabling 2fa.

I think it's similar to, say, serving raw HTTP instead of HTTPS. If, say, Facebook still served HTTP and people were getting their passwords swiped, Meta would be in the crosshairs.

Even though you could say a person getting their 1FA account details phished is technically "their own fault", certainly to a greater extent than my HTTP example, spending the time understanding the issue well enough to realise that it was their own fault and not BigRichCompany's fault is not high on most people's list of fun things to do.

Re: Never buy a .online domain

#504

Earlier quoted context omitted.

As someone who has also been bit by this, and with the only possible resolution being that I sign up for google services and register my site with them in the google search dashboard... Fuck Google. This is absolutely libel. They put a big fucking red banner on top of my site, telling the world that it's unsafe, using all the authority they have as one of the largest tech companies in the world. In my case - it was a…

There’s nothing wrong with your dislike of Google. No matter how much you dislike them, though, the word “libel” has a meaning that should be respected. To opine that a site is unsafe is simply not libelous.

Sure it is - it's factually incorrect, misleading, and has an impact to my reputation.

> Libel is the publication of writing, pictures, cartoons, or any other medium that expose a person to public hatred, shame, disgrace, or ridicule, or induce an ill opinion of a person, and are not true

They literally show a giant red banner to every user of their browser that tries to access my site, calling me unsafe. Which is factually incorrect, and absolutely induces a negative opinion.

There's nothing on my site except a login page, it wasn't compromised, and it wasn't available for public access or registration. They can't "opine" on safety - it's just factually incorrect.

Convenient for them that the only way to resolve the issue is to sign up for Google products, though. Wonder how that works...

---

Next you'll try telling me that calling someone a cheat is also just an opinion, but it's standard legal libel.

Re: Never buy a .online domain

#505

Earlier quoted context omitted.

You don't. Google has to prove that something on that domain can cause harm.

I'm afraid that's not how it works in modern law in the U.S.: "In addition to establishing that the defendant was aware of his statement's defamatory meaning, the plaintiff also must show that the defamatory statement is false. The falsity requirement has evolved gradually through a two-step process. Initially, the courts recognized that truth was a defense in a defamation suit. With time, however, the burden of proo…

You'd enumerate the resources the server sends, for a typical page load/request and demonstrate they're all valid js/css/html etc.

If a typical page can be shown to be prima facie safe to well formed parsers, without obvious shell code. It would require a response if there was additional evidence google was using in their determination.

Re: Never buy a .online domain

#506

Earlier quoted context omitted.

I’m a different person, but this happens to me, too. I have the kstrauser@yahoo.com email address because I signed up for it like 25 years ago. I log in every 6 months to see what the few other kstrausers in the world have signed me up for. Not jsmith, but kstrauser. Not Gmail, but Yahoo. And I still get banking docs, and HOA meeting minutes, and birthday party invitations, and Facebook logins, and other bizarre rand…

Yeah I have josephg@gmail. The amount of spam that account gets is wild - about 50-100 emails hit the inbox per day. I got soft-locked out of google docs a few months ago because my google account's 25gb quota was exhausted. Some of the emails are really unfortunate stuff. "Your account was added as a backup address." - Then inevitably, a few weeks later, dozens of password reset emails. Sorry bud. I've received pay…

Some of these banks are ridiculous. HDFC bank insists that I send them my photo id, address, phone number, and my Indian id number to prove that I'm not their customer. I tried explaining that I don't have an Indian id number because I don't live in India but they insisted they can't help me unless I provide all of this. Then they sent me legal notices threatening me for not paying "my" bills. I send all their stuff to spam now.

Re: Never buy a .online domain

#507

Earlier quoted context omitted.

> Fundamentally, this was google's fault for misusing a recovery email for 2FA. While this would absolutely suck and I sympathise with anyone getting hit by this out of the blue, it's pretty clearly your fault, not Google's. What should they have done? Just permit everyone to avoid upgrading to 2FA indefinitely? That would result in relatively more account hacks overall, for which they would inevitably be roasted in…

The only reason Google does that 2FA dance is to get your phone number 'cuz it tends to be a very strong persistent marker which is very useful for... advertisement.

I have the same suspicion in general, but isn't it possible to use an authenticator app as the second factor instead of a phone number?

Re: Never buy a .online domain

#508
Hi Sid,

We understand how frustrating it can be when a domain stops resolving unexpectedly. We’ve sent you an email with more details on what happened and the steps taken so far. We’re also reviewing this internally to understand why the domain was flagged and how we can reduce friction in similar cases going forward. We’re happy to continue the conversation over email and share any additional context if helpful.

Thank you.

Re: Never buy a .online domain

#509

Earlier quoted context omitted.

The only reason Google does that 2FA dance is to get your phone number 'cuz it tends to be a very strong persistent marker which is very useful for... advertisement.

I have the same suspicion in general, but isn't it possible to use an authenticator app as the second factor instead of a phone number?

Try to register a new account without a phone number.

Re: Never buy a .online domain

#510
post #424

Earlier quoted context omitted.

People often have trouble with this saying, and that trouble often boils down to the difference between intent and purpose. The people who create a system have some intent for it. The system may or may not effectively achieve that intent, may or may not outlive the initial conditions that surrounded its creation, and may or may not have side effects. Purpose is something humans assign. It is sometimes linked to inten…

Sometimes intent and outcomes matter, but the aphorism is simply not a good guide to understanding reality. It should be discarded. The classic example is a hospital for treating cancer patients. Suppose that one third of the patients are successfully treated, while the other two thirds die of their cancer. Is the purpose of the hospital to kill two thirds of the patients? Clearly not, but that is the outcome.

No, that is not what the hospital does, and thus based on this heuristic, it is not its purpose. What a system does is not the same as the context-free outcome. It is the outcome compared to the outcome that could be expected without the system. You have to define your priors.

However, if the expected 5 year mortality for the cancer was 50%, and with this treatment 2/3 died, then the rule would apply. A choice to continue using that treatment could be criticized as equivalent to a choice to kill 1/6 more patients. Because despite the intention, the known outcome was more patients dying.

Post reply on HN