Live data from Hacker News

Someone bought 'Google.com' from Google for one minute

finance.yahoo.com

81–90 of 100 posts

Re: Someone bought 'Google.com' from Google for one minute

#82
post #76

In Ireland some one managed to redirect google.ie (The irish google search domain): http://technology.ie/google-ie-hijacked/ The ccTLD register (The IEDR) had a vulnerability in their management portal that was exploited (I believe it was an SQL injection if I recall correctly). The attacker changed the DNS servers to their own and then put an A name record pointing google.ie to their own server. The server just disp…

'their'

Re: Someone bought 'Google.com' from Google for one minute

#83
post #76

In Ireland some one managed to redirect google.ie (The irish google search domain): http://technology.ie/google-ie-hijacked/ The ccTLD register (The IEDR) had a vulnerability in their management portal that was exploited (I believe it was an SQL injection if I recall correctly). The attacker changed the DNS servers to their own and then put an A name record pointing google.ie to their own server. The server just disp…

'their'

Thank you.

Re: Someone bought 'Google.com' from Google for one minute

#84
post #80

Honest question. If he bought the domain from Google and the transaction went through, is that not technically a legitimate transaction and "cancelling" and refunding the money is essentially theft? How is that any different than walking in to someone's house and leaving them $20 for the TV you took? It seems to me that "oops, take-backs" Is not a legitimate enough justification to reverse a transaction under contrac…

There are consumer protection laws that protect both consumers and sellers when mistakes are made like in this case (at least here in Québec and Canada, it must be similar in the US).

Let's say you're selling a 10$ gift card on your website but through some bug/error it's now worth 1000$ (an easy mistake to make, just forget the decimal place). What if someone bought the 1000$ worth gift card for the original intended price of 10$? I'm sure you would invalidate that purchase and send them an email explaining that it was a mistake, and it would be perfectly within your rights to do so.

It goes both ways too, if a mistake is made that advantages the seller, they have to fix it.

Re: Someone bought 'Google.com' from Google for one minute

#85
post #75

finally. i like the idea someone can remove my last purchase and manipulate my account.

It wasn't a valid purchase. What would you expect to happen? Google.com, like the Brooklyn Bridge, isn't for sale.

To expand on this, google.com is registered through MarkMonitor, which is a registrar. Google Domains is also a registrar. A registrar cannot sell a domain that is owned, and certainly not one that is owned by a client on another registrar! There was some error on the Google Domains side that indicated a domain was available for purchase that was in fact not available for purchase. That's it. The money was refunded when the error was reported. It's the only possible sane solution to the problem.

Your comment implies that the sale should have gone through anyway, which is nonsensical. Otherwise we could have situations where I steal foo.bar from you (which you have registered with, say, NameCheap) by buying it through, say, GoDaddy, which is currently experiencing a similar bug that incorrectly marks your domain as available.

Re: Someone bought 'Google.com' from Google for one minute

#87
post #80

Honest question. If he bought the domain from Google and the transaction went through, is that not technically a legitimate transaction and "cancelling" and refunding the money is essentially theft? How is that any different than walking in to someone's house and leaving them $20 for the TV you took? It seems to me that "oops, take-backs" Is not a legitimate enough justification to reverse a transaction under contrac…

Google Domains is not the registrar for google.com. MarkMonitor is. Your situation is analogous to agreeing to buy a deep-discount TV from someone off Craigslist, who meets up with you in a hotel parking lot, goes inside with you, points you to the TV in the lobby that you just "bought" and says take it. That TV was not for sale and the person "selling" it didn't own it. It's unreasonable to expect MarkMonitor to honor a sale that couldn't happen because some other registrar messed up.

Mistakes can and do happen in business all the time, because businesses are composed of people and people aren't perfect. The solution is to deal with mistakes in whatever is the most sane way.

Re: Someone bought 'Google.com' from Google for one minute

#88
post #56
post #55

On the 20.09, I received a totally legit invoice from invoice@google.com (99.99€ Candyclub - Bag of Gems). The sender is invoice@google.com, but no names, no other personal information. I thought it was somewhat strange, and reported it, but no answer.

It's extemely simple to fake the sender of email. That's what probably happened.

Sure, but google uses SPF and DKIM. The spam mail would not validate and be marked as spam.

Re: Someone bought 'Google.com' from Google for one minute

#90
post #79
post #14

Earlier quoted context omitted.

How exactly would that work. modify an instance of bind and check if the client is requesting to resolve 'google.com'? If true, then respond with the rouge IP? First we must make sure the client machine is set up to use our name servers, the ones we have control over.

Never use a rouge IP. They're red for a reason, man.

I'm glad someone else picked up on that! :)
Post reply on HN