Live data from Hacker News

Before you buy a domain name, first check to see if it's haunted

bryanbraun.com

81–90 of 195 posts

Re: Before you buy a domain name, first check to see if it's haunted

#81
post #48
post #42

"Ideally, search engine algorithms would give new domain owners a fresh start." I don't think it's possible to fix this problem without also helping bad actors. Maybe it's a problem that just isn't worth fixing. Just don't buy preexisting domains unless it's a project big enough to justify the necessary cost of due diligence.

"Maybe it's a problem that just isn't worth fixing." There is a finite amount of short, memorisable names.

But also an ever-increasing number of TLDs under which to register them.

Re: Before you buy a domain name, first check to see if it's haunted

#82
I have a lot of sites (all saas) and more and more people send me cease and desists and lawyer threats because they go to google, enter 'something' that's remotely phonetically similar to a domain I run and then click on my site. They paid on some site that sounds a LITTLE bit (if you squint) like my domain and now they are scammed and want to sue me. Now I understand scammers do this as well, but I had actually someone turn up at our office (which is my business partner his home) with bank receipts with a really not so similar name, however if you type it in google we pop up first even though our businesses are not at all related.

Re: Before you buy a domain name, first check to see if it's haunted

#83
post #69

Earlier quoted context omitted.

That’s pretty much what happened to those domains.

No, those domains are completely fine, they are just marked as untrustworthy on some obscure google list.

That’s a contradictory statement.

Re: Before you buy a domain name, first check to see if it's haunted

#84

Earlier quoted context omitted.

Require a deposit then, say 1000$, that is to be refunded after a year of probationary period. You get caught being a scammer/spammer, you lose the deposit.

The deposit would be either too high for normal people to pay, or too low to matter to bad actors

Given that spammers cycle through thousands of domains, they'd run into serious cash flow issues very soon.

Re: Before you buy a domain name, first check to see if it's haunted

#85
post #70

Also be careful connecting new domains to cloudflare. It has a habit of adding old info from presumably a previous owner. Managed to get a takedown notice thanks to that idiotic "feature" while not even aware the domain is serving anything

Please drop me an email with what you’re seeing - justin (at) cloudflare.com ?

That doesn’t sound like old info - that sounds like someone might still be reporting it for abuse even after the domain changed owners.

Re: Before you buy a domain name, first check to see if it's haunted

#86

Earlier quoted context omitted.

So much of the world is still based on who you know. This is a bug in our society I would really, really like to see fixed in my lifetime.

Sadly, the most likely "fix" would be to remove the "who you know" path and just make things shit for everyone. :(

But would that not introduce pressure for the official paths to become better oiled and working better than before?

Re: Before you buy a domain name, first check to see if it's haunted

#87
Another variant of this is cached or preloaded security configurations.

HSTS (which forces browsers to validate HTTPS when connecting) asks browsers to cache the configuration for a set "max-age". Some sites set huge values here, like Twitter's 20 year max-age[1]. There's also the preload lists [2] to consider. This creates a problem if you want to serve non-HTTPS/unencrypted HTTP on your new domain and the previous owner didn't.

MTA-STS [3] is another variant that's becoming more popular. It limits which mail servers your domain uses and enforces TLS certificate verification. "max_age" is capped to a year by the RFC. If you don't set your own policy, then the previous domain owners policy would impact any senders who previously cached the policy.

Thankfully HPKP (key pinning) is obsolete, otherwise you'd also need to worry about old pinned keys too. That RFC recommended, but did not enforce, a 60 day max-age limit.

These are especially tricky as the old security policy only lives in the caches of any end-user devices that previously connected to the domain. Double haunted.

[1] https://alexsci.com/blog/hsts-adoption/

[2] https://hstspreload.org/

[3] https://alexsci.com/blog/smtp-downgrade-attacks-and-mta-sts/

Re: Before you buy a domain name, first check to see if it's haunted

#88
post #53

> Ideally, search engine algorithms would give new domain owners a fresh start. Sadly, I think this would be instantly gamed by abusers. They would release the domain name and attempt to register as a new owner or start repeatedly doing handoffs. It's difficult to tell who the owner is changing between and whether or not the new one is a better actor than the former.

If it's instantly released, then yes. But in this thread are reports where the offensive actions happened 15 years ago. After such a long time of "good behavior" it makes no sense for me to still keep the domain blocked/downranked.

Honestly, these days, with domains in general being nearly free compared to the profit potential of a single successful spammer grift, I’m not sure I even see the point of blacklisting domains at all. 25 years ago maybe a spammer would be devastated that he had to “start all over and buy a new domain and build up its reputation.” Now, spammers launch and abandon what, a million new domains a day? Google or anyone spitefully holding onto hard feelings about what a domain “did” years ago is pointless because the spammers will move on anyway. They wouldn’t reuse abcqwertuiop26abc dot xyz anyway because it’s safer to make up a new gibberish domain anyway. Only people who acquire domains legitimately are hurt by this.

I would want to experiment judging them based on what they’ve been seen to do in the past month.

Re: Before you buy a domain name, first check to see if it's haunted

#89
post #42

"Ideally, search engine algorithms would give new domain owners a fresh start." I don't think it's possible to fix this problem without also helping bad actors. Maybe it's a problem that just isn't worth fixing. Just don't buy preexisting domains unless it's a project big enough to justify the necessary cost of due diligence.

The really bad actors just buy and discard new domains daily and silly blacklisting techniques are powerless to prevent that. I don’t think they renew and come back to try to use their domains years later.

Re: Before you buy a domain name, first check to see if it's haunted

#90
post #30

Earlier quoted context omitted.

I'd be somewhat interested in seeing the cels. :)

https://www.neotokyo.com I have a +100 cel backlog that I need to catalog and photograph. Was planning to do it this holiday season so check back in.

I... actually remember that address floating around and it indeed was hentai.

We're talking like 20 years back. Holy shit, my brain is getting jostled by this sudden tsunami of forgotten memories.

EDIT: Digging around on Wayback Machine (obviously NSFW, for the curious), apparently it was actually still around until somewhere between 2018 and '19 when it finally died. The snapshots from around 2007 are peak Web 1.5 design with stuff like affiliate buttons and table layouts. Man I miss that era.

Post reply on HN