4 ms·
As someone in the domain registrar industry, are there any features beyond 2FA that you would like to see implemented by registrars? More bluntly, what is it t
by jqueryin 10y ago
As someone in the domain registrar industry, are there any features beyond 2FA that you would like to see implemented by registrars?
More bluntly, what is it that you think your current registrar is lacking?
I read a few comments on Gandi and support of GPG keys. I'm guessing this is what you're referring to:
https://wiki.gandi.net/en/gandi/documents https://wiki.gandi.net/en/gandi/documents
- bhartzer 10y agoI have seen some registrars offer USB devices that must be plugged into a laptop in order to gain access to an account.
- tamar 10y agoHey Bill - when I was remote staff at AOL in the 90s, we had SecurIDs too (which is basically a key fob with 6 numbers that changed every 60 seconds, pretty reminiscent of 2FA on phones/Authy/Google Authenticator). Problem is if you lose that, you're not able to get into your account...
- extrapickles 10y agoI would like to see something where a postcard is mailed and a phone call, each with half of the code needed for a reset. Postcard should not be sent using a method that supports forwarding so an attacker cannot setup a mail forward. Customer support should not be able to see anything about these accounts except for a reset button. I do expect to be charge a fee for a reset if I need to use it. This would need to be rate limited to prevent people from dosing an account through it.
- PhantomGremlin 10y agoa postcard is mailed If you want them to go thru the trouble of mailing something, at least require it to be a letter. Inside an opaque envelope. A postcard is the exact opposite of something you want to use to send sensitive information.
- darkhorn 10y agoI would like to see more use of client side certificates.
- 9248 10y agoI would like to see more control options for the end users. Let users chose if their account can be recovered through a password reset form, let users leave 'secret memos' for support which can't be viewed on the site later, let the users decide if their accounts can be altered in any way by support staff, etc, etc.