7 ms·
DNS hijacked on GoDaddy?
- kube-system 6y agoHonestly, it seems like this headline pops up at least once per year. I switched to another registrar close to a decade ago because of security concerns.
- Waterluvian 6y agoI thought GoDaddy was an industry pariah, avoided by anyone who knows anything. What's the motivation to use them beyond saving a few dollars? Do they have a monopoly on certain domains?
- BoysenberryPi 6y ago> avoided by anyone who knows anything Most people don't know anything. The 99.9% of people buying domains don't browse Hacker News or stay privy of news regarding domain registrars.
- dhnajsjdnd 6y agoThey do a lot of marketing, which makes them the default choice for many.
- strombofulous 6y agoFwiw you don't save a few dollars with GD, they have terrible pricing. The only - only - thing they have is a big advertising budget. Their services, support, pricing, ... all bad
- abaga129 6y agoI use GD simply because their advertising worked. When I registered my first domain I didn't know where else to start and just haven't bothered to transfer to another provider.
- markdown 6y agoAccording to the Twitter thread, Microsoft made a deal with Godaddy that makes them the default domain registrar for Office360.
- nly 6y agoNot just the default..you can't use O365 Premium with your own domain name at all unless you transfer it to GoDaddy.
- Nextgrid 6y agoMany non-technical founders go to them for the domain. By the time technical people (who know better) are involved the domain is already purchased and presumably transferring it out isn't prioritized.
- partiallypro 6y agoI personally use NameCheap, but my company uses GoDaddy and has since before I got there...and the company we bought? Also uses GoDaddy. In total that is about 2000 domains. Transferring them would cost a lot of money and time and in the end is not worth it to save over the long run.
- cgtyoder 6y agoPotentially getting their DNS redirected would cost even more. (Also there are no "transfer fees" - although maybe GD unscrupulously does that?) So it's only a time consideration.
- ficklepickle 6y agoYou actually pay a years domain fee typically upon transfer. So it is best to transfer near your regular renewal time. I just went through this transferring a domain from GD to namecheap.
- TedDoesntTalk 6y agoGoDaddy has been caught registering domains that users search for on their site. Search to see if wowlolkittenseatingpizzaarecool.com is available. It is available and you dont buy it. Check tomorrow. It is not available but you can buy it drom the owner for $99 instead of $8. Dirty
- dole 6y agoThis is known as Domain Name Front Running and I think their evidence/excuse was that they publicize what gets searched and others buy them. http://en.wikipedia.org/wiki/Domain_name_front_running http://en.wikipedia.org/wiki/Domain_name_front_running
- baxtr 6y agoSo what’s the best alternative to GD? I use moniker for some domains and I am happy.
- speedgoose 6y agoI don't think there is a best one but better ones. Personally I use Gandi when I want to pay a bit more to have a user friendly interface and support. When I just need a domain for myself I use bookmyname because it can't be cheaper and the old interface is fine for me. If you are already sending your money to Amazon, AWS Route 53 is also a good alternative.
- srockets 6y agoAWS Route 53 is a Gandi reseller for most TLDs. As far as I can tell[0], only .com, .net and .org are registered directly with Amazon. -- [0] https://www.google.com/search?q=%22The+registrar+for+this+TLD+is+Amazon+Registrar,+Inc.%22+site:docs.aws.amazon.com&filter=0 https://www.google.com/search?q=%22The+registrar+for+this+TL...
- mech422 6y agoI've been really happy with EasyDNS over the past 10-20 years... definitely not the cheapest registrar but well worth it in my opinion. They offer several pricing plans, but I like the $40/year registration and backup mail spool. If your main MX server goes down, I believe they hold your email on the secondary for up to a week? Cheap insurance at $3/month. Been very happy with support (live person picks up the phone, and generally is an engineer). Web interface is nice, they support standard privacy screen functions for whois, and generally seem to be good people. My only affiliation with them is as a happy customer.
- wetpaws 6y agoI had the least problems with porkbun so far.
- cgtyoder 6y agoI have been using joker.com for ~20 years for several dozen domains, and have never had a problem. Based in Germany, works very well.
- technion 6y agoIn a lot of my experience, tech people first hear about a new domain when someone in marketing says "we're launching a new x. I've already done a lot of work by going to GoDaddy and buying the domain. You should be able to finish the web and services from here now that all the hard works done". You can't transfer a domain within 60 days of purchase so I usually end up going live with services there.
- glaive123 6y agoProbably because people just complain about Godaddy but don't recommend alternatives and explain why they are trustworthy/better. Who do you use and why?
- ironmagma 6y agoNearlyFreeSpeech.net is great. They don’t upsell you, there are no ads, whois privacy is easy, and everything just works.
- viraptor 6y agoThere's a common list of providers mentioned every time on similar articles. Gandi, namecheap, dnssimple, and a few others. + all the usual cloud providers and CloudFlare.
- RealStickman_ 6y agoPorkbun is also recommended usually.
- forty 6y agoI see recommendation very regularly here. I use Gandi.net and they are great, but I also regularly see namecheap being recommended (I never used them though, in my book "cheap" means low quality ^^ I'm French and the English word is often used that way :) )
- ketamine__ 6y agoSo the big shots in crypto still don't understand how to secure their coins?
- Triv888 6y agoI only have a few dollars, but I keep mine offline gpg encrypted... when I don't need them
- gruez 6y agoWhat gave you the impression that coins were stolen? The twitter thread only mentioned that a few people's domains were hijacked, and that the victims all had their emails (and hence domains) exposed in a recent hack/leak of Ledger. It's conceivable that after hijacking a domain, you can gain access to the victim's cryptocurrency exchange account via password reset email and steal coins that way, but most exchange I know require multiple factors (eg. passport scans, phone/sms verification, waiting periods, security questions, etc.) so a hijacked email isn't going to do much.
- ketamine__ 6y agoThere is a security solution that is much stronger than 2FA, passport, etc. It's called a hardware wallet.
- gruez 6y agoThat's true, but where in my comment does it suggest that keeping coins on an exchange account is a good idea? If you're a bitcoin whale, there's invariably going to be a decent amount of coins worth stealing on an exchange account somewhere. The only reason exchange accounts were brought up is that's the only conceivable way a domain compromise can lead to coins being stolen.
- echelon 6y agoBack when I was a college student, my popular video game wiki's domain [1] was stolen by a former associate of mine while I was overseas. Godaddy did nothing to help the situation, and the thief had substantial monetary resources and threatened to get me tied up in court. He was ten years older, had an engineering income, and came from a family of lawyers. I was just a college student and felt powerless to do anything about it. I assume it was social engineering. He had access to the server and database, but was never supposed to have domain name access. Godaddy sucks. Also, their founder kills elephants for sport. So there's that too. [1] strategywiki.org
- nathanyz 6y agoWonder if this is any way related to the 13 hour outage[1] at Wasabi storage related to GoDaddy? [1] https://news.ycombinator.com/item?id=25567294 https://news.ycombinator.com/item?id=25567294
- donmcronald 6y agoNo, not according to Wasabi’s incident page. It’s pretty funny though to see GoDaddy suspending domains for abuse when they can’t get their own house in order. Also, who made GoDaddy the content police? I didn’t think domains were that easy to suspend. Is that just a GoDaddy thing?
- idorosen 6y agoWhat registrar do people recommend these days for domain registration that's (more?) secure against domain theft attack vectors? Namecheap? Gandi? MarkMonitor? One of the cloud providers?
- ampdepolymerase 6y agoI don't think MarkMonitor is for casual domain owners.
- jsharkey 6y agoNamecheap is excellent and they have solid YubiKey support. Plus whois privacy proxy service included for free.
- EvangelicalPig 6y agoI've been concerned about NameCheap since this alleged incident occurred https://news.ycombinator.com/item?id=18063667 https://news.ycombinator.com/item?id=18063667
- axaxs 6y agoI use and like Gandi. If you're worried about social engineering though, I'd probably go Google since they would be the hardest for someone to get ahold of.
- grapehut 6y agoI had my domain taken over while on Gandi. Interestingly they didn't do it via customer support, but instead were directly in contact with Gandi's legal department. Their legal guys approved the request/order without thinking to actually verify anything at all. Funnily enough, I had way more trouble getting my domain back than the people who stole it. As far as I can tell, Google, Cloudflare and Namecheap are really the only guys in town that don't fall for stupid shit.
- EvangelicalPig 6y ago
- tmk1108 6y agoReading the Twitter thread, what's the current best security practices for email addresses? Because I thought getting your own domain was the better thing to do but it seemed in this case using a Gmail address would have been better?
- ttul 6y agoIf you want your domain to be safe from compromise via social engineering of the registrar, then use a registrar with a strong security policy. GoDaddy is a mass market registrar with tens of millions of customers for whom security is not their top concern. Cloudflare offers a security-oriented registrar service that is also extremely affordable. I would recommend using them. https://www.cloudflare.com/en-ca/products/registrar/ https://www.cloudflare.com/en-ca/products/registrar/
- illiniboy 6y agoWill 2FA and having a customer support PIN set up prevent this hijacking with GoDaddy?
- LinuxBender 6y ago2FA reduces the changes of someone logging into your registrars web interface as you. It does not prevent actual hacking, an inept or malicious employee or someone operating a compromised registrar.
- dpcan 6y agoI think it boils down to a shitty employee at the end of the day. If you have someone who decides to cut even 1 corner, it can be devastating to a domain owner. I have hundreds of clients who have used them, and I've never been on the phone with GoDaddy and had them do any less than tell me to bug off if I don't have a pin or get the 2-factor auth code to verify myself.
- billp3 6y agoSomething doesn't add up here. His nameservers have been set to DigitalOcean servers for well over a year. A GoDaddy rep wouldn't be able to change MX records on those nameservers. They would have to change the nameservers on his domain to GoDaddy servers and then add new MX records. That's more than just a simple MX record change and seems more unlikely to me. Perhaps his DigitalOcean account was compromised?
- viraptor 6y agoThey could change the NS to point to the attacker's server. That one would respond to the MX queries with the new hostname and forward everything else to the original DNS server, ensuring no other differences are noticed.