5 ms·
Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not
by xsc 6y ago
Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.
- bhartzer 6y agoAgreed, definitely use 2fa if it’s offered. What many people don’t realize is that there are a lot of registrars still using less secure platforms. So moving to a more secure registrar can help as well. I mention registering for 5 years in the future because if something like this happens, there will be no question as to whether or not you lost the domain because it expired.
- pletsch 6y agoAny recommendations on a good registrar?
- sjn 6y agoGandi.net is awesome. (not affiliated, just a happy user)
- throw14082020 6y agonamecheap.com is great (always good prices). Obviously, never go with Godaddy.com (rip offs)
- _wldu 6y agoGandi.net
- jimsmart 6y agoWe've been using joker.com for years.
- pyyu 6y agojoker.com, inwx.com ,namesilo.com, register4less.com, epag.de, iwantmyname.com, hover.com, Porkbun.com, www.nearlyfreespeech.net .name domain isn't available in some of these, decide to use inwx.com
- tialaramex 6y agoI'm actually not sure for this type of attack how much I'd value OTP authenticators over SMS. They are both vulnerable to phishing in the same way. What I'd like to see a lot more of is WebAuthn specifically, rather than "hardware keys" generally. It's frustrating to me that the outfits I deal with only have OTP and not WebAuthn.
- everybodyknows 6y agoAnyone have a short list of registrars who support Yubikey (or competitors)?
- blowfish721 6y agoGandi.net seems to support it https://www.yubico.com/works-with-yubikey/catalog/gandi-net/ https://www.yubico.com/works-with-yubikey/catalog/gandi-net/ There’s a short list found here with supported sites including registrars https://www.yubico.com/works-with-yubikey/catalog/ https://www.yubico.com/works-with-yubikey/catalog/
- alfiedotwtf 6y agoWhen 2FA is not enough... https://fastmail.blog/2014/04/10/when-two-factor-authentication-is-not-enough/ https://fastmail.blog/2014/04/10/when-two-factor-authenticat...
- fckthisguy 6y agoThey do, I use it.
- pavel_lishin 6y agoTo phishing, yes, but not to SIM card cloning/social engineering your cell phone provider shenanigans.
- chaz6 6y agoI use Gandi which supports 2FA, but annoyingly they do not let you disable TOTP if you want to use U2F.
- fckthisguy 6y agoI've found that to be pretty common. I guess sites don't want to risk you losing your hardware and then not having a backup method.
- technion 6y agoThis actually rules out a substantive number of registrars. I have a statement from an account manager at our wholesale supplier arguing that the requirement to know both the email address and password is considered "two factor" in the industry. I don't see why offering MFA hasn't been made a requirement in order to be an accredited domain registrar.
- LordAtlas 6y agoWhich registrars do you recommend that have 2FA?