4 ms·
It sound like they’re hosting at the same place (gandi) where they registered the domain. This is absolutely never recommended, for security purposes. If someon
by bhartzer 4y ago
It sound like they’re hosting at the same place (gandi) where they registered the domain. This is absolutely never recommended, for security purposes. If someone gains access to your hosting account you’ll likely lose all your domain names.
Transfer the domains over to a better more secure registrar. Then set up a server or vps and set up as many mailboxes or emails that you need.
- justeleblanc 4y agoIs there any indication that Gandi is insecure?
- mbreese 4y agoNot that I know of, it’s just good practice to separate services like this (even if it can be more expensive and logistically difficult).
- justeleblanc 4y agoI'm asking because the GGP wrote "better more secure registrar". Since I'm using Gandi right now (and I don't care about their mailbox offer), I wanted to know if it was really insecure.
- judge2020 4y agoGGP said hosting, but I think they mean email hosting. Even if you keep your actual registrar account @gmail or anther third-party, it's not recommended to handle your registrar, DNS, and email in the same place, since a compromise of any of them is likely to lead to compromise of the other systems (eg. an attacker gains admin permissions on the website / backend and uses it to reset your email password and download your email inbox)
- justeleblanc 4y agoI'm sorry but I don't understand what you're saying. The sentence was literally "Transfer the domains over to a better more secure registrar." This is about domain names and registrars and it's implying that Gandi is insecure. Your point about putting your eggs in the same basket is a different point.
- Tijdreiziger 4y agoAren't these orthogonal concerns? registrar or DNS gets hacked -> attacker can receive mail as you (by transferring your domain or changing your MX record) e-mail host gets hacked -> attacker can download your inbox both -> both
- jeffreyrogers 4y agoIs there not some way to undue that? I'm sure it would be a hassle, but hacking someone's account and transferring their domain name is a crime, it also leaves a very obvious paper trail. Seems like the registrars involved would be willing to reverse transfers under such circumstances.
- TylerE 4y agoSeems like the definition of a pyrrhic victory.
- devmor 4y agoAnd until that reversal is done, you've exposed all the users of your domains (including yourself) to security issues, potential data theft, and destroyed your own website's reputation.
- bhartzer 4y agoI've been running a stolen domain name recovery service for a few years now. Even though hacking into someone's account and transferring the domain name to themselves or transferring it to another domain registrar is a crime, it's never prosecuted (when they come to us the first thing we have them do is file a police report). The problem is that most domain registrars won't help get your domain name back. Many domains are stolen because they hacked the email address and not the domain registrar account (even though that's how they got access). Most domain registrars don't care at all, and won't help. And there are no current ICANN policies for dealing with stolen domain names. Even UDRP is not set up for dealing with stolen domains. Although we were successful getting one back via UDRP since the business was using the domain previously and we ended up claiming 'commonlaw trademark'. This is one reason why we've been so successful getting stolen domain names back for clients: we use some alternative methods, such as actually talking to people at the registrars involved and talking with the domain thief, to get domains back.
- xoa 4y ago>Most domain registrars don't care at all, and won't help. Don't leave us hanging like that! Which are the registrars that do care, and will help then? Even if they cost more.
- toast0 4y agoI personally prefer keeping domain registrar separate from dns host separate from server host, and probably email host separate from the others, too, but on the other hand, you now have several different vendors that can ruin your day. Using bundled services from your domain registrar is especially problematic though, because when you switch registrars, you usually lose those bundled services, even though you already paid for them. Often, there's similar services available at the new registrar, but there's a cost to switch, and it's much more difficult to switch because the service provisioning is often tied to the domain process; service at registrar B won't be online until the domain is moved, and service at registrar A may be turned off immediately after the domain is moved, so you have no way to make an orderly transition.
- jacques_chester 4y ago> you now have several different vendors that can ruin your day. The point is that a single vendor for everything can ruin your life.
- capableweb 4y agoInfrastructure best practices have gone out the window, haven't you heard? Most people who use AWS/$cloud_service use it for everything, best practices be damned. Many new projects start their working thinking about how to scale, before making it simple and before having paying users.
- Strom 4y ago> thinking about how to scale Having a good plan for scaling is absolutely a great move. Changing fundamental architecture later isn't easy. Implementing it all immediately however ..
- capableweb 4y agoSure, I agree, some sort of plan is a good idea. What I've seen many times though is engineers building systems for supporting 100k daily users while the product hasn't even found market fit yet, wasting lots of time on building complicated distributed systems way too early.