5 ms·
> I mean, I assume that most people registering a .US domain are not registering it at the top level. No, 99% of the people are registering at the top-level. I
by ArchOversight 3y ago
> I mean, I assume that most people registering a .US domain are not registering it at the top level.
No, 99% of the people are registering at the top-level. It's not like .uk where there is second-level domains that each domain falls under.
- NoZebra120vClip 3y agoWell except for k12.xx.us, which used to be standard in every state. Some of these domains are still alive, so there are definitely third- and fourth-level domains available for hijacking and malicious injections.
- loeg 3y agoThey might exist, but it is a far cry from “most people registering a .US domain are not registering it at the top level,” which is mistaken.
- kube-system 3y agoThese namespaces are controlled differently. You can't just go to godaddy.com and register "phishingdomain.k12.ny.us"
- NoZebra120vClip 3y agoYes, that's exactly what I mean. The subdomains are administered by the autonomous IT departments and administrators who run their delegated, authoritative name servers. Therefore, they are rather more vulnerable than a centralized registry that has the resources to scrutinize every application for veracity.
- kube-system 3y agoThe article is about how GoDaddy doesn't even bother scrutinizing second level registrations. Nobody is bothering to hack local governments to set up phishing domains. It's a lot easier to navigate to godaddy.com with 5 dollars and a fake address to grab a second-level domain.
- NoZebra120vClip 3y agotomayto, tomahto