8 ms·
Thank god, .tk caused so many headaches for us, truly a cesspit of a tld. The rate of fraud and abuse on our platform was staggeringly high from it, it was clos
by chomp 3y ago
Thank god, .tk caused so many headaches for us, truly a cesspit of a tld. The rate of fraud and abuse on our platform was staggeringly high from it, it was close 99%.
- jackblemming 3y agoYou think that fraud is just going to go away because .tk is gone?
- jamespo 3y agoprobably not, but very little of value has been lost
- _mlbt 3y agoI would disagree, I remember as a kid in the late 90s being able to host a website on one of the free hosting providers and then pairing it with a free domain name just made the whole thing that much more special. $10 or so a year for a paid domain name isn't a ton of money, but it can be for a kid with no credit cards and parents that aren't convinced as to why you "need" a domain name.
- bombcar 3y agoThe problem is that "free for kids" is also "free for scammers" and it's hard to square that circle.
- kdmccormick 3y agoWould be really cool if public schools provided a free domain and basic hosting for any interested middle/high school student.
- cube00 3y agoGood luck considering we can't even pay teachers properly.
- kdmccormick 3y agoCost would be negligible compared to a teacher's salary. (1 teacher / 20 students) * ($50k / teacher-yr) = $2500 per student per year to fund teacher salary. Compare that to $40/yr domain+hosting, which maybe 10% of students will use. $4/student-yr will not be the diffence between paying teachers probably or not.
- lxgr 3y agoThat budget only works if you don't care about content moderation or abuse management at all – or did you expect teachers to just do that on the side?
- where-group-by 3y agoI don't think that would be a good idea. It would introduce an admin burden on the schools related to moderating/monitoring the sites. And they would more than likely overstep in one way or another, when enforcing their rules.
- kdmccormick 3y agoI was thinking state-administered. Public school enrollment would just be the precondition to access the program. But sure, yeah, there'd be some admin time spent managing it. As with anything, there are plenty of reasons not to do it. It struck me as a low cost-to-impact ratio thing that could get kids into tech, but reasonable minds could disagree.
- bombcar 3y agoThe only way it would work is if it was literally handled by the government, and the associated 1st amendment rules applied (so it wouldn't be moderated unless it was actually shut down by a court case). It would result in rampant wildness and people complaining, but if you didn't do it that way the burden would be too high.
- lxgr 3y agoAnother way of looking at this is that scammers can probably afford to spend $5-10 on a TLD since it's just a cost of doing "business" to them, but many kids can't. I was very happy about free TLDs back in the day as a teenager, since I could just try things out before having to convince my parents to let me use their credit card to register a proper domain name.
- Caligatio 3y agoIt's infinitely easier to spend $0 vs $0.01 if you're trying to be anonymous online. The criminals can certainly afford it but that also almost certainly means interacting with financial systems that leave a paper trail.
- lxgr 3y agoI doubt that that's any kind of obstacle to criminals. At a quick glance, many registrars and hosters seem to accept crypto, and anyone can buy prepaid Visa and Mastercard cards anonymously for cash for the ones that don't.
- knodi 3y agowe're not in the 90s anymore. Many free subdomains options such as gitpages or full on free app (heroku) exists now.
- deleted 3y ago[deleted]
- eszed 3y agoIt would follow that Cloudflare is tacitly admitting they have been / are hosting a large number of domains used for fraud and abuse. That surprises me, given the time and effort they spend mitigating fraud and abuse. Anyone care to explain what I'm missing?
- dspillett 3y ago> admitting they have been / are hosting a large number of domains used for fraud and abuse Only if the abuse happened through them. Perhaps they were just hosting holding pages, and the traffic was pushed elsewhere when active scams were running? > surprises me, given the time and effort they spend mitigating fraud and abuse They mitigate it incoming as one of their features for their customers. That doesn't mean they are going to mitigate it outgoing quite as fiercely. Though I'd assume they'd made some effort at least to maintain a reasonable reputation for their IP ranges.
- Alifatisk 3y agoShouldn't be a surprise, there is a tight relationship between Cloudflare and the booter community. I remember every booter site or similar was always behind Cloudflare, I think it was a common practice because it didn't seem like Cloudflare cared about these abusive sites.
- KomoD 3y ago> That surprises me, given the time and effort they spend mitigating fraud and abuse What time? What mitigations? Cloudflare will proxy anything and then tell you "we're just a proxy, so we wont do anything lol" when you report anything other than cf pages. Doesn't matter if it's terror groups, animal torture, piracy, doxing, far right groups, etc. I have personally submitted abuse reports and seen that absolutely nothing happens. Oh and also the amount of abuse I see from people using Cloudflare Warp is also very high.
- eszed 3y agoI was thinking particularly about the DDoS protections they advertise (and explain in lovely technical posts on this site). So you're saying that they protect their network from others, whilst disregarding harms their clients cause to others. That was something I was missing, so I thank you.
- creatonez 3y agoIf .tk was such a clear signal for abuse, isn't it a bad thing that signal no longer exists? I'd rather ICANN finally introduce .free, give a few years to alert everyone, and those developing spam filters can treat it how they want.
- refulgentis 3y ago> If .tk was such a clear signal for abuse, isn't it a bad thing that signal no longer exists? No, this is (obviously) contrarianism for contrarianisms sake. It's good when entities facilitating crime stop facilitating it. No debate necessary. Additionally, it's completely unclear what you mean by your proposal.
- creatonez 3y agoSpam and scams will happen no matter what. It will just be spread across the cheapest domain registrations that are still available now. The narrow and self-serving aspect that Facebook investigated, cybersquatting, should not justify killing off legitimate free domain registrations forever, at least in a better world where we more directly tackle these problems.
- refulgentis 3y agoNobody cut off "legitimate free domain registrations" forever. Airquotes aren't sarcastic, just, idk exactly what that combination of words means so I want to leave myself an out. You are free to hand out domains for free to strangers, if you so desire. Nobody stopped anyone from anything.
- creatonez 3y ago> You are free to hand out domains for free to strangers, if you so desire. > Nobody stopped anyone from anything. This is impossible, as we have just seen with the ICANN termination of Freenom. Turns out, the legal threats will kill it, even if other TLDs also have plenty of cybersquatting going on. There's realistically no way to repeat Freenom's success in giving out free domains without greatly heightened legal expenses now. It's gone, the fun is over. Likewise, because of this legal pressure they will likely never allow a .free proposal -- which is to assign .free to an organization wishing to provide free domain names and foot the bill themselves, essentially becoming the LetsEncrypt of domain name registrars.
- TheAdamist 3y agoInteresting, .xyz was by far higher on my list of disreputable spam domains. I'd be happy with that one shut down too.
- majani 3y agoAs someone who had also grown to automatically ignore .tk domains, perhaps we've lost a reliable spam signal and honeypot