19 ms·
The concept of WHOIS has felt sleazy for many years. If I register a domain, the registrar will basically extort me a couple extra dollars per year for “domain
by transcriptase 2y ago
The concept of WHOIS has felt sleazy for many years.
If I register a domain, the registrar will basically extort me a couple extra dollars per year for “domain privacy” for the privilege of not having my name, home address, phone number, and email publicly available and then mirrored across thousands of shady scraped content sites in perpetuity. Even If you don’t care about that, then begins the never ending emails texts and calls begin from sleazy outfits who want to sell you related domains, do SEO for you, revamp your site, schedule a call, or just fill your spam box up with legitimate scams and bootleg pharma trash.
All because you wanted a $10/year dot com without paying the bribe.
And yes I grew up leafing through well worn phone books next to corded phones. This is not comparable.
- october8140 2y agoYou’re just using bad registrars. https://porkbun.com/products/whois_privacy https://porkbun.com/products/whois_privacy
- CursedSilicon 2y agoPorkbun only came out in 2014 Two decades late on a problem
- nextts 2y agoOh the good ol days. $10/m for slow PHP shared hosting and $150 for an SSL certificate too.
- dkh 2y agoWeb hosts competing based on who had the prettiest cPanel theme. The number of email accounts were allowed was something that mattered. If you were lucky enough to get SSH access, it was jailed and only really allowed you to move files around easier or edit something with vim/nano. Oh, I have unintentionally become a GoDaddy customer (a company I have spent ample time hating and shitting on over the years) because I was a legacy Media Temple customer going back to like 2006 and I still just can't be bothered to clear out everything on those sites/domains and they eventually got acquired
- DonHopkins 2y ago[flagged]
- endofreach 2y agoLet's encrypt has done great work with certs for free. But they do still cost money. Insane for how long unencrypted traffic was the default. But i could not have done anything, if browsers had soft-enforced https earlier. I simply could not have paid that money.
- chias 2y agoYou and everyone else: unencrypted stopped being the default as a pretty direct consequence of increased accessibility of TLS certificates.
- mattl 2y agoHow do they still cost money?
- cship2 2y agoYeah in late 90s telnet to server was the default. So all those delicious cli were just flowing in the Ethernet traffic in plain text.
- account42 2y agoYou could get free SSL certs before LE. What LE changed was making it possible to fully automate the process.
- scarab92 2y agoI still can't get my head around why a .com costs $9.59 (plus registrar margin) There are 160 million registered .com domain names. I understand that operating root servers isn't free, but surely they don't cost $1.5 billion per year! Wikipedia's hosting costs are $3 million per year, for comparison.
- ocdtrekkie 2y agoBecause it's a natural monopoly. Nobody ever got taken seriously with a .biz address. (.com is basically price-regulated because of this, FWIW, Verisign can't just raise prices whenever or however it wants. But obviously it's still a pretty sweet deal for them, I'd imagine.)
- dylan604 2y agoHell, even .net will lose you traffic. If someone has your desired name with .com so that you use any other TLD, you will lose traffic. If your .com is taken by someone in the same line of work and not just a coincidental use of the same domain, then you'd be insane to not change the domain. I'm not sure how many people manually type domains in any more (I do though), and .com is muscle memory.
- scarab92 2y agoSure, it's a natural monopoly, but it's owned by a non-profit (ICAAN), so where is all the money going?
- fc417fc802 2y agoIf a system is built in a way that creates a monopoly I'm not sure it's legitimate to refer to it as "natural". The characteristic that defines natural monopolies is that there's no realistic (at least known) alternative way to go about things which isn't also a monopoly.
- DoctorOW 2y agoOnly $0.18 goes to ICANN, the non-profit. The rest goes to the Verisign which is a publicly traded for-profit company which ultimately gets that $9.59. I bring this up because it of course _doesn't_ cost that much. Incidentally, Verisign posted $1.56 billion in revenue last year and spent about $1.21 billion on stock buybacks in the same time.
- cship2 2y agoOr had to get an isdn line just to get an static ip for your clients to ftp the files
- Tarball10 2y agoThis is about sunsetting the WHOIS protocol in favor of RDAP, not doing away with domain owner registration data.
- anthropodie 2y agoIt's crazy how many people just read the headline and choose to comment or upvote these links. Also, why the title is not same as the article? It makes no sense.
- mattl 2y agoThe site tweaks some words out of titles
- jader201 2y agoTo be fair, OP never said this was necessarily related directly to the article. I’ll often post loosely related tangents like this because I would enjoy discussing the tangent with the HN crowd, but there’s often not a better opportunity to discuss it, so why not while we’re sort of on the topic anyway. Ack that I don’t think it makes sense to discuss not even remotely related topics. But as long as it’s in the ballpark and it’s not going against other guidelines and leads to interesting discussion, I think it’s fine.
- hyperbrainer 2y agoIndeed. Furthermore, the fact that there is still a replacement makes the discussion even more pertinent in this case, since OP is arguing for the abolition of any such protocol.
- vachina 2y agoI can’t downvote. Not sure about others.
- whalesalad 2y agoTangentially - RDAP was created partially to resolve issues with PII in WHOIS
- jsheard 2y agoThat was a common racket a long time ago, but pretty much every widely recommended registrar offers free whois privacy now. At least when they're allowed to, some TLDs forbid obfuscating the whois information.
- mrbluecoat 2y agoFor example, *.us domain registrars aren't allowed to privacy protect your domain: https://www.reddit.com/r/webdev/comments/101qjbq/wow_never_buy_a_us_domain_without_reading_this https://www.reddit.com/r/webdev/comments/101qjbq/wow_never_b...
- throwaway150 2y agoWow! These policies are like 30 years behind. Exposing your phone number and address on WHOIS makes absolutely no sense in this day and age!
- kevindamm 2y agoAt the same time, expecting that your NAP info isn't already in the hands of anyone who wants it makes no sense in this day and age. Between the countless DB leaks and numerous infostealer campaigns, and considering that anyone who has you in their contacts list is extending the exposed surface area, it's untenable. Other events like marriage and home ownership further complicate any attempt to keep your name and address private. Not saying you shouldn't opt for domain privacy, just giving a reality check. To really enforce your privacy you have to have multiple phone lines and a shell company, at the least. And really, even that isn't enough unless you can also commit to being a hermit.
- simonh 2y agoThere is a tangible difference between some people having this data somewhere out there, and literally anyone who wants to have it being able to look it up in a few seconds using tools already installed on almost every computer anywhere.
- deleted 2y ago[deleted]
- doublepg23 2y agoI've never had to pay Namecheap extra for WHOIS protection.
- TZubiri 2y agoIt used to be more common back then
- renewiltord 2y agoThey always list it in the line items and in the renewal but whatever. In fact, it looks like I forgot to turn on auto-renew on their domain privacy product so it's sitting there in the 'grace' period. They work as a registrar so I use it.
- TZubiri 2y agoNote that it is being replaced with a different protocol, is there any indication that there are less stringent requirements on identity data disclosure on the new proto?
- CydeWeys 2y agoIt's just a different protocol for how to send the data. It doesn't affect requirements on the data itself.
- TZubiri 2y agoOften different protocols cover different data or data differently. Two protocols that have the same data would be quite redundant.
- CydeWeys 2y agoIt's the same data. What's different is essentially the transport layer for the information. > Two protocols that have the same data would be quite redundant. When one is plaintext, underspecified, and decades old, they're not. I don't think you realize how primitive WHOIS is; this is the entirety of its RFC: https://datatracker.ietf.org/doc/html/rfc3912 https://datatracker.ietf.org/doc/html/rfc3912 Note how it doesn't go any farther than "it's a plain text blob retrieved over TCP". Now contrast with the RDAP RFCs, which fully specify every aspect of how an RDAP service works: https://datatracker.ietf.org/doc/html/rfc7480 https://datatracker.ietf.org/doc/html/rfc7480 https://datatracker.ietf.org/doc/html/rfc7481 https://datatracker.ietf.org/doc/html/rfc7481 https://datatracker.ietf.org/doc/html/rfc7482 https://datatracker.ietf.org/doc/html/rfc7482 https://datatracker.ietf.org/doc/html/rfc7483 https://datatracker.ietf.org/doc/html/rfc7483 Integrating with WHOIS is a nightmare, as every registrar/registry does it differently since there's no common specification other than "connect over TCP". RDAP is fully specified, so you can simply use a language-specific library and then inspect a strongly typed response object returned by said library to get specific information out of the response. It's a night-and-day difference, and there's obviously a reason for the new spec to exist even though it conveys the same data. It's absolutely not redundant.
- TZubiri 2y ago[flagged]
- int_19h 2y agoI'm fine with the notion that corporations have to provide public information but not individuals.
- fitsumbelay 2y agoI don't have the greatest registrar but hiding my info from whois is free
- CydeWeys 2y agoGDPR is what changed this. Before that, registrars had little incentive to hide it for free when they could instead charge you for the service. It was not trivial that Google Domains (rip) came with free privacy proxy right from the beginning.
- betaby 2y ago> GDPR And yet all German sites must have such thing: https://0pointer.net/imprint https://0pointer.net/imprint
- whilenot-dev 2y agoNot all sites, personal websites don't require an imprint AFAICS.
- TiredOfLife 2y agoThey do. Even your bluesky/mastodont account does.
- lompad 2y agoAbsolutely not, where did you get that idea? Mastodon _instances_ have Impressumspflicht, sure. But normal users don‘t and I have never seen anything contrary about private accounts. Edit: unless the Account is for/by a business of course.
- nicbou 2y agoOnly commercial websites. https://allaboutberlin.com/guides/website-compliance-germany#impressum https://allaboutberlin.com/guides/website-compliance-germany...
- inetknght 2y ago> The concept of WHOIS has felt sleazy for many years. The concept of most internet things has felt sleazy for many years. Right around the time that businesses started monetizing the internet is when that feeling really kicked off tbqh
- kelnos 2y ago> The concept of WHOIS has felt sleazy for many years. More recently, yes. But the original (perhaps naive) goal was to keep domain owners accountable for whatever they were serving from hosts under their domains. That seems reasonable, at least on a more "polite" internet, where things weren't scraped and monetized and SEO'd into garbage.
- throwaway48476 2y agoPhone books went out to the city , the internet is full of every scammer from Bangalore to Bangladesh.
- b800h 2y agoStrangely limited region of focus.
- mckn1ght 2y agoWell, traveling west
- throwaway48476 2y agoAlso alliterative.
- billpg 2y agoI was going to buy a domain back in my student days, but I stopped when I realised I didn't have a phone number. I used the public phone-box on the corner whenever I needed to actually call anyone. It was a little annoying to have to register a phone number when I didn't actually want anyone to call me.
- neuroticnews25 2y agoFor .pl TLD, due to GDPR, domain data is hidden by default for private individuals (as opposed to companies), yet some registrars still try to upsell the "domain privacy", hoping you don't know about it.
- belorn 2y agoThe general purpose of publicly accessible registrant data is that people should be able to contact the owner of the domain in case of an issue, rather than the registry or registrar. "domain privacy" is simply the registrar putting themselves as the domain contact and becoming a forwarding service to you. For large companies, and registrants under those ccTLD's that require local presence, it not uncommon that a legal firm acts like a proxy for the domain owner. This is a service that they take a few dollars for, and is in many ways similar to domain privacy. The requirement of having the registrant as the contact person for a domain is something that (to my knowledge) comes from ICANN, and I think it has a positive effect. A domain should be owned and controlled by the registrant and not the registrar, which is then reflected in the contact information. In an alternate history we could see that the registrar (or even registry) owned the domain and only leased it to the registrant, in which case the registrant's power would be limited to other online services that people "buy" today.
- arccy 2y agoif you use a sleazy domain registrar, you get what you get. the good ones offer privacy for free.
- thiht 2y ago> the registrar will basically extort me a couple extra dollars per year for “domain privacy” for the privilege of not having my name, home address, phone number, and email publicly available Your registrar is scamming you.
- bastardoperator 2y agoOr you find one of the many registrars that offer free private whois, and none of these problems exist.