8 ms·
Someone forgot to renew NodeJS.org
- deleted 14y ago[deleted]
- aelaguiz 14y agoWow, what recourse is available in this situation? None? Does this mean that 100% they are going to now be blackmailed to get their domain back?
- dj2stein9 14y agoUsually there's a grace period where the owner can still renew it, and before anyone else can. If the domain actually expired 60 or 90 days ago then they're probably hosed.
- calvinlough 14y agoAccording to WHOIS, the expiration date is 29-Sep-2012 14:50:55 UTC.
- deleted 14y ago[deleted]
- dj2stein9 14y agoBut it's still registered to Ryan Dahl/Joyent, so it probably can still be renewed.
- yoda_sl 14y agoYes you are correct about that... It happened to me once on an old domain and I was able to get it back in the following week after expiration but I don't recall seeing a parked page during that period of time. Doing a quick Whois for nodejs.org show that the name is expiring today: Domain ID:D157222203-LROR Domain Name:NODEJS.ORG Created On:29-Sep-2009 14:50:55 UTC Last Updated On:20-Sep-2011 00:04:23 UTC Expiration Date:29-Sep-2012 14:50:55 UTC Sponsoring Registrar:eNom, Inc. (R39-LROR) Status:OK Ouch!
- Karunamon 14y agoeNom does all kinds of shady shenanigans with domain renewals. There are stories of names going up on their auction block the moment the registration expires (meaning someone has to pay a greatly inflated amount of cash to reclaim the name)
- larrys 14y ago"eNom does all kinds of shady shenanigans with domain renewals." This wasn't done by enom. It was done by the reseller, namecheap. Their DNS is in the record (and it points to a page controlled by namecheap).
- davidandgoliath 14y agoUnlikely. As much as enom sucks I don't think one could misconstrue any of their ineptitude as evil. They do however have the redemption period at inflated prices, but I've never heard of them moving an expired domain to immediate auction. [citation please]
- Karunamon 14y agohttp://www.ripoffreport.com/Search/Enom.aspx http://www.ripoffreport.com/Search/Enom.aspx Start here.
- davidandgoliath 14y agoNone of those reference enom directly -- only resellers of enom. That's like saying I bought a widget off amazon & chase paymentech is fraudulent as a result.
- deleted 14y ago[deleted]
- sturadnidge 14y agoShouldn't be anything to worry about - here’s how the domain expiry process works. 1. Domain ‘expires’, and enters a 40 day grace period. I have read things that imply this can vary from registrar to registrar, but it seems pretty standard from what I have seen. 2. After the grace period, it enters a 30 day redemption period. Again, apparently this can vary, but I have yet to see it (admittedly I have only looked at a small number of domains) 3. Finally, when the redemption period expires, a 5 day ‘pending deletion’ period is entered. Between 11am and 2pm Pacific Time on the 6th day of pending deletion, the registrars theoretically start dropping the names from the ICANN database. It is kind of odd that such a domain would only be renewed annually... it's hardly speculative!
- chinmoy 14y agoWhat you say is correct. I'll chip in a bit on "registrar to registrar". In case of Namecheap,renewing a expired domain is just like renewing a regular domain. While other registrars charge re-activation fee, Namecheap has no additional fees. So, Ryan can just renew the domain instantly whenever this comes into his attention.
- larrys 14y agoThe "registrar" of this name is actually enom. In this particular case namecheap is merely a reseller for enom. Important to point out here that namecheap which is much touted on HN as being so great to deal with is the organization that made the decision to take this domain offline - not enom.com the registrar.
- cstejerean 14y agoWhen people fail to respond to expiration notices, taking the domain offline on the expiration date seems like a good way to bring it to their attention.
- larrys 14y agoOff the top I wonder if an idea might be to do the following, keeping in mind that the registrar would charge extra but ultimately it would be to the registrants benefit and less disruptive if the normal ways (that have no cost) were interupted: - Send postal notice (some do this already) - Send express or certified letter (charging up front to be notified this way) - Make phone call - Send email to any contact addresses on the website I would like to point out also that this is a reason also why "privacy" on whois is a bad idea in some cases. In this case it is fairly easy for a third party to get in touch with the joyent contact (someone might know him or have an alternative means of contacting him - even by phone if not the whois phone number). If contact info is protected by privacy that becomes a different issue (you would have to have more specific knowledge).
- chinmoy 14y agoNope, Namecheap doesn't practice the shady conditions practiced by other registrars. The expired domian can be renewed just like a regular domain. No extra fees and fuss involved.
- Jailout2000 14y agoI don't understand. It looks normal and works for me?
- garysieling 14y agoThat means the old DNS entry is cached for you.
- asdfs 14y agoWait half an hour or so, and flush your computer's DNS cache. Your ISP is probably caching the DNS entry.
- InclinedPlane 14y agoIt's been fixed. So it might be YOU who now have the old, bad DNS entry cached. Domain Name:NODEJS.ORG Created On:29-Sep-2009 14:50:55 UTC Last Updated On:29-Sep-2012 16:27:30 UTC Expiration Date:29-Sep-2013 14:50:55 UTC
- harbhag 14y agoYou can use one of the proxy sites. Try this link http://ninjacloak.com/index.php/1010110A/7dc98701d4de0a559b48260b874b116017992 http://ninjacloak.com/index.php/1010110A/7dc98701d4de0a559b4...
- sonier 14y agoIt now shows "Welcome! This domain was registered at namecheap.com. Please check back later!"
- wilsaj 14y agoFor those who need it, the IP address is: 8.12.44.238
- bilalq 14y agoThis caught me and my coworkers by surprise just now. Thanks for the link.
- binarymax 14y agoI know people make mistakes and overlook things, but really...there is no excuse for this. I get about 8 emails from my registrars warning me before a domain expires...60 days, 45 days, 30 days, 1 week, then one like every day until the date. Unless these emails are going to an address nobody is monitoring I can't see how this can get overlooked.
- mise 14y agoIf an email was sent to a mailbox that wasn't being checked, it doesn't matter how many emails were sent. I don't know if it's the case, just guessing as one possibility.
- larrys 14y agoThat's exactly true. Emails bounce and the person who is in charge of the domain often changes jobs and the contact isn't changed. Some go straight to the spam bin. But you'd be surprised at how many people ignore even postal notices that some registrars send. What you have to keep in mind is that restoring domains that have expired is a profit center for registrars. [1] And having incorrect email contact info helps as well since not only does it favor that profit center but it also prevents competitors from soliciting your accounts (as well as preventing spam, right?) [1] In the case of the nodejs.org domain it was taken offline on the day of expiration. It wasn't deleted it didn't go into redemption. Generally most registrars give some grace period (but if you aren't getting the emails that doesn't really matter, does it?) There is a new policy being floated by ICANN that addresses these issues. If I can find the link I will post.
- Shish2k 14y agoI don't know if this is a standard, but on the few registrars I've used, they don't allow you to use an email address on the domain itself -- so if you register X.com because you want bob@X.com to be your primary identity, it's pretty easy to forget about the bob@gmail.com address you used to register with...
- deweller 14y agowhois nodejs.org Registrant Name:Ryan Dahl Registrant Organization:Joyent Registrant Street1:345 California St Suite 2000 Registrant City:San Francisco Registrant State/Province:CA Registrant Postal Code:94104 Registrant Country:US Registrant Email:ryan@joyent.com
- sirrealle 14y agoWith the email "ryan@joyent.com", it doesn't seem likely that it's an unmonitored email address that would have missed the registration, unless it was seen as spam / junk mail.
- ck2 14y agoIt used to be possible to pay for other people's domains (they still own it, you are just gifting the payment). Someone once renewed a hotmail domain after Microsoft forgot. Registrars should allowing gifting, source doesn't matter.
- larrys 14y agoMany do actually. There are some problems with allowing that though. In some cases a clueless CSR could allow the person paying for the domain to gain access to it. The assumption is wrongly made that if the person is paying for the domain they have rights to it. After paying they will simply say something like "oh, by the way my address needs to be changed" or open a conversation about something else and end up gaining access.
- nivla 14y ago>Someone once renewed a hotmail domain after Microsoft forgot http://www.doublewide.net/ http://www.doublewide.net/ This is what ck2 is referring to. Its was an interesting incident. Slashdot discusssion around it: http://slashdot.org/story/03/11/06/1540257/microsoft-forgets-to-renew-hotmailcouk http://slashdot.org/story/03/11/06/1540257/microsoft-forgets...
- carsongross 14y agoERROR 500.5150 - Too busy being rockstar tech
- kombine 14y agoPlease stop using this bs terminology, rockstars, ninjas and all that sort of crap. With all respect to Ryan he is just one of many great programmers.
- bgilroy26 14y agoNo one can truly know the mind of another human being, but I'm pretty sure Carson Gross is sick of the term as well. I do agree with you that sincere language is more likely than sarcastic derision to turn the tide, but you should know that you guys are on the same side.
- jbooth 14y agoI think it's a gag on nodeJS's current trendiness.
- comm_it 14y agoI thought this was just an allusion to the 5150 in the error message. http://en.wikipedia.org/wiki/5150_(album) http://en.wikipedia.org/wiki/5150_(album) and http://en.wikipedia.org/wiki/Peavey_5150 http://en.wikipedia.org/wiki/Peavey_5150 So rockstar in this context is spot on. But otherwise, that terminology is complete shit, yes.
- kombine 14y agoAs clarified by others, I missed the reference to the album because I never really listened to Van Halen and I apologise for my harshness. But we are on the same boat. P.S. I need to listen to 5150 now!
- ck2 14y agoAlso, 10 year registrations are typically only $80 If you have a serious domain, why not just grab the decade. Domain prices will only go up, sometimes $1 a year, so there are savings too.
- larrys 14y ago"10 year registrations are typically only $80" Where are you seeing $80 for 10 years (not doubting just curious). $80 is below the cost that the registrar pays (for .com) to the registry and ICANN variable fees. Not to mention the cost for credit card processing as a variable fee. Consequently in order to charge that amount the registrar has to make money in other places (could be to charge for things that are free elsewhere as one example).
- moeffju 14y agoHow does this keep happening to people? No registrar I know has a default of "don't renew", and they send your reminders. Why not just buy the doman for 10 years, or set autorenew, or ... seriously. There is NO excuse for this.
- Shish2k 14y agoMaybe the creators didn't expect node to live this long? :P
- trotsky 14y agoI know there is a joke about event driven programming in here somewhere.
- dfc 14y agoI hope the node installation never did one of these: curl -s -L http://nodejs.org/some-script.sh |sh I have never understood why people install software like that. I can not remember which project it is that uses this in the installation.
- jaredonline 14y agoHomebrew, rbenv, rvm, to name a few. Never understood it either. If you could get ahold of a domain write a malicious script at /some-script.sh, you could do a lot of damage.
- halvsjur 14y agoI agree that it feels insecure, but is there really a difference between this and downloading and running files from a .tar.gz or installing a .deb for example?
- IsaacSchlueter 14y agoSorry, folks. My bad. The root cause here is that some stuff didn't get handed over properly in the switch from Ryan to me as Node.js manager. So, the emails were indeed going to a non-functioning inbox. It's resolved now, and we're setting it up to auto-renew so that this doesn't happen again.
- javajosh 14y agoIt's kind of amazing how much certain data (in this case, a record in DNS) comes to mean to people. And how much we come to rely on that little bit of data. And really, how much we trust the DNS system and it's maintainers. "Ruling the world" might be difficult, but "ruling the internet" appears to be a matter of controlling DNS and then mimicking well-known sites well enough to install arbitrary software on every PC and device on the planet via a nefarious auto-update. It's the ultimate MITM attack. Even better if you can take over the DNS system for a short period, get a few million installs, then put the system back. tl;dr: He who controls the DNS, controls the universe.
- bdg 14y agoIt's not who controls the spice, its the one who can disrupt the flow.
- deleted 14y ago[deleted]
- larrys 14y ago"setting it up to auto-renew" Auto renew of course assumes that the credit card on file is current. If the email address is wrong and the cc doesn't work auto-renew obviously will fail. As anyone who has to charge credit cards on a repeat basis might tell you, cc's fail fairly frequently. Since the domain (any domain) is important it's critical that someone manually also keeps track of the expiration date. And by the way if anyone thinks the answer to this is to renew for the max time period that opens up all sorts of problems in the future when the domain expires and people who were in charge years ago no longer exist and any current people aren't even aware that the domain needs to be renewed. This happens which is why there is an entire part of the domain business catering to what is known as "drop catching" deleted domain names and selling them back to the owners.
- aneth4 14y agoThere is a lot of self-righteous dickishness and schadenfraude in these responses. Proclaiming there to be "NO excuse" to someone who has worked their ass off to create a stellar open-source project really says more about yourself than the person you are attacking. Most certainly there is some sort of explanation, and whether or not it was a terrible mistake, being a jerk about it doesn't relieve you from the terrible mistakes you've made in your past - we all have them. And in the end, this is really not a big deal.
- IsaacSchlueter 14y agoYou have hit on the exact reason why I almost never look at Hacker News any more, except when someone explicitly asks me to respond to something. This site appeals to the absolute worst in everyone. I find myself becoming an asshole every time I come here, and I don't like that feeling.
- aneth4 14y agoI don't know about the worst in everyone :). Lots of people still manage to hold their temper. I've certainly gotten snippy here before. I still come here for great commentary on complex topics, but usually resist the urge to look at comments on gotcha articles like this where I know there is probably nothing constructive to say, so the trollishness comes out.
- TheHippo 14y agoIt actually pronounced "Schadenfreude" ;-)
- holdenweb 14y agoFile under shit happens and move on. Nothing to see here, people.