Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

UK.GOV has a good guide on "Keeping your domain name secure." https://www.gov.uk/guidance/keeping-your-domain-name-secure


TFA reminds me that most people miss the basics (eventually letting their domain expire), which is a much bigger threat than domain takeover:

- Enable 2FA

- Check that your domain is set to auto renew

- Lock your domain from transfer

- Check your payment details

- Use a reputable domain registrar

- Be sure you actually own your domain

- Extend your domain registration

- Be aware of any TLD-specific rules around renewals

from: https://onlineornot.com/guidelines-to-help-avoid-losing-your...


If your domain name is critical to you, pay 10 years in advance where possible, and still extend every year, to keep this 10 year buffer.


I did a 100 year registration. This was under $1;000 about 10 years ago. The status only show 10 year increments. I did it with network solutions.


Do you worry about the registra going down during that time? I guess ICANNs records should include the lease length and as long as you can prove you exist at the correct physical address or whatever you can "reassign" it to a down stream registra?


The domain pre-exists ICANN. I guess I’m counting on money and receipts still being being valid. If I ever find myself with a fear that hints at a breakdown of society or the monetary system I pull back and reorient my perspective.

If society fails planning likely won’t help.


I think a lot of people make bets like this that are very black and white. It's also very possible that something goes wrong at the registrar and your receipts aren't accepted because they don't have any records of it on their end. And society doesn't collapse but you're still screwed.


In this case I think 30+ years of ssl certs and other ephemera would help in this world where network solutions disappears but there is still an appeal to paperwork.

Sometimes luck is all one should relay on.


100 years is too long, you will completely forget to renew


I think I’m also auto paying. I figure I’m giving a 100 year head start on finding the paperwork.

I have told my kids but who knows if there listening. I’m in process of buying a sailboat and wondering how important a domain name is.


It’s safer to regularly have a transaction with the registrar. This serves as a sanity check that they keep record of your registration. Without any interaction, a lot can go wrong over decades, and you might notice only too late.


Ironic as last I checked (admittedly 2016) .uk domain transfers saw no verification: https://pricey.uk/blog/uk-domain-transfers-are-scary/

> I registered a new domain at one registrar and immediately asked they change the IPS tag to another. A coworker [saw] ... the tag change, but then I got distracted looking for cake/looking over their shoulder. They set up a new account at the second registrar and claimed the domain, using no secret information and without either registrar or Nominet gaining my consent.

To be clear, the IPS was (is?) publicly visible. So you could poll a list of domains looking for it.

It's worth noting that even if you registered .co.uk with e.g. Gandi, you still get a separate Nominet account with it's own authentication. It doesn't matter if you add 2FA etc - after such a transfer, the domain was registered to a different nominet account.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: