And what if somebody hacked the registrar? Are there global mechanisms to undo wrongful domain transfers?
And what if somebody hacked the registrar? Are there global mechanisms to undo wrongful domain transfers?
As a non-US citizen you should definitely move to another TLD entirely. US asserts jurisdiction over .com/.net/.org and has been known to seize such domains at will even if they have no ties to the US. You would have little recourse without great difficulty.
As a non-US person myself I will therefore personally never hold such a domain.
National TLD's would be a good choice but there's also .eu which I reckon would also be a safe choice. They also do not publish WHOIS information for privately held domains.
People rarely consider this when purchasing domains (which jurisdiction they fall under) but it's an important issue in my opinion.
(Source: http://yro.slashdot.org/story/12/03/06/1720230/us-asserts-su...)
My business is on a .com domain and that will never change. I'm a businessman, not an extremist idealist.
The CloudFlare Registrar would auto-renew your domain a year in advance, aggressively lock it and prevent transfer, and allow you to require multiple people in your organisation to approve significant changes.
Any registrar that is selling you a domain for $10 per year is making such razor thin margins that they cannot do more than the minimum and rarely enforce doing that with diligence.
I was rather pleased that one of my domains ultimately is managed by an arcane human process involving actually dealing with a bureaucracy... this slows everything down so much that it's hard to achieve anything at all. It was entirely accidental, the domain has a .sm TLD and that municipality is tiny.
What CloudFlare are effectively doing is using a highly bureaucratic and formal process to ensure the domains are safe and secure, to mitigate the risks involved. That your organisation can shape the policy you want is also a benefit, you can ensure only the real decision makers get to authorise changes.
This does very little for security indeed.