What Is Going to Happen With Whois?
motherboard.vice.com
motherboard.vice.com
SSL certificates already aren't good enough to prove the legitimacy of an organization, not even EV ones. Why Whois data would be any use is beyond me.
Even legit sites are starting to hide whois data behind privacy proxies. Hijacked sites only ever map back to a victim, not the perpetrator. As part of my investigative workflow it's largely a waste of time to whois anything.
It seems to only benefit domain squatters and spammers.
Some domain name providers, such as Gandi, offer privacy of address, phone, and email data while leaving your name as the owner of record.
Definitely is a pro-company and anti-individual concept. If you are a company no problem using your address. As an individual it is not private, do you want people who hate your site knocking at your door and your kid answers?
Then namecheap as whois guard and all that. Extra rent you have to pay to keep your privacy!
I’ve had my street address on my domains for two decades now. All it does is save would be crazy people 10 minutes of googling, as there are searchable public records of home ownership.
Unless someone's gotten into a fight with 4chan or Kiwi Farms, the chances of someone actually hunting them down like an internet detective is pretty slim.
https://splinternews.com/how-an-internet-mapping-glitch-turn...
Hiding your home address is just a workaround.
This is silly. Public ownership records are a practical utility, not a deep-rooted moral practice.
Incidentally, we’ve figured out how to have digital asset ownership without invoking “the social contract” or any of its many connotations; we have blockchains now. Namecoin solved this exact problem, although it never took off.
How do you think the Freedom of Information Act got there? It may be going out of fashion, but many of us do believe that the workings of public institutions should be transparent because we value transparency itself. The public record would be much smaller if pragmatism were the only reason to make something public record.
ICANN (or whatever supplants it, like Namecoin) is the Register of Deeds of the internet.
I have been very tempted to register an ultra offensive sounding domain name just to get someone at a call center to ask me about it by name :-D
I never answer the phone if the caller ID is unknown, so I may be missing some there also.
The idea of hiding the contact information never quite made sense to me. If you're a business, then you already have to provide an address of record to the state for certified mail to go to.
If, as a private citizen, I am running a controversial website then there are already institutes in place that will receive, process, and provide anonymity for your physical mailing address.
The emails can be blocked easily, but the SMSes don't come from a number, they just have a random word in the "From" field and they use a random one each time, meaning blocking the "sender" is useless. They also come at all sorts of hours, so I can get 2-3 SMSes at 4am advertising Amazon crap, or other affiliate spam.
Spam seems to be getting worse and worse, despite all the efforts to combat it.
Services like Cloudflare on the other hand are fully complicit in making abuse easy on the internet. If you want something abusive taken offline it is better to go after whoever is hosting it instead of some pointer to where it is hosted, which is difficult when they are behind Cloudflare. If you want a laugh search Google for the terms "booter" or "http stress tester" and try to gauge the legitimacy of the results.
1) its UTF-8 clean 2) its JSON 3) its getting Oauth, so LEA requirements can be met while keeping personal data private 4) it uses web protocol underneath so 302 redirect works 5) its fully deployed in the RIR system for numbers, and has a global directory at the root in IANA.
RDAP is going to happen to WHOIS. Its long overdue.
(bias: I work on RDAP)
Even without whois, you can dig the IP address and find out their ISP (sometimes). I've had some success getting compromised servers shut down by reporting them to the abuse email address in the dig record. If you email amazon with the details of malicious AWS instance, they will notify the customer and/or kill the instance pretty darn quickly.
Does anyone know of an open source program that finds malicious IP's in apache / nginx logs and reports them automatically? I've been thinking of making this tool but it must exist already.
In my head, I call it the internet hygiene project. It's a slow and very unsexy way of dealing with the botnet problem, but I think it could make a positive difference. Admittedly, it'll only catch the low hanging fruit, but there is so much of it, I think it is a good start.
Apologies for going off-topic.
Some months ago I was curious about buying a domain name. So I poked around on various reseller sites to find out the pricing. I couldn't buy it at the time.
Only a couple months later (I still couldn't buy the domain), I found the site had been registered. The domain was an obscure but novel sequence of letters; the likelihood that I and someone else came up with the sequence at the same time is objectively possible, but slim.
So, I can only conclude that list reselling DEFINITELY DOES happen, and yes, I am very mad. But there is of course nothing that can be done.
Now, when I want to find out what domains do and don't exist, I just use WHOIS, because I don't trust any of the "domain lookup" sites.
What do I do now? :(
Still waiting on approval, am somewhat interested to see whether they approve my request.
As far as spam goes, I don't generally use private registration, but use dedicated email addresses for my whois contacts, and I rotate them on a regular basis.
The scraping seems to happen soon after a domain is registered, but there's a much longer lag when changing the email address.
For companies and organizations though, yeah, they have to be public, but I think that's fair enough.
Owner Addr : Obfuscated whois Gandi-63-65 boulevard Massena
Owner Addr : Obfuscated whois Gandi-Paris
Owner Addr : WA
Owner Addr : FR
and my full name. Seems obfuscated enough, especially since the name was not remotely validated.