GoDaddy injecting JavaScript into websites and how to stop it
igorkromin.net
igorkromin.net
<script>'undefined'=== typeof _trfq || (window._trfq = []);'undefined'=== typeof _trfd && (window._trfd=[]),_trfd.push({'tccl.baseHost':'secureserver.net'}),_trfd.push({'ap':'cpbh'},{'server':'a2plvcpnl83247'}) // Monitoring performance to make your website faster. If you want to opt-out, please contact web hosting support.</script><script src='https://img1.wsimg.com/tcc/tcc_l.combined.1.0.6.min.js'></sc...
That's pretty gross.
Also, another time I was having problems with their stupid 2FA app (back when they ran their own app and it broke constantly), and their solution was to just disable the 2FA for my account. They said I can set it up again whenever I want to. So then I told the woman, that if someone wanted to hack into my account, they could just open a livechat and get my 2FA disabled and then log in, why should I even bother having 2FA at all if you're just going to disable it.
To be fair, they finally moved to a more traditional 2FA now, where you can use any 2FA app instead of their proprietary namecheap app. So they might not do this anymore. I think they were disabling 2FA back when they used their own app for it, because it was super buggy and people (like myself) would get locked out of our accounts for no reason other than their app was buggy.
Their UI hasn't always been the latest & greatest (but even here they came a long way in the past 2 years). their knowledgeable (and helpful) customer support really makes up for it.
I don't know the internals of the company but would assume that the people running it are still the same team who founded it and they really know networking & DNS inside-out. Refreshing in a time where financial and marketer types have taken over a lot of the decision making in tech or where you're in a customer support loop for ages and everything is handled by a bot.
But you know what? I'm okay with that. I honestly can't think of a scenario where I'd want to use any other nameservers.
What about the scenerio where you are thrown off of cloudflare service? A CDN is more inclined to ban sites to limit their own risks from litigious IP owners, etc, irregardless of who would win an actual court case.
That could be an argument not to use their DNS service and their CDN service.
It shouldn't be an issue for the DNS service by itself.
I still have a few domains with them it I’ve been using namesilo lately after hearing about them here and no complaints. Well the only complaint I have of them is they don’t have the range of TLD’s as namecheap does (but it’s only a handful of TLDs such as .es)
But... I haven't been a fan of them lately.
I've got a password manager and 2FA on all my accounts, and I went to sign in. I kept getting an incorrect password response. Reset, tried again. Just kept getting the same error. Freaked me out as I couldn't sign in.
Fast forward, came to find out because I was on my company VPN they were blocking me. Rather than just show a message, "We don't accept users on a VPN..." they let me think my password was wrong and go through the panic of not being able to sign in. And, even thought they thought I was some sort of spammer / hacker for using a VPN, they were more than happy to discuss my sign in details over live chat.
I sort of get "security" here, but they shouldn't be heavy handed with just saying who can and can't sign in, and if you are going to block me, tell me why -- at least send an email letting me know what's up if you don't want to display a browser message. 2FA was enabled, at that point... just leave it up to the user where they want to sign in from, don't put in secret rules around who can and can't sign in.
Anyway, I moved everyone over to Amazon Route 53 and haven't had any more issues.
Run a website of any importance and you will quickly be shocked at the amount of malicious traffic that keep coming from Tor/DigitalOcean/VPN/openproxy and a few other sources.
And they blocked me.
They didn't tell me why, I figured it out on my own inadvertently.
I wasn't on a junky free VPN, I was on a corporate VPN service.
And I was blocked, worse I was given false information about my password being incorrect... and worse still, given that they assumed someone was trying to enter a fake password, they never emailed me to let me know -- I had to contact them.
Plenty of legit reasons for someone to use a VPN. I'm relatively certain nobody from the telco in Australia who set up the VPN had been trying to hack Namecheap, looks more just like someone found a way to classify that IP as a VPN and blocked it.
And look, to put the nail in the coffin, they were more that willing to tell me the email address to check for the reset password via live chat.
Anyway I tend to be the guy harping about security, but when they start banning VPNs just for being a VPN I don't think that's secure, I think it's obnoxious. We should encourage people to use VPNs, not make it annoying for them.
Proper procedure would be to let the bad guy try, block the IP (or better yet, browser finger print), let them know why they were blocked (in case they aren't a bad guy), and (if the owner didn't have 2FA) send the owner an email saying someone was trying to get access but wasn't successful.
For users with 2FA, all you'd ever really have to do is send an email to the owner, and / or access distribution list, letting them know when a certain user signed in. I wish more people offered this service, getting access notifications when any admin signed in would be key for helping me figure out what task broke something if I have to go fix it.
But then comes namecheap. They are literally the only service on the internet where I will get locked out with 2FA. It will keep claiming it is the wrong password, when I know its not. I don't ever have a problem with any other online service, but the 2FA on namecheap is a constant problem. I have been locked out on Namecheap for no reason now 5+ times that I have now just turned it off.
Now that I read your comment, I wonder if I have the same problem. I am sometimes logged in via VPN and I wonder now if that is why it was rejecting me. Its frustrating because i know the password is correct and the app is set up correctly, but it will keep claiming I have the wrong password. Like i said, I now just have it turned off, because I am terrified of losing access to my domains. But I am also terrified of not having 2FA protecting my domains. So its made me consider transferring elsewhere.
I also considered just using Amazon. Most of my domains are already using Route53 as a premium DNS instead of relying on Namecheap as a DNS anyway. So I am considering just having them be the registrar too.
I am purposefully staying away from AWS. They are super popular right now and developer friendly, but I know how their business operates and that popularity will subside in a few years. I predict many of their users will feel betrayed at some point in the future after enough people have moved to their DNS.
Managed hosting is a requirement for the masses, and comparing a managed hosting service with a self-service VPS is a bit disingenuous IMO. Managed may seem more pricey, but that's only unless you don't value your own time as an administrator, or if your time isn't valuable (you're not good at it lol).
FWIW I use Namecheap / Linode myself, and will probably never go back to shared hosting. But the flip side of that coin is you do need to manage it, regardless of the website you are hosting.
And I don't think GoDaddy or other managed hosting providers are doing a better job than this.
Also FYI static websites have a much smaller surface of attack when compared to forever-vulnerable shit like WordPress.
Godaddy is not doing much more than auto-updating packages with security fixes. This is easily handled with most Linux VPSs (often automatically, in the case of DigitalOcean). I am pretty sure the Amazon Linux AMIs do this too on AWS EC2. And most other distros can turn this on once with one command.
I don't think GoDaddy is going much deeper than this, so security is a moot comparison between the two. In fact most sites are hacked at the application level anyway, not the system level. So the real security hole is not something on Linux, but the actual wordpress site thats installed within it. Food for thought: 83% of hacked websites in 2017 were Wordpress sites. Source: https://sucuri.net/reports/2017-hacked-website-report
Or you can opt out of this mess and run a simple server. Not as root.
The update & maintenance treadmill can be slowed down to nearly a halt if you're ok using simple software that doesn't have a billion features and just as many bugs. Which, I suppose, someone running a static site would be quite willing to do.
Little old grandma just loves ssh'ing into her pet server every day to read her system logs.
It's not a strawman at all. I am speaking from real experience, except for the part where my grandmother could tell you the difference between SSH and SSL.
http://yaffa-cdn.s3.amazonaws.com/adnews/live/images/yafNews...
^ I know this statement appears absurd to you, so I'm wondering why you're posting as if it's true?
I remember it being surprisingly good!
It's about as simple as it gets to add services, but Google's DNS is included (as opposed to GoDaddy's, which is slower) and I don't get pressured multiple times and have to click less obvious links to not choose other services. Privacy is included at cost, for TLDs that support the option.
NOTE: I am not a lawyer, and this is not legal advice.
At their scale, trying to automate it hardly seems surprising.
Not at any professional hosting service. It's not hard to secure the environment so that it'll take a classier attack than guessing somebody's WP login to get access to any other sites on the host.
The actual problem for hosting services is that compromised sites can be used to annoy visitors or other hosting services.
edit: okay, I don't care about the points, but I'm getting really curious why people disagree with this.
In any case, yes, I agree.
What is more plausible is malicious server-side code eating up server resources, and that load impacting the websites of other customers, but that has its own solutions which are different from automated detection of malicious JavaScript code.
1. Data theft. So, ripping off a database or intercepting credentials while people log in.
2. Embed a link into page output which will try to download something from somewhere somehow. It might be phishing, or (usually) it's some kind of JS trying to infect the user with malware. Lazy attacks work by just popping up a convincing-enough warning message with a link that lets the user download the malware themselves, and it's effective enough.
3. Credit card theft. Using a third party service with iframes makes this harder, but not impossible.
4. Dropping some kind of web-based shell, like C99.
#1 doesn't get anybody to care. If that's all that ever happened, I'm pretty sure shared hosting providers would still be saying, "sucks to be you." #3 causes headaches for the site owner and makes them care, but still not the hosting provider.
#2 got the hosting providers' attention once Google launched Safe Browsing. Suddenly this put some of the responsibility for maintaining a safe network back onto the hosting providers. Their first solution was to just shut down sites discovered to have malicious code, but that really irritated the customers. So gradually hosting providers started trying to be a little more helpful.
#4 is a big headache for hosting providers, because those things don't get picked up automatically by Google, and the shells can be used to irritate other hosting providers, who will definitely start lodging complaints with whoever's upstream of the hosting provider.
Not on this list is, "try to infect other sites on the same server", because shared hosting environments have had easy access to a variety of tools for a long time now that prevents that. In a LAMP environment, that used to include SuexecUserGroup; more modern LAMP environments now use php-fpm and have PHP processes running from distinct unprivileged user accounts. There's also the usual php.ini values, like open_basedir, which limit access to the filesystem or to other PHP functions (allow_url_fopen).
I won't say it's impossible for an infected site to attack another site on the same server in a shared hosting context, but you'll need a get-out-of-jail card and those are harder to come by.
No professional shared host would allow one site to access or modify another site on the same server.
Hell, Wordpress recommends against it (and still doesn't do a great job explaining): https://codex.wordpress.org/Changing_File_Permissions#The_da... -- probably because people keep suggesting it. A search for "chmod 777" brings up plenty of examples.
Even chroot will mitigate this, but e.g. reseller types quite often don't have that level of competence.
I was under the (false) assumption that every user’s website was in their own little VM, not they were sharing a web server.
Running a full VM, especially on the tools back then, took a ton of resources. Even server class machines only had 4 or 8GB of RAM typically.
By the time I got to the point where I would think about doing something on my own, VPS hosting was so cheap, I wouldn’t have thought about anything besides a VPS like Linode.
https://blog.linode.com/2003/11/04/new-linode-96-plan/
96M RAM
3GB Disk Space
38GB xfer
$29.95
Funny story (but not the ah-ah funny kind): such a service (hosting different customers on the same Windows machine) was still running in my previous company as of 4-5 years ago. They had long moved from physical hosts to VM, but were stuck with the legacy CMS/control panel which was more or less unpatchable (as in, the software editor didn’t exist anymore). About once a week, one of the host VMs would be taken over by hackers using one exploit or another. In that case they would kill the VM, boot a fresh one from a clean image, and start serving the customer data again after making sure it was clean. The service was not sold anymore but they had long-running customer contracts. It wasn’t making enough money to justify rebuilding it with modern software, but it was making enough that simply killing it wasn’t an option.
It wasn’t until I started architecting and developing in cloud environments that the true cost of Windows became apparent - when the cost of every project I do can more or less be directly tied to me.
I still development on Windows but I found an appreciation for deploying to Linux.
Unfortunately, shared hosting comes with all the risks described: if just one site on the server gets infected, everything else co-hosted on the box feels the effects, especially when the infection is something resource intensive like a cryptominer, or sends out spam emails en masse and gets the physical box on a blacklist. From an infrastructure standpoint we can only do so much; keeping the OS patched and up to date helps to curb the really nasty infections, but the reseller plays whack-a-mole with their customers, detecting infections and shutting domains down as needed.
It's a bit of a mess really. At the same time though, the economies of scale really seem to favor shared hosting from a pure cost perspective, especially for very small businesses that can't otherwise afford a technical team to manage a VPS. So, I think that market is always going to be there.
I’m way out of my area of expertise here. But from a management perspective, when it comes to managing a lot of VPS’s for something like WordPress, is there a simple service where the underlying OS and plug ins stay patched by the provider? I guess something like Elastic Beanstalk but simpler.
There's a thing called Cloudlinux, which is an additional licensed feature that provides resource fencing, but its a lot less capable than advertised ime.
Moreover, many end users rush to chmod 777 their installation because there's a lot of guides out there telling them to do so. There are also highly rated Wordpress plugins that do this silently because developers read those guides.
Also I don't have to update operating systems or do backups, etc.
Unless you website is serverless, good old shared hosting isn't bad. You have less control, but also less responsibility :)
It would take us time to assess everything and do up contracts for bring-up with these sites. Everything from old revslider and timthumb to more exotic infections. Once you got a file injection or reverse shell on a host, it would spread fast to everything on the server. Only way reliably back was catching when it came in and rolling it back to before then upgrading the vulnerable components.
Offering it as an opt-in service, yes. Doing it to websites that have not agreed to to it, no.
Which is still how it should be done.
I am guessing the hosting provider gets access to the information the client also gets, but that's just a guess without any evidence. It would just make sense in the absence of regulation.
This should be inserted by the customer instead of filtering traffic, but not necessarily. It's very user friendly to only have a button to turn something on or off.
When faced with egregious business practices the best option is to switch company. What guarantees do we have that GoDaddy won't toggle the switch back at some point, or introduce other trackers?
There are plenty of website hosting solutions out there. While at it, switch your domain registrar to a reputable one like https://www.gandi.net/
For the unitiated, Content Security Policies (CSP) allow you to, among other things, define a whitelist of origins for things like scripts, css etc. and also notify you of violations. There is little excuse to not set a strong CSP on your sites if you can and you'll be glad you have it once something does happen.
true, but
> if you can
IIRC that excludes every website with Google Adsense and even just using a manual ad network includes always fiddling with your CSP.
Can't use CSP if you want any ads on your page usually. If anyone here knows an ad provider that plays nice with CSP and pays okay then please do let me know, I'd love to securely monetize a few webapps of mine.
[0]: https://twitter.com/JackyHallyday/status/968263408003973121
However, "was caught" is important :) The more noise they make the more likely they are to get caught.
Then again, GoDaddy could just rewrite your headers.
window.tcg = ...
And the script will do nothing.Therefor this is probably a violation of copyright. Does anybody using GoDaddy for hosting want to sue GoDaddy? Statutory damages up[2] to $150,000 per work adds up fast.
[1] https://www.law.cornell.edu/uscode/text/17/107
[2] actual damage amount in copyright cases varies a lot - this is simply an upper limit
I'll admit I didn't look that closely though.
I’m all for GoDaddy being held responsible but advocating this kind of copyright abuse is as ridiculous as it is scary. Are we going to start suing CDN’s for setting custom HTTP headers now?
I think the important part is: Use a hosting provider you trust!
You might as well be complaining that you're surprised Larry Ellison isn't looking out for your best interests, David Miscavige tried to brainwash you, Donald Trump didn't tell you the truth, and Rick James ground his muddy cowboy boots all over your suede couch.
Blame should stick to the bad actor, not the people they sucker.
But you don't have to be an expert to conduct a web search.
> Blame should stick to the bad actor, not the people they sucker.
I mostly agree with this, but I have a hard time not placing just a little blame on the people who don't engage in even the bare minimum of research.
And if you don't know how to conduct a web search, you shouldn't be building a web site.
>... placing just a little blame on the people who don't engage in even the bare minimum of research
And GoDaddy's uncritical customers tend to be the kind of people who are easily influenced instead of permanently repelled by the kind of commercials GoDaddy is infamous for running.
The free hosts I used many years ago would do something similar, with no way to opt out --- that is, until I figured out they were just detecting the '</html>' and inserting before it.
Combine that knowledge with the fact that the closing tag of the HTML element is optional, and you can guess what I did pretty easily. ;-)
<!--
</html>
-->
Unrelatedly, <html> is surprisingly hard to omit if you want to properly set the lang attribute.
https://www.w3.org/International/questions/qa-html-language-...
There are at least three places where you can get injected, one is from the ISP (including phone company networks), one is from the hosting provider, and one is from add-ons in the browser.
One of the first Java applets I wrote (and you could easily do this in js) did a hash over the document page and reported if the hash didn't match the one stored in the applet. These days you could throw up an other wise invisible div that said "Page Tampered" please report to webmaster (or you could even do that yourself with a lookup on your hosted side to a script that would log IP/browser etc.
I've already encountered pages like that, they piss off everyone who uses adblocking/filtering so I would consider it an anti-user technique.
I'm not sure if they still do it, but Vodafone in my country (and many others) used to cache and compress photos on all websites, which often led to visible degradation in image quality. Luckily I discovered that their software respected the `Cache-Control: no-transform` header so include that header on all my websites now.
A little more than a year ago, we created a RUM javascript for our customers. The javascript is extremely lightweight and evaluates hosting performance only. We did this to create a better hosting environment for our customers. We rolled this out to a small subset of customers.
As the RUM proved very beneficial in optimizing our hosting platform for our customers, we decided to roll it out to a wider audience. That said, we clearly could have better communicated this program.
Based on all the feedback, we have decided to turn off the RUM javascript immediately and focus on designing the program so that customer participation is on an opt-in only basis. While the RUM data is beneficial in helping us improve our customers’ website performance, we regret that the implementation has upset many of our customers and we apologize for any inconvenience this has caused.
Narasimha Krishnakumar VP of Product Management - Hosting GoDaddy
Please Daddy, don't be so rough.
Who's a good alternative these days?
There are many decent alternatives. From the above, I have used all but Google and Cloudflare. My experience has been pleasant with all that I have used.
I normally don't like qoutes but i think the Batman one fits well here with how people perceive companies: 'You Either Die A Hero, Or You Live Long Enough To See Yourself Become The Villain'
The biggest advantage over Google's registrar service, is there's no upsell, at least not that I noticed. They do offer some integrated service options. The included google dns hosting and mail forwarding services are great imho. It could use some slight improvements in UI/UX, but still better than any other registrar I've tried by a large margin.
Mileage may vary, of course, but I really do like the service overall. I'm not affiliated with Google, don't always like everything they do, and do have some reservations about them as a company. That said, imho the best registrar option available.
I do wish that Let's Encrypt would work with them to whitelist all the domains on freedns.
Since they're not the cheapest, I throw my experimental projects up on DreamHost, but my mission critical stuff is on FutureQuest.
Time to move away from webfaction now.
It’s as simple as document.getElementsByTagName(“script”).length
EDIT:
Here is my tested more sane approach: https://gist.github.com/prettydiff/f9f85fffb00a903ecd3f2cfe0...
I do not have an xhr notification in place in the gist, because I have not written a service to receive it yet.
This approach has the added benefit of letting you know that malicious things are happening.
https://gist.github.com/technion/5de5739ee803ed0641b2de81660...
Edit: My other pet peeve was that they supported SOPA when that whole mess was ongoing. I can't trust them at all since.
Namecheap is not cheapest neither (Namesilo)
Besides, he sounds super unprofessional to me; 7 months ago he was sparing with me because he chose to be blind who is #2 top registrar [1]. He suppose to know this shit as a CEO, no?
Here is another nightmarish story: https://news.ycombinator.com/item?id=18206464
At some point they deleted someone's 75 domains without any warning or support to resolve the issue.
Their UI will remind you of 2012 but it's functional and has all features you'd expect to be there.
For me GoDaddy is like a client test. If they are using something else for hosting, plus one point to them. If they use GoDaddy for hosting, minus ten points. If you can't convince them to move away from GoDaddy, you probably want to replace that client if possible with a more reasonable or less cheapskate one.
Also I believe that https would prevent injections.
Depends where it happens. On shared web hosting, they control SSL termination and everything behind it.
There's a reason why companies like namecheap which market themselves on "no bullshit" registrar services are popular these days.
As far as "no bullshit" registrars, Domai.nr has been short of incredible.
Thought I'd share the option if anyone is looking to migrate and at least wants options on the table to think about, along with namecheap.
I’ll probably go with an OpenBSD vps somewhere, praying not to get hacked, plus Heroku for when I really can’t be arsed to look after a service. Quite a pain in the ass, though. At least my domains are already on Gandi...
On the other hand, I've heard less than great things about Gandi's reliability and support lately. If you've had to contact their support team, what's your experience been like?
I recently went looking for a registrar and one of the must-haves was U2F. Only Amazon and Google had it. Didn't know that Gandi has it as well. Good to know!
PS: I was disappointed that Cloudflare still doesn't have a U2F support yet they are a part of critical infrastructure for much of the web. We ended up not using them because of that.
GDPR matters to the EU. It doesn't apply elsewhere.
It applies to "an enterprise established in the EEA or—regardless of its location and the data subjects' citizenship—that is processing the personal information of data subjects inside the EEA" (emphasis mine, text from Wikipedia)
Territorial scope
1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
(b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
3. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.
The EU would use EU courts to enforce EU law. This might mean that non-compliant websites are blocked, via court orders to ISPS, in the EU.
This already happens with some piracy sites. The blocking is inconsistant and easily circimvented.
GDPR doesn't apply to companies that only have a tiny portion of EU customers. Good examples would be: small local news, US only shops. (K-Mart, gun shops, etc)
GDPR being an EU law doesn't matter so much when there are so many treaties allowing fines to be forced. This means not being in the EU just makes it more expensive to deal with.
The GDPR will however care that your traffic passes through GoDaddy, no matter if they set cookies or not. To be more precise, the GDPR will consider GoDaddy a processor of your data and you as a controller will need a proof from all your processors that they process data in a GDPR compliant way.
In practice, most european web hosting companies set up a web page somewhere that gives you this proof, and will,for a small payment, give you a signed, printed copy of this page. For most small to medium sites, either option will do.
by not using GoDaddy.
I mean sure, it’s fixable, but this shouldn’t be a norm (for a paid service)!
I noticed some of my sites getting Vodaphone banners when using Ireland/UK sim cards and realize they were injecting crap into my site. That really helped me make the push to use LetsEncrypt on everything.
I realize that 3rd party Wi-Fi/ISPs injecting code is a slightly different issue that the one in the article, but the solution is running SSL everywhere. If you need to login to a captive portal that redirects, there's always neverssl.com
There's also:
(which is easier at least for me to remember for some reason)
https://gawker.com/5787676/meet-godaddys-ridiculous-elephant...
"Oh, but we've changed" they said... Glad I ran away from anything they touched since they acquired Media Temple.
Aside from the cap topic, it's outrageous to me that they find it OK to alter/inject into HTTP responses like this. Send me an email, sure -- but to alter responses?!
Note: fixing redirect rules for logins on some sites is a significant PITA, but should be adjusted accordingly by now anyway.
Or are they able to inject it even then since they are the hosting provider?
See http://nginx.org/en/docs/http/ngx_http_sub_module.html & https://httpd.apache.org/docs/2.4/filter.html
I would consider using Cloudflare's new at-cost registrar service[3] for everything, but they don't allow you to use non-Cloudflare nameservers.
I've also experienced strange issues with logging in to Namecheap. From what I remember, I kept getting a server error message. Sometimes it happened after submitting my password, and sometimes it happened after submitting my 2FA code. Customer support couldn't help, and the issue went away the next day.
[1]: https://tld-list.com
[2]: https://porkbun.com
Another provider I found doing something similar is 000WebHost: https://urlscan.io/search/#filename%3A000webhost They "just" inject a footer with an image and a link to their service though. Not sure how common this is in the low-cost hosting space.
On a related note, last I tried Cloudflare (a couple of years ago) they also injected JavaScript into my site. The JavaScript was larger than my site.
https://www.reddit.com/r/india/comments/8wj6ec/bsnl_and_mtnl...
It's not surprising that this PSU like every other in India is being destroyed from the inside, and is well on its way into the mouths of the private vulture funds.
I can't think of anything related to performance of the server that can/should be monitored using a client-side script versus a server-side component.
I can easily imagine a scenario where someone innocently added this code with good intentions (i.e. purely for performance data that sites can use) as opposed to being evil. It may be the case that there wasn't enough internal review of the code in question, and that's all. Also you have the ability to opt out...
I'll talk about alternatives now. Yeah, I know Gandi is cool, but they want too much money so majority of people pass them by.
If you want a really horrid example: 1and1 is a company that sets the bar. They buy up superbowl and print ads to lure in old people with cheap domain registrations (like $1 or so). Once sucked in they use a careful reading of the ICANN regulations to maximize difficulty in doing anything.
Oh, you want a transfer? That's going to be a week. Most things either go over the phone or through a panel that's down or nonfunctional half of the time.
Want to change nameserver delegation to your own DNS servers? Fuck you then. They wipe the current DNS records and process the change in a couple days. Your site can take a vacation.
Now, I hear a lot of people saying Namecheap is a good choice. They are ok, we recommend them but their panel likes to shit the bed and it can take hours to push DNS updates when things aren't running great there. They finally got off being an ENOM reseller, which is great. ENOM are assholes. I had a client that hired an ENOM reseller some time ago to register their domain and host their site. The reseller's company's owner got arrested and/or deported and while we were able to save the client's files the domain expired with no way for us to renew it. The good news is you can gripe up the chain to ENOM which will require a 5 year domain registration for $200.
That's it in a nutshell. They are a large company which has a service that mostly works for a cheaper price than arguably better options like Gandi.
Shout out to other terrible registrars like Yahoo Small Business (ugh)
Yup !! Thats my experience also !
You can query the authoritative DNS servers for any domain using dig.
NOTE: I use the free mail forwarding so I can continue using some very old email addresses.
As bad as the ENOM example is, at least I don't have to spend a week hammering the same dude on a certain subcontinent that has no escalation path.
They bait and switch their customers into buying a really cheap domain for the first year and then rake up the price for subsequent years.
It's annoying for businesses to switch everything over to a new provider, especially not so technical people that don't want downtime, so they eat the cost.
GoDaddy alternatives which aren't shady are:
Namecheap
iwantmyname
AWS Route53 Domains
Google Domains (wouldn't be surprised if they kill this service though)
Also lost my DNS settings for another domain after i "browsed" their backend !
All the options we might call "better", including deploying a static site to Netlify or GH Pages, using a cheap VPS or a complex AWS deployment, aren't actually options for the people buying these services, who expect a one click Wordpress deployment.
I've been VERY happy with them. Hadn't been on their main app in a while and it looks like they've improved the UX a bit. I do have gdocs on one of my domains, but probably will drop it. Otherwise I'm externally hosting a few things. I am also making use of the mail forwarding options for addresses on a couple of said domains.
Has any one encountered sleezy practices like GoDaddy with name.com? I take my domain registrars reliability and business practices very seriously!
But look at line #230. You're basically seeing a list of information it gathers, and everything above helps populate that information.
Then everything below posts it off to their server.
It appears that GoDaddy's reputation for being dodgy is well-earned.
2) It is probably not a good idea to have people manage webservers without in-depth security and server knowledge.
3) You still have to arrange DNS-hosting.
4) Webhosting can be a lot of things, e.g. database hosting, http website hosting, email hosting, etc...
5) When hosting your own website, traffic bursts might become a problem for your own internet. Do you really want to open your own IP for DDoS attacks?
6) Probably external nameservers (e.g. cloudflare) would be a good idea (see 5).
7) By hosting your own server, you have a lot more legal liabilities.
There's a lot more to this than you would think on first sight. I outlined just a few problems and issues above, but there's probably many more. Truth is that it's probably not a good idea to host your own website if you're just a small business, or hobbyist (unless you want to learn something).
> You need an ISP which allows this (opening ports 80 and 443)
Anywhere on the internet that allows you to run a box allows you pretty much any port you like. DO, Linode, Light Sail
> It is probably not a good idea to have people manage webservers without in-depth security and server knowledge.
Yes. But in my experiences most pwning happens due to application sec rather than server sec. i.e wordpress/drupal instances that aren't updated regularly and vulnerable plugins installed on the same. But I see your point, and I think it applies to any DIY effort.
> database hosting, http website hosting, email hosting
Yeah, when you sign up to any host out there they give email, seo, and logging. But I feel most clients would only really need database + app + email services. And for email Gmail and Proton are really the only quality choices. So you could get away with only offering database + app hosting.
> You still have to arrange DNS-hosting.
no, I think most domain registras will do this for you and offer a decent interface around this. I use namecheap and they are just stellar!
> When hosting your own website, traffic bursts might become a problem
This is the same for most webhosts anyway. In fact the problem is worse for webhosts. The cheapest box on Digital Ocean can easily outperform you run of the mill webhosting package. The resources available to each app on shared hosting is laughable for anything but you mom and pops local bakery or blog.
> Do you really want to open your own IP for DDoS attacks?
I don't think this is a problem you can get away from either way. You eventually have to use a service like cloudflare as you mentioned for this; webhosted or DIY.
> By hosting your own server, you have a lot more legal liabilities. I agree with you on this one.
So instead of paying someone to run Apache for you, you pay someone to run the box you run your Apache on? Why is that better if you just need Apache running somewhere? I run my own stuff on a VPS too, but for people just wanting hosting I'd generally recommend plain hosting from a trustworthy provider.
NOTE: if you use the $5 droplet level, you must add a swap file or you will have issues. You probably should do this anyway.
Was excited to move my GoDaddy registered domains there, alas none of them are supported (yet).
https://support.cloudflare.com/hc/en-us/articles/200167866-H...
Personally, I have a ResellerClub account that I 'sell' to myself and my families. I also use name.com and namecheap.com for both my personal and my companies domains. They all are good.
There is Google too, and CloudFlare entered the market.
Question: Even if one registers with GoDaddy, what if the DNS is at CloudFlare, it won't have this problem, right?