My .in domain has been transferred to another registrant without notification
twitter.com
twitter.com
Commenters have speculated that the domain was seized by law enforcement due to participation in a malware campaign. The domain in question may have been used by malware that was phoning home, perhaps because the Linode server hosting it was compromised. This stems from the fact that the domain's new nameservers are Shadowserver's sinkholes:
Name Server: sc-c.sinkhole.shadowserver.org
Name Server: sc-d.sinkhole.shadowserver.org
Name Server: sc-a.sinkhole.shadowserver.org
Name Server: sc-b.sinkhole.shadowserver.org
Edit: When querying the domain in RiskIQ, one of the Linode IP addresses formerly associated is tagged with `emerging_threats` and `kaspersky`. Other domains/subdomains associated with the same IP address have similar tags.One such domain is MathB.in, which is a public pastebin. It's conceivable that malware was phoning home by creating pastes on that site.
Susam, I don't have much experience recovering domains in this state, but it's conceivable that Namecheap will be able to put you in contact with someone who can help resolve the matter. However, if there's something like a sealed court order involved, you may find that you're stonewalled at first. I don't know if there's any available recourse for this, especially since this appears to be an international effort.
[1]: https://twitter.com/namecheap/status/1200682593500483584?s=2...
[2]: https://twitter.com/namecheapceo/status/1200714718610153472?... (This is from Namecheap’s CEO)
* https://news.ycombinator.com/item?id=15293578
* https://www.theregister.co.uk/2019/05/27/io_domains_uk_un/
If you had a hot new product called CyberTrk and someone ran and registered cybertrk.com, that is arguably squatting and can be legally enforced as such.
If you have what you think is a great new online notepad and notes.com is sitting registered but dormant, the inelegant but reasonable way to respond to your situation is "tough shit". Keep looking.
99% of the time that people rant about "squatting" they're talking about the latter case. Yet they are not entitled to a domain because of some imagined better use for it.
Sorry for the rant, but misclaims about "Squatting" lead to an iffy area where people have a profound misunderstanding about property rights. I have zero "parked" domains, but contemplating the issue long ago made me less outraged when I lazily searched for the most blatantly obvious domains.
You can tell it's not property because the one thing that's guaranteed to result in losing a domain is failing to pay the fees.
The idea that first registration entitles someone to (a) waste a finite resource forever and (b) sell it at arbitrary prices later was fought out in the early 00s, and the real WIPO trademark system won. A number of people who had squatted the names of famous companies in hope of extorting a payout were disappointed.
Don't pay your property taxes and you lose your property. Courts have argued that domains are property countless times, and they are treated absolutely as such. They are in the sense of contract law, with rights and grants, but obviously are a virtual good, of sorts.
https://www.lexology.com/library/detail.aspx?g=016ee90b-496e...
"The idea that first registration entitles someone to (a) waste a finite resource forever and (b) sell it at arbitrary prices later was fought out in the early 00s, and the real WIPO trademark system won."
I specifically excluded trademark infringement, so why are you arguing that case? But yes, someone can "waste a finite resource forever" (by paying the same fee that a "useful" use of it would). Those are the rules of the game.
That may be true according to the current authorities running the show, but clearly those rules are far beyond their useful lifetime now. For practical purposes, domains often function as a primary form of identification, for websites, email and other functions. Both the domain registrant and anyone trying to reach them have a reasonable expectation that the identity in question will not silently and suddenly be changed, a huge amount of everyday activity now depends on that expectation, and the consequences of violating it can be severe. We are well past the point where such critical infrastructure should not be in the hands of private businesses or individuals without sufficient regulation to safeguard the common good.
I don't think anyone disagrees that those are the rules we have. I think everyone who actually creates websites thinks those rules are not working as intended and should be changed.
I refuse to believe that having speculators pay for thousands and thousands of empty domains is "working as intended".
I'm more thinking of the waste and expense. Clogging up infrastructure with utterly useless "holding pages". People spending vast amounts in registration fees in the hope of getting that big win. And that big win being at the expense of a company that genuinely needs the name but is forced to spend massively more than it needs to in order to get it.
If this was what was intended, then whoever designed it was evil.
I certainly agree that opinions can differ whether various things (e.g. intellectual property) should be called property or not. But personally I don't like the dilution of the concept. "Ownership" of a URL is more like a contractual right.
As for your home/land, if you don't pay property taxes the govt may begin a legal proceeding to seize it which must satisfy the usual checks and balances when the govt wants to violate your rights. Then they probably auction it off and the balance minus your back taxes goes to you. The point is you have real rights. Meanwhile your domain may be worth a million bucks at auction but you aren't getting squat because you forgot to pay the $12 fee, or violated some other detail in the contract.
There's a sibling comment that points out that courts recognize it as property, and certainly trademarks are a similar "property" that requires active enforcement.
But while the law is a good authority because they've gone through many disputes and have had to work out good arguments, I don't think it's the final authority; laws can change after all.
That a domain requires upkeep doesn't make it not property. Even in the absence of taxes, your house or any of your stuff requires some degree of upkeep.
But a domain is certainly not chattel, and intangible property always does seem like... not property. (Though, even with tangible property, it feels fuzzy, and that's part of why fences are used to reify borders.)
To my mind, a bigger issue with calling it property is that there's not necessarily a single registry system.
My thought experiment is to ask what we'd do without registrars. We'd all simply advertise our domains to the DNS servers, with all the obvious conflicts that registration is meant to avoid. And we'd have to resolve those conflicts by having the DNS providers agree that a particular advertisment was correct. I think that gets a bit closer to the heart of what "owning a domain name" means.
Owning an agreement with these entities to manage those disputes looks very similar to any other kind of security or bond. It also has qualities of an asset: you can trade it, it's not very liquid, you can derive an income from it by developing things on it, etc. That's why I lean on the side of the "domains are property" camp.
I'm not trying to be spicy -- the literal definition of domain squatting is intentional trademark infringement or confusion. Someone else sitting on your grand plan doesn't make it domain squatting because someone else has their own grand plan they want to sit on.
Squatting by definition is illegally occupying property that you don't own, which would be a trademarked term.
e.g. If someone builds a hut at the back of your property, they're squatting. If someone else looks at your property and decides they want to make it a lucrative Taco Bell location, it'd be pretty rich for them to call you a squatter and claim right to it, yet that's exactly what's happening in that incorrect usage.
This is hardly a hill I want to die on, but on HN -- of all places -- I'd expect we'd have a somewhat proper use of terminology.
"the US legal term defined by ACPA is "cybersquatting," not "domain squatting."
Okay? What is the point of this? The key is the term squatting -- illegally occupying property that is not your own. Calling completely legal, completely compliant ownership of something squatting because you personally don't like it is...well...it's nonsense. It's the dumbing down of terminology.
It also paradoxically means that .com domains are not quite what they used to be: as more cool new companies have a .ai or .co, the public has stopped thinking that "only .com matters". Like I said, the holders of the .coms are just poisoning the well for the TLD.
To address your point directly, I do personally disagree with you that "squatting for speculation" or "parking" as you prefer is harmless. Since ICANN (or Verisign, I guess) controls the TLD, I do think they should disincentivize this holding behavior with some kind of property tax. It's as if vast tracts of Manhattan were just empty fields - not really in anyone's best interest, in the long run, not even the property investors, who are at risk of property developers going to more-hospitable jurisdictions.
Further, nowhere did I say that it was "harmless", or pass any value judgment at all on it. I just said that it's not squatting (cyber, domain, or any other prefix). Those people pay the same domain fees as anyone else.
"I do think they should disincentivize this holding behavior with some kind of property tax"
They are paying the same domain fees as everyone else. However let's imagine that they change it to charging some sort of "how lucrative is the domain name" property tax, like Google hilariously tried to do with some of their failed TLDs: We're currently talking about parked domains that cost an absolutely negligible amount...I imagine a lucrative fee would be a bit more disliked by these imaginary startups ready to fill all the good domains.
Sidenote - there was a rush to .io, .ly and other TLDs -- against all reasonable caution -- because people thought they were cool and new, not because they were their last resort
If they are indeed different, I would argue that learning of an emerging product and preemptively buying the domain is not cybersquatting but more like IP theft.
Regardless, the point remains that the .com TLD is saturated with parked domains, meaning folks must go to more poorly managed TLDs for reasonably priced domains. Personally, that’s not the way the world should work. A parked domain does not offer value to the world the same way that undeveloped/underdeveloped land does. Indeed, a small store holding its own against gentrified land often provides more value to the community that if it were consumed by public domain. And even with physical property, it is possible to seize underutilized land in the name of public good.
TL;DR: I get that you #define cybersquatting in a way that excludes speculative parking. Not only do I disagree with your definition, but I don’t see how speculative parking or whatever you call it is reasonable.
There’s no sane way to validate a domain isn’t in use.
This is such a self-defeating effort, but I don't define it that way, most everyone does. Because the root -- squatting -- refers to occupying someone else's property. This isn't a point in debate -- a quick search verifies that every single authoritative source seemingly in existence is in agreement with me.
"And even with physical property, it is possible to seize underutilized land in the name of public good."
That is an extraordinary action that happens incredibly rarely and is extremely contentious. It does happen, but it's certainly not comparable with "I got an idea and I want that domain".
And let's be real here -- those domain resellers usually sell the domains they are "squatting" [sic] on for an absolute _pittance_. If a couple hundred dollars is what ruins some great startup plan, I'm going to go on a limb and say it wasn't such a great startup plan.
Indeed, what most people want is to say "Hey that's unfair that he's parked on that! Let ME park on that and sit on it indefinitely because I've got a Great Idea that I'm going to get around eventually". That's what 99% of the parked domains already are.
Or how about investment? If you can see the future, pay for the valuable domain before it's valuable, then get your return by selling it to the company that wants it. Isn't that quite a lot like giving money to the company in exchange for a share of the profits? The risk is that you might misjudge and waste money on worthless domains, just like traditional investing.
It would make more sense to let registrars charge what they please instead.
It's the opposite of investing. Squatters aren't providing value they are pure parasites. People are most apt to learn of the parties smartly chosen name not through their marketing but via being the second person to come up with it and learning they must pay the squatter.
- Let the market set the price.
- Recurring fee for holding it to discourage unproductive speculation.
- An authority decides who deserves it and gives and takes according to their rules.
The 3rd option is particularly nasty. Usually, it's very hard and is what communists hope to do on a broader scale. It would certainly result in seizures whenever the authority decided somebody isn't fully utilizing their domain name. Maybe you spent too long setting up your business and right before launch, you get branded a squatter and your domain is taken after you've already used it in all your marketing material, registered a corresponding trademark, and everything. You might imagine the authority would be fair and not kick out a genuine owner like that, but it's unlikely to have the resources or incentive to investigate every case properly.
Registrar: NIXI Special Projects Registrar IANA ID: 700066
The variation between TLD and TLD is massive. Practically all ccTLDs have their own home made rules and more often than not their own technical solutions to match. A big reason why the more exotic ccTLD's can cost a lot of money is the hoops that registrars need to jump through, both legal and technical, and the "workarounds" for both.
In my case it was actually a trademark infringement legal action. My domain got listed as hosting a site that sold knock-off sunglasses[1] . The plaintiff in the case got a court order to transfer all the suspected domains to them, a list of about 1,000 domains. I got no notice, my domain just suddenly disappeared.
I had my lawyer contact the plaintiff, in which we apologized, told them we had no idea this had happened, and promised to up the security (in reality I just nuked the WP site.) About a week or so later they transferred the domain back. For me this was annoying and cost a few hundred bucks in legal fees, but not that big a deal. Obviously not the case for Susam.
[1] My (largely abandoned) self-promotion Wordpress site got hacked, and was used to host an e-commerce site. Weirdly the domain was ${my_real_name}.com, hardly an obvious choice for selling knock off sunglasses.
Same reason that deliberately letting domain registration lapse for a domain that was used widely for email is a scary prospect.
NIXI is regulated by Indian law and is the cctld registrar of .in . The domain records show a registry lock and the new owner being "The Verden Public Prosecutor's Office".
This is not common in India.
In a lot of countries you will lose the name if the well connected person there wants. They'll find a justification that doesn't pass any smell test but you're out of luck. Nothing, absolutely nothing can be done. So use them, but be prepared to lose your names. Everything is fine, until it isn't.
The idea is:
1. By having no other services on it that minimizes the chances that it could get hacked and used for nefarious purposes that might get it seized by law enforcement.
2. By using a meaningless name like 4e4eee247a69fab841ec36eabc95eee9 there is no chance someone will come along with a trademark claim or an accusation that I'm squatting on a name that they have a better claim to.
[1] dd if=/dev/urandom bs=1 count=16 | xxd -g 16
Which brings up the question, is this problem limited to ccTLDs or TLDs like com, net as well?
I've always wondered why so many people are using .io domains (and now .ai domains).
Hum... No. On ccTLDs you have the protections the issuing country gives you. On gTLDs, you have the protections the US gives you.
Some countries won't protect your domains at all, others will protect it even more than the US.
It looks like after going through the courts they have had their domain returned.
Contrast with the situation in the linked post, in which a .in domain was randomly seized without warning, and crucially, without due process. Bodog had the benefit of due process.
Registrars also can't just change owner data, or move a domain between registrars easily, that requires a two-factor authentication.
Most people do not know the difference between gTLD and ccTLDs. They think .io and .ai are just like .com. Registrars like Namecheap ought to do a much better job informing their customers about the risks of using ccTLDs.
There are other options, but they require hosting on overlay networks, and running your own name servers. But then people must install suitable gateway routers to reach your sites. Those can be VMs, but it's nontrivial for most people.
"Over the following years, the Luneberg police and the Verden Public Prosecutor’s Office, in combination with the BSI, FKIE, BFK, and numerous other law enforcement and industry partners, continued investigating the Avalanche network, discovering a massive operation responsible for controlling a large number of compromised computers across the world.
https://www.symantec.com/connect/blogs/avalanche-malware-net...
Rented. They rented this domain for 12 years.
Not to excuse the appropriation. But no one owns their domain, except possibly govs and mega-corps by virtue of mass.
> I have considered shutting down this website several times in the past. But when another of my domain, susam.in, where I used to host my personal blog (archive) was seized and transferred to a law enforcement organization without any notification or authorization, it was the last straw. I do not wish to spend my weekends worrying about spam and unlawful content. I do not wish to maintain constant vigilance on my online servers to maintain ownership. It consumes time, more time than I can afford.
This is sad for WWW. We need more independently run websites, not less. The web of early 2000 is rapidly disappearing.
Its still there, but there is a lot less of it. Recently I've decided to go back to ownership of my music and rebuild my old (~20 000 track) collection. Some of the stuff is rather obscure so I end up on niche blogs with pixelated-animated favicons, no weird whitespace and sometimes almost bare HTML. Definitely makes for nostalgic feelings..
2) Both have to do with site operators experiencing a sense of uncertainty due to problems with the ICANN landscape.
Is it really so hard to comprehend relevance? I'd tell you to try to keep up, but that's against HN rules & regulations, so I won't say that.
gnunet is an application. the fact that the development is hosted on a .org is entirely irrelevant. gnunet's function doesn't depend on it.
Cite: look up Mencius Moldbug or Curtis Yarvin. Alt-right 'darling'.
The tech itself has him residing as the root node, and able to 'kick anybody off the island'.
A domain being seized by law enforcement for hosting illegal content (even if it was put there by hackers) is nothing new and has nothing to do with the state of the modern web.
Centralization is the issue. May it be registries, ISPs, hosting providers or anything else. Heroku and PaaS do not solve this at all.
Of course many people could fill out the ICANN paperwork themselves and run a server from their own home, but many people can do that now too. And if you do that, you still run into the issue of hackers being able to install malware on your systems. But instead of the police seizing your domain, they kick in your door in the middle of the night with guns pointed at your family.
Maybe it would clear things up if you could lay out for me the exact scenario that combines "the web of the 2000s is rapidly disappearing" with "registrar, ISP, and hosting provider centralization is the issue" and ends with "if that wasn't the case, this website would never have had to shut down". I feel like you're remembering the web of the 2000s very VERY differently than I am.
There were a ton of hosts back then, but there still are. I don't remember exactly when registrars became a concept, i'd guess that might have been 1999 though; I don't think there's that many more or less now. A lot more registries with .ninja and .bike and whatever.
I agree though, if law enforcement wanted your domain back then, it would be about the same as now. Although, maybe someone would have called/emailed you about it with whois contacts back then.
Actually it might just be easier to link to the Wikipedia article about ISPs serving the US because there are a lot: https://en.wikipedia.org/wiki/List_of_broadband_providers_in...
Sorry, one of my pet peeves is when people say "the Web of [insert time here] is dead!" when the Web has never been more accessible both from a consumer standpoint and from a developer standpoint. The existence of Facebook and Google can be completely ignored if you actually want to. Emphasis on if you actually want to.
Again, it all comes back to the idea of some people "wish" the web of the 2000s still existed, but aren't willing to sacrifice the comforts of the 2010's web to make it happen. You can host your own lightweight website but Wordpress and Facebook is easier. You can search the web without tracking and Javascript but the modern websites don't work without it. You can pick from a huge variety of ISPs but they won't all be at 100 Mbps. Basically, you can have the web of the 2000s, but it comes at the cost of some of the conveniences of the 2010s web. A lot of people aren't willing to make that trade.
Nostalgia is hard. It seemed amazing back then but not many people would choose to go back to dial-up and phpMyAdmin. For those who say they would... what's stopping you? It all still exists today.
The only way to get good ddos protection is to centralize because it requires you to have close personal relationships across the world in order to get good bandwidth at every location.
And it's the same reactions to it on the internet that hurt and not the DoSes. Just run your website. If it gets DoS'd no big deal. It's not like you even need a single nine of uptime consistency.
I've run my for 20 years from my home connection, I've been a jerk on IRC, I've used it for gaming clans, I've hosted and continue to host tor onion services. I have never been DoS'd.
The first DDoS happened in 1996. Absolutely nothing to do with the current topic at hand, completely off topic.
Do a search, https://www.google.com/search?q=stresser
An attack that can cripple all but the largest networks can be had for $5-10.
The internet really, really needs to be more reliable than this. Losing a domain name for an unknown reason should be impossible. Also, losing a domain name by accident should be a lot harder.
We need create a new internet on the internet that does not search the new internet. DDG brings back content from the same sites google and bing does.
I want a new search engine focused on the passionate creatives who produce for the web. The early adopters of the web who have been overshadowed by the adwords and the interstitials and lightboxes.
I want content. I want a recipe site with the ingredients at the top and a list of instructions below it. Not 6 paragraphs of why you want to eat this food because of your grandma making it and then people come NO, just tell me what to put in it and how to do it and that's it and load in .1 seconds instead of 100 seconds and then stall every time I try to scroll because you need to tell your advertisers which part of your page is looked at the most.
Your advertisers are more important than your readers and it's not cool.
* Stack Exchange Sites
* Wikipedia
Today we have the concept of "user-contributed content", which means content produced without expectation of monetary reward, then uploaded to a site operated by an organization with an expectation of monetary reward. In 1992 these for-profit organizations did not exist: the services through which people accessed the content were created and operated without expectation of monetary reward, too.
It was glorious. There are some valuable content and valuable services that weren't produced in 1992 and would not be produced in the future if it became impossible to profit from producing it, so I don't want to remove the profit motive from the internet. But search results from Google (and its competitors) are now almost completely dominated by for-profit actors, and I agree with grandparent that we need a new search engine that essentially specializes in content produced without expectation of monetary reward.
I don't have any figures - that would be interesting - but I guess even today the 'vast majority of internet content' is produced not expecting any monetary reward. It depends how you count the stuff what exact figure you'd arrive at. 99.9% seems closer to what it might be than 50%. Maybe I'm super-wrong about that.
Of course there are middlemen today like Hacker News and Wikipedia that pretty much stay out of the reader's way, but they are the middlemen for closer to 0.1% of the user-generated content than 50% of it.
Serious question: Do you think the 'old Internet' still exists to such a degree? I'm not just talking about link rot (although most of my links from a decade ago sadly no longer work), but also things like outdated content, like a car review of a 2010 Toyota.
I don't know if the old internet exists anymore, as much as I want it. Sure, we are at an old internet site right now (Hacker News), but what more?
Because you'll try to put something up and you get flooded with spam/hacking attempts and whatnot
Because registering a domain, deploying wp, etc if not so trivial
Gmail and other "big email providers" are needed since there's no litigation against email abusers, and there's a constant flood of crap to the spam folder
Walled gardens are surely problematic but they're less trouble than going independent.
The OP wouldn't be talking like this if he were actually responsible for the "unlawful content".
And seriously, does Twitter lose its domain because someone posted malware or child porn or whatever?
Edit: So where's a safer place to register domains?
Maybe China?
Summary: The Shadowserver Foundation contacted me by email and informed me that my domain name was sinkholed accidentally as part of an operation they were performing. They have now examined my domain name and found that my domain name should be excluded from their operation. They worked with NIXI to transfer the domain name back to me.
Thank you, everyone, for your support as well as for the great quality of discussion on this thread.
I love the WWW, but I don’t mind if Capital will take it. They’ve already ruined much of it... the ads, the surveillance, SquareSpace’s cookie cutter stores, ES6, Webpack, etc. Erasing everything that was good about the old days.
The old will rise again anew.
https://news.ycombinator.com/newsguidelines.html
We detached this subthread from https://news.ycombinator.com/item?id=21671771 and marked it off-topic.
I'd say DNS is the poster-child example of why - in spite of all the naysayers - blockchain is a desperately needed technology.
Sadly, no. In addition to the hive of scum and villainy that are Bitcoin exchanges and other ecosystem players, there are a thousand stories of first-party losses. https://www.wired.com/story/wired-lost-bitcoin/
My point with bitcoin is that bitcoin itself works as advertised. But like gold, directly working with bitcoin requires a good deal of specialist knowledge.
That's why, as with any medium of exchange, you need an infrastructure to manage funds and enable transactions, and the crypto-monkeys are trying to replicate systems that developed over centuries.
If it's authentication of authoritative response data you're looking for then that's what https://en.wikipedia.org/wiki/Domain_Name_System_Security_Ex... is for.