> and to clarify, said account must be protected by 2fa to begin with.
I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mechanism.
> and to clarify, said account must be protected by 2fa to begin with.
I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mechanism.
You do realize that many companies will prosecute people just "following through and testing it", right?
Though the person you did say it to very likely has an international warrant out for them anyway for pissing off the DoD, so I guess it's all water under the bridge.
A bug bounty really ought to be thought out carefully.
And then from all those people you'd still need to find someone who 1) would successfully pull it off and 2) be stupid enough to demonstrate this in a damaging manner.
It’s also worth noting that this offer was made to only one person.
How so? It’s clearly a tweet to a single individual.
Are you saying that based on quality of the service or something else?
I thought your original comment made it sound like there was some obvious reason for keeping DNS and registrars separate.
On the other hand, a registrar transfer is usually simple and quick and has no user visible changes. Unlock the domain, get a transfer code, do any confirmation stuff, make sure the glue records didn't change, you're done.
If you have a high value domain, you might want to look for a corporate registrar, like MarkMonitor or CSC, or anyone else who can do Registry locks (which are very different than registrar locks and are rather inconvenient, but potentially very useful); but know it's going to be expensive. I also had a good corporate experience with register.eu, they've got a lot of ability to satisfy foreign presence needs for restricted TLDs, if that's something you need/want. If it's a low value domain (like my personal domains), I don't have strong feelings, except for the love of whatever you hold dear, don't use Network Solutions; they were a fine choice when they were the only choice, but ever since we had options, they should have been used. A lot of registrars are really pushy with upsells and what not, so I've tried to go with no fuss registrars over the years.
In terms of DNS services, I don't have any particular recommendations; I personally run my primary DNS on my hosted machine and secondary with Hurricane Electric, which is free for my usage. There are (or were) several free secondary DNS services out there, but the one I used to use stopped maintaining their website (TLS 1.0 only, certificate issued 2014, expired 2015) and I already had an account with HE's tunnel broker, so it seemed like a reasonable choice. I still have a domain I host for a friend that uses that old service, because I can't get my friend to update the glue records at her registrar; the service still works enough, I guess.