Someone forgot to renew NodeJS.org
nodejs.org
nodejs.org
The root cause here is that some stuff didn't get handed over properly in the switch from Ryan to me as Node.js manager. So, the emails were indeed going to a non-functioning inbox.
It's resolved now, and we're setting it up to auto-renew so that this doesn't happen again.
tl;dr: He who controls the DNS, controls the universe.
Auto renew of course assumes that the credit card on file is current. If the email address is wrong and the cc doesn't work auto-renew obviously will fail. As anyone who has to charge credit cards on a repeat basis might tell you, cc's fail fairly frequently.
Since the domain (any domain) is important it's critical that someone manually also keeps track of the expiration date. And by the way if anyone thinks the answer to this is to renew for the max time period that opens up all sorts of problems in the future when the domain expires and people who were in charge years ago no longer exist and any current people aren't even aware that the domain needs to be renewed. This happens which is why there is an entire part of the domain business catering to what is known as "drop catching" deleted domain names and selling them back to the owners.
Most certainly there is some sort of explanation, and whether or not it was a terrible mistake, being a jerk about it doesn't relieve you from the terrible mistakes you've made in your past - we all have them. And in the end, this is really not a big deal.
This site appeals to the absolute worst in everyone. I find myself becoming an asshole every time I come here, and I don't like that feeling.
I still come here for great commentary on complex topics, but usually resist the urge to look at comments on gotcha articles like this where I know there is probably nothing constructive to say, so the trollishness comes out.
But you'd be surprised at how many people ignore even postal notices that some registrars send.
What you have to keep in mind is that restoring domains that have expired is a profit center for registrars. [1]
And having incorrect email contact info helps as well since not only does it favor that profit center but it also prevents competitors from soliciting your accounts (as well as preventing spam, right?)
[1] In the case of the nodejs.org domain it was taken offline on the day of expiration. It wasn't deleted it didn't go into redemption. Generally most registrars give some grace period (but if you aren't getting the emails that doesn't really matter, does it?)
There is a new policy being floated by ICANN that addresses these issues. If I can find the link I will post.
curl -s -L http://nodejs.org/some-script.sh |sh
I have never understood why people install software like that. I can not remember which project it is that uses this in the installation.apt-get:
$ ls -l /etc/apt/trusted.gpg.d/
Source Installation: $ wget http://nmap.org/dist/sigs/nmap-6.01.tgz.asc
$ wget http://nmap.org/dist/nmap-6.01.tgz
$ gpg nmap-6.01.tgz.asc # apt-get --allow-unauthenticated ...Distributing a hash check over HTTPS would offer some protection against man in the middle style attacks, to the extent that TLS protects against man in the middle attacks, but accomplishes nothing if the server has been compromised.
Distributing a signature of the download gives stronger protection, because the private key can be kept offline and encrypted except when in use. Breaking into a server and overwriting a few files is easier than breaking into someone's laptop in the brief moment where they unlock their keypair to sign a release.
If you have a serious domain, why not just grab the decade.
Domain prices will only go up, sometimes $1 a year, so there are savings too.
Where are you seeing $80 for 10 years (not doubting just curious).
$80 is below the cost that the registrar pays (for .com) to the registry and ICANN variable fees. Not to mention the cost for credit card processing as a variable fee.
Consequently in order to charge that amount the registrar has to make money in other places (could be to charge for things that are free elsewhere as one example).
I do agree with you that sincere language is more likely than sarcastic derision to turn the tide, but you should know that you guys are on the same side.
http://en.wikipedia.org/wiki/5150_(album) and http://en.wikipedia.org/wiki/Peavey_5150
So rockstar in this context is spot on.
But otherwise, that terminology is complete shit, yes.
P.S. I need to listen to 5150 now!
Someone once renewed a hotmail domain after Microsoft forgot.
Registrars should allowing gifting, source doesn't matter.
There are some problems with allowing that though. In some cases a clueless CSR could allow the person paying for the domain to gain access to it. The assumption is wrongly made that if the person is paying for the domain they have rights to it. After paying they will simply say something like "oh, by the way my address needs to be changed" or open a conversation about something else and end up gaining access.
This is what ck2 is referring to. Its was an interesting incident.
Slashdot discusssion around it: http://slashdot.org/story/03/11/06/1540257/microsoft-forgets...
Registrant Name:Ryan Dahl
Registrant Organization:Joyent
Registrant Street1:345 California St Suite 2000
Registrant City:San Francisco
Registrant State/Province:CA
Registrant Postal Code:94104
Registrant Country:US
Registrant Email:ryan@joyent.comDoing a quick Whois for nodejs.org show that the name is expiring today:
Domain ID:D157222203-LROR
Domain Name:NODEJS.ORG
Created On:29-Sep-2009 14:50:55 UTC
Last Updated On:20-Sep-2011 00:04:23 UTC
Expiration Date:29-Sep-2012 14:50:55 UTC
Sponsoring Registrar:eNom, Inc. (R39-LROR)
Status:OK
Ouch!
This wasn't done by enom. It was done by the reseller, namecheap. Their DNS is in the record (and it points to a page controlled by namecheap).
[citation please]
Start here.
1. Domain ‘expires’, and enters a 40 day grace period. I have read things that imply this can vary from registrar to registrar, but it seems pretty standard from what I have seen.
2. After the grace period, it enters a 30 day redemption period. Again, apparently this can vary, but I have yet to see it (admittedly I have only looked at a small number of domains)
3. Finally, when the redemption period expires, a 5 day ‘pending deletion’ period is entered.
Between 11am and 2pm Pacific Time on the 6th day of pending deletion, the registrars theoretically start dropping the names from the ICANN database.
It is kind of odd that such a domain would only be renewed annually... it's hardly speculative!
In this particular case namecheap is merely a reseller for enom.
Important to point out here that namecheap which is much touted on HN as being so great to deal with is the organization that made the decision to take this domain offline - not enom.com the registrar.
- Send postal notice (some do this already) - Send express or certified letter (charging up front to be notified this way) - Make phone call - Send email to any contact addresses on the website
I would like to point out also that this is a reason also why "privacy" on whois is a bad idea in some cases. In this case it is fairly easy for a third party to get in touch with the joyent contact (someone might know him or have an alternative means of contacting him - even by phone if not the whois phone number). If contact info is protected by privacy that becomes a different issue (you would have to have more specific knowledge).
Grace period (as you have pointed out somewhat) varies by registrar. The basis for what you are saying is how long a registrar has to delete the domain before they can get their money refunded. That time period is 45 days. So on the expiration date the registrar is automatically charged for the renewal. If they delete on day 45 (by a certain time depending on when registered) they will have their fee refunded. Consequently they can give a grace period if they want of up to 45 days but from a practical standpoint it's tricky to wait until the last minute before deleting (if you have a system problem on day 44 that prevents you from deleting 2000 names you're stuck with them).
After they delete the domain (which can theoretically be anytime and keep in mind that "delete" is different than "take off line" "change ownership" etc.) it goes into redemption.
It is in redemption for 30 days during which only the sponsoring registrar can submit the necessary report to get the domain back. With .com .net .org .info the cost for the registrar to get the name out of redemption is $40 plus the renewal fee.
Once 30 days have past it is in pending delete and goes into a 5 day black hole where nothing happens and not even the sponsoring registrar can get it back. After that 5 day period it's released and anyone can grab it, first come first serve.
nodejs.org as I pointed out elsewhere was simply taken offline. It wasn't "deleted" in the sense that it goes into redemption. From the registrars point of view this makes sense since it allows them (if they want) to charge a fee to restore the domain w/o having to incur any extra ($40) costs.
"the registrars theoretically start dropping the names"
The time the domains drop is not controlled by registrars. It's controlled by the registries. The registrars only control (in addition to other things pointed out) when the domain goes offline or gets "deleted" and enters redemption.
" it enters a 30 day redemption period. Again, apparently this can vary"
Can't vary it's 30 days.
Thanks for clearing up the redemption period invariability though.
"here’s how the domain expiry process works." (might have been better to say "here's how I think").
"Domain ‘expires’, and enters a 40 day grace period" although you qualified this saying it like that gives people the wrong impression of your actual knowledge in this area.
"After the grace period, it enters a 30 day redemption period. Again, apparently this can vary, but I have yet to see it "
You say "it enters" (like a fact) but then say "it can vary, but I haven't seen it yet".
My point isn't to give you a hard time but on HN crowd tends to jump on anything incorrect and it's clear from your summary that you don't have much experience in this area. I've made mistakes when I've said things on HN that I haven't doubled checked or don't know very well. (It's possible of course to even make mistakes on things you know well!)
Domain Name:NODEJS.ORG
Created On:29-Sep-2009 14:50:55 UTC
Last Updated On:29-Sep-2012 16:27:30 UTC
Expiration Date:29-Sep-2013 14:50:55 UTC