Namecheap takes great care of me at $10/year though, so I'm not very compelled to switch.
Namecheap takes great care of me at $10/year though, so I'm not very compelled to switch.
The domain renewal with whois privacy/guard at NameCheap ends up being a little more than Google Domains.
I keep hoping NameCheap will overhaul their control panel design like they did with their main site.
I will probably end up moving to AWS Route53 or Google Domains or to use their DNS and a clean/modern interface and simpler pricing (include whois privacy).
It's been how many years now? And all they say is "we're working on it" and have no ETA. So we moved most things to Gandi.
Feels good having no GoDaddy, however.
<insert-standard-many-hundred-line-exchange-between-you-and-I-that-has-happened-in-other-HN-threads-here>
DANE can work perfectly fine with the existing CA system to provide another way of verifying that the correct TLS certificate (or CA) is being used. Or... it can be used with a completely different trust anchor or TLS certificate that you control. Your choice.
But you and I will just have to disagree on this topic. Your dislike of DNSSEC is well-known, as is my support for it.
1. I sign my domains and generate a DS record.
2. I upload the DS record to my registrar who passes the DS record up to the .COM registry.
Now, when someone does DNSSEC validation on my DNS records, they wind up doing this process:
1. Going through the DNS process to get my DNS records as well as the DNSKEY and RRSIGs.
2. Following the chain of DS records up to the .COM registry and on up to the root of DNS... being able to validate along the way the integrity of the records.
Where do world governments get to interfere here?
If a govt were able to manipulate the TLD registry the best they could do would be to point my domain to some other name servers that weren't mine... is THAT the attack you see? I seriously would like to understand.
This is not, of course, the only problem with DNSSEC. It's also an archaic 1990s cryptosystem built around 1024-bit PKCS1v15 RSA, which by default makes every DNS record in the system public, trivially dramatically amplifies DNS traffic, and does all this without actually securing DNS lookups from browsers, which still run the old insecure DNS protocol to talk to DNSSEC-enabled caches.
It's a silly system, has been since the USG paid TIS to design it in the 1990s, is nearing two decades delayed, and isn't going to happen. Look at what Chris Palmer from Google has to say about it. Whatever the opposite of "betting on it" is, that's what Chromium is doing with DNSSEC. We should get to work designing a modern alternative.
http://www.zdnet.com/article/europes-answer-to-terror-attack...
Welcome to the new world.
I did move a couple of domains to Google Domains. While they do not provide DNSSEC in their DNS hosting, they do support DNSSEC records (DS) if you host your domains somewhere else that supports DNSSEC signing.
But really all registrars boil down to two "types" the sub-$20/year ones (which are like 90% of the market) and then the $1K+/year ones which bundle in all kinds of brand protection products and domain protection stuff (e.g. Mark Monitor).
Neither Google or Name Cheap are different enough for price to be a deciding factor, but NameCheap has a better track record than Google in this specific space. GoDaddy is someone I wouldn't touch even if they were cheaper, I hate their bullshit (e.g. upsell, misleading checkout, misleading prices, etc).
If you could pay $5 extra a year and get better service, if it was a business website I'd definitely consider it, but for personal shit I wouldn't, and in general there is no way to spend just $5 or similar more a year and get any marked improvement.
The only thing which might be an upgrade is $12/year for the registrar and then $6~7 for Route53 on top. That's a nice improvement for an extra few bucks.
* Use code WGSPECIAL for a discounted whoisguard. :)
* Renewals for several years at a time offer a baked-in savings.
* Our control panel overhaul is underway. It's a huge project for us, but we're ecstatic.