zlacker

[return to "Tell HN: Godaddy canceled my domain, gave me 2h to respond, then charged €150"]
1. dinkbl+14[view] [source] 2022-08-15 14:40:09
>>M0r13n+(OP)
Hetzner just turned off our hole domain, without contacting us first at all! All servers unreachable, 10k angry customers hammering us. All because if they receive a trademark complaint they won't contact the domain owner first and give them reasonable time to "fix" the "issue" (even 2 hours would have been enough). No, they just turn off the production server and simultaneously send an e-mail "you better respond to their complaint if you want your domain back up".

Totally unprofessional and a complete joke. Will never use them on a production system again. Always angry if they are mentioned here like they are a legitimate choice...

◧◩
2. luckyl+Xi[view] [source] 2022-08-15 15:48:51
>>dinkbl+14
Hey, that reminds me of Cloudflare's response to Phishing Reports. Someone claims you're phishing? Page gets locked and there's no recourse. You can reach out to Trust & Safety, but I've never gotten a reply in over a year. Tech support just says "sorry, we can't do anything about it". So you either live with some page(s) on your site getting a big fat "EVIL LURKS AHEAD" warning, or you migrate off of CF.

That said, with Hetzner I've had the trademark complaints as well, but they've always given us 24h, and were always okay with us saying that our usage (e.g. showing a logo of a shop next to their review) was fair use.

◧◩◪
3. creebl+Vt[view] [source] 2022-08-15 16:36:34
>>luckyl+Xi
I’d like verification of that behavior from CF.

I have an email from them forwarded by a third party reporting phishing on a CF-DNS-hosted site where Cloudflare denied they had any responsibility whatsoever as “they host no content”.

Of course, it requires a subpoena to discover who DOES host the content, as they are the only ones who know.

◧◩◪◨
4. luckyl+OT[view] [source] 2022-08-15 18:31:10
>>creebl+Vt
They'll put a warning message in front of the URL that's been claimed to use phishing ("Warning: Suspected Phishing Site Ahead!"), here's what that looks like: https://archive.ph/qqR8t

They do it for lots of right reasons, I'm sure, but they also do it based on simple claims. While I thought that's a great way to hurt any site if such a claim is all it takes, I haven't experimented with it, so I don't know if you have to make it a legalese thing, or if they do some automated checks. But once you get a site flagged, it'll probably stay so, unless they have some very good connections to CF.

They will forward any complaints also to the hosting company of the origin, but if you're not in luck, the site will be hosted at a questionable company that has no trouble hosting phishing sites. Hetzner for example did quickly react and requested comments from us under threat of shutting down the server. They were happy with our response and their own checks however.

Still, I agree that they should have a way of de-anonymizing who is behind a site, their business is in protecting against technical attacks, not protecting against the law.

◧◩◪◨⬒
5. creebl+Nr1[view] [source] 2022-08-15 21:24:52
>>luckyl+OT
Thanks for that.

By contrast, this is the email that a MAANG company received recently regarding a site being reported for phishing one of their login sites:

https://ibb.co/kcsQN0w

So I guess they are somewhat arbitrary in their phishing actions.

[go to top]