Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> They're insane and should not be in charge.

I remember back when we had to write mechanize scripts to drive a browser through the renewal process, because if you had dozens, hundreds, or thousands of domains there was no nonmanual way, especially if you wanted extended verification or something silly like that.

So what I'm saying is, agreed and that has always been true.

 help



That actually sounds like a good thing. Why are you hording hundreds or thousands of domains?

I was working for a company that had hundreds and thousands of domains. It was a fortune 50 company, and they had a policy generally against wildcard domains.

I really wish I could be this stupid and have enough power to make such stupid policies

I felt the same way at the time. Now, I believe we have better things to spend our collective time and energy on.

What do you mean wildcard domain? Are you perhaps confusing domain renewals with dns entries?

Instead of registering foo.com, and having bob.foo.com, they would register bobfoo.com - they had hundreds or thousands of certs, as a result, and had to renew them all annually or biannually. We didn't even manage all of the domains, we just had to renew the ones our group was responsible for, and it was in the dozens, and each form was ~30-40 actions to fill out correctly. I forget whether they were quarterly or we just ended up doing it all the time, but it was a maddening task.

Part of the explosion was that domains were not just in one TLD, they were bobfoo.com bobfoo.bar bobfoo.xyz and in many cases regionalized to bobfoo.co.uk or whatever. It wasn't "domain hoarding", because if you registered bobfoo.info you'd just get UDRP'd by corporate anyway, and nobody really wanted domains of the form somelongnamebobfoo.com

This was also before something like LetsEncrypt where you could automatically generate certs for programmatic usage, so they were all done manually.


> nobody really wanted domains of the form somelongnamebobfoo.com

You'd be surprised

and renewing annually is a great way to accidentally forget some of these and let someone use them to hack your customers


Not OP, but I am guessing they have domains like fordcareers.com or fordsecurity.com instead of careers.fore.com or security.ford.com, etc

Exactly what they did in many instances.

This really grinds my gears, way more than it should for some reason.

Use the system as it was intended, people!


Far from the most frustrating thing they did, trust me. I could tell you stories for days and never run out of more frustrating anecdotes.

Sometimes you don’t want everything hanging off the main domain, because if DNS gets horked everything goes down.

Really large companies have lots of domains even if they aren’t “hoarding” them. But even a few dozen domains is enough to need automation.

One reason could be to prevent phishers from getting names similar to your actual domain(s).

Should Google be allowed to keep Google dot lol if it doesn't do anything useful with it? What about Google dot wtf? Any person with two brain cells would say these domains should belong to a fervent critic of Google, not to Google.

Sadly neither our world not its legal system is built on common sense.


Domains are an infinite resource. Even a random string of characters can become valuable if the services running off that domain are valuable.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: