Hacker News new | ask | show | jobs
by xsc 1974 days ago
Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.
5 comments

Agreed, definitely use 2fa if it’s offered. What many people don’t realize is that there are a lot of registrars still using less secure platforms. So moving to a more secure registrar can help as well.

I mention registering for 5 years in the future because if something like this happens, there will be no question as to whether or not you lost the domain because it expired.

Any recommendations on a good registrar?
Gandi.net is awesome. (not affiliated, just a happy user)
joker.com, inwx.com ,namesilo.com, register4less.com, epag.de, iwantmyname.com, hover.com, Porkbun.com, www.nearlyfreespeech.net

.name domain isn't available in some of these, decide to use inwx.com

namecheap.com is great (always good prices). Obviously, never go with Godaddy.com (rip offs)
We've been using joker.com for years.
Gandi.net
I'm actually not sure for this type of attack how much I'd value OTP authenticators over SMS. They are both vulnerable to phishing in the same way.

What I'd like to see a lot more of is WebAuthn specifically, rather than "hardware keys" generally. It's frustrating to me that the outfits I deal with only have OTP and not WebAuthn.

To phishing, yes, but not to SIM card cloning/social engineering your cell phone provider shenanigans.
Anyone have a short list of registrars who support Yubikey (or competitors)?
Gandi.net seems to support it https://www.yubico.com/works-with-yubikey/catalog/gandi-net/ There’s a short list found here with supported sites including registrars https://www.yubico.com/works-with-yubikey/catalog/
They do, I use it.
This actually rules out a substantive number of registrars. I have a statement from an account manager at our wholesale supplier arguing that the requirement to know both the email address and password is considered "two factor" in the industry.

I don't see why offering MFA hasn't been made a requirement in order to be an accredited domain registrar.

I use Gandi which supports 2FA, but annoyingly they do not let you disable TOTP if you want to use U2F.
I've found that to be pretty common. I guess sites don't want to risk you losing your hardware and then not having a backup method.
Which registrars do you recommend that have 2FA?