<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet title="XSL formatting" type="text/xsl" href="http://www.gandibar.net/feed/rss2/xslt" ?><rss version="2.0"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:wfw="http://wellformedweb.org/CommentAPI/"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Gandi Bar - Security</title>
  <link>http://www.gandibar.net/</link>
  <atom:link href="http://www.gandibar.net/feed/tag/Security/rss2" rel="self" type="application/rss+xml"/>
  <description>Gandi blog, to share our opinions</description>
  <language>en</language>
  <pubDate>Wed, 08 Feb 2012 10:03:57 -0400</pubDate>
  <copyright></copyright>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Dotclear</generator>
  
    
  <item>
    <title>8 Things a Domain Thief Loves</title>
    <link>http://www.gandibar.net/post/2009/02/15/8-Things-a-Domain-Thief-Loves</link>
    <guid isPermaLink="false">urn:md5:6c9c1d3a84fa2e1a2907cad5dadf2899</guid>
    <pubDate>Sun, 15 Feb 2009 21:19:00 +0000</pubDate>
    <dc:creator>Joe</dc:creator>
        <category>Internet</category>
        <category>Domain names</category><category>Domain thief</category><category>Security</category>    
    <description>&lt;p&gt;We all put a lot of effort into securing the &lt;a href=&quot;http://uk.gandi.net/&quot; hreflang=&quot;en&quot;&gt;domain names&lt;/a&gt; we purchase. It may be creative energy finding the perfect name for your blog in an increasingly crowded landscape; or waiting patiently for your company name to be released back into the wild by someone who's owned it for 5 years but never used it.&lt;/p&gt;


&lt;p&gt;Regardless, your domains can be stolen or sniped from right under your nose. We thought we'd take a light hearted look at how to keep your domains safe from potential domain thieves:&lt;/p&gt;    &lt;p&gt;1. Unlocked Domain Names&lt;/p&gt;


&lt;p&gt;The thief does not like a locked domain name, it means they have to go through another layer of protection to steal it. Lock all your domains by default.&lt;/p&gt;


&lt;p&gt;Do you realise how easy it is for a thief to crack your free email compared to pop3. C'mon now, get serious.&lt;/p&gt;


&lt;p&gt;Solution: Lock all your domains by default.&lt;/p&gt;


&lt;p&gt;2. Domain name front running (also called domain sniffing)&lt;/p&gt;


&lt;p&gt;Just because that domain you searched for three months ago is now with someone using it to promote a Nigerian Strip Poker site, does not mean that it was sniffed and then stolen. However, enough evidence does exist to suggest the practice does exist.&lt;/p&gt;


&lt;p&gt;&lt;a href=&quot;http://www.gandibar.net/post/2008/10/22/Why-domain-name-services-are-not-all-equal&quot; hreflang=&quot;en&quot;&gt;http://www.gandibar.net/post/2008/10/22/Why-domain-name-services-are-not-all-equal&lt;/a&gt;&lt;/p&gt;


&lt;p&gt;What more can a domain thief hope for than to know the domain name you want.&lt;/p&gt;


&lt;p&gt;Solution: search for your name on reputable domain registrar's site (not to blow our own trumpet but you won't catch anyone 'sniffing' here)&lt;/p&gt;


&lt;p&gt;3. Weak Passwords&lt;/p&gt;


&lt;p&gt;You may think that having a password like &amp;quot;123abc&amp;quot; is an ironic way to fool password crackers, but you wont be laughing when your domain name is used to promote a One Legged Albanian Car wash service.&lt;/p&gt;


&lt;p&gt;Solution, make it long and hard. the password that is.&lt;/p&gt;


&lt;p&gt;4. Non Variant password implementation&lt;/p&gt;


&lt;p&gt;Yes I know it's easier to have the same password for every online account you own. Not wise, if you lose one, you lose them all. Think about that for a minute.&lt;/p&gt;


&lt;p&gt;Solution: Keep a hard copy of your accounts and respective passwords handy.&lt;/p&gt;


&lt;p&gt;5. Shady, Not to be Trusted Domain registrars&lt;/p&gt;


&lt;p&gt;I'm not naming names here, but there are some places you should not be registering your domain. Your neighbourhood domain name thief knows the weak registrars. When you're a vulture you hang where the meat is.&lt;/p&gt;


&lt;p&gt;Solution: Read up on the registrar, make sure they have a good rep.&lt;/p&gt;


&lt;p&gt;6. Industrial Password Cracking software&lt;/p&gt;


&lt;p&gt;If you have a free email service, or you are with a registrar whose security is weak, then the domain name thief will be bringing out his favourite password cracking software.&lt;/p&gt;


&lt;p&gt;Solution: Chose a long password and include non dictionary letters.&lt;/p&gt;


&lt;p&gt;7. Downloads of Dodgy Software&lt;/p&gt;


&lt;p&gt;If you want to spend hours downloading all six series of T. J. Hooker using Bit Torrent I'm not going to judge you, even though Shatner will be losing the royalties. But, are you really sure that download isn't letting some hairy-assed keylogging software onto your pristine machine.&lt;/p&gt;


&lt;p&gt;Once the domain thief has a keylogger installed he can open a can of rampant destruction on your security and as you say goodbye to that domain name at least Shatner can comfort you.&lt;/p&gt;


&lt;p&gt;8. Naive people who cannot spot a Phishing scam&lt;/p&gt;


&lt;p&gt;I've never met someone who has had their details phished, but who would admit it? If your registrar has sent you an email to confirm personal details or to confirm your password, it is most probably a phishing exercise.&lt;/p&gt;


&lt;p&gt;If in doubt, email or call the registrar.&lt;/p&gt;


&lt;p&gt;So there you have it. It's impossible to guarantee 100% security, but if you make it so hard that even the hardened domain thief cannot work up the enthusiasm, it's job done.&lt;/p&gt;</description>
    
    
    
      </item>
    
</channel>
</rss>
