Big security upgrade for .ZA domain

@Murmaider

Have you guys had to call on ZACR after hours to make any changes to your domain?
What has support been like, have you tried calling at 1 am on a Monday morning and been able to get through within the first call?

Domain Name: domains.co.za
Registry Domain ID: DOM_24PU0-CO.ZA
Registrar WHOIS Server: whois.domains.co.za
Registrar URL: https://www.domains.co.za
Updated Date: 2020-07-29T08:37:59Z
Creation Date: 1998-09-02T22:00:00Z
Registry Expiry Date: 2021-09-02T22:00:00Z
Registrar Registration Expiration Date: 2021-09-02T22:00:00Z
Registrar: Domains
Registrar IANA ID: 1645
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +27.116409700
Reseller:
Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
 
@Jade @ Absolute Hosting

We haven't had the need to phone them at 1am yet, hopefully we never need too.
Fair enough - hopefully the security team that handles this new "security feature" are up to scratch when you do need to make a change.
Murphy never favors regular business hours and ZACR after hours support is non existent
 
@calvin- The issue with the pricing is a customer can go and buy 5 .com domains that come with transfer lock for the same price of locking 1 .co.za domain.

Lets be honest, charging over R1000 for a single status on a domain (a db entry), that should already be the de facto in domain security on .co.za domains is actually ridiculous.

clientTransferProhibited should have been supported and allowed to be set by the registrars many years ago.

The fact of the matter is that ZACR is putting profits above domain security.
 
As @Sapphiron pointed out, any security system which involves humans is one that is open for failure.

The mere fact that the registrar needs to call in and provide a password / passphrase to allow a change indicates that the system is flawed and not secure.

This would mean that staff who work at the registrar and zacr would need access to these passwords in order pass validation and this is a major issue.

Instead the EPP system should provide a mechanism for RAR's to autonomously provide a passphrase which can be used for changing the domains status locked to unlock and remove any possible human interaction. RAR's can then encrypt these fields and the same on ZACR's side.
 
@calvin- The issue with the pricing is a customer can go and buy 5 .com domains that come with transfer lock for the same price of locking 1 .co.za domain.

Lets be honest, charging over R1000 for a single status on a domain (a db entry), that should already be the de facto in domain security on .co.za domains is actually ridiculous.

clientTransferProhibited should have been supported and allowed to be set by the registrars many years ago.

The fact of the matter is that ZACR is putting profits above domain security.

I have not followed ZACR's Ry lock closely TBH, but AFAIK, you're not paying for the database entry, you paying for the human interaction around that. Like, if you source the similar product from Verisign, the one where they charge US$120 pa. That one. Not the Rar lock one. This has already been pointed out to you earlier in this thread.

Oh - and by all means, take them to task about their service levels - at the price they're charging, one would imagine (hope/expect) a decent level of service.

If you want to sell a Rar lock, simply sell your clients a mechanism whereby you auto-Nack update requests.
Of course leaves the pesky problem of the Rant overriding your stuff, but the client can simply automate a nack on that receiving address if they're concerned about that. Or a cleaver Rar could offer this as a service, set the email to their own bot, and auto-nack as per agreement with their client, and you're in the exact position.
Umm, but what if the Rant's email is compromised, you cry. Well, there's a good chance all bets are off in that case, when it comes to protection.
 
As @Sapphiron pointed out, any security system which involves humans is one that is open for failure.

The mere fact that the registrar needs to call in and provide a password / passphrase to allow a change indicates that the system is flawed and not secure.

This would mean that staff who work at the registrar and zacr would need access to these passwords in order pass validation and this is a major issue.

Instead the EPP system should provide a mechanism for RAR's to autonomously provide a passphrase which can be used for changing the domains status locked to unlock and remove any possible human interaction. RAR's can then encrypt these fields and the same on ZACR's side.

I'll let Verisign know their Ry lock stuff on .com sucks....
 
If you want to sell a Rar lock, simply sell your clients a mechanism whereby you auto-Nack update requests.
Of course leaves the pesky problem of the Rant overriding your stuff, but the client can simply automate a nack on that receiving address if they're concerned about that. Or a cleaver Rar could offer this as a service, set the email to their own bot, and auto-nack as per agreement with their client, and you're in the exact position.
Umm, but what if the Rant's email is compromised, you cry. Well, there's a good chance all bets are off in that case, when it comes to protection.

We dont want to sell Rar lock, it should be there by default as protection for peoples domains.
This isn't the 1990's anymore Calvin. We shouldn't have to parse emails anymore.
Modern technology has been created to solve these archaic processes Calvin... like API's and EPP.


I'll let Verisign know their Ry lock stuff on .com sucks....

Sure, but at least they offer Rar lock, unlike some other self-proclaimed "World Class Registry"
 
We dont want to sell Rar lock, it should be there by default as protection for peoples domains.
This isn't the 1990's anymore Calvin. We shouldn't have to parse emails anymore.
Modern technology has been created to solve these archaic processes Calvin... like API's and EPP.

Can I ask you about the API for Verisign's Registry lock? You're an ICANN Rar and signed up with Verisign right? I mean, Jade has an excuse for not knowing how it works, but I'm curious as to yours.
 
Can I ask you about the API for Verisign's Registry lock? You're an ICANN Rar and signed up with Verisign right? I mean, Jade has an excuse for not knowing how it works, but I'm curious as to yours.
I understand how the process works, I don’t understand the exorbitant fee behind providing a service that is prone to human error
 
Can I ask you about the API for Verisign's Registry lock? You're an ICANN Rar and signed up with Verisign right? I mean, Jade has an excuse for not knowing how it works, but I'm curious as to yours.

Please re-read my post properly and take that in context, my reference to modern technology is regarding your comments on registrar lock.

I'm well aware of the registry lock process at Verisign, however this still doesn't detract from the fact that ZACR does not offer Registrar lock as an option.

Please do not even give me the poor example of "what if a registrants email gets hacked, then registrar lock is pointless".

That is like saying that "if your phone is cloned and your email is hacked, they can steal money from your bank account" - sure in that circumstance they can, it doesn't mean the banks shouldn't offer the extra security like 2FA or 3D Secure.

The above example applies to registrar lock as well, it should be offered.
You are mixing a registrants poor choice in email security with something that secures the other 99% of people who do follow good security practices.

ZACR is not offering registrar lock because they want to make money on registry lock.
Hence ZACR is not putting the registrants best interests first, they are putting profits above domain security.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X