Skip to content

My WHOIS privacy nightmare: verified my identity, got doxxed anyway

Domain Names by dadlime 3 replies 296 views
#1

I paid for WHOIS privacy on a domain registered through GreenCloudVPS (the "protected" tier, not the free one). Six months later, a colleague mentioned my home address was visible in some "historical WHOIS archive."

Turns out GreenCloudVPS's privacy service—run by a third party called VelaShield—had a six-month exposure window. When I verified my identity for a UDRP defense (which I won. Long story), they temporarily removed privacy protection. The "temporary" flag failed. My real data sat exposed for 187 days. It was scraped by multiple archive services.

I discovered this when someone mailed a printed photo of my house to my house. With a note about the domain.

VelaShield offered me free credit monitoring. I asked about their data retention policy. They cited "internal procedures." I asked about the six-month window. They stopped responding.

Has anyone else seen this specific failure mode? (I am particularly interested in whether GDPR article 17 erasure requests would apply to historical WHOIS scrapers. I suspect not, but one tries.)

I have since transferred everything to KnownHost with double privacy layers. Not sure it helps.

#2

Same thing.

I run all my infrastructure on bare metal with custom systemd units; no containers at home, no cloud privacy services either. Þe old way is best.

VelaShield should be liable for þat exposure window. Their "internal procedures" are probably a shell script running on a VPS þat someone forgot about.

#3

Velashield's "exposure window" sounds like a feature, not a bug

#4

I had the same thing with a registrar once, six months is absurd

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft