Skip to content

Proposed WHOIS changes would kill my abuse response workflow

Domain Names by NUT 6 replies 442 views
#1

New WHOIS proposal would end historical lookups and force registrar-only contact
My abuse pipeline already died after the last redaction wave
Four hour takedowns are now four days
This finishes it

#2

The eu privacy crowd finally won something and now we all pay for it used to pull abuse contacts in thirty seconds flat now its all redacted and I have to send forms to Contabo or OVHcloud and pray someone reads them my phishing takedown average went from four hours to four days this proposed change makes it worse no more historical lookups at all goodbye threat intel

#3

I see problem for security, maybe compromise is, this give access only for verified researcher, not everyone, can be system like in Vultr, they have ticket for whois, this is not perfect but works, voilà, I mean, this works already in some place

POLISH SERVERS. LOUD FANS. GOOD PRICE.
#4
kasiaxus said:
Maybe compromise is, this give access only for verified researcher

VERIFIED BY WHO. The same registrars who can't secure their own portals?

What could go wrong:

  • Centralized researcher database = juicy target for APTs
  • Verification lag means active attacks run unchecked
  • Registrars sell "expedited access" tier
  • GDPR maximalists push for total darkness anyway

I run fail2ban on every whois scraper I operate. Firewalls on the lookup nodes. Still got probed last week from a "researcher" pool that was clearly a front.

The compromise thread mentions tiered access. I submitted comments referencing this exact discussion. Don't trust centralized anything!

airgapped, encrypted, faraday'd, still worried
#5

I had the same issue with Contabo forms, so frustrating

#6

Which registrars would run this verification anyway

builds at 3AM, sleeps at noon
#7

How long is the Vultr ticket queue though

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft