Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Jeeves

301 posts

Ultimate Geek


#171160 8-Apr-2015 15:24
Send private message

So I just signed up with domainz to register a domain, thinking they have been around for ages and pretty trustworthy.

1) Their credit  card sign up page is not secured.
2) They sent me my password in plain text in my signup email! This obviously proves that they don't encrypt the passwords on their database, and to send it over email?

Wondering if this is grounds enough for me to request that they refund my purchase?

View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
wasabi2k
2096 posts

Uber Geek


  #1279096 8-Apr-2015 15:31
Send private message

Domainz continue to drive me utterly mad every time I have to deal with them. Account managers that take days to respond to an email, 20+ minutes waits on phone. We are not a small customer, we have 250+ domains.

Regarding password in email - they may capture it when you sign up and email, then encrypt and store in DB. But I may be giving them more credit than they deserve.

I would strongly recommend against putting your cc details into an unsecured form, ever.

They also get you to phone for ANYTHING registrar related - very little possible online - it is mental in 2015 I have to spend an hour on the phone to transfer a domain.

1stdomains in comparison I transferred 8 domains online, in under an hour.



Jeeves

301 posts

Ultimate Geek


  #1279099 8-Apr-2015 15:34
Send private message

Hmm. Damn. I've registered my domain with them - is there a cool off period etc or can they now hold it ransom? I want to cancel my account now :(

timmmay
20580 posts

Uber Geek

Trusted
Lifetime subscriber

  #1279111 8-Apr-2015 15:53
Send private message

You can move domains easily, any time, from any reputable registrar. In NZ I think you just need the UDAI code and transfer it anywhere.



mattwnz
20155 posts

Uber Geek


  #1279112 8-Apr-2015 15:53
Send private message

If you just registered a NZ domain, you can cancel it within 5 days anyway. Not sure if they are required to give a refund though, although most NZ registrars do refund if you cancel a NZ domain within 5 days. You would need to ask them.

gzt

gzt
17122 posts

Uber Geek

Lifetime subscriber

  #1279121 8-Apr-2015 16:16
Send private message

2) doesn't prove passwords are not encrypted but at least makes it more likely any enc is not one way if it exists at all.
1) is this even allowed by cc com's? Sure it's not a frame? Look at source.

Check the facts before conclusions.

geocom
594 posts

Ultimate Geek

Subscriber

  #1279124 8-Apr-2015 16:19
Send private message

Jeeves: 2) They sent me my password in plain text in my signup email! This obviously proves that they don't encrypt the passwords on their database, and to send it over email?


There is no way you can come to this conclusion.

You send the server your password in plain text(SSL encrypts this between you and the server.)

So when you sign up or login the server receives your password if it encrypts it, it can still email you the password in plain text as it has it from the request you sent it.

Its not a good thing to do as email is not encrypted anyway but it does not prove that the server stores your password in plain text.

If on the other hand you happen to tell them you have lost your password and they send it to you or tell you it then yes the password is stored in plain text or a weak encryption method that allows them to decrypt it themselves.




Geoff E


wasabi2k
2096 posts

Uber Geek


  #1279132 8-Apr-2015 16:27
Send private message

Jeeves: Hmm. Damn. I've registered my domain with them - is there a cool off period etc or can they now hold it ransom? I want to cancel my account now :(


You can transfer to another registrar pretty much for nothing - just need the UDAI - which Domainz can generate for you.

 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Note that to use Quic Broadband you must be comfortable with configuring your own router.
kiwitrc
4123 posts

Uber Geek
Inactive user


  #1279160 8-Apr-2015 16:53
Send private message

Ha, I got an email from Zeald to say one of their staff had copied details of its clients and was threatening to contact them. They gave details on how to change passwords etc for accounts.

Just shows even the best security amounts to nothing if someone decides to walk out with your details.

robcreid
243 posts

Master Geek


  #1279170 8-Apr-2015 17:14
Send private message

I moved off them some time ago.
I didn't trust them after they got hacked.
What annoyed me the most was not that they got hacked but that I only found out about it via the tech press. There didn't appear to be any customer communication about it.
 

MackinNZ
450 posts

Ultimate Geek

Lifetime subscriber

  #1279186 8-Apr-2015 17:52
Send private message

Move your domain to Metaname.  Great service & support.  Easy DNS management.  Low cost.

Jeeves

301 posts

Ultimate Geek


  #1279442 9-Apr-2015 08:42
Send private message

Thanks, I'll move the domain asap and dispute the charge.

For those assuming that I don't know the facts etc:

They sent my email in plain text. I am aware that they can encrypt it after sending the email, so I did a password reset to double check and lo and behold, they sent my password and username AGAIN in plain text. Ergo, my password is not encrypted on their DB.

The credit card page is encrypted I should add - with TLS 1.0, MD5 and RC4 128. All of these are considered completely insecure these days, so as far as I am concerned, the CC page is not encrypted.

Edit: Boo. I have to wait 5 days before transferring the domain.

alasta
6704 posts

Uber Geek

Trusted
Subscriber

  #1279486 9-Apr-2015 09:33
Send private message

I used to work for Domainz up until about five years ago. I won't go into detail about their back end systems or processes in a public forum, but if anyone really needs to know about this then feel free to PM me.

As I understand it you have two options:
 - Cancel the registration within five days and re-register somewhere else. Domainz will not incur any downstream cost from the registry and should refund you, although you may encounter some resistance.
 - Leave the registration active and transfer it to another registrar. Your payment to Domainz will not be refunded, but the new registrar will honour the registration term that you originally paid for and you will pay them the next time the renewal is due.

itxtme
2102 posts

Uber Geek


  #1279511 9-Apr-2015 10:14
Send private message

Jeeves: Thanks, I'll move the domain asap and dispute the charge.

For those assuming that I don't know the facts etc:

They sent my email in plain text. I am aware that they can encrypt it after sending the email, so I did a password reset to double check and lo and behold, they sent my password and username AGAIN in plain text. Ergo, my password is not encrypted on their DB.

The credit card page is encrypted I should add - with TLS 1.0, MD5 and RC4 128. All of these are considered completely insecure these days, so as far as I am concerned, the CC page is not encrypted.

Edit: Boo. I have to wait 5 days before transferring the domain.


What Alasta said, you dont need to cancel or dispute the payment.  Get the UDAI, use it at new registrar- pay nothing more until it comes up for renewal again..

gzt

gzt
17122 posts

Uber Geek

Lifetime subscriber

  #1279675 9-Apr-2015 14:36
Send private message

Hmm. I wonder if they are subject to pci-dss requirements.

I'm curious what platform & browser you are using.

mattwnz
20155 posts

Uber Geek


  #1279713 9-Apr-2015 15:13
Send private message

Jeeves: Thanks, I'll move the domain asap and dispute the charge.

For those assuming that I don't know the facts etc:

They sent my email in plain text. I am aware that they can encrypt it after sending the email, so I did a password reset to double check and lo and behold, they sent my password and username AGAIN in plain text. Ergo, my password is not encrypted on their DB.

The credit card page is encrypted I should add - with TLS 1.0, MD5 and RC4 128. All of these are considered completely insecure these days, so as far as I am concerned, the CC page is not encrypted.

Edit: Boo. I have to wait 5 days before transferring the domain.


I am just wondering why you are wanting to dispute the charge? You got the domain which is the product you paid for, and the domain is a commodity, so that is all your money got you. eg. The right to use that domain name for the period you paid for.  Just transfer it if you are not happy with the service or their control panels for managing it . Alternatively if you have an issue with the registrar, you should contact the Domain Name Commissioner, and they can look into any possible security issues, as the registrars have to meet their standards.

 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.