logoalt Hacker News

FlamingMoetoday at 6:58 PM6 repliesview on HN

He mentions these 3:

"- Every email address that exists out in the world is now wrong. - Every piece of marketing material is now incorrect. - All of the SEO is gone."

but it seems to miss even the biggest one, which is that you are effectively locked out of any online business accounts, your bank, your crm, anything that says "we noticed an unusual login, please enter the code we just sent to your email to verify the login."


Replies

ryukopostingtoday at 7:53 PM

Yep. Binding 2FA flows to email is risky business for a lot of reasons, but registrar incompetence might be the spookiest thing of all.

show 1 reply
simultsoptoday at 8:32 PM

exactly, few years ago I was thinking to bind all on domain email, thinking when I own it, I can host anywhere and seemed best option. After thinking it through, had to stick to a gmail, again. Due to the possible catastrophy scenario!

Luckily in EU, they still hardly depend on presencs validation, therefore all these sorts of errors can be resolved in couple of hours.

namegulftoday at 7:03 PM

The cascading effect is unimaginable since everything tied to that email.

It is similar like losing phone or sim or even being in a foreign country where you can't access your number but worse.

lukebouchtoday at 7:08 PM

That’s such a good point I didn’t think about!

relaxingtoday at 8:40 PM

Really toxic security anti-pattern.

I’m locked out of my 20 year old wikipedia account because they instituted 2fa without asking and my email on file was no longer valid.

merlindrutoday at 7:35 PM

Also huge opportunity for scams etc if this ever was a targeted takeover type thing. Emails and other stuff go to the same domain, and an impostor could just keep answering correspondence like nothing had happened

And even worse, if I wanted to take over npmjs.com tomorrow and godaddy would kinda... just hand it over (?!?!?!) then i could probably become a crypto billionaire overnight