Re: Registry lock - two-factor or intervention
Patrik Fältström <[email protected]> Sat, 21 Sep 2013 08:14:21 +0200
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
On 21 sep 2013, at 07:53, Jay Daley <[email protected]> wrote: > On 21/09/2013, at 1:52 AM, Patrik Fältström <[email protected]> wrote: > >>> If this is still the business justification (protection against a compromised Registrar), then there is a problem with facilitating turning on the Registry Lock via the EPP server. >> >> Well, I see that as a potential denial of service attack. But my only point was that we should see the "Turn ON", "Turn OFF", "Make changes" as separate operations as they MIGHT require different mechanisms. > > > There's quite a big risk here that a hacker compromises a registrar, switches a domain name to a compromised site and then locks the record, which makes undoing the malicious change much harder when the registrar regains control of their systems. Correct, what I would say a "denial of service attack". :-P My point is still that the various operations should be investigated individually. Nothing more, nothing less. Patrik _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg
signature.asc
(application/pgp-signature, 195 B)
-----BEGIN PGP SIGNATURE----- Comment: GPGTools - http://gpgtools.org iD8DBQFSPTk9rMabGguI180RAvZEAKCKs0o2/4a5fTGyyR0RtF7FflGSqgCfckhM UqfOnpqdCHnr2DdQjNN00aM= =51kV -----END PGP SIGNATURE-----