INForum.in - Home of the Indian Domain Industry
Page 1 of 2 12 LastLast
Results 1 to 10 of 11
  1. #1
    Ceres's Avatar
    Ceres is offline Senior Member
    Join Date
    Mar 2008
    Location
    Canada
    Posts
    2,206
    Thanks
    544
    Thanked 576 Times in 347 Posts

    Exclamation Bottle Domains Suffers Security Breach

    If the Australian company Bottle Domains is the registrar or host of one of your domains, please note:

    The Australian Federal Police is investigating a security breach at Australian registrar Bottle Domains that may have exposed an unknown number of account and domain name passwords.
    Read more here.

  2. #2
    Jeff's Avatar
    Jeff is offline Administrator
    Join Date
    Mar 2008
    Posts
    2,996
    Thanks
    1,780
    Thanked 474 Times in 277 Posts

    Default Re: Bottle Domains Suffers Security Breach

    I can't believe the registrar actually stores passwords in plain text. It's so ridiculous. Even INForum's software doesn't do that - we could be hacked and there would be no security problems. It's really not hard to set things up so that passwords can't be stolen.

  3. #3
    Ceres's Avatar
    Ceres is offline Senior Member
    Join Date
    Mar 2008
    Location
    Canada
    Posts
    2,206
    Thanks
    544
    Thanked 576 Times in 347 Posts

    Default Re: Bottle Domains Suffers Security Breach

    Bottle Domains has announced that the security breach relates to another breach that took place in 2007 . It is alleged that an employee of a third party registrar is involved.

    The AFP have arrested a Perth male in relation to the investigation.

  4. #4
    RaghavK is offline Senior Member
    Join Date
    Sep 2008
    Posts
    413
    Thanks
    0
    Thanked 3 Times in 3 Posts

    Default Re: Bottle Domains Suffers Security Breach

    Saving passwords in a text file is really really ridiculous..have they updated about any new security features?

  5. #5
    Ace
    Ace is offline Senior Member
    Join Date
    Nov 2008
    Posts
    550
    Thanks
    357
    Thanked 547 Times in 212 Posts

    Default Re: Bottle Domains Suffers Security Breach

    We are in 2009 and and yet passwords are stored in plain text. I don't know what to say, my professor who thought me security would be fuming.

    Jeff, regarding inforum having hashed password, its the software vBulletin which has this small but important feature. In "Bottle Domains" case I believe they might have made custom software and who ever architected the software missed that case.

  6. #6
    Jeff's Avatar
    Jeff is offline Administrator
    Join Date
    Mar 2008
    Posts
    2,996
    Thanks
    1,780
    Thanked 474 Times in 277 Posts

    Default Re: Bottle Domains Suffers Security Breach

    I don't think it was posted about here, but Namedrive recently had a similar issue. What's more, the hackers posted the usernames and passwords in a hackers' forum.

    Ace, your professor is absolutely correct!

  7. #7
    Ceres's Avatar
    Ceres is offline Senior Member
    Join Date
    Mar 2008
    Location
    Canada
    Posts
    2,206
    Thanks
    544
    Thanked 576 Times in 347 Posts

    Default Re: Bottle Domains Suffers Security Breach

    Update: The auDA has now terminated the registrar accreditation of Bottle Domains due to "a serious breach of its obligations under the registrar agreement."

    Nicholas Bolton loses internet domain registration business

    If you have domains registered with Bottle Domains, I assume you'll need to transfer to a different registrar?

  8. #8
    Ceres's Avatar
    Ceres is offline Senior Member
    Join Date
    Mar 2008
    Location
    Canada
    Posts
    2,206
    Thanks
    544
    Thanked 576 Times in 347 Posts

    Default Re: Bottle Domains Suffers Security Breach

    Update #2: Bottle Domains has been reinstated as a domain name registrar after the Supreme Court granted a temporary injunction against auDA.

    In the meantime, Bottle Domains is commencing legal proceedings against auDA over its cancellation of their accreditation.

  9. #9
    Jeff's Avatar
    Jeff is offline Administrator
    Join Date
    Mar 2008
    Posts
    2,996
    Thanks
    1,780
    Thanked 474 Times in 277 Posts

    Default Re: Bottle Domains Suffers Security Breach

    Quote Originally Posted by Ceres View Post
    Update #2: Bottle Domains has been reinstated as a domain name registrar after the Supreme Court granted a temporary injunction against auDA.
    Do you have a link?

    Quote Originally Posted by Ceres View Post
    [In the meantime, Bottle Domains is commencing legal proceedings against auDA over its cancellation of their accreditation.
    On what ground?

  10. #10
    Ceres's Avatar
    Ceres is offline Senior Member
    Join Date
    Mar 2008
    Location
    Canada
    Posts
    2,206
    Thanks
    544
    Thanked 576 Times in 347 Posts

    Default Re: Bottle Domains Suffers Security Breach

    Quote Originally Posted by Jeff View Post
    Do you have a link?
    Bolton takes on internet controller

    Quote Originally Posted by Jeff View Post
    On what ground?
    The article states:

    "Mr Disspain of auDA has acted as judge, jury and executioner by cancelling Bottle Domains' accreditation so suddenly, and this action is now proving to be grossly negligent," said Mr Bloch. "There is now the possibility that, if Bottle Domains wins its case, auDA may be subject to severe damages for loss of business, potentially bankrupting the tightly budgeted administrator."

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Reasons to Invest in Indian Domains
    By Ceres in forum General Indian Domain Name Discussion
    Replies: 5
    Last Post: 02-03-2009, 09:36 AM
  2. 1,200+ premium domains - ALL .com - NO hyphens
    By PremiumGenerics in forum Non-India Related Domains
    Replies: 0
    Last Post: 12-23-2008, 03:08 PM
  3. Expiry Date of .JP Domains
    By Jeff in forum Non-Indian Domains
    Replies: 0
    Last Post: 10-12-2008, 02:29 AM
  4. Gambling Domains Seized in America
    By Jeff in forum Legal Issues and Dispute
    Replies: 2
    Last Post: 09-23-2008, 11:02 AM
  5. 1,000 Indian domains. Comments? Poll.
    By DomainWalla in forum General Indian Domain Name Discussion
    Replies: 4
    Last Post: 09-22-2008, 06:20 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •