{"id":4230,"date":"2014-10-07T11:46:38","date_gmt":"2014-10-07T15:46:38","guid":{"rendered":"http:\/\/acro.net\/blog\/?p=4230"},"modified":"2014-10-07T11:56:20","modified_gmt":"2014-10-07T15:56:20","slug":"exactly-secure-domain-registrar","status":"publish","type":"post","link":"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/","title":{"rendered":"What exactly is a secure Domain Registrar?"},"content":{"rendered":"<p>Modern security principles are stricter than ever.<\/p>\n<p>Implementing security at several levels involves the admission that any system is vulnerable by default.<\/p>\n<p>Defining the weak points of any electronic system, whether it is on the Internet or on intranets, is the fist step towards establishing a secure platform to launch customer-oriented services from.<\/p>\n<p>As far as domain registrars are concerned, the idea is to build a system on a solid platform. Whether it&#8217;s Windows based or Linux, expert administrators must be used for the job of locking down and maintaining it.<\/p>\n<p>The second layer up involves the use of code that adheres to strict security principles. Code must be audited and scrutinized for errors, omissions or rogue, mischievous circumstances of sabotage.<\/p>\n<p>Physical access to servers and their controlling hardware must be restricted to authorized personnel, with zero access to anyone outside of that particular department. Even if you are the CEO, you should not be able to access the customer data without a recorded decision and authorization, just because you are at the company&#8217;s top.<\/p>\n<p>Isolation of customer data and encrypted storage offline should be meticulous. No partial data should be exposed to the outside, in ways that could lead to accessing the full data, or crucial parts thereof.<\/p>\n<p>Accounts should be non-sequential, to lessen any brute forcing potential, and a hashing system should link the usernames to the accounts, authenticating every access with extra measures present. These measures, should enforce a range of security add-ons, such as two way authentication, IP range authentication, account lockdown after a set number of failed access attempts and other layers of protection.<\/p>\n<p>Domain registrar customer service should be made aware of the dangers of social engineering and other approaches that directly or indirectly would reveal vital account information to random persons. The use of credit card information to authenticate accounts is a no-no. Instead, the use of private PIN numbers, security questions and two-way authentication via apps or SMS should be enforced &#8211; no exceptions.<\/p>\n<p>System auditing should be performed by authorized, licensed professionals that would systematically attempt to identify weak points across every security layer. Logs on everything, from customer account access to internal management of user data should be kept and audited periodically. Mechanisms that trigger alerts for mishandling of data or other breaches, internal or external, should be set in place.<\/p>\n<p>A modern domain registrar is not unlike the United States Bullion Depository, where the gold is stored. So build it like Fort Knox, <a title=\"Moniker password reset points to apparent mass hacking of accounts\" href=\"http:\/\/acro.net\/blog\/domains\/moniker-password-reset-points-apparent-mass-hacking-accounts\/\" target=\"_blank\"><strong>or bad things can and will happen.<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Modern security principles are stricter than ever. Implementing security at several levels involves the admission that any system is vulnerable by default. Defining the weak points of any electronic system, whether it is on the Internet or on intranets, is the fist step towards establishing a secure platform to launch customer-oriented services from. As far [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[601,1091,1092],"class_list":["post-4230","post","type-post","status-publish","format-standard","hentry","category-business","tag-domain-security","tag-secure-domain-registrars","tag-security-principles","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What exactly is a secure Domain Registrar? - Acro.net - A Domain Investing Blog by Theo Develegas<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What exactly is a secure Domain Registrar? - Acro.net - A Domain Investing Blog by Theo Develegas\" \/>\n<meta property=\"og:description\" content=\"Modern security principles are stricter than ever. Implementing security at several levels involves the admission that any system is vulnerable by default. Defining the weak points of any electronic system, whether it is on the Internet or on intranets, is the fist step towards establishing a secure platform to launch customer-oriented services from. As far [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/\" \/>\n<meta property=\"og:site_name\" content=\"Acro.net - A Domain Investing Blog by Theo Develegas\" \/>\n<meta property=\"article:published_time\" content=\"2014-10-07T15:46:38+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2014-10-07T15:56:20+00:00\" \/>\n<meta name=\"author\" content=\"Theo Develegas\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Theo Develegas\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/exactly-secure-domain-registrar\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/exactly-secure-domain-registrar\\\/\"},\"author\":{\"name\":\"Theo Develegas\",\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/#\\\/schema\\\/person\\\/9c9625f061a0e603a87f5bf0f6f781fe\"},\"headline\":\"What exactly is a secure Domain Registrar?\",\"datePublished\":\"2014-10-07T15:46:38+00:00\",\"dateModified\":\"2014-10-07T15:56:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/exactly-secure-domain-registrar\\\/\"},\"wordCount\":430,\"commentCount\":3,\"keywords\":[\"domain security\",\"secure domain registrars\",\"Security principles\"],\"articleSection\":[\"Business\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/acro.net\\\/blog\\\/exactly-secure-domain-registrar\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/exactly-secure-domain-registrar\\\/\",\"url\":\"https:\\\/\\\/acro.net\\\/blog\\\/exactly-secure-domain-registrar\\\/\",\"name\":\"What exactly is a secure Domain Registrar? - Acro.net - A Domain Investing Blog by Theo Develegas\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/#website\"},\"datePublished\":\"2014-10-07T15:46:38+00:00\",\"dateModified\":\"2014-10-07T15:56:20+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/#\\\/schema\\\/person\\\/9c9625f061a0e603a87f5bf0f6f781fe\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/exactly-secure-domain-registrar\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/acro.net\\\/blog\\\/exactly-secure-domain-registrar\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/exactly-secure-domain-registrar\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/acro.net\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What exactly is a secure Domain Registrar?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/acro.net\\\/blog\\\/\",\"name\":\"Acro.net - A Domain Investing Blog by Theo Develegas\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/acro.net\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/acro.net\\\/blog\\\/#\\\/schema\\\/person\\\/9c9625f061a0e603a87f5bf0f6f781fe\",\"name\":\"Theo Develegas\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6794630c371bee89f2b833c1f4b777d9ba75767b217c8fce2cfd6e6d7d90960d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6794630c371bee89f2b833c1f4b777d9ba75767b217c8fce2cfd6e6d7d90960d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6794630c371bee89f2b833c1f4b777d9ba75767b217c8fce2cfd6e6d7d90960d?s=96&d=mm&r=g\",\"caption\":\"Theo Develegas\"},\"description\":\"Theo Develegas - News and opinions on domain name investing, brand development, design, and the occasional rant or two about life's challenges. Founder of Acroplex LLC.\",\"sameAs\":[\"https:\\\/\\\/acro.net\",\"https:\\\/\\\/x.com\\\/acroplex\"],\"url\":\"https:\\\/\\\/acro.net\\\/blog\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What exactly is a secure Domain Registrar? - Acro.net - A Domain Investing Blog by Theo Develegas","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/","og_locale":"en_US","og_type":"article","og_title":"What exactly is a secure Domain Registrar? - Acro.net - A Domain Investing Blog by Theo Develegas","og_description":"Modern security principles are stricter than ever. Implementing security at several levels involves the admission that any system is vulnerable by default. Defining the weak points of any electronic system, whether it is on the Internet or on intranets, is the fist step towards establishing a secure platform to launch customer-oriented services from. As far [&hellip;]","og_url":"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/","og_site_name":"Acro.net - A Domain Investing Blog by Theo Develegas","article_published_time":"2014-10-07T15:46:38+00:00","article_modified_time":"2014-10-07T15:56:20+00:00","author":"Theo Develegas","twitter_misc":{"Written by":"Theo Develegas","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/#article","isPartOf":{"@id":"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/"},"author":{"name":"Theo Develegas","@id":"https:\/\/acro.net\/blog\/#\/schema\/person\/9c9625f061a0e603a87f5bf0f6f781fe"},"headline":"What exactly is a secure Domain Registrar?","datePublished":"2014-10-07T15:46:38+00:00","dateModified":"2014-10-07T15:56:20+00:00","mainEntityOfPage":{"@id":"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/"},"wordCount":430,"commentCount":3,"keywords":["domain security","secure domain registrars","Security principles"],"articleSection":["Business"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/","url":"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/","name":"What exactly is a secure Domain Registrar? - Acro.net - A Domain Investing Blog by Theo Develegas","isPartOf":{"@id":"https:\/\/acro.net\/blog\/#website"},"datePublished":"2014-10-07T15:46:38+00:00","dateModified":"2014-10-07T15:56:20+00:00","author":{"@id":"https:\/\/acro.net\/blog\/#\/schema\/person\/9c9625f061a0e603a87f5bf0f6f781fe"},"breadcrumb":{"@id":"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/acro.net\/blog\/exactly-secure-domain-registrar\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/acro.net\/blog\/"},{"@type":"ListItem","position":2,"name":"What exactly is a secure Domain Registrar?"}]},{"@type":"WebSite","@id":"https:\/\/acro.net\/blog\/#website","url":"https:\/\/acro.net\/blog\/","name":"Acro.net - A Domain Investing Blog by Theo Develegas","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/acro.net\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/acro.net\/blog\/#\/schema\/person\/9c9625f061a0e603a87f5bf0f6f781fe","name":"Theo Develegas","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/6794630c371bee89f2b833c1f4b777d9ba75767b217c8fce2cfd6e6d7d90960d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/6794630c371bee89f2b833c1f4b777d9ba75767b217c8fce2cfd6e6d7d90960d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6794630c371bee89f2b833c1f4b777d9ba75767b217c8fce2cfd6e6d7d90960d?s=96&d=mm&r=g","caption":"Theo Develegas"},"description":"Theo Develegas - News and opinions on domain name investing, brand development, design, and the occasional rant or two about life's challenges. Founder of Acroplex LLC.","sameAs":["https:\/\/acro.net","https:\/\/x.com\/acroplex"],"url":"https:\/\/acro.net\/blog\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/acro.net\/blog\/wp-json\/wp\/v2\/posts\/4230","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/acro.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/acro.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/acro.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/acro.net\/blog\/wp-json\/wp\/v2\/comments?post=4230"}],"version-history":[{"count":0,"href":"https:\/\/acro.net\/blog\/wp-json\/wp\/v2\/posts\/4230\/revisions"}],"wp:attachment":[{"href":"https:\/\/acro.net\/blog\/wp-json\/wp\/v2\/media?parent=4230"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/acro.net\/blog\/wp-json\/wp\/v2\/categories?post=4230"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/acro.net\/blog\/wp-json\/wp\/v2\/tags?post=4230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}