List of Available LLLL.INs as of August-27th, 2016

Here is the list of all available LLLL.INs as of the scan done on August 27th, 2016.

Here are the stats:

Available: 245,105

CVCV Names Available: 0

VCVC Names Available: 7,894

AAAB Names Available: 0

ABBB Names Available: 0

ABAB Names Available: 0

AABB Names Available: 0

ABBA Names Available: 25

CHIPs Names Available: 691

The trend graph is:

Dropping.LLL.IN.By.Month

Three Factor Authentication Provided by DynaDot

Domains getting stolen is not new. Like every valuable object in the world, premium domains are susceptible to being taken. What differs is the mechanism by which these are stolen compared to physical objects. Usually, it’s one of these methods:

  • Phishing attacks: These manifest when users are tricked into clicking on links that mimic the real URL and site and the user is led to believe that they are on a legitimate site. Once the user enters the credentials on these illegal/fake sites, the password is stolen.
  • Simple/Obvious passwords: Having simple or obvious passwords is the biggest reason why passwords are a weak form of security. There are various reasons for users having weak passwords, but its a reality that we live in today.
  • Social Engineering: In this form of attack, the attacker tries to impersonate a user (when interacting with a registrar) or impersonate a registrar (when interacting with a user) and somehow gain access to to the domain(s). Social engineering predates the internet and can be as old as any trick.

There may be other forms of attacks in the wild as well, but the ones as mentioned above are the most common ones. In the past few years, as stolen domains are becoming a big issue and registrants wanting some more security, the registrars started offering two-factor authentication. With two-factor authentication, in addition to a password, some other form of authentication is used. Most commonly, the second form of authentication is something that the user possesses exclusively with him/her. These days, the second form of authentication involves a code that expires in a short span of time and is SMSed(texted) to the registrant after with authenticating with a correct password. So, the user enters the SMSed code to gain access to their account. This is another layer of security in case the password is compromised.

In my opinion, this a big step up by registrars to provide extra service to its customers. But, keep in mind that two-factor authentication is NOT a silver bullet against names being stolen, it just makes stealing harder. For example, it is possible that an attacker can social engineer the telecom company to transfer the SIM card to them (attacker). See these two links about how SIM cards can be compromised: Link1 and Link2. When this happens, the attacker can receive SMSs from the registrar for authentication and along with the compromised password, gain access to a user’s domains. DynaDot, a registrar, have recently come out with a different approach to preventing domains from getting stolen. Instead of using SMSs for authentication, DynaDot uses Google Authenticator  to authenticate user along with username and passwords. Google Authenticator is an APP that generates a time-based (60 seconds)one-time password and can be used to log in. However, even after the user logs in, the account is still secure, as the transferring domains out or getting EPP code requires unlocking the account again. The unlocking of the account requires:

  1. Month and date of birth
  2. The token code from Google Authenticator
  3. A token code from SMS

As you can observe from the above, getting all the three above could be challenging. Another reminder that these are extra layers of security which decrease the chances of domains being stolen, but not 100% secure. Also, note with DynaDot, after an account is unlocked after correctly entering the above three pieces of information, the account gets locked automatically after 60 minutes.

In the future, I expect that that biometrics being ubiquitous and would be used to secure domains.

Disclaimer: This is NOT a paid post.

Lok Sabha TV Programme on Domaining

Lok Sabha TV, a channel associated with the lower house of the Indian parliament (Lok Sabha) aired a programme on domaining on August 8th, 2016. The name of the show is India Speaks and is hosted by Mr. Anurag Punetha. The participants were:

1. Mr. Dima Beitzke (CFO – SEDO)
2. Ms. Sophie Pieck (Country Manager of France / Italy / India – SEDO)
3. Mr. Paul Singh (Paul.IN)
4. Mr. Aishwin Vikhona (UIX.COM
5. Mr. Gaurav Kohli (President – DNOAi)
6. Mr. Pankaj Vijayvargiya (CEO – Bitlevel International)

The format of the show more a question answer session type where the host would ask questions on a subject and this occasion it was about state of domaining in India. ALSO NOTE THAT MOST OF THE SHOW IS IN HINDI.

Here are the questions asked during the show:

  1. Introduces the members.
  2. What is the need of a conference ? Question asked to Gaurav Kohli.
  3. How big is the domain market ? And how big is the Indian domain market ?
  4. Question to Paul about being in US and interested in .in domains ?
  5. What goes into the decision making of investing in a particular TLD?
  6. Question to Pankaj talks about the his portfolio size
  7. Aishwin talks about how he got into domaining.
  8. Anurag asks if he had to get a name for himself, would he get AP.COM or AnuragPunetha.COM ?
  9. Question what are the differences between Chinese and Indian market in terms of short domains?
  10.   At what point is the growth of Indian domain market?
  11.   Are easily pronounceable names good investment option ?
  12.   How do you go about registering .in names ?
  13.   There are many associated cottage industries catering to domains, why is SEDO doing so well?
  14.   How does some domain investor start getting into the domain business?
  15.   Are there any risk associated with domaining in India?
  16.   What is the ROI can a domain investor expect?
  17.   Are there big sales taking place in recent times or are they rare ?
  18.   Question to Aishwin about his book — “Sell Domains Fast” ?
  19.   What companies should one use for transactions ?
  20.   Question to Indy about despite being in US, why is is interested in Indian extensions? (I know it is repeated)
  21.   Question to Pankaj about advise on domaining?
  22.   Are there are various news sites about domaining?
  23.   Talk about DomainX conference
  24.   What are the changes taken place in the last 4-5 years that changed Indian’s knowledge / curiosity about domains?
  25.   Question to SEDO about any advise that they would like to give to Indian domain buyers?
  26.   Another question to SEDO about what kind of questions do Indians generally ask?
  27.   Question to Paul about his blog?
  28.   Is .COM done and dusted?
  29.   Last major question to Pankaj if he intends to keep investing in domains ?

You can see the full program here with answers:

https://www.youtube.com/watch?v=G97SRuKuZQY

List of Available LLLL.INs as of August-19th, 2016

Here is the list of all available LLLL.INs as of the scan done on August 19th, 2016.

Here are the stats:

Available: 245,180

CVCV Names Available: 0

VCVC Names Available: 7,893

AAAB Names Available: 0

ABBB Names Available: 0

ABAB Names Available: 0

AABB Names Available: 0

ABBA Names Available: 27

CHIPs Names Available: 703

The trend graph is:

LLLL.INs.Trend