Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Risk of lost authinfo-codes

...

The authinfo code is usually send via unencrypted email from the losing reseller to the registrant. Even inhouse the authinfo code is mostly handled carelessly by the registrant. There is a good chance to obtain the authinfo code may be leaked to an attacker. The attacker can use the authinfo code to start the transfer earlier, than the registrant itself. How can the registrant notice such an impersonation fraud without a losing FOA? Which data must be included into the losing FOA to prevent this type of attacks?

Change of Registrant (aka Owner Change/COR)

...