Not really much different than a user buying dankstartup.net, setting up a catch-all email, observing what comes in, and performing password resets for those accounts, allowing for account takeovers.
Calling it a vuln in oauth may be a bit hyperbolic, but Google could help prevent it.
I have catchall email accounts in every domain name I own (mostly so I can do differentiated emails for every service to track/combat leakage), and you would not believe the amount of emails I get that are intended for previous domain owners (and typos too). I haven’t actually done any reset password flows, but there are a bunch of social media and SaaS accounts I could easily take over if I wanted. I used to try to track down whoever the emails were intended to go to and forward it to them and let them know to change it, but that got to be too tedious so nowadays I just ignore them.
Still, I wouldn’t call this a vulnerability on the service provider’s part, it’s just user negligence.
I think it's important to differentiate between domain name squatters and domain name investors. Squatters are typically registering trademarked names with the hopes of flipping them to the trademark holder, or registering accidentally expired domains names with the hopes of selling them back to the previous registrant (as in OP's case). This is wrong.
Legitimate domain name investors are typically investing in generic words, brandables, or exact search term match domains.
I used to get mad about domain investors having every name I wanted to use for a project, until someone analogized it to real estate investing. Everybody would open their store on Fifth Ave. in New York City if they could afford it. Unfortunately, storefronts there are very limited. This is basically what generic, one-word .com domains are (frequent sales of $1M+). Domain names are just digital real estate.
This explains the 30% 24hr growth of Stellar. Stellar has been working in this area for years and is built to facilitate exactly these types of transactions. I think they are probably the best positioned to take this on.
Also, Stellar USDC support was already slated for February.
Definitely not. Ethereum is on top of the DeFi world, for sure. But DeFi is not CeFi. As an analogy: DeFi is to smart contracts as CeFi is to “dumb” contracts. The legal entity behind Stellar has significantly more of the latter than the entity behind Ethereum--which has none, to my knowledge. ... Plus, gas fees. It's currently cheaper to wire money than to send some ETH.
> Plus, gas fees. It's currently cheaper to wire money than to send some ETH.
Wrong. If all you wish for Christmas is to send some ETH, look no further than into ZK-Rollups such as zkSync & Loopring.
1) A transfer costs around $0.01 in fees.
2) ZK-Rollups are not sidechains. These are layer 2 solutions that settle on Ethereum with a novel trust model of 1-of-N: you only need to trust that a single node is honest!
3) Exchanges (such as Coinbase) would eventually support depositing/withdrawing to a rollup, which means most folks would never need to interact the expensive base layer directly.
Sending money across countries has never been cheaper, faster & as secure as it is now on an Ethereum ZK-Rollup.
...yeah... I don't think those words mean what you think they mean...