I don't want to educate the thieves by elaborating too much. But, basically relying upon the GAINING registrar, a party you have no existing contract with whatsoever, to authenticate a transfer is a stupid idea. The old system of double-authentication (where the existing registrar also had to autheticate) was safer.
The "meat" of ICANN's new policy was the requirement that registrars provide an easy to use unlock mechanism (some registrars like Totalnic were infamous for making it nearly impossible to unlock your own domains). Then, ICANN went too far, in my opinion, in reducing security by making transfers too easy. Yes, too easy for legit transfers, but also too easy for rogue transfers.
__________________
I buy good domain names. Send lists to George (at) LOFFS.com
|