Live data from Hacker News

Taking control of all .io domains with a targeted registration

thehackerblog.com

111–120 of 258 posts

Re: Taking control of all .io domains with a targeted registration

#111
post #84

Side note: Please don’t use such gray and thin fonts. I had to modify the CSS to use black instead of #555 for the text color.

#555 is still quite dark and should be easy to read. The real culprit is the 300 font weight - when set to 400 it's quite another matter.

Re: Taking control of all .io domains with a targeted registration

#112

Earlier quoted context omitted.

Why should they get any revenue from .io? The .io is an invention of the government and has nothing to do with the original inhabitants. The "original" people were removed well before .io even existed. Might as well demand they get paid for any inventions the military makes while testing stuff out there. And if the British hadn't done this and gave control over to the people living there 50 years ago, they wouldn't g…

When Britain (and thus the US) decide they no longer require the island for a naval base, it will be given to Mauritius. The .IO domain would eventually be deleted, and that territory represented under the existing .MU (Mauritius) domain. Judging by https://en.wikipedia.org/wiki/.mu I don't think the Mauritian people have much benefit from the arrangements for .MU.

.SU - for the Soviet Union - still exists, I somewhat doubt that many TLDs will ever be deleted in general.

Re: Taking control of all .io domains with a targeted registration

#113

This is a huge screwup on the part of the people who run the 'root' of .IO, and their entire operation should be severely scrutinized by ICANN. In my opinion almost all of the 'weird' TLDs which are country codes that are actually operated by a third party commercial service are 95% spam and junk registrations. .TV is a good example. Technical screwups aside, the existence of .IO and the fact that it "belongs" to the…

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

Besides the old .org, what better options are there for software projects?

Re: Taking control of all .io domains with a targeted registration

#114
post #62

Earlier quoted context omitted.

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

As an average user, how do I know which is which? How can I tell whether .ABCXYZ is competently run and trustworthy? gTLDs & ccTLDs have to be some of the worst ideas in Internet history.

ccTLDs (Country Codes) are always two letters. gTLDs aren't.

The gTLDs have a pretty strict ICANN contract they have to follow; ccTLDs are looser.

Re: Taking control of all .io domains with a targeted registration

#115
post #57

Earlier quoted context omitted.

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

There are a few ccTLDs that differ from that, though. DENIC and CZNIC are two that are generally very well-run, DENIC even offering better security and safety than many gTLDs (while also being a cooperative, not a commercial NIC, so prices are very low, too)

It is really nice, that the .de domain is seen more as infrastructure than some business. But there are a few downsides to DENIC as well.

1. you need to have a person (juridicial or natural) with an address in Germany to register and list that person as ADMIN-C

2. if you run a website that provide contents which COULD generate revenue, you have to have an Impressum [1] which includes the address, names, etc. of the website owner.

This is pretty annoying if you are sensitive about privacy and do not want your details out in the open.

[1] https://en.wikipedia.org/wiki/Impressum

Re: Taking control of all .io domains with a targeted registration

#116
post #62

Earlier quoted context omitted.

I'm in the TLD space (we run a fair number of gTLDs). If a gTLD operator screwed up like this then there could be consequences. A ccTLD, however, runs with very few restrictions. I don't see much of consequence happening to it as a result of this. I will, however, say that gTLDs are generally more secure and well-run than smaller ccTLDs, and are worth preferring for that reason. It's a weird historical quirk that .io…

As an average user, how do I know which is which? How can I tell whether .ABCXYZ is competently run and trustworthy? gTLDs & ccTLDs have to be some of the worst ideas in Internet history.

ccTLDs are pretty much the most sensible thing in DNS hierarchy. The "original" TLDs (.com, .net, .org etc) had mostly lost their meaning by late 90s (iirc), and were heavily biased towards the US anyways and as such would have made far more sense as second-level domains for .us, where enforcing the separation could have at least hypothetically worked in some reasonable way.

Re: Taking control of all .io domains with a targeted registration

#117
post #103

Earlier quoted context omitted.

It doesn't really matter at all. The land didn't come with a .io ccTLD. It's dervived from a name the British chose, so it's not like they stole the domain name from those people, right? Displacing settlers is a different question.

Still, why does the UK need a special TLD for a naval base?

IANA allows delegation of country-code TLDs for all countries and territories represented in the ISO 3166-1 standard.

The thing to bear in mind is this standard is used for a number of different purposes historically that has informed territories and other "non"-countries being added.

For example, it is used by postal services for routing physical mail. A lot of far flung island dependencies are coded individually because their mail wouldn't route through their mother country but through other ports.

The addition of "EU", while not a country, reflected the needs of the "EUR" currency code when the Euro was introduced (the first two letters of ISO 4217 currency codes are derived from the ISO 3166-1 standard).

Re: Taking control of all .io domains with a targeted registration

#118

This is a huge screwup on the part of the people who run the 'root' of .IO, and their entire operation should be severely scrutinized by ICANN. In my opinion almost all of the 'weird' TLDs which are country codes that are actually operated by a third party commercial service are 95% spam and junk registrations. .TV is a good example. Technical screwups aside, the existence of .IO and the fact that it "belongs" to the…

People make mistakes. This seems like some manual configuration/technical debt issues. Don't get me wrong, mistakes for these big, highly used TLDs is pretty massive. The scale of this is could have been devastating. Responsible disclosure to the company that runs the TLD seems like the right first step. This should probably posted on ICANN, ARIN, etc mailing lists even now, but I think the writer's original response…

*coordinated disclosure. "Responsible disclosure" is coercive.

Re: Taking control of all .io domains with a targeted registration

#119

Earlier quoted context omitted.

When Britain (and thus the US) decide they no longer require the island for a naval base, it will be given to Mauritius. The .IO domain would eventually be deleted, and that territory represented under the existing .MU (Mauritius) domain. Judging by https://en.wikipedia.org/wiki/.mu I don't think the Mauritian people have much benefit from the arrangements for .MU.

.SU - for the Soviet Union - still exists, I somewhat doubt that many TLDs will ever be deleted in general.

.SU is actually the only former country with a TLD still delegated, and quite a few have been removed. In recent years .AN, .TP, .YU, .ZR have been phased out representing former countries.

Re: Taking control of all .io domains with a targeted registration

#120

Earlier quoted context omitted.

I'm fine with that happening, because the people who run .IO need to be spanked. If their customers are subsequently unhappy that their domain names have been hijacked, they can take it up with whatever corporate entity runs .IO. Same problem as publicly disclosing serious flaws with an SSL/TLS root CA.

I own an .IO domain. Do I deserve to have fake LetsEncrypt certs issued against me and my domain hijacked because some engineer forgot to remove some critical NS records or forgot to register some aliases? Responsible disclosure cat is responsible!

"Responsible disclosure" is a coercive term. It implies that it's irresponsible to do anything else. "Coordinated disclosure" is far better.

That said, coordinated disclosure is the neighborly thing to do, but it's by no means a moral obligation. It would be perfectly fine for the author to tweet about it, for example.

Post reply on HN