Live data from Hacker News

Save .org

savedotorg.org

231–240 of 355 posts

Re: Save .org

#231
post #226

Earlier quoted context omitted.

.com has price caps. Imagine what happens when they remove those and they can just price everyone out of their .com names, names they may have had for 25+ years. Imagine a world where whomever has the most money can control your brand. What happens when McDonalds buys the Burger King brand because BK was priced out? .com, .org, and .net are long standing shared resources that should not have unlimited prices. They sh…

I agree with your principles. If it came to that, I'm pretty sure there would be a hard response by the worldwide body of developers and companies (especially the 80-90% of small businesses that make up rich economies; the biggest corporations altogether barely accounting for single-digit % of national GDP, so I don't know who's the target of price hiking to a ridiculous degree). There are ways to circumvent DNS so l…

Another option will be using an alternative DNS root such as OpenNIC which is user owned and controlled. Besides offering resolv of ICANN root, it also adds its own TLDs. The now defunct ORSN was also another choice.

Re: Save .org

#232
post #175

Earlier quoted context omitted.

> And let's not forget that DNS is ultimately a global issue, which means that the rule of law cannot be taken for granted. I think this strongly points towards ccTLDs being the best solution. It is very difficult to get all the different countries to agree on common rules/governance for the legacy TLDs, but if everyone gets their own independent corner then that should be easier to get agreements on. Dividing the co…

I think ccTLDs don't work so well in a globalised world. Many internet services are not country specific, and ccTLDs sort of put you in the local business category.

> Many internet services are not country specific

The companies and/or owners of those services do operate under a certain legal aegis, though. It’s not like they are stateless.

I just happened to read the text on a food product; it had text in three languages, and the www.* domains listed in the three texts were in the ccTLD for each country. No .com was mentioned anywhere.

Re: Save .org

#233

As a plan B. Is there any top level domain run by a non-profit where I can switch to long term?

If you mostly trust your local government, perhaps your national ccTLD would be fine?

Re: Save .org

#234
post #230
post #215

Earlier quoted context omitted.

I agree. As long as there's scarcity, there's someone trying to exploit it. I think it could be better to just accept that unique global names are not a great idea, and start identifying parties by certificates rather than name. Various chain of trust & reputation type arrangements can be used to ensure people won't confuse Their Bank (certificate issued by/for Their Bank) for Their Bank (certificate issued by & for…

> Various chain of trust & reputation type arrangements The problem of course is that as you said, you still need authorities or a chain of authorities to tell you which one is the genuine Debian and which ones are trying to shove malware onto your machines. Today we go to debian.org, see the valid TLS cert, and assuming there’s no fraudulent issuance of debian.org cert and no attacker injected their cert into our de…

I don't have a problem with having authorities as long as we can choose which ones to trust (and have limitations on the scope of their authority), and form our own as necessary.

For example, I'll be happy to add and pin my government's authority for the services that they control. I'll be happy to add a group of FLOSS hobbyists issuing certs for open source projects, as long as they are transparent and can demonstrate that they have a handle on security. In both cases, there must be some way to limit the scope of their authority, and ideally do things like pinning the authority so that one can't sneakily take over the other in an attack that results from e.g. misconfigured scope.

I think establishing identity is something that we should learn to do. When John Smith gives me his phone number, I'm probably looking at his face and I know which John it is that is giving me their number. I should also be able to go to my bank and get their cert when I sign up for an account & credit card. I'd like to have additional confirmation of their identity (-> reputation) e.g. from my government, but I don't know if I want them to be automatically trusted just because there happens to be a chain that checks out.

If I'm looking at some entity that I cannot meet in person, I should be able to see who have vouched for their cert and make a judgement based on that.

Kinda like PGP I guess, at a larger scale and with better infrastructure (geek signing parties and wide open keyservers are not good enough). The system does not need to be centralized.

It should be possible to have certs signed by multiple parties, to help establish trust without having everyone agree on a single source of trust. (At this point, I'd like to use a term that sounds smaller and less powerful than authority)

I'm not particularly happy with the model where the chain of trust in every case is established starting at some international megacorps that do who know what, and countless issuers are directly or indirectly "trusted" from the get-go until someone points out their abuse and removes their certs.

Re: Save .org

#235
Why can't we simply configure clients to use a phonebook we like, rather than the phonebook we don't like?

Today, it's relatively easy to create something like a piece of software and a db of alternative roots. And any clients which have that kit installed are suddenly simply ignoring pieces of what the traditional roots say.

Yes it would be fractured for a while. But it's no worse than say, dns over https, and the way say, you can't reach archive.is while your browser is using doh, but can when you turn doh off. (unless they finally fixed that, but that was the situation for a ridiculously long time after both cloudflare and archive.is were made aware.)

We already have such things today, so might as well employ it as well as suffer it.

Re: Save .org

#236

Earlier quoted context omitted.

If we in the United States had a forceful, competent FTC or FCC, perhaps this would be investigated. I don't think a Sanders or Warren administration would ignore something like this entirely.

The SEC are both competent and forceful, and this smacks of self-dealing, which is within their remit.

ICANN is a "non-profit". They do not issue a publicly traded security, and so they are not subject to the SEC's jurisdiction. The FTC is probably the best hope for intervention in a matter like this.

Re: Save .org

#237

Why can't we simply configure clients to use a phonebook we like, rather than the phonebook we don't like? Today, it's relatively easy to create something like a piece of software and a db of alternative roots. And any clients which have that kit installed are suddenly simply ignoring pieces of what the traditional roots say. Yes it would be fractured for a while. But it's no worse than say, dns over https, and the w…

As a website owner, how do I track down all the alternate roots I'd need to register with? If each of those charge a fee, how much will I need to spend on each root? If I need to perform an OPS task like flipping to a new external load balancer IP, how many alternate robots do I need to coordinate with, and how much testing do I need to verify each root is updated?

Re: Save .org

#238
post #38

Earlier quoted context omitted.

If you decentralize, you don't end up with something equivalent to "the internet" anymore -- you end up with several islands of things that (to varying degrees) resemble "the internet", and run on the same layer 4 fabric, but are largely isolated from one another. I think we actually experience a mild version of this today, where entities publish their all their Twitter/Facebook/Instagram/Snapchat/Whatsapp/Linkedin e…

Islands already exist, with national firewalls, corporate networks, dark nets, etc. Decentralization of DNS would just take middlemen out of the picture. A dominant decentralized system would probably handle most requests if one were to ever get off the ground, making it equivalent to what we have now.

> Islands already exist, with national firewalls, corporate networks, dark nets

And you don't see companies posting their addresses on those things. They still advertise "example.org" not "if you're in {county} use {county-specific address}, or on Tor use {onion address} or using {decentralized DNS} use example.com".

> A dominant decentralized system

How does this result in a different situation then the "centralized" DNS we have today?

Re: Save .org

#239

Some further background on what happened. I don't see how this can be interpreted as anything other than corruption, plain and simple. https://www.theregister.co.uk/2019/11/20/org_registry_sale_s... "Former ICANN CEO Fadi Chehade personally registered the domain name currently used by Ethos Capital in May and it was registered as a limited company in the US state of Delaware on May 14. That date is significant becaus…

Posting from a throwaway account. I worked at one of the main TLDs for years and was on one of the ICANN boards and got to know the industry well. It is well know amongst the domain name community that ICANN is a poorly run organization, whose directors have in recent years have used their position of leadership to lead decisions from which they are afterwards benefiting themselves economically, in many cases by rush…

At the risk of being overly-nationalistic, this is exactly the sort of scenario that many were worried about when the rest of the world demanded that the US hand over control to an international governing body. Just as you see with - for example - the IOC, many international governing bodies have a dangerous tendency to devolve to the ethical standards of their most corrupt members.

Re: Save .org

#240
post #222
post #198

Earlier quoted context omitted.

The process of mapping name=IP is not remotely technically difficult, and I'd dare say most people reading this message could implement the backend to such a system in a few days. Setting up the peering replication and nameservers around the world is considerably harder, but it's definitely not a $10 billion+ problem (the current value of registrars and certificate authorities.) A startup funded by YC could handle th…

I may be mistaken, but I always thought DNS resolution was handled by the underlying OS, and not by the browser through HTTP. Support from browser vendors would probably matter a great deal for this, but not at a technical/implementation level, right?

Conventionally, yes, but that's changing somewhat with the deployment of DNS over HTTPS.
Post reply on HN