Earlier quoted context omitted.
Isn't it just that .gov is the US one? Like .com vs. .co.uk (though since it's not actually important that's blurred) or .org vs. .org.uk. Or .edu vs. .ac.uk; .mil vs. .mod.uk. They got there first and just spread over TLDs before consigning other nations to fit under one I suppose.
I was under the impression that the US government controls / owns .gov
Government URLs that don't end in .gov
41–50 of 202 posts
Re: Government URLs that don't end in .gov
#42I think it's particularly interesting that the US use .gov and not .gov.us (as a Brit). I'm sure there are oversights on who can acquire an inherently international .gov domain, but for example here in the UK .gov.uk domains have a strict application process [0] managed by central government. It just seems to me that it would be more secure, and more reassuring to citizens and visitors that they are on the correct si…
Isn't it just that .gov is the US one? Like .com vs. .co.uk (though since it's not actually important that's blurred) or .org vs. .org.uk. Or .edu vs. .ac.uk; .mil vs. .mod.uk. They got there first and just spread over TLDs before consigning other nations to fit under one I suppose.
Re: Government URLs that don't end in .gov
#43Earlier quoted context omitted.
> it's under a cctld that clearly affiliated to and managed by that government. Maybe this is my latent American nationalism showing, but isn't .gov "clearly affiliated to and managed by" the US government? I think this bit was added as an edit or maybe I just missed it: > an inherently international .gov domain .gov is not inherently international for all the reasons in this subthread (and probably others as well)
I don't think thats clear at all. We have three people in this thread already confused on the issue. I think the poster wasn't talking of the US government but of knowing which government a domain is related to by just looking at it. ".gov" is not clear while ".gov.uk" is clear due to the ccTLD. > but isn't .gov "clearly affiliated to and managed by" the US government I would say no. What makes it clear to you?
Not the OP, but also American. For me it's clear because I've never seen a US government site on a non-.gov domain (though apparently some obscure ones exist as this submission points out), nor have I ever seen a non-US-government site on .gov.
Re: Government URLs that don't end in .gov
#44Earlier quoted context omitted.
> it's under a cctld that clearly affiliated to and managed by that government. Maybe this is my latent American nationalism showing, but isn't .gov "clearly affiliated to and managed by" the US government? I think this bit was added as an edit or maybe I just missed it: > an inherently international .gov domain .gov is not inherently international for all the reasons in this subthread (and probably others as well)
I don't think thats clear at all. We have three people in this thread already confused on the issue. I think the poster wasn't talking of the US government but of knowing which government a domain is related to by just looking at it. ".gov" is not clear while ".gov.uk" is clear due to the ccTLD. > but isn't .gov "clearly affiliated to and managed by" the US government I would say no. What makes it clear to you?
I won't go so far as to say that the internet is an American invention but it was certainly primarily American in origin. .gov has been managed by the US government since the beginning.
Re: Government URLs that don't end in .gov
#45Earlier quoted context omitted.
This sounds like a decent idea until you realize that means one of two options: - A US Government controlled CA root preinstalled on computers. Privacy advocates would be in arms. - Constant untrusted CA warnings when trying to access any government site.
Does our CA/browser infrastructure prevent the government from registering a trusted .gov CA instead of a trusted root CA?
Which is a problem with the root cA design.
Re: Government URLs that don't end in .gov
#46I think it's particularly interesting that the US use .gov and not .gov.us (as a Brit). I'm sure there are oversights on who can acquire an inherently international .gov domain, but for example here in the UK .gov.uk domains have a strict application process [0] managed by central government. It just seems to me that it would be more secure, and more reassuring to citizens and visitors that they are on the correct si…
Do .gov's have to be renewed every year with ICANN? What if a dept lets theirs lapse and some squatter swoops in and takes it? We'll start the bidding at $1B USD...
Re: Government URLs that don't end in .gov
#47A few years ago I was hired on at my local sheriff's department and I was so disappointed that we did not have a dot gov domain.
Re: Government URLs that don't end in .gov
#48I’ve always thought it was weird that the Canadian federal government uses canada.ca almost exclusively. You see a lot of https://service-service.canada.ca/sign-up-sinscrire.aspx .ca is open for registration by anyone, and people are used to seeing that TLD. Combine that with the bilingual super long domain names and every once in a while you’ll see a phishing scam like: https://service-service-canada.ca/sign-up-sins…
I believe the canada.ca thing relates to the centralization of federal government IT under Shared Services Canada (SSC) in 2011. SSC is an attempt to make a "one stop shop" for government IT services, and Canada.ca is an extension of that philosophy to web presence.
As an aside, SSC is very controversial in the Canadian federal government. They have a reputation for glacially slow delivery of services and inflexibility in IT policies. The head of StatCan actually resigned in 2016 in protest as a result of problems with SSC [1]. They have gotten better since then but it's still rocky.
[1] https://www.cbc.ca/news/politics/statistics-canada-interview...
Re: Government URLs that don't end in .gov
#49We need a government root CA more than a government TLD. Domain names aren't even the only thing we should attest.
This sounds like a decent idea until you realize that means one of two options: - A US Government controlled CA root preinstalled on computers. Privacy advocates would be in arms. - Constant untrusted CA warnings when trying to access any government site.
Before Certificate Transparency, I'm pretty sure they already could do that relatively easily by forcing a private CA to make them a cert. (National Security Letters and all that fun)
Even now, with CT, I think they'd be more inclined to use a private or at least an "unofficial" CA, instead of basically leaving "your's truly, The Government" in the CT log. If you already know you'll leave a trace, why would you want to make that trace extra obvious?