Live data from Hacker News

.name Termination

neil.fraser.name

201–210 of 551 posts

Re: .name Termination

#201
post #41

Earlier quoted context omitted.

Also note that their response is the exact length of the shortest allowed one, and yet still wrong.

I want to hear you justify, with perfect gravity, “N/A.” being the exact same length as “None.” Pictures of handwriting or specific fonts accepted. :D

    N . / A .
    N o n e .

Re: .name Termination

#203

It kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.). Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd l…

To me that sounds like reasonable structure. I hold that every single edu, gow and mil domains should be moved under respective ccTLDs. After this sort of move that doesn't seem unreasonable thing.

Re: .name Termination

#204
post #138

Earlier quoted context omitted.

There are many examples; k12. .us is another.

It is (or was for a long time, IDK) a strongly recommended practice from ICANN. I imagine nearly all countries to do that.

There end up being some weird edge cases where there are some countries which have both the equivalent of .co.uk but also allow registrations directly under the two-letter country code as well. .mx is one such case where most business are, e.g., costco.com.mx, but it’s also possible to register directly under .mx as well so Toyota Mexico is toyota.mx and not toyota.com.mx (the latter is registered, and ostensibly to Toyota, but the whois and nslookup records give very different results and the website doesn’t load when I try to visit it).

Re: .name Termination

#205
post #116

Earlier quoted context omitted.

Since neither smith.name nor the wildcard *.name appear in the Public Suffix List ( https://publicsuffix.org/ ), browsers would likely allow any page on a *.smith.name domain to set cookies for .smith.name. There was an effort to properly handle the .name 2LDs, but it was never resolved because there’s no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name: https://githu…

I think this says more about how the cookies security model is stupid. They should always have been scoped to the single, exact name they were set from and nothing else. Websites would have had to be designed a bit more thoughtfully.

It seems like it would be easily resolvable with TXT records these days. Anyone could try, say, on www.google.com to set a cookie for all of google.com, and the browser can fetch TXT records on google.com to see what, if any subdomains, it wants to allow this privilege for. Google could return a list or a wildcard; co.uk wouldn't allow any.

In a world without advertising, there's no reason why google.com couldn't also allow *.youtube.com to set cookies for it, but of course that would cause a tremendous privacy freakout. Though in practice they can and do just send every login/logout through a 302 redirect roundtrip to take care of the cookies on youtube.com.

Re: .name Termination

#209

One of the reasons I stick with Big Email for my primary email is cases similar to this. If I host email and lose the domain one day, I’ve lost two factor on a thousand different services (the single factor on some). Big Email’s policy is to not reissue my address, should I lose it or die. The .name scenario is even worse. One domain gives you access to tens of thousands of users email. It seems like a privacy nightm…

You can look through my history how many times I’ve brought this up to people and they just don’t seem to care. A defence is that they’ll buy the domain for a century and not care once they’re dead which is fair but the situation in this article is a valid one. I will always stick with Big Email for accounts.

Re: .name Termination

#210
post #198

Earlier quoted context omitted.

I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real. It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something lik…

That is definitely not true. There are literally thousands if not tens of thousands of well known domains that do this. .co.uk is a very common example.

I think the problem is that .co.uk, .gov.uk and so on are very well known in the UK.

The .name subdomain rules are not very well known anywhere.

Post reply on HN