Live data from Hacker News

.name Termination

neil.fraser.name

411–420 of 551 posts

Re: .name Termination

#411

One of the reasons I stick with Big Email for my primary email is cases similar to this. If I host email and lose the domain one day, I’ve lost two factor on a thousand different services (the single factor on some). Big Email’s policy is to not reissue my address, should I lose it or die. The .name scenario is even worse. One domain gives you access to tens of thousands of users email. It seems like a privacy nightm…

You can look through my history how many times I’ve brought this up to people and they just don’t seem to care. A defence is that they’ll buy the domain for a century and not care once they’re dead which is fair but the situation in this article is a valid one. I will always stick with Big Email for accounts.

Your response seems to imply those people are irrational, but it's really just different priorities. Yeah, you need to make sure you don't lose the domain. With Google/etc, you need to make sure you don't break any of their usage policies across their suite of apps, etc. Neither are super likely to happen. Neither are impossible, either.

(Update: as it happens… https://news.ycombinator.com/item?id=49548452)

Personally I like having a custom domain as I like the idea of being able to move between providers. So far, over the past decade, I've hosted my email with Google, Fastmail, Hey.com and then Fastmail again. I like being able to move it around if I find one provider better than another. Others won't care, that's fine too.

Re: .name Termination

#412
post #220

Earlier quoted context omitted.

I don't get the difference. If I acquire the y domain and make it work as a subdomain broker, it's the same thing no? There is no subdomain/TLD bit

You are technically correct, but Verisign billed buying an x subdomain as if the y domain was part of a stable infrastructure. Which it kind of was until they decided to pull the rug.

Is there any resource you can point towards understanding this? I'm well versed on DNS itself, so it can be a technical document.

What I understand would be the following:

1- Verisign manages the TLD registry for .name (and others), which includes managing the authoritative DNS servers (as pointed to by the .name NS and A records on the root DNS servers), 2- as well as for updating the NS records of .name records it is authoritative at the request of registrars (like, say GoDaddy), which act on behalf of domain owners. 3- one or some of the domain owners, for example for fraser.name, acted as a registry themselves managing authoritative DNS servers for NS records of .fraser.name domains, these third level DNS servers being pointed to by the name. NS records.

4- Upon registration of a .name domain, verisign charged a fee, (in the case of .coms this is around 10$ currently I believe, not sure how much they charge), and ICANN charges a much lesser fee (like 20 cents).

5- Upon registration of a .fraser.name domain, the fraser.name domain owner charged a fee, and they kept the totality of that fee (potentially paying a fee to ICANN, but definitely not to verisign.)

6- Verisign issues this request, requesting registrars of second level domains (domain.tld) like GoDaddy, to stop selling third level domains of this TLD (domain.2ld.tld).

This is my understanding of the situation, and in that case, verisign was not billing for the domain. This might (a bit cynically) provide a commercial motivation for the actions of verisign.

It's worth noting that this is not at all a weird or shady practice, multi-level domains are the very ethos of the domain system, it's built for that, I'm not saying any domain is obligated to do that on the basis that it can, but it's not some esoteric illegal activity, it's normal.

Re: .name Termination

#413

Earlier quoted context omitted.

I don't get the difference. If I acquire the y domain and make it work as a subdomain broker, it's the same thing no? There is no subdomain/TLD bit

The Public Suffix List is the closest thing we have to the "subdomain/TLD bit", but afaik it doesn't include wildcards like `*.name`. It does influence TLS though (or possibly just browsers) in that a wildcard cert for an entire TLD or public suffix won't be honored, nor will a public CA issue such a cert. Still, I'm not sure there's any easy technical fix for the .name debacle.

I'm aware of that, it's an ad-hoc out of band list maintained by Mozilla, not 'official' or recognized by any process like an RFC, but it does exist.

It's safe to ignore altogether, but it can come in handy as a starting domain block/allowlist.

>Still, I'm not sure there's any easy technical fix for the .name debacle.

I think that it's gonna be ok, the owner of the 2ld is still the owner, so they are free to allow the 3ld domain owners to continue "owning" their domains and updating them on the authoritative 2ld DNS. It's just that verisign is no longer sanctifying it by allow vendors of other 2ld to sell 3ld with the 2ld together.

This might explain the whole situation, many of us are interpreting that the domains are deleted, but in reality, they may more likely be prohibited from being represented as official .name domains in registrars .

Re: .name Termination

#414
post #187

I don't think it's hyperbolic to say that this is the most careless, disruptive change to anything to do with DNS or internet names I have ever seen. > "will increase efficiency for the operation of the .name TLD." What a preposterous excuse -- especially for something already up and running. Sounds like they probably want to change the backend in some way - or adopt some kind of off-the-shelf software - which doesn'…

Agreed. If you don't want to care about backwards compatibility, there's plenty of space for you in tech. Just not at a domain registry!!

Re: .name Termination

#415

Earlier quoted context omitted.

Except nobody uses the .us tld, but pretty much every every Japanese company is on a .co.jp

The .us domain should’ve been universally useful for state and municipal governments, but most of those began registering directly under .gov, and not even in an orderly hierarchy under . st .gov But that was simply the easiest way to market your website as a trusted government entity. And now nobody has ever heard of .us domains in active use.

.us was primarily a hierarchy structure which in practice made confusing and hard to remember domain names, whereas .gov addresses hand out single domains which are generally easy to remember.

Re: .name Termination

#416
post #332
post #315

Earlier quoted context omitted.

I own a .name domain that is an initialism for my wife and I, and Namecheap never gave me any problems adding a record for vpn.mwai.name, for example. In fact I never even realized you could register a 3LD, much less that this was the intended(?) behavior.

The idea is: * .name is open for everybody * a company called "Global Name Registry" scooped up a BUNCH of common last names, including fraser.name * Global Name Registry then sold access to neil.fraser.name for far cheaper than the fraser.name domain would cost on its own; someone else could also buy john.fraser.name or jane.fraser.name, so the single fraser.name domain that they owned could have dozens of customers…

Oh, I get it, I guess the question is what will Verisign do with the surname.name domains. They could be auctioned individually or by bulk, and somebody could buy them. But in essence they are exercising their right as a 2ld holder (Global Name Registry) to stop providing service.

This is an ostensibly uncharacteristic move for verisign, but the customers that bought these 2ld did so from a non-verisign vendor, it is only after verisign bought the 2ld holder that they became the holders and are now proceeding to extinguishing them after embracing and extending.

Might be an anti-trust case. Like textbook clear-cut case. IANAL, this is not legal advice.

Re: .name Termination

#417
post #296
post #255

Earlier quoted context omitted.

They rolled this out in March this year in the US (and December last year in India). I've successfully renamed an old account with an email address I no longer liked. It works quite well on everything 1st party, but does have the potential of causing issues with OAuth on poorly-coded websites that key on email instead of user ID (ie. most of them). You do get to keep your old email address though, so it still ends up…

Holy crap really? Yay! I know a couple of trans folks that will be ecstatic.

The feature is about fifteen years too late for me, unfortunately. By this point I need this feature to let me "merge Google accounts". But then I barely use Google anything anymore anyways.

Re: .name Termination

#419

Earlier quoted context omitted.

Yeah, that’s why RFC 9989 replaced use of PSL with a dns signifier.

(That's DMARC, to save others the trouble.) The problem DMARC solves is different than the problem the PSL solves, though. DMARC prevents a 3LD from pretending to be a different 3LD on the same 2LD. But the PSL handles things like what it means to make a "cross-site request" or how to handle cookies. I mean now I'm thinking if DMARC _could_ solve that... but I don't think it could, unless I'm missing some extension o…

Yes, DMARC isn't solving the same problem — but DMARC is showing how the category of PSL problems can be solved with DNS. With HTTP/3 now fully expecting browsers to be able to benefit from transparent-upgrade record responses, i.e. `www IN HTTPS 1 . alpn="h3,h2"`, then it is possible for the style of solution shown by DMARC to be applied to other problems that PSL solves today.

CAA isn't a good fit as-is either, because the subdomain has top precedence over the parent domain — precisely the inverse relationship needed here. But having worked with the PSL for quite some time operationally and seeing the direction of trends away from it and towards structural DNS declarations rather than a centralized list, I think the 3LD-2LD-CRSF problem would be far better off solved with DNS than PSL.

Basically, just adding `co.uk. IN TLD subs=independent` as an SVCB record would fully deprecate the need for the PSL versus cross-site and other such ownership-changes-hands boundary problems with both A.co.uk being allowed cross-site with B.co.uk, and with co.uk being treated as equivalent to B.co.uk by password managers, cookie repositories, and so on. It would also benefit CAA by defining whether the boundary exists — if TLS is hosted by the provider, then any CAA records published by the subdomain should be disregarded; if the subdomains are fully independent, then any CAA records published by the parent should be disregarded — which simply isn't possible today without either referring to the PSL or implementing DMARC-style DNS solutions.

(I don't formally suggest that exact record as structured or written but it's sufficient a napkin sketch of what I mean by gesturing at that RFC to be considered.)

Re: .name Termination

#420

Earlier quoted context omitted.

> Early termination of a domain registration does not impact the life cycle of the domain, as the domain can still go through the various stages of a standard life cycle. According to ICANN cutting the life cycle short doesn't have any effect on the life cycle? ICANN corruption is at the level of FIFA corruption.

What language games are we playing?

Life cycle. Y'know. Birth, life, death. It had that. If you die tomorrow, you still had a life cycle. Totally not impacted. All 3 things still present and accounted for.
Post reply on HN