Live data from Hacker News

.name Termination

neil.fraser.name

461–470 of 562 posts

Re: .name Termination

#461

This is why I am building DNTLS. These organizations no longer deserve our trust and they have inadvertently gained too much power over the last two decades of massive internet expansion. Names need to be fully owned by individuals and a shared, decentralized trust system must be in place for resolution. The more I see actions like this, the more convinced I am that a solution is long overdue.

Off-topic, sorry, but I did a double take when I saw your name just now.

Re: .name Termination

#463
Wonder what's up with the GNUnet (https://www.gnunet.org). Apparently there's still activity on it's development, but I didn't see adaptation/integration, even in free software like Linux. Sure it's not 1.0 yet, but the open source world is filled with sub 1.0 software that works great.

A stable online identify is important, that's maybe why you rent those domains etc. But after rent and forego quite a few, I slowly realized that domain at it's current format isn't a stable presence, instead it's more like branding instead of an identify. If an identify can be operated by different people without it's previous operator agreeing, is it truly an identify?

But I do need an identify, always under my control as much as possible, so people can trust the content and service running on it without having to guess if it's still me operating it.

Re: .name Termination

#464
post #188

Earlier quoted context omitted.

Even that doesn't pass basic scrutiny. The same ambiguity can and always will exist with tim-apple.com and tim.apple.com - there's nothing here that needs fixing.

I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real. It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something lik…

People still fall for paypal.com.4385ht43987th34098rh34279h3.legitorg.ru

Re: .name Termination

#465

Earlier quoted context omitted.

I'm always mystified why we haven't leveraged DNS. I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP. Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...

You're talking about DAME (which email uses). It has it's own issues like not having transparency logs, and if a DNSSEC signing keyholder goes rogue, there is no easy way to revoke trust (unlike CRLs for Web PKI).

Web PKI also has not had transparency logs until fairly recently. And Web PKI revocation is a joke as well. At least a "rogue" DNSSEC signer can only sign domains they have been delegated authority over and not literally everything.

Re: .name Termination

#466
post #263

Earlier quoted context omitted.

Outside of the context of ccTLDs and city.state.gov etc, I struggle to think of examples 3LD+ domains where they are owned and operated by completely different concerns than the parent. If at some point you could just register your own mysite.state.gov domains willy nilly that's probably before my initial time online around 2000. Another poster raised the point of hosting services which is valid. But at present outsi…

All Indian banks use bankname.bank.in as their domain. I’m not sure who owns bank.in but this is a common suffix which is different from the .co.uk pattern.

IDRBT Institute for Development and Research in Banking Technology

Re: .name Termination

#467

Earlier quoted context omitted.

I'm always mystified why we haven't leveraged DNS. I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP. Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...

No, we wouldn't, you're right. We'd just replace LetsEncrypt and the ISRG with the security track records and policy integrity of the major DNS providers, many of which are state-controlled, and the largest of which are too important to revoke. Really hard to understand why that hasn't happened yet!

You can chose under which registry you can register your domain. You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name. And Web PKI revocation is a joke that many clients don't check at all and others do using privacy-hostile mechanisms.

But sure, keep spreading FUD like you always do on this topic.

Re: .name Termination

#468
post #362

Earlier quoted context omitted.

I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real. It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something lik…

Looking at the threads below, very few people are discussing technical things in dns terms like zone or nameserver. Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with. Then when you consider DNS is fundamental infrastructure and people build secure things…

Problem is, all these systems we still use were never designed to be like this.

Hell DNS used to be one woman in an office who updated the zone if you e-mailed her.

Re: .name Termination

#469
post #100

Earlier quoted context omitted.

About 20 year ago I registered {lastname}.name and have dozens third level domains below it. So there are "privately owned" second level domains under .name for quite some time...

I'm working on same for my family since I want to properly degoogle a bit. One thing I think long term - if I give my kids first-name @ last name , that means that I forever hold power over their email. Which isn't great. But what's the alternative? Register one full domain name per kid? Even ignoring the cost, the ergonomics are awful. Imho email is missing a feature for nameless email addresses for when somebody ju…

Maybe there is a way to set up a legal entity for the domain that will guarantee continued shared control?

Re: .name Termination

#470
post #196

Earlier quoted context omitted.

True, they can’t outright prevent the ambiguity, but much fewer people will go to the trouble of establishing such subdomains when the option isn’t directly offered by the registrar. This is my theory because, a priori, 3LDs should be more profitable than 2LDs, because with 3LDs John Doe and Jane Doe don’t have to compete over doe.name , but instead can each separately purchase john.doe.name and jane.doe.name . Appar…

Prior to reading the OP blog post, I had never looked into the particular rules that .name has. To me, prior to knowing how it works, I would have assumed that either a) john.doe.name would be a subdomain that someone who was just starting out had gotten for free supported by ads. Similar to having johndoe.freewebs.com back in the day. Not something most people would use for anything professional. or, b) doe.name was…

>I would not have guessed that .name 3LDs worked the way that it did if I hadn’t read about it.

The situation in the OP is exactly what you just put as A)

Post reply on HN