Live data from Hacker News

.name Termination

neil.fraser.name

531–540 of 560 posts

Re: .name Termination

#531

Earlier quoted context omitted.

I think DMARC works well because email tends to blindly trust DNS (opportunistic encryption). On the web we expect authenticated TLS, often strictly enforced (organization policy, HSTS). So it would feel weird if a website changes how it handles HTTPS cookies based on an insecure DNS record, perhaps delivered by the resolver on an untrustworthy WiFi router. Specifically, if I register subdomain attack.co.uk and set u…

The SVCB HTTPS rfc considers downgrade attacks here: https://www.rfc-editor.org/info/rfc9460/#name-handling-resol... And essentially boils it down to ‘either the client implements wire-security to a known dns server using DoH or DoT, implements dnssec to verify the untrusted response as legitimate, or the client risks being mitm’d to attacker addresses’. They ultimately sidestepped the problem by structuring it to be…

> simply permanently end all service to the concept of subdomains at all

That doesn't sound simple at all.

Re: .name Termination

#532
post #393

Earlier quoted context omitted.

Why would they want to drop the possibility of selling some as premium domains? If they have their shells setup right they will probably be able to get a premium from some 3rd level domain owners wrongly afraid someone else is interested. The main problem with the Internet today is that we didn't destroy ICANN when they started this TLD sell off crap. A replacement institution may have at least told Verisign a TLD th…

Because it's not worth it financially. After icann is the tld registrar, and after that above. So, if anyone is destroying it, it's not the registrar, it's the tld.

>> In light of the fact that Verisign and ICANN are in the process of discussing the upcoming renewal of the .NAME Registry Agreement, ICANN is issuing Verisign this letter in lieu of a contract amendment to the expiring

It's clear to me ICANN can say no agreement change or total destruction. You are correct that they could do something else and show every indication that they would never do the right thing and that is why they should be destroyed.

Re: .name Termination

#533

Earlier quoted context omitted.

> They're insane and should not be in charge. I remember back when we had to write mechanize scripts to drive a browser through the renewal process, because if you had dozens, hundreds, or thousands of domains there was no nonmanual way, especially if you wanted extended verification or something silly like that. So what I'm saying is, agreed and that has always been true.

That actually sounds like a good thing. Why are you hording hundreds or thousands of domains?

One reason could be to prevent phishers from getting names similar to your actual domain(s).

Re: .name Termination

#534

Earlier quoted context omitted.

Not OP, but I am guessing they have domains like fordcareers.com or fordsecurity.com instead of careers.fore.com or security.ford.com, etc

This really grinds my gears, way more than it should for some reason. Use the system as it was intended, people!

Far from the most frustrating thing they did, trust me. I could tell you stories for days and never run out of more frustrating anecdotes.

Re: .name Termination

#535

Earlier quoted context omitted.

That actually sounds like a good thing. Why are you hording hundreds or thousands of domains?

Should Google be allowed to keep Google dot lol if it doesn't do anything useful with it? What about Google dot wtf? Any person with two brain cells would say these domains should belong to a fervent critic of Google, not to Google. Sadly neither our world not its legal system is built on common sense.

Domains are an infinite resource. Even a random string of characters can become valuable if the services running off that domain are valuable.

Re: .name Termination

#536
post #325

I can only assume somebody was asleep on the job when this scheme was approved, because the outcome is in direct contradiction to ICANN’s mission statement: > Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems. https://www.icann.org/resources/pages/about-icann Arbitrary termination of service is not stability. Enabling name hijacking is not security. The answer…

It's been through the Ombuds and a reconsideration request [1]. ICANN says: > There will not be any effect on the life cycle of domain names. While the Requestor may disagree with Verisign’s response, the Requestor has not shown that ICANN relied upon false or inaccurate material information. The life cycle of a domain name begins when the domain is registered, then moves through various stages before ultimately comi…

That's insanely obtuse and bureaucratic response and has likely been designed as such. I mean, to claim that because _some_ domains can get unregistered, abruptly removing a whole class of domains "does not impact the life cycle of the domain" is entirely nonsensical. It's like saying because computers, being physical entities, may sometimes break, and all of them will break in finite time, it's entirely fine if all your computers shut down immediately and it has no impact on anything. This just sounds as "we don't care and you can't do anything about it, suck it up, peasant".

Re: .name Termination

#538

Earlier quoted context omitted.

I thought that was the point of .me, but apparently that’s actually the Montenegro national TLD despite widespread use for personal sites. https://en.wikipedia.org/wiki/.me

All two letter TLDs are reserved for ccTLDs.

And some, like Anguilla or Tuvalu, hit the lottery and get a nice income from renting theirs out for general use.

Re: .name Termination

#539
post #325

I can only assume somebody was asleep on the job when this scheme was approved, because the outcome is in direct contradiction to ICANN’s mission statement: > Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems. https://www.icann.org/resources/pages/about-icann Arbitrary termination of service is not stability. Enabling name hijacking is not security. The answer…

Sorry, I don't understand this rule, would someone kindly explain? I own lastname.name and use it for email only like this: firstname@lastname.name I always thought as owner of lastname.name, I'm the only one able to add subdomain.lastname.name. Is this wrong?? 1) Can anyone "buy" scam.lastname.name without my authorization on .name?? 2) Can anyone owning not.lastname.name then steal my emails going to: firstname@*.l…

[dead]

Re: .name Termination

#540

Earlier quoted context omitted.

That actually sounds like a good thing. Why are you hording hundreds or thousands of domains?

I was working for a company that had hundreds and thousands of domains. It was a fortune 50 company, and they had a policy generally against wildcard domains.

I really wish I could be this stupid and have enough power to make such stupid policies
Post reply on HN