Live data from Hacker News

.name Termination

neil.fraser.name

551–560 of 562 posts

Re: .name Termination

#551

Earlier quoted context omitted.

Not OP, but I am guessing they have domains like fordcareers.com or fordsecurity.com instead of careers.fore.com or security.ford.com, etc

This really grinds my gears, way more than it should for some reason. Use the system as it was intended, people!

Sometimes you don’t want everything hanging off the main domain, because if DNS gets horked everything goes down.

Re: .name Termination

#552

Earlier quoted context omitted.

My aside wasn't intended to be pedantic, rather observing the apparent inconsistency in how it appears people think about these matters versus what the present situation illustrates the reality to be. > but (1) I’m referring to a registrar/issuer, which makes it yet more complicated We're also talking about a ccTLD which makes it even more complicated. AFAIK those fall entirely under the jurisdiction of the respectiv…

> AFAIK those fall entirely under the jurisdiction of the respective UN recognized government How does that work for e.g. Taiwan, where the UN recognises the mainland government's claim to sovereignty in practice?

It's complicated and political, like always. Officially, the ISO 3166-1 alpha-2 country code list is used to decide who gets a ccTLD. (And Taiwan is included there.) But for example ".su" still exists for historical reasons, even though the Soviet Union is long gone (and its code is listed as "exceptionally reserved", which I assume translates as "we have no fucking idea what to do here.")

Re: .name Termination

#553
post #362

Earlier quoted context omitted.

I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real. It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something lik…

Looking at the threads below, very few people are discussing technical things in dns terms like zone or nameserver. Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with. Then when you consider DNS is fundamental infrastructure and people build secure things…

There is a list called the Public Suffix List, which is used for most purposes to make determinations about which 2lds do not own/manage the corresponding 3lds. It's maintained by Mozilla as a public service, which isn't exactly where you'd expect to find it. But it's mostly important for web security / "same origin" stuff, so it makes sense.

In addition to all the country codes TLDs that do 3rd-level registration, the PSL does also include stuff like github.io. (Maintenance of the list involves manual volunteer labor, so scaling is a real problem...)

(And of course the PSL wouldn't work well for the .name situation, where it's sometimes 2 and sometimes 3, and it can change over time. But that's no excuse for this clusterfuck of just suddenly dropping a bunch of domains that are paid up years in advance.)

Re: .name Termination

#554

This risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices used were entirely disconnected from domain names, and why the discovery protocol I put together did not rely on registered domains, but could use these as an untrusted part of discovery. Domain names are leased. Things that are leased can disappear. The compa…

"Online identity" seems like a castle built on quicksand in every single case. What's your account tied to? E-mail? That's usually on a mail server owned by someone else. If not, it's still on a domain owned by someone else. Phone number? Definitely owned by someone else. The only account that's reliably "yours" is one that asks for a login, a password, maybe a TOTP, and absolutely nothing else. Because everything el…

You've hit the nail on the head. That's why I strongly preferred email and password login, backed by a keepass(xc) store to hold the data. Owned by me, backed up, impossible to take from me, the works. Sure, most of the time I have to verify my mail address, but after that the account is mine. Well, okay. On some services, I have to "confirm the new device" I'm loggin in from, so I still need access to my mail.

Weeeell... Some services I use seem to have switched to a magic link EVERY TIME for login. No password anymore at all. And all of a sudden, my mail account is the single point of compromise for these accounts.

And there is absolutely nothing that I can do. If the mail is hosted by someone else, they may terminate my account at a whim. Or give it to someone else who happens to have convinced my phone provider to hand them a sim card with my number on it. If I do self host I still need a domain, and I can never really own a domain, only rent it from somewhere. So, whenever that lease goes up, my account is compromised by default.

I really hate that this problem seems still unsolvable. Keybase had the right idea, but no one used it and they got aquihired by zoom during the pandemic...

Re: .name Termination

#555

Earlier quoted context omitted.

No, we wouldn't, you're right. We'd just replace LetsEncrypt and the ISRG with the security track records and policy integrity of the major DNS providers, many of which are state-controlled, and the largest of which are too important to revoke. Really hard to understand why that hasn't happened yet!

You can chose under which registry you can register your domain. You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name. And Web PKI revocation is a joke that many clients don't check at all and others do using privacy-hostile mechanisms. But sure, keep spreading FUD like you always do on this topic.

> You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name.

Are there any remaining CAs in browser root stores that don’t enforce CAA record validation?

Re: .name Termination

#556
post #523

Earlier quoted context omitted.

It's the same reason I was nervous moving our company domain to a .ai TLD; your entire presence, identity and trust is now beholden to the whims and political winds of a Caribbean island smaller than Topeka.

It's a real risk. The British Indian Ocean Territory is going away, and by ICANN's rules, that means .io should as well.

It's not anymore: "in April 2026 the implementation of the agreement was put on an indefinite hold due to opposition from US President Donald Trump." So whatever ICANN was going to do with .io, it's all on hold for now.

Re: .name Termination

#557
This feels insane to me. Like, they're just terminating existing registrations? As the article says, this is a massive security problem waiting to happen, and there will be a lot of untoward consequences if things aren't handled very carefully.

Let's not forget the SEO or marketing consequences either. If you've got a business with this sort of domain, you're basically screwed. If existing third level registrations are terminated, and you can't get the relevant second level domain, your SEO/marketing work has literally been shot to pieces. I wouldn't be surprised if Verisign got sued for this.

There's no reason not to honour existing registrations while discontinuing new ones here, and the fact they're not feels completely at odds with how the internet should work as a whole.

Re: .name Termination

#558

Earlier quoted context omitted.

> AFAIK those fall entirely under the jurisdiction of the respective UN recognized government How does that work for e.g. Taiwan, where the UN recognises the mainland government's claim to sovereignty in practice?

It's complicated and political, like always. Officially, the ISO 3166-1 alpha-2 country code list is used to decide who gets a ccTLD. (And Taiwan is included there.) But for example ".su" still exists for historical reasons, even though the Soviet Union is long gone (and its code is listed as "exceptionally reserved", which I assume translates as "we have no fucking idea what to do here.")

This raises an interesting question. If they aren't strictly following UN recognition then would it be possible for ICANN to award control to one party while the UN recognizes an opposing party as the legitimate government?

Re: .name Termination

#559

Earlier quoted context omitted.

Yes, but you have to admit that the existence of these SLDs (like co.uk) is always going to be a point of confusion for anyone with a basic knowledge of how the domain hierarchy _usually_ works. Needing to be familiar with all the special cases (like the VERY special case of x.y.name which I previously knew nothing about) kind of ruins everything and introduces yet more security risk.

> but you have to admit that the existence of these SLDs (like co.uk) I'm sorry, what ? Admit ? Confusion ? In the case of .co.uk it has been around since 1996. HN is a technical forum, most people here should be well aware it is a serious SLD. I honestly can't believe it even needs clarifying. Hell, if you use AWS Route 53 you'll see they use co.uk as one of their nameserver suffixes[1]. [1] https://docs.aws.amazon.…

I'm not referring to the HN audience; I mean the larger evergreen cohort of people in the world who are still building their mental model of how the web works. They will each eventually be doomed to the same misconceptions because it's a system full of inconsistencies and special cases.

Re: .name Termination

#560
post #506
post #328

Earlier quoted context omitted.

> There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level. Yes. I've been asking VeriSign for this for years, and they always refused.

Update report: they are still categorically refusing, even for third-level customer who are alone (and have always been for 20 years) on the second-level they use. It makes no sense.

Maybe their justification is that allowing anyone to reserve means they'll have to admit they're screwing the ones with conflicts?

Maybe there's some legal loophole that says screwing everyone == not screwing.

Post reply on HN