Live data from Hacker News

Perl.com Taken over by Domain Squatters

twitter.com

11–20 of 82 posts

Re: Perl.com Taken over by Domain Squatters

#13

Earlier quoted context omitted.

Central authority is a poor substitute for social consensus. If you look at a case like this, there is absolutely no question or ambiguity "which perl.com domain people really want." This issue only exists because of an artificial monopoly and an application of capitalism to an allocation problem that doesn't exist . Domain names should be a thin wrapper around private/public keypairs. Domain keys should be pinned pe…

How would you prevent a group from trolling or performing a hostile takeover of a small domain? How would someone acquire a domain? How do you determine consensus? In this case, as someone who doesn't follow Perl, how would I make an informed decision on which perl.com domain I really want?

It's not an obvious problem to solve, but nobody would invest much in performing a hostile take over of a small domain. In the case of Perl.com it looks like a hostile takeover, of a popular domain, and it didnt cost them much to take it over I guess.

Re: Perl.com Taken over by Domain Squatters

#14
So a potential service here:

https://www.icann.org/news/blog/documentation-is-key-to-reco...

If documentation is key, then perhaps have a service that will, take your documentation, hash it and then you can store the hash on your domain root (much like google analytics). Then if you lose the domain, you have wayback machine style proof that the domain originally had these docs associated with it.

(I can see some downsides to this but what do people think?)

Re: Perl.com Taken over by Domain Squatters

#16

Earlier quoted context omitted.

How would you prevent a group from trolling or performing a hostile takeover of a small domain? How would someone acquire a domain? How do you determine consensus? In this case, as someone who doesn't follow Perl, how would I make an informed decision on which perl.com domain I really want?

It's not an obvious problem to solve, but nobody would invest much in performing a hostile take over of a small domain. In the case of Perl.com it looks like a hostile takeover, of a popular domain, and it didnt cost them much to take it over I guess.

I think it's naive to assume trolls wouldn't invest much time

Re: Perl.com Taken over by Domain Squatters

#18
post #5

Earlier quoted context omitted.

why?

Central authority is a poor substitute for social consensus. If you look at a case like this, there is absolutely no question or ambiguity "which perl.com domain people really want." This issue only exists because of an artificial monopoly and an application of capitalism to an allocation problem that doesn't exist . Domain names should be a thin wrapper around private/public keypairs. Domain keys should be pinned pe…

> Domain names should be a thin wrapper around private/public keypairs.

This way anyone who gets access to the keys, even temporarily gets to take over the whole domain. No chance to resolve the issue with a registrar who can manually review the case and revert changes. This would include anyone working on that level of infra in your company and anyone who hacks them.

I'm not sure what would you compare the https cert to without a central authority in that case.

We tried the web or trust with PGP and it turns out key management is really hard and apart from few geeks nobody's that interested.

Post reply on HN