Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

101–110 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#103
Supporting https is only an infinitesimal part of what makes downloading apps on the internet like playing Russian Roulette. It still doesn't prevent unsuspecting users from downloading malware, adware, ransomware, and apps that siphon user data. It also doesn't prevent users of sites depending on third party ad networks from being a victim of the same vulnerabilities they are now.

Re: Introducing .app, a more secure home for apps on the web

#104
post #17
post #2

Excellent, this will surely cause no confusion with macOS executables.

Just like .com didn’t cause confusion with DOS and Windows .com executables.

It helped a little that .com executables were pretty much obsolete by the time the web became common, but that was still a pretty nice gift to early malware authors.

Re: Introducing .app, a more secure home for apps on the web

#105
post #31

Earlier quoted context omitted.

You severely overestimate the technical skill of the average user. And even people who know their way around computers rely heavily on patterns in order to identify relationships, so a strong pattern without an underlying relationship is, of course, going to lead to confusion.

Average user is able to learn.

I see, the downvote confirms the truth.

Re: Introducing .app, a more secure home for apps on the web

#106
post #42

How does this work technically? What prevents use of plaintext http on these domains? The preloading seems like a browser specific feature.

It is only enforced by the browser. So curl and similar stuff still works. But on a sidenote: Why shouldn't it. It is just a domain, whatever is running on the resolving IP address is up to the server administrator.

Re: Introducing .app, a more secure home for apps on the web

#107

Not surprisingly Google has already prevented registration(pre pre registration) of anything related to their services alphabet[1], chrome[2], chromeos[3], etc... I guess you can do whatever you want when you own the domain extension. [1] https://www.godaddy.com/dpp/find?checkAvail=1&tmskey=&domain... [2] https://www.godaddy.com/dpp/find?checkAvail=1&tmskey=&domain... [3] https://www.godaddy.com/dpp/find?checkAvail=1…

> Mar 29 - May 1: Trademark holders can register .app domains (known as the "Sunrise" period).

Re: Introducing .app, a more secure home for apps on the web

#108

Barely related question: does Google plan to deploy the .google gTLD for use in its services, i.e. will mail.google.com become mail.google, and drive.google.com change to drive.google just like they did for blog.google and registry.com?

I think they’d like to possibly but there are concerns. I have had trouble with vanity tlds and I can imagine with google being so ubiquitous, there could be so many issues.

And also security. I know there’s an implicit trust of .com and so I wonder if seeing just google will lead to people thinking it’s safer. I have Metcalfe.rocks and more than once I’ve had people try Metcalfe.rocks.com

Re: Introducing .app, a more secure home for apps on the web

#109

Earlier quoted context omitted.

Godaddy enables you to preregister at the moment. This is only a preorder and doesn't guarantee the domain.

You can register a domain name at this moment during the Early Access Period through any registrar which supports it (which includes GoDaddy and many others listed at https://www.registry.google/about/register.html ). It's not a pre-registration; the domain is created and assigned to you immediately.

This list is useful, but the early access domains are mostly unfamiliar to me. Does anyone have any recommendations?
Post reply on HN