Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

171–180 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#171

Arbitrarily picking web standards seems like an abuse of power. If this is the direction in which they want the internet to steer (a great one as far as I’m concerned) Google should advocate for the deprecation of HTTP in the appropriate bodies instead though. It baffles me that TLDs are at the mercy of private companies... I guess I should read more about the history of the internet to understand how this came to be…

It's not arbitrarily. You can use the standard HSTS to be applied domain wide https://hstspreload.org/#tld

Re: Introducing .app, a more secure home for apps on the web

#172
post #140

Earlier quoted context omitted.

Why would that be unnecessary? Are we supposed to use extension-less filenames and then guess their type every time by looking at their content?

Should URLs end in .html?

Web servers respond to your requests stating what type of content they’re sending you. There’s no such thing for files on disk.

Re: Introducing .app, a more secure home for apps on the web

#173
post #155

Earlier quoted context omitted.

> (it is not necessarily!) HTTP traffic -is- necessarily insecure. It's trivial for anyone on your network to run Wireshark and see/modify all of your traffic. And a lack of HSTS leaves your site potentially vulnerable to SSLstrip.

And we have the first person to confound not having a .app with not encrypting the connection here. The comment you replied to did not imply that HTTP is not necessarily insecure, it said that you can (quite obviously) use HTTPS with any TLD.

[deleted]

Re: Introducing .app, a more secure home for apps on the web

#174

Is being cynical about this allowed? Google throws down a few hundred grand to get the .app domain, in concert with modifying their web browser to deliberately mark others' traffic as "Insecure" (it is not necessarily!), and reaps the fees now and in perpetuity ever year thereafter for maintaining a simple database of DNS glue entries which you literally could maintain using MS Access (by which I mean, the database s…

.app was a tiny bit more expensive to acquire than that ... http://www.businessinsider.com/google-just-paid-25-million-t...

We're not expecting to make our money back on this one. And these amounts are a drop in bucket compared to many other Google products anyway.

So a cynical profit motive is not why we're doing it. We're doing it for the stated reasons, to move security forward on the Web; see https://security.googleblog.com/2017/09/broadening-hsts-to-s... and https://security.googleblog.com/2018/02/a-secure-web-is-here...

Also, I could talk your ear off about the design of our infrastructure for hours. Suffice it to say, it's a lot harder than you're making it out to be, particularly as regards to scaling. Our registry platform is open source, so feel free to inspect the code at https://nomulus.foo . And that's not even getting into DNS hosting, which involves a very large number of instances distributed around the entire globe.

Re: Introducing .app, a more secure home for apps on the web

#175

Is being cynical about this allowed? Google throws down a few hundred grand to get the .app domain, in concert with modifying their web browser to deliberately mark others' traffic as "Insecure" (it is not necessarily!), and reaps the fees now and in perpetuity ever year thereafter for maintaining a simple database of DNS glue entries which you literally could maintain using MS Access (by which I mean, the database s…

And it won't take many registrations to recoup the investment. They're charging $999 / year at least for pre-registrations. I clicked through to the price using godaddy and the $16.99 / year price quickly got replaced by the higher number which also indicated that $1000 was the yearly renewal price if one gets the domain through pre-registration. (Your money gets refunded if you don't get the domain.) I'm sure godadd…

That preregistration amount changes based on the domain you are trying to register. More popular terms cost significantly more.

Re: Introducing .app, a more secure home for apps on the web

#176

Arbitrarily picking web standards seems like an abuse of power. If this is the direction in which they want the internet to steer (a great one as far as I’m concerned) Google should advocate for the deprecation of HTTP in the appropriate bodies instead though. It baffles me that TLDs are at the mercy of private companies... I guess I should read more about the history of the internet to understand how this came to be…

> Google should advocate for the deprecation of HTTP in the appropriate bodies instead though

I agree with your larger point. For instance, I believe Google purposefully avoided implementing some privacy-preserving features in its QUIC protocol.

However, in this case, it was the ISPs and wireless carriers that fought against deprecating HTTP, while Google and Mozilla wanted to deprecate it. It's why I think they only enabled the HTTPS version of HTTP/2 in their browsers. The carriers and ISPs wanted the web to stay on HTTP so they can mine everyone's data, as they're already doing with the sites that have remained on HTTP.

Re: Introducing .app, a more secure home for apps on the web

#177

Arbitrarily picking web standards seems like an abuse of power. If this is the direction in which they want the internet to steer (a great one as far as I’m concerned) Google should advocate for the deprecation of HTTP in the appropriate bodies instead though. It baffles me that TLDs are at the mercy of private companies... I guess I should read more about the history of the internet to understand how this came to be…

It's not arbitrarily. You can use the standard HSTS to be applied domain wide https://hstspreload.org/#tld

That’s fair, given that HSTS is after all a standard itself and Google is merely applying it.

Then I guess my perplexity is towards IETF in that they allow for two conflicting standards to exist.

What if I want to use local.my.app for development; Or, in a more textbook example, i want to use workstation-1.building-a.my.internal.my.app without https?

Re: Introducing .app, a more secure home for apps on the web

#178

Is being cynical about this allowed? Google throws down a few hundred grand to get the .app domain, in concert with modifying their web browser to deliberately mark others' traffic as "Insecure" (it is not necessarily!), and reaps the fees now and in perpetuity ever year thereafter for maintaining a simple database of DNS glue entries which you literally could maintain using MS Access (by which I mean, the database s…

.app was a tiny bit more expensive to acquire than that ... http://www.businessinsider.com/google-just-paid-25-million-t... We're not expecting to make our money back on this one. And these amounts are a drop in bucket compared to many other Google products anyway. So a cynical profit motive is not why we're doing it. We're doing it for the stated reasons, to move security forward on the Web; see https://security.goo…

Thanks for the correction about the price.

However, 10 years of 1 million domains, even if Google's cut is only $1 out of the registration price, is still $10 million per year * 10 years = $100 million.

If Google's own registry is used and you capture more of the ($17/year ?) domain fee, it goes up by multiples of that.

Correct me if I am wrong, but serving the DNS entries of .app will be almost the same as serving up a DNS entry for another domain like .com: the HSTS/https-only requirements will be set up in the browser, not the DNS server.

And serving DNS has been handled successfully and profitably by Namecheap/GoDaddy/Moniker et al for years.

Re: Introducing .app, a more secure home for apps on the web

#179

Arbitrarily picking web standards seems like an abuse of power. If this is the direction in which they want the internet to steer (a great one as far as I’m concerned) Google should advocate for the deprecation of HTTP in the appropriate bodies instead though. It baffles me that TLDs are at the mercy of private companies... I guess I should read more about the history of the internet to understand how this came to be…

How about namecoin ? You can use it to buy .bit domains, but ICANN doesn't recognize those, so users need a special addon to access .bit websites.

Re: Introducing .app, a more secure home for apps on the web

#180

Is being cynical about this allowed? Google throws down a few hundred grand to get the .app domain, in concert with modifying their web browser to deliberately mark others' traffic as "Insecure" (it is not necessarily!), and reaps the fees now and in perpetuity ever year thereafter for maintaining a simple database of DNS glue entries which you literally could maintain using MS Access (by which I mean, the database s…

.app was a tiny bit more expensive to acquire than that ... http://www.businessinsider.com/google-just-paid-25-million-t... We're not expecting to make our money back on this one. And these amounts are a drop in bucket compared to many other Google products anyway. So a cynical profit motive is not why we're doing it. We're doing it for the stated reasons, to move security forward on the Web; see https://security.goo…

I'm seeing prices from $17 - $15,000 for preregistration and the pricing tiers seem very arbitrary... is there any documentation on how Google sets the pricing?
Post reply on HN