Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

191–200 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#191

Earlier quoted context omitted.

Sketchy CAs that issue certificates to people that don't actually own the domains in question tend to get nuked from the chain of trust very quickly.

Historically, I'd disagree with you, although it is improving with Certificate Transparency monitoring and alerting.

Fair enough, but it's getting better, especially thanks to CT as you point out.

Re: Introducing .app, a more secure home for apps on the web

#192

Earlier quoted context omitted.

That’s fair, given that HSTS is after all a standard itself and Google is merely applying it. Then I guess my perplexity is towards IETF in that they allow for two conflicting standards to exist. What if I want to use local.my.app for development; Or, in a more textbook example, i want to use workstation-1.building-a.my.internal.my.app without https?

That's a bad idea but here you go https://stackoverflow.com/questions/44650854/how-to-disable-...

Well, disabling HSTS is a badidea as long as the logical (or legal) entity creating the subdomain is the same one that enforces HSTS, which was the case up until this point, (in that being the same entity they know which subdomains need HSTS and which ones don't).

Re: Introducing .app, a more secure home for apps on the web

#195

Earlier quoted context omitted.

.app was a tiny bit more expensive to acquire than that ... http://www.businessinsider.com/google-just-paid-25-million-t... We're not expecting to make our money back on this one. And these amounts are a drop in bucket compared to many other Google products anyway. So a cynical profit motive is not why we're doing it. We're doing it for the stated reasons, to move security forward on the Web; see https://security.goo…

I'm seeing prices from $17 - $15,000 for preregistration and the pricing tiers seem very arbitrary... is there any documentation on how Google sets the pricing?

Please see my top level comment here that I've since left.

Note that registrars ultimately set the pricing that you see, which is why it's different across different registrars, same as if you wanted to buy, e.g., a .com domain.

Re: Introducing .app, a more secure home for apps on the web

#198

Supporting https is only an infinitesimal part of what makes downloading apps on the internet like playing Russian Roulette. It still doesn't prevent unsuspecting users from downloading malware, adware, ransomware, and apps that siphon user data. It also doesn't prevent users of sites depending on third party ad networks from being a victim of the same vulnerabilities they are now.

...and I'm not sure Google has claimed any different. Just that HSTS enforced on the TLD level is more secure than otherwise, which it is.

Re: Introducing .app, a more secure home for apps on the web

#200
post #138

Earlier quoted context omitted.

Is everything on the backlog? Still not supporting long DKIM keys. Still using deprecated and discouraged SMS as 2factor. Are your margins really that thin? It's been years :(

We introduced an alternative to 2FA SMS - Authy OneTouch. We're working on adding TOTP as well.

Hey Ted, since you're here, may I please suggest that the future implementation of 2FA not require a separate app? Even though Namecheap is using Authy OneTouch, it still requires a dedicate app, which is unnecessary. Thanks.
Post reply on HN