Earlier quoted context omitted.
Sketchy CAs that issue certificates to people that don't actually own the domains in question tend to get nuked from the chain of trust very quickly.
Historically, I'd disagree with you, although it is improving with Certificate Transparency monitoring and alerting.
Introducing .app, a more secure home for apps on the web
191–200 of 378 posts
Re: Introducing .app, a more secure home for apps on the web
#192Earlier quoted context omitted.
That’s fair, given that HSTS is after all a standard itself and Google is merely applying it. Then I guess my perplexity is towards IETF in that they allow for two conflicting standards to exist. What if I want to use local.my.app for development; Or, in a more textbook example, i want to use workstation-1.building-a.my.internal.my.app without https?
That's a bad idea but here you go https://stackoverflow.com/questions/44650854/how-to-disable-...
Re: Introducing .app, a more secure home for apps on the web
#193Three arbitrary letters in a list of TLDs and they call it "innovation"...
Re: Introducing .app, a more secure home for apps on the web
#194Still waiting for them to release the .dev domains
Re: Introducing .app, a more secure home for apps on the web
#195Earlier quoted context omitted.
.app was a tiny bit more expensive to acquire than that ... http://www.businessinsider.com/google-just-paid-25-million-t... We're not expecting to make our money back on this one. And these amounts are a drop in bucket compared to many other Google products anyway. So a cynical profit motive is not why we're doing it. We're doing it for the stated reasons, to move security forward on the Web; see https://security.goo…
I'm seeing prices from $17 - $15,000 for preregistration and the pricing tiers seem very arbitrary... is there any documentation on how Google sets the pricing?
Note that registrars ultimately set the pricing that you see, which is why it's different across different registrars, same as if you wanted to buy, e.g., a .com domain.
Re: Introducing .app, a more secure home for apps on the web
#196Get.app said the domain I want is available, but none of the linked websites said they supported that tld Edit: any recommendations for what to do with my new domain, donaldtrump.app?
Re: Introducing .app, a more secure home for apps on the web
#197Still waiting for them to release the .dev domains
Re: Introducing .app, a more secure home for apps on the web
#198Supporting https is only an infinitesimal part of what makes downloading apps on the internet like playing Russian Roulette. It still doesn't prevent unsuspecting users from downloading malware, adware, ransomware, and apps that siphon user data. It also doesn't prevent users of sites depending on third party ad networks from being a victim of the same vulnerabilities they are now.
Re: Introducing .app, a more secure home for apps on the web
#199Can any company get a tld made? Who's even in charge of that sort of thing?
Re: Introducing .app, a more secure home for apps on the web
#200Earlier quoted context omitted.
Is everything on the backlog? Still not supporting long DKIM keys. Still using deprecated and discouraged SMS as 2factor. Are your margins really that thin? It's been years :(
We introduced an alternative to 2FA SMS - Authy OneTouch. We're working on adding TOTP as well.