Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

241–250 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#241
post #211

I want to clarify some details on how the Early Access Program (EAP) works because I'm seeing some confusion here in the comments. EAP is a 7-day period in advance of General Availability (GA) during which domains can be registered immediately (not pre-ordered). EAP is a descending price ("Dutch") auction, meaning that prices start off high and then decrease as the auction goes on. The reason for this is to efficient…

what defines a domain name as premium?

A couple easy metrics: Existing brand names/trademarks, existing websites on other TLDs, and length of domain with additional weighting for actual words (maybe additional weighting based on word/tuple frequency in say the google books corpus).

Re: Introducing .app, a more secure home for apps on the web

#242

Earlier quoted context omitted.

It's not arbitrarily. You can use the standard HSTS to be applied domain wide https://hstspreload.org/#tld

That’s fair, given that HSTS is after all a standard itself and Google is merely applying it. Then I guess my perplexity is towards IETF in that they allow for two conflicting standards to exist. What if I want to use local.my.app for development; Or, in a more textbook example, i want to use workstation-1.building-a.my.internal.my.app without https?

Arbitrarily across an entire TLD.

Because IANA decided to start selling off the web for companies to abuse.

> What if I want to use local.my.app for development;

You can switch to .dev... oh right.

Re: Introducing .app, a more secure home for apps on the web

#243
post #233

This is confusing because Mac apps literally end in that extension, and if I say Messages.app you would know what I mean. Also, if I say “dingus dot app” it confuses people because that’s not a mobile app, it’s a site or web app.

Old DOS executables (actually, commands) (which still run on Windows) ended in .com ; there was an overlap with the Internet when they were still quite common (command.com was how you started a command prompt on windows 95), and no-one seemed to get confused

Re: Introducing .app, a more secure home for apps on the web

#244

Earlier quoted context omitted.

I can't speak specifically for Google Domains as that's a completely different team that we have limited interactions with. What I can say is that we are currently in the Early Access Period, and that General Availability begins on May 8 at 16:00:00.000 Z. That's when you'd expect to see any remaining registrars not yet selling them start to sell them.

Wait, so you put out this launch announcement telling people they can early register .app domains. It links to a bunch of partners including Google Domains, but you have no idea whether I can actually register a domain there or not? Why promise it in your launch announcement then?

They put this announcement out so they can sell spots on the "Priority Pre Registration" list for $16,000.

It's just another fucking cash grab.

Re: Introducing .app, a more secure home for apps on the web

#246

Earlier quoted context omitted.

You can register a domain name at this moment during the Early Access Period through any registrar which supports it (which includes GoDaddy and many others listed at https://www.registry.google/about/register.html ). It's not a pre-registration; the domain is created and assigned to you immediately.

To be blunt, this is a horrible roll-out by Google. It is a perfect example of the right hand not talking to the left hand, or the rest of the body for that matter. Several significant issues: 1) The announcement is made by Google, yet Google is not accepting EAP registrations. Very confusing. 2) The registrars accepting EAP are not as widely known as you would expect for something like this, meaning that I am going…

The $173 is a "Phase 7 Pre Registration", for the low low just for you price of $16,000 you can have a Phase 1 Priority Registration!

They're just auctioning off all the good names - same as every other domain squatting rent seeker...

Re: Introducing .app, a more secure home for apps on the web

#247

Earlier quoted context omitted.

I'm not sure how a .app TLD could be mistaken for a .app executable.

You severely overestimate the technical skill of the average user. And even people who know their way around computers rely heavily on patterns in order to identify relationships, so a strong pattern without an underlying relationship is, of course, going to lead to confusion.

Referring to Mac applications as "Mail dot app" is a thing that only geeks do in the first place.

Re: Introducing .app, a more secure home for apps on the web

#248

Earlier quoted context omitted.

There has to be an error somewhere on a couple registrars. Trying through 101Domain adding a domain to the cart results in a total of $12,025.16 USD. I can get it slightly cheaper at Yay.com for $10,209.09.

Different registrars set different prices. .com domains cost different amounts across different registrars too. It's not a mistake, and if price factors into your determination of which registrar to use, then that totally makes sense.

Right - so you've just built this to give bdirty scammers another way with which to rip everybody off. Thanks for that. Lucky "Do no evil" isn't written on the wall there anymore...

Re: Introducing .app, a more secure home for apps on the web

#249
Sigh. As I’ve said before, we need stronger identity profiles and user agents that verify much more than legitimate-sounding names. A name alone should effectively be treated like it could be completely and utterly fake, period.

Yes, they’re requiring "https" but it’s not like it is hard to acquire a certificate anymore.

All the ".app" domain will do is screw app developers into paying to register their chosen name on a particular domain. Again. After all, if you don’t register then someone else could, giving their site perceived legitimacy over yours. Let’s not forget, many apps are not making millions on top-10 lists; developers aren’t exactly eager to further cut into their meager earnings to cover web sites.

We already know that entire apps are being copied. Scammers have never been deterred from copying entire web sites either (just look at those E-mails from “your bank”). This new domain might serve mainly as a way for scammers to make stolen copies seem even more real. Frankly, I predict that all the real talented developers will be slowly discouraged from continuing to try to make money in an environment where obvious fakes can thrive so easily and the costs just keep going up.

Re: Introducing .app, a more secure home for apps on the web

#250
post #64

Earlier quoted context omitted.

Is there a list of which registrars are participating in the early access period? None of the ones I tried seemed to recognize .app.

hexonet.net does. $11,080 then $3,205 $1,625 $1,130 $690 $580 This sucks. This is like, truly evil. There's two hard problems: Naming things Cashing [sic] : Paying for the right to name things

It's only for the current early access period, so if you don't have a named project already I'd suggest just waiting for the period to end then your pricing is steady. We know how to design good auctions but I'm not sure there's any design that'll be kind to purchasers who can't easily evaluate the value of the item to them while still meeting other more basic goals.
Post reply on HN