Live data from Hacker News

.INTERNAL is now reserved for private-use applications

icann.org

251–260 of 290 posts

Re: .INTERNAL is now reserved for private-use applications

#252

Ever since this kind of stuff was introduced I've been annoyed that there is no way to disable it for yourself. And it's allowed for straight up evil stuff like google buying the .dev TLD

Your mention of .dev seems like a complete non-sequiter to me. What happened to .internal here is the exact opposite of what happened to .dev. And how would you even propose to "disable" reservation of a TLD. Sorry your comment just makes no sense from my POV.

Re: .INTERNAL is now reserved for private-use applications

#253

Can we get .local or .l added for private-use applications too?

Please also reserve .lan which is what I now prefer to use since .local got stolen from private networks.

You can use .home.arpa.

https://datatracker.ietf.org/doc/html/rfc8375

Re: .INTERNAL is now reserved for private-use applications

#254
post #8

1. Buy .intern TLD 2. Sell to scammers. 3. Profit. (I want to appreciate how hard it probably is for ICANN to figure out proper TLDs.)

Amateur hour. Real professionals use .int domains... https://www.iana.org/domains/int

Aren't those real hard to come by because you have to be a UN agency or maybe a prominent NGO to get one?

Re: .INTERNAL is now reserved for private-use applications

#255
post #208

Earlier quoted context omitted.

Remember how tons of developers got surprised when Google got the .dev TLD, because they were using domains they didn't own to develop software? Well, now .internal has been reserved so developers and companies can safely use .internal domains without that happening to them.

.local being used for mDNS while Microsoft were using it in AD examples/documentation is another good example. .internal is just admitting there's only so many times we can repeat the same mistake before we start to look silly.

Our internal domain is still .local and has been since Microsoft recomended we do it that way 15 years ago.

Re: .INTERNAL is now reserved for private-use applications

#256
post #172

Earlier quoted context omitted.

.com is not a full word either (company), or .org (organization), .net (internet), .gov (government), ...

.com is literally the opposite of a "reserved to never be used" word though?

I'm not sure how that leads to the conclusion that other short, convenient TLDs like `.dev` should just be given to companies like Google to use very sparingly, if at all.

EDIT: Looks like I misunderstood what Google having .dev meant in the above discussion; domains using it are available to purchase through their registrar (or more precisely resellers since I guess they don't sell directly anymore)

Re: .INTERNAL is now reserved for private-use applications

#257
post #209

Earlier quoted context omitted.

Then why does .americanexpress exist? Sounds like someone simply pulled their wallet. Or maybe you forgot "/s"

It's a bit of both - you do have to pull out your wallet, but there's also an approval process. Just because you can buy a gTLD, doesn't mean you can buy .con

Getting ICANN to sell off .con would be the best con ever.

Re: .INTERNAL is now reserved for private-use applications

#258

Earlier quoted context omitted.

I issue a wildcard cert for *.something.example.com . All subdomains which are meant for public consumption are at the first level, like www.example.com or blog.example.com , and the ones I use internally (or even privately accessible on the internet, like xmpp.something.example.com ) are not up for discovery, as no public records exist. Everything at *.something.example.com , if it is supposed to be privately access…

This is the DNS setup I’d have in mind as well. Regarding the certificates, if you don’t want to set up stuff on clients manually, the only drawback is the use of a wildcard certificate (which when compromised can be used to hijack everything under something.example.com). An intermediate CA with name constraints (can only sign certificates with names under something.example.com) sounds like a better solution if you d…

I'm "ok" with that risk. It's less risky than other solutions, and there's also the issue that hijacked.something.example.com needs to be resolved by the internal DNS server.

All of this would most likely need to be an inside job with some relatively big criminal energy. At that level you'd probably also have other attack vectors which you could consider.

Re: .INTERNAL is now reserved for private-use applications

#259

Earlier quoted context omitted.

What do you see as the intended reasons with no other solutions?

The biggest benefit of .internal IMO is that it is free to use. Free domains used to be a thing, but after the fall of Freenom you're stuck with free subdomains.

If `.internal` is for private-use only, they must be resolved by some sort of private or internal DNS. In that case, all domains are free for private-use anyway.

Re: .INTERNAL is now reserved for private-use applications

#260
post #7

Earlier quoted context omitted.

.local is already reserved for mDNS.

Give Apple / mDNS .mdns and let it use THAT instead of .local which should NEVER have been taken from local use in the first place.

mDNS (which isn't just an Apple thing) has been using .local for roughly 20 years now. It's a little late to change that.
Post reply on HN