Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

271–280 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#271

Earlier quoted context omitted.

Can you provide an example? Something more specific than merely competing with existing businesses. The intent is key in the original definition of EEE.

Google Reader would be the often mentioned first example: Google entered the RSS reader market, became the best, added a bunch of features and really became "the" de facto place to read feeds. ...Then closed up shop and killed much of the ecosystem outright, directing people towards proprietary places to get their news like social networks or Google News. Hangouts did very much the same with XMPP, a move which a Goog…

Google Reader is pretty much the opposite of EEE. They built and publicised the market and then walked away.

Just having the best app isn't EEE.

Re: Introducing .app, a more secure home for apps on the web

#272
post #4

> The big difference is that HTTPS is required to connect to all .app websites...Because .app will be the first TLD with enforced security made available for general registration, it’s helping move the web to an HTTPS-everywhere future in a big way. This sounds good but how does it really help users or developers compared to having a .com website that uses HTTPS? Expecting that users will think "oh, .app, must be sec…

Tech lead of Google Registry here. I can help answer some questions. HSTS preloading offers the highest possible level of security, as the user's browser is enforcing the use of HTTPS. Merely serving via HTTPS is only optional security, as any man-in-the-middle attacker can strip that encryption (see sslstrip, released six years ago). For more information see my blog post from last year: https://security.googleblog.c…

Go fuck yourself scumbag you work for nazis. Shame on you!!!

Re: Introducing .app, a more secure home for apps on the web

#273
post #198

Supporting https is only an infinitesimal part of what makes downloading apps on the internet like playing Russian Roulette. It still doesn't prevent unsuspecting users from downloading malware, adware, ransomware, and apps that siphon user data. It also doesn't prevent users of sites depending on third party ad networks from being a victim of the same vulnerabilities they are now.

...and I'm not sure Google has claimed any different. Just that HSTS enforced on the TLD level is more secure than otherwise, which it is.

Because telling my grandma ".app urls are safer because Google" is like saying "here's a loaded handgun, but the safety is on, go nuts!"

actually that's a bad example because even then my grandma knows to be careful. but she's tech illiterate enough that if she hears something is "safer" she will put blind faith in it.

This isn't an issue for me and you, the readers of HN, this is an issue for Jane Doe, who already has low standards, and is now going to lower those standards even further for a set of websites.

Re: Introducing .app, a more secure home for apps on the web

#274

Yeah, the play store of websites. Where we need to get permissions and approvals and can get banned. No thanks, Google is trying to bring their walled garden idea for websites. Don't trust Google on this. They just turned off their service rather than support signal, what if signal was signal.app would they block em? Don't trust Google on this. It's a decent idea but no.

Is there any precedent for a TLD owner doing what you describe? I think this is HSTS preload and nothing more.

Yes:

http://www.cbsnews.com/news/daily-stormer-being-dumped-by-go...

https://www.cnbc.com/2017/08/14/godaddy-boots-the-daily-stor...

Re: Introducing .app, a more secure home for apps on the web

#275

Earlier quoted context omitted.

Is there any precedent for a TLD owner doing what you describe? I think this is HSTS preload and nothing more.

Yes: http://www.cbsnews.com/news/daily-stormer-being-dumped-by-go... https://www.cnbc.com/2017/08/14/godaddy-boots-the-daily-stor...

Both of those are articles are about registrars refusing to do business with one specific hate group. They're not about registries.

Re: Introducing .app, a more secure home for apps on the web

#276
post #270

Earlier quoted context omitted.

They put this announcement out so they can sell spots on the "Priority Pre Registration" list for $16,000. It's just another fucking cash grab.

For end users it costs ~$20, right now from one of the EAP registrars. Outrage is great, but it's a good idea to read before firing off like this.

[deleted]

Re: Introducing .app, a more secure home for apps on the web

#277

Earlier quoted context omitted.

Yes: http://www.cbsnews.com/news/daily-stormer-being-dumped-by-go... https://www.cnbc.com/2017/08/14/godaddy-boots-the-daily-stor...

Both of those are articles are about registrars refusing to do business with one specific hate group. They're not about registries.

Aren't Google and Godaddy both TLD owners?

Re: Introducing .app, a more secure home for apps on the web

#278

Earlier quoted context omitted.

Both of those are articles are about registrars refusing to do business with one specific hate group. They're not about registries.

Aren't Google and Godaddy both TLD owners?

GoDaddy is a registrar. Google has both a registrar and a registry, but the linked actions were taken on the registrar side (i.e. not relevant to what the registry can do with its TLDs). The list of TLDs run by the registry can be found here: https://www.registry.google

Re: Introducing .app, a more secure home for apps on the web

#279

Earlier quoted context omitted.

Both of those are articles are about registrars refusing to do business with one specific hate group. They're not about registries.

Aren't Google and Godaddy both TLD owners?

Yes, technically. But GoDaddy's GTLD (.godaddy) isn't available for public use, so your point is moot.

Re: Introducing .app, a more secure home for apps on the web

#280
post #270

Earlier quoted context omitted.

They put this announcement out so they can sell spots on the "Priority Pre Registration" list for $16,000. It's just another fucking cash grab.

For end users it costs ~$20, right now from one of the EAP registrars. Outrage is great, but it's a good idea to read before firing off like this.

It costs end users ~$20, for whatever's left over after the seven rounds of expensive "priority access" pick over the namespace carcass... At least for the two out of three resellers I tried (Google themselves still don't appear to know this exists...)
Post reply on HN