Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

281–290 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#281

Yeah, the play store of websites. Where we need to get permissions and approvals and can get banned. No thanks, Google is trying to bring their walled garden idea for websites. Don't trust Google on this. They just turned off their service rather than support signal, what if signal was signal.app would they block em? Don't trust Google on this. It's a decent idea but no.

You mean Signal the messaging app? Can you link to a news?

Re: Introducing .app, a more secure home for apps on the web

#282

Supporting https is only an infinitesimal part of what makes downloading apps on the internet like playing Russian Roulette. It still doesn't prevent unsuspecting users from downloading malware, adware, ransomware, and apps that siphon user data. It also doesn't prevent users of sites depending on third party ad networks from being a victim of the same vulnerabilities they are now.

Later google will launch .ampp for apps that are certified to only have Google and their thousands of partners sharing your PII 'securely'.

That honestly doesn't even sound like a joke. I'd believe it if you said that's a quote from the article.

Re: Introducing .app, a more secure home for apps on the web

#284

Yeah, the play store of websites. Where we need to get permissions and approvals and can get banned. No thanks, Google is trying to bring their walled garden idea for websites. Don't trust Google on this. They just turned off their service rather than support signal, what if signal was signal.app would they block em? Don't trust Google on this. It's a decent idea but no.

You mean Signal the messaging app? Can you link to a news?

https://www.theverge.com/2018/5/1/17308508/amazon-web-servic...

https://www.theverge.com/2018/4/18/17253784/google-domain-fr...

Re: Introducing .app, a more secure home for apps on the web

#285
post #270

Earlier quoted context omitted.

They put this announcement out so they can sell spots on the "Priority Pre Registration" list for $16,000. It's just another fucking cash grab.

For end users it costs ~$20, right now from one of the EAP registrars. Outrage is great, but it's a good idea to read before firing off like this.

That’s misleading. That won’t fire until May 9 (GA). If it’s left.

(You can use your TMCH SMD file to register your trademark.app for ~$20, but that’s not really what we’re taking about here.)

Re: Introducing .app, a more secure home for apps on the web

#286

Earlier quoted context omitted.

You mean Signal the messaging app? Can you link to a news?

https://www.theverge.com/2018/5/1/17308508/amazon-web-servic... https://www.theverge.com/2018/4/18/17253784/google-domain-fr...

Jesus, now Signal is useless.

Re: Introducing .app, a more secure home for apps on the web

#287

Earlier quoted context omitted.

Aren't Google and Godaddy both TLD owners?

Yes, technically. But GoDaddy's GTLD (.godaddy) isn't available for public use, so your point is moot.

My point is that google will ban your website off the internet in whatever way possible for them, if they don't agree with what you're saying. They have demonstrated this as I linked. Just because their role is now TLD owner, doesn't mean they will not do what they think is necessary.

Re: Introducing .app, a more secure home for apps on the web

#288

Earlier quoted context omitted.

You can always get a new SSL certificate from someone else quite easily (e.g. Let's Encrypt). So that's a temporary problem at worst.

As long as the CA is in a jurisdiction that can require revoking access, it becomes an attack vector if HSTS is enabled and you’re at the mercy of preloaded root CAs.

There are many preloaded root CAs. Are you saying you're worried that every single one of them will simultaneously be required to revoke your certificates?

Re: Introducing .app, a more secure home for apps on the web

#289

Earlier quoted context omitted.

Google Reader does not fit the pattern of EEE; if anything, it shows their failure to pursue it. EEE with Reader would be to add proprietary extension to feeds and transform it into a closed system. What they actually did was lose a bunch of people for alternative readers, for Twitter and for Facebook. AMP for email does seem a good example. RCS is not developed by or supported exclusively by Google. They weren't eve…

> EEE with Reader would be to add proprietary extension to feeds and transform it into a closed system Like Google+?

Reader didn't transform into Google+. Google+ was a Facebook clone.

Re: Introducing .app, a more secure home for apps on the web

#290

Earlier quoted context omitted.

You mean Signal the messaging app? Can you link to a news?

https://www.theverge.com/2018/5/1/17308508/amazon-web-servic... https://www.theverge.com/2018/4/18/17253784/google-domain-fr...

I don't understand why Google or Amazon are to blame here. It's like using an unofficial API and then complaining when it's taken down. Yes, it sucks that Signal can't hide behind them to bypass censorship, but as far as I understanding, it's not a good practice for these big sites to support Domain fronting in the first place.
Post reply on HN