Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

291–300 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#291

Earlier quoted context omitted.

Yes: http://www.cbsnews.com/news/daily-stormer-being-dumped-by-go... https://www.cnbc.com/2017/08/14/godaddy-boots-the-daily-stor...

Both of those are articles are about registrars refusing to do business with one specific hate group. They're not about registries.

Yes, but that still represents a very serious problem. The EFF has written extensively on it since this occurred in August. Here's a starting point: https://www.eff.org/deeplinks/2017/10/eff-icanns-registrars-....

ICANN has worked very well so far, but if they don't put up a strong response to registrar-based censorship on already-registered domains and make this contractually impossible, the internet is going to be in big trouble. We can't let "you can't have a domain because we don't want you to be able to talk, as a matter of corporate policy" become a thing.

Re: Introducing .app, a more secure home for apps on the web

#292
post #4

> The big difference is that HTTPS is required to connect to all .app websites...Because .app will be the first TLD with enforced security made available for general registration, it’s helping move the web to an HTTPS-everywhere future in a big way. This sounds good but how does it really help users or developers compared to having a .com website that uses HTTPS? Expecting that users will think "oh, .app, must be sec…

Tech lead of Google Registry here. I can help answer some questions. HSTS preloading offers the highest possible level of security, as the user's browser is enforcing the use of HTTPS. Merely serving via HTTPS is only optional security, as any man-in-the-middle attacker can strip that encryption (see sslstrip, released six years ago). For more information see my blog post from last year: https://security.googleblog.c…

IIRC, .app isn't the first TLD to be included in HSTS preload list. I hope the registrars will make it clear to customers that .app itself is in the HSTS preload list to prevent any confusion.

Re: Introducing .app, a more secure home for apps on the web

#293

Sigh. As I’ve said before, we need stronger identity profiles and user agents that verify much more than legitimate-sounding names. A name alone should effectively be treated like it could be completely and utterly fake , period. Yes, they’re requiring "https" but it’s not like it is hard to acquire a certificate anymore. All the ".app" domain will do is screw app developers into paying to register their chosen name…

HTTPS and SSL certificates are primarily used for encrypting the connection, thus protecting your data from snooping and modification in transit. They are not actually that useful for authenticating identity. Users tend to simply ignore the padlock icon, which is why Chrome is moving away from an affirmative security display model (which users don't pay much attention to) to displaying prominent warnings for insecure…

> Now imagine that that ad had instead said "Go to curb.app to get our app", and that said site had prominent links to mobile app stores.

Now imagine it's a year or two from now and you have the exact same problems that you had with curb.com.

What's the strategy for when .app gets mined out? Are we just going to keep creating new tlds over and over for eternity?

Bear in mind that the only way .app won't get mined out will be if either very few people use it, or if users ignore it and don't treat it any differently than any other namespace. Ironically, the only way this will be useful for developers like me is if Google's advertising campaign utterly fails and it's ignored by most people.

The solution to identity management can't be that users will stay one tld ahead of hackers. That's just never gonna happen. Users are slower than hackers.

Re: Introducing .app, a more secure home for apps on the web

#294

I want to clarify some details on how the Early Access Program (EAP) works because I'm seeing some confusion here in the comments. EAP is a 7-day period in advance of General Availability (GA) during which domains can be registered immediately (not pre-ordered). EAP is a descending price ("Dutch") auction, meaning that prices start off high and then decrease as the auction goes on. The reason for this is to efficient…

Both pricing mechanisms are great at: (a) transferring wealth from the secondary market to registrars, and (b) guaranteeing that desirable domain names get allocated purely on economic value terms, thus effectively shutting out non-profit-oriented enterprises from the best domain names. If someone with some quirky desire to name a domain name after their cat would like to grab the domain name and refuse to sell, this…

Without a system like this you don't get your quirky cat domain name, someone swoops in on minute 0 with a script and registers the top 1000 desirable domain names and squats them.

Anything that wouldn't have been swooped up by squatters will _also_ still be available when the early access period is over and everything is $20.

Re: Introducing .app, a more secure home for apps on the web

#295
post #200
post #138

Earlier quoted context omitted.

We introduced an alternative to 2FA SMS - Authy OneTouch. We're working on adding TOTP as well.

Hey Ted, since you're here, may I please suggest that the future implementation of 2FA not require a separate app? Even though Namecheap is using Authy OneTouch, it still requires a dedicate app, which is unnecessary. Thanks.

We partnered with Authy/Twilio on this integration to try something new. Totally get that we need additional options.

Re: Introducing .app, a more secure home for apps on the web

#296
post #87
post #6

Ted from Namecheap here - we've been excited about this TLD launch for a couple of years now and we plan to sell .app domains! Stoked it's launching very soon.

I bet all registrars are stoked when any new gTLD comes out, that auction and "valuable word"-based system must bring loads of cash. This one of the most outrageous, user-hostile things I've ever seen. It only preys on the need for brands to protect themselves while bringing no value and only confusion to end-users.

I definitely wouldn't say "loads of cash." .Com is still a very major part of any registrar's business. However, I like when new registries try new things that go beyond the namespace - requiring HTTPS could have a meaningful impact. Completely disagree that it's user-hostile — there are far fewer registration options in .com so opening up a new namespace gives users more flexibility in what they can register.

Re: Introducing .app, a more secure home for apps on the web

#297
post #54

In case someone is wondering about availability: https://www.registry.google/ Here are the important dates to be aware of in 2018: Mar 29 - May 1: Trademark holders can register .app domains (known as the "Sunrise" period). May 1 - May 8: Anyone can register available .app domains for an extra fee (known as the "Early Access" period). May 8 and onwards: Anyone can register available .app domains (known as “General Av…

Anyone know of any registrars supporting the early access registration? My usual haunts all say they don't support .app

Have a look at the list against .app with 'EAP' against their names:

https://www.registry.google/about/register.html

Re: Introducing .app, a more secure home for apps on the web

#298

Earlier quoted context omitted.

Godaddy enables you to preregister at the moment. This is only a preorder and doesn't guarantee the domain.

You can register a domain name at this moment during the Early Access Period through any registrar which supports it (which includes GoDaddy and many others listed at https://www.registry.google/about/register.html ). It's not a pre-registration; the domain is created and assigned to you immediately.

This is not true. One of my friends and myself have both paid for registration of different .app domains and some ten hours later it still says pending at two different vendors listed there as EAP providers.

Re: Introducing .app, a more secure home for apps on the web

#300
post #185

I wish Google or someone else with a lot of money would go and register every word in the English dictionary and then sell domains for reasonable prices. And there should also be a rule against domain squatting, for example only allow five domains per person/company.

What if we just sell TLDs directly to consumers?

I think it's important that any TLD is open for registration of domains. For example if Facebook bough .book they should need to allow others to register under it.
Post reply on HN