Earlier quoted context omitted.
I'm not sure how a .app TLD could be mistaken for a .app executable.
You severely overestimate the technical skill of the average user. And even people who know their way around computers rely heavily on patterns in order to identify relationships, so a strong pattern without an underlying relationship is, of course, going to lead to confusion.
Introducing .app, a more secure home for apps on the web
31–40 of 378 posts
Re: Introducing .app, a more secure home for apps on the web
#32> The big difference is that HTTPS is required to connect to all .app websites...Because .app will be the first TLD with enforced security made available for general registration, it’s helping move the web to an HTTPS-everywhere future in a big way. This sounds good but how does it really help users or developers compared to having a .com website that uses HTTPS? Expecting that users will think "oh, .app, must be sec…
Tech lead of Google Registry here. I can help answer some questions. HSTS preloading offers the highest possible level of security, as the user's browser is enforcing the use of HTTPS. Merely serving via HTTPS is only optional security, as any man-in-the-middle attacker can strip that encryption (see sslstrip, released six years ago). For more information see my blog post from last year: https://security.googleblog.c…
Re: Introducing .app, a more secure home for apps on the web
#33Earlier quoted context omitted.
Exactly the same, the preload list data is public and used by all the major browsers.
What is the "single source of truth" for the HSTS preload list? It must be on a server somewhere... who runs the server? Which browsers use this list by default?
Re: Introducing .app, a more secure home for apps on the web
#34Here are the important dates to be aware of in 2018:
Mar 29 - May 1: Trademark holders can register .app domains (known as the "Sunrise" period).
May 1 - May 8: Anyone can register available .app domains for an extra fee (known as the "Early Access" period).
May 8 and onwards: Anyone can register available .app domains (known as “General Availability").
Re: Introducing .app, a more secure home for apps on the web
#35So what registrars are taking part Early Access Program?
Re: Introducing .app, a more secure home for apps on the web
#36Re: Introducing .app, a more secure home for apps on the web
#37What's the pricing? I couldn't find this info on the site.
Re: Introducing .app, a more secure home for apps on the web
#38Earlier quoted context omitted.
What are your thoughts on HSTS for a TLD when a CA can then revoke a site’s cert, preventing access entirely (See: Comodo and Sci-Hub).
You can always get a new SSL certificate from someone else quite easily (e.g. Let's Encrypt). So that's a temporary problem at worst.
Re: Introducing .app, a more secure home for apps on the web
#39Earlier quoted context omitted.
You can always get a new SSL certificate from someone else quite easily (e.g. Let's Encrypt). So that's a temporary problem at worst.
As long as the CA is in a jurisdiction that can require revoking access, it becomes an attack vector if HSTS is enabled and you’re at the mercy of preloaded root CAs.
Re: Introducing .app, a more secure home for apps on the web
#40In case someone is wondering about availability: https://www.registry.google/ Here are the important dates to be aware of in 2018: Mar 29 - May 1: Trademark holders can register .app domains (known as the "Sunrise" period). May 1 - May 8: Anyone can register available .app domains for an extra fee (known as the "Early Access" period). May 8 and onwards: Anyone can register available .app domains (known as “General Av…