Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

331–340 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#331

Earlier quoted context omitted.

https://www.theverge.com/2018/5/1/17308508/amazon-web-servic... https://www.theverge.com/2018/4/18/17253784/google-domain-fr...

Jesus, now Signal is useless.

Only if you live somewhere that blocks it.

And I suspect even then, you could still use a Signal server hosted by someone else.

Re: Introducing .app, a more secure home for apps on the web

#332

Earlier quoted context omitted.

> Are we just going to keep creating new tlds over and over for eternity? Yes. The "easily memorable global namespace" is a limited natural resource, there is no definitive fix and there can't be - unless you accept the totalitarian single gatekeeper scheme Cyde describes. In an open system, you always need to deal with the Sybil attack and the only solution is proof of work, resources - money. This means domain squa…

Wouldn't it be easier to just raise domain registration /renewal prices, making squatting a poor return on investment?

That's what Google did here, by having an early period during which domains cost more.

And this is the predictable response: https://news.ycombinator.com/item?id=16972813

Re: Introducing .app, a more secure home for apps on the web

#333
post #273
post #198

Earlier quoted context omitted.

...and I'm not sure Google has claimed any different. Just that HSTS enforced on the TLD level is more secure than otherwise, which it is.

Because telling my grandma ".app urls are safer because Google" is like saying "here's a loaded handgun, but the safety is on, go nuts!" actually that's a bad example because even then my grandma knows to be careful. but she's tech illiterate enough that if she hears something is "safer" she will put blind faith in it. This isn't an issue for me and you, the readers of HN, this is an issue for Jane Doe, who already h…

Jane Doe is not reading the Google Blog. The article is directed at developers.

Re: Introducing .app, a more secure home for apps on the web

#334

Earlier quoted context omitted.

I'm getting it from here: > modifying their web browser to deliberately mark others' traffic as "Insecure" I'm assuming the parent comment meant how Chrome marks HTTP connections as insecure; they're not marking TLD's that aren't .app as insecure.

I think the idea would be that Chrome would sooner or later mark non-HSTS sites like .app as 'half secure' or add a special extra greener bar for .app sites. Given Google's track record, I wouldn't really doubt it.

non-HSTS sites like .app

What?

add a special extra greener bar for .app sites

That would be really weird, considering that most Google sites are not .app, and would be quite a pain to change. Suddenly every competitor to their services get a special greener bar for a few bucks?

Re: Introducing .app, a more secure home for apps on the web

#335

Is being cynical about this allowed? Google throws down a few hundred grand to get the .app domain, in concert with modifying their web browser to deliberately mark others' traffic as "Insecure" (it is not necessarily!), and reaps the fees now and in perpetuity ever year thereafter for maintaining a simple database of DNS glue entries which you literally could maintain using MS Access (by which I mean, the database s…

And it won't take many registrations to recoup the investment. They're charging $999 / year at least for pre-registrations. I clicked through to the price using godaddy and the $16.99 / year price quickly got replaced by the higher number which also indicated that $1000 was the yearly renewal price if one gets the domain through pre-registration. (Your money gets refunded if you don't get the domain.) I'm sure godadd…

also indicated that $1000 was the yearly renewal price if one gets the domain through pre-registration.

That's just on GoDaddy.

"EAP is a one-time acquisition fee; you do not pay that on subsequent renewal."

https://news.ycombinator.com/item?id=16971246

Re: Introducing .app, a more secure home for apps on the web

#336

I want to clarify some details on how the Early Access Program (EAP) works because I'm seeing some confusion here in the comments. EAP is a 7-day period in advance of General Availability (GA) during which domains can be registered immediately (not pre-ordered). EAP is a descending price ("Dutch") auction, meaning that prices start off high and then decrease as the auction goes on. The reason for this is to efficient…

Both pricing mechanisms are great at: (a) transferring wealth from the secondary market to registrars, and (b) guaranteeing that desirable domain names get allocated purely on economic value terms, thus effectively shutting out non-profit-oriented enterprises from the best domain names. If someone with some quirky desire to name a domain name after their cat would like to grab the domain name and refuse to sell, this…

Why is (a) shitty?

Re: Introducing .app, a more secure home for apps on the web

#337

Earlier quoted context omitted.

That's a bad idea but here you go https://stackoverflow.com/questions/44650854/how-to-disable-...

Well, disabling HSTS is a badidea as long as the logical (or legal) entity creating the subdomain is the same one that enforces HSTS, which was the case up until this point, (in that being the same entity they know which subdomains need HSTS and which ones don't).

Anyone registering a .app domain knows it will have HSTS, so they feel it's appropriate for their site to use it.

Re: Introducing .app, a more secure home for apps on the web

#338
post #242

Earlier quoted context omitted.

That’s fair, given that HSTS is after all a standard itself and Google is merely applying it. Then I guess my perplexity is towards IETF in that they allow for two conflicting standards to exist. What if I want to use local.my.app for development; Or, in a more textbook example, i want to use workstation-1.building-a.my.internal.my.app without https?

Arbitrarily across an entire TLD. Because IANA decided to start selling off the web for companies to abuse. > What if I want to use local.my.app for development; You can switch to .dev... oh right.

What makes .net OK but .app is "selling off the web"? I mean, besides traditionalist conservatism?

Re: Introducing .app, a more secure home for apps on the web

#339
post #308

Why does "his.app" cost $499.99 for pre-registration, but "her.app" only costs $249.99? :) Is this some built-in gender bias?

I am new to domain trading. I have one question - Would I be sued (i.e is it legal?) if I buy some .app domains related to some popular apps of my country and list their google play store and apple store link with some ads on those domains?

I don't know if it's illegal, but unless you have a trademark on those names, you're almost certain to lose them.

Re: Introducing .app, a more secure home for apps on the web

#340

Why is Google launching a TLD and you cannot purchase it through Google Domains? It's currently showing as "Not Supported" even though they link to Google Domains from get.app. It's mind-boggling to think they couldn't come up with a "coming soon" blip if somebody tries to look up a Google-owned TLD on Google Domains.

From another post in this thread, ICANN rules prevent the two from coordinating.
Post reply on HN