Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

351–360 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#351

Barely related question: does Google plan to deploy the .google gTLD for use in its services, i.e. will mail.google.com become mail.google, and drive.google.com change to drive.google just like they did for blog.google and registry.com?

The funny thing about their blogs is that many of em are still on the regular domain. I'd imagine there's many hurdles in migrating so many large services, and there's barely any benefits to doing so. In addition, I'm not sure if all their supported legacy browsers can even handle gTLDs.

If I were in their position I'd probably use it for new deployments, with a low priority task for evaluating the possibility of migrating existing systems.

Re: Introducing .app, a more secure home for apps on the web

#352
post #53

> HTTPS is required to connect to all .app websites, helping protect against ad malware Can somebody explain this claim? How does HTTPS protect against malware? Does no malware use HTTPS, so it all gets blocked?

Keyword here is "helping". It's only reducing the probability to get a malware.

Re: Introducing .app, a more secure home for apps on the web

#353
post #331

Earlier quoted context omitted.

Jesus, now Signal is useless.

Only if you live somewhere that blocks it. And I suspect even then, you could still use a Signal server hosted by someone else.

Not with the official client.

Re: Introducing .app, a more secure home for apps on the web

#354
post #138

Earlier quoted context omitted.

Is everything on the backlog? Still not supporting long DKIM keys. Still using deprecated and discouraged SMS as 2factor. Are your margins really that thin? It's been years :(

We introduced an alternative to 2FA SMS - Authy OneTouch. We're working on adding TOTP as well.

Just wanna give a quick +1 to this request. The lack of proper 2FA is one of my complaints as well.

Authy OneTouch pushes you towards some fairly strong platform and vendor lock-in, which I always try to avoid.

Re: Introducing .app, a more secure home for apps on the web

#355

Just for fun, I tried these domain names via the url get.app: apple.app facebook.app instagram.app twitter.app ycombinator.app * snapchat.app * producthunt.app * whatsapp.app amazon.app microsoft.app google.app hotmail.app * dropbox.app intercom.app * pivotal.app * tesla.app dell.app ibm.app * * AVAILABLE

Would I be sued (i.e is it legal?) if I buy some .app domains related to popular apps of my country and list their google play store and apple store link with some ads on those domains?

If your intention is to make some money and they have trademarks and already existing similar domains you are not acting legal! There were other people who already had the same thought as you... they failed!

Re: Introducing .app, a more secure home for apps on the web

#356
post #317

Earlier quoted context omitted.

Nope: > Google throws down a few hundred grand to get the .app domain , > in concert with modifying their web browser > to deliberately mark others' traffic as "Insecure" > (it is not necessarily!), > and reaps the fees now This is what patrickg_zill's comment said, just with some newlines and emphasis to make it more understandable. The not necessarily does not refer to HTTP, it refers to non-.app domains. And there…

It still reads to me like they meant non-HTTPS connections, as that is what they mark insecure in concert with buying the .app domain. They -could- have meant .app, but we'd need the guys word to know for sure. It's not as straightforward of a comment as you think it is.

That is probably because you want to understand it so. I give up, they completely meant HTTP vs. HTTPS...

Re: Introducing .app, a more secure home for apps on the web

#357

Yeah, the play store of websites. Where we need to get permissions and approvals and can get banned. No thanks, Google is trying to bring their walled garden idea for websites. Don't trust Google on this. They just turned off their service rather than support signal, what if signal was signal.app would they block em? Don't trust Google on this. It's a decent idea but no.

It's weird how Facebook is getting all the heat but Google is the real snake in the grass.

When Google bans you, they delete your drive, Gmail, photos and everything associated with it including the ability to search. Also they are associative; if one of your accounts are banned then any account, even business accounts, are all purged.

One of a startup in my previous cohort was completely deleted after one of it's employees who had a banned Google account logged into Google for business

Don't risk. Avoid

Re: Introducing .app, a more secure home for apps on the web

#359

Registration opens May 8th. I went through a few of the registrars and got error messages that the TLD wasn’t supported. Godaddy of course has a solidly gouging pre-registration price. Set an alarm to park park park. Edit: Godaddy isn’t straight up gouging. Seems like dictionary words are much more expensive than made up words or non-dictionary brand names. Name.com somehow has a “buy it now” option in the 10k+ range…

.app is in the sunrise phase right now -- I think all the registrars pay the same wholesale rate and it's possible that the actual price is set as well.

It'll drop to the regular price on 5/8.

Re: Introducing .app, a more secure home for apps on the web

#360
post #273

Earlier quoted context omitted.

Because telling my grandma ".app urls are safer because Google" is like saying "here's a loaded handgun, but the safety is on, go nuts!" actually that's a bad example because even then my grandma knows to be careful. but she's tech illiterate enough that if she hears something is "safer" she will put blind faith in it. This isn't an issue for me and you, the readers of HN, this is an issue for Jane Doe, who already h…

Jane Doe is not reading the Google Blog. The article is directed at developers.

When grandparents start seeing .app urls, they are going to be naturally wary. And they might even avoid clicking them. Then someone is going to ask about them to someone who is only partially tech savvy.

And that someone will tell them that those are safer URLs. And that gets misinterpreted and soon you have people saying they are special approved by google URLs that are guaranteed to be safe.

Regardless of who the article is for, tech illiterate people are going to ask "what is this new URL thing, and should I trust it?"

Post reply on HN