Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

41–50 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#41
post #9

The defining feature here seems to be HSTS - all .app domains will connect via HTTPS by default, and never try HTTP. Which is nice. Otherwise... eh. In theory this becomes a home for web sites specifically related to apps. Certainly that seems to be what Google are suggesting. But are web apps "apps"? Is this native only? Are Google going to be actively monitoring these to make sure the content is related to the .app…

If they're PWAs they get really close to being apps. Seems like Google is making a big push in Chrome and Android to provide that App experience for websites which do the work to support it.

Re: Introducing .app, a more secure home for apps on the web

#44
post #4

> The big difference is that HTTPS is required to connect to all .app websites...Because .app will be the first TLD with enforced security made available for general registration, it’s helping move the web to an HTTPS-everywhere future in a big way. This sounds good but how does it really help users or developers compared to having a .com website that uses HTTPS? Expecting that users will think "oh, .app, must be sec…

Tech lead of Google Registry here. I can help answer some questions. HSTS preloading offers the highest possible level of security, as the user's browser is enforcing the use of HTTPS. Merely serving via HTTPS is only optional security, as any man-in-the-middle attacker can strip that encryption (see sslstrip, released six years ago). For more information see my blog post from last year: https://security.googleblog.c…

I know TLD's doesn't affect SEO, but does Google enhance .app domain SEO when people search for apps on Google search?

Re: Introducing .app, a more secure home for apps on the web

#45
post #9

The defining feature here seems to be HSTS - all .app domains will connect via HTTPS by default, and never try HTTP. Which is nice. Otherwise... eh. In theory this becomes a home for web sites specifically related to apps. Certainly that seems to be what Google are suggesting. But are web apps "apps"? Is this native only? Are Google going to be actively monitoring these to make sure the content is related to the .app…

> But are web apps "apps"?

Both Google and Microsoft are both strongly in the "Yes" category here and are heavily pushing PWAs as a future of many types of apps. If a lot of PWAs also want to use .app as their TLD, that serves Google's purposes just fine, I'd imagine.

> Are Google going to be actively monitoring these to make sure the content is related to the .app TLD?

Where's the creativity in that? The internet decided a long time ago that it would rather do interesting things with TLDs than strictly enforce them; use the origins and "purpose" of a TLD as a loose guideline.

What's the harm in a restaurant deciding that .app fits their brand because they have the best apps (appetizers) in town?

Is it any worse than all the startups that have been using Chagos' country TLD .io without having anything to do with the atoll of Chagos? (Which of course is made worse by the funds from .io going to British corporate colonialists rather than directly to benefit anyone in Chagos. How many startups even think of that when paying for their hip domain name?)

Re: Introducing .app, a more secure home for apps on the web

#48
post #43

If there's anyone with an x-rated business idea, f.app is available though it's marked as a "premium" domain, likely due to the single letter. It'll cost you a cool $1,790.88/year. I wonder how much of that goes to Google.

I mean, what kinda of app want's to be called Fapp for $1500+/yr?

Re: Introducing .app, a more secure home for apps on the web

#49

What's the pricing? I couldn't find this info on the site.

On GoDaddy at least, pricing seems to vary by domain name. beer.app is $1,999.99 while hackernews.app is $16.99. You can check pricing on individual .app domains here: https://www.godaddy.com/tlds/app-domain

Edit: It appears this pre-registration doesn't even guarantee you'll get the domain. It just increases your chances :( I'm gonna pass...

Re: Introducing .app, a more secure home for apps on the web

#50
post #17
post #2

Excellent, this will surely cause no confusion with macOS executables.

Just like .com didn’t cause confusion with DOS and Windows .com executables.

Just like .sh didn't cause confusion with the .sh extension for shell scripts.
Post reply on HN