Live data from Hacker News

Google .dev domain early access

domains.google

441–450 of 475 posts

Re: Google .dev domain early access

#441
post #392

Earlier quoted context omitted.

Who is a good/trustworthy registrar then?

https://namesilo.com - reliable, cheap & they offer free whois privacy. All they do is sell domains.

I couldn't recommend namesilo more! They almost always have the slowest price, very close to what the registry charges them.

Their UI is dead simple and gets things done well and fast.

Re: Google .dev domain early access

#442

Earlier quoted context omitted.

If I register a domain, can google boot me off it at a later year if they don't like my politics? Or do I own the domain with the continuing option to re-register it or transfer to another domain registrar? Does google ultimately own the domains and simply lease them to me with no guaranteed option to continue?

That's a redundant question, because just about every registry can dictate what their TLDs can be used for. It's part of the design laid down by ICANN. - For Verisign with .com, they don't care if you're really a company or not. - With Minds & Machines and .law, they only want qualified lawyers, courts, legal schools, etc. using the TLD. Keep in mind that the registry and registrar are different things.

@bduerst, Forgive my ignorance, but just to distill it down to brass tacks:

In this case, Google is the registry and thus the supreme court of who can and cannot be on this domain and there is no recourse if they yank your claim on the domain?

Is it more nuanced than that?

Re: Google .dev domain early access

#443
post #418

Earlier quoted context omitted.

cloudflare?

Problem with Cloudflare is that their CEO has taken down a domain for political reasons. While I agree with him taking the domain down, but what about the next CEO?

Unless I'm thinking of something else, it's not a domain registered through CloudFlare. The taken down site was using CloudFlare's reverse proxy service. IIRC, Matthew wrote about the incident in length.

I personally don't use CF for various reasons, but this site take down is not one of them.

Re: Google .dev domain early access

#444

Earlier quoted context omitted.

Because this is your area of expertise, can I ask you why more registrars are not selling 10 or 20 year domain ownership? Who wants a domain for just a year (if you agree with the premise behind individuals owning domains in the first place)? If I could buy a domain for 50 years, I'd do it.

Most TLDs allow registration lengths up to 10 years. And registrars will happily sell you registration for 10 years. Buy the domain, then immediately renew it for 9 years. I suspect the reason they don't offer a choice of registration years in the initial checkout flow is to reduce purchasing friction -- they don't want you to have to make another choice and then potentially back out of the sale. It's the same reason…

I recently read an HN thread about Romanian ccTLD registry selling domains for lifetime. They have stopped it and asked the former customers to pay up though.

Re: Google .dev domain early access

#445
post #397

Earlier quoted context omitted.

OV is useless. No consumers look at it. It’s just a sad attempt for CAs to trick people into paying for something they don’t need.

Seeing the organisation name next to the lock icon definitely gives me an extra layer of warm and fuzzy feelings. I’d say it has some value for those that can pay for it.

You are talking about EV certificates. OV-validated certificates require (the best case) the user to click on the padlock icon to reveal more information about the certificate.

Re: Google .dev domain early access

#446
post #339

Earlier quoted context omitted.

ACME is an open protocol (and very soon it will be an IETF Internet Standard too). There are many alternative implementations. Just find one you trust. We actually did our own DNS-based implementation for our infrastructure.

I don't want to run someone else's code on my server just for this (the default certbot wants root access too, yikes), nor do I want to analyze someone else's implementation before running their code, and I sure as heck don't have the time, patience, or interest to write my own implementation of ACME just for the one service that uses it. I want to go to a website, have it tell me to put a string into a meta tag or D…

ACME protocol is fairly straight forward to implement, and you can easily write your own implementation with existing code (OpenSSL, Apache/nginx, etc).

With many commercial registrar's, although they offer a valid and long certificate, their technical aspects aren't very good. Many CAs don't support ECC certificates, the must-staple flag or CT SCTs embedded in the certificate.

I work a lot with web PKI, and every time I have to deal with a CA that's not LE or Digicert, I sigh out loud.

Re: Google .dev domain early access

#447
post #418

Earlier quoted context omitted.

cloudflare?

Problem with Cloudflare is that their CEO has taken down a domain for political reasons. While I agree with him taking the domain down, but what about the next CEO?

The full context here is: https://en.wikipedia.org/wiki/The_Daily_Stormer#Site_hosting...

Re: Google .dev domain early access

#448
post #444

Earlier quoted context omitted.

Most TLDs allow registration lengths up to 10 years. And registrars will happily sell you registration for 10 years. Buy the domain, then immediately renew it for 9 years. I suspect the reason they don't offer a choice of registration years in the initial checkout flow is to reduce purchasing friction -- they don't want you to have to make another choice and then potentially back out of the sale. It's the same reason…

I recently read an HN thread about Romanian ccTLD registry selling domains for lifetime. They have stopped it and asked the former customers to pay up though.

And also ccTLDs can make up whatever rules they want, whereas gTLDs are all bound by the same common set of rules. There are many ccTLDs that don't even use EPP (the spec I linked to above).

Re: Google .dev domain early access

#449
post #401
post #355

Earlier quoted context omitted.

Why would you need a real cert? This is for your local machine, right? Use the tool, generate a CA, important into Mozilla's trust store, and go nuts. I'm trying to imagine a webdev workflow where you couldn't get a machine-local CA working.

No admin privileges to manipulate the certificate store is one.

You shouldn't need admin to add a CA to the Windows User Trusted Root Store.

https://docs.microsoft.com/en-us/windows/desktop/seccrypto/s...

Re: Google .dev domain early access

#450

Earlier quoted context omitted.

Hi. I'm the Tech Lead of Google Registry, the team that is launching .dev (not to be confused with the linked Google Domains, which is one of many registrars selling .dev domains to end users). You'll be glad to know that TLDs can't simply be discontinued like other products might be. ICANN doesn't allow it. The procedures in place preventing a live TLD from shutting down are called EBERO; more details here: https://…

If I register a domain, can google boot me off it at a later year if they don't like my politics? Or do I own the domain with the continuing option to re-register it or transfer to another domain registrar? Does google ultimately own the domains and simply lease them to me with no guaranteed option to continue?

And just like that, the 'Tech Lead of Google Registry' has fallen silent.
Post reply on HN