Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

51–60 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#54

In case someone is wondering about availability: https://www.registry.google/ Here are the important dates to be aware of in 2018: Mar 29 - May 1: Trademark holders can register .app domains (known as the "Sunrise" period). May 1 - May 8: Anyone can register available .app domains for an extra fee (known as the "Early Access" period). May 8 and onwards: Anyone can register available .app domains (known as “General Av…

Anyone know of any registrars supporting the early access registration? My usual haunts all say they don't support .app

Re: Introducing .app, a more secure home for apps on the web

#55
post #32

Earlier quoted context omitted.

Tech lead of Google Registry here. I can help answer some questions. HSTS preloading offers the highest possible level of security, as the user's browser is enforcing the use of HTTPS. Merely serving via HTTPS is only optional security, as any man-in-the-middle attacker can strip that encryption (see sslstrip, released six years ago). For more information see my blog post from last year: https://security.googleblog.c…

Trying to register via google domain says "Google Domains does not support the .APP ending". Is that on purpose (Google domain is listed on get.app as compatible) ? A cache issue ?

I can't speak specifically for Google Domains as that's a completely different team that we have limited interactions with.

What I can say is that we are currently in the Early Access Period, and that General Availability begins on May 8 at 16:00:00.000 Z. That's when you'd expect to see any remaining registrars not yet selling them start to sell them.

Re: Introducing .app, a more secure home for apps on the web

#56
post #47

Took me a while to figure out that Google Domains isn't participating in the Early Access Program. Apparently the "additional fee" for early access is extraordinarily high from some registrars. For example -> https://imgur.com/a/E9WRqTI

The Early Access Period is a descending price ("Dutch") auction. The fee will decrease every day at 16:00:00 Z for the first four days throughout the week-long period.

Re: Introducing .app, a more secure home for apps on the web

#57
post #47

Took me a while to figure out that Google Domains isn't participating in the Early Access Program. Apparently the "additional fee" for early access is extraordinarily high from some registrars. For example -> https://imgur.com/a/E9WRqTI

have you checked other registars? it's about 20eur on gandi.

https://shop.gandi.net/en/domain/suggest?search=whatthefucki...

Re: Introducing .app, a more secure home for apps on the web

#58
post #47

Took me a while to figure out that Google Domains isn't participating in the Early Access Program. Apparently the "additional fee" for early access is extraordinarily high from some registrars. For example -> https://imgur.com/a/E9WRqTI

This might be a good litmus test to see which registrars look out for their customers.

Re: Introducing .app, a more secure home for apps on the web

#59

Earlier quoted context omitted.

What are your thoughts on HSTS for a TLD when a CA can then revoke a site’s cert, preventing access entirely (See: Comodo and Sci-Hub).

You can always get a new SSL certificate from someone else quite easily (e.g. Let's Encrypt). So that's a temporary problem at worst.

Finally, "there are several dozen CAs and some are really sketchy" becomes a strength, rather than a weakness!

Re: Introducing .app, a more secure home for apps on the web

#60

HSTS seems to require the website to conform to what google defines as 'Serve a valid certificate.' Does this mean that self-signed certs will not be acceptable for a .app domain and centralized certificate authorities will be required?

Validity of SSL certificates is enforced by web browsers. If you choose to allow your self-signed certs in your browser then it will work for you, though of course not for other people.
Post reply on HN