Live data from Hacker News

It's Way Too Easy to Get a .gov Domain Name

krebsonsecurity.com

51–60 of 184 posts

Re: It's Way Too Easy to Get a .gov Domain Name

#51
post #17

> A review of the Top 10 most populous U.S. cities indicates only half of them have obtained .gov domains, including Chicago, Dallas, Phoenix, San Antonio, and San Diego. > Yes, you read that right: houston.gov, losangeles.gov, newyorkcity.gov, and philadelphia.gov are all still available. As is the .gov for San Jose, Calif., the economic, cultural and political center of Silicon Valley. A minor nit: Many of these ci…

I would assume the LA City one was chosen because it’s still shorter than Los Angeles and it also differentiates from LA County. Much of the LA metropolitan area is within the county limits but not part of the city of LA.

Re: It's Way Too Easy to Get a .gov Domain Name

#52
post #14

Earlier quoted context omitted.

Yeah but A) military gear is more than automatic weapons. Sometimes they send out things harder to come by than guns to police departments. B) This scheme costs less than pennies on the dollar.

This scheme only makes economic sense if you neglect to factor in the cost of being sent to federal prison for many years.

Isn't that part of the cost with all the schemes?

Re: It's Way Too Easy to Get a .gov Domain Name

#53

Earlier quoted context omitted.

> Some cities may also use a subdomain of their states domain, which may or may not be a .gov. This reminds me of how longwinded the domain hierarchy for .us originally was. In MN (not sure if it's the same for every state), city domains were "www.ci.cityname.mn.us". Then the school district's web site was "www.cityname.k12.mn.us". Not only was the order inconsistent (why not www.k12.cityname etc.?) but sometimes the…

School districts are separate from municipalities and often will span multiple.

> School districts are separate from municipalities and often will span multiple.

School districts may or may not be subordinate to city or county governments, and this may not be consistent state wide (of course, he heirarchy of city vs county may not be consistent statewide—looking at NYC.)

Re: It's Way Too Easy to Get a .gov Domain Name

#55

Earlier quoted context omitted.

That's not how .nyc is used or is expected to be used. It's a top-level domain, not a dotless host name. Here's an example of how it's used: https://thecity.nyc/

> That's not how .nyc is used or is expected to be used. It's a top-level domain, not a dotless host name. While it is prohibited by the ICANN policy [1], it is not strictly enforced so that there are multiple TLDs with A/AAAA records. They traditionally could be resolved with a trailing dot (thus it is not a dotless host name, that would have no dot), but nowadays many browsers refuse to resolve them without an expl…

HN doesn't like your link's formatting. Try: http://www.pn./ or http://www.pn/

Re: It's Way Too Easy to Get a .gov Domain Name

#57

Earlier quoted context omitted.

We have a TLD for NYC. It is, expectedly, not used for the city's official website. I guess people don't know how to visit TLDs in their browser. (I believe it would be "nyc.")

That's not how .nyc is used or is expected to be used. It's a top-level domain, not a dotless host name. Here's an example of how it's used: https://thecity.nyc/

I mean, someone made some policy that says that... but it would be fun! Do people still have fun these days?

Re: It's Way Too Easy to Get a .gov Domain Name

#58

Isn't the main issue that TLDs are a poor way of establishing trust? Otherwiae does every company and government need to get specialized TLDs to prevent impersonation? Even then it only works is users know and always notice the domain. EV certs are dead for good reason but nothing seems to have replaced them. I guess the only option is to verify each site once and then bookmark it and always make sure it's https. But…

Well the back of my Chase card says chase.com.

If you tend to use search engines to find websites, you are trusting the search engine to give you the website for Chase Bank.

Re: It's Way Too Easy to Get a .gov Domain Name

#59
post #6

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

I see what you mean, but I suspect the author might be referring to the Russian disinformation campaign to favour Republicans. I see it just as an example - obviously it can be adapted in either direction, or both just to deter voter participation altogether.

It would be shocking, though, if it turned out that Russia was the only country trying to influence US elections, though, instead of the only one that has been publically exposed.

Re: It's Way Too Easy to Get a .gov Domain Name

#60
post #24

Earlier quoted context omitted.

From an outsiders perspective, there's very little difference between both your political parties.

One party asked for voter data by race, then got rid of voting methods disproportionately used by black people. The same party also passed voter ID laws, and allowed NRA membership cards but not college ID cards. Your comment amounts to "I'm ignorant, but to me both parties are the same".

I don't know about NRA membership cards but I know for a fact that college ID cards tend to be quite easily to forge.

Regardless, it seems very weird to me that they would accept non-government issued IDs for elections.

Post reply on HN