Earlier quoted context omitted.
Tech lead of Google Registry here. I can help answer some questions. HSTS preloading offers the highest possible level of security, as the user's browser is enforcing the use of HTTPS. Merely serving via HTTPS is only optional security, as any man-in-the-middle attacker can strip that encryption (see sslstrip, released six years ago). For more information see my blog post from last year: https://security.googleblog.c…
Trying to register via google domain says "Google Domains does not support the .APP ending". Is that on purpose (Google domain is listed on get.app as compatible) ? A cache issue ?
Introducing .app, a more secure home for apps on the web
61–70 of 378 posts
Re: Introducing .app, a more secure home for apps on the web
#62If there's anyone with an x-rated business idea, f.app is available though it's marked as a "premium" domain, likely due to the single letter. It'll cost you a cool $1,790.88/year. I wonder how much of that goes to Google.
I mean, what kinda of app want's to be called Fapp for $1500+/yr?
Re: Introducing .app, a more secure home for apps on the web
#63Earlier quoted context omitted.
So I have a Namecheap account and trying looking at an .app domain just now, but it says "We don't support this TLD". Because of this I am now on GoDaddys page pre-registering there.
Preregistrations don't really mean anything. We only do GA launches, which is on May 8.
Re: Introducing .app, a more secure home for apps on the web
#64Took me a while to figure out that Google Domains isn't participating in the Early Access Program. Apparently the "additional fee" for early access is extraordinarily high from some registrars. For example -> https://imgur.com/a/E9WRqTI
The Early Access Period is a descending price ("Dutch") auction. The fee will decrease every day at 16:00:00 Z for the first four days throughout the week-long period.
Re: Introducing .app, a more secure home for apps on the web
#65In case someone is wondering about availability: https://www.registry.google/ Here are the important dates to be aware of in 2018: Mar 29 - May 1: Trademark holders can register .app domains (known as the "Sunrise" period). May 1 - May 8: Anyone can register available .app domains for an extra fee (known as the "Early Access" period). May 8 and onwards: Anyone can register available .app domains (known as “General Av…
Anyone know of any registrars supporting the early access registration? My usual haunts all say they don't support .app
Re: Introducing .app, a more secure home for apps on the web
#66In case someone is wondering about availability: https://www.registry.google/ Here are the important dates to be aware of in 2018: Mar 29 - May 1: Trademark holders can register .app domains (known as the "Sunrise" period). May 1 - May 8: Anyone can register available .app domains for an extra fee (known as the "Early Access" period). May 8 and onwards: Anyone can register available .app domains (known as “General Av…
Anyone know of any registrars supporting the early access registration? My usual haunts all say they don't support .app
Re: Introducing .app, a more secure home for apps on the web
#67If it’s not clear from the article, HTTPS is required for all .app domains, which Google accomplished by adding the .app TLD to the default chrome HSTS preload list. Interestingly that will only ensure HTTPS only when using a browser with HSTS enabled with a preload list that includes the .app TLD. Therefore non-web code, or code in browsers without the TLD in the HSTS preload list, will be able to make HTTP requests…
On it's own I could see the argument for it being more security theater, but if I had an app on the ".app" TLD I can now stop listening on port 80 altogether without as much worry that I'm breaking stuff. That's a real security improvement.
.app will be HTTPS only from the start and for the foreseeable future, so (at least in my opinion) there's no need to care about HTTP, or even open port 80 at all.
Granted you could do this before with HSTS preload, but setting that up yourself requires fiddling with headers and waiting a bit while browsers update with the new list. With ".app" it happens automatically, so it lowers the barrier, making it easier for strong encryption to be used by everyone for anything and everything.
This makes HTTPS easier than HTTP, which doesn't look like much on paper, but is (again, in my opinion) one of the best ways to increase security overall.
Re: Introducing .app, a more secure home for apps on the web
#68Earlier quoted context omitted.
Ted, any reason why you don't permit pasting the 2-factor auth code into the input box?
trust me, it's on the backlog to fix.
Re: Introducing .app, a more secure home for apps on the web
#69Earlier quoted context omitted.
The Early Access Period is a descending price ("Dutch") auction. The fee will decrease every day at 16:00:00 Z for the first four days throughout the week-long period.
Is there a list of which registrars are participating in the early access period? None of the ones I tried seemed to recognize .app.
$11,080
then $3,205
$1,625
$1,130
$690
$580
This sucks. This is like, truly evil.
There's two hard problems:
Naming things
Cashing [sic] : Paying for the right to name things
Re: Introducing .app, a more secure home for apps on the web
#70What's the pricing? I couldn't find this info on the site.
On GoDaddy at least, pricing seems to vary by domain name. beer.app is $1,999.99 while hackernews.app is $16.99. You can check pricing on individual .app domains here: https://www.godaddy.com/tlds/app-domain Edit: It appears this pre-registration doesn't even guarantee you'll get the domain. It just increases your chances :( I'm gonna pass...