Live data from Hacker News

Introducing .app, a more secure home for apps on the web

blog.google

71–80 of 378 posts

Re: Introducing .app, a more secure home for apps on the web

#71
post #64

Earlier quoted context omitted.

The Early Access Period is a descending price ("Dutch") auction. The fee will decrease every day at 16:00:00 Z for the first four days throughout the week-long period.

Is there a list of which registrars are participating in the early access period? None of the ones I tried seemed to recognize .app.

See https://www.registry.google/about/register.html -- the ones supporting EAP are annotated as such.

Re: Introducing .app, a more secure home for apps on the web

#72
post #47

Took me a while to figure out that Google Domains isn't participating in the Early Access Program. Apparently the "additional fee" for early access is extraordinarily high from some registrars. For example -> https://imgur.com/a/E9WRqTI

I just tried to buy one. Got an email saying I'd be invoiced on allocation of that domain to the registrar. WTF does that mean? How can they take my money if they don't even know they'll have the domain to sell?

Re: Introducing .app, a more secure home for apps on the web

#73
post #50
post #17

Earlier quoted context omitted.

Just like .com didn’t cause confusion with DOS and Windows .com executables.

Just like .sh didn't cause confusion with the .sh extension for shell scripts.

Except, .sh means nothing in particular in Linux. It just so happens people use .sh for shell scripts.

Re: Introducing .app, a more secure home for apps on the web

#74
post #54

In case someone is wondering about availability: https://www.registry.google/ Here are the important dates to be aware of in 2018: Mar 29 - May 1: Trademark holders can register .app domains (known as the "Sunrise" period). May 1 - May 8: Anyone can register available .app domains for an extra fee (known as the "Early Access" period). May 8 and onwards: Anyone can register available .app domains (known as “General Av…

Anyone know of any registrars supporting the early access registration? My usual haunts all say they don't support .app

Confirmed that gandi.net does support it

Re: Introducing .app, a more secure home for apps on the web

#75
post #74
post #54

Earlier quoted context omitted.

Anyone know of any registrars supporting the early access registration? My usual haunts all say they don't support .app

Confirmed that gandi.net does support it

That must have been a just-missed thing - I checked Gandi just before my post

Re: Introducing .app, a more secure home for apps on the web

#76

Earlier quoted context omitted.

You can always get a new SSL certificate from someone else quite easily (e.g. Let's Encrypt). So that's a temporary problem at worst.

Finally, "there are several dozen CAs and some are really sketchy" becomes a strength, rather than a weakness!

Sketchy CAs that issue certificates to people that don't actually own the domains in question tend to get nuked from the chain of trust very quickly.

Re: Introducing .app, a more secure home for apps on the web

#77
post #72
post #47

Took me a while to figure out that Google Domains isn't participating in the Early Access Program. Apparently the "additional fee" for early access is extraordinarily high from some registrars. For example -> https://imgur.com/a/E9WRqTI

I just tried to buy one. Got an email saying I'd be invoiced on allocation of that domain to the registrar. WTF does that mean? How can they take my money if they don't even know they'll have the domain to sell?

I believe that, as a general policy, registrars refund your money if they don't actually manage to acquire the domain name on your behalf.

Re: Introducing .app, a more secure home for apps on the web

#78
post #53

> HTTPS is required to connect to all .app websites, helping protect against ad malware Can somebody explain this claim? How does HTTPS protect against malware? Does no malware use HTTPS, so it all gets blocked?

It doesn't. They are likely referring to some malware attack vectors that rely on hijacking local DNS or routing between the web browser and the server (eg, at your coffee shop wifi, or your ISP injecting junk into the HTTP stream), and requiring HTTPS makes such attacks a little bit harder. But there are plenty of other ways to send "ad malware" to browsers that work just fine over HTTPS. And as for ISPs, they could easily (in some places, they likely do, and someday most probably will) require you to install their own custom certs in your trusted store and MITM all your web traffic. TLS 1.3 tried to work around this threat as well, but enterprise security people who "need" to monitor all traffic in and out of their network blew that up. But your browser will show a green lock icon, so it's fine.

Re: Introducing .app, a more secure home for apps on the web

#79
post #32

Earlier quoted context omitted.

Trying to register via google domain says "Google Domains does not support the .APP ending". Is that on purpose (Google domain is listed on get.app as compatible) ? A cache issue ?

Godaddy enables you to preregister at the moment. This is only a preorder and doesn't guarantee the domain.

You can register a domain name at this moment during the Early Access Period through any registrar which supports it (which includes GoDaddy and many others listed at https://www.registry.google/about/register.html ). It's not a pre-registration; the domain is created and assigned to you immediately.

Re: Introducing .app, a more secure home for apps on the web

#80
https://blog.google/topics/developers/introducing-app-more-s...

It may just be on my end, but attempting to access the page using www.blog.google does not work, but blog.google works. The link may need to be changed...

  > nslookup www.blog.google

  Non-authoritative answer:
  Name:       ghs-svc-https-sni.ghs-ssl.googlehosted.com
  Addresses:  2607:f8b0:4009:80b::2013
              172.217.8.179
  Aliases:    www.blog.google
  
  > nslookup blog.google
  
  Non-authoritative answer:
  Name:       blog.google
  Addresses:  2001:4860:4802:38::15
              2001:4860:4802:32::15
              2001:4860:4802:36::15
              2001:4860:4802:34::15
              216.239.32.21
              216.239.36.21
              216.239.38.21
              216.239.34.21
Post reply on HN