Live data from Hacker News

Government URLs that don't end in .gov

github.com

1–10 of 202 posts

Re: Government URLs that don't end in .gov

#7

We need a government root CA more than a government TLD. Domain names aren't even the only thing we should attest.

This sounds like a decent idea until you realize that means one of two options:

- A US Government controlled CA root preinstalled on computers. Privacy advocates would be in arms. - Constant untrusted CA warnings when trying to access any government site.

Re: Government URLs that don't end in .gov

#8

We need a government root CA more than a government TLD. Domain names aren't even the only thing we should attest.

GSA had that chance when they wrote the rules for all government services to use https. They didn’t even offer letsencrypt, much less build their own CA. The corporate CAs wanted their cut of more tax money.

Re: Government URLs that don't end in .gov

#10
I’ve always thought it was weird that the Canadian federal government uses canada.ca almost exclusively. You see a lot of

    https://service-service.canada.ca/sign-up-sinscrire.aspx
.ca is open for registration by anyone, and people are used to seeing that TLD. Combine that with the bilingual super long domain names and every once in a while you’ll see a phishing scam like:

    https://service-service-canada.ca/sign-up-sinscrire.aspx
CIRA could set up a .gov.ca second level or something if they really wanted to keep the .ca, but I don’t think that will happen at this point.

It’s at least consistant in looking like a phishing scam!

Post reply on HN