Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- What's wild is that when initially launched you could only register 3LD domains. If you were quick out the gate and registered one in 2002 and have been using 10 year renewals you're about to have a domain you've owned for almost a quarter century with 6 years left on its registration nuked.by baylisscg
- I am also one of the 22,000 people who have a third-level .name domain and I am livid about this, not least because Verisign flat-out lied in their proposal to ICANN: (https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2...) :
"2.1. What effect, if any, will the proposed service have on the life cycle of domain names? None. There will not be any effect on the life cycle of domain names.
...
2.3. Explain how the proposed service will affect the throughput, response time, consistency or coherence of responses to Internet servers or end systems. There will be no effect on the throughput, response time, consistency or coherence of responses to Internet servers or end systems."
My registrar is also suggesting that they are going to just keep the money I pre-paid for years of registration, which is a minor annoyance compared to the loss of my entire online identity but an annoyance nonetheless.
Since ICANN is a non-profit that is required to operate in the public interest I do hope there can be some pushback on this. I will be writing to the CA AG myself.
by anominal - @dang can you update the domain extraction logic for hn titles to include the 3rd level domain for .name domains? It's a little too poetically unfortunate that HN lists the domain on this article as `fraser.name`by NAR8789
- Sure. We have this for countries, like "example.co.uk", so I made "name" be a country and it...just works (maybe).
You only get a first name and a last name and a .name though. You can't be robert.louis.stevenson.name - just louis.stevenson.name.
(Incidentally, this was a Claude suggestion. The change only took a couple minutes but figuring out what mechanism in the code could do this would have taken me a lot longer.)
by dang - There's a DNS wizard at my job (not doing DNS stuff currently; but in his past life), and while he was talking to me about certain topics my eyes glazed over, and I thought, "Man, surely that won't affect me, right?"
Well, it's still not affecting me, personally, but wow, seeing articles like this makes it feel just a tiny bit more real.
by sigbottle - This points to a more general problem with some of the Internet infrastructure -- since real people don't actually own domain names, much less e-mail addresses (assuming they use e.g. @gmail.com), they're always at the mercy of a third party, which is normally tolerable except that with prevalence of user accounts at various Internet services, for any given person, tied to an e-mail that receives password reset instructions and what not, ultimately ownership of the service account is in the hands of whomever owns the e-mail. Although Google doesn't read your e-mail to order pizza on your behalf and bill, and even if your crypto-savvy brethren encrypt their communication to you, services you more or less depend on do _not_ send you e-mail that only _you_ can open -- regardless of the mail transfer or storage system (read: the e-mail is plaintext).
In light of this particular situation, I think a secret key shared between you and the service, at least, could guarantee that even in the event the e-mail address is stolen (or otherwise taken) from you, the service account remains in your hands.
I know I am not breaking new ground here, but I don't think the Internet is getting healthier for the human, it's at least going to get worse before it may get better. So maybe we need to adjust our assumptions and mitigate accordingly.
by hackrmn - We keep expecting for-profit organizations to behave as governments. And this is an especially easy sell in the US, where government has been vilified for decades as part of a long propaganda game run by those who wish to privatize and steal those things which should rightfully exist in the public domain. But for-profit organizations, by design, will never ever ever behave in the public interest, and it’s foolish to expect otherwise. This is not a criticism of the author; this is a criticism of ICANN, and the subcontracting of governance.
- Amen to this. I don't know why we put up with this for infrastructure in particular.by crabmusket
- We were rescued from that dot org scam by the fact that ICANN is a California non profit. I wonder if the AG can lean on them again. This is an outrageous thing to do.by arjie
- This is the comment I was looking for. Thank youby patcon
- > ICANN is a California non profit
I wonder how long that'll last. If the regulators in Califonrnia keep forcing them to act in the public's interest, won't they just move to a more favorable jurisdiction?
by donmcronald - MagicMoonlight was [dead]ed for not knowing what "dot org scam" refers to. Since I can't reply there right now and it's not reasonable to expect everyone to know what this refers to:
ICANN, a 501(c)(3), proposed to remove the price cap on .org registration, commonly used for non profits, so PIR, the 501(c)(3) registrar for .org, could then announce it planned to sell .org operations to private equity investment firm Ethos Capital.
Thankfully the overwhelming response caused the proposal to be scrapped.
by zamadatix - It kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.).
Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?
by akersten - Note that the posted link talks about .uk.co, which currently does not exist but I guess may have in the past. Where .co is the ccTLD of Colombia.
Different from .co.uk.
- Surprisingly the public suffix list doesn't list `*.name`. So they're indeed not properly isolated from each other.
edit: apparently not all second level domains in .name are public suffixes anymore, so a wildcard addition wouldn't be correct.
by CodesInChaos - > It kind of seems like an insane TLD structure to begin with, right?
It's been around for years. I seem to remember this issue coming up around 2001 where originally .name was for third level registration (i.e. john.doe.name) and changed to second level it a few years later and caused some problems... https://publicsuffix.org/ talks about it in light of architectural limitations of domain names.
> can Joe set a cookie on all of .smith.name?
That can happen. I seem to remember ancient browsers made it so .name (and other non-generic TLDs) required three periods. I think country code domains and new generic TLDS caused the browsers to change it.
It's pretty screwed up, but a lot of the people with .name domains have had them for a very long time. Sad to see them all lose their identity online that way.
by indymike - About 20 year ago I registered {lastname}.name and have dozens third level domains below it. So there are "privately owned" second level domains under .name for quite some time...by omnibrain
- Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.by orra
- So, this kind of thing happens all the time, and there's the Public Suffix List for exactly this problem.
There would be no issue at all if Verisign, or maybe Global Name Registry, decided to stick to the 3rd level registrations exclusively. Problem is, the chucklefucks over there decided it was a good idea to also hand out 2nd level registrations. Those 2nd level registrations outnumber the 3rd level registrations by an order of magnitude, so the PSL decided to just let joe.smith.name and john.smith.name share cookies. Which, IMO, was not a good decision, but it is what it is.
- Since neither smith.name nor the wildcard *.name appear in the Public Suffix List (https://publicsuffix.org/), browsers would likely allow any page on a *.smith.name domain to set cookies for .smith.name.
There was an effort to properly handle the .name 2LDs, but it was never resolved because there’s no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name: https://github.com/publicsuffix/list/issues/2306
So yes, this TLD’s setup is in fact pretty insane.
by nneonneo - .co.uk is run by the same people as .uk. There is no additional org that you trust when you register a .co.uk: https://en.wikipedia.org/wiki/.uk#Second-level_domains
> do browsers have a wildcard suffix list
Yes: https://publicsuffix.org/ and they have discussed this situation here: https://github.com/publicsuffix/list/issues/2306
by SahAssar - This risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices used were entirely disconnected from domain names, and why the discovery protocol I put together did not rely on registered domains, but could use these as an untrusted part of discovery.
Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.
I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.
I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.
by nanolith - Can you share how the discovery worked?by fh67
- It's the same reason I was nervous moving our company domain to a .ai TLD; your entire presence, identity and trust is now beholden to the whims and political winds of a Caribbean island smaller than Topeka.by sciyoshi
- "Online identity" seems like a castle built on quicksand in every single case.
What's your account tied to?
E-mail? That's usually on a mail server owned by someone else. If not, it's still on a domain owned by someone else.
Phone number? Definitely owned by someone else.
The only account that's reliably "yours" is one that asks for a login, a password, maybe a TOTP, and absolutely nothing else. Because everything else is introducing "things owned by a third party" into the equation.
by ACCount37 - I freaked out for a second because I've owned `dvt.name` for like 15 years. `.name` is not getting terminated, so it's important to be precise here. The third-level x.y.name (where you're the `x`) is getting terminated, and the respective `y.name` domains are going to be released.
Still a crappy thing for people, but it does not affect owned second-level domains.
by dvt - I don't get the difference. If I acquire the y domain and make it work as a subdomain broker, it's the same thing no?
There is no subdomain/TLD bit
by TZubiri - Yea. Super confused.
I have myname .name - so I thought that was going away. Granted I barely use it, but still it would be annoying. I didn't recall there were 3rd level domains there.
by ShakataGaNai - I understood by just looking at the title and after reading what is going on I am still concerned and not for some .name domains but I've .net and .com domains.
The main issue here is the way VeriSign and ICANN are operating. Unchecked, hostile, and without consequences (even the ombudsman okay the move). Someone might come along and say but you can always fight in the court - and that's the problem! Some company or entity claims one of those .net/.com domains I "use" and just gets us suspended and handed over, as someone not living in the USA I will literally be out of any option. This "then go to the court" is a very dangerous setting. We all know this but this squarely rigged to be in favour of the offenders with means and power.
by shelled - There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level.
But I didn't think about the 1st level competitors. There'd still need a mechanism to resolve that...
1. First come first serve? (e.g. whoever registered a y.name first, whether x is bob or sue is determined by the earliest registrant on record) 2. Lottery/random selection? 3. Bidding war?
I think the problem is 2nd level domains who have the same name will be a problem when they find out all these other 3rd level are now expiring and can run a route to spoof? Likely wouldn't happen, but with the fuckery in the DNS that can happen... This is such a rash and weird decision to push through so quickly just because engineers find it "easier" while ignoring the implications of the move, seemingly when it comes to larger scale security.
I assume there would have to be some method to prevent routing of third level domains to subdomains of two-levels... (or is that just me being a fool yet again, assuming we have competent administration of our systems).
by wormius