Rendered at 07:30:00 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
nneonneo 15 hours ago [-]
It seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3LD registered on top). It’s a bit insane that they can decide to just terminate all existing 3LD registrations. One would hope that they’d at least continue to reserve the 2LDs for some period to avoid domain squatting, but this isn’t mentioned in the proposal and I doubt Verisign would graciously do so.
p4bl0 12 hours ago [-]
Another thing that should be obvious and yet they refuse to do: when there is a single third-level customer for a given second-level, offer them a way to get the second level domain. I've been asking VeriSign this for 15+ years, they always said no, even if at some point they confirmed that there were no other third-level than mine under that second-level domain. They're insane and should not be in charge.
jaggederest 9 hours ago [-]
> They're insane and should not be in charge.
I remember back when we had to write mechanize scripts to drive a browser through the renewal process, because if you had dozens, hundreds, or thousands of domains there was no nonmanual way, especially if you wanted extended verification or something silly like that.
So what I'm saying is, agreed and that has always been true.
palemoonsinking 9 hours ago [-]
Why would they want to drop the possibility of selling some as premium domains? If they have their shells setup right they will probably be able to get a premium from some 3rd level domain owners wrongly afraid someone else is interested.
The main problem with the Internet today is that we didn't destroy ICANN when they started this TLD sell off crap. A replacement institution may have at least told Verisign a TLD they can't run transfer to someone who can meet its promises can only be destroyed.
p4bl0 2 hours ago [-]
The .name predates the TLD well-off crap. The first huge bulk of new TLDs happened in 2014, .name dates back from 2001. Also, .name filled an actual need for general non ccTLD: companies had .com, organizations had .org, Internet related stuff had .net, there was .gov, .edu, .mil, and ccTLDs, but nothing made for individuals. It filled this use case, it actually made sense.
abofh 7 hours ago [-]
Because it's not worth it financially. After icann is the tld registrar, and after that above. So, if anyone is destroying it, it's not the registrar, it's the tld.
gblargg 5 hours ago [-]
It seems insane because it seems like a big point was to have a permanent site for your name. This just devalues all domain names, showing that they can do a rug-pull at any time because they don't want to manage it (how about turn it over to a private company that can adjust costs so they can make a profit and keep it running?).
asdfsa32 1 hours ago [-]
This is why new gTLDs are insane and stupid. It is about time there is some _yours for life_ DNS system.
In this age, allowing domain names to be owned by other entities is almost like allowing a company business registration number or one's national id card number to be transferred to others.
I think name squatting is a problem, but it is not like that current system has solved it.
layer8 13 hours ago [-]
Maybe they want to avoid the ambiguity between john.doe.name versus john-doe.name, and I assume they prefer the latter scheme because it probably sells better. Nevertheless, discontinuing existing domains is disgraceful.
xp84 13 hours ago [-]
Even that doesn't pass basic scrutiny. The same ambiguity can and always will exist with tim-apple.com and tim.apple.com - there's nothing here that needs fixing.
dpoloncsak 13 hours ago [-]
I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real.
It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com
In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com
edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule
dbt00 13 hours ago [-]
That is definitely not true. There are literally thousands if not tens of thousands of well known domains that do this. .co.uk is a very common example.
ndiddy 12 hours ago [-]
.name is still a weird edge case because of the naming rules. Whether or not all subdomains under doe.name belong to the same person depends solely on whether the first person registered "doe.name" (in which case they do) or "john.doe.name" (in which case they don't, and "doe.name" is excluded from purchase as a standalone domain).
12 hours ago [-]
desas 13 hours ago [-]
I think the problem is that .co.uk, .gov.uk and so on are very well known in the UK.
The .name subdomain rules are not very well known anywhere.
necovek 2 hours ago [-]
How familiar are you with Serbian co.rs, org.rs, in.rs (individuals) and top-level .rs too? Will you confuse it with iz.rs giving free subdomains to individuals too ("iz" means from in Serbian)?
How about all the other 200+ country TLDs and rules for non-country TLDs?
dpoloncsak 12 hours ago [-]
The fact that multiple organizations need to keep a public list of known 3LDs proves it's the edge case, does it not?
"Here's a list of things that look like subdomains for you to treat as 3LDs instead of subdomains" sounds exactly like the solution to an edge case to me.
davkan 13 hours ago [-]
I can’t think of any prominent ones outside of country code domains.
bombcar 12 hours ago [-]
You can almost guess someone's age from that alone - they're more rare, but long domain names still appear that encode a city and a state, and you could just "grab" the first part when signing up.
davkan 12 hours ago [-]
Outside of the context of ccTLDs and city.state.gov etc, I struggle to think of examples 3LD+ domains where they are owned and operated by completely different concerns than the parent. If at some point you could just register your own mysite.state.gov domains willy nilly that's probably before my initial time online around 2000.
Another poster raised the point of hosting services which is valid. But at present outside of that example and the above I really can't think of an example where you have a link to entity.com and you have any significant cause to verify the identity beyond the 2LD.
All Indian banks use bankname.bank.in as their domain. I’m not sure who owns bank.in but this is a common suffix which is different from the .co.uk pattern.
strenholme 12 hours ago [-]
I remember I had beach.santa-cruz.ca.us at one point registered to me. I owned beach.santa-cruz.ca.us, someone else owned santa-cruz.ca.us, yet someone else owned ca.us, and I believe Network Solutions took care of .us at the time.
fc417fc802 11 hours ago [-]
You say "registered" to you as though this was via an official registrar but surely you mean that someone rented ca.us and decided on their own to lease out subdomains to people?
(Aside, I always see "owned" and "bought" but you can only ever "lease" under the ICANN system as the present situation so clearly demonstrates.)
brirec 11 hours ago [-]
Historically, xx.us (where xx is a two letter state code) domains have been owned* by the named US state, which then would issue subdomains on top. I believe this was originally planned and set up by ICANN themselves.
*: I realize that “owned” is a loaded word here, but (1) I’m referring to a registrar/issuer, which makes it yet more complicated as to how much “ownership” (de facto or otherwise) a given entity may have, and (2) I really don’t give a fuck about pedantic word choice if the meaning is unambiguous.
fc417fc802 10 hours ago [-]
My aside wasn't intended to be pedantic, rather observing the apparent inconsistency in how it appears people think about these matters versus what the present situation illustrates the reality to be.
> but (1) I’m referring to a registrar/issuer, which makes it yet more complicated
We're also talking about a ccTLD which makes it even more complicated. AFAIK those fall entirely under the jurisdiction of the respective UN recognized government although I don't know how strong that agreement is in practice (treaty versus something else).
So at that point I guess we've roughly got ICANN -> US federal government -> CA state government -> registrar -> private party -> sublet.
strenholme 10 hours ago [-]
The way it worked is that someone nominally representing the CA State Government had* ca.us, and they in turn gave* san-jose to someone who nominally represented San Jose, los-angeles to someone who nominally represented Los Angeles, santa-cruz to someone who nominally represented Santa Cruz, and so on. city-name.ca.us domains were still free (and charging for .com and .org domains was a new thing at the time); you would look in the zone file to see who owned* a given domain, email them with your nameserver names and IP, and they would add it to their zone.
This isn’t how things are done these days; names visible to the public are pretty much always in the form {domain}.{tld} or sometimes {name}.{domain}.{tld} (e.g. my own https://samboy.github.io). Registration is now done by bots and companies that spam you to death to try and get more money from you (the Internet wasn’t like that in the beach.santa-cruz.ca.us days). Domain names with multiple levels of delegation aren’t around they way they used to be.
* rented/leased/had control over/whatever
greyface- 10 hours ago [-]
> This isn’t how things are done these days
The old locality domains still exist, and in many localities you can still register them today by the same "email a request to some sysadmin" process. https://news.ycombinator.com/item?id=48122635
Your beach.santa-cruz.ca.us domain is still in DNS, just with a broken delegation chain. You could reclaim it right now by setting up a nameserver at reality.samiam.org.
strenholme 5 hours ago [-]
I’m amazed beach.santa-cruz.ca.us is still around. I’ve given it some SSL certs and have reclaimed it:
Thanks for checking the zone files of the parent domain to verify it’s still there.
ndom91 16 minutes ago [-]
Wait what haha. Do you also own samiam.org?
ketzu 12 hours ago [-]
Github Pages is probably the most well known one (on here).
I think geocities had this as well?
A lot of hosting services offer this in general. (eg render)
Tumblr? (Might not count as the control over the page is more limited. The subdomains "are" still tumblr.)
For reddits subdomains are redirects to subreddits of the same name, so I guess that doesn't count.
davkan 12 hours ago [-]
None of these examples are of actual separate registration/ownership of a 3LD from the parent 2LD. Cloudflare owns the domain for myproject.pages.dev and hosts all the relevant infra. Not to say that there isn't a different entity represented by the 3LD than the 2LD but it's not exactly the same.
Also I would not consider the examples of tumblr and reddit to be relevant. A person's blog on myprofile.tumblr.org is still the tumblr organization. This would be true for reddit even if they didn't redirect. Reddit admins moderate content on all subreddits.
ketzu 12 hours ago [-]
I see, that's a valid way to think of domain ownership.
When I read
> I have been taught and tell my users to check the domain to verify a website is real.
I was thinking more of control of the content as "ownership" of the domain.
davkan 12 hours ago [-]
The point on hosting providers is well taken. You do have to consider x.pages.dev as the wild west not cloudflare of course. One difference though is you will never receive an email from x.pages.dev asking you to do something. The domain ownership still does play a part.
megagpt1 12 hours ago [-]
You can buy example.it.com on many registrars. Someone bought it.com and operates it like a TLD.
davkan 12 hours ago [-]
Interesting. I do wonder how many people outside scammers and squatters buy them. I'd rather have an .xyz or .biz address personally.
esseph 4 hours ago [-]
This seems largely country dependent with some exceptions.
In the US, once upon a time, elementary/middle/highschools might be attached to something like schoolname.district.state.gov. But now, even my local area school now has a .com. It seems that older hierarchy style is falling out of fashion for smaller/shorter domains across public services, schools, government agencies, etc.
Now here it seems to be either a .com, .gov, .org, or a totally different and newer tld. Even .net has fallen out of fashion.
The writing was on the wall when Pennsylvania switched their license plates from www.state.pa.us to visitpa.com
12 hours ago [-]
Glide 9 hours ago [-]
Looking at the threads below, very few people are discussing technical things in dns terms like zone or nameserver.
Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with.
Then when you consider DNS is fundamental infrastructure and people build secure things on top of it, (ahem DNS challenges for certs), it's remarkable that anyone would want or desire edge cases.
strken 6 hours ago [-]
This doesn't seem like a problem if you exclusively support 3LDs and don't let anyone register 2LDs.
veltas 12 hours ago [-]
Yet that is a problem the owner of such a domain has freely entered into by buying that domain, it's their right to keep it despite this apparent problem, if they wish.
dpoloncsak 12 hours ago [-]
Understood, and .name isn't being used enough in business to worry about 'the effect it will have on my users'. Just pointing out that it doesn't work like the 'norm' (although I guess it's not quite as unique as I thought, either)
gapan 13 hours ago [-]
There are still exceptions to this like .co.uk and many others.
amiga386 12 hours ago [-]
Hello sysadmin. Good luck navigating the internet.
What you should know, and what your browser does know and automatically applies cookie policy and colouring your URL bar, is the Public Suffix List: https://en.wikipedia.org/wiki/Public_Suffix_List
It will let you know that, for example, one does not need to own .co.uk to own the subdomain foo.co.uk.
The public suffix list is a half assed bandaid over a fundamentally broken system.
dpoloncsak 12 hours ago [-]
I appreciate this, and yeah the government/education ones slipped my mind, but I stand by the fact that the reason a list needs to be kept in the first place is because this is the edge case and not the norm.
layer8 13 hours ago [-]
True, they can’t outright prevent the ambiguity, but much fewer people will go to the trouble of establishing such subdomains when the option isn’t directly offered by the registrar.
This is my theory because, a priori, 3LDs should be more profitable than 2LDs, because with 3LDs John Doe and Jane Doe don’t have to compete over doe.name, but instead can each separately purchase john.doe.name and jane.doe.name. Apparently, however, that’s not a benefit of 3LDs in practice, which leads me to conclude that john-doe.name and jane-doe.name just sell better.
QuantumNomad_ 12 hours ago [-]
Prior to reading the OP blog post, I had never looked into the particular rules that .name has.
To me, prior to knowing how it works, I would have assumed that either
a) john.doe.name would be a subdomain that someone who was just starting out had gotten for free supported by ads. Similar to having johndoe.freewebs.com back in the day. Not something most people would use for anything professional.
or,
b) doe.name was registered by one of the people in a family of Doe’s where every Doe is pretty closely related. For example, John of john.doe.name and Jane of jane.doe.name are husband and wife, or third cousins, or what have you. Most of the content, I would assume, is mostly about things that relate to the family. Like maybe one guy is doing a family genealogy project tracing the roots of this little cluster of Doe’s back in time and has made a site covering the findings from his research. And another one probably has some photo albums with pictures of like previous Thanksgivings and other family get togethers. In other words, nothing I would care about unless I was in their family or a very close friend of the family.
I would not have guessed that .name 3LDs worked the way that it did if I hadn’t read about it.
And on the other hand, if I saw just www.doe.name or johndoe.name, I would not make such assumptions. It would be not much different than seeing www.doe.com or johndoe.com respectively. I would just assume that .com was already taken and therefore they used .name, or that they happened to like the .name TLD because it emphasises that their site has their name as domain name.
toast0 12 hours ago [-]
> This is my theory because, a priori, 3LDs should be more profitable than 2LDs,
3LDs are less valuable. In a market of many different tlds, why register foo.bar.name when you could get foobar.name or foobar.something_else
layer8 11 hours ago [-]
Because your name is John Doe and not JohnDoe.
toast0 11 hours ago [-]
Your name is also not John.Doe.
Mr. Fraser registered neil.fraser.name in 2002, when 2nd level registration under .name was unavailable; fraser.com had been registered in 1996 and neilfraser.com in 2000; he may have been able to get .org or .net, their registration dates are later, but they may have been registered and there was a gap --- my personal domain shows a creation date of 2003, but I registered it much earlier and abandoned it, but got it back after it was registered and then abandoned by someone else.
.name added 2nd level registration in 2004 and it seems to be vastly preferred. .us added 2nd level registration in 2002 and it was vastly preferred to the locality based naming. People don't want to have to educate their contacts about "weird" domains, which includes having an "extra" dot in your hostname.
joemi 12 hours ago [-]
Was it even possible to register just a second level .name domain name? It sounds like it wasn't, so therefore no one would be using john-doe.name and there'd be no ambiguity.
p4bl0 12 hours ago [-]
Not at the very beginning, but then it became possible.
anttihaapala 12 hours ago [-]
Yes it has been. I have had a second level .name for 20 years.
WesolyKubeczek 12 hours ago [-]
It was, I have one.
brlewis 11 hours ago [-]
It's exceedingly charitable of you to try to infer a good reason for what they're proposing. I say "exceedingly" because in their proposal they had the opportunity to present a good reason, and they chose not to use that opportunity.
JumpCrisscross 10 hours ago [-]
> the right thing they should do
Can someone explain why a product "registered and paid for until 2040" can be unilaterally voided like this without compensation?
toast0 10 hours ago [-]
Especially when the marketing was saying [1]:
> As your .name can be registered for up to 10 years and ownership is renewable, your .name really can be yours for life.
It seemed like there was an offer of renewable registration at least for a life term.
That's the crazy part - they can take your money, prorated to some future-period but, upon cancellation, the remaining future period of YOUR money becomes THEIR immediate revenue recognition. Is it fraud or theft? To me, it has to be one or the other...
lazide 10 hours ago [-]
Because they haven’t been sued enough yet?
giancarlostoro 15 hours ago [-]
I'm surprised they don't just do that, and maybe even to go a little further, disallow renewals so you can phase people out and reclaim domains you can sell.
xp84 13 hours ago [-]
Whether disallowing renewals or terminating them tomorrow, there's still the same core problems, only the date of the offense changes: (1) seizing people's names that they've established, breaking innumerable things including email and server hostnames, and (2) the possible resale of the 2LD fraser.com to a third party who will be free to do malicious things like reading OP's email, redirecting his traffic, or extorting him, to sell continued access at any price demanded.
zamadatix 12 hours ago [-]
There's one less core problem: those who just bought/renewed their domain e.g. yesterday are fucked out of both their money and forced to migrate sooner than they could have reasonably planned for. People's who registrations expire and they are unable to renew is a very different level of unfairness and inconvenience.
In either case, the security concern should be directly addressed.
xp84 6 hours ago [-]
Well, I'm guessing that Verisign will throw people a bone in terms of refunds just to avoid getting repeatedly hit with justifiably spiteful lawsuits that (I hope) would be trivially easy for customers to win.
That will cost them very little in terms of cash, as I doubt that many people register that many years ahead, plus in terms of accounting, they won't have accrued that revenue anyway so it wouldn't even hurt their books. Not that a couple hundred K would even matter on the financial statements of a giant, money-printing corporation like that.
The reason why they wouldn't go the route of waiting for expiry is that at least a few have nearly a decade left, and clearly they really want these gone, not just reduced in number. By 2036 when they would finally get to that point, I doubt whatever's driving this concern would even matter.
kees99 10 hours ago [-]
Having a mix of both 2LD and 3LD registrations under the same TLD is a bit of a nightmare in terms of public-suffix list [0], which is kind of important thing when enrolling your domain for some services, cloudflare among them.
Yeah, that’s why RFC 9989 replaced use of PSL with a dns signifier.
wlonkly 7 hours ago [-]
(That's DMARC, to save others the trouble.)
The problem DMARC solves is different than the problem the PSL solves, though. DMARC prevents a 3LD from pretending to be a different 3LD on the same 2LD. But the PSL handles things like what it means to make a "cross-site request" or how to handle cookies.
I mean now I'm thinking if DMARC _could_ solve that... but I don't think it could, unless I'm missing some extension or rare use case.
altairprime 4 hours ago [-]
Yes, DMARC isn't solving the same problem — but DMARC is showing how the category of PSL problems can be solved with DNS. With HTTP/3 now fully expecting browsers to be able to benefit from transparent-upgrade record responses, i.e. `www IN HTTPS 1 . alpn="h3,h2"`, then it is possible for the style of solution shown by DMARC to be applied to other problems that PSL solves today.
CAA isn't a good fit as-is either, because the subdomain has top precedence over the parent domain — precisely the inverse relationship needed here. But having worked with the PSL for quite some time operationally and seeing the direction of trends away from it and towards structural DNS declarations rather than a centralized list, I think the 3LD-2LD-CRSF problem would be far better off solved with DNS than PSL.
Basically, just adding `co.uk. IN TLD subs=independent` as an SVCB record would fully deprecate the need for the PSL versus cross-site and other such ownership-changes-hands boundary problems with both A.co.uk being allowed cross-site with B.co.uk, and with co.uk being treated as equivalent to B.co.uk by password managers, cookie repositories, and so on. It would also benefit CAA by defining whether the boundary exists — if TLS is hosted by the provider, then any CAA records published by the subdomain should be disregarded; if the subdomains are fully independent, then any CAA records published by the parent should be disregarded — which simply isn't possible today without either referring to the PSL or implementing DMARC-style DNS solutions.
(I don't formally suggest that exact record as structured or written but it's sufficient a napkin sketch of what I mean by gesturing at that RFC to be considered.)
echelon 15 hours ago [-]
That would be so cool and would make these limited hot commodities.
.name was one of the very first expansions of gTLDs back in the very early 2000s. It's a shame that it's being shut down as it was spearheaded by the ICANN itself rather than some registrar / investor like Donuts, Inc.
I suppose this is impractical as someone has to run the registry and there are costs associated with that. But don't the domain fees cover it?
ajmurmann 14 hours ago [-]
From having worked in that space what feels another lifetime ago, I vaguely recall that you can just offload the registry work to a registry that would manage this together with a mountain of other TLDs.
AtNightWeCode 14 hours ago [-]
As I recall it. This was mostly a money scam that targeted private users with ads like "make sure to claim to your .name domain so no one else does it and use it to impersonate you". It was stupid from the beginning and never took off.
10 hours ago [-]
DrewADesign 10 hours ago [-]
In the tech industry of yore, corporations having tech ecosystem stewardship duties was a quaint necessary evil to placate the developer crowd so you could hire them. Today, c-suites consider that indulgent soft-hearted hippie nonsense utterly gauche.
jl6 11 hours ago [-]
I can only assume somebody was asleep on the job when this scheme was approved, because the outcome is in direct contradiction to ICANN’s mission statement:
> Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems.
Arbitrary termination of service is not stability.
Enabling name hijacking is not security.
The answer cannot be a rival name scheme based on decentralization or crypto or whatever. Those are never going to help normal non-wizard users. The answer has to be to make the regulators do their job.
TLDRisk 9 hours ago [-]
It's been through the Ombuds and a reconsideration request [1]. ICANN says:
> There will not be any effect on the life cycle of domain names. While the Requestor may disagree with Verisign’s response, the Requestor has not shown that ICANN relied upon false or inaccurate material information. The life cycle of a domain name begins when the domain is registered, then moves through various stages before ultimately coming to a close. Early termination of a domain registration does not impact the life cycle of the domain, as the domain can still go through the various stages of a standard life cycle. Moreover, as stated above, ICANN was aware that discontinuation of these registry services in the .NAME gTLD would result in the termination of approximately 22,000 third-level domain registrations and of email services/addresses.
I don't agree. If I have a domain registered for 10 years the expected life cycle is for deletion to occur 10 years from now, not 90 days from now. They've changed the life cycle by changing the agreed upon deletion date for the current registration term.
I could maybe see if they stop accepting renewals and delete the domains as they expire. It's not a good look, but at least people are getting what they've been promised.
> Early termination of a domain registration does not impact the life cycle of the domain, as the domain can still go through the various stages of a standard life cycle.
According to ICANN cutting the life cycle short doesn't have any effect on the life cycle?
ICANN corruption is at the level of FIFA corruption.
disillusioned 4 hours ago [-]
That's like saying murdering someone doesn't have any effect on their life cycle because the full cycle: birth, life, death, plays out. The timing, evidently, isn't a factor!
TZubiri 5 hours ago [-]
What language games are we playing?
hdjrudni 4 hours ago [-]
Life cycle. Y'know. Birth, life, death. It had that. If you die tomorrow, you still had a life cycle. Totally not impacted. All 3 things still present and accounted for.
bilkow 8 hours ago [-]
Let's pretend it's OK for them to just drop your domain, ignoring the stability and security issues that arise from that (and how ICANN should prevent that, in theory).
How about the fact that you paid for a service for 10 years and they decided to stop providing it midway? Will you at least get a refund? If not, that's surely illegal right?
ALLTaken 9 hours ago [-]
Sorry, I don't understand this rule, would someone kindly explain?
I own lastname.name and use it for email only like this: firstname@lastname.name
I always thought as owner of lastname.name, I'm the only one able to add subdomain.lastname.name. Is this wrong??
1) Can anyone "buy" scam.lastname.name without my authorization on .name??
2) Can anyone owning not.lastname.name then steal my emails going to: firstname@*.lastname.name or even firstname@lastname.name??
BUT: If someone ONLY bought not.lastname.name and doesn't own lastname.name, they'll get terminated. Would that be 'good' as it would stop 1) and 2) ??
I'm really concerned. My family is using first@lastname.name as the personal email, I'm hosting and paying for since many years.
judge2020 8 hours ago [-]
> I always thought as owner of lastname.name, I'm the only one able to add subdomain.lastname.name. Is this wrong??
TFA mentions that `.name` was unique in that it sold a good amount of third-level domain names directly from the registry.
9 hours ago [-]
dvt 14 hours ago [-]
I freaked out for a second because I've owned `dvt.name` for like 15 years. `.name` is not getting terminated, so it's important to be precise here. The third-level x.y.name (where you're the `x`) is getting terminated, and the respective `y.name` domains are going to be released.
Still a crappy thing for people, but it does not affect owned second-level domains.
wormius 13 hours ago [-]
There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level.
But I didn't think about the 1st level competitors. There'd still need a mechanism to resolve that...
1. First come first serve? (e.g. whoever registered a y.name first, whether x is bob or sue is determined by the earliest registrant on record)
2. Lottery/random selection?
3. Bidding war?
I think the problem is 2nd level domains who have the same name will be a problem when they find out all these other 3rd level are now expiring and can run a route to spoof? Likely wouldn't happen, but with the fuckery in the DNS that can happen... This is such a rash and weird decision to push through so quickly just because engineers find it "easier" while ignoring the implications of the move, seemingly when it comes to larger scale security.
I assume there would have to be some method to prevent routing of third level domains to subdomains of two-levels... (or is that just me being a fool yet again, assuming we have competent administration of our systems).
Nition 10 minutes ago [-]
fraser.name does not seem to be currently registered, so it seems they could automatically give him that name, and hence solve the problem entirely.
But I wonder if there might be some competing names on the third level? Like, he's neil.fraser.name, but what if there's also bob.fraser.name and they'd both very much like to keep their domains?
p4bl0 11 hours ago [-]
> There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level.
Yes. I've been asking VeriSign for this for years, and they always refused.
mulmen 12 hours ago [-]
Or just honor the deal. The only reason for doing this is Verisign’s bottom line.
13 hours ago [-]
ShakataGaNai 10 hours ago [-]
Yea. Super confused.
I have myname .name - so I thought that was going away. Granted I barely use it, but still it would be annoying. I didn't recall there were 3rd level domains there.
TZubiri 13 hours ago [-]
I don't get the difference. If I acquire the y domain and make it work as a subdomain broker, it's the same thing no?
There is no subdomain/TLD bit
dvt 13 hours ago [-]
You are technically correct, but Verisign billed buying an x subdomain as if the y domain was part of a stable infrastructure. Which it kind of was until they decided to pull the rug.
chuckadams 12 hours ago [-]
Presumably Verisign is the owner of the y domain and wouldn't dare sell it off to the highest bidder...
megagpt1 10 hours ago [-]
[dead]
TZubiri 5 hours ago [-]
Is there any resource you can point towards understanding this? I'm well versed on DNS itself, so it can be a technical document.
What I understand would be the following:
1- Verisign manages the TLD registry for .name (and others), which includes managing the authoritative DNS servers (as pointed to by the .name NS and A records on the root DNS servers),
2- as well as for updating the NS records of .name records it is authoritative at the request of registrars (like, say GoDaddy), which act on behalf of domain owners.
3- one or some of the domain owners, for example for fraser.name, acted as a registry themselves managing authoritative DNS servers for NS records of .fraser.name domains, these third level DNS servers being pointed to by the name. NS records.
4- Upon registration of a .name domain, verisign charged a fee, (in the case of .coms this is around 10$ currently I believe, not sure how much they charge), and ICANN charges a much lesser fee (like 20 cents).
5- Upon registration of a
.fraser.name domain, the fraser.name domain owner charged a fee, and they kept the totality of that fee (potentially paying a fee to ICANN, but definitely not to verisign.)
6- Verisign issues this request, requesting registrars of second level domains (domain.tld) like GoDaddy, to stop selling third level domains of this TLD (domain.2ld.tld).
This is my understanding of the situation, and in that case, verisign was not billing for the domain. This might (a bit cynically) provide a commercial motivation for the actions of verisign.
It's worth noting that this is not at all a weird or shady practice, multi-level domains are the very ethos of the domain system, it's built for that, I'm not saying any domain is obligated to do that on the basis that it can, but it's not some esoteric illegal activity, it's normal.
chuckadams 13 hours ago [-]
The Public Suffix List is the closest thing we have to the "subdomain/TLD bit", but afaik it doesn't include wildcards like `*.name`. It does influence TLS though (or possibly just browsers) in that a wildcard cert for an entire TLD or public suffix won't be honored, nor will a public CA issue such a cert.
Still, I'm not sure there's any easy technical fix for the .name debacle.
TZubiri 5 hours ago [-]
I'm aware of that, it's an ad-hoc out of band list maintained by Mozilla, not 'official' or recognized by any process like an RFC, but it does exist.
It's safe to ignore altogether, but it can come in handy as a starting domain block/allowlist.
>Still, I'm not sure there's any easy technical fix for the .name debacle.
I think that it's gonna be ok, the owner of the 2ld is still the owner, so they are free to allow the 3ld domain owners to continue "owning" their domains and updating them on the authoritative 2ld DNS. It's just that verisign is no longer sanctifying it by allow vendors of other 2ld to sell 3ld with the 2ld together.
This might explain the whole situation, many of us are interpreting that the domains are deleted, but in reality, they may more likely be prohibited from being represented as official .name domains in registrars .
mhink 13 hours ago [-]
From what it sounds like, unlike domains under other TLDs, when you purchase a domain under .name you always purchase specifically the three-segment domain.
i.e. I own john.doe.name, you own george.joe.name. Once this change goes through, only "doe.name" can be owned, so who gets it?
plorg 11 hours ago [-]
I own a .name domain that is an initialism for my wife and I, and Namecheap never gave me any problems adding a record for vpn.mwai.name, for example. In fact I never even realized you could register a 3LD, much less that this was the intended(?) behavior.
cowsup 10 hours ago [-]
The idea is:
* .name is open for everybody
* a company called "Global Name Registry" scooped up a BUNCH of common last names, including fraser.name
* Global Name Registry then sold access to neil.fraser.name for far cheaper than the fraser.name domain would cost on its own; someone else could also buy john.fraser.name or jane.fraser.name, so the single fraser.name domain that they owned could have dozens of customers associated to it. They worked with ICANN to allow each domain to have its own registered owner.
* The article in the OP bought neil.fraser.name and has used it for years
* Verisign bought Global Name Registry; later they realized, hey, we're sorta not making a lot of money on this idea, and we're spending a lot of time/resources maintaining these domains "for cheap" and chasing renewals, and not scooping up more customers. Let's just stop it and stop paying for fraser.name and the potentially hundreds of other domains we own.
* Neil Fraser, not the only Fraser in the world, is upset because he might lose the domain he's had forever
So one CAN buy the mwai.name domain, as you have, and continue using vpn.mwai.name just fine. It's just you can't "officially" start selling out these subdomains as a separate registrar entry.
plorg 6 hours ago [-]
Is this quite accurate? My reading was that Global Name Registry was the registrar for the .name TLD, with Verisign providing DNS and email forwarding services, but that for several years GNR would only grant registration to third-level domains, then would set up corresponding second-level domains and email forwarding.
I guess in practice it doesn't make much of a difference for me anymore, I registered mwai.name 20 years after they began allowing second-level registrations and more than 15 years after GNR was sold to Verisign. So presumably GNR's concept was long-abandoned by the time I made my registration (which was, to be truthful, mostly based on mwai.name being the cheapest domain with the initialism). I was more curious about the implications of having held a second-level domain, whether it could have caused trouble for me or for a different person who held a tertiary domain. But also my registrar at least doesn't seem to allow tertiary domain registration for .name.
Any any case, nothing in OP or any of its referenced sources suggest Verisign is giving up .name. rather they will stop accepting and serving tertiary registrations, so if Neil wants to keep his domain he or another beneficent Fraser will need to register the fraser.name domain and register the subdomains for neil, joe, jill, or whichever other fraser currently owns a tertiary domain. The same would be the case for anyone else who still held a tertiary domain. Perhaps Verisign or the registrars who work with them might be able to migrate the registrations of anyone with these domains, particularly in what I suspect are most cases where there is a single tertiary registration under a secondary domain. Perhaps offer fraser.name to Neil and he can add his own subdomains.
I was intending to replying to a different comment on the above thread, sorry if this made my previous reply a bit incoherent.
skarz 7 hours ago [-]
Thank you for the clarification. Not sure if it was the author's intent but they made it sound like .name will cease to exist.
LelouBil 7 hours ago [-]
You should post it as a top level comment, I finally understood the situation exactly here.
plorg 6 hours ago [-]
Cowsup is mostly correct, but GNR didn't snap up subdomains, they owned .name originally with the explicit intention of providing domains by name and initially did not accept second-level registrations. Verisign owns all of .name and will simply stop accepting or serving third-level registrations.
TZubiri 5 hours ago [-]
Oh, I get it, I guess the question is what will Verisign do with the surname.name domains. They could be auctioned individually or by bulk, and somebody could buy them. But in essence they are exercising their right as a 2ld holder (Global Name Registry) to stop providing service.
This is an ostensibly uncharacteristic move for verisign, but the customers that bought these 2ld did so from a non-verisign vendor, it is only after verisign bought the 2ld holder that they became the holders and are now proceeding to extinguishing them after embracing and extending.
Might be an anti-trust case. Like textbook clear-cut case. IANAL, this is not legal advice.
echoangle 42 minutes ago [-]
> This is an ostensibly uncharacteristic move for verisign, but the customers that bought these 2ld did so from a non-verisign vendor, it is only after verisign bought the 2ld holder that they became the holders and are now proceeding to extinguishing them after embracing and extending.
Why should I care as the customer? If I buy a for-life subscription plan and the company gets bought, can they just not honor it because it’s a different company now? Maybe they should check which promises they are buying when acquiring other companies.
nanolith 11 hours ago [-]
This risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices used were entirely disconnected from domain names, and why the discovery protocol I put together did not rely on registered domains, but could use these as an untrusted part of discovery.
Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.
I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.
I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.
sciyoshi 4 hours ago [-]
It's the same reason I was nervous moving our company domain to a .ai TLD; your entire presence, identity and trust is now beholden to the whims and political winds of a Caribbean island smaller than Topeka.
fh67 8 hours ago [-]
Can you share how the discovery worked?
ACCount37 6 hours ago [-]
"Online identity" seems like a castle built on quicksand in every single case.
What's your account tied to?
E-mail? That's usually on a mail server owned by someone else. If not, it's still on a domain owned by someone else.
Phone number? Definitely owned by someone else.
The only account that's reliably "yours" is one that asks for a login, a password, maybe a TOTP, and absolutely nothing else. Because everything else is introducing "things owned by a third party" into the equation.
akersten 15 hours ago [-]
It kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.).
Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?
I know about the public suffix list - I was wondering about the wildcard specifically. In the very issue you linked to, as of 2025, it seems this was still unresolved...:
> We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't.
xg15 13 hours ago [-]
Yeah, apparently they both (used to) offer unbounded registrations of 3LDs and unbounded registrations of 2LDs? So if I see j.doe.name, the only way to find out if "doe.name" is a public suffix or not, i.e. if I should (not) be able to set a cookie on it, would be to email the registrar?
So does that mean that in practice, .name domains were always treated by browsers like regular 2LDs, meaning the cookie and origin protection was always broken for those domains?
Doesn't sound like good news for the guy in the OP...
12 hours ago [-]
SahAssar 14 hours ago [-]
I'm just saying that they have discussed the situation. They seem to have no answer and for cookies and similar things the answer probably is "maybe don't run security critical web stuff in the third level under .name".
IIRC orgs like letsencrypt also use the PSL for rate limits, so there are probably more issues that are not browser-based.
eloisant 14 hours ago [-]
Yes, Japan does the same with .co.jp but also .ne.jp, ac.jp, etc.
adw 14 hours ago [-]
There are many examples; k12.<state>.us is another.
marcosdumay 14 hours ago [-]
It is (or was for a long time, IDK) a strongly recommended practice from ICANN. I imagine nearly all countries to do that.
dhosek 13 hours ago [-]
There end up being some weird edge cases where there are some countries which have both the equivalent of .co.uk but also allow registrations directly under the two-letter country code as well. .mx is one such case where most business are, e.g., costco.com.mx, but it’s also possible to register directly under .mx as well so Toyota Mexico is toyota.mx and not toyota.com.mx (the latter is registered, and ostensibly to Toyota, but the whois and nslookup records give very different results and the website doesn’t load when I try to visit it).
dgoldstein0 10 hours ago [-]
This isn't so bad as .com.mx and .mx should be on the public suffix list then.
But letting arbitrary customers take arbitrary 3 level domains, and others take 2 level domains, seems like a mistake as it's not very reasonable for every 3LD customer to put the 2LD on the public suffix list, but mixing 3LD and 2LD registrations means you can't public suffix *.name.
Seems the whole idea of having both was always misguided.
justincormack 12 hours ago [-]
uk is one example - they opened up x.uk later, and gave x.co.uk registrations first dibs.
eloisant 13 hours ago [-]
Except nobody uses the .us tld, but pretty much every every Japanese company is on a .co.jp
SenHeng 9 hours ago [-]
It used to be that only Japanese corporations could register a .co.jp while anyone else anywhere could register for a .jp. So I had several .jp domains registered through Gandi.net.
The issue is that .jp registered outside of a few Japanese registrars are legally not allowed to offer Whois privacy.
adw 10 hours ago [-]
Schools use it!
toast0 10 hours ago [-]
Based on my small sample of schools, all of the ones that were using locality based names under ca.us have migrated elsewhere, including to 2nd level domains under .us.
ButlerianJihad 8 hours ago [-]
The .us domain should’ve been universally useful for state and municipal governments, but most of those began registering directly under .gov, and not even in an orderly hierarchy under .st.gov
But that was simply the easiest way to market your website as a trusted government entity. And now nobody has ever heard of .us domains in active use.
ocdtrekkie 5 hours ago [-]
.us was primarily a hierarchy structure which in practice made confusing and hard to remember domain names, whereas .gov addresses hand out single domains which are generally easy to remember.
ButlerianJihad 2 hours ago [-]
Personally, I never saw anything confusing about city.state.us; the hierarchy was organized perfectly logically in the 3-tier jurisdictional structure that every American schoolboy knows by 3rd grade.
But your point about them being rather longer and difficult to remember stands, and the same for a .gov, which could be shorter and catchier.
However amusingly, .us opened up second-level registrations 24 years ago, which means that any qualifying entity could have their name registered directly under .us, which is obviously recognizable, and also one character shorter, than a .gov registration. However, by that time, I believe that .gov had increased in stature so that registering governmental entities under .gov carried more certainty of conveying official status than anything under .us.
Also sadly, QR Codes and URL shorteners today sort of obviate the need to directly register the shortest possible domain name. I don't know: I was always kind of fond of the .us hierarchy, and I'm just personally sad that it's fading away.
flomo 55 minutes ago [-]
> city.state.us
In reality, it wasn't that simple, and a lot of those .us domains looked like line noise.
Government sites are used to distribute public information. They need something they can print on a poster/sign. Not some bogus 'logical' hierarchy.
ocdtrekkie 2 hours ago [-]
City/state/US is logical, the problem is most other hierarchies confuse people. For instance k12 subdomains for schools couldn't use that nomenclature because school districts do not map cleanly to towns. And that's before you talk about fire departments, townships, libraries, park districts, and countless other governmental bodies and districts which have overlapping boundaries of their own.
.gov certainly cares a level of exclusionary access that isn't really true of .us. Only one entity, the US federal government, can decide to hand someone a .gov address. And generally there is few signals harder to fake or impersonate than one.
jomar 9 hours ago [-]
> Except nobody uses the .us tld
This is a bug, not a feature.
joquarky 6 hours ago [-]
Sure, it is right now. What if they decide to sell it off?
nneonneo 15 hours ago [-]
Since neither smith.name nor the wildcard *.name appear in the Public Suffix List (https://publicsuffix.org/), browsers would likely allow any page on a *.smith.name domain to set cookies for .smith.name.
There was an effort to properly handle the .name 2LDs, but it was never resolved because there’s no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name: https://github.com/publicsuffix/list/issues/2306
So yes, this TLD’s setup is in fact pretty insane.
rwmj 14 hours ago [-]
I think this says more about how the cookies security model is stupid. They should always have been scoped to the single, exact name they were set from and nothing else. Websites would have had to be designed a bit more thoughtfully.
xp84 13 hours ago [-]
It seems like it would be easily resolvable with TXT records these days. Anyone could try, say, on www.google.com to set a cookie for all of google.com, and the browser can fetch TXT records on google.com to see what, if any subdomains, it wants to allow this privilege for. Google could return a list or a wildcard; co.uk wouldn't allow any.
In a world without advertising, there's no reason why google.com couldn't also allow *.youtube.com to set cookies for it, but of course that would cause a tremendous privacy freakout. Though in practice they can and do just send every login/logout through a 302 redirect roundtrip to take care of the cookies on youtube.com.
dgoldstein0 10 hours ago [-]
Totally agree that a DNS based replacement to the suffix list would make sense. Especially with more secure forms of DNS like DoH or Dnssec.
That said I don't know about making cookies shareable across TLDs. That seems like allowing more privacy nightmares; at least today if you want to share you need complicated redirect dances that make you question if the user perf hit is worth it. I think there was some proposal for a mechanism for allowing non partitioned 3rd party cookies which seemed more sane to me, forget what the details were and if it ever made it beyond just a proposal.
megagpt1 10 hours ago [-]
[dead]
megagpt1 10 hours ago [-]
[dead]
lxgr 14 hours ago [-]
It’s not nearly just cookies, and I think interpreting domain hierarchies as administrative structure generally does make sense.
Maybe it could be opt-in or opt-out via some markers at the DNS level, though? The public suffix list having to exist at all is bizarre.
amluto 14 hours ago [-]
An “administrative structure” seems fine, but the fact that a subdomain gets any sort of privilege over the parent has always seemed absurd to me.
Surely a better solution would involve an actual request. login.foo.com could send a request to foo.com with Origin: login.foo.com asking to set a cookie, and foo.com could make its own decision.
toast0 11 hours ago [-]
That might be reasonable today, but it's not really reasonable at the time the policies were formed.
If you require domain wide cookies be set from a webserver on the domain apex, the domain apex (for high volume destinations) needs to be set up for high volume webserving. High volume webserving often means at least geotargetted DNS, maybe a CDN, often anycast in today's reality.
Back in the day, it was common for high traffic domains to run their DNS with a normal DNS server and then delegate (typically via CNAME) high volume subdomains off to a 3rd party DNS server for geotargetting (usually Akamai DNS, but there were others). But you can't CNAME the apex domain away. You'd have to delegate the whole domain to your DNS provider and then you have no way to manage an outage of your fancy DNS provider. Especially if you go back to the days where NetworkSolutions did a single daily zone update for .com ... if you wanted to switch to a new DNS provider for your domain, you would submit the change request and hope it happened in the 24 hours, but sometimes you'd miss the window (or there would be some process error) and it would happen much later.
Less of a problem in today's world, where registries typically update the glue records in near real time (although many TLD servers have a 2 day TTL for glue, so you can't switch off a dead provider very quickly) and lots of domains seem comfortable with delegating the whole thing to their CDN.
markhahn 14 hours ago [-]
that seems strange to me: why shouldn't policy leverage name resolution? sort of like dkim, but taken further. for instance, for site.com, I'd much rather retrieve its public key from DNS (some DNS++ version, of course).
dgoldstein0 10 hours ago [-]
There are use cases for cookies to affect multiple domains, like shared logins. Keep in mind multiple domains let's you run completely independent servers for different parts of your web presence but that doesn't mean that you want them to act independently.
That said the dumbest thing with cookies is not sending their attributes in the cookie header which makes it impossible to distinguish expected cookies from tampered cookies set by insecure subdomains. __Host prefix is basically a workaround for this but took more than a decade to get into browsers. Samesite similarly was bolted on after the fact.
Cookies aren't the only web security feature that follow sites instead of origins but they are the only one that was clearly designed without thinking through the consequences.
quotemstr 14 hours ago [-]
> no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name
And that's one reason why the public-ness of a hierarchy level belongs on a DNS record on that level and not some separately-distributed side list.
markhahn 14 hours ago [-]
I'm always mystified why we haven't leveraged DNS.
I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP.
Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...
tptacek 4 hours ago [-]
No, we wouldn't, you're right. We'd just replace LetsEncrypt and the ISRG with the security track records and policy integrity of the major DNS providers, many of which are state-controlled, and the largest of which are too important to revoke.
Really hard to understand why that hasn't happened yet!
ambigious7777 10 hours ago [-]
You're talking about DAME (which email uses). It has it's own issues like not having transparency logs, and if a DNSSEC signing keyholder goes rogue, there is no easy way to revoke trust (unlike CRLs for Web PKI).
OkayPhysicist 14 hours ago [-]
So, this kind of thing happens all the time, and there's the Public Suffix List for exactly this problem.
There would be no issue at all if Verisign, or maybe Global Name Registry, decided to stick to the 3rd level registrations exclusively. Problem is, the chucklefucks over there decided it was a good idea to also hand out 2nd level registrations. Those 2nd level registrations outnumber the 3rd level registrations by an order of magnitude, so the PSL decided to just let joe.smith.name and john.smith.name share cookies. Which, IMO, was not a good decision, but it is what it is.
orra 15 hours ago [-]
Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.
traceroute66 14 hours ago [-]
> Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.
Yup. The original statement was dangerous FUD which should be urgently corrected.
11 hours ago [-]
BHSPitMonkey 13 hours ago [-]
Yes, but you have to admit that the existence of these SLDs (like co.uk) is always going to be a point of confusion for anyone with a basic knowledge of how the domain hierarchy _usually_ works.
Needing to be familiar with all the special cases (like the VERY special case of x.y.name which I previously knew nothing about) kind of ruins everything and introduces yet more security risk.
traceroute66 13 hours ago [-]
> but you have to admit that the existence of these SLDs (like co.uk)
I'm sorry, what ? Admit ? Confusion ?
In the case of .co.uk it has been around since 1996. HN is a technical forum, most people here should be well aware it is a serious SLD. I honestly can't believe it even needs clarifying.
Hell, if you use AWS Route 53 you'll see they use co.uk as one of their nameserver suffixes[1].
> It kind of seems like an insane TLD structure to begin with, right?
It's been around for years. I seem to remember this issue coming up around 2001 where originally .name was for third level registration (i.e. john.doe.name) and changed to second level it a few years later and caused some problems... https://publicsuffix.org/ talks about it in light of architectural limitations of domain names.
> can Joe set a cookie on all of .smith.name?
That can happen. I seem to remember ancient browsers made it so .name (and other non-generic TLDs) required three periods. I think country code domains and new generic TLDS caused the browsers to change it.
It's pretty screwed up, but a lot of the people with .name domains have had them for a very long time. Sad to see them all lose their identity online that way.
omnibrain 15 hours ago [-]
About 20 year ago I registered {lastname}.name and have dozens third level domains below it. So there are "privately owned" second level domains under .name for quite some time...
Pxtl 14 hours ago [-]
I'm working on same for my family since I want to properly degoogle a bit. One thing I think long term - if I give my kids first-name @ last name , that means that I forever hold power over their email. Which isn't great. But what's the alternative? Register one full domain name per kid? Even ignoring the cost, the ergonomics are awful.
Imho email is missing a feature for nameless email addresses for when somebody just buys their full name as a domain name. If I get "firstname-lastname.name", having the email be "firstname@firstname-lastname.name' kinda ruins it.
londons_explore 14 hours ago [-]
A child born today sees email like we see the telegraph...
they'll grumpily sign up to gmail just so they can get a verification email, and that'll be all it gets used for. Messaging their irl friends will be done in apps like Discord.
peezd 13 hours ago [-]
Truth.
lol I ran a sizeable team around 2020 and I had to educate a couple of our new hires straight from college that they actually needed to check their work email, after they missed important HR related stuff and they had just completely not realized it was an avenue for company communication, with an assumption that everything was available on our heavily used slack.
xp84 13 hours ago [-]
tbh I'm with the zoomers on this one. Work email is 99% junk. Newsletters from every SaaS product we use, "A meeting started", invitations for calendar events that I can just accept ON the calendar, notifications for every transaction on every system ("X posted a comment on Y,") and spam from salespeople, recruiters, etc. And then 1% of it is actionable important stuff that I don't get through Slack.
londons_explore 13 hours ago [-]
Email died because of the junk/spam issue. And it's self-fulfilling - when most emails are junk, nobody sends a love-letter or party invitation by email because the recipient probably won't notice it, which in turn lowers the usefulness even further.
If email was a commercial product, the company would have done something about that. Email died because it was an open platform, with nobody to address this systematic issue.
megagpt2 10 hours ago [-]
[dead]
skinfaxi 14 hours ago [-]
From what I can tell most people do something like me@myname.whatever or hi@domain.
14 hours ago [-]
kennywinker 14 hours ago [-]
Not to mention some of those kids may end up changing their names at some point if they get married and decide to take their partner’s last name.
Pxtl 13 hours ago [-]
Aside: I'm honestly bewildered that Google doesn't have the ability to handle that in gmail accounts. If somebody gets married or otherwise needs to change their name, their answer is "just make a new google account" when all your stuff is still tied to the old account.
avarun 12 hours ago [-]
They rolled this out in March this year in the US (and December last year in India).
I've successfully renamed an old account with an email address I no longer liked. It works quite well on everything 1st party, but does have the potential of causing issues with OAuth on poorly-coded websites that key on email instead of user ID (ie. most of them). You do get to keep your old email address though, so it still ends up working fine in practice.
Pxtl 11 hours ago [-]
Holy crap really? Yay! I know a couple of trans folks that will be ecstatic.
ocdtrekkie 5 hours ago [-]
The feature is about fifteen years too late for me, unfortunately. By this point I need this feature to let me "merge Google accounts". But then I barely use Google anything anymore anyways.
megagpt2 10 hours ago [-]
[dead]
CodesInChaos 15 hours ago [-]
Surprisingly the public suffix list doesn't list `*.name`. So they're indeed not properly isolated from each other.
edit: apparently not all second level domains in .name are public suffixes anymore, so a wildcard addition wouldn't be correct.
gpvos 14 hours ago [-]
It wouldn't surprise me if that is (maybe even a large) part of the reason for this change.
xp84 13 hours ago [-]
What does Verisign care though? It's been that way for way over a decade since they started allowing 2LD registrations. I very highly doubt they are suddenly so worried about random individuals' personal internet security.
It has to be a money problem. Something they want to do will be simpler if this is no longer a quirky registry. And they know they'll get the money back that they lose from not having bob.smith pay -- probably by throwing all the "last names" once registered this way into some "premium name" bucket and selling them for $1000 and up instead of the ~$10 that zyzgdhaf234.name fetches.
In fact, I'm not sure that scheme isn't the reason itself.
QuantumNomad_ 15 hours ago [-]
Note that the posted link talks about .uk.co, which currently does not exist but I guess may have in the past. Where .co is the ccTLD of Colombia.
Different from .co.uk.
kevin_thibedeau 13 hours ago [-]
Originally there was uk.co.orgname.
cpach 11 hours ago [-]
Huh? I don’t follow.
QuantumNomad_ 11 hours ago [-]
They might be referring to this kind of thing:
> The first appearance of reversed DNS strings predated the Internet domain name standards. The UK Joint Academic Networking Team (JANET) used this order in its Name Registration Scheme, before the Internet domain name standard was established. For example, the name `uk.ac.bris.pys.as` was interpreted as a host named `as` within the UK (top level domain .uk)
But I don’t know if uk.co.somethingsomething did or did not exist at that time. Or if it was only introduced after the Internet domain name standards we use today existed and so was .co.uk from the beginning.
zvr 10 hours ago [-]
Oh, uk.co definitely existed for companies. The other 2nd-level domain (besides the academic uk.ac and uk.co) was uk.mod (Ministry of Defence), equivalent to the US .mil. And then, because life is never this simple, things appeared that were neither universities nor companies nor military, so uk.bl was given to the British Library. There might have been others as well, I don't remember.
Back then the code in various pieces of software had hand-written exceptions for domain processing. The joke was that all Computer Science departments in the UK (uk.ac.university-name.cs) ended up in Czechoslovakia.
zahllos 12 hours ago [-]
In the UK Nominet (the UK domain namr registrar - nic.uk) only permitted 3rd domains - co.uk. org.uk, me.uk. then there were "prove your status" ones such as ltd.uk, plc.uk and ac.uk plus ones like gov.uk, mod.uk, sch.uk, nhs.uk etc.
.uk was opened up relatively recently.
eterm 12 hours ago [-]
I own a .uk and it still feels weird not having something in-between.
dolmen 14 hours ago [-]
.uk.co (mentioned in the blog) isn't .co.uk
pushcx 15 hours ago [-]
It wasn't obviously wrong in 2001. .pro started with a similar structure around the same time.
Ekaros 13 hours ago [-]
To me that sounds like reasonable structure. I hold that every single edu, gow and mil domains should be moved under respective ccTLDs. After this sort of move that doesn't seem unreasonable thing.
Pxtl 14 hours ago [-]
Agree that the .name 3rd level domains are silly, disagree on .co.uk being a problem.
If .gov and .mil and .com make sense, then .gov.cc and .mil.cc and .com.cc make sense.
Of course, I think having more than one non-cc TLD was a mistake, but that's just me. If it makes sense to have topical TLDs for international and US institutions, it make sense to have national ones.
gpvos 14 hours ago [-]
The 3rd level .name domains are the original ones. They didn't hand out 2nd level domains until three years after they started.
traceroute66 14 hours ago [-]
> disagree on .co.uk being a problem
Nominet and therefore .co.uk has been around since 1996.
.co.uk is not going anywhere, and neither is Nominet.
The only "problem" is the original poster did not do their homework. I suspect they were inferring `uk.co` which is a completely different kettle of fish. The original poster should urgently correct their post.
megagpt1 10 hours ago [-]
[dead]
traceroute66 14 hours ago [-]
[flagged]
akersten 13 hours ago [-]
Ok, co.uk was perhaps a bad example, because it's owned by the same registry as the TLD, but perhaps there are other 2nd level TLDs where that is not the case. My point is both that it's hard to tell, and more broadly why would anyone want their domain to be tacked on to some 3rd level subscript anyway, when there's so many plain top level domains available. Surely most of us (present company excluded perhaps) do not feel so passionately about the reverence of `co.uk`
I don't have some nefarious desire to scare people away from the TLD of their choosing. Really I'm bringing it up to be like "why would you even, like, want some 3rd rate domain instead of getting a .com" so I don't think there's anything to correct
digitalPhonix 12 hours ago [-]
> so passionately about the reverence of `co.uk`
It's not reverence? I think that you're missing that it was a requirement. Basically every country (that followed ICANN's original rules) does this: .com.au, .co.nz, .co.jp, .com.mx, .co.ke (+ the org/net variants for each country)
The US is the only country where registering .com was allowed by ICANN (and not .com.us or something).
ICANN relaxed these rules in the 2010s I think, so now you can register 2LDs at most/all of those country TLDs.
drdexebtjl 13 hours ago [-]
Sovereignty? If you live in the UK, choosing a registry in the UK is a pretty good idea even if they only offered 3rd levels. You’ll have someone to contact and possibly sue locally. Your domain will be subject to UK law and standards, not those of a foreign registry.
traceroute66 13 hours ago [-]
> My point is both that it's hard to tell,
Its not hard to tell for things like ".uk" or other serious suffixes.
It only (maybe) becomes hard(er) to tell for all the vanity ccTLDs that came along in the 2000s. But even then 10 seconds on WHOIS and Google should fix any doubt.
> about the reverence of `co.uk`
What are you on about ? Lots of other countries do it too. Japan is one example given already here, but there are dozens. It is very common practice for country tlds.
stronglikedan 14 hours ago [-]
geez, dude, someone woke up on the wrong side of the bed this morning...
traceroute66 14 hours ago [-]
> geez, dude, someone woke up on the wrong side of the bed this morning...
5 seconds on wikipedia or google would have stopped them spreading completely dangerous FUD about .co.uk.
yreg 14 hours ago [-]
What's so dangerous about it?
traceroute66 14 hours ago [-]
> What's so dangerous about it?
Implying lack of trust in `co.uk`
Implying `co.uk` may suffer the same fate at `.name`
Complete FUD.
necovek 39 minutes ago [-]
Actually, the fact that you have to cite official registrar docs is exactly the problem. There are 200+ country TLDs, and by now probably thousands of other self-governed TLDs like .name.
For instance, in Serbia, there is a similar scheme to UK: .gov.rs, .co.rs, edu.rs, but also in.rs (for individuals) and top-level .rs. So someone has registered "iz.rs" and offers free subdomains to individuals.
The fact that there is implied hierarchical trust is what the problem is, and keeping track of individual rules for each TLD is prone to errors.
gertrunde 13 hours ago [-]
You're absolutely right, when it's Nominet's actions that actually inspire a lack of trust in .co.uk, given they've been a bit of a hot mess since the early 2010's-ish.
;)
(Edit: although I should add that I'm hopeful that things have improved there over the last few years).
traceroute66 13 hours ago [-]
> given they've been a bit of a hot mess since the early 2010's-ish
No.
Oversimplified summary:
There was a period around 2010 when the management at the time wanted to follow a more commercial route with various unrelated "investments".
Nominet members made it impeccably clear in a very loud manner to management that it would not be tolerated.
Management insisted on a vote which they inevitably lost.
Management departed.
TL;DR Don't piss off Nominet members
dokyun 14 hours ago [-]
[flagged]
arjie 15 hours ago [-]
We were rescued from that dot org scam by the fact that ICANN is a California non profit. I wonder if the AG can lean on them again. This is an outrageous thing to do.
zamadatix 11 hours ago [-]
MagicMoonlight was [dead]ed for not knowing what "dot org scam" refers to. Since I can't reply there right now and it's not reasonable to expect everyone to know what this refers to:
ICANN, a 501(c)(3), proposed to remove the price cap on .org registration, commonly used for non profits, so PIR, the 501(c)(3) registrar for .org, could then announce it planned to sell .org operations to private equity investment firm Ethos Capital.
Thankfully the overwhelming response caused the proposal to be scrapped.
NewJazz 11 hours ago [-]
MM looks to be shadowbanned, I don't think anyone downed/flagged their comment.
Ah, good catch! I suppose I should check the comment history page before assuming why :)
donmcronald 11 hours ago [-]
> ICANN is a California non profit
I wonder how long that'll last. If the regulators in Califonrnia keep forcing them to act in the public's interest, won't they just move to a more favorable jurisdiction?
NewJazz 11 hours ago [-]
This crossed my mind too. At least such a move could serve as an indication to the international community that ICANN is not a good steward of name and number resources. If they're paying attention. I know our (the US) governance is full of crap like this.
patcon 12 hours ago [-]
This is the comment I was looking for. Thank you
MagicMoonlight 12 hours ago [-]
[dead]
projectileboy 9 hours ago [-]
We keep expecting for-profit organizations to behave as governments. And this is an especially easy sell in the US, where government has been vilified for decades as part of a long propaganda game run by those who wish to privatize and steal those things which should rightfully exist in the public domain. But for-profit organizations, by design, will never ever ever behave in the public interest, and it’s foolish to expect otherwise. This is not a criticism of the author; this is a criticism of ICANN, and the subcontracting of governance.
crabmusket 4 hours ago [-]
Amen to this. I don't know why we put up with this for infrastructure in particular.
NAR8789 5 hours ago [-]
@dang can you update the domain extraction logic for hn titles to include the 3rd level domain for .name domains? It's a little too poetically unfortunate that HN lists the domain on this article as `fraser.name`
dang 3 hours ago [-]
Sure. We have this for countries, like "example.co.uk", so I made "name" be a country and it...just works (maybe).
You only get a first name and a last name and a .name though. You can't be robert.louis.stevenson.name - just louis.stevenson.name.
(Incidentally, this was a Claude suggestion. The change only took a couple minutes but figuring out what mechanism in the code could do this would have taken me a lot longer.)
epaga 2 hours ago [-]
While we have you here - I've seen this discussion multiple times - does @dang "do" anything to get your attention, or did you just happen to see it because you were scanning the comments manually, and therefore email is better for letting you know something?
dang 1 hours ago [-]
We don't monitor @dang. We only monitor emails. Someone emailed me in this case.
sigbottle 14 hours ago [-]
There's a DNS wizard at my job (not doing DNS stuff currently; but in his past life), and while he was talking to me about certain topics my eyes glazed over, and I thought, "Man, surely that won't affect me, right?"
Well, it's still not affecting me, personally, but wow, seeing articles like this makes it feel just a tiny bit more real.
aliasxneo 14 hours ago [-]
This is why I am building DNTLS. These organizations no longer deserve our trust and they have inadvertently gained too much power over the last two decades of massive internet expansion. Names need to be fully owned by individuals and a shared, decentralized trust system must be in place for resolution. The more I see actions like this, the more convinced I am that a solution is long overdue.
theK 14 hours ago [-]
Never heard of DNTLS, thanks for sharing. I skimmed the Website and am a bit uncertain what the ai angle is. Shouldnt naming be, well, just naming?
aliasxneo 14 hours ago [-]
Yeah, the website is a holdover from when we were pitching AI VCs a few months ago. We quickly determined that the whole system is now "Cancer Capital" (see the other front page HN thread) and have pivoted to just bootstrapping from a close syndicate of like minded individuals. We plan to update the website this month, sorry it's a bit behind.
In short, AI identities were just a happy accident that comes with the system/architecture. It's not tied to AI at all.
But if anyone is interested in talking about what we're doing more, happy to connect at hn@sepositus.com.
xur17 13 hours ago [-]
Do you have a brief explanation of what DNTLS is that you could post here?
aliasxneo 13 hours ago [-]
Sure, happy to put something here as a comment.
Alice registers `alice.dntls` and Bob registers `bob.dntls` on the DNTLS network. During the registration process, they generate PQ key pairs that are registered along with the name. Alice's and Bob's name are hashed before being stored on the network. Bob knows Alice's name, so he can perform the necessary hash computation to look up Alice's public key material on the network. Likewise, Alice can do the same for Bob.
Bob wants to send a file to Alice. Bob takes his name key and signs the document with it and sends it to Alice. Alice looks up Bob's public key material on the network and verifies the signature.
Bob now stands up a new website, but he only wants Alice to access it. He sets up a standard HTTP server but slightly modifies it to be "DNTLS native." He does this by requiring mTLS on incoming TLS connections. The connecting party must identify themselves with a signed certificate. Each name has what we call a "name record" that allows publishing arbitrary metadata signed by the name key. Bob publishes a standard "HTTP" record in his own name record that points to the IP address. Alice now goes to connect to Bob's website. She opens her "special" browser and types in bob's name. The special browser looks up Bob's name record, finds the published IP address, and attempts an mTLS connection. Bob's server is configured to _only_ allow connections from Alice. Since Alice signed her TLS connection with her own name, the connection is allowed, while every other is rejected.
Alice now wants to communicate with Bob's agent. Bob publishes a subname called `agent.bob.dntls`. In that subname's record he publishes an A2A packet that contains the information for connecting to his agent. But, like the website, the agent is listening on a TLS connection that rejects anyone except Alice. She uses an A2A tool to initiate a connection using her name key and is allowed to make a mutually secured connection to Bob's agent.
Bob wants to connect to a VM he purchased that runs the website. He configures SSH with his name key as one of the recognized users. His SSH connection simply leverages the name key to authenticate him to the machine. But he shares the machine with another person and wants to share a secret with them. So he creates a SOPS encrypted file with his name and this other person's names as the only recipients. They both securely access the secret using their respective name keys.
I'll leave it there, but hopefully that's descriptive enough.
zamadatix 11 hours ago [-]
The technical implementation aside, "what" prevents this from going down the exact same path as ICANN? E.g. how do we know next year the registration fees won't be 5x or certain registrations denied?
aliasxneo 11 hours ago [-]
A good question. Unfortunately, all I can say is we have a solution that involves specific European countries, laws, and regulations. As I said in a previous comment, happy to share more outside of this venue, but not all details are 100% public at this point.
breakingcups 10 hours ago [-]
If your solution can't survive public scrutiny, it doesn't seem like a trustworthy solution?
aliasxneo 8 hours ago [-]
We're simply choosing to build in a small group of closely aligned individuals and organizations right now. Many will become the first participants in helping run the public network across the globe. The network will launch completely in the open, including open sourcing the code. People can choose to wait until then to make their decisions or if they are particularly interested they can reach out to me about joining earlier.
zamadatix 4 hours ago [-]
A solution built in isolation by a group who just publicly tried to ride the AI wave with it is not a promising set of signs, but I have no problem leaving it at that until all is public and hoping it regains trust then!
12 hours ago [-]
xur17 12 hours ago [-]
Does alice "own" alice.dntls after she registers it? If so, how do you prevent name squating?
aliasxneo 12 hours ago [-]
Names are not able to be traded, so it's first come first serve. It's impossible to completely defeat name squatting, but you can make it less enticing. In the above case, Alice can "sell" her name to Bob on some aftermarket but the only way to do so is by transferring the cryptographic material. This is fraught with issues, especially considering once Bob has the keys he has no obligation to pay.
Names are valid for one year and range from $10/yr up like current domain names. Letting a name expire opens it back up to being registered again.
We have quite a few other "tools" in play behind the scenes that make name trading/squatting extremely impractical, but I won't go into those details here :)
hellcow 12 hours ago [-]
Seems like you could use an escrow to defeat this and sell domain names safely and easily.
aliasxneo 12 hours ago [-]
Like I said, it's impossible to "defeat" it outright because the concept doesn't really lend itself to this sort of structure. If I buy a plaque with my name on it , therefore owning it, the only thing that could really keep me from selling it would be some centralized authority. Even then, black markets have existed for drugs for centuries.
also until such a time that pkarr is widely adopted, you are better off using .onion domains anyway. it becomes a question of requiring custom DNS client vs. Tor browser.
both approaches use a DHT.
delfinom 14 hours ago [-]
There is already ENS.
aliasxneo 14 hours ago [-]
The adoption has basically been non-existent. I have a lot of theories on where they've gone wrong. Being so heavily tied to a blockchain (Ethereum being the worst due to its state bloat) is probably the biggest mistake I think they made.
colordrops 14 hours ago [-]
isn't yours tied to crypto and AI?
aliasxneo 14 hours ago [-]
No, see the above comment.
nubinetwork 15 hours ago [-]
> Once the 3rd-level domains are terminated, it is assumed that the now vacant 2nd-level domains will become available for registration. Should someone (other than me) scoop up fraser.name (...)
What's to stop someone from doing that, and keeping the status quo? Sure, it might be expensive, but pool together a few frasers for the initial buy, and make the money back on the sublets.
bityard 13 hours ago [-]
Well, nothing, but it does assume that Verisign doesn't have an unstated plan to do something else with .name. Domain registration is the real estate of the Internet and very little has happened in the last 30 years of domain name policy that has been for the benefit of anyone outside the the registrars.
For all we know, this is simply the first step in a series of moves for Verisign to better monetize the .name TLD in some novel fashion.
My evidence for this is that Verisign's own arguments for terminating the third-level domains are highly dubious. They claim that the third-level domains are too hard for them to manage. Bollocks: there are only 22,000 of them in use. That is a VERY small database that practically fits on a calculator and I refuse to believe that any manual labor around it is an outsized burden compared to pretty much any other semi-popular TLD. The second claim is that "the majority of those are not in use." Okay, if that's true, then where is the management burden coming from? That means tens of thousands of people are giving them money and getting nothing in return, isn't that the definition of an ideal business model?
It just doesn't pass the sniff test.
And finally, having read both of the linked documents, it sounds like people who have registered their .name for years in the future are not getting their money back. Are they likely to pay a second time, to a sub-registrar with no history?
xamde 13 hours ago [-]
Also, someone managed to run all this 20 years ago. Has technology gotten so much worse? Is RAM now THAT expensive?
toast0 10 hours ago [-]
Not just someone, Verisign managed to run this registry since its delegation.
Restrict future 3rd level registrations, offer a path to upgrade a 3rd level registration to a 2nd level registration for those 2nd level domains with a single registrant and the burden will decrease over time.
theandrewbailey 15 hours ago [-]
Depends on how much one trusts whoever's running fraser.name. Is it more or less than Verisign?
ZiiS 14 hours ago [-]
You have to trust them and Verisign; which will always be less then just Verisign.
Y_Y 14 hours ago [-]
Unless your trust for VeriSign is already zero
willwade 14 hours ago [-]
I worked for .name briefly right at the beginning of their entry into the world. Interesting but very odd part of my career.. Ill give it that.. I personally found the product at first a great idea but somewhat crippled by execution..
jonhohle 13 hours ago [-]
One of the reasons I stick with Big Email for my primary email is cases similar to this. If I host email and lose the domain one day, I’ve lost two factor on a thousand different services (the single factor on some). Big Email’s policy is to not reissue my address, should I lose it or die.
The .name scenario is even worse. One domain gives you access to tens of thousands of users email. It seems like a privacy nightmare.
I’m not sure how future auth and privacy will work, but my child lost a tracfone phone and some mixup had separated it from my account. There was no way to recover the number. If that was my personal phone, how difficult would it be to restore banking, medical, and government access to things that assume I’ll always have that number.
Doing the same with personal email seems like too big of a risk.
sunnybeetroot 13 hours ago [-]
You can look through my history how many times I’ve brought this up to people and they just don’t seem to care. A defence is that they’ll buy the domain for a century and not care once they’re dead which is fair but the situation in this article is a valid one. I will always stick with Big Email for accounts.
famfamfam 12 hours ago [-]
I moved to a third-level .name domain in 2005 precisely because one of the Big Email providers (Google) locked me out of my account with no recourse; presumably because I had a very common email address that was getting a large number of login attempts from other people which had triggered some abuse automation.
At the time - before the explosion of new gLTDs - third-level .name domains were advertised as the 'correct' domain to register for individuals wanting personal email addresses.
sandcat_ 5 hours ago [-]
Your response seems to imply those people are irrational, but it's really just different priorities. Yeah, you need to make sure you don't lose the domain. With Google/etc, you need to make sure you don't break any of their usage policies across their suite of apps, etc. Neither are super likely to happen. Neither are impossible, either.
Personally I like having a custom domain as I like the idea of being able to move between providers. So far, over the past decade, I've hosted my email with Google, Fastmail, Hey.com and then Fastmail again. I like being able to move it around if I find one provider better than another. Others won't care, that's fine too.
drdexebtjl 12 hours ago [-]
I don’t see the problem if you stick with .com or the ccTLD for the country you live in.
To me, the risk these registries screwing me over is smaller than Big Email deciding I broke their ToS and shutting down my account.
I wouldn’t use these novel TLDs either.
xp84 12 hours ago [-]
By Big Email are you just referring to the biggest providers (e.g. Google and Microsoft)? or is there another meaning?
wiether 12 hours ago [-]
If they're talking about Google or Microsoft, putting more trust in the worst tech companies than in the TLD of your country seems crazy to me.
ethanhawksley 12 hours ago [-]
I think it's pretty reasonable. The percentage of email accounts Google & Microsoft terminate seems far far lower than the chance I misconfigure my email or lose my domain
jonhohle 11 hours ago [-]
I was talking about one of those. Specifically they have a policy of not reissuing email addresses. Once it’s registered it’s burned. If they were to reverse that policy, the sky would fall.
donmcronald 11 hours ago [-]
I'd rather trust myself.
If you walk around all day with your wallet in your pocket, it might fall out and you'll lose it. Would you like me to hold onto it for you to make sure that doesn't happen?
xp84 6 hours ago [-]
I agree with you and other selfhosting fans in spirit, I really do.
On the other hand, it's email. I was at a hospital to do a blood draw, and needed them to receive an email (insurance info). I sent them an email from my Gmail. We wait 4-5 minutes. I notice they're checking an office 365 outlook. So, I re-send the same message from my @outlook.com email. Arrives instantly.
Deliverability between MS and GOOG is normally really good, and even that wasn't working right that day. My self-hosted email server being able to deliver to them reliably every time is hopeless. "Big Email" has made it excruciatingly painful to not be on sending from one of their platforms, unless you're one of the big 5 or whatever platforms that send bulk email or bulk transactional email. The SendGrids, Amazon SES, etc.
sandcat_ 5 hours ago [-]
There's a difference between controlling the domain and self-hosting. You can still use Gmail and Outlook (I assume, I don't know for a fact) with a custom domain. But the difference is if any of those services become less reliable or whatever, you can move your email across to another provider. You can't do that if you're stuck on an @outlook.com address.
But also, even if you're self hosting on a server in your basement, you can still use SES to deliver your mail. Delivery is not an issue here.
thombles 8 hours ago [-]
The reason we happily walk around with our wallets is because Big Finance and Big Government are willing to invalidate and reissue our credit cards and identity documents, maybe even help us out with the fraudulent transactions after it was stolen.
bigstrat2003 9 hours ago [-]
I trust myself a hell of a lot more than I trust Google (or other big tech companies) to not terminate my account because of an automated process gone wrong. Not only are my own mistakes less frequent than theirs, I actually have recourse if I screw something up. Not so when big tech does.
bluebarbet 11 hours ago [-]
Came to the same conclusion. With primary email I do not need multiple points of failure. The optimal solution is a contractual - paid - relationship with a single reputable email provider. There are a bunch of them.
koeliga 12 hours ago [-]
The risk of losing your big email account is higher than losing your domain.
Furthermore, if you happen to lose your domain, it will in most cases be easier to recover than a restricted account.
DaiPlusPlus 10 hours ago [-]
> if you happen to lose your domain, it will in most cases be easier to recover than a restricted account.
I used to think this, until I inadvertently let a registration fail to renew because I didn't update my expired credit-card's billing details with NameCheap - they did send me automated emails about it but I missed them, unfortunately. Their grace-period is only 30 days and I didn't notice the problem until 45 days had passed when my domain-name was bought-up by a spam-site-scammer and redirected the site to a porn/virus-downloader site (yes, those still exist).
I paid $1500 (uugghhh) for the UDRP process to get the domain-name back ($1000 UDRP fee, $500 for the lawyer to do the paperwork), and the UDRP panel ruled against me: their response reasoning made it clear that they never actually looked at my submitted evidence - and unfortunately that $1000 is nonrefundable, gaaaaah. I still haven't gotten that domain-name back. (I will say that my previous other UDRP cases all ruled in my favour; I don't know why/how I somehow drew a crappy arbiter in this case, I'm just vexed that they can rule against me without any right to appeal; I expected better).
noAnswer 7 hours ago [-]
The ratio between people who lost their "free big provider" account do to arbitrary algo decisions and people who lost their domain because they ignored provider's invoice for over a month must be 1.000.000 to 1. :-)
I use a prepaid provider. If at the day of the renewal there is no money "in the bank" they immediately release the domain. So yeah, I treat their reminders with priority. I really should change providers...
UltraSane 8 hours ago [-]
one neat thing having your own domain lets you do is have ANY <string>@domainyouown be sent to your inbox so this gives you unlimited email aliases. I often prefix the SOURCE of the email, like toyota@domainIown
jonhohle 3 hours ago [-]
I understand the advantages and have run email on my own domains for decades. Those aliases are used for business or partitioning senders. If they fail, my life goes on.
Wow! Years ago I initially bought my firstname.lastname.name, then I let it expire and then bought lastname.name. So glad I did!
Never dreamed that such a supposedly durable thing would just disappear. How hard is it really to preserve a global resource like this that exists only in software?
ipython 15 hours ago [-]
From the Verisign application [0] for this change:
> 2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
> None. There will not be any effect on the life cycle of domain names.
ehhh, how is that possibly true? This change (deleting all third level names) by definition affects the lifecycle of domain names ... by terminating them!
Many years ago I wrote articles bringing attention to the negative effects of Verisign's SiteFinder [1] - if you don't remember this, it's when Verisign hijacked NXDOMAIN by redirecting any unresolvable domain to a site they owned and controlled.
"Well, it doesn't affect the lifecycle of domain names. The lifecycle is defined in some RFC somewhere, and this change doesn't modify that. Now, these particular domain name instances might be adversely affected, but you didn't ask about that." -- lawyers, probably.
donmcronald 11 hours ago [-]
You're closer than you think. Big companies and institutions just change the definition of words they don't like. In this case, they could argue that a domain's lifecycle is registration, renewal (optional), deletion. Deletion is part of the expected lifecycle, so this doesn't change it.
The ambiguity is a feature so they can do whatever they want. We all know it's bullshit, but it gives the parties involved the ability to disenfranchise one group to benefit another while claiming they're following the rules.
donmcronald 10 hours ago [-]
Here's an example of someone genuinely making that argument in another hacker news post. I'm having a laugh about how spot on I was.
> Changes to the life-cycles of domains is a question meant to ask if this seeks to modify the life cycle policy, which is a separate type of change from termination of the service as a whole. I.e. this does not seek to change the life cycle policy, it seeks to terminate the service offering completely - making the life cycle policy irrelevant.
econ 13 hours ago [-]
I don't like the way domains work in general. It's really quite expensive if you are wise enough to buy everything that looks to much like your website.
What useful functionality is there in selling these domains?
Expiring domains is bad for the web and selling them to someone else is as terrible as the article makes it out to be.
zamadatix 12 hours ago [-]
You're also never going to register e.g. xcombinator.* nor is that necessarily a domain which should never be sold on the basis it's similar to ycombinator.*. Rather than buy everything, buy the ones most likely to be accidentally entered for only the most common tlds so you can set up redirects or the like and then enforce and protect your trademark like you have to in any other situation.
jacobgkau 11 hours ago [-]
> Expiring domains is bad for the web
Short-term, it might seem like it would make sense for domain registrations to be permanent, but long-term, it introduces at least two insurmountable problems:
1. Unless some other cleanup mechanism is in place, eventually (like, hundreds of years into the future) domains will need to get longer and longer as people who owned old ones disappear and new people need new ones.
2. The infrastructure costs (while nominal) to keep existing domains functioning would not be sustainable in perpetuity without relying on the assumption of more and more domains always being sold.
decimalenough 15 hours ago [-]
I've had a .name domain forever and I had no idea first.last.name was even a thing, meaning that it was possible to register this without owning last.name.
That said, my domain is simply unusual.name, and everybody in my family has email addresses in the form first@unusual.name. So this is a no-op for me, and I gather www.unusual.name will also continue to work, since I own the 2nd level outright.
NelsonMinar 14 hours ago [-]
I'm sure Verisign would be thrilled to have a bidding war between the legitimate owners of fraser.name and a bunch of third parties they suddenly enabled.
febusravenga 15 hours ago [-]
This is silly question, but is your family managing trust in you as lone guy - cousin, father, brother - having potentially access to all their emails?
I feel that I more trust some corpo (Google, etc) that one particular person.
I don't imagine setup where you can effictevely guarantee them full privacy.
Some people in my family use it as their main address, others don't, it's entirely their call.
But yes, ultimately I control the domain and could be nefarious if I wanted to. But there's a certain baseline level of trust as a family, I'm reasonably certain my wife won't poison the milk in the fridge and she's reasonably certain I'm not going to read her emails.
sunnybeetroot 13 hours ago [-]
How do you manage the bus factor? You die tomorrow and what happens to management of the domain and therefore access to their emails?
decimalenough 7 hours ago [-]
There's a document explaining how it all works, and I have Google's Inactive Account Manager setup to transfer credentials to my trusted contacts if I go permanently offline.
> This is silly question, but is your family managing trust in you as lone guy - cousin, father, brother - having potentially access to all their emails?
I believe this is a very common setup: the "computer wizard" kid of the family manages the computers for the whole family. Not just emails, they have access to the whole computer (and have to fix when it breaks).
bityard 13 hours ago [-]
I manage the email accounts for the others in my household because it's free for them and I'm happy to do it. Plus, they trust me more than they trust a random tech company. Maybe that is not a universal thing among all families or parts of the world.
sunnybeetroot 13 hours ago [-]
How do you manage the bus factor? You die tomorrow and what happens to management of the domain and therefore access to their emails?
xp84 12 hours ago [-]
The implication, that one should make a plan for that, is a valid reminder not enough of us probably do.
But it hardly needs to be difficult. If you're running dovecot and postfix on a server somewhere then yes, family is screwed. But it's simple to use either some mail forwarding service that you pay for with a credit card, or something like fastmail (etc). Leave 2 pages of instructions for how to log into and renew the domain (print the QR code used for the 2fa enrollment!) and how to log in and pay for whatever the underlying services are. Place in a binder and label "Family.Name Email Management" and put it with your other important documents.
bityard 12 hours ago [-]
I stay out of the way of fast-moving buses!
But more seriously, my domain and VPS is on auto-pay, so it doesn't just shut off the day I die. My survivors will have plenty of time to back up their emails and do whatever they want with them afterward.
Plus, the password for my computers and keychain is in a safe-deposit box if they feel like handing it over to a trusted tech-savvy friend of the family to shut down properly.
vidarh 15 hours ago [-]
It was deemphasized pretty early because people didn't understand it.
It made sense to us because our starting point was an email service letting people share lastname.sometld, but we never got close to as many registrants on .name as we had users on the webmail service (we had a couple of million accounts on that when it was sold to one of Marc Cubans companies for a relative pittance in the aftmath of the dot com bubble bursting)
"2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
None. There will not be any effect on the life cycle of domain names.
...
2.3. Explain how the proposed service will affect the throughput, response time,
consistency or coherence of responses to Internet servers or end systems.
There will be no effect on the throughput, response time, consistency or coherence of responses to Internet servers or end systems."
My registrar is also suggesting that they are going to just keep the money I pre-paid for years of registration, which is a minor annoyance compared to the loss of my entire online identity but an annoyance nonetheless.
Since ICANN is a non-profit that is required to operate in the public interest I do hope there can be some pushback on this. I will be writing to the CA AG myself.
baylisscg 7 hours ago [-]
What's wild is that when initially launched you could only register 3LD domains. If you were quick out the gate and registered one in 2002 and have been using 10 year renewals you're about to have a domain you've owned for almost a quarter century with 6 years left on its registration nuked.
xyzzy_plugh 15 hours ago [-]
> Despite the fact that it's registered and paid for until 2040
How is this possible? I thought there was a 10 year limit.
elashri 15 hours ago [-]
I think it was figure of speech. The domain is registered until 2036
> Registry Expiration: 2036-01-29 00:00:00 UTC
Updated: 2026-09-03 08:12:27 UTC
Created: 2002-01-23 14:41:45 UTC
leni536 13 hours ago [-]
Will they get a refund?
swiftcoder 15 hours ago [-]
it's probably a 10 year registration, plus a pre-paid renewal at the registrar
chanux 15 hours ago [-]
I kind of assumed .name was a product of relatively new TLD explosion [1]
Gotta wonder what other possible disasters introduced with gTLDs.
vidarh 15 hours ago [-]
No, we were in fact part of the very first batch of "new" TLDs
xp84 13 hours ago [-]
I don't think it's hyperbolic to say that this is the most careless, disruptive change to anything to do with DNS or internet names I have ever seen.
> "will increase efficiency for the operation of the .name TLD."
What a preposterous excuse -- especially for something already up and running. Sounds like they probably want to change the backend in some way - or adopt some kind of off-the-shelf software - which doesn't jive so well with this unique TLD, and they figure "Ehh, fuck 'em, let's just pull the plug on these tens of thousands of people."
TLDRisk 13 hours ago [-]
I thought I knew a lot about the policies and expectations when it comes to domains. I was surprised to see 3rd level domains called out in the .name registry agreement and I’m stunned that ICANN allowed this.
It’s incredibly one sided. The registry gets to cut costs and the detriment to registrants is extreme. ICANN is supposed to act on behalf of all participants.
The flagrant disregard for DNS stability in this case is jaw dropping.
sandcat_ 5 hours ago [-]
Agreed. If you don't want to care about backwards compatibility, there's plenty of space for you in tech. Just not at a domain registry!!
padjo 13 hours ago [-]
Who is running the show over at ICANN? How can this possibly be a reasonable thing for a registrar to do?
mchesters 15 hours ago [-]
Wow, they were extremely laziest in the request form too. Most answers are just a few words.
> 3.6. Have you communicated with any of the entities whose products or services might be affected...
> "No. Not applicable."
mchesters 15 hours ago [-]
Seriously.
> 7.3. Provide any other relevant information to include with the request. If none, respond with “N/A.”
> None.
fetzu 15 hours ago [-]
Also note that their response is the exact length of the shortest allowed one, and yet still wrong.
chrismorgan 15 hours ago [-]
I want to hear you justify, with perfect gravity, “N/A.” being the exact same length as “None.” Pictures of handwriting or specific fonts accepted. :D
johntash 14 hours ago [-]
It's _almost_ the same length if you count the period on "N/A." but not on "None."
fwlr 13 hours ago [-]
N . / A .
N o n e .
chrismorgan 15 hours ago [-]
I think the “not applicable” is to the elided second sentence of the question:
> 3.6. Have you communicated with any of the entities whose products or services might be affected by the introduction of your proposed service? [→ No.] If so, please describe the communications. [→ Not applicable.]
Gotta say that the entire form feels not applicable. The proposed service is the discontinuation of an existing service. I see from their website that other similar things do the same, but it feels broken when so many of the questions become nonsense.
wmf 15 hours ago [-]
This is how you fill out an application when you know it's going to be rubber-stamped.
xp84 12 hours ago [-]
Bingo. They just do whatever they want, and cash our checks.
jacobgkau 11 hours ago [-]
I caught this one:
> 2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
> None. There will not be any effect on the life cycle of domain names.
If they're dropping existing domain names, that seems like it has an effect on the life cycle of those domain names. I suspect I must be misunderstanding what they mean by that question, because it otherwise seems like it shouldn't have passed basic muster.
MadameMinty 15 hours ago [-]
The nerve.
noja 15 hours ago [-]
ICANN approved this.
Glyptodon 11 hours ago [-]
It's kind of crazy to me that the whole domain was originally set up so that people would buy 2nd and 3rd level pairs. But it also seems really obvious that backtracking is going to be a disaster.
Ok I don’t get it. Why not register `fraser.nameˋ directly? Or pick any TLD and register ˋ a 2nd-level domain (ˋfraser.tld`)? It just feels easier, plus this way you don’t have to pay for any new member of your family?
djoldman 15 hours ago [-]
If aaa.bbb.name is registered, then bbb.name cannot be registered.
bbb.name can ONLY be registered if it is not already registered AND there are no 3rd levels registered on bbb.name currently.
> Or pick any TLD and register ˋ a 2nd-level domain (ˋfraser.tld`)?
How would that help? The problem is that he's losing access to all the accounts currently tied to fraser.name, if he is changing that he can just use any arbitrary domain anyways.
Ecco 15 hours ago [-]
I mean in the first place. Now it's too late indeed.
Aachen 14 hours ago [-]
The post sounds like that wasn't possible; that this TLD operated by exception with third-level domains. It would be like asking why you don't just register smith.uk instead of smith.co.uk: because you can't (https://en.wikipedia.org/wiki/.uk#Second-level_domains)
That's just my reading of the situation though. The person could now hope they're the first to claim their second-level domain once it becomes up for grabs, but there's probably a dozen other people with a fraser subdomain that would want the same, plus however many hundreds of scalper scum. Probably the best you can hope for is that whoever does get it, has the decency to honor the original third-level domains for a reasonable fee
KomoD 14 hours ago [-]
> It would be like asking why you don't just register smith.uk instead of smith.co.uk: because you can't
You can. Anyone can register a .uk, and you don't need to own the .co.uk
Aachen 6 hours ago [-]
Wikipedia says "second-level domains are managed by various government agencies, and generally more strongly controlled" besides the exceptions mentioned like co.uk. Why else would anyone ever have gone for a third-level domain?
If they've recently changed that and I'm misreading Wikipedia, that doesn't change the underlying point that the answer was "you couldn't". Otherwise I've grossly misunderstood the whole post and how verisign is proposing to cancel this person's third-level domain
orra 15 hours ago [-]
There will other people with the Fraser surname in the exact same position.
e_l 15 hours ago [-]
Because only one lucky person can own `fraser.name` at any one time in your model. And whilst that lucky person might be able to register their family members for free. There will be countless more (unrelated) Frasers who won't be able to register (even for money) their own `FIRST.fraser.name`.
So the argument goes, society as a whole gains more if we prevent anyone from owning `fraser.name`.
A legitimate alternative though, is to register `FIRST-fraser.name`
p4bl0 15 hours ago [-]
At the beginning of the existence of the .name TLD you couldn't do that, you were forced to register firstname.lastname.name and provide an ID to justify registering this specific domain.
With it you got an email redirection from firstname@lastname.name to the address of your choice. At some point this feature was discontinued (I assume when VeriSign took control of the .name TLD), a bit after it was decided (again by VeriSign) to allow registering first level .name domain. My main email address stopped working from one day to another without me being warned in any way.
When this happened I've emailed VeriSign and my registrar at the time, and tried several time since then, to be able to register the first level domain I'm the only one using, but they categorically refuse, despite recognizing that a single subdomain has ever been registered. They kept saying that I could just let the domain expire, wait for the grace period, and register it once it's liberated, hoping that no one does it before me, and without any solution for the downtime in the mean time…
And now this… fuck VeriSign -_-
antif 15 hours ago [-]
This really sounds like VeriSign has no business owning .name … best possible outcome would be transferring it to somebody who will retain the originally intended services.
ZiiS 14 hours ago [-]
It has been extreamly clear VeriSign has no business doing anaything for years.
xp84 12 hours ago [-]
What a perfect example of the sort of fuckery Verisign would do. You have the simplest use case and they can't even help you transition onto the scheme THEY WANT everyone to use now.
anominal 14 hours ago [-]
The firstname@lastname.name email forwarding is still working for me. I think only some registrars support it, though.
p4bl0 12 hours ago [-]
Really? Mine have been discontinued without notice something like 15 years ago!
15 hours ago [-]
15 hours ago [-]
NewJazz 15 hours ago [-]
You might want to write to the CA attorney general. Former AG Xavier Becerra was able to dissuade ICANN from letting the .org fuckery happen, maybe Bonta could try to strong arm ICANN in this case.
qrobit 15 hours ago [-]
What was the deal with .org?
EDIT: seems like Ethos Capital private equity firm wanted the .org registry, and Xavier Becerra (Attorney General of California at the time) wrote a letter that played major role in transaction being rejected
> Dear Messrs. Botterman and Marby:
>
> I urge ICANN to reject the transfer of control over the .ORG registry to Ethos Capital.
> The proposed transfer raises serious concerns that cannot be overlooked.
Thanks yeah was too lazy to go searching for a link.
Apocryphon 14 hours ago [-]
I wonder which tech nonprofit would be best to champion this cause. Doesn't seem quite the EFF's domain.
ClarityJones 13 hours ago [-]
If this proves to be a viable business strategy, then verisign could equally use it to re-sell google.com, ycombinator.com, etc. to the highest bidder.
lacoolj 14 hours ago [-]
Dude, this is one of the craziest things I think I've read on HN
First, that a legit dealer could/did(does?) sell third-level domains at all (Verisign, no less)
Second, that the top-level is staying available, allowing for second-levels to be bought/sniped like you mention.
If you do lawyer up and need help with legal fees, I think this would be a worthy cause.
thbb123 8 hours ago [-]
Wtf, I have been using my x.y.name domain for everything, haven't been notified of this.
Should I rush to reserve y.name so my email address and personal website can stay online?
kronodeus 7 hours ago [-]
Based on my understanding of the situation, the 2LDs are getting sold, so yes, you should try to acquire the 2LD if you want to retain control of your subdomain(s).
doublepg23 16 hours ago [-]
I didn't even know I was using .name incorrectly...
morissette 11 hours ago [-]
It seems as if only 40 people are needed for a class action suit. Me, not a lawyer. Gemini says chances are you could only get a refund. But maybe worth the fight for some.
niraj-agarwal 8 hours ago [-]
22,000 people affected. Link up and lawyer up is right. To have identity and existence taken away is a no go.
aeternum 14 hours ago [-]
How would the avg person know that ..name is different and somehow more trustworthy than ..uk
Overall this seems like the right move, either they all are trusted or none.
akulbe 12 hours ago [-]
I don't get the concept of 3LD. We own kulbe.name - does this news mean it's going to go away entirely?
aff-vasileva 12 hours ago [-]
Turns out “buying your name on the internet” was technically just renting a room in someone else’s last name.
mzajc 12 hours ago [-]
In this case the registry itself (Verisign) was the owner of the second-level domain, and they most certainly shouldn't be allowed to just drop your registration whenever they please.
xbar 9 hours ago [-]
I can only assume ICANN was co-opted by Verisign some decades ago.
delduca 15 hours ago [-]
I never bet in any other than .com, .org, .net?
CodesInChaos 15 hours ago [-]
.org almost got screwed in 2019 too:
> In April 2019, ICANN proposed an end to the price cap of .org domains and effectively removed it in July in spite of having received 3,252 opposing comments and only six in favor. A few months later, the owner of the domain, the Public Interest Registry, proposed to sell the domain to investment firm Ethos Capital. After intense criticism from nonprofit groups and significant figures in Internet history, the proposal was scrapped.
Surprisingly not by Verisign, who gave up .org in 2003.
r_lee 14 hours ago [-]
I love that name, "Ethos Capital", it's so wholesome
it'd fit like a PE firm focusing on chemical weapons
jeroenhd 14 hours ago [-]
Those are all controlled by companies in and subject to the demands of the USA, which has been proving for many years that they cannot be trusted.
Also, all common names with any of those prefixes have been registered a long time ago.
jmuguy 14 hours ago [-]
I can't be the only one that assumed based on the domain that this was some bizarre DMCA action by Paramount.
Aachen 14 hours ago [-]
What does Paramount have to do with the last name Frazer?
.name is the part I keep having to relearn, so seeing it spelled out helps.
mig4ng 13 hours ago [-]
And that kids is why it's always DNS fault.
Again, you're security is only as strong as your DNS.
r_lee 14 hours ago [-]
I would not use a 2nd level tld for a "stable presence". it seems like a gimmick
cjjuice 15 hours ago [-]
I really think ENS is on to something with blockchain based domain registration and management
Aachen 14 hours ago [-]
Family of ESR or who is this?
basilikum 8 hours ago [-]
I seriously wonder what ICANN is good for.
Henchman21 13 hours ago [-]
How is it that they can just nullify the contracts they had with people they were providing services for?
swiftcoder 15 hours ago [-]
That's pretty shit. You'd think changes like this would need to go through a public comment period with the affected users (much like city planning decisions do)
>2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
>None. There will not be any effect on the life cycle of domain names.
>2.2. Does the proposed service alter the storage and input of Registry Data?
>No. There will not be an alteration to the storage and input of Registry Data.
This sounds wrong? Is this just a knee-jerk form-filler reaction? It seems to me that the admitted "Upon discontinuation, no new third level domain names will be registered and existing third level domain names will be terminated."
In general this sounds like a grotesque misplay that is wildly uncharacteristic for the entity behind the timeless .com
1970-01-01 14 hours ago [-]
Instead of giving up, why can't all 22k .name owners move on to OpenNIC? They will not say no, you can't have that.
notahacker 14 hours ago [-]
The ability to register fraser.geek so a very small number of OpenNIC users can access that new URL doesn't really solve the OP's problem with his family's long-established URLs disappearing and their emails being directed to whichever scammer buys up the fraser.name domain.
1970-01-01 13 hours ago [-]
That isn't the correct problem. The 3rd level domain is going away, which can be reconqured via OpenNIC and mass re-adoption. There will surely be new problems, but owning will not be among those problems.
Macha 13 hours ago [-]
The problem is everyone else (such as email providers...) recognising your ownership.
1970-01-01 11 hours ago [-]
That's why you form leverage with 22k others that are in the same boat as you. The root with the users is the root that becomes trusted, which then becomes the root that resolves. Rolling-over and allowing ICANN to quietly get away with this is exactly what they want.
0xbadcafebee 11 hours ago [-]
Prediction: In 20 years, ICANN, IANA, ARIN become increasingly abandoned by nations wary of The Imperialist States of America's control over global communication & commerce, and the internet becomes an uber-net of nationalist internets, subverted by satellites.
khalic 14 hours ago [-]
Ah! verisign! Proving the world over and over what kind of scum they are
TZubiri 13 hours ago [-]
I wonder if this could constitute a violationiof article 6 of the UN declaration of human rights.
It has been established that national identifiers are protected by it, and a domain works as a sort of international identifier, in this case a personal one.
No one is obligated to give you a domain, but by contracting an obligation to provide that identifier until 2040, they would at least be liable for those damages, but there's an argument that depriving you of an identifier already granted is a more fundamental violation of a right to a name, an identifier and recordkeeping of them.
AtNightWeCode 14 hours ago [-]
Things like this happens from time to time and yet people insists on using stupid TLD:s just because of "cool" suffixes.
psychoslave 15 hours ago [-]
Breaking trust, one TLD at a time.
So, where is our fully decentralized TLD alternative, free of ICANN or any central authority to handle how we grant names by conventions, without any money scheme in the game that attracts malevolent actors moving only through greed strings?
Also, this time let’s make it like usenet, so "person:named:Neil Fraser" or even "::Neil Fraser" (harder to type but less culturally entangled into English).
toast0 14 hours ago [-]
> So, where is our fully decentralized TLD alternative, free of ICANN or any central authority to handle how we grant names by conventions, without any money scheme in the game that attracts malevolent actors moving only through greed strings?
We can all edit our hosts file.
The problem with a lack of a central authority is domain names are most useful if they follow the highlander principle. There can only be one neil.fraser.name ... otherwise it's not usable for routing traffic if every webserver a Neil Fraser runs uses that address. (Yes, there are useful ways for one name to resolve to different webservers, but almost always those are webservers under at least loose control of a single entity or very exceptional cases)
CodesInChaos 14 hours ago [-]
Namecoin (.bit) was an attempt to create naming system without a central authority using a blockchain.
But from what I remember, they fucked up the pricing function and it got overrun by domain grabbers.
15 hours ago [-]
eleventen 15 hours ago [-]
> Minutes after my daughter was born, I also registered beverly.fraser.name.
...minutes?
Evidlo 15 hours ago [-]
Don't want to get scooped by GoDaddy when they hear the good news.
cxr 14 hours ago [-]
Consider whether you'd be questioning this if the author had written that within minutes of his daughter being born, her photo was on Facebook. The only thing it suffers from is not being normalized and taking marginally more* effort, while being nowhere nearly as creepy.
* or arguably the same amount or less; for additional context: the author is an ex-Googler
kotaKat 15 hours ago [-]
To be faiiiir, when your partner is absolutely zonked out in the minutes post-delivery, what else is there to do when you're by their side and still half-asleep? Time to start announcing your pride and joy to the world, starting with a domain zone file.
14 hours ago [-]
gpvos 15 hours ago [-]
I even suspect that the name of the child was dependent on the domain name being free... but then, it shouldn't be too hard to set up the request in advance and just press the button once the child is born. Maybe there was some rule that names could only be registered for living (i.e., born) persons?
rationalist 13 hours ago [-]
Maybe they wanted the Created Date for the domain to match the birth date.
cpach 11 hours ago [-]
And maybe she was born like five minutes before midnight, so he couldn’t just wait an hour or two (:
xp84 12 hours ago [-]
That's actually really cute.
advisedwang 15 hours ago [-]
Pretty crazy to be focused on anything other than your immediate family in after a birth... but not exactly unprecedented when you look at social media posts!
15 hours ago [-]
ipython 15 hours ago [-]
I mean, you've already had 10 months to come up with some name ideas. It's not like it's a huge surprise when it happens. You could even register the names before they're born.
buzzy_hacker 15 hours ago [-]
I registered a domain name for my son the day he was born...
whois firstlast.com | grep 'Creation Date'
shows his birthday, which I found amusing!
Aachen 14 hours ago [-]
GDPR would like to have a word with you! :D Nah seriously though, that's awesome.
echoangle 15 hours ago [-]
I thought there might have been a need to send an ID to prove that you actually have the name you're registering for so you would need to wait for the birth certificate but from wikipedia it doesn't seem like that's the case.
alaithea 15 hours ago [-]
No requirements at all. My mom had registered my firstlast.com domain some 30 years ago. While caring for my dying dad, she let all her domain registrations expire. I then had to negotiate with a domain squatter to get my domain back.
layer8 15 hours ago [-]
He didn’t say how many minutes.
mcmcmc 15 hours ago [-]
Presumably less than 60
tasty_freeze 15 hours ago [-]
It was more than one minute.
xiaoyu2006 15 hours ago [-]
just a figure of speech
bossyTeacher 15 hours ago [-]
Priorities. /s
notorandit 13 hours ago [-]
It's just money. Nothing else. Just money.
rburhum 13 hours ago [-]
Lawyer up and fight it. This is bs.
nikanj 13 hours ago [-]
I wrote to ICANN support and got a template-AI answer wholly unrelated to my complaint about this:
”Greetings from ICANN Global Support.
I am sorry to hear you are experiencing this domain access issue after your registrar's transfer. I will happy to provide you with relevant information and guidance.
Please note that, ICANN accredits companies as domain name registrars and works to ensure contractual compliance with the terms and conditions of the 2009 and 2013 Registrar Accreditation Agreements (RAAs).
ICANN does not provide domain name registration or manage domain accounts. As a result of that ICANN is not able to perform domain management for you.
If you need help to access and manage your domain, you will need to contact your domain service provider or registrar for assistance.
You may check who your registrar is by doing a domain search at lookup.icann.org.”
Absolutely infuriating
strenholme 13 hours ago [-]
The correct way to handle this mess is to simply keep things messy. BGP tables are a big mess, for example, because a lot of companies keep their IPs when going from ISP to ISP.
But, assuming that Verisign can’t keep third level domains (as a DNS implementer, I don’t think third level domains is a huge deal; see thread below):
* Third level names where only one person has the second level domain should be transferred to whoever owns that single third level name.
* Third level names where multiple people have the same second level domain should be put up for closed bidding: Only current owners of .name domains with a given second level domain name (e.g. last name) will be able to bid for the second-level domain. So, if one has john.smith.name and joe.smith.name, Joe Smith and John Smith will be in a bidding war for smith.name.
If the issue of .name not being in public suffix is a real issue, Verisign can handle that by disabling new third-level .name registrations, and provide Public Suffix with a list of those registrations (just send all the owners a privacy notice, making it clear that the existence of the name will be made public for security reasons). More reading: https://github.com/publicsuffix/list/issues/2306 (There seems to be issues with this list being too long to keep in the Public Suffix because there’s too much software out there which can’t handle it. That seems strange to me: Even here in 2026 where RAM costs far too much, Deadwood can store a list of 240,000 blacklisted entries in under 10 megs; there are about 22,000 three-level .name domains and I could store that list in a way that could be very quickly looked up in about a meg of memory)
Now, personally, I think Verisign can keep these messy third level names, and are doing things this way so that Neil Fraser has to compete with every single 2-bit cybersquatter out there for the rights to fraser.name.
As an aside, it’s trivial to have DNS servers handle multi-level domains without having to have a zone file for every level; e.g. https://this.is.a.long.name.maradns.org works, and there’s no zone file for name.maradns.org, long.name.maradns.org, a.long.name.maradns.org, and so on.
You know dang well if .org was owned by an investment entity, they would had jacked up the prices as much as they could get away with.
xp84 12 hours ago [-]
The auction plan is gross. It is unfair to say "This thing you thought you were buying the right to exclusively control (subject to continued renewal payments)? We're gonna transfer it next week to whichever Fraser pays us the most. Happy bidding!" It wouldn't be any more fair to do that than to announce to all .com owners that there will now be an auction between them and everyone who ever typed that name into a search at the registrar.
What they should do, is nothing.
strenholme 12 hours ago [-]
I agree.
As a DNS implementer, the action plan is unnecessary. There are, what, only 22,000 or so .name domains. One can write code to do two lookups for firstname.lastname.name: If firstname.lastname.name is found, return the NS delegation. Otherwise, if lastname.name is found, return that NS delegation. Finally, if neither is found, return NXDOMAIN.
One argument is that this is hard to implement in the real world (it’s about one day, at most one week for a skilled DNS developer to pull off; probably half a day to be honest, and yes I have written code like this), so then yeah if that’s a real concern let’s have a closed auction. I’m opposed to the auction, based on my experience that this isn’t hard to implement.
If it’s an issue, just stop all new firstname.lastname.name registrations, and only allow lastname.name new registrations. Then we only need to deal with this corner case for about 22,000 domains, which we can keep in a special hash and would take about four megs to store.
xp84 6 hours ago [-]
Love the practical explanation of how straightforward it should be. Especially with the finite set. Hell, they could send an email to all 22,000 saying "We're sorry, we have to raise your renewal fees by $12 a year. We hate to do this, but we're having to do a lot of extra work to support this unique type of domain." they'd bring in $264,000 a year, surely that should be enough to pay a single skilled developer to manage this and also be available to help smooth over any future complications.
MagicMoonlight 13 hours ago [-]
[dead]
pmdr 15 hours ago [-]
> I had history with Verisign and did not trust them.
I don't know what that history is, but did it really make a tld used by only 22k people more appealing?
decimalenough 15 hours ago [-]
That's 22k people with third level domains like first.last.name. There are close to 100,000 second level last.name registrations, which are not going anywhere.
According to Wikipedia, "Verisign was the outsourced operator for .name since the .name launch in 2002". That makes the reasoning yet more puzzling.
swiftcoder 15 hours ago [-]
They ran the backend services, but didn't set the policies (until they acquired the operator in 2008-2009)
bawolff 13 hours ago [-]
I feel like TLDs as a concept are more trouble than they are worth. We should just have .com and get rid of the rest (except special purpose tlds).
drnick1 14 hours ago [-]
> Second, my email address also disappears. Third, all the IoT devices that use services on this domain become bricks. Basically, I disappear from the Internet.
While changing email is inconvenient, I don't understand the point about IoT devices. IoT devices should not depend on the Internet at all for obvious privacy and security reasons. If you are using IoT devices with "cloud" accounts, then this is a blessing in disguise. Put that garbage in the trash and rebuild around HomeAssistant, Zigbee, RTSP, etc. I find it hard to believe that someone hosting their own website would fall for the cloud IoT scam.
jmuguy 14 hours ago [-]
Plenty of people and businesses have their own (DIY, etc) devices that need to use DNS. I mean it wouldn't really be the internet of things, if it didn't actually use the internet...
For instance, I own a .house domain that I use for a bunch of stuff that I've programmed. It would be a pain in the ass to go change that domain out. Now take that to next level and you're a business that's deployed a few thousand devices that need to call home.
I guess all this is to say - IoT doesn't just mean cheap botnet honeypot IP cameras. Take a look at https://www.balena.io/cloud for instance
drnick1 14 hours ago [-]
"Internet" in this context usually means IP, and in any case it should be restricted to a LAN. If you actually own the device changing the domain or IP should be trivial, I don't think this is what the article refers to.
Sharlin 14 hours ago [-]
It's dubious whether the Internet of Things was ever a good idea in any sense. Especially given how, famously, the "S" in "IoT" stands for security.
rahimnathwani 14 hours ago [-]
He didn't say his IoT devices relied on 'cloud' accounts. He said there are IoT that use services on this domain.
Imagine he's set up some IoT devices at his parents' home, and those devices use services that he hosts somewhere on the internet. It would be silly to hard code the IP addresses in there, right (unless he operates his own ASN)? So he would use DNS to allow those devices to find his server(s). This would be the case whether the servers are at his home, at his office, or in a rack at a data centre.
monkeyfacebag 14 hours ago [-]
It sounds to me like you understand the point perfectly well, you just cared to make a different point.
jawns 15 hours ago [-]
Surely the author must have anticipated some heightened level of risk in pegging important parts of his personal and business life on a nonstandard TLD like this.
It's a pretty bizarre exception to the normal, intuitive ways that domains work.
I'll admit that it's a crappy situation and I would be frustrated in his place. But if I were in his place, I probably would have also thought it prudent to have a backup plan.
swiftcoder 15 hours ago [-]
> nonstandard TLD
What exactly is non-standard about an ICANN-approved TLD? Yes, the multi-level structure is a little odd, but given that ICANN approved it in the first place, one has a reasonable expectation that they would work as advertised.
jawns 14 hours ago [-]
I have a .science domain and a .com domain.
Even though .science was launched in 2014 (more than a decade ago), I still consider it a non-standard TLD and still deal regularly with difficulties around its use. (For instance, you wouldn't believe how many online services reject email addresses than end in .science because they use regexes that exclude TLDs with 7 letters.)
Likewise, I've registered .lol and .fun domains but never would have assumed that just because they're available now, they will be available in perpetuity.
In that sense, .name as a third-level TLD is even more non-standard, because the standard way domain registration works is by choosing a single "second level" domain name, then adding subdomains.
angoragoats 14 hours ago [-]
> Likewise, I've registered .lol and .fun domains but never would have assumed that just because they're available now, they will be available in perpetuity.
Why wouldn't you assume this?
> the standard way domain registration works is by choosing a single "second level" domain name, then adding subdomains
The entire ccTLD systems of the UK, China, Germany, France, Japan, and many others would beg to differ.
jawns 14 hours ago [-]
I don't think those are comparable, because when you register a .co.uk domain, you are selecting one name that precedes .co.uk, similar to how you register one name that precedes .com.
Whereas with .name, you are choosing what appears to be a subdomain, followed by what appears to be a domain name. But under the hood, you do not own all subdomains for that domain name; you own only the combination of first_name.last_name.name.
angoragoats 14 hours ago [-]
I'm not sure I understand. How is registering first.last.name not also selecting one name ("first") that precedes last.name, similar to how you register one name that precedes .com?
(And yes, I am aware that you can also register last.name by itself, but only if there are no third-level domains using it, so for practical purposes it doesn't change my question above. Plus, when the OP originally purchased his domain, you could only buy third-level domains for .name.)
jawns 13 hours ago [-]
Present these two domain names to the average person:
1) benedict.cumberbatch.name
2) drstrange.co.uk
I expect the average person would assume that for the domain 1, .name is the TLD, cumberbatch.name is registered by a private entity, and benedict (and any other subdomains associated with cumberbatch.name) is a subdomain fully controlled by that private entity.
Whereas for domain 2, I think the average person will view ".co.uk" the same way they view ".com", even though technically it is both a ccTLD and a second-level domain.
swiftcoder 11 hours ago [-]
Luckily the average person has no idea what a TLD or a subdomain are
angoragoats 9 hours ago [-]
The average person doesn’t have the foggiest idea how TLDs, DNS, or domain registration work at all.
The only people who will make the assumptions you state are people who are tech-savvy enough to be familiar with those concepts, but not well-versed enough in them to understand the nuances we’re discussing.
And none of this does anything to advance the argument that .name is somehow nonstandard.
efreak 11 hours ago [-]
My insurance will not send emails to my first@last.family domain. Neither will several other systems. A number of systems flat out refuse to acknowledge that such a tld exists. (Improper assumptions about valid email addresses)
zamadatix 11 hours ago [-]
Non-standard as in "it's not up to my usual standards" not "is not part of a technical standard". I.e. it's a gTLD rather than a "standard" (in the previous sense) TLD.
avazhi 14 hours ago [-]
> What exactly is non-standard about an ICANN-approved TLD?
Uh, 99% of people would assume a .name address is a scam. Hate to break it to you.
swiftcoder 11 hours ago [-]
I mean, we could say much the same of any other non-country TLD, and probably half the country TLDs. That doesn’t mean one shouldn’t expect it to be administered responsibly
userbinator 4 hours ago [-]
Anything other than .com, .net, .org, and well-known ccTLDs I see in search results subconsciously get skipped over as "probably SEO spam or other useless content". These new weird TLDs are like the .tk and .us of old.
angoragoats 15 hours ago [-]
.name is in no way a "nonstandard TLD." It has been in existence for a quarter of a century and was part of the first batch of new gTLDs approved after the dot-com boom had begun, in 2000.
For the first couple of years of .name's existence, it only allowed registration of third-level domains, and the ability to register second-level domains was added later (and only if no third-level domains existed for that second-level domain).
The author is in no way at fault here, and I don't think I would have assumed there was a heightened level of risk if I were him.
I remember back when we had to write mechanize scripts to drive a browser through the renewal process, because if you had dozens, hundreds, or thousands of domains there was no nonmanual way, especially if you wanted extended verification or something silly like that.
So what I'm saying is, agreed and that has always been true.
The main problem with the Internet today is that we didn't destroy ICANN when they started this TLD sell off crap. A replacement institution may have at least told Verisign a TLD they can't run transfer to someone who can meet its promises can only be destroyed.
In this age, allowing domain names to be owned by other entities is almost like allowing a company business registration number or one's national id card number to be transferred to others.
I think name squatting is a problem, but it is not like that current system has solved it.
It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com
In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com
edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule
The .name subdomain rules are not very well known anywhere.
How about all the other 200+ country TLDs and rules for non-country TLDs?
"Here's a list of things that look like subdomains for you to treat as 3LDs instead of subdomains" sounds exactly like the solution to an edge case to me.
Another poster raised the point of hosting services which is valid. But at present outside of that example and the above I really can't think of an example where you have a link to entity.com and you have any significant cause to verify the identity beyond the 2LD.
(Aside, I always see "owned" and "bought" but you can only ever "lease" under the ICANN system as the present situation so clearly demonstrates.)
*: I realize that “owned” is a loaded word here, but (1) I’m referring to a registrar/issuer, which makes it yet more complicated as to how much “ownership” (de facto or otherwise) a given entity may have, and (2) I really don’t give a fuck about pedantic word choice if the meaning is unambiguous.
> but (1) I’m referring to a registrar/issuer, which makes it yet more complicated
We're also talking about a ccTLD which makes it even more complicated. AFAIK those fall entirely under the jurisdiction of the respective UN recognized government although I don't know how strong that agreement is in practice (treaty versus something else).
So at that point I guess we've roughly got ICANN -> US federal government -> CA state government -> registrar -> private party -> sublet.
This isn’t how things are done these days; names visible to the public are pretty much always in the form {domain}.{tld} or sometimes {name}.{domain}.{tld} (e.g. my own https://samboy.github.io). Registration is now done by bots and companies that spam you to death to try and get more money from you (the Internet wasn’t like that in the beach.santa-cruz.ca.us days). Domain names with multiple levels of delegation aren’t around they way they used to be.
* rented/leased/had control over/whatever
The old locality domains still exist, and in many localities you can still register them today by the same "email a request to some sysadmin" process. https://news.ycombinator.com/item?id=48122635
Your beach.santa-cruz.ca.us domain is still in DNS, just with a broken delegation chain. You could reclaim it right now by setting up a nameserver at reality.samiam.org.
https://beach.santa-cruz.ca.us/
Thanks for checking the zone files of the parent domain to verify it’s still there.
I think geocities had this as well?
A lot of hosting services offer this in general. (eg render)
Tumblr? (Might not count as the control over the page is more limited. The subdomains "are" still tumblr.)
For reddits subdomains are redirects to subreddits of the same name, so I guess that doesn't count.
Also I would not consider the examples of tumblr and reddit to be relevant. A person's blog on myprofile.tumblr.org is still the tumblr organization. This would be true for reddit even if they didn't redirect. Reddit admins moderate content on all subreddits.
When I read > I have been taught and tell my users to check the domain to verify a website is real.
I was thinking more of control of the content as "ownership" of the domain.
In the US, once upon a time, elementary/middle/highschools might be attached to something like schoolname.district.state.gov. But now, even my local area school now has a .com. It seems that older hierarchy style is falling out of fashion for smaller/shorter domains across public services, schools, government agencies, etc.
Now here it seems to be either a .com, .gov, .org, or a totally different and newer tld. Even .net has fallen out of fashion.
https://computer.rip/2025-11-11-dot-us.html
Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with.
Then when you consider DNS is fundamental infrastructure and people build secure things on top of it, (ahem DNS challenges for certs), it's remarkable that anyone would want or desire edge cases.
What you should know, and what your browser does know and automatically applies cookie policy and colouring your URL bar, is the Public Suffix List: https://en.wikipedia.org/wiki/Public_Suffix_List
It will let you know that, for example, one does not need to own .co.uk to own the subdomain foo.co.uk.
https://github.com/publicsuffix/list/issues/2306 for more discussion.
This is my theory because, a priori, 3LDs should be more profitable than 2LDs, because with 3LDs John Doe and Jane Doe don’t have to compete over doe.name, but instead can each separately purchase john.doe.name and jane.doe.name. Apparently, however, that’s not a benefit of 3LDs in practice, which leads me to conclude that john-doe.name and jane-doe.name just sell better.
To me, prior to knowing how it works, I would have assumed that either
a) john.doe.name would be a subdomain that someone who was just starting out had gotten for free supported by ads. Similar to having johndoe.freewebs.com back in the day. Not something most people would use for anything professional.
or,
b) doe.name was registered by one of the people in a family of Doe’s where every Doe is pretty closely related. For example, John of john.doe.name and Jane of jane.doe.name are husband and wife, or third cousins, or what have you. Most of the content, I would assume, is mostly about things that relate to the family. Like maybe one guy is doing a family genealogy project tracing the roots of this little cluster of Doe’s back in time and has made a site covering the findings from his research. And another one probably has some photo albums with pictures of like previous Thanksgivings and other family get togethers. In other words, nothing I would care about unless I was in their family or a very close friend of the family.
I would not have guessed that .name 3LDs worked the way that it did if I hadn’t read about it.
And on the other hand, if I saw just www.doe.name or johndoe.name, I would not make such assumptions. It would be not much different than seeing www.doe.com or johndoe.com respectively. I would just assume that .com was already taken and therefore they used .name, or that they happened to like the .name TLD because it emphasises that their site has their name as domain name.
3LDs are less valuable. In a market of many different tlds, why register foo.bar.name when you could get foobar.name or foobar.something_else
Mr. Fraser registered neil.fraser.name in 2002, when 2nd level registration under .name was unavailable; fraser.com had been registered in 1996 and neilfraser.com in 2000; he may have been able to get .org or .net, their registration dates are later, but they may have been registered and there was a gap --- my personal domain shows a creation date of 2003, but I registered it much earlier and abandoned it, but got it back after it was registered and then abandoned by someone else.
.name added 2nd level registration in 2004 and it seems to be vastly preferred. .us added 2nd level registration in 2002 and it was vastly preferred to the locality based naming. People don't want to have to educate their contacts about "weird" domains, which includes having an "extra" dot in your hostname.
Can someone explain why a product "registered and paid for until 2040" can be unilaterally voided like this without compensation?
> As your .name can be registered for up to 10 years and ownership is renewable, your .name really can be yours for life.
It seemed like there was an offer of renewable registration at least for a life term.
[1] https://web.archive.org/web/20020609132126/http://nic.name/c...
In either case, the security concern should be directly addressed.
That will cost them very little in terms of cash, as I doubt that many people register that many years ahead, plus in terms of accounting, they won't have accrued that revenue anyway so it wouldn't even hurt their books. Not that a couple hundred K would even matter on the financial statements of a giant, money-printing corporation like that.
The reason why they wouldn't go the route of waiting for expiry is that at least a few have nearly a decade left, and clearly they really want these gone, not just reduced in number. By 2036 when they would finally get to that point, I doubt whatever's driving this concern would even matter.
[0] https://publicsuffix.org/
The problem DMARC solves is different than the problem the PSL solves, though. DMARC prevents a 3LD from pretending to be a different 3LD on the same 2LD. But the PSL handles things like what it means to make a "cross-site request" or how to handle cookies.
I mean now I'm thinking if DMARC _could_ solve that... but I don't think it could, unless I'm missing some extension or rare use case.
CAA isn't a good fit as-is either, because the subdomain has top precedence over the parent domain — precisely the inverse relationship needed here. But having worked with the PSL for quite some time operationally and seeing the direction of trends away from it and towards structural DNS declarations rather than a centralized list, I think the 3LD-2LD-CRSF problem would be far better off solved with DNS than PSL.
Basically, just adding `co.uk. IN TLD subs=independent` as an SVCB record would fully deprecate the need for the PSL versus cross-site and other such ownership-changes-hands boundary problems with both A.co.uk being allowed cross-site with B.co.uk, and with co.uk being treated as equivalent to B.co.uk by password managers, cookie repositories, and so on. It would also benefit CAA by defining whether the boundary exists — if TLS is hosted by the provider, then any CAA records published by the subdomain should be disregarded; if the subdomains are fully independent, then any CAA records published by the parent should be disregarded — which simply isn't possible today without either referring to the PSL or implementing DMARC-style DNS solutions.
(I don't formally suggest that exact record as structured or written but it's sufficient a napkin sketch of what I mean by gesturing at that RFC to be considered.)
.name was one of the very first expansions of gTLDs back in the very early 2000s. It's a shame that it's being shut down as it was spearheaded by the ICANN itself rather than some registrar / investor like Donuts, Inc.
I suppose this is impractical as someone has to run the registry and there are costs associated with that. But don't the domain fees cover it?
> Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems.
https://www.icann.org/resources/pages/about-icann
Arbitrary termination of service is not stability.
Enabling name hijacking is not security.
The answer cannot be a rival name scheme based on decentralization or crypto or whatever. Those are never going to help normal non-wizard users. The answer has to be to make the regulators do their job.
> There will not be any effect on the life cycle of domain names. While the Requestor may disagree with Verisign’s response, the Requestor has not shown that ICANN relied upon false or inaccurate material information. The life cycle of a domain name begins when the domain is registered, then moves through various stages before ultimately coming to a close. Early termination of a domain registration does not impact the life cycle of the domain, as the domain can still go through the various stages of a standard life cycle. Moreover, as stated above, ICANN was aware that discontinuation of these registry services in the .NAME gTLD would result in the termination of approximately 22,000 third-level domain registrations and of email services/addresses.
I don't agree. If I have a domain registered for 10 years the expected life cycle is for deletion to occur 10 years from now, not 90 days from now. They've changed the life cycle by changing the agreed upon deletion date for the current registration term.
I could maybe see if they stop accepting renewals and delete the domains as they expire. It's not a good look, but at least people are getting what they've been promised.
1. https://www.icann.org/resources/pages/reconsideration-26-2-s...
According to ICANN cutting the life cycle short doesn't have any effect on the life cycle?
ICANN corruption is at the level of FIFA corruption.
How about the fact that you paid for a service for 10 years and they decided to stop providing it midway? Will you at least get a refund? If not, that's surely illegal right?
I own lastname.name and use it for email only like this: firstname@lastname.name
I always thought as owner of lastname.name, I'm the only one able to add subdomain.lastname.name. Is this wrong??
1) Can anyone "buy" scam.lastname.name without my authorization on .name??
2) Can anyone owning not.lastname.name then steal my emails going to: firstname@*.lastname.name or even firstname@lastname.name??
BUT: If someone ONLY bought not.lastname.name and doesn't own lastname.name, they'll get terminated. Would that be 'good' as it would stop 1) and 2) ??
I'm really concerned. My family is using first@lastname.name as the personal email, I'm hosting and paying for since many years.
TFA mentions that `.name` was unique in that it sold a good amount of third-level domain names directly from the registry.
Still a crappy thing for people, but it does not affect owned second-level domains.
But I didn't think about the 1st level competitors. There'd still need a mechanism to resolve that...
1. First come first serve? (e.g. whoever registered a y.name first, whether x is bob or sue is determined by the earliest registrant on record) 2. Lottery/random selection? 3. Bidding war?
I think the problem is 2nd level domains who have the same name will be a problem when they find out all these other 3rd level are now expiring and can run a route to spoof? Likely wouldn't happen, but with the fuckery in the DNS that can happen... This is such a rash and weird decision to push through so quickly just because engineers find it "easier" while ignoring the implications of the move, seemingly when it comes to larger scale security.
I assume there would have to be some method to prevent routing of third level domains to subdomains of two-levels... (or is that just me being a fool yet again, assuming we have competent administration of our systems).
But I wonder if there might be some competing names on the third level? Like, he's neil.fraser.name, but what if there's also bob.fraser.name and they'd both very much like to keep their domains?
Yes. I've been asking VeriSign for this for years, and they always refused.
I have myname .name - so I thought that was going away. Granted I barely use it, but still it would be annoying. I didn't recall there were 3rd level domains there.
There is no subdomain/TLD bit
What I understand would be the following:
1- Verisign manages the TLD registry for .name (and others), which includes managing the authoritative DNS servers (as pointed to by the .name NS and A records on the root DNS servers), 2- as well as for updating the NS records of .name records it is authoritative at the request of registrars (like, say GoDaddy), which act on behalf of domain owners. 3- one or some of the domain owners, for example for fraser.name, acted as a registry themselves managing authoritative DNS servers for NS records of .fraser.name domains, these third level DNS servers being pointed to by the name. NS records.
4- Upon registration of a .name domain, verisign charged a fee, (in the case of .coms this is around 10$ currently I believe, not sure how much they charge), and ICANN charges a much lesser fee (like 20 cents).
5- Upon registration of a
.fraser.name domain, the fraser.name domain owner charged a fee, and they kept the totality of that fee (potentially paying a fee to ICANN, but definitely not to verisign.)6- Verisign issues this request, requesting registrars of second level domains (domain.tld) like GoDaddy, to stop selling third level domains of this TLD (domain.2ld.tld).
This is my understanding of the situation, and in that case, verisign was not billing for the domain. This might (a bit cynically) provide a commercial motivation for the actions of verisign.
It's worth noting that this is not at all a weird or shady practice, multi-level domains are the very ethos of the domain system, it's built for that, I'm not saying any domain is obligated to do that on the basis that it can, but it's not some esoteric illegal activity, it's normal.
Still, I'm not sure there's any easy technical fix for the .name debacle.
It's safe to ignore altogether, but it can come in handy as a starting domain block/allowlist.
>Still, I'm not sure there's any easy technical fix for the .name debacle.
I think that it's gonna be ok, the owner of the 2ld is still the owner, so they are free to allow the 3ld domain owners to continue "owning" their domains and updating them on the authoritative 2ld DNS. It's just that verisign is no longer sanctifying it by allow vendors of other 2ld to sell 3ld with the 2ld together.
This might explain the whole situation, many of us are interpreting that the domains are deleted, but in reality, they may more likely be prohibited from being represented as official .name domains in registrars .
i.e. I own john.doe.name, you own george.joe.name. Once this change goes through, only "doe.name" can be owned, so who gets it?
* .name is open for everybody
* a company called "Global Name Registry" scooped up a BUNCH of common last names, including fraser.name
* Global Name Registry then sold access to neil.fraser.name for far cheaper than the fraser.name domain would cost on its own; someone else could also buy john.fraser.name or jane.fraser.name, so the single fraser.name domain that they owned could have dozens of customers associated to it. They worked with ICANN to allow each domain to have its own registered owner.
* The article in the OP bought neil.fraser.name and has used it for years
* Verisign bought Global Name Registry; later they realized, hey, we're sorta not making a lot of money on this idea, and we're spending a lot of time/resources maintaining these domains "for cheap" and chasing renewals, and not scooping up more customers. Let's just stop it and stop paying for fraser.name and the potentially hundreds of other domains we own.
* Neil Fraser, not the only Fraser in the world, is upset because he might lose the domain he's had forever
So one CAN buy the mwai.name domain, as you have, and continue using vpn.mwai.name just fine. It's just you can't "officially" start selling out these subdomains as a separate registrar entry.
I guess in practice it doesn't make much of a difference for me anymore, I registered mwai.name 20 years after they began allowing second-level registrations and more than 15 years after GNR was sold to Verisign. So presumably GNR's concept was long-abandoned by the time I made my registration (which was, to be truthful, mostly based on mwai.name being the cheapest domain with the initialism). I was more curious about the implications of having held a second-level domain, whether it could have caused trouble for me or for a different person who held a tertiary domain. But also my registrar at least doesn't seem to allow tertiary domain registration for .name.
Any any case, nothing in OP or any of its referenced sources suggest Verisign is giving up .name. rather they will stop accepting and serving tertiary registrations, so if Neil wants to keep his domain he or another beneficent Fraser will need to register the fraser.name domain and register the subdomains for neil, joe, jill, or whichever other fraser currently owns a tertiary domain. The same would be the case for anyone else who still held a tertiary domain. Perhaps Verisign or the registrars who work with them might be able to migrate the registrations of anyone with these domains, particularly in what I suspect are most cases where there is a single tertiary registration under a secondary domain. Perhaps offer fraser.name to Neil and he can add his own subdomains.
I was intending to replying to a different comment on the above thread, sorry if this made my previous reply a bit incoherent.
This is an ostensibly uncharacteristic move for verisign, but the customers that bought these 2ld did so from a non-verisign vendor, it is only after verisign bought the 2ld holder that they became the holders and are now proceeding to extinguishing them after embracing and extending.
Might be an anti-trust case. Like textbook clear-cut case. IANAL, this is not legal advice.
Why should I care as the customer? If I buy a for-life subscription plan and the company gets bought, can they just not honor it because it’s a different company now? Maybe they should check which promises they are buying when acquiring other companies.
Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.
I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.
I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.
What's your account tied to?
E-mail? That's usually on a mail server owned by someone else. If not, it's still on a domain owned by someone else.
Phone number? Definitely owned by someone else.
The only account that's reliably "yours" is one that asks for a login, a password, maybe a TOTP, and absolutely nothing else. Because everything else is introducing "things owned by a third party" into the equation.
Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?
> do browsers have a wildcard suffix list
Yes: https://publicsuffix.org/ and they have discussed this situation here: https://github.com/publicsuffix/list/issues/2306
> We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't.
So does that mean that in practice, .name domains were always treated by browsers like regular 2LDs, meaning the cookie and origin protection was always broken for those domains?
Doesn't sound like good news for the guy in the OP...
IIRC orgs like letsencrypt also use the PSL for rate limits, so there are probably more issues that are not browser-based.
But letting arbitrary customers take arbitrary 3 level domains, and others take 2 level domains, seems like a mistake as it's not very reasonable for every 3LD customer to put the 2LD on the public suffix list, but mixing 3LD and 2LD registrations means you can't public suffix *.name.
Seems the whole idea of having both was always misguided.
The issue is that .jp registered outside of a few Japanese registrars are legally not allowed to offer Whois privacy.
But that was simply the easiest way to market your website as a trusted government entity. And now nobody has ever heard of .us domains in active use.
https://en.wikipedia.org/wiki/.us
But your point about them being rather longer and difficult to remember stands, and the same for a .gov, which could be shorter and catchier.
However amusingly, .us opened up second-level registrations 24 years ago, which means that any qualifying entity could have their name registered directly under .us, which is obviously recognizable, and also one character shorter, than a .gov registration. However, by that time, I believe that .gov had increased in stature so that registering governmental entities under .gov carried more certainty of conveying official status than anything under .us.
Also sadly, QR Codes and URL shorteners today sort of obviate the need to directly register the shortest possible domain name. I don't know: I was always kind of fond of the .us hierarchy, and I'm just personally sad that it's fading away.
In reality, it wasn't that simple, and a lot of those .us domains looked like line noise.
Government sites are used to distribute public information. They need something they can print on a poster/sign. Not some bogus 'logical' hierarchy.
.gov certainly cares a level of exclusionary access that isn't really true of .us. Only one entity, the US federal government, can decide to hand someone a .gov address. And generally there is few signals harder to fake or impersonate than one.
This is a bug, not a feature.
There was an effort to properly handle the .name 2LDs, but it was never resolved because there’s no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name: https://github.com/publicsuffix/list/issues/2306
So yes, this TLD’s setup is in fact pretty insane.
In a world without advertising, there's no reason why google.com couldn't also allow *.youtube.com to set cookies for it, but of course that would cause a tremendous privacy freakout. Though in practice they can and do just send every login/logout through a 302 redirect roundtrip to take care of the cookies on youtube.com.
That said I don't know about making cookies shareable across TLDs. That seems like allowing more privacy nightmares; at least today if you want to share you need complicated redirect dances that make you question if the user perf hit is worth it. I think there was some proposal for a mechanism for allowing non partitioned 3rd party cookies which seemed more sane to me, forget what the details were and if it ever made it beyond just a proposal.
Maybe it could be opt-in or opt-out via some markers at the DNS level, though? The public suffix list having to exist at all is bizarre.
Surely a better solution would involve an actual request. login.foo.com could send a request to foo.com with Origin: login.foo.com asking to set a cookie, and foo.com could make its own decision.
If you require domain wide cookies be set from a webserver on the domain apex, the domain apex (for high volume destinations) needs to be set up for high volume webserving. High volume webserving often means at least geotargetted DNS, maybe a CDN, often anycast in today's reality.
Back in the day, it was common for high traffic domains to run their DNS with a normal DNS server and then delegate (typically via CNAME) high volume subdomains off to a 3rd party DNS server for geotargetting (usually Akamai DNS, but there were others). But you can't CNAME the apex domain away. You'd have to delegate the whole domain to your DNS provider and then you have no way to manage an outage of your fancy DNS provider. Especially if you go back to the days where NetworkSolutions did a single daily zone update for .com ... if you wanted to switch to a new DNS provider for your domain, you would submit the change request and hope it happened in the 24 hours, but sometimes you'd miss the window (or there would be some process error) and it would happen much later.
Less of a problem in today's world, where registries typically update the glue records in near real time (although many TLD servers have a 2 day TTL for glue, so you can't switch off a dead provider very quickly) and lots of domains seem comfortable with delegating the whole thing to their CDN.
That said the dumbest thing with cookies is not sending their attributes in the cookie header which makes it impossible to distinguish expected cookies from tampered cookies set by insecure subdomains. __Host prefix is basically a workaround for this but took more than a decade to get into browsers. Samesite similarly was bolted on after the fact.
Cookies aren't the only web security feature that follow sites instead of origins but they are the only one that was clearly designed without thinking through the consequences.
And that's one reason why the public-ness of a hierarchy level belongs on a DNS record on that level and not some separately-distributed side list.
I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP.
Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...
Really hard to understand why that hasn't happened yet!
There would be no issue at all if Verisign, or maybe Global Name Registry, decided to stick to the 3rd level registrations exclusively. Problem is, the chucklefucks over there decided it was a good idea to also hand out 2nd level registrations. Those 2nd level registrations outnumber the 3rd level registrations by an order of magnitude, so the PSL decided to just let joe.smith.name and john.smith.name share cookies. Which, IMO, was not a good decision, but it is what it is.
Yup. The original statement was dangerous FUD which should be urgently corrected.
Needing to be familiar with all the special cases (like the VERY special case of x.y.name which I previously knew nothing about) kind of ruins everything and introduces yet more security risk.
I'm sorry, what ? Admit ? Confusion ?
In the case of .co.uk it has been around since 1996. HN is a technical forum, most people here should be well aware it is a serious SLD. I honestly can't believe it even needs clarifying.
Hell, if you use AWS Route 53 you'll see they use co.uk as one of their nameserver suffixes[1].
[1] https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/SO...
It's been around for years. I seem to remember this issue coming up around 2001 where originally .name was for third level registration (i.e. john.doe.name) and changed to second level it a few years later and caused some problems... https://publicsuffix.org/ talks about it in light of architectural limitations of domain names.
> can Joe set a cookie on all of .smith.name?
That can happen. I seem to remember ancient browsers made it so .name (and other non-generic TLDs) required three periods. I think country code domains and new generic TLDS caused the browsers to change it.
It's pretty screwed up, but a lot of the people with .name domains have had them for a very long time. Sad to see them all lose their identity online that way.
Imho email is missing a feature for nameless email addresses for when somebody just buys their full name as a domain name. If I get "firstname-lastname.name", having the email be "firstname@firstname-lastname.name' kinda ruins it.
they'll grumpily sign up to gmail just so they can get a verification email, and that'll be all it gets used for. Messaging their irl friends will be done in apps like Discord.
lol I ran a sizeable team around 2020 and I had to educate a couple of our new hires straight from college that they actually needed to check their work email, after they missed important HR related stuff and they had just completely not realized it was an avenue for company communication, with an assumption that everything was available on our heavily used slack.
If email was a commercial product, the company would have done something about that. Email died because it was an open platform, with nobody to address this systematic issue.
I've successfully renamed an old account with an email address I no longer liked. It works quite well on everything 1st party, but does have the potential of causing issues with OAuth on poorly-coded websites that key on email instead of user ID (ie. most of them). You do get to keep your old email address though, so it still ends up working fine in practice.
https://publicsuffix.org/
edit: apparently not all second level domains in .name are public suffixes anymore, so a wildcard addition wouldn't be correct.
It has to be a money problem. Something they want to do will be simpler if this is no longer a quirky registry. And they know they'll get the money back that they lose from not having bob.smith pay -- probably by throwing all the "last names" once registered this way into some "premium name" bucket and selling them for $1000 and up instead of the ~$10 that zyzgdhaf234.name fetches.
In fact, I'm not sure that scheme isn't the reason itself.
Different from .co.uk.
> The first appearance of reversed DNS strings predated the Internet domain name standards. The UK Joint Academic Networking Team (JANET) used this order in its Name Registration Scheme, before the Internet domain name standard was established. For example, the name `uk.ac.bris.pys.as` was interpreted as a host named `as` within the UK (top level domain .uk)
from the History section of https://en.wikipedia.org/wiki/Reverse_domain_name_notation
But I don’t know if uk.co.somethingsomething did or did not exist at that time. Or if it was only introduced after the Internet domain name standards we use today existed and so was .co.uk from the beginning.
Back then the code in various pieces of software had hand-written exceptions for domain processing. The joke was that all Computer Science departments in the UK (uk.ac.university-name.cs) ended up in Czechoslovakia.
.uk was opened up relatively recently.
If .gov and .mil and .com make sense, then .gov.cc and .mil.cc and .com.cc make sense.
Of course, I think having more than one non-cc TLD was a mistake, but that's just me. If it makes sense to have topical TLDs for international and US institutions, it make sense to have national ones.
Nominet and therefore .co.uk has been around since 1996.
.co.uk is not going anywhere, and neither is Nominet.
The only "problem" is the original poster did not do their homework. I suspect they were inferring `uk.co` which is a completely different kettle of fish. The original poster should urgently correct their post.
I don't have some nefarious desire to scare people away from the TLD of their choosing. Really I'm bringing it up to be like "why would you even, like, want some 3rd rate domain instead of getting a .com" so I don't think there's anything to correct
It's not reverence? I think that you're missing that it was a requirement. Basically every country (that followed ICANN's original rules) does this: .com.au, .co.nz, .co.jp, .com.mx, .co.ke (+ the org/net variants for each country)
The US is the only country where registering .com was allowed by ICANN (and not .com.us or something).
ICANN relaxed these rules in the 2010s I think, so now you can register 2LDs at most/all of those country TLDs.
Its not hard to tell for things like ".uk" or other serious suffixes.
It only (maybe) becomes hard(er) to tell for all the vanity ccTLDs that came along in the 2000s. But even then 10 seconds on WHOIS and Google should fix any doubt.
> about the reverence of `co.uk`
What are you on about ? Lots of other countries do it too. Japan is one example given already here, but there are dozens. It is very common practice for country tlds.
5 seconds on wikipedia or google would have stopped them spreading completely dangerous FUD about .co.uk.
Implying lack of trust in `co.uk`
Implying `co.uk` may suffer the same fate at `.name`
Complete FUD.
For instance, in Serbia, there is a similar scheme to UK: .gov.rs, .co.rs, edu.rs, but also in.rs (for individuals) and top-level .rs. So someone has registered "iz.rs" and offers free subdomains to individuals.
The fact that there is implied hierarchical trust is what the problem is, and keeping track of individual rules for each TLD is prone to errors.
;)
(Edit: although I should add that I'm hopeful that things have improved there over the last few years).
No.
Oversimplified summary:
There was a period around 2010 when the management at the time wanted to follow a more commercial route with various unrelated "investments".
Nominet members made it impeccably clear in a very loud manner to management that it would not be tolerated.
Management insisted on a vote which they inevitably lost.
Management departed.
TL;DR Don't piss off Nominet members
ICANN, a 501(c)(3), proposed to remove the price cap on .org registration, commonly used for non profits, so PIR, the 501(c)(3) registrar for .org, could then announce it planned to sell .org operations to private equity investment firm Ethos Capital.
Thankfully the overwhelming response caused the proposal to be scrapped.
https://news.ycombinator.com/item?id=48426337 was apparently the final straw.
I wonder how long that'll last. If the regulators in Califonrnia keep forcing them to act in the public's interest, won't they just move to a more favorable jurisdiction?
You only get a first name and a last name and a .name though. You can't be robert.louis.stevenson.name - just louis.stevenson.name.
(Incidentally, this was a Claude suggestion. The change only took a couple minutes but figuring out what mechanism in the code could do this would have taken me a lot longer.)
Well, it's still not affecting me, personally, but wow, seeing articles like this makes it feel just a tiny bit more real.
In short, AI identities were just a happy accident that comes with the system/architecture. It's not tied to AI at all.
But if anyone is interested in talking about what we're doing more, happy to connect at hn@sepositus.com.
Alice registers `alice.dntls` and Bob registers `bob.dntls` on the DNTLS network. During the registration process, they generate PQ key pairs that are registered along with the name. Alice's and Bob's name are hashed before being stored on the network. Bob knows Alice's name, so he can perform the necessary hash computation to look up Alice's public key material on the network. Likewise, Alice can do the same for Bob.
Bob wants to send a file to Alice. Bob takes his name key and signs the document with it and sends it to Alice. Alice looks up Bob's public key material on the network and verifies the signature.
Bob now stands up a new website, but he only wants Alice to access it. He sets up a standard HTTP server but slightly modifies it to be "DNTLS native." He does this by requiring mTLS on incoming TLS connections. The connecting party must identify themselves with a signed certificate. Each name has what we call a "name record" that allows publishing arbitrary metadata signed by the name key. Bob publishes a standard "HTTP" record in his own name record that points to the IP address. Alice now goes to connect to Bob's website. She opens her "special" browser and types in bob's name. The special browser looks up Bob's name record, finds the published IP address, and attempts an mTLS connection. Bob's server is configured to _only_ allow connections from Alice. Since Alice signed her TLS connection with her own name, the connection is allowed, while every other is rejected.
Alice now wants to communicate with Bob's agent. Bob publishes a subname called `agent.bob.dntls`. In that subname's record he publishes an A2A packet that contains the information for connecting to his agent. But, like the website, the agent is listening on a TLS connection that rejects anyone except Alice. She uses an A2A tool to initiate a connection using her name key and is allowed to make a mutually secured connection to Bob's agent.
Bob wants to connect to a VM he purchased that runs the website. He configures SSH with his name key as one of the recognized users. His SSH connection simply leverages the name key to authenticate him to the machine. But he shares the machine with another person and wants to share a secret with them. So he creates a SOPS encrypted file with his name and this other person's names as the only recipients. They both securely access the secret using their respective name keys.
I'll leave it there, but hopefully that's descriptive enough.
Names are valid for one year and range from $10/yr up like current domain names. Letting a name expire opens it back up to being registered again.
We have quite a few other "tools" in play behind the scenes that make name trading/squatting extremely impractical, but I won't go into those details here :)
but you lose the ability to have short domains.
also until such a time that pkarr is widely adopted, you are better off using .onion domains anyway. it becomes a question of requiring custom DNS client vs. Tor browser.
both approaches use a DHT.
What's to stop someone from doing that, and keeping the status quo? Sure, it might be expensive, but pool together a few frasers for the initial buy, and make the money back on the sublets.
For all we know, this is simply the first step in a series of moves for Verisign to better monetize the .name TLD in some novel fashion.
My evidence for this is that Verisign's own arguments for terminating the third-level domains are highly dubious. They claim that the third-level domains are too hard for them to manage. Bollocks: there are only 22,000 of them in use. That is a VERY small database that practically fits on a calculator and I refuse to believe that any manual labor around it is an outsized burden compared to pretty much any other semi-popular TLD. The second claim is that "the majority of those are not in use." Okay, if that's true, then where is the management burden coming from? That means tens of thousands of people are giving them money and getting nothing in return, isn't that the definition of an ideal business model?
It just doesn't pass the sniff test.
And finally, having read both of the linked documents, it sounds like people who have registered their .name for years in the future are not getting their money back. Are they likely to pay a second time, to a sub-registrar with no history?
Restrict future 3rd level registrations, offer a path to upgrade a 3rd level registration to a 2nd level registration for those 2nd level domains with a single registrant and the burden will decrease over time.
The .name scenario is even worse. One domain gives you access to tens of thousands of users email. It seems like a privacy nightmare.
I’m not sure how future auth and privacy will work, but my child lost a tracfone phone and some mixup had separated it from my account. There was no way to recover the number. If that was my personal phone, how difficult would it be to restore banking, medical, and government access to things that assume I’ll always have that number.
Doing the same with personal email seems like too big of a risk.
At the time - before the explosion of new gLTDs - third-level .name domains were advertised as the 'correct' domain to register for individuals wanting personal email addresses.
(Update: as it happens… https://news.ycombinator.com/item?id=49548452)
Personally I like having a custom domain as I like the idea of being able to move between providers. So far, over the past decade, I've hosted my email with Google, Fastmail, Hey.com and then Fastmail again. I like being able to move it around if I find one provider better than another. Others won't care, that's fine too.
To me, the risk these registries screwing me over is smaller than Big Email deciding I broke their ToS and shutting down my account.
I wouldn’t use these novel TLDs either.
If you walk around all day with your wallet in your pocket, it might fall out and you'll lose it. Would you like me to hold onto it for you to make sure that doesn't happen?
On the other hand, it's email. I was at a hospital to do a blood draw, and needed them to receive an email (insurance info). I sent them an email from my Gmail. We wait 4-5 minutes. I notice they're checking an office 365 outlook. So, I re-send the same message from my @outlook.com email. Arrives instantly.
Deliverability between MS and GOOG is normally really good, and even that wasn't working right that day. My self-hosted email server being able to deliver to them reliably every time is hopeless. "Big Email" has made it excruciatingly painful to not be on sending from one of their platforms, unless you're one of the big 5 or whatever platforms that send bulk email or bulk transactional email. The SendGrids, Amazon SES, etc.
But also, even if you're self hosting on a server in your basement, you can still use SES to deliver your mail. Delivery is not an issue here.
I used to think this, until I inadvertently let a registration fail to renew because I didn't update my expired credit-card's billing details with NameCheap - they did send me automated emails about it but I missed them, unfortunately. Their grace-period is only 30 days and I didn't notice the problem until 45 days had passed when my domain-name was bought-up by a spam-site-scammer and redirected the site to a porn/virus-downloader site (yes, those still exist).
I paid $1500 (uugghhh) for the UDRP process to get the domain-name back ($1000 UDRP fee, $500 for the lawyer to do the paperwork), and the UDRP panel ruled against me: their response reasoning made it clear that they never actually looked at my submitted evidence - and unfortunately that $1000 is nonrefundable, gaaaaah. I still haven't gotten that domain-name back. (I will say that my previous other UDRP cases all ruled in my favour; I don't know why/how I somehow drew a crappy arbiter in this case, I'm just vexed that they can rule against me without any right to appeal; I expected better).
I use a prepaid provider. If at the day of the renewal there is no money "in the bank" they immediately release the domain. So yeah, I treat their reminders with priority. I really should change providers...
Never dreamed that such a supposedly durable thing would just disappear. How hard is it really to preserve a global resource like this that exists only in software?
Many years ago I wrote articles bringing attention to the negative effects of Verisign's SiteFinder [1] - if you don't remember this, it's when Verisign hijacked NXDOMAIN by redirecting any unresolvable domain to a site they owned and controlled.
[0] https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2... [1] https://en.wikipedia.org/wiki/Site_Finder
The ambiguity is a feature so they can do whatever they want. We all know it's bullshit, but it gives the parties involved the ability to disenfranchise one group to benefit another while claiming they're following the rules.
> Changes to the life-cycles of domains is a question meant to ask if this seeks to modify the life cycle policy, which is a separate type of change from termination of the service as a whole. I.e. this does not seek to change the life cycle policy, it seeks to terminate the service offering completely - making the life cycle policy irrelevant.
Did buy https://ycombinator.us
Didn't buy https://ycombinator.co.uk
https://ycombinator.de
What useful functionality is there in selling these domains?
Expiring domains is bad for the web and selling them to someone else is as terrible as the article makes it out to be.
Short-term, it might seem like it would make sense for domain registrations to be permanent, but long-term, it introduces at least two insurmountable problems:
1. Unless some other cleanup mechanism is in place, eventually (like, hundreds of years into the future) domains will need to get longer and longer as people who owned old ones disappear and new people need new ones.
2. The infrastructure costs (while nominal) to keep existing domains functioning would not be sustainable in perpetuity without relying on the assumption of more and more domains always being sold.
That said, my domain is simply unusual.name, and everybody in my family has email addresses in the form first@unusual.name. So this is a no-op for me, and I gather www.unusual.name will also continue to work, since I own the 2nd level outright.
I feel that I more trust some corpo (Google, etc) that one particular person.
I don't imagine setup where you can effictevely guarantee them full privacy.
Some people in my family use it as their main address, others don't, it's entirely their call.
But yes, ultimately I control the domain and could be nefarious if I wanted to. But there's a certain baseline level of trust as a family, I'm reasonably certain my wife won't poison the milk in the fridge and she's reasonably certain I'm not going to read her emails.
https://support.google.com/accounts/answer/3036546?hl=en
I believe this is a very common setup: the "computer wizard" kid of the family manages the computers for the whole family. Not just emails, they have access to the whole computer (and have to fix when it breaks).
But it hardly needs to be difficult. If you're running dovecot and postfix on a server somewhere then yes, family is screwed. But it's simple to use either some mail forwarding service that you pay for with a credit card, or something like fastmail (etc). Leave 2 pages of instructions for how to log into and renew the domain (print the QR code used for the 2fa enrollment!) and how to log in and pay for whatever the underlying services are. Place in a binder and label "Family.Name Email Management" and put it with your other important documents.
But more seriously, my domain and VPS is on auto-pay, so it doesn't just shut off the day I die. My survivors will have plenty of time to back up their emails and do whatever they want with them afterward.
Plus, the password for my computers and keychain is in a safe-deposit box if they feel like handing it over to a trusted tech-savvy friend of the family to shut down properly.
It made sense to us because our starting point was an email service letting people share lastname.sometld, but we never got close to as many registrants on .name as we had users on the webmail service (we had a couple of million accounts on that when it was sold to one of Marc Cubans companies for a relative pittance in the aftmath of the dot com bubble bursting)
"2.1. What effect, if any, will the proposed service have on the life cycle of domain names? None. There will not be any effect on the life cycle of domain names.
...
2.3. Explain how the proposed service will affect the throughput, response time, consistency or coherence of responses to Internet servers or end systems. There will be no effect on the throughput, response time, consistency or coherence of responses to Internet servers or end systems."
My registrar is also suggesting that they are going to just keep the money I pre-paid for years of registration, which is a minor annoyance compared to the loss of my entire online identity but an annoyance nonetheless.
Since ICANN is a non-profit that is required to operate in the public interest I do hope there can be some pushback on this. I will be writing to the CA AG myself.
How is this possible? I thought there was a 10 year limit.
> Registry Expiration: 2036-01-29 00:00:00 UTC Updated: 2026-09-03 08:12:27 UTC Created: 2002-01-23 14:41:45 UTC
[1] https://blog.asmartbear.com/free-markets-bad/
Gotta wonder what other possible disasters introduced with gTLDs.
> "will increase efficiency for the operation of the .name TLD."
What a preposterous excuse -- especially for something already up and running. Sounds like they probably want to change the backend in some way - or adopt some kind of off-the-shelf software - which doesn't jive so well with this unique TLD, and they figure "Ehh, fuck 'em, let's just pull the plug on these tens of thousands of people."
It’s incredibly one sided. The registry gets to cut costs and the detriment to registrants is extreme. ICANN is supposed to act on behalf of all participants.
The flagrant disregard for DNS stability in this case is jaw dropping.
> 3.6. Have you communicated with any of the entities whose products or services might be affected by the introduction of your proposed service? [→ No.] If so, please describe the communications. [→ Not applicable.]
Gotta say that the entire form feels not applicable. The proposed service is the discontinuation of an existing service. I see from their website that other similar things do the same, but it feels broken when so many of the questions become nonsense.
> 2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
> None. There will not be any effect on the life cycle of domain names.
If they're dropping existing domain names, that seems like it has an effect on the life cycle of those domain names. I suspect I must be misunderstanding what they mean by that question, because it otherwise seems like it shouldn't have passed basic muster.
IMHO, this whole TLD seems kind of messed up from the start: https://en.wikipedia.org/wiki/.name
bbb.name can ONLY be registered if it is not already registered AND there are no 3rd levels registered on bbb.name currently.
https://manage.whois.com/kb/servlet/KBServlet/faq1485.html
How would that help? The problem is that he's losing access to all the accounts currently tied to fraser.name, if he is changing that he can just use any arbitrary domain anyways.
That's just my reading of the situation though. The person could now hope they're the first to claim their second-level domain once it becomes up for grabs, but there's probably a dozen other people with a fraser subdomain that would want the same, plus however many hundreds of scalper scum. Probably the best you can hope for is that whoever does get it, has the decency to honor the original third-level domains for a reasonable fee
You can. Anyone can register a .uk, and you don't need to own the .co.uk
If they've recently changed that and I'm misreading Wikipedia, that doesn't change the underlying point that the answer was "you couldn't". Otherwise I've grossly misunderstood the whole post and how verisign is proposing to cancel this person's third-level domain
So the argument goes, society as a whole gains more if we prevent anyone from owning `fraser.name`.
A legitimate alternative though, is to register `FIRST-fraser.name`
With it you got an email redirection from firstname@lastname.name to the address of your choice. At some point this feature was discontinued (I assume when VeriSign took control of the .name TLD), a bit after it was decided (again by VeriSign) to allow registering first level .name domain. My main email address stopped working from one day to another without me being warned in any way.
When this happened I've emailed VeriSign and my registrar at the time, and tried several time since then, to be able to register the first level domain I'm the only one using, but they categorically refuse, despite recognizing that a single subdomain has ever been registered. They kept saying that I could just let the domain expire, wait for the grace period, and register it once it's liberated, hoping that no one does it before me, and without any solution for the downtime in the mean time…
And now this… fuck VeriSign -_-
EDIT: seems like Ethos Capital private equity firm wanted the .org registry, and Xavier Becerra (Attorney General of California at the time) wrote a letter that played major role in transaction being rejected
> Dear Messrs. Botterman and Marby:
>
> I urge ICANN to reject the transfer of control over the .ORG registry to Ethos Capital.
> The proposed transfer raises serious concerns that cannot be overlooked.
(from https://itp.cdn.icann.org/en/files/correspondence/becerra-to...)
First, that a legit dealer could/did(does?) sell third-level domains at all (Verisign, no less) Second, that the top-level is staying available, allowing for second-levels to be bought/sniped like you mention.
If you do lawyer up and need help with legal fees, I think this would be a worthy cause.
Should I rush to reserve y.name so my email address and personal website can stay online?
Overall this seems like the right move, either they all are trusted or none.
> In April 2019, ICANN proposed an end to the price cap of .org domains and effectively removed it in July in spite of having received 3,252 opposing comments and only six in favor. A few months later, the owner of the domain, the Public Interest Registry, proposed to sell the domain to investment firm Ethos Capital. After intense criticism from nonprofit groups and significant figures in Internet history, the proposal was scrapped.
Surprisingly not by Verisign, who gave up .org in 2003.
it'd fit like a PE firm focusing on chemical weapons
Also, all common names with any of those prefixes have been registered a long time ago.
Again, you're security is only as strong as your DNS.
This is ridiculous.
>2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
>None. There will not be any effect on the life cycle of domain names.
>2.2. Does the proposed service alter the storage and input of Registry Data?
>No. There will not be an alteration to the storage and input of Registry Data.
This sounds wrong? Is this just a knee-jerk form-filler reaction? It seems to me that the admitted "Upon discontinuation, no new third level domain names will be registered and existing third level domain names will be terminated."
In general this sounds like a grotesque misplay that is wildly uncharacteristic for the entity behind the timeless .com
It has been established that national identifiers are protected by it, and a domain works as a sort of international identifier, in this case a personal one.
No one is obligated to give you a domain, but by contracting an obligation to provide that identifier until 2040, they would at least be liable for those damages, but there's an argument that depriving you of an identifier already granted is a more fundamental violation of a right to a name, an identifier and recordkeeping of them.
So, where is our fully decentralized TLD alternative, free of ICANN or any central authority to handle how we grant names by conventions, without any money scheme in the game that attracts malevolent actors moving only through greed strings?
Also, this time let’s make it like usenet, so "person:named:Neil Fraser" or even "::Neil Fraser" (harder to type but less culturally entangled into English).
We can all edit our hosts file.
The problem with a lack of a central authority is domain names are most useful if they follow the highlander principle. There can only be one neil.fraser.name ... otherwise it's not usable for routing traffic if every webserver a Neil Fraser runs uses that address. (Yes, there are useful ways for one name to resolve to different webservers, but almost always those are webservers under at least loose control of a single entity or very exceptional cases)
But from what I remember, they fucked up the pricing function and it got overrun by domain grabbers.
...minutes?
* or arguably the same amount or less; for additional context: the author is an ex-Googler
”Greetings from ICANN Global Support.
I am sorry to hear you are experiencing this domain access issue after your registrar's transfer. I will happy to provide you with relevant information and guidance.
Please note that, ICANN accredits companies as domain name registrars and works to ensure contractual compliance with the terms and conditions of the 2009 and 2013 Registrar Accreditation Agreements (RAAs).
ICANN does not provide domain name registration or manage domain accounts. As a result of that ICANN is not able to perform domain management for you.
If you need help to access and manage your domain, you will need to contact your domain service provider or registrar for assistance.
You may check who your registrar is by doing a domain search at lookup.icann.org.”
Absolutely infuriating
But, assuming that Verisign can’t keep third level domains (as a DNS implementer, I don’t think third level domains is a huge deal; see thread below):
* Third level names where only one person has the second level domain should be transferred to whoever owns that single third level name.
* Third level names where multiple people have the same second level domain should be put up for closed bidding: Only current owners of .name domains with a given second level domain name (e.g. last name) will be able to bid for the second-level domain. So, if one has john.smith.name and joe.smith.name, Joe Smith and John Smith will be in a bidding war for smith.name.
If the issue of .name not being in public suffix is a real issue, Verisign can handle that by disabling new third-level .name registrations, and provide Public Suffix with a list of those registrations (just send all the owners a privacy notice, making it clear that the existence of the name will be made public for security reasons). More reading: https://github.com/publicsuffix/list/issues/2306 (There seems to be issues with this list being too long to keep in the Public Suffix because there’s too much software out there which can’t handle it. That seems strange to me: Even here in 2026 where RAM costs far too much, Deadwood can store a list of 240,000 blacklisted entries in under 10 megs; there are about 22,000 three-level .name domains and I could store that list in a way that could be very quickly looked up in about a meg of memory)
Now, personally, I think Verisign can keep these messy third level names, and are doing things this way so that Neil Fraser has to compete with every single 2-bit cybersquatter out there for the rights to fraser.name.
As an aside, it’s trivial to have DNS servers handle multi-level domains without having to have a zone file for every level; e.g. https://this.is.a.long.name.maradns.org works, and there’s no zone file for name.maradns.org, long.name.maradns.org, a.long.name.maradns.org, and so on.
Also, since people have brought up the “org fuckery” without providing details: https://bluecatnetworks.com/press/the-org-domain-sale-explai...
You know dang well if .org was owned by an investment entity, they would had jacked up the prices as much as they could get away with.
What they should do, is nothing.
As a DNS implementer, the action plan is unnecessary. There are, what, only 22,000 or so .name domains. One can write code to do two lookups for firstname.lastname.name: If firstname.lastname.name is found, return the NS delegation. Otherwise, if lastname.name is found, return that NS delegation. Finally, if neither is found, return NXDOMAIN.
One argument is that this is hard to implement in the real world (it’s about one day, at most one week for a skilled DNS developer to pull off; probably half a day to be honest, and yes I have written code like this), so then yeah if that’s a real concern let’s have a closed auction. I’m opposed to the auction, based on my experience that this isn’t hard to implement.
If it’s an issue, just stop all new firstname.lastname.name registrations, and only allow lastname.name new registrations. Then we only need to deal with this corner case for about 22,000 domains, which we can keep in a special hash and would take about four megs to store.
I don't know what that history is, but did it really make a tld used by only 22k people more appealing?
https://www.icann.org/resources/pages/name-2014-03-03-en
While changing email is inconvenient, I don't understand the point about IoT devices. IoT devices should not depend on the Internet at all for obvious privacy and security reasons. If you are using IoT devices with "cloud" accounts, then this is a blessing in disguise. Put that garbage in the trash and rebuild around HomeAssistant, Zigbee, RTSP, etc. I find it hard to believe that someone hosting their own website would fall for the cloud IoT scam.
For instance, I own a .house domain that I use for a bunch of stuff that I've programmed. It would be a pain in the ass to go change that domain out. Now take that to next level and you're a business that's deployed a few thousand devices that need to call home.
I guess all this is to say - IoT doesn't just mean cheap botnet honeypot IP cameras. Take a look at https://www.balena.io/cloud for instance
Imagine he's set up some IoT devices at his parents' home, and those devices use services that he hosts somewhere on the internet. It would be silly to hard code the IP addresses in there, right (unless he operates his own ASN)? So he would use DNS to allow those devices to find his server(s). This would be the case whether the servers are at his home, at his office, or in a rack at a data centre.
It's a pretty bizarre exception to the normal, intuitive ways that domains work.
I'll admit that it's a crappy situation and I would be frustrated in his place. But if I were in his place, I probably would have also thought it prudent to have a backup plan.
What exactly is non-standard about an ICANN-approved TLD? Yes, the multi-level structure is a little odd, but given that ICANN approved it in the first place, one has a reasonable expectation that they would work as advertised.
Even though .science was launched in 2014 (more than a decade ago), I still consider it a non-standard TLD and still deal regularly with difficulties around its use. (For instance, you wouldn't believe how many online services reject email addresses than end in .science because they use regexes that exclude TLDs with 7 letters.)
Likewise, I've registered .lol and .fun domains but never would have assumed that just because they're available now, they will be available in perpetuity.
In that sense, .name as a third-level TLD is even more non-standard, because the standard way domain registration works is by choosing a single "second level" domain name, then adding subdomains.
Why wouldn't you assume this?
> the standard way domain registration works is by choosing a single "second level" domain name, then adding subdomains
The entire ccTLD systems of the UK, China, Germany, France, Japan, and many others would beg to differ.
Whereas with .name, you are choosing what appears to be a subdomain, followed by what appears to be a domain name. But under the hood, you do not own all subdomains for that domain name; you own only the combination of first_name.last_name.name.
(And yes, I am aware that you can also register last.name by itself, but only if there are no third-level domains using it, so for practical purposes it doesn't change my question above. Plus, when the OP originally purchased his domain, you could only buy third-level domains for .name.)
1) benedict.cumberbatch.name
2) drstrange.co.uk
I expect the average person would assume that for the domain 1, .name is the TLD, cumberbatch.name is registered by a private entity, and benedict (and any other subdomains associated with cumberbatch.name) is a subdomain fully controlled by that private entity.
Whereas for domain 2, I think the average person will view ".co.uk" the same way they view ".com", even though technically it is both a ccTLD and a second-level domain.
The only people who will make the assumptions you state are people who are tech-savvy enough to be familiar with those concepts, but not well-versed enough in them to understand the nuances we’re discussing.
And none of this does anything to advance the argument that .name is somehow nonstandard.
Uh, 99% of people would assume a .name address is a scam. Hate to break it to you.
For the first couple of years of .name's existence, it only allowed registration of third-level domains, and the ability to register second-level domains was added later (and only if no third-level domains existed for that second-level domain).
The author is in no way at fault here, and I don't think I would have assumed there was a heightened level of risk if I were him.