.name Termination
Posted by pavel_lishin 5 days ago
Comments
Comment by nneonneo 5 days ago
Comment by p4bl0 5 days ago
Comment by jaggederest 5 days ago
I remember back when we had to write mechanize scripts to drive a browser through the renewal process, because if you had dozens, hundreds, or thousands of domains there was no nonmanual way, especially if you wanted extended verification or something silly like that.
So what I'm saying is, agreed and that has always been true.
Comment by account42 4 days ago
Comment by jaggederest 4 days ago
Comment by lqstuart 4 days ago
Comment by jaggederest 4 days ago
Comment by SpaceNugget 4 days ago
Comment by jaggederest 4 days ago
Part of the explosion was that domains were not just in one TLD, they were bobfoo.com bobfoo.bar bobfoo.xyz and in many cases regionalized to bobfoo.co.uk or whatever. It wasn't "domain hoarding", because if you registered bobfoo.info you'd just get UDRP'd by corporate anyway, and nobody really wanted domains of the form somelongnamebobfoo.com
This was also before something like LetsEncrypt where you could automatically generate certs for programmatic usage, so they were all done manually.
Comment by ShinyLeftPad 2 days ago
You'd be surprised
and renewing annually is a great way to accidentally forget some of these and let someone use them to hack your customers
Comment by AznHisoka 4 days ago
Comment by jaggederest 4 days ago
Comment by arcfour 4 days ago
Use the system as it was intended, people!
Comment by jaggederest 4 days ago
Comment by dpark 4 days ago
Comment by skywhopper 4 days ago
Comment by thayne 4 days ago
Comment by collabs 4 days ago
Sadly neither our world not its legal system is built on common sense.
Comment by bigbuppo 4 days ago
Comment by palemoonsinking 5 days ago
The main problem with the Internet today is that we didn't destroy ICANN when they started this TLD sell off crap. A replacement institution may have at least told Verisign a TLD they can't run transfer to someone who can meet its promises can only be destroyed.
Comment by p4bl0 4 days ago
Also, .name filled an actual need for general non ccTLD: companies had .com, organizations had .org, Internet related stuff had .net, there was .gov, .edu, .mil, and ccTLDs, but nothing made for individuals. It filled this use case, it actually made sense.
Comment by pbronez 4 days ago
Comment by devrand 4 days ago
Comment by syncsynchalt 4 days ago
Comment by simiones 4 days ago
That's a silly idea. While there are laws that ensure to a decent extent that there is a single company called "Google", so that it's relatively unambiguous who `google.com` should refer to, there is no uniqueness whatsoever to personal names. There are likely hundreds of thousands of people called "John Smith", so the FQDN `john.smith.name.` would not really tell you anything.
This is without even going into the fact that "first-name.last-name" is culturally specific (though, to be fair, a large proportion of cultures in the world use this format).
Comment by vidarh 4 days ago
There aren't laws to ensure that. Within specific jurisdictions, sure, but not globally.
A lot of companies also don't trade under their full name. Apple, famously, wasn't founded as Apple but as Apple Computer, and was only able to rename after achieving a deal with Apple Records.
The lack of more namespaces also led to things like nissan.com being owned by Uzi Nissan (and now his family, I assume) rather than the car company.
While you're right that there are many duplicates, one extra TLD still broadened the namespace a lot, and the most important part of the idea was that by giving people less of a reason to register <lastname>.com or <lastname>.cctld, we'd give far more people the option to get <firstname>@<lastname>.name as an email address.
(The cultural aspect is irrelevant - it was not enforcing a specific order. If people wanted to register lastname.firstname.com, nothing would stop that)
By the time we applied for .name we actually had experience running a webmail service where people shared ~60,000 domain names, and had ~2 million accounts on that, and we'd done extensive modelling before acquiring those, and as a result at the time we probably had better data than anyone on the distribution of names worldwide.
What we seriously overestimated (every applicant overestimated how popular the new TLDs would be, but the generic ones, generally did better) was how many people were in the intersection of people who'd figure out how to buy a domain name and people who wanted firstname@lastname.name as an e-mail address.
Comment by simiones 1 day ago
Many trademarks are indeed more or less global.
> A lot of companies also don't trade under their full name. Apple, famously, wasn't founded as Apple but as Apple Computer, and was only able to rename after achieving a deal with Apple Records.
That's irrelevant - Apple Computers owns the Apple trademark (for certain industries).
> The lack of more namespaces also led to things like nissan.com being owned by Uzi Nissan (and now his family, I assume) rather than the car company.
It's not perfect and not guaranteed to be unique, yes. But people's names have many orders of magnitude more collisions.
> <firstname>@<lastname>.name as an email address.
No, you'd at best get `??@firstname.lastname.name` as your email address. Which, again, is irrelevant, as it's impossible to say which of the many thousands of Firstname Lastname people this might belong to.
> (The cultural aspect is irrelevant - it was not enforcing a specific order. If people wanted to register lastname.firstname.com, nothing would stop that)
I wasn't referring to a specific order, but to the cultural idea that people have 1 firstname and 1 lastname. In Spain, for example, people typically have 1 first name and 2 last names - but you couldn't get `a.b.c.name` as an address. Having a first name, a middle name, and a last name is also very common.
There are also cultures where people simply have one name, not first + last. For example, a person's full legal name in Tibet might just be "Woeser".
Comment by vidarh 15 hours ago
And the vast majority are not, so this has no relevance.
> That's irrelevant - Apple Computers owns the Apple trademark (for certain industries).
And yet you yourself concede in this very same statement that it is not absolute. Even with one of the most famous examples from one of the largest companies in the world.
> It's not perfect and not guaranteed to be unique, yes. But people's names have many orders of magnitude more collisions.
For most people our data was very clear that for most names the number of collisions are in fact relatively low, further significantly mitigated by the combination of nicknames and ability to use middle names. Very few last names are highly frequent, and very few of those with common last names have an intersection of a very common first name and a very common last name. The vast majority of people fall in a long tail of last names held by a few thousand people, and first names held by a few thousand people.
For the webmail service that preceded .name, the vast majority of the two million accounts registered were for names for people who would have no way of getting their firstnam@lastname.<tld> addresses without it because of colissions. That some of those would not be able to get one of our addresses either because their specific combination was particularly common does not alter the objective fact that we massively broadened the availability.
> No, you'd at best get `??@firstname.lastname.name` as your email address. Which, again, is irrelevant, as it's impossible to say which of the many thousands of Firstname Lastname people this might belong to.
No, that was categorically not how it worked. I personally designed the system to handle this. We provided firstname@lastname.name e-mail forwarding to an address of the registrants choice, and provided a reference platform for registrars to support that, that I also designed, and managed the implementation of.
Given that you haven't even bothered to understand what it provided before criticising it, it's hard to assign much value to your arguments.
> I wasn't referring to a specific order, but to the cultural idea that people have 1 firstname and 1 lastname. In Spain, for example, people typically have 1 first name and 2 last names - but you couldn't get `a.b.c.name` as an address. Having a first name, a middle name, and a last name is also very common.
Spanish people are perfectly capable of using their firstname and their fathers first lastname when limited to one last name. They are also capable of using 2, 3, or 4 last names depending on context and preference. For any that wanted to use more, they had more flexibility, because they could similarly register b.c.name, and use a.b.c.name, or register any combination preferred for the last two labels and set up the rest themselves.
Same if you insisted on using your middle name. We only provided the increased ability to share among those with overlapping two last labels, but that did not change the ability to use regular DNS features.
> There are also cultures where people simply have one name, not first + last. For example, a person's full legal name in Tibet might just be "Woeser".
While you're right that exists, firstly it's a miniscule proportion of people. We collected stats on that two. If you fell in that group, your options were either to use another TLD, or use another indicator. In Europe as well, in cultures that used to use only one legal name, people would still regularly use distinguishing attributes, such as place names or occupations. In fact, both of those are the source of most legal lastnames in Europe today. E.g. my last name is the name of the farm my great great grandfather came from, and names like Baker and Smith are occupations.
There is no need to be able to be a perfect match to a given format for everyone to still meaningfully and significantly enlargen the available namespace.
This is a long way of saying you're being intentionally obtuse.
We overestimated the demand for paying for "vanity" addresses, but ability to register peoples names was not a problem - something we categorically proved with the webmail service that preceded it.
Comment by abofh 5 days ago
Comment by palemoonsinking 4 days ago
It's clear to me ICANN can say no agreement change or total destruction. You are correct that they could do something else and show every indication that they would never do the right thing and that is why they should be destroyed.
Comment by megagpt2 4 days ago
Comment by naikrovek 4 days ago
Comment by gblargg 5 days ago
Comment by asdfsa32 4 days ago
In this age, allowing domain names to be owned by other entities is almost like allowing a company business registration number or one's national id card number to be transferred to others.
I think name squatting is a problem, but it is not like that current system has solved it.
Comment by simiones 4 days ago
Comment by JumpCrisscross 5 days ago
Can someone explain why a product "registered and paid for until 2040" can be unilaterally voided like this without compensation?
Comment by toast0 5 days ago
> As your .name can be registered for up to 10 years and ownership is renewable, your .name really can be yours for life.
It seemed like there was an offer of renewable registration at least for a life term.
[1] https://web.archive.org/web/20020609132126/http://nic.name/c...
Comment by vidarh 4 days ago
Comment by jayde2767 5 days ago
Comment by account42 4 days ago
Comment by lazide 5 days ago
Comment by account42 4 days ago
Comment by lazide 4 days ago
Is it corrupt? Yes. Is there a factor making corruption inevitable? Yes.
Comment by JumpCrisscross 4 days ago
Comment by spider-mario 4 days ago
Comment by Toynbeeidea 4 days ago
Comment by layer8 5 days ago
Comment by xp84 5 days ago
Comment by dpoloncsak 5 days ago
It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com
In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com
edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule
Comment by xp84 10 hours ago
I think you meant to say "the owner of John.Doe.name does not need to own Doe.name" since .com just works under the 'normal' rules you're used to.
But it's worth pointing out that under the current system (that Verisign is destroying), no registrant owns (e.g.) fraser.name just as no one (but the registry itself) owns co.uk. So, if someone checks who owns fraser.name they wouldn't have found a scenario, for instance, that fraser.name belongs to, say, Simon Fraser University, with admissions.fraser.name belonging to some phishing site.
> I have been taught and tell my users to check the domain to verify a website is real.
Anyway, having seen enough eyes glaze over at the most basic tutorials of this sort, I'm afraid you're wasting your time. Given that this edge case is on nobody's radar, I don't think it's what's preventing 80% of Internet users from being able to get a passing score on a basic quiz on the hierarchial DNS. As evidenced by all the government entities that gave up and registered literal ".coms"
Comment by dbt00 5 days ago
Comment by ndiddy 5 days ago
Comment by dpoloncsak 5 days ago
"Here's a list of things that look like subdomains for you to treat as 3LDs instead of subdomains" sounds exactly like the solution to an edge case to me.
Comment by desas 5 days ago
The .name subdomain rules are not very well known anywhere.
Comment by necovek 4 days ago
How about all the other 200+ country TLDs and rules for non-country TLDs?
Comment by esseph 4 days ago
In the US, once upon a time, elementary/middle/highschools might be attached to something like schoolname.district.state.gov. But now, even my local area school now has a .com. It seems that older hierarchy style is falling out of fashion for smaller/shorter domains across public services, schools, government agencies, etc.
Now here it seems to be either a .com, .gov, .org, or a totally different and newer tld. Even .net has fallen out of fashion.
Comment by CoffeeOnWrite 4 days ago
Comment by pests 4 days ago
Comment by davkan 5 days ago
Comment by bombcar 5 days ago
Comment by davkan 5 days ago
Another poster raised the point of hosting services which is valid. But at present outside of that example and the above I really can't think of an example where you have a link to entity.com and you have any significant cause to verify the identity beyond the 2LD.
Comment by bombcar 5 days ago
Comment by notpushkin 4 days ago
Comment by strenholme 5 days ago
Comment by fc417fc802 5 days ago
(Aside, I always see "owned" and "bought" but you can only ever "lease" under the ICANN system as the present situation so clearly demonstrates.)
Comment by brirec 5 days ago
*: I realize that “owned” is a loaded word here, but (1) I’m referring to a registrar/issuer, which makes it yet more complicated as to how much “ownership” (de facto or otherwise) a given entity may have, and (2) I really don’t give a fuck about pedantic word choice if the meaning is unambiguous.
Comment by fc417fc802 5 days ago
> but (1) I’m referring to a registrar/issuer, which makes it yet more complicated
We're also talking about a ccTLD which makes it even more complicated. AFAIK those fall entirely under the jurisdiction of the respective UN recognized government although I don't know how strong that agreement is in practice (treaty versus something else).
So at that point I guess we've roughly got ICANN -> US federal government -> CA state government -> registrar -> private party -> sublet.
Comment by strenholme 5 days ago
This isn’t how things are done these days; names visible to the public are pretty much always in the form {domain}.{tld} or sometimes {name}.{domain}.{tld} (e.g. my own https://samboy.github.io). Registration is now done by bots and companies that spam you to death to try and get more money from you (the Internet wasn’t like that in the beach.santa-cruz.ca.us days). Domain names with multiple levels of delegation aren’t around they way they used to be.
* rented/leased/had control over/whatever
Comment by greyface- 5 days ago
The old locality domains still exist, and in many localities you can still register them today by the same "email a request to some sysadmin" process. https://news.ycombinator.com/item?id=48122635
Your beach.santa-cruz.ca.us domain is still in DNS, just with a broken delegation chain. You could reclaim it right now by setting up a nameserver at reality.samiam.org.
Comment by strenholme 5 days ago
https://beach.santa-cruz.ca.us/
Thanks for checking the zone files of the parent domain to verify it’s still there.
Comment by ndom91 4 days ago
Comment by notpushkin 4 days ago
Comment by dotancohen 4 days ago
> AFAIK those fall entirely under the jurisdiction of the respective UN recognized government
How does that work for e.g. Taiwan, where the UN recognises the mainland government's claim to sovereignty in practice?Comment by gwillen 4 days ago
Comment by fc417fc802 4 days ago
Comment by ketzu 5 days ago
I think geocities had this as well?
A lot of hosting services offer this in general. (eg render)
Tumblr? (Might not count as the control over the page is more limited. The subdomains "are" still tumblr.)
For reddits subdomains are redirects to subreddits of the same name, so I guess that doesn't count.
Comment by davkan 5 days ago
Also I would not consider the examples of tumblr and reddit to be relevant. A person's blog on myprofile.tumblr.org is still the tumblr organization. This would be true for reddit even if they didn't redirect. Reddit admins moderate content on all subreddits.
Comment by ketzu 5 days ago
When I read > I have been taught and tell my users to check the domain to verify a website is real.
I was thinking more of control of the content as "ownership" of the domain.
Comment by davkan 5 days ago
Comment by megagpt1 5 days ago
Comment by davkan 5 days ago
Comment by dotancohen 4 days ago
Or, more succinctly, when money gets involved.
Comment by veltas 5 days ago
Comment by dpoloncsak 5 days ago
Comment by veltas 2 days ago
Comment by Glide 5 days ago
Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with.
Then when you consider DNS is fundamental infrastructure and people build secure things on top of it, (ahem DNS challenges for certs), it's remarkable that anyone would want or desire edge cases.
Comment by gwillen 4 days ago
In addition to all the country codes TLDs that do 3rd-level registration, the PSL does also include stuff like github.io. (Maintenance of the list involves manual volunteer labor, so scaling is a real problem...)
(And of course the PSL wouldn't work well for the .name situation, where it's sometimes 2 and sometimes 3, and it can change over time. But that's no excuse for this clusterfuck of just suddenly dropping a bunch of domains that are paid up years in advance.)
Comment by strken 5 days ago
Comment by vidarh 4 days ago
Comment by marysol5 4 days ago
Hell DNS used to be one woman in an office who updated the zone if you e-mailed her.
Comment by marysol5 4 days ago
Comment by gapan 5 days ago
Comment by amiga386 5 days ago
What you should know, and what your browser does know and automatically applies cookie policy and colouring your URL bar, is the Public Suffix List: https://en.wikipedia.org/wiki/Public_Suffix_List
It will let you know that, for example, one does not need to own .co.uk to own the subdomain foo.co.uk.
Comment by strenholme 5 days ago
https://github.com/publicsuffix/list/issues/2306 for more discussion.
Comment by fc417fc802 5 days ago
Comment by dpoloncsak 5 days ago
Comment by iminatx 4 days ago
Comment by layer8 5 days ago
This is my theory because, a priori, 3LDs should be more profitable than 2LDs, because with 3LDs John Doe and Jane Doe don’t have to compete over doe.name, but instead can each separately purchase john.doe.name and jane.doe.name. Apparently, however, that’s not a benefit of 3LDs in practice, which leads me to conclude that john-doe.name and jane-doe.name just sell better.
Comment by QuantumNomad_ 5 days ago
To me, prior to knowing how it works, I would have assumed that either
a) john.doe.name would be a subdomain that someone who was just starting out had gotten for free supported by ads. Similar to having johndoe.freewebs.com back in the day. Not something most people would use for anything professional.
or,
b) doe.name was registered by one of the people in a family of Doe’s where every Doe is pretty closely related. For example, John of john.doe.name and Jane of jane.doe.name are husband and wife, or third cousins, or what have you. Most of the content, I would assume, is mostly about things that relate to the family. Like maybe one guy is doing a family genealogy project tracing the roots of this little cluster of Doe’s back in time and has made a site covering the findings from his research. And another one probably has some photo albums with pictures of like previous Thanksgivings and other family get togethers. In other words, nothing I would care about unless I was in their family or a very close friend of the family.
I would not have guessed that .name 3LDs worked the way that it did if I hadn’t read about it.
And on the other hand, if I saw just www.doe.name or johndoe.name, I would not make such assumptions. It would be not much different than seeing www.doe.com or johndoe.com respectively. I would just assume that .com was already taken and therefore they used .name, or that they happened to like the .name TLD because it emphasises that their site has their name as domain name.
Comment by marysol5 4 days ago
The situation in the OP is exactly what you just put as A)
Comment by iminatx 4 days ago
Go to whois.nic.name and search for neil.fraser.name, and you will find whois information for that registration. It is properly paid for and registered with Verisign. I use the same registrar, 007Names, for my own .name 3LD.
What process did you use to decide this was not the case?
Comment by QuantumNomad_ 4 days ago
1: In the blog post they wrote:
> this website vanishes in February. Despite the fact that it's registered and paid for until 2040.
So the way .name 3LDs worked, was that you had to pay for it. Not a free subdomain that’s handed out in return for the domain owner injecting ads into your site.
2: The other thing I meant by a) but that I failed to state explicitly is that in scenario a) I am imagining that doe.name and some other 2LDs with highly common last names had been bought by a third-party, similar to how the Freewebs company was owning freewebs.com and giving out subdomains of that to people. See also https://en.wikipedia.org/wiki/Webs_(web_hosting) for details on how Freewebs worked if interested and not familiar with them.
I would not have guessed that the .name registry itself was running a 3LD setup for everyone across all of .name, because it is so different from how all other TLD registries I know of manage the domain name hierarchies. For example .co.uk which is also 3LD was much more straightforward to understand and recognise historically because the 2nd level was a category (alongside a few other categories like .gov.uk, .ac.uk, .org.uk).
A few years ago, .uk opened to second level registration also, which somewhat similarly makes domains under .uk more confusing to me as someone outside the UK who knew about .co.uk and the likes because now I can no longer know if a 3LD under .uk is the way it is because it’s under an official category or not. For example, say that there is a 3LD domain manchester.autos.uk. I wouldn’t know if .autos.uk was an official category domain or not without specifically looking it up, now that 2LD registrations under .uk are open to others.
Comment by vidarh 4 days ago
In practice the demand was lacklustre.
We ran a webmail provider prior to that, with 60k domains or so, and the demand was higher for that, basically. To get a decent return out of it, you'd probably have to package it up with services on top, and our investors made us sell off the webmail service when we got .name... It turned out to be the more profitable of the two services. Doh.
Comment by toast0 5 days ago
3LDs are less valuable. In a market of many different tlds, why register foo.bar.name when you could get foobar.name or foobar.something_else
Comment by layer8 5 days ago
Comment by toast0 5 days ago
Mr. Fraser registered neil.fraser.name in 2002, when 2nd level registration under .name was unavailable; fraser.com had been registered in 1996 and neilfraser.com in 2000; he may have been able to get .org or .net, their registration dates are later, but they may have been registered and there was a gap --- my personal domain shows a creation date of 2003, but I registered it much earlier and abandoned it, but got it back after it was registered and then abandoned by someone else.
.name added 2nd level registration in 2004 and it seems to be vastly preferred. .us added 2nd level registration in 2002 and it was vastly preferred to the locality based naming. People don't want to have to educate their contacts about "weird" domains, which includes having an "extra" dot in your hostname.
Comment by VonGallifrey 4 days ago
Similarly, I recently got a scam email that linked to de-apple.com (not a domain owned by APPLE) and also used apple.com-18221.com (also not apple.com).
I reported those domains to the registrar, but apparently it is not impersonating enough to take action.
Comment by brlewis 5 days ago
Comment by joemi 5 days ago
Comment by iminatx 4 days ago
I have the .name zone file and can confirm that no records for baxter.name appear therein, so it is not reserved only because a 3LD registration has ever taken place, it is reserved proactively just in case someone with that surname might want to register a 3LD under it.
Comment by p4bl0 5 days ago
Comment by anttihaapala 5 days ago
Comment by WesolyKubeczek 5 days ago
Comment by echelon 5 days ago
.name was one of the very first expansions of gTLDs back in the very early 2000s. It's a shame that it's being shut down as it was spearheaded by the ICANN itself rather than some registrar / investor like Donuts, Inc.
I suppose this is impractical as someone has to run the registry and there are costs associated with that. But don't the domain fees cover it?
Comment by ajmurmann 5 days ago
Comment by account42 4 days ago
Comment by AtNightWeCode 5 days ago
Comment by giancarlostoro 5 days ago
Comment by xp84 5 days ago
Comment by zamadatix 5 days ago
In either case, the security concern should be directly addressed.
Comment by xp84 5 days ago
That will cost them very little in terms of cash, as I doubt that many people register that many years ahead, plus in terms of accounting, they won't have accrued that revenue anyway so it wouldn't even hurt their books. Not that a couple hundred K would even matter on the financial statements of a giant, money-printing corporation like that.
The reason why they wouldn't go the route of waiting for expiry is that at least a few have nearly a decade left, and clearly they really want these gone, not just reduced in number. By 2036 when they would finally get to that point, I doubt whatever's driving this concern would even matter.
Comment by marysol5 4 days ago
Comment by kees99 5 days ago
Comment by account42 4 days ago
Comment by altairprime 5 days ago
Comment by wlonkly 5 days ago
The problem DMARC solves is different than the problem the PSL solves, though. DMARC prevents a 3LD from pretending to be a different 3LD on the same 2LD. But the PSL handles things like what it means to make a "cross-site request" or how to handle cookies.
I mean now I'm thinking if DMARC _could_ solve that... but I don't think it could, unless I'm missing some extension or rare use case.
Comment by altairprime 5 days ago
CAA isn't a good fit as-is either, because the subdomain has top precedence over the parent domain — precisely the inverse relationship needed here. But having worked with the PSL for quite some time operationally and seeing the direction of trends away from it and towards structural DNS declarations rather than a centralized list, I think the 3LD-2LD-CRSF problem would be far better off solved with DNS than PSL.
Basically, just adding `co.uk. IN TLD subs=independent` as an SVCB record would fully deprecate the need for the PSL versus cross-site and other such ownership-changes-hands boundary problems with both A.co.uk being allowed cross-site with B.co.uk, and with co.uk being treated as equivalent to B.co.uk by password managers, cookie repositories, and so on. It would also benefit CAA by defining whether the boundary exists — if TLS is hosted by the provider, then any CAA records published by the subdomain should be disregarded; if the subdomains are fully independent, then any CAA records published by the parent should be disregarded — which simply isn't possible today without either referring to the PSL or implementing DMARC-style DNS solutions.
(I don't formally suggest that exact record as structured or written but it's sufficient a napkin sketch of what I mean by gesturing at that RFC to be considered.)
Comment by 8organicbits 4 days ago
Specifically, if I register subdomain attack.co.uk and set up a malicious WiFi router, I trick some *.co.uk cookies to get set on co.uk and then steal them from attack.co.uk by tampering with the (proposed) SVCB record.
I think the signal needs to be secure, which means DNSSEC. Adding a hard requirement for DNSSEC validation in all web browsers is a huge change from where we are now.
Comment by altairprime 4 days ago
And essentially boils it down to ‘either the client implements wire-security to a known dns server using DoH or DoT, implements dnssec to verify the untrusted response as legitimate, or the client risks being mitm’d to attacker addresses’. They ultimately sidestepped the problem by structuring it to be hints rather than guarantees and thus allowing DNSSEC to be optional, and so as of today, it’s definitely not sufficient to implement this.
I think that adding a CORS rejection to DNS — declaring subdomains independent of a TLD, that is — does not require DNSSEC, so long as clients adhere to the steps to prohibit attacker interference described. But it still asks a great deal of DNS that I’m unsure is possible today, not just in DNSSEC but in ripple-subward records that somehow tie into client responses.
More likely, I assume browsers will simply permanently end all service to the concept of subdomains at all; no cookie sharing across domains at all, no inherent cross-origin just because tld and www.tld share a few characters, etc. rather than either depending on the PSL or having to implement strange and complex DNS anything. Admins will throw their hands up about it, but the net is no longer a place where control of a TLD defines the trust of its subordinates, so it’s certainly time to rip that bandaid off if they haven’t yet.
Comment by 8organicbits 4 days ago
That doesn't sound simple at all.
Comment by DrewADesign 5 days ago
Comment by jl6 5 days ago
> Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems.
https://www.icann.org/resources/pages/about-icann
Arbitrary termination of service is not stability.
Enabling name hijacking is not security.
The answer cannot be a rival name scheme based on decentralization or crypto or whatever. Those are never going to help normal non-wizard users. The answer has to be to make the regulators do their job.
Comment by TLDRisk 5 days ago
> There will not be any effect on the life cycle of domain names. While the Requestor may disagree with Verisign’s response, the Requestor has not shown that ICANN relied upon false or inaccurate material information. The life cycle of a domain name begins when the domain is registered, then moves through various stages before ultimately coming to a close. Early termination of a domain registration does not impact the life cycle of the domain, as the domain can still go through the various stages of a standard life cycle. Moreover, as stated above, ICANN was aware that discontinuation of these registry services in the .NAME gTLD would result in the termination of approximately 22,000 third-level domain registrations and of email services/addresses.
I don't agree. If I have a domain registered for 10 years the expected life cycle is for deletion to occur 10 years from now, not 90 days from now. They've changed the life cycle by changing the agreed upon deletion date for the current registration term.
I could maybe see if they stop accepting renewals and delete the domains as they expire. It's not a good look, but at least people are getting what they've been promised.
1. https://www.icann.org/resources/pages/reconsideration-26-2-s...
Comment by Calavar 5 days ago
According to ICANN cutting the life cycle short doesn't have any effect on the life cycle?
ICANN corruption is at the level of FIFA corruption.
Comment by disillusioned 4 days ago
Comment by bilkow 5 days ago
How about the fact that you paid for a service for 10 years and they decided to stop providing it midway? Will you at least get a refund? If not, that's surely illegal right?
Comment by smsm42 4 days ago
Comment by ALLTaken 5 days ago
I own lastname.name and use it for email only like this: firstname@lastname.name
I always thought as owner of lastname.name, I'm the only one able to add subdomain.lastname.name. Is this wrong??
1) Can anyone "buy" scam.lastname.name without my authorization on .name??
2) Can anyone owning not.lastname.name then steal my emails going to: firstname@*.lastname.name or even firstname@lastname.name??
BUT: If someone ONLY bought not.lastname.name and doesn't own lastname.name, they'll get terminated. Would that be 'good' as it would stop 1) and 2) ??
I'm really concerned. My family is using first@lastname.name as the personal email, I'm hosting and paying for since many years.
Comment by judge2020 5 days ago
TFA mentions that `.name` was unique in that it sold a good amount of third-level domain names directly from the registry.
Comment by calfuris 4 days ago
Comment by iminatx 4 days ago
Comment by dvt 5 days ago
Still a crappy thing for people, but it does not affect owned second-level domains.
Comment by wormius 5 days ago
But I didn't think about the 1st level competitors. There'd still need a mechanism to resolve that...
1. First come first serve? (e.g. whoever registered a y.name first, whether x is bob or sue is determined by the earliest registrant on record) 2. Lottery/random selection? 3. Bidding war?
I think the problem is 2nd level domains who have the same name will be a problem when they find out all these other 3rd level are now expiring and can run a route to spoof? Likely wouldn't happen, but with the fuckery in the DNS that can happen... This is such a rash and weird decision to push through so quickly just because engineers find it "easier" while ignoring the implications of the move, seemingly when it comes to larger scale security.
I assume there would have to be some method to prevent routing of third level domains to subdomains of two-levels... (or is that just me being a fool yet again, assuming we have competent administration of our systems).
Comment by ctippett 4 days ago
I had/have a .net.nz and someone else owned the .co.nz. I went through the conflict resolution process and ended up being able to register the .nz.
Not sure if or how other registrars manage this sort of thing, but I thought the way NZ's Domain Name Commission handled things was pretty fair and transparent.
[1] https://dnc.org.nz/tools-and-services/how-do-i-2/register-a-...
Comment by p4bl0 5 days ago
Yes. I've been asking VeriSign for this for years, and they always refused.
Comment by p4bl0 4 days ago
Comment by glub 4 days ago
Maybe there's some legal loophole that says screwing everyone == not screwing.
Comment by mulmen 5 days ago
Comment by Nition 4 days ago
But I wonder if there might be some competing names on the third level? Like, he's neil.fraser.name, but what if there's also bob.fraser.name and they'd both very much like to keep their domains?
Comment by marcus_holmes 4 days ago
The change that Verisign is making is to deregister all the *.fraser.name domain registrations, which will then free up fraser.name for registration.
So it becomes a race to register fraser.name and the winner gets to recreate all the *.fraser.name subdomains they want, for whatever purpose they want.
Comment by Nition 4 days ago
Comment by shelled 4 days ago
The main issue here is the way VeriSign and ICANN are operating. Unchecked, hostile, and without consequences (even the ombudsman okay the move). Someone might come along and say but you can always fight in the court - and that's the problem! Some company or entity claims one of those .net/.com domains I "use" and just gets us suspended and handed over, as someone not living in the USA I will literally be out of any option. This "then go to the court" is a very dangerous setting. We all know this but this squarely rigged to be in favour of the offenders with means and power.
Comment by ShakataGaNai 5 days ago
I have myname .name - so I thought that was going away. Granted I barely use it, but still it would be annoying. I didn't recall there were 3rd level domains there.
Comment by TZubiri 5 days ago
There is no subdomain/TLD bit
Comment by dvt 5 days ago
Comment by TZubiri 5 days ago
What I understand would be the following:
1- Verisign manages the TLD registry for .name (and others), which includes managing the authoritative DNS servers (as pointed to by the .name NS and A records on the root DNS servers), 2- as well as for updating the NS records of .name records it is authoritative at the request of registrars (like, say GoDaddy), which act on behalf of domain owners. 3- one or some of the domain owners, for example for fraser.name, acted as a registry themselves managing authoritative DNS servers for NS records of .fraser.name domains, these third level DNS servers being pointed to by the name. NS records.
4- Upon registration of a .name domain, verisign charged a fee, (in the case of .coms this is around 10$ currently I believe, not sure how much they charge), and ICANN charges a much lesser fee (like 20 cents).
5- Upon registration of a .fraser.name domain, the fraser.name domain owner charged a fee, and they kept the totality of that fee (potentially paying a fee to ICANN, but definitely not to verisign.)
6- Verisign issues this request, requesting registrars of second level domains (domain.tld) like GoDaddy, to stop selling third level domains of this TLD (domain.2ld.tld).
This is my understanding of the situation, and in that case, verisign was not billing for the domain. This might (a bit cynically) provide a commercial motivation for the actions of verisign.
It's worth noting that this is not at all a weird or shady practice, multi-level domains are the very ethos of the domain system, it's built for that, I'm not saying any domain is obligated to do that on the basis that it can, but it's not some esoteric illegal activity, it's normal.
Comment by realityking 4 days ago
> 3- one or some of the domain owners, for example for fraser.name, acted as a registry themselves managing authoritative DNS servers for NS records of .fraser.name domains, these third level DNS servers being pointed to by the name. NS records.
There was no domain owner for fraser.name. Verisgn acted as the registry for fraser.name and allowed a registrar to directly register bob.fraser.name.
Before 2004 these third-level domains were the only way to register .name domains. It was the intended structure. See Wilipedia for an explanation: https://en.wikipedia.org/wiki/.name#Structure
Comment by chuckadams 5 days ago
Comment by megagpt1 5 days ago
Comment by chuckadams 5 days ago
Still, I'm not sure there's any easy technical fix for the .name debacle.
Comment by TZubiri 5 days ago
It's safe to ignore altogether, but it can come in handy as a starting domain block/allowlist.
>Still, I'm not sure there's any easy technical fix for the .name debacle.
I think that it's gonna be ok, the owner of the 2ld is still the owner, so they are free to allow the 3ld domain owners to continue "owning" their domains and updating them on the authoritative 2ld DNS. It's just that verisign is no longer sanctifying it by allow vendors of other 2ld to sell 3ld with the 2ld together.
This might explain the whole situation, many of us are interpreting that the domains are deleted, but in reality, they may more likely be prohibited from being represented as official .name domains in registrars .
Comment by mhink 5 days ago
i.e. I own john.doe.name, you own george.joe.name. Once this change goes through, only "doe.name" can be owned, so who gets it?
Comment by plorg 5 days ago
Comment by cowsup 5 days ago
* .name is open for everybody
* a company called "Global Name Registry" scooped up a BUNCH of common last names, including fraser.name
* Global Name Registry then sold access to neil.fraser.name for far cheaper than the fraser.name domain would cost on its own; someone else could also buy john.fraser.name or jane.fraser.name, so the single fraser.name domain that they owned could have dozens of customers associated to it. They worked with ICANN to allow each domain to have its own registered owner.
* The article in the OP bought neil.fraser.name and has used it for years
* Verisign bought Global Name Registry; later they realized, hey, we're sorta not making a lot of money on this idea, and we're spending a lot of time/resources maintaining these domains "for cheap" and chasing renewals, and not scooping up more customers. Let's just stop it and stop paying for fraser.name and the potentially hundreds of other domains we own.
* Neil Fraser, not the only Fraser in the world, is upset because he might lose the domain he's had forever
So one CAN buy the mwai.name domain, as you have, and continue using vpn.mwai.name just fine. It's just you can't "officially" start selling out these subdomains as a separate registrar entry.
Comment by plorg 5 days ago
I guess in practice it doesn't make much of a difference for me anymore, I registered mwai.name 20 years after they began allowing second-level registrations and more than 15 years after GNR was sold to Verisign. So presumably GNR's concept was long-abandoned by the time I made my registration (which was, to be truthful, mostly based on mwai.name being the cheapest domain with the initialism). I was more curious about the implications of having held a second-level domain, whether it could have caused trouble for me or for a different person who held a tertiary domain. But also my registrar at least doesn't seem to allow tertiary domain registration for .name.
Any any case, nothing in OP or any of its referenced sources suggest Verisign is giving up .name. rather they will stop accepting and serving tertiary registrations, so if Neil wants to keep his domain he or another beneficent Fraser will need to register the fraser.name domain and register the subdomains for neil, joe, jill, or whichever other fraser currently owns a tertiary domain. The same would be the case for anyone else who still held a tertiary domain. Perhaps Verisign or the registrars who work with them might be able to migrate the registrations of anyone with these domains, particularly in what I suspect are most cases where there is a single tertiary registration under a secondary domain. Perhaps offer fraser.name to Neil and he can add his own subdomains.
I was intending to replying to a different comment on the above thread, sorry if this made my previous reply a bit incoherent.
Comment by TZubiri 5 days ago
This is an ostensibly uncharacteristic move for verisign, but the customers that bought these 2ld did so from a non-verisign vendor, it is only after verisign bought the 2ld holder that they became the holders and are now proceeding to extinguishing them after embracing and extending.
Might be an anti-trust case. Like textbook clear-cut case. IANAL, this is not legal advice.
Comment by echoangle 4 days ago
Why should I care as the customer? If I buy a for-life subscription plan and the company gets bought, can they just not honor it because it’s a different company now? Maybe they should check which promises they are buying when acquiring other companies.
Comment by LelouBil 5 days ago
Comment by plorg 5 days ago
Comment by skarz 5 days ago
Comment by jibal 4 days ago
> On 15 April 2026 Verisign proposed the destruction of the entire 3rd level of the '.name' hierarchy in order to simplify their administration.
Comment by nanolith 5 days ago
Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.
I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.
I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.
Comment by ACCount37 5 days ago
What's your account tied to?
E-mail? That's usually on a mail server owned by someone else. If not, it's still on a domain owned by someone else.
Phone number? Definitely owned by someone else.
The only account that's reliably "yours" is one that asks for a login, a password, maybe a TOTP, and absolutely nothing else. Because everything else is introducing "things owned by a third party" into the equation.
Comment by remuskaos 4 days ago
Weeeell... Some services I use seem to have switched to a magic link EVERY TIME for login. No password anymore at all. And all of a sudden, my mail account is the single point of compromise for these accounts.
And there is absolutely nothing that I can do. If the mail is hosted by someone else, they may terminate my account at a whim. Or give it to someone else who happens to have convinced my phone provider to hand them a sim card with my number on it. If I do self host I still need a domain, and I can never really own a domain, only rent it from somewhere. So, whenever that lease goes up, my account is compromised by default.
I really hate that this problem seems still unsolvable. Keybase had the right idea, but no one used it and they got aquihired by zoom during the pandemic...
Comment by sciyoshi 4 days ago
Comment by paholg 4 days ago
Comment by gwillen 4 days ago
Comment by fh67 5 days ago
Comment by akersten 5 days ago
Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?
Comment by SahAssar 5 days ago
> do browsers have a wildcard suffix list
Yes: https://publicsuffix.org/ and they have discussed this situation here: https://github.com/publicsuffix/list/issues/2306
Comment by akersten 5 days ago
> We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't.
Comment by xg15 5 days ago
So does that mean that in practice, .name domains were always treated by browsers like regular 2LDs, meaning the cookie and origin protection was always broken for those domains?
Doesn't sound like good news for the guy in the OP...
Comment by SahAssar 5 days ago
IIRC orgs like letsencrypt also use the PSL for rate limits, so there are probably more issues that are not browser-based.
Comment by eloisant 5 days ago
Comment by adw 5 days ago
Comment by marcosdumay 5 days ago
Comment by dhosek 5 days ago
Comment by dgoldstein0 5 days ago
But letting arbitrary customers take arbitrary 3 level domains, and others take 2 level domains, seems like a mistake as it's not very reasonable for every 3LD customer to put the 2LD on the public suffix list, but mixing 3LD and 2LD registrations means you can't public suffix *.name.
Seems the whole idea of having both was always misguided.
Comment by justincormack 5 days ago
Comment by eloisant 5 days ago
Comment by ButlerianJihad 5 days ago
But that was simply the easiest way to market your website as a trusted government entity. And now nobody has ever heard of .us domains in active use.
Comment by ocdtrekkie 5 days ago
Comment by ButlerianJihad 4 days ago
https://en.wikipedia.org/wiki/.us
But your point about them being rather longer and difficult to remember stands, and the same for a .gov, which could be shorter and catchier.
However amusingly, .us opened up second-level registrations 24 years ago, which means that any qualifying entity could have their name registered directly under .us, which is obviously recognizable, and also one character shorter, than a .gov registration. However, by that time, I believe that .gov had increased in stature so that registering governmental entities under .gov carried more certainty of conveying official status than anything under .us.
Also sadly, QR Codes and URL shorteners today sort of obviate the need to directly register the shortest possible domain name. I don't know: I was always kind of fond of the .us hierarchy, and I'm just personally sad that it's fading away.
Comment by flomo 4 days ago
In reality, it wasn't that simple, and a lot of those .us domains looked like line noise.
Government sites are used to distribute public information. They need something they can print on a poster/sign. Not some bogus 'logical' hierarchy.
Comment by ocdtrekkie 4 days ago
.gov certainly cares a level of exclusionary access that isn't really true of .us. Only one entity, the US federal government, can decide to hand someone a .gov address. And generally there is few signals harder to fake or impersonate than one.
Comment by stephen_g 4 days ago
If anything the .gov, .mil and .edu being just American is confusing, as well plainly inappropriate (it feels like an American cultural imperialist thing to people from outside the US). It would have been much better if those had been retired decades ago and moved to under the .us TLD, so e.g. whatever.edu would become whatever.edu.us like every other country. Any existing domains on .gov, .mil, .edu etc. should only be allowed to exist as 301 redirects.
Comment by mixdup 4 days ago
If .gov had been an international TLD that was at some point available to everyone, or had been created by everyone, ok. But .gov was created as part of the work the US government did to build out the initial DNS structure. It probably wasn't even a given at the time that arpanet would be international in nature
Also, 301 redirects are not a DNS thing, that is an HTTP thing. Not sure how that would solve your problem since HTTP is intrinsically at the base of it tied to just A or AAAA records. DNS does a lot more than pointing to websites
Comment by SenHeng 5 days ago
The issue is that .jp registered outside of a few Japanese registrars are legally not allowed to offer Whois privacy.
Comment by adw 5 days ago
Comment by toast0 5 days ago
Comment by jomar 5 days ago
This is a bug, not a feature.
Comment by joquarky 5 days ago
Comment by nneonneo 5 days ago
There was an effort to properly handle the .name 2LDs, but it was never resolved because there’s no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name: https://github.com/publicsuffix/list/issues/2306
So yes, this TLD’s setup is in fact pretty insane.
Comment by rwmj 5 days ago
Comment by xp84 5 days ago
In a world without advertising, there's no reason why google.com couldn't also allow *.youtube.com to set cookies for it, but of course that would cause a tremendous privacy freakout. Though in practice they can and do just send every login/logout through a 302 redirect roundtrip to take care of the cookies on youtube.com.
Comment by dgoldstein0 5 days ago
That said I don't know about making cookies shareable across TLDs. That seems like allowing more privacy nightmares; at least today if you want to share you need complicated redirect dances that make you question if the user perf hit is worth it. I think there was some proposal for a mechanism for allowing non partitioned 3rd party cookies which seemed more sane to me, forget what the details were and if it ever made it beyond just a proposal.
Comment by megagpt1 5 days ago
Comment by megagpt1 5 days ago
Comment by lxgr 5 days ago
Maybe it could be opt-in or opt-out via some markers at the DNS level, though? The public suffix list having to exist at all is bizarre.
Comment by amluto 5 days ago
Surely a better solution would involve an actual request. login.foo.com could send a request to foo.com with Origin: login.foo.com asking to set a cookie, and foo.com could make its own decision.
Comment by toast0 5 days ago
If you require domain wide cookies be set from a webserver on the domain apex, the domain apex (for high volume destinations) needs to be set up for high volume webserving. High volume webserving often means at least geotargetted DNS, maybe a CDN, often anycast in today's reality.
Back in the day, it was common for high traffic domains to run their DNS with a normal DNS server and then delegate (typically via CNAME) high volume subdomains off to a 3rd party DNS server for geotargetting (usually Akamai DNS, but there were others). But you can't CNAME the apex domain away. You'd have to delegate the whole domain to your DNS provider and then you have no way to manage an outage of your fancy DNS provider. Especially if you go back to the days where NetworkSolutions did a single daily zone update for .com ... if you wanted to switch to a new DNS provider for your domain, you would submit the change request and hope it happened in the 24 hours, but sometimes you'd miss the window (or there would be some process error) and it would happen much later.
Less of a problem in today's world, where registries typically update the glue records in near real time (although many TLD servers have a 2 day TTL for glue, so you can't switch off a dead provider very quickly) and lots of domains seem comfortable with delegating the whole thing to their CDN.
Comment by markhahn 5 days ago
Comment by dgoldstein0 5 days ago
That said the dumbest thing with cookies is not sending their attributes in the cookie header which makes it impossible to distinguish expected cookies from tampered cookies set by insecure subdomains. __Host prefix is basically a workaround for this but took more than a decade to get into browsers. Samesite similarly was bolted on after the fact.
Cookies aren't the only web security feature that follow sites instead of origins but they are the only one that was clearly designed without thinking through the consequences.
Comment by quotemstr 5 days ago
And that's one reason why the public-ness of a hierarchy level belongs on a DNS record on that level and not some separately-distributed side list.
Comment by markhahn 5 days ago
I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP.
Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...
Comment by tptacek 4 days ago
Really hard to understand why that hasn't happened yet!
Comment by account42 4 days ago
But sure, keep spreading FUD like you always do on this topic.
Comment by tptacek 4 days ago
The PKI run by state-level actors isn't going to happen.
Comment by akerl_ 4 days ago
Are there any remaining CAs in browser root stores that don’t enforce CAA record validation?
Comment by ambigious7777 5 days ago
Comment by account42 4 days ago
Comment by OkayPhysicist 5 days ago
There would be no issue at all if Verisign, or maybe Global Name Registry, decided to stick to the 3rd level registrations exclusively. Problem is, the chucklefucks over there decided it was a good idea to also hand out 2nd level registrations. Those 2nd level registrations outnumber the 3rd level registrations by an order of magnitude, so the PSL decided to just let joe.smith.name and john.smith.name share cookies. Which, IMO, was not a good decision, but it is what it is.
Comment by orra 5 days ago
Comment by traceroute66 5 days ago
Yup. The original statement was dangerous FUD which should be urgently corrected.
Comment by BHSPitMonkey 5 days ago
Needing to be familiar with all the special cases (like the VERY special case of x.y.name which I previously knew nothing about) kind of ruins everything and introduces yet more security risk.
Comment by traceroute66 5 days ago
I'm sorry, what ? Admit ? Confusion ?
In the case of .co.uk it has been around since 1996. HN is a technical forum, most people here should be well aware it is a serious SLD. I honestly can't believe it even needs clarifying.
Hell, if you use AWS Route 53 you'll see they use co.uk as one of their nameserver suffixes[1].
[1] https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/SO...
Comment by BHSPitMonkey 4 days ago
Comment by omnibrain 5 days ago
Comment by Pxtl 5 days ago
Imho email is missing a feature for nameless email addresses for when somebody just buys their full name as a domain name. If I get "firstname-lastname.name", having the email be "firstname@firstname-lastname.name' kinda ruins it.
Comment by skinfaxi 5 days ago
Comment by londons_explore 5 days ago
they'll grumpily sign up to gmail just so they can get a verification email, and that'll be all it gets used for. Messaging their irl friends will be done in apps like Discord.
Comment by peezd 5 days ago
lol I ran a sizeable team around 2020 and I had to educate a couple of our new hires straight from college that they actually needed to check their work email, after they missed important HR related stuff and they had just completely not realized it was an avenue for company communication, with an assumption that everything was available on our heavily used slack.
Comment by xp84 5 days ago
Comment by londons_explore 5 days ago
If email was a commercial product, the company would have done something about that. Email died because it was an open platform, with nobody to address this systematic issue.
Comment by zlokki 4 days ago
Comment by megagpt2 5 days ago
Comment by kennywinker 5 days ago
Comment by omnibrain 4 days ago
Nice twist: The father of my wife owned {newlastname}.de since the dawn of the internet. So I'm still fine on that front. ;)
Comment by Pxtl 5 days ago
Comment by avarun 5 days ago
I've successfully renamed an old account with an email address I no longer liked. It works quite well on everything 1st party, but does have the potential of causing issues with OAuth on poorly-coded websites that key on email instead of user ID (ie. most of them). You do get to keep your old email address though, so it still ends up working fine in practice.
Comment by Pxtl 5 days ago
Comment by ocdtrekkie 5 days ago
Comment by account42 4 days ago
Comment by megagpt2 5 days ago
Comment by indymike 5 days ago
It's been around for years. I seem to remember this issue coming up around 2001 where originally .name was for third level registration (i.e. john.doe.name) and changed to second level it a few years later and caused some problems... https://publicsuffix.org/ talks about it in light of architectural limitations of domain names.
> can Joe set a cookie on all of .smith.name?
That can happen. I seem to remember ancient browsers made it so .name (and other non-generic TLDs) required three periods. I think country code domains and new generic TLDS caused the browsers to change it.
It's pretty screwed up, but a lot of the people with .name domains have had them for a very long time. Sad to see them all lose their identity online that way.
Comment by CodesInChaos 5 days ago
edit: apparently not all second level domains in .name are public suffixes anymore, so a wildcard addition wouldn't be correct.
Comment by gpvos 5 days ago
Comment by xp84 5 days ago
It has to be a money problem. Something they want to do will be simpler if this is no longer a quirky registry. And they know they'll get the money back that they lose from not having bob.smith pay -- probably by throwing all the "last names" once registered this way into some "premium name" bucket and selling them for $1000 and up instead of the ~$10 that zyzgdhaf234.name fetches.
In fact, I'm not sure that scheme isn't the reason itself.
Comment by gpvos 4 days ago
Comment by QuantumNomad_ 5 days ago
Different from .co.uk.
Comment by kevin_thibedeau 5 days ago
Comment by cpach 5 days ago
Comment by QuantumNomad_ 5 days ago
> The first appearance of reversed DNS strings predated the Internet domain name standards. The UK Joint Academic Networking Team (JANET) used this order in its Name Registration Scheme, before the Internet domain name standard was established. For example, the name `uk.ac.bris.pys.as` was interpreted as a host named `as` within the UK (top level domain .uk)
from the History section of https://en.wikipedia.org/wiki/Reverse_domain_name_notation
But I don’t know if uk.co.somethingsomething did or did not exist at that time. Or if it was only introduced after the Internet domain name standards we use today existed and so was .co.uk from the beginning.
Comment by zvr 5 days ago
Back then the code in various pieces of software had hand-written exceptions for domain processing. The joke was that all Computer Science departments in the UK (uk.ac.university-name.cs) ended up in Czechoslovakia.
Comment by dolmen 5 days ago
Comment by Pxtl 5 days ago
If .gov and .mil and .com make sense, then .gov.cc and .mil.cc and .com.cc make sense.
Of course, I think having more than one non-cc TLD was a mistake, but that's just me. If it makes sense to have topical TLDs for international and US institutions, it make sense to have national ones.
Comment by gpvos 5 days ago
Comment by traceroute66 5 days ago
Nominet and therefore .co.uk has been around since 1996.
.co.uk is not going anywhere, and neither is Nominet.
The only "problem" is the original poster did not do their homework. I suspect they were inferring `uk.co` which is a completely different kettle of fish. The original poster should urgently correct their post.
Comment by zahllos 5 days ago
.uk was opened up relatively recently.
Comment by eterm 5 days ago
Comment by pumplekin 4 days ago
Quirky stuff like .co.uk / .org.uk / .sch.uk 2nd level domains partly come around from .uk being the worlds first CCTLD outside the US (and as other parts of this thread say, .us isn't that popular a CCTLD).
Everything was new and different people tried different hierarchy and structures to 2LD and 3LD's. .co.uk is also far from unique, I know this is common in many other places (UK/NZ/IN/ZA/KR/MX).
The UK now allows directy foo.uk registrations as well, but many people still have SLD's registered and will continue to do so.
Comment by preisschild 4 days ago
But I agree it makes no sense for public sales to the wider world such as `co.uk`. At least have the registrar be the govt company register and hand out subdomains to each registered company.
Comment by pushcx 5 days ago
Comment by Ekaros 5 days ago
Comment by megagpt1 5 days ago
Comment by traceroute66 5 days ago
Comment by akersten 5 days ago
I don't have some nefarious desire to scare people away from the TLD of their choosing. Really I'm bringing it up to be like "why would you even, like, want some 3rd rate domain instead of getting a .com" so I don't think there's anything to correct
Comment by digitalPhonix 5 days ago
It's not reverence? I think that you're missing that it was a requirement. Basically every country (that followed ICANN's original rules) does this: .com.au, .co.nz, .co.jp, .com.mx, .co.ke (+ the org/net variants for each country)
The US is the only country where registering .com was allowed by ICANN (and not .com.us or something).
ICANN relaxed these rules in the 2010s I think, so now you can register 2LDs at most/all of those country TLDs.
Comment by drdexebtjl 5 days ago
Comment by traceroute66 5 days ago
Its not hard to tell for things like ".uk" or other serious suffixes.
It only (maybe) becomes hard(er) to tell for all the vanity ccTLDs that came along in the 2000s. But even then 10 seconds on WHOIS and Google should fix any doubt.
> about the reverence of `co.uk`
What are you on about ? Lots of other countries do it too. Japan is one example given already here, but there are dozens. It is very common practice for country tlds.
Comment by stronglikedan 5 days ago
Comment by traceroute66 5 days ago
5 seconds on wikipedia or google would have stopped them spreading completely dangerous FUD about .co.uk.
Comment by yreg 5 days ago
Comment by traceroute66 5 days ago
Implying lack of trust in `co.uk`
Implying `co.uk` may suffer the same fate at `.name`
Complete FUD.
Comment by gertrunde 5 days ago
;)
(Edit: although I should add that I'm hopeful that things have improved there over the last few years).
Comment by traceroute66 5 days ago
No.
Oversimplified summary:
There was a period around 2010 when the management at the time wanted to follow a more commercial route with various unrelated "investments".
Nominet members made it impeccably clear in a very loud manner to management that it would not be tolerated.
Management insisted on a vote which they inevitably lost.
Management departed.
TL;DR Don't piss off Nominet members
Comment by necovek 4 days ago
For instance, in Serbia, there is a similar scheme to UK: .gov.rs, .co.rs, edu.rs, but also in.rs (for individuals) and top-level .rs. So someone has registered "iz.rs" and offers free subdomains to individuals.
The fact that there is implied hierarchical trust is what the problem is, and keeping track of individual rules for each TLD is prone to errors.
Comment by dokyun 5 days ago
Comment by arjie 5 days ago
Comment by zamadatix 5 days ago
ICANN, a 501(c)(3), proposed to remove the price cap on .org registration, commonly used for non profits, so PIR, the 501(c)(3) registrar for .org, could then announce it planned to sell .org operations to private equity investment firm Ethos Capital.
Thankfully the overwhelming response caused the proposal to be scrapped.
Comment by NewJazz 5 days ago
Comment by shagie 5 days ago
https://news.ycombinator.com/item?id=48426337 was apparently the final straw.
Comment by zamadatix 5 days ago
Comment by crossroadsguy 4 days ago
This is a very hn thing (shadow-banned accounts should not be able to comment though and should be treated differently than "dead" because I could see the comment). I was accused by a fellow hn'er just a few days back I was performing ignorance because I didn't know something very US specific legal term and had asked in a sub thread. Another person said I could just google that, or ask an AI.
Coming back to the scam - it's bizarre to think ICANN could begin to do that! TLDs are such a basic aspect of online identity today and just to think that an outrage, i.e an overwhelming response, caused the proposal to be scrapped, is unsettling.
I am not sure but we should rather move to something else or remove this power from such for profit companies or non-profits that often behave worse than for profits, or at the behest of them.
Comment by donmcronald 5 days ago
I wonder how long that'll last. If the regulators in Califonrnia keep forcing them to act in the public's interest, won't they just move to a more favorable jurisdiction?
Comment by NewJazz 5 days ago
Comment by patcon 5 days ago
Comment by MagicMoonlight 5 days ago
Comment by projectileboy 5 days ago
Comment by crabmusket 5 days ago
Comment by hackrmn 4 days ago
In light of this particular situation, I think a secret key shared between you and the service, at least, could guarantee that even in the event the e-mail address is stolen (or otherwise taken) from you, the service account remains in your hands.
I know I am not breaking new ground here, but I don't think the Internet is getting healthier for the human, it's at least going to get worse before it may get better. So maybe we need to adjust our assumptions and mitigate accordingly.
Comment by sigbottle 5 days ago
Well, it's still not affecting me, personally, but wow, seeing articles like this makes it feel just a tiny bit more real.
Comment by NAR8789 5 days ago
Comment by dang 4 days ago
You only get a first name and a last name and a .name though. You can't be robert.louis.stevenson.name - just louis.stevenson.name.
(Incidentally, this was a Claude suggestion. The change only took a couple minutes but figuring out what mechanism in the code could do this would have taken me a lot longer.)
Comment by epaga 4 days ago
Comment by dang 4 days ago
Comment by NAR8789 4 days ago
Comment by anominal 5 days ago
"2.1. What effect, if any, will the proposed service have on the life cycle of domain names? None. There will not be any effect on the life cycle of domain names.
...
2.3. Explain how the proposed service will affect the throughput, response time, consistency or coherence of responses to Internet servers or end systems. There will be no effect on the throughput, response time, consistency or coherence of responses to Internet servers or end systems."
My registrar is also suggesting that they are going to just keep the money I pre-paid for years of registration, which is a minor annoyance compared to the loss of my entire online identity but an annoyance nonetheless.
Since ICANN is a non-profit that is required to operate in the public interest I do hope there can be some pushback on this. I will be writing to the CA AG myself.
Comment by baylisscg 5 days ago
Comment by aliasxneo 5 days ago
Comment by theK 5 days ago
Comment by aliasxneo 5 days ago
In short, AI identities were just a happy accident that comes with the system/architecture. It's not tied to AI at all.
But if anyone is interested in talking about what we're doing more, happy to connect at hn@sepositus.com.
Comment by xur17 5 days ago
Comment by aliasxneo 5 days ago
Alice registers `alice.dntls` and Bob registers `bob.dntls` on the DNTLS network. During the registration process, they generate PQ key pairs that are registered along with the name. Alice's and Bob's name are hashed before being stored on the network. Bob knows Alice's name, so he can perform the necessary hash computation to look up Alice's public key material on the network. Likewise, Alice can do the same for Bob.
Bob wants to send a file to Alice. Bob takes his name key and signs the document with it and sends it to Alice. Alice looks up Bob's public key material on the network and verifies the signature.
Bob now stands up a new website, but he only wants Alice to access it. He sets up a standard HTTP server but slightly modifies it to be "DNTLS native." He does this by requiring mTLS on incoming TLS connections. The connecting party must identify themselves with a signed certificate. Each name has what we call a "name record" that allows publishing arbitrary metadata signed by the name key. Bob publishes a standard "HTTP" record in his own name record that points to the IP address. Alice now goes to connect to Bob's website. She opens her "special" browser and types in bob's name. The special browser looks up Bob's name record, finds the published IP address, and attempts an mTLS connection. Bob's server is configured to _only_ allow connections from Alice. Since Alice signed her TLS connection with her own name, the connection is allowed, while every other is rejected.
Alice now wants to communicate with Bob's agent. Bob publishes a subname called `agent.bob.dntls`. In that subname's record he publishes an A2A packet that contains the information for connecting to his agent. But, like the website, the agent is listening on a TLS connection that rejects anyone except Alice. She uses an A2A tool to initiate a connection using her name key and is allowed to make a mutually secured connection to Bob's agent.
Bob wants to connect to a VM he purchased that runs the website. He configures SSH with his name key as one of the recognized users. His SSH connection simply leverages the name key to authenticate him to the machine. But he shares the machine with another person and wants to share a secret with them. So he creates a SOPS encrypted file with his name and this other person's names as the only recipients. They both securely access the secret using their respective name keys.
I'll leave it there, but hopefully that's descriptive enough.
Comment by hackrmn 4 days ago
Anyway, name resolution needs to be federated because ICANN is apparently compromised as far as doing the right thing goes. A single root model may not work anymore. Maybe blockchain can finally do some good...
Comment by zamadatix 5 days ago
Comment by aliasxneo 5 days ago
Comment by breakingcups 5 days ago
Comment by aliasxneo 5 days ago
Comment by zamadatix 5 days ago
Comment by xur17 5 days ago
Comment by aliasxneo 5 days ago
Names are valid for one year and range from $10/yr up like current domain names. Letting a name expire opens it back up to being registered again.
We have quite a few other "tools" in play behind the scenes that make name trading/squatting extremely impractical, but I won't go into those details here :)
Comment by hellcow 5 days ago
Comment by aliasxneo 5 days ago
Comment by teravor 5 days ago
but you lose the ability to have short domains.
also until such a time that pkarr is widely adopted, you are better off using .onion domains anyway. it becomes a question of requiring custom DNS client vs. Tor browser.
both approaches use a DHT.
Comment by delfinom 5 days ago
Comment by aliasxneo 5 days ago
Comment by dbdr 4 days ago
I suspect the lack adoption might rather be because of:
- DNS being "good enough". Rug pulls as described in this article are sadly possible, but not frequent enough to motivate enough actors to work on the switch
- The stigma attached to crypto. Which is understandable given the number of bad actors trying to make easy bucks with false promises. But it's also a shame, given that this actually seems a perfect use case: the code is simple enough, and as far as I know, only a blockchain can guarantee a specific code will be executed without relying on a third party being and staying honest (in others words, true self-custody of a domain name).
Comment by colordrops 5 days ago
Comment by aliasxneo 5 days ago
Comment by alias_neo 4 days ago
Comment by willwade 5 days ago
Comment by jonhohle 5 days ago
The .name scenario is even worse. One domain gives you access to tens of thousands of users email. It seems like a privacy nightmare.
I’m not sure how future auth and privacy will work, but my child lost a tracfone phone and some mixup had separated it from my account. There was no way to recover the number. If that was my personal phone, how difficult would it be to restore banking, medical, and government access to things that assume I’ll always have that number.
Doing the same with personal email seems like too big of a risk.
Comment by drdexebtjl 5 days ago
To me, the risk these registries screwing me over is smaller than Big Email deciding I broke their ToS and shutting down my account.
I wouldn’t use these novel TLDs either.
Comment by notpushkin 4 days ago
Both of these are in the US jurisdiction. If you’re not prepared to sue in the US if somebody screw you over, the ccTLD route is probably better, and the country you live in is usually a good choice indeed (unless you live in, say, Russia, in which case the government might be the ones doing the screwing-over).
[1]: https://icannwiki.org/.org#Proposed_Sale_to_Ethos_Capital
Comment by koeliga 5 days ago
Comment by DaiPlusPlus 5 days ago
I used to think this, until I inadvertently let a registration fail to renew because I didn't update my expired credit-card's billing details with NameCheap - they did send me automated emails about it but I missed them, unfortunately. Their grace-period is only 30 days and I didn't notice the problem until 45 days had passed when my domain-name was bought-up by a spam-site-scammer and redirected the site to a porn/virus-downloader site (yes, those still exist).
I paid $1500 (uugghhh) for the UDRP process to get the domain-name back ($1000 UDRP fee, $500 for the lawyer to do the paperwork), and the UDRP panel ruled against me: their response reasoning made it clear that they never actually looked at my submitted evidence - and unfortunately that $1000 is nonrefundable, gaaaaah. I still haven't gotten that domain-name back. (I will say that my previous other UDRP cases all ruled in my favour; I don't know why/how I somehow drew a crappy arbiter in this case, I'm just vexed that they can rule against me without any right to appeal; I expected better).
Comment by noAnswer 5 days ago
I use a prepaid provider. If at the day of the renewal there is no money "in the bank" they immediately release the domain. So yeah, I treat their reminders with priority. I really should change providers...
Comment by account42 4 days ago
* Providers I have used send them multiple months ahead of expiry but I also don't use automated renewal and buy as far ahead as I can and still extend that yearly.
Comment by sunnybeetroot 5 days ago
Comment by famfamfam 5 days ago
At the time - before the explosion of new gLTDs - third-level .name domains were advertised as the 'correct' domain to register for individuals wanting personal email addresses.
Comment by sandcat_ 5 days ago
(Update: as it happens… https://news.ycombinator.com/item?id=49548452)
Personally I like having a custom domain as I like the idea of being able to move between providers. So far, over the past decade, I've hosted my email with Google, Fastmail, Hey.com and then Fastmail again. I like being able to move it around if I find one provider better than another. Others won't care, that's fine too.
Comment by xp84 5 days ago
Comment by wiether 5 days ago
Comment by ethanhawksley 5 days ago
Comment by jonhohle 5 days ago
Comment by bigstrat2003 5 days ago
Comment by donmcronald 5 days ago
If you walk around all day with your wallet in your pocket, it might fall out and you'll lose it. Would you like me to hold onto it for you to make sure that doesn't happen?
Comment by xp84 5 days ago
On the other hand, it's email. I was at a hospital to do a blood draw, and needed them to receive an email (insurance info). I sent them an email from my Gmail. We wait 4-5 minutes. I notice they're checking an office 365 outlook. So, I re-send the same message from my @outlook.com email. Arrives instantly.
Deliverability between MS and GOOG is normally really good, and even that wasn't working right that day. My self-hosted email server being able to deliver to them reliably every time is hopeless. "Big Email" has made it excruciatingly painful to not be on sending from one of their platforms, unless you're one of the big 5 or whatever platforms that send bulk email or bulk transactional email. The SendGrids, Amazon SES, etc.
Comment by sandcat_ 5 days ago
But also, even if you're self hosting on a server in your basement, you can still use SES to deliver your mail. Delivery is not an issue here.
Comment by thombles 5 days ago
Comment by UltraSane 5 days ago
Comment by jonhohle 4 days ago
Comment by bluebarbet 5 days ago
Comment by ipython 5 days ago
> 2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
> None. There will not be any effect on the life cycle of domain names.
ehhh, how is that possibly true? This change (deleting all third level names) by definition affects the lifecycle of domain names ... by terminating them!Many years ago I wrote articles bringing attention to the negative effects of Verisign's SiteFinder [1] - if you don't remember this, it's when Verisign hijacked NXDOMAIN by redirecting any unresolvable domain to a site they owned and controlled.
[0] https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2... [1] https://en.wikipedia.org/wiki/Site_Finder
Comment by politician 5 days ago
Comment by donmcronald 5 days ago
The ambiguity is a feature so they can do whatever they want. We all know it's bullshit, but it gives the parties involved the ability to disenfranchise one group to benefit another while claiming they're following the rules.
Comment by donmcronald 5 days ago
> Changes to the life-cycles of domains is a question meant to ask if this seeks to modify the life cycle policy, which is a separate type of change from termination of the service as a whole. I.e. this does not seek to change the life cycle policy, it seeks to terminate the service offering completely - making the life cycle policy irrelevant.
Comment by troyrollo 23 hours ago
Comment by semiquaver 5 days ago
Risk: none
Rollback plan: N/AComment by aidenn0 5 days ago
Comment by nubinetwork 5 days ago
What's to stop someone from doing that, and keeping the status quo? Sure, it might be expensive, but pool together a few frasers for the initial buy, and make the money back on the sublets.
Comment by bityard 5 days ago
For all we know, this is simply the first step in a series of moves for Verisign to better monetize the .name TLD in some novel fashion.
My evidence for this is that Verisign's own arguments for terminating the third-level domains are highly dubious. They claim that the third-level domains are too hard for them to manage. Bollocks: there are only 22,000 of them in use. That is a VERY small database that practically fits on a calculator and I refuse to believe that any manual labor around it is an outsized burden compared to pretty much any other semi-popular TLD. The second claim is that "the majority of those are not in use." Okay, if that's true, then where is the management burden coming from? That means tens of thousands of people are giving them money and getting nothing in return, isn't that the definition of an ideal business model?
It just doesn't pass the sniff test.
And finally, having read both of the linked documents, it sounds like people who have registered their .name for years in the future are not getting their money back. Are they likely to pay a second time, to a sub-registrar with no history?
Comment by troyrollo 23 hours ago
Verisign could create a work-around by defining a format at the second level - such as ml--2-4-johnsmith.name in which the first number is the number of levels, then there are n - 1 numbers to identify the number of characters at this level, so in this case it would map to john.smith.name at the registry level. There are only about 5 or 6 existing second level domains that are too long for that to work and they could be remapped as, say, ml--id-1 through to ml--id-6.
Since the double dash at that position is reserved for registries (the registry should reject a registration with double dash at that position outside of its own defined uses and xn-- for punycode domains) , this would allow Verisign to facilitate those domains being managed (or even created afresh as long as they are not too long) as if they were second level domains while continuing the third level domain service, avoiding the registrar implementation problem.
They won't do it though because Verisign has never been known for the customer-focus or corporate responsibility.
Comment by xamde 5 days ago
Comment by toast0 5 days ago
Restrict future 3rd level registrations, offer a path to upgrade a 3rd level registration to a 2nd level registration for those 2nd level domains with a single registrant and the burden will decrease over time.
Comment by theandrewbailey 5 days ago
Comment by m4tthumphrey 4 days ago
> Time to move to a new domain, one that will not obsolesce quite so quickly: neil.fraser.name.
I guess it wasn't quick, but eventual. :'(
Comment by CM30 4 days ago
Let's not forget the SEO or marketing consequences either. If you've got a business with this sort of domain, you're basically screwed. If existing third level registrations are terminated, and you can't get the relevant second level domain, your SEO/marketing work has literally been shot to pieces. I wouldn't be surprised if Verisign got sued for this.
There's no reason not to honour existing registrations while discontinuing new ones here, and the fact they're not feels completely at odds with how the internet should work as a whole.
Comment by econ 5 days ago
Did buy https://ycombinator.us
Didn't buy https://ycombinator.co.uk
What useful functionality is there in selling these domains?
Expiring domains is bad for the web and selling them to someone else is as terrible as the article makes it out to be.
Comment by jacobgkau 5 days ago
Short-term, it might seem like it would make sense for domain registrations to be permanent, but long-term, it introduces at least two insurmountable problems:
1. Unless some other cleanup mechanism is in place, eventually (like, hundreds of years into the future) domains will need to get longer and longer as people who owned old ones disappear and new people need new ones.
2. The infrastructure costs (while nominal) to keep existing domains functioning would not be sustainable in perpetuity without relying on the assumption of more and more domains always being sold.
Comment by econ 4 days ago
2) just solve the puzzle? The existing domain name system was wonderful when it was introduced.
I'll do a crude solution that shouldn't make it to the short list of goodness: Just make the commercial part into a web directory with all registered businesses. Have some of those filters we are now all familiar with. It might even smoothly transition into a product catalog. Sell placement rather than some random name no one will accidentally bump into. Let's also do a nice tag based web directory for personal websites. Extra points if there is opml
<link rel="outline" type="text/x-opml" href="webdir://hotel" title="Hotels">
It's not really my problem to solve under technofeudalism but it should be possible to make something modern.Comment by zamadatix 5 days ago
Comment by wmf 5 days ago
Comment by johnplatte 5 days ago
Never dreamed that such a supposedly durable thing would just disappear. How hard is it really to preserve a global resource like this that exists only in software?
Comment by chriscjcj 4 days ago
Comment by chanux 5 days ago
[1] https://blog.asmartbear.com/free-markets-bad/
Gotta wonder what other possible disasters introduced with gTLDs.
Comment by vidarh 5 days ago
Comment by xp84 5 days ago
> "will increase efficiency for the operation of the .name TLD."
What a preposterous excuse -- especially for something already up and running. Sounds like they probably want to change the backend in some way - or adopt some kind of off-the-shelf software - which doesn't jive so well with this unique TLD, and they figure "Ehh, fuck 'em, let's just pull the plug on these tens of thousands of people."
Comment by TLDRisk 5 days ago
It’s incredibly one sided. The registry gets to cut costs and the detriment to registrants is extreme. ICANN is supposed to act on behalf of all participants.
The flagrant disregard for DNS stability in this case is jaw dropping.
Comment by sandcat_ 5 days ago
Comment by padjo 5 days ago
Comment by troyrollo 23 hours ago
Comment by decimalenough 5 days ago
That said, my domain is simply unusual.name, and everybody in my family has email addresses in the form first@unusual.name. So this is a no-op for me, and I gather www.unusual.name will also continue to work, since I own the 2nd level outright.
Comment by NelsonMinar 5 days ago
Comment by febusravenga 5 days ago
I feel that I more trust some corpo (Google, etc) that one particular person.
I don't imagine setup where you can effictevely guarantee them full privacy.
Comment by decimalenough 5 days ago
Some people in my family use it as their main address, others don't, it's entirely their call.
But yes, ultimately I control the domain and could be nefarious if I wanted to. But there's a certain baseline level of trust as a family, I'm reasonably certain my wife won't poison the milk in the fridge and she's reasonably certain I'm not going to read her emails.
Comment by troyrollo 23 hours ago
This is only a safe bet until it isn't. If she starts asking about your life insurance and hiding her phone from your view, you will know it isn't a safe bet anymore.
Comment by sunnybeetroot 5 days ago
Comment by decimalenough 5 days ago
Comment by cesarb 5 days ago
I believe this is a very common setup: the "computer wizard" kid of the family manages the computers for the whole family. Not just emails, they have access to the whole computer (and have to fix when it breaks).
Comment by bityard 5 days ago
Comment by sunnybeetroot 5 days ago
Comment by xp84 5 days ago
But it hardly needs to be difficult. If you're running dovecot and postfix on a server somewhere then yes, family is screwed. But it's simple to use either some mail forwarding service that you pay for with a credit card, or something like fastmail (etc). Leave 2 pages of instructions for how to log into and renew the domain (print the QR code used for the 2fa enrollment!) and how to log in and pay for whatever the underlying services are. Place in a binder and label "Family.Name Email Management" and put it with your other important documents.
Comment by bityard 5 days ago
But more seriously, my domain and VPS is on auto-pay, so it doesn't just shut off the day I die. My survivors will have plenty of time to back up their emails and do whatever they want with them afterward.
Plus, the password for my computers and keychain is in a safe-deposit box if they feel like handing it over to a trusted tech-savvy friend of the family to shut down properly.
Comment by bentinata 4 days ago
Comment by vidarh 5 days ago
It made sense to us because our starting point was an email service letting people share lastname.sometld, but we never got close to as many registrants on .name as we had users on the webmail service (we had a couple of million accounts on that when it was sold to one of Marc Cubans companies for a relative pittance in the aftmath of the dot com bubble bursting)
Comment by xyzzy_plugh 5 days ago
How is this possible? I thought there was a 10 year limit.
Comment by elashri 5 days ago
> Registry Expiration: 2036-01-29 00:00:00 UTC Updated: 2026-09-03 08:12:27 UTC Created: 2002-01-23 14:41:45 UTC
Comment by leni536 5 days ago
Comment by swiftcoder 5 days ago
Comment by ClarityJones 5 days ago
Comment by mchesters 5 days ago
> 3.6. Have you communicated with any of the entities whose products or services might be affected...
> "No. Not applicable."Comment by mchesters 5 days ago
> 7.3. Provide any other relevant information to include with the request. If none, respond with “N/A.”
> None.Comment by fetzu 5 days ago
Comment by chrismorgan 5 days ago
Comment by chrismorgan 5 days ago
> 3.6. Have you communicated with any of the entities whose products or services might be affected by the introduction of your proposed service? [→ No.] If so, please describe the communications. [→ Not applicable.]
Gotta say that the entire form feels not applicable. The proposed service is the discontinuation of an existing service. I see from their website that other similar things do the same, but it feels broken when so many of the questions become nonsense.
Comment by wmf 5 days ago
Comment by xp84 5 days ago
Comment by jacobgkau 5 days ago
> 2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
> None. There will not be any effect on the life cycle of domain names.
If they're dropping existing domain names, that seems like it has an effect on the life cycle of those domain names. I suspect I must be misunderstanding what they mean by that question, because it otherwise seems like it shouldn't have passed basic muster.
Comment by account42 4 days ago
Comment by MadameMinty 5 days ago
Comment by noja 5 days ago
Comment by Yizahi 4 days ago
Comment by Henchman21 5 days ago
Comment by nirui 4 days ago
A stable online identify is important, that's maybe why you rent those domains etc. But after rent and forego quite a few, I slowly realized that domain at it's current format isn't a stable presence, instead it's more like branding instead of an identify. If an identify can be operated by different people without it's previous operator agreeing, is it truly an identify?
But I do need an identify, always under my control as much as possible, so people can trust the content and service running on it without having to guess if it's still me operating it.
Comment by summm 20 hours ago
Comment by psychoslave 5 days ago
So, where is our fully decentralized TLD alternative, free of ICANN or any central authority to handle how we grant names by conventions, without any money scheme in the game that attracts malevolent actors moving only through greed strings?
Also, this time let’s make it like usenet, so "person:named:Neil Fraser" or even "::Neil Fraser" (harder to type but less culturally entangled into English).
Comment by toast0 5 days ago
We can all edit our hosts file.
The problem with a lack of a central authority is domain names are most useful if they follow the highlander principle. There can only be one neil.fraser.name ... otherwise it's not usable for routing traffic if every webserver a Neil Fraser runs uses that address. (Yes, there are useful ways for one name to resolve to different webservers, but almost always those are webservers under at least loose control of a single entity or very exceptional cases)
Comment by CodesInChaos 5 days ago
But from what I remember, they fucked up the pricing function and it got overrun by domain grabbers.
Comment by NewJazz 5 days ago
Comment by qrobit 5 days ago
EDIT: seems like Ethos Capital private equity firm wanted the .org registry, and Xavier Becerra (Attorney General of California at the time) wrote a letter that played major role in transaction being rejected
> Dear Messrs. Botterman and Marby:
>
> I urge ICANN to reject the transfer of control over the .ORG registry to Ethos Capital.
> The proposed transfer raises serious concerns that cannot be overlooked.
(from https://itp.cdn.icann.org/en/files/correspondence/becerra-to...)
Comment by NewJazz 5 days ago
Comment by Apocryphon 5 days ago
Comment by lacoolj 5 days ago
First, that a legit dealer could/did(does?) sell third-level domains at all (Verisign, no less) Second, that the top-level is staying available, allowing for second-levels to be bought/sniped like you mention.
If you do lawyer up and need help with legal fees, I think this would be a worthy cause.
Comment by TZubiri 5 days ago
>2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
>None. There will not be any effect on the life cycle of domain names.
>2.2. Does the proposed service alter the storage and input of Registry Data?
>No. There will not be an alteration to the storage and input of Registry Data.
This sounds wrong? Is this just a knee-jerk form-filler reaction? It seems to me that the admitted "Upon discontinuation, no new third level domain names will be registered and existing third level domain names will be terminated."
In general this sounds like a grotesque misplay that is wildly uncharacteristic for the entity behind the timeless .com
Comment by TZubiri 5 days ago
It has been established that national identifiers are protected by it, and a domain works as a sort of international identifier, in this case a personal one.
No one is obligated to give you a domain, but by contracting an obligation to provide that identifier until 2040, they would at least be liable for those damages, but there's an argument that depriving you of an identifier already granted is a more fundamental violation of a right to a name, an identifier and recordkeeping of them.
Comment by Glyptodon 5 days ago
Comment by cpach 5 days ago
IMHO, this whole TLD seems kind of messed up from the start: https://en.wikipedia.org/wiki/.name
Comment by xbar 5 days ago
Comment by morissette 5 days ago
Comment by thbb123 5 days ago
Should I rush to reserve y.name so my email address and personal website can stay online?
Comment by kronodeus 5 days ago
Comment by doublepg23 5 days ago
Comment by 0xbadcafebee 5 days ago
Comment by xyst 5 days ago
Comment by xiaoyu2006 5 days ago
Comment by DaSHacka 5 days ago
Comment by gpvos 5 days ago
Comment by OtomotO 4 days ago
Everything business related runs over such a domain.
So I totally get you! It's like someone pulled the ruck from under your feet.
Comment by drnick1 5 days ago
While changing email is inconvenient, I don't understand the point about IoT devices. IoT devices should not depend on the Internet at all for obvious privacy and security reasons. If you are using IoT devices with "cloud" accounts, then this is a blessing in disguise. Put that garbage in the trash and rebuild around HomeAssistant, Zigbee, RTSP, etc. I find it hard to believe that someone hosting their own website would fall for the cloud IoT scam.
Comment by jmuguy 5 days ago
For instance, I own a .house domain that I use for a bunch of stuff that I've programmed. It would be a pain in the ass to go change that domain out. Now take that to next level and you're a business that's deployed a few thousand devices that need to call home.
I guess all this is to say - IoT doesn't just mean cheap botnet honeypot IP cameras. Take a look at https://www.balena.io/cloud for instance
Comment by drnick1 5 days ago
Comment by Sharlin 5 days ago
Comment by rahimnathwani 5 days ago
Imagine he's set up some IoT devices at his parents' home, and those devices use services that he hosts somewhere on the internet. It would be silly to hard code the IP addresses in there, right (unless he operates his own ASN)? So he would use DNS to allow those devices to find his server(s). This would be the case whether the servers are at his home, at his office, or in a rack at a data centre.
Comment by monkeyfacebag 5 days ago
Comment by swiftcoder 5 days ago
Comment by bix6 5 days ago
Comment by allthetime 4 days ago
Comment by nikanj 5 days ago
”Greetings from ICANN Global Support.
I am sorry to hear you are experiencing this domain access issue after your registrar's transfer. I will happy to provide you with relevant information and guidance.
Please note that, ICANN accredits companies as domain name registrars and works to ensure contractual compliance with the terms and conditions of the 2009 and 2013 Registrar Accreditation Agreements (RAAs).
ICANN does not provide domain name registration or manage domain accounts. As a result of that ICANN is not able to perform domain management for you.
If you need help to access and manage your domain, you will need to contact your domain service provider or registrar for assistance.
You may check who your registrar is by doing a domain search at lookup.icann.org.”
Absolutely infuriating
Comment by AtNightWeCode 5 days ago
Comment by mococa 5 days ago
Comment by CodesInChaos 5 days ago
> In April 2019, ICANN proposed an end to the price cap of .org domains and effectively removed it in July in spite of having received 3,252 opposing comments and only six in favor. A few months later, the owner of the domain, the Public Interest Registry, proposed to sell the domain to investment firm Ethos Capital. After intense criticism from nonprofit groups and significant figures in Internet history, the proposal was scrapped.
Surprisingly not by Verisign, who gave up .org in 2003.
Comment by r_lee 5 days ago
it'd fit like a PE firm focusing on chemical weapons
Comment by jeroenhd 5 days ago
Also, all common names with any of those prefixes have been registered a long time ago.
Comment by SJA7 4 days ago
Comment by niraj-agarwal 5 days ago
Comment by akulbe 5 days ago
Comment by aff-vasileva 5 days ago
Comment by mzajc 5 days ago
Comment by menzoic 4 days ago
Comment by mig4ng 5 days ago
Again, you're security is only as strong as your DNS.
Comment by r_lee 5 days ago
Comment by cute_boi 3 days ago
Comment by johnnyApplePRNG 5 days ago
This is ridiculous.
Comment by haebom 4 days ago
Comment by hoppp 4 days ago
Comment by Ecco 5 days ago
Comment by djoldman 5 days ago
bbb.name can ONLY be registered if it is not already registered AND there are no 3rd levels registered on bbb.name currently.
Comment by iminatx 4 days ago
Comment by echoangle 5 days ago
How would that help? The problem is that he's losing access to all the accounts currently tied to fraser.name, if he is changing that he can just use any arbitrary domain anyways.
Comment by Ecco 5 days ago
Comment by Aachen 5 days ago
That's just my reading of the situation though. The person could now hope they're the first to claim their second-level domain once it becomes up for grabs, but there's probably a dozen other people with a fraser subdomain that would want the same, plus however many hundreds of scalper scum. Probably the best you can hope for is that whoever does get it, has the decency to honor the original third-level domains for a reasonable fee
Comment by KomoD 5 days ago
You can. Anyone can register a .uk, and you don't need to own the .co.uk
Comment by Aachen 5 days ago
If they've recently changed that and I'm misreading Wikipedia, that doesn't change the underlying point that the answer was "you couldn't". Otherwise I've grossly misunderstood the whole post and how verisign is proposing to cancel this person's third-level domain
Comment by orra 5 days ago
Comment by e_l 5 days ago
So the argument goes, society as a whole gains more if we prevent anyone from owning `fraser.name`.
A legitimate alternative though, is to register `FIRST-fraser.name`
Comment by p4bl0 5 days ago
With it you got an email redirection from firstname@lastname.name to the address of your choice. At some point this feature was discontinued (I assume when VeriSign took control of the .name TLD), a bit after it was decided (again by VeriSign) to allow registering first level .name domain. My main email address stopped working from one day to another without me being warned in any way.
When this happened I've emailed VeriSign and my registrar at the time, and tried several time since then, to be able to register the first level domain I'm the only one using, but they categorically refuse, despite recognizing that a single subdomain has ever been registered. They kept saying that I could just let the domain expire, wait for the grace period, and register it once it's liberated, hoping that no one does it before me, and without any solution for the downtime in the mean time…
And now this… fuck VeriSign -_-
Comment by antif 5 days ago
Comment by ZiiS 5 days ago
Comment by xp84 5 days ago
Comment by anominal 5 days ago
Comment by p4bl0 5 days ago
Comment by iminatx 4 days ago
Comment by underdeserver 5 days ago
Comment by aidenn0 5 days ago
Comment by aeternum 5 days ago
Overall this seems like the right move, either they all are trusted or none.
Comment by basilikum 5 days ago
Comment by account42 4 days ago
Comment by 1970-01-01 5 days ago
Comment by notahacker 5 days ago
Comment by 1970-01-01 5 days ago
Comment by Macha 5 days ago
Comment by 1970-01-01 5 days ago
Comment by j16sdiz 4 days ago
A random youtube channel have way more than that.
Comment by khalic 5 days ago
Comment by cjjuice 5 days ago
Comment by Aachen 5 days ago
Comment by marbleotter115 5 days ago
Comment by eleventen 5 days ago
...minutes?
Comment by kotaKat 5 days ago
Comment by Evidlo 5 days ago
Comment by cxr 5 days ago
* or arguably the same amount or less; for additional context: the author is an ex-Googler
Comment by gpvos 5 days ago
Comment by rationalist 5 days ago
Comment by advisedwang 5 days ago
Comment by ipython 5 days ago
Comment by buzzy_hacker 5 days ago
whois firstlast.com | grep 'Creation Date'
shows his birthday, which I found amusing!Comment by Aachen 5 days ago
Comment by echoangle 5 days ago
Comment by alaithea 5 days ago
Comment by layer8 5 days ago
Comment by mcmcmc 5 days ago
Comment by tasty_freeze 5 days ago
Comment by xiaoyu2006 5 days ago
Comment by bossyTeacher 5 days ago
Comment by Maxforever 5 days ago
Comment by rburhum 5 days ago
Comment by notorandit 5 days ago
Comment by strenholme 5 days ago
But, assuming that Verisign can’t keep third level domains (as a DNS implementer, I don’t think third level domains is a huge deal; see thread below):
* Third level names where only one person has the second level domain should be transferred to whoever owns that single third level name.
* Third level names where multiple people have the same second level domain should be put up for closed bidding: Only current owners of .name domains with a given second level domain name (e.g. last name) will be able to bid for the second-level domain. So, if one has john.smith.name and joe.smith.name, Joe Smith and John Smith will be in a bidding war for smith.name.
If the issue of .name not being in public suffix is a real issue, Verisign can handle that by disabling new third-level .name registrations, and provide Public Suffix with a list of those registrations (just send all the owners a privacy notice, making it clear that the existence of the name will be made public for security reasons). More reading: https://github.com/publicsuffix/list/issues/2306 (There seems to be issues with this list being too long to keep in the Public Suffix because there’s too much software out there which can’t handle it. That seems strange to me: Even here in 2026 where RAM costs far too much, Deadwood can store a list of 240,000 blacklisted entries in under 10 megs; there are about 22,000 three-level .name domains and I could store that list in a way that could be very quickly looked up in about a meg of memory)
Now, personally, I think Verisign can keep these messy third level names, and are doing things this way so that Neil Fraser has to compete with every single 2-bit cybersquatter out there for the rights to fraser.name.
As an aside, it’s trivial to have DNS servers handle multi-level domains without having to have a zone file for every level; e.g. https://this.is.a.long.name.maradns.org works, and there’s no zone file for name.maradns.org, long.name.maradns.org, a.long.name.maradns.org, and so on.
Also, since people have brought up the “org fuckery” without providing details: https://bluecatnetworks.com/press/the-org-domain-sale-explai...
You know dang well if .org was owned by an investment entity, they would had jacked up the prices as much as they could get away with.
Comment by xp84 5 days ago
What they should do, is nothing.
Comment by strenholme 5 days ago
As a DNS implementer, the action plan is unnecessary. There are, what, only 22,000 or so .name domains. One can write code to do two lookups for firstname.lastname.name: If firstname.lastname.name is found, return the NS delegation. Otherwise, if lastname.name is found, return that NS delegation. Finally, if neither is found, return NXDOMAIN.
One argument is that this is hard to implement in the real world (it’s about one day, at most one week for a skilled DNS developer to pull off; probably half a day to be honest, and yes I have written code like this), so then yeah if that’s a real concern let’s have a closed auction. I’m opposed to the auction, based on my experience that this isn’t hard to implement.
If it’s an issue, just stop all new firstname.lastname.name registrations, and only allow lastname.name new registrations. Then we only need to deal with this corner case for about 22,000 domains, which we can keep in a special hash and would take about four megs to store.
Comment by xp84 5 days ago
Comment by sillygoatdev 2 days ago
Comment by Unified-Mentor 4 days ago
Comment by MagicMoonlight 5 days ago
Comment by jmuguy 5 days ago
Comment by Aachen 5 days ago
Comment by mminer237 5 days ago
Comment by Aachen 4 days ago
Someone whose last name is Oppenheimer should also not have a problem registering their last name at any TLD so long as it's still available (first come first serve, and both have a reasonable claim to it so it won't be taketh away from either one), much less if yours is actually a different word
Comment by pmdr 5 days ago
I don't know what that history is, but did it really make a tld used by only 22k people more appealing?
Comment by decimalenough 5 days ago
Comment by cormorant 5 days ago
Comment by swiftcoder 5 days ago
Comment by bawolff 5 days ago
Comment by jawns 5 days ago
It's a pretty bizarre exception to the normal, intuitive ways that domains work.
I'll admit that it's a crappy situation and I would be frustrated in his place. But if I were in his place, I probably would have also thought it prudent to have a backup plan.
Comment by angoragoats 5 days ago
For the first couple of years of .name's existence, it only allowed registration of third-level domains, and the ability to register second-level domains was added later (and only if no third-level domains existed for that second-level domain).
The author is in no way at fault here, and I don't think I would have assumed there was a heightened level of risk if I were him.
Comment by swiftcoder 5 days ago
What exactly is non-standard about an ICANN-approved TLD? Yes, the multi-level structure is a little odd, but given that ICANN approved it in the first place, one has a reasonable expectation that they would work as advertised.
Comment by jawns 5 days ago
Even though .science was launched in 2014 (more than a decade ago), I still consider it a non-standard TLD and still deal regularly with difficulties around its use. (For instance, you wouldn't believe how many online services reject email addresses than end in .science because they use regexes that exclude TLDs with 7 letters.)
Likewise, I've registered .lol and .fun domains but never would have assumed that just because they're available now, they will be available in perpetuity.
In that sense, .name as a third-level TLD is even more non-standard, because the standard way domain registration works is by choosing a single "second level" domain name, then adding subdomains.
Comment by angoragoats 5 days ago
Why wouldn't you assume this?
> the standard way domain registration works is by choosing a single "second level" domain name, then adding subdomains
The entire ccTLD systems of the UK, China, Germany, France, Japan, and many others would beg to differ.
Comment by jawns 5 days ago
Whereas with .name, you are choosing what appears to be a subdomain, followed by what appears to be a domain name. But under the hood, you do not own all subdomains for that domain name; you own only the combination of first_name.last_name.name.
Comment by angoragoats 5 days ago
(And yes, I am aware that you can also register last.name by itself, but only if there are no third-level domains using it, so for practical purposes it doesn't change my question above. Plus, when the OP originally purchased his domain, you could only buy third-level domains for .name.)
Comment by jawns 5 days ago
1) benedict.cumberbatch.name
2) drstrange.co.uk
I expect the average person would assume that for the domain 1, .name is the TLD, cumberbatch.name is registered by a private entity, and benedict (and any other subdomains associated with cumberbatch.name) is a subdomain fully controlled by that private entity.
Whereas for domain 2, I think the average person will view ".co.uk" the same way they view ".com", even though technically it is both a ccTLD and a second-level domain.
Comment by angoragoats 5 days ago
The only people who will make the assumptions you state are people who are tech-savvy enough to be familiar with those concepts, but not well-versed enough in them to understand the nuances we’re discussing.
And none of this does anything to advance the argument that .name is somehow nonstandard.
Comment by swiftcoder 5 days ago
Comment by account42 4 days ago
Comment by angoragoats 4 days ago
Comment by swiftcoder 3 days ago
Mine just has an animated llama telling me not to click suspicious links in emails
Comment by account42 4 days ago
.de doesn't use third level registrations.
Comment by angoragoats 4 days ago
Comment by efreak 5 days ago
Comment by zamadatix 5 days ago
Comment by avazhi 5 days ago
Uh, 99% of people would assume a .name address is a scam. Hate to break it to you.
Comment by swiftcoder 5 days ago
Comment by userbinator 5 days ago