Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3LD registered on top). It’s a bit insane that they can decide to just terminate all existing 3LD registrations. One would hope that they’d at least continue to reserve the 2LDs for some period to avoid domain squatting, but this isn’t mentioned in the proposal and I doubt Verisign would graciously do so.


Another thing that should be obvious and yet they refuse to do: when there is a single third-level customer for a given second-level, offer them a way to get the second level domain. I've been asking VeriSign this for 15+ years, they always said no, even if at some point they confirmed that there were no other third-level than mine under that second-level domain. They're insane and should not be in charge.


> They're insane and should not be in charge.

I remember back when we had to write mechanize scripts to drive a browser through the renewal process, because if you had dozens, hundreds, or thousands of domains there was no nonmanual way, especially if you wanted extended verification or something silly like that.

So what I'm saying is, agreed and that has always been true.


That actually sounds like a good thing. Why are you hording hundreds or thousands of domains?


I was working for a company that had hundreds and thousands of domains. It was a fortune 50 company, and they had a policy generally against wildcard domains.


I really wish I could be this stupid and have enough power to make such stupid policies


I felt the same way at the time. Now, I believe we have better things to spend our collective time and energy on.


What do you mean wildcard domain? Are you perhaps confusing domain renewals with dns entries?


Instead of registering foo.com, and having bob.foo.com, they would register bobfoo.com - they had hundreds or thousands of certs, as a result, and had to renew them all annually or biannually. We didn't even manage all of the domains, we just had to renew the ones our group was responsible for, and it was in the dozens, and each form was ~30-40 actions to fill out correctly. I forget whether they were quarterly or we just ended up doing it all the time, but it was a maddening task.

Part of the explosion was that domains were not just in one TLD, they were bobfoo.com bobfoo.bar bobfoo.xyz and in many cases regionalized to bobfoo.co.uk or whatever. It wasn't "domain hoarding", because if you registered bobfoo.info you'd just get UDRP'd by corporate anyway, and nobody really wanted domains of the form somelongnamebobfoo.com

This was also before something like LetsEncrypt where you could automatically generate certs for programmatic usage, so they were all done manually.


> nobody really wanted domains of the form somelongnamebobfoo.com

You'd be surprised

and renewing annually is a great way to accidentally forget some of these and let someone use them to hack your customers


Not OP, but I am guessing they have domains like fordcareers.com or fordsecurity.com instead of careers.fore.com or security.ford.com, etc


Exactly what they did in many instances.


This really grinds my gears, way more than it should for some reason.

Use the system as it was intended, people!


Far from the most frustrating thing they did, trust me. I could tell you stories for days and never run out of more frustrating anecdotes.


Sometimes you don’t want everything hanging off the main domain, because if DNS gets horked everything goes down.


Really large companies have lots of domains even if they aren’t “hoarding” them. But even a few dozen domains is enough to need automation.


One reason could be to prevent phishers from getting names similar to your actual domain(s).


Should Google be allowed to keep Google dot lol if it doesn't do anything useful with it? What about Google dot wtf? Any person with two brain cells would say these domains should belong to a fervent critic of Google, not to Google.

Sadly neither our world not its legal system is built on common sense.


Domains are an infinite resource. Even a random string of characters can become valuable if the services running off that domain are valuable.


Why would they want to drop the possibility of selling some as premium domains? If they have their shells setup right they will probably be able to get a premium from some 3rd level domain owners wrongly afraid someone else is interested.

The main problem with the Internet today is that we didn't destroy ICANN when they started this TLD sell off crap. A replacement institution may have at least told Verisign a TLD they can't run transfer to someone who can meet its promises can only be destroyed.


The .name predates the TLD well-off crap. The first huge bulk of new TLDs happened in 2014, .name dates back from 2001, just like .info or .coop.

Also, .name filled an actual need for general non ccTLD: companies had .com, organizations had .org, Internet related stuff had .net, there was .gov, .edu, .mil, and ccTLDs, but nothing made for individuals. It filled this use case, it actually made sense.


I thought that was the point of .me, but apparently that’s actually the Montenegro national TLD despite widespread use for personal sites.

https://en.wikipedia.org/wiki/.me


All two letter TLDs are reserved for ccTLDs.


And some, like Anguilla or Tuvalu, hit the lottery and get a nice income from renting theirs out for general use.


> Also, .name filled an actual need for general non ccTLD

That's a silly idea. While there are laws that ensure to a decent extent that there is a single company called "Google", so that it's relatively unambiguous who `google.com` should refer to, there is no uniqueness whatsoever to personal names. There are likely hundreds of thousands of people called "John Smith", so the FQDN `john.smith.name.` would not really tell you anything.

This is without even going into the fact that "first-name.last-name" is culturally specific (though, to be fair, a large proportion of cultures in the world use this format).


> While there are laws that ensure to a decent extent that there is a single company called "Google"

There aren't laws to ensure that. Within specific jurisdictions, sure, but not globally.

A lot of companies also don't trade under their full name. Apple, famously, wasn't founded as Apple but as Apple Computer, and was only able to rename after achieving a deal with Apple Records.

The lack of more namespaces also led to things like nissan.com being owned by Uzi Nissan (and now his family, I assume) rather than the car company.

While you're right that there are many duplicates, one extra TLD still broadened the namespace a lot, and the most important part of the idea was that by giving people less of a reason to register <lastname>.com or <lastname>.cctld, we'd give far more people the option to get <firstname>@<lastname>.name as an email address.

(The cultural aspect is irrelevant - it was not enforcing a specific order. If people wanted to register lastname.firstname.com, nothing would stop that)

By the time we applied for .name we actually had experience running a webmail service where people shared ~60,000 domain names, and had ~2 million accounts on that, and we'd done extensive modelling before acquiring those, and as a result at the time we probably had better data than anyone on the distribution of names worldwide.

What we seriously overestimated (every applicant overestimated how popular the new TLDs would be, but the generic ones, generally did better) was how many people were in the intersection of people who'd figure out how to buy a domain name and people who wanted firstname@lastname.name as an e-mail address.


> There aren't laws to ensure that. Within specific jurisdictions, sure, but not globally.

Many trademarks are indeed more or less global.

> A lot of companies also don't trade under their full name. Apple, famously, wasn't founded as Apple but as Apple Computer, and was only able to rename after achieving a deal with Apple Records.

That's irrelevant - Apple Computers owns the Apple trademark (for certain industries).

> The lack of more namespaces also led to things like nissan.com being owned by Uzi Nissan (and now his family, I assume) rather than the car company.

It's not perfect and not guaranteed to be unique, yes. But people's names have many orders of magnitude more collisions.

> <firstname>@<lastname>.name as an email address.

No, you'd at best get `??@firstname.lastname.name` as your email address. Which, again, is irrelevant, as it's impossible to say which of the many thousands of Firstname Lastname people this might belong to.

> (The cultural aspect is irrelevant - it was not enforcing a specific order. If people wanted to register lastname.firstname.com, nothing would stop that)

I wasn't referring to a specific order, but to the cultural idea that people have 1 firstname and 1 lastname. In Spain, for example, people typically have 1 first name and 2 last names - but you couldn't get `a.b.c.name` as an address. Having a first name, a middle name, and a last name is also very common.

There are also cultures where people simply have one name, not first + last. For example, a person's full legal name in Tibet might just be "Woeser".


> Many trademarks are indeed more or less global.

And the vast majority are not, so this has no relevance.

> That's irrelevant - Apple Computers owns the Apple trademark (for certain industries).

And yet you yourself concede in this very same statement that it is not absolute. Even with one of the most famous examples from one of the largest companies in the world.

> It's not perfect and not guaranteed to be unique, yes. But people's names have many orders of magnitude more collisions.

For most people our data was very clear that for most names the number of collisions are in fact relatively low, further significantly mitigated by the combination of nicknames and ability to use middle names. Very few last names are highly frequent, and very few of those with common last names have an intersection of a very common first name and a very common last name. The vast majority of people fall in a long tail of last names held by a few thousand people, and first names held by a few thousand people.

For the webmail service that preceded .name, the vast majority of the two million accounts registered were for names for people who would have no way of getting their firstnam@lastname.<tld> addresses without it because of colissions. That some of those would not be able to get one of our addresses either because their specific combination was particularly common does not alter the objective fact that we massively broadened the availability.

> No, you'd at best get `??@firstname.lastname.name` as your email address. Which, again, is irrelevant, as it's impossible to say which of the many thousands of Firstname Lastname people this might belong to.

No, that was categorically not how it worked. I personally designed the system to handle this. We provided firstname@lastname.name e-mail forwarding to an address of the registrants choice, and provided a reference platform for registrars to support that, that I also designed, and managed the implementation of.

Given that you haven't even bothered to understand what it provided before criticising it, it's hard to assign much value to your arguments.

> I wasn't referring to a specific order, but to the cultural idea that people have 1 firstname and 1 lastname. In Spain, for example, people typically have 1 first name and 2 last names - but you couldn't get `a.b.c.name` as an address. Having a first name, a middle name, and a last name is also very common.

Spanish people are perfectly capable of using their firstname and their fathers first lastname when limited to one last name. They are also capable of using 2, 3, or 4 last names depending on context and preference. For any that wanted to use more, they had more flexibility, because they could similarly register b.c.name, and use a.b.c.name, or register any combination preferred for the last two labels and set up the rest themselves.

Same if you insisted on using your middle name. We only provided the increased ability to share among those with overlapping two last labels, but that did not change the ability to use regular DNS features.

> There are also cultures where people simply have one name, not first + last. For example, a person's full legal name in Tibet might just be "Woeser".

While you're right that exists, firstly it's a miniscule proportion of people. We collected stats on that two. If you fell in that group, your options were either to use another TLD, or use another indicator. In Europe as well, in cultures that used to use only one legal name, people would still regularly use distinguishing attributes, such as place names or occupations. In fact, both of those are the source of most legal lastnames in Europe today. E.g. my last name is the name of the farm my great great grandfather came from, and names like Baker and Smith are occupations.

There is no need to be able to be a perfect match to a given format for everyone to still meaningfully and significantly enlargen the available namespace.

This is a long way of saying you're being intentionally obtuse.

We overestimated the demand for paying for "vanity" addresses, but ability to register peoples names was not a problem - something we categorically proved with the webmail service that preceded it.


Because it's not worth it financially. After icann is the tld registrar, and after that above. So, if anyone is destroying it, it's not the registrar, it's the tld.


>> In light of the fact that Verisign and ICANN are in the process of discussing the upcoming renewal of the .NAME Registry Agreement, ICANN is issuing Verisign this letter in lieu of a contract amendment to the expiring

It's clear to me ICANN can say no agreement change or total destruction. You are correct that they could do something else and show every indication that they would never do the right thing and that is why they should be destroyed.


It seems insane because it seems like a big point was to have a permanent site for your name. This just devalues all domain names, showing that they can do a rug-pull at any time because they don't want to manage it (how about turn it over to a private company that can adjust costs so they can make a profit and keep it running?).


This is why new gTLDs are insane and stupid. It is about time there is some _yours for life_ DNS system.

In this age, allowing domain names to be owned by other entities is almost like allowing a company business registration number or one's national id card number to be transferred to others.

I think name squatting is a problem, but it is not like that current system has solved it.


Squatting is purely a result of being able to resell domains.


DNS managed by the United Nations.


DNS names are never permanent, they are in fact extremely im-permanent, always requiring periodic re-registration (though, to be fair, with pre-emption rights, so you have some guarantee of keeping your registration if you don't forget).


> the right thing they should do

Can someone explain why a product "registered and paid for until 2040" can be unilaterally voided like this without compensation?


Especially when the marketing was saying [1]:

> As your .name can be registered for up to 10 years and ownership is renewable, your .name really can be yours for life.

It seemed like there was an offer of renewable registration at least for a life term.

[1] https://web.archive.org/web/20020609132126/http://nic.name/c...


Fun fact: The Peter Morgan listed on that page was an actual employee of Global Name Registry. I believe he agreed to sign a contract to let us use the name as example.


That's the crazy part - they can take your money, prorated to some future-period but, upon cancellation, the remaining future period of YOUR money becomes THEIR immediate revenue recognition. Is it fraud or theft? To me, it has to be one or the other...


And lets be clear here, refunding the registration fees should NOT be considered even close to sufficient compensation as Neil and others like him have reasonable assumed they would control the name for that time and made choices that depend on that.


Because they haven’t been sued enough yet?


ICANN should not approve such an obviously fraudulent move even without anyone being sued. Neither should Verisign even consider that they'll be able to get away with it. If you need to sue for this something else is already very wrong with the system.


A lack of consequences (getting sued and losing) is what leads to this.

Is it corrupt? Yes. Is there a factor making corruption inevitable? Yes.


I guess I’m confused why the author isn’t pursuing this legally.


The post ends with: “Time to lawyer up...”


He is.


Maybe they want to avoid the ambiguity between john.doe.name versus john-doe.name, and I assume they prefer the latter scheme because it probably sells better. Nevertheless, discontinuing existing domains is disgraceful.


Even that doesn't pass basic scrutiny. The same ambiguity can and always will exist with tim-apple.com and tim.apple.com - there's nothing here that needs fixing.


I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real.

It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com

In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com

edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule


That is definitely not true. There are literally thousands if not tens of thousands of well known domains that do this. .co.uk is a very common example.


.name is still a weird edge case because of the naming rules. Whether or not all subdomains under doe.name belong to the same person depends solely on whether the first person registered "doe.name" (in which case they do) or "john.doe.name" (in which case they don't, and "doe.name" is excluded from purchase as a standalone domain).


The fact that multiple organizations need to keep a public list of known 3LDs proves it's the edge case, does it not?

"Here's a list of things that look like subdomains for you to treat as 3LDs instead of subdomains" sounds exactly like the solution to an edge case to me.


I think the problem is that .co.uk, .gov.uk and so on are very well known in the UK.

The .name subdomain rules are not very well known anywhere.


How familiar are you with Serbian co.rs, org.rs, in.rs (individuals) and top-level .rs too? Will you confuse it with iz.rs giving free subdomains to individuals too ("iz" means from in Serbian)?

How about all the other 200+ country TLDs and rules for non-country TLDs?


This seems largely country dependent with some exceptions.

In the US, once upon a time, elementary/middle/highschools might be attached to something like schoolname.district.state.gov. But now, even my local area school now has a .com. It seems that older hierarchy style is falling out of fashion for smaller/shorter domains across public services, schools, government agencies, etc.

Now here it seems to be either a .com, .gov, .org, or a totally different and newer tld. Even .net has fallen out of fashion.


The writing was on the wall when Pennsylvania switched their license plates from www.state.pa.us to visitpa.com


Good article on this by a fellow hner

https://computer.rip/2025-11-11-dot-us.html


I can’t think of any prominent ones outside of country code domains.


You can almost guess someone's age from that alone - they're more rare, but long domain names still appear that encode a city and a state, and you could just "grab" the first part when signing up.


Outside of the context of ccTLDs and city.state.gov etc, I struggle to think of examples 3LD+ domains where they are owned and operated by completely different concerns than the parent. If at some point you could just register your own mysite.state.gov domains willy nilly that's probably before my initial time online around 2000.

Another poster raised the point of hosting services which is valid. But at present outside of that example and the above I really can't think of an example where you have a link to entity.com and you have any significant cause to verify the identity beyond the 2LD.


Many services today support vanity domains - Google even has special support for it: https://publicsuffix.org/list/public_suffix_list.dat


Tangential, but why call out Google specifically? PSL is widely used: https://publicsuffix.org/learn/


All Indian banks use bankname.bank.in as their domain. I’m not sure who owns bank.in but this is a common suffix which is different from the .co.uk pattern.


IDRBT Institute for Development and Research in Banking Technology


I remember I had beach.santa-cruz.ca.us at one point registered to me. I owned beach.santa-cruz.ca.us, someone else owned santa-cruz.ca.us, yet someone else owned ca.us, and I believe Network Solutions took care of .us at the time.


You say "registered" to you as though this was via an official registrar but surely you mean that someone rented ca.us and decided on their own to lease out subdomains to people?

(Aside, I always see "owned" and "bought" but you can only ever "lease" under the ICANN system as the present situation so clearly demonstrates.)


Historically, xx.us (where xx is a two letter state code) domains have been owned* by the named US state, which then would issue subdomains on top. I believe this was originally planned and set up by ICANN themselves.

*: I realize that “owned” is a loaded word here, but (1) I’m referring to a registrar/issuer, which makes it yet more complicated as to how much “ownership” (de facto or otherwise) a given entity may have, and (2) I really don’t give a fuck about pedantic word choice if the meaning is unambiguous.


My aside wasn't intended to be pedantic, rather observing the apparent inconsistency in how it appears people think about these matters versus what the present situation illustrates the reality to be.

> but (1) I’m referring to a registrar/issuer, which makes it yet more complicated

We're also talking about a ccTLD which makes it even more complicated. AFAIK those fall entirely under the jurisdiction of the respective UN recognized government although I don't know how strong that agreement is in practice (treaty versus something else).

So at that point I guess we've roughly got ICANN -> US federal government -> CA state government -> registrar -> private party -> sublet.


The way it worked is that someone nominally representing the CA State Government had* ca.us, and they in turn gave* san-jose to someone who nominally represented San Jose, los-angeles to someone who nominally represented Los Angeles, santa-cruz to someone who nominally represented Santa Cruz, and so on. city-name.ca.us domains were still free (and charging for .com and .org domains was a new thing at the time); you would look in the zone file to see who owned* a given domain, email them with your nameserver names and IP, and they would add it to their zone.

This isn’t how things are done these days; names visible to the public are pretty much always in the form {domain}.{tld} or sometimes {name}.{domain}.{tld} (e.g. my own https://samboy.github.io). Registration is now done by bots and companies that spam you to death to try and get more money from you (the Internet wasn’t like that in the beach.santa-cruz.ca.us days). Domain names with multiple levels of delegation aren’t around they way they used to be.

* rented/leased/had control over/whatever


> This isn’t how things are done these days

The old locality domains still exist, and in many localities you can still register them today by the same "email a request to some sysadmin" process. https://news.ycombinator.com/item?id=48122635

Your beach.santa-cruz.ca.us domain is still in DNS, just with a broken delegation chain. You could reclaim it right now by setting up a nameserver at reality.samiam.org.


I’m amazed beach.santa-cruz.ca.us is still around. I’ve given it some SSL certs and have reclaimed it:

https://beach.santa-cruz.ca.us/

Thanks for checking the zone files of the parent domain to verify it’s still there.


Wait what haha. Do you also own samiam.org?


Judging by his username (strenholme) and the contents of https://samiam.org/ (Sam Trenholme's webpage), he does indeed!


  > AFAIK those fall entirely under the jurisdiction of the respective UN recognized government
How does that work for e.g. Taiwan, where the UN recognises the mainland government's claim to sovereignty in practice?


It's complicated and political, like always. Officially, the ISO 3166-1 alpha-2 country code list is used to decide who gets a ccTLD. (And Taiwan is included there.) But for example ".su" still exists for historical reasons, even though the Soviet Union is long gone (and its code is listed as "exceptionally reserved", which I assume translates as "we have no fucking idea what to do here.")


This raises an interesting question. If they aren't strictly following UN recognition then would it be possible for ICANN to award control to one party while the UN recognizes an opposing party as the legitimate government?


Github Pages is probably the most well known one (on here).

I think geocities had this as well?

A lot of hosting services offer this in general. (eg render)

Tumblr? (Might not count as the control over the page is more limited. The subdomains "are" still tumblr.)

For reddits subdomains are redirects to subreddits of the same name, so I guess that doesn't count.


None of these examples are of actual separate registration/ownership of a 3LD from the parent 2LD. Cloudflare owns the domain for myproject.pages.dev and hosts all the relevant infra. Not to say that there isn't a different entity represented by the 3LD than the 2LD but it's not exactly the same.

Also I would not consider the examples of tumblr and reddit to be relevant. A person's blog on myprofile.tumblr.org is still the tumblr organization. This would be true for reddit even if they didn't redirect. Reddit admins moderate content on all subreddits.


I see, that's a valid way to think of domain ownership.

When I read > I have been taught and tell my users to check the domain to verify a website is real.

I was thinking more of control of the content as "ownership" of the domain.


The point on hosting providers is well taken. You do have to consider x.pages.dev as the wild west not cloudflare of course. One difference though is you will never receive an email from x.pages.dev asking you to do something. The domain ownership still does play a part.


You can buy example.it.com on many registrars. Someone bought it.com and operates it like a TLD.


Interesting. I do wonder how many people outside scammers and squatters buy them. I'd rather have an .xyz or .biz address personally.


When someone defames at SEO-optimized large-company.it.com, then Large Company gets interested.

Or, more succinctly, when money gets involved.


>It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com

I think you meant to say "the owner of John.Doe.name does not need to own Doe.name" since .com just works under the 'normal' rules you're used to.

But it's worth pointing out that under the current system (that Verisign is destroying), no registrant owns (e.g.) fraser.name just as no one (but the registry itself) owns co.uk. So, if someone checks who owns fraser.name they wouldn't have found a scenario, for instance, that fraser.name belongs to, say, Simon Fraser University, with admissions.fraser.name belonging to some phishing site.

> I have been taught and tell my users to check the domain to verify a website is real.

Anyway, having seen enough eyes glaze over at the most basic tutorials of this sort, I'm afraid you're wasting your time. Given that this edge case is on nobody's radar, I don't think it's what's preventing 80% of Internet users from being able to get a passing score on a basic quiz on the hierarchial DNS. As evidenced by all the government entities that gave up and registered literal ".coms"


Yet that is a problem the owner of such a domain has freely entered into by buying that domain, it's their right to keep it despite this apparent problem, if they wish.


Understood, and .name isn't being used enough in business to worry about 'the effect it will have on my users'. Just pointing out that it doesn't work like the 'norm' (although I guess it's not quite as unique as I thought, either)


That's actually the point of the .name TLD is that it's not for businesses, it's for individuals. This whole situation demonstrates ICANN is more for businesses than individuals. It should just be there for everyone and every organisation that's trying to use URI's, shame that it's not worked out that way. This is exactly what the big tech companies want, they might as well hand ICANN over to Facebook or Google, they wouldn't do much worse.

Looking at the threads below, very few people are discussing technical things in dns terms like zone or nameserver.

Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with.

Then when you consider DNS is fundamental infrastructure and people build secure things on top of it, (ahem DNS challenges for certs), it's remarkable that anyone would want or desire edge cases.


There is a list called the Public Suffix List, which is used for most purposes to make determinations about which 2lds do not own/manage the corresponding 3lds. It's maintained by Mozilla as a public service, which isn't exactly where you'd expect to find it. But it's mostly important for web security / "same origin" stuff, so it makes sense.

In addition to all the country codes TLDs that do 3rd-level registration, the PSL does also include stuff like github.io. (Maintenance of the list involves manual volunteer labor, so scaling is a real problem...)

(And of course the PSL wouldn't work well for the .name situation, where it's sometimes 2 and sometimes 3, and it can change over time. But that's no excuse for this clusterfuck of just suddenly dropping a bunch of domains that are paid up years in advance.)


This doesn't seem like a problem if you exclusively support 3LDs and don't let anyone register 2LDs.


This wasn't really a consideration for anyone back when we applied for .name, and it already wasn't true back then (.us, and .uk were both prominent examples where it didn't hold)


Problem is, all these systems we still use were never designed to be like this.

Hell DNS used to be one woman in an office who updated the zone if you e-mailed her.


People still fall for paypal.com.4385ht43987th34098rh34279h3.legitorg.ru


There are still exceptions to this like .co.uk and many others.


Hello sysadmin. Good luck navigating the internet.

What you should know, and what your browser does know and automatically applies cookie policy and colouring your URL bar, is the Public Suffix List: https://en.wikipedia.org/wiki/Public_Suffix_List

It will let you know that, for example, one does not need to own .co.uk to own the subdomain foo.co.uk.


The .name mess is not in the public suffix list.

https://github.com/publicsuffix/list/issues/2306 for more discussion.


The public suffix list is a half assed bandaid over a fundamentally broken system.


I appreciate this, and yeah the government/education ones slipped my mind, but I stand by the fact that the reason a list needs to be kept in the first place is because this is the edge case and not the norm.


Supposing it were not an edge case and were typical, how exactly would you implement the same thing without keeping a list?


True, they can’t outright prevent the ambiguity, but much fewer people will go to the trouble of establishing such subdomains when the option isn’t directly offered by the registrar.

This is my theory because, a priori, 3LDs should be more profitable than 2LDs, because with 3LDs John Doe and Jane Doe don’t have to compete over doe.name, but instead can each separately purchase john.doe.name and jane.doe.name. Apparently, however, that’s not a benefit of 3LDs in practice, which leads me to conclude that john-doe.name and jane-doe.name just sell better.


Prior to reading the OP blog post, I had never looked into the particular rules that .name has.

To me, prior to knowing how it works, I would have assumed that either

a) john.doe.name would be a subdomain that someone who was just starting out had gotten for free supported by ads. Similar to having johndoe.freewebs.com back in the day. Not something most people would use for anything professional.

or,

b) doe.name was registered by one of the people in a family of Doe’s where every Doe is pretty closely related. For example, John of john.doe.name and Jane of jane.doe.name are husband and wife, or third cousins, or what have you. Most of the content, I would assume, is mostly about things that relate to the family. Like maybe one guy is doing a family genealogy project tracing the roots of this little cluster of Doe’s back in time and has made a site covering the findings from his research. And another one probably has some photo albums with pictures of like previous Thanksgivings and other family get togethers. In other words, nothing I would care about unless I was in their family or a very close friend of the family.

I would not have guessed that .name 3LDs worked the way that it did if I hadn’t read about it.

And on the other hand, if I saw just www.doe.name or johndoe.name, I would not make such assumptions. It would be not much different than seeing www.doe.com or johndoe.com respectively. I would just assume that .com was already taken and therefore they used .name, or that they happened to like the .name TLD because it emphasises that their site has their name as domain name.


>I would not have guessed that .name 3LDs worked the way that it did if I hadn’t read about it.

The situation in the OP is exactly what you just put as A)


It's... not.

Go to whois.nic.name and search for neil.fraser.name, and you will find whois information for that registration. It is properly paid for and registered with Verisign. I use the same registrar, 007Names, for my own .name 3LD.

What process did you use to decide this was not the case?


The difference what I put as a) and what was written in the OP blog post are a couple of things.

1: In the blog post they wrote:

> this website vanishes in February. Despite the fact that it's registered and paid for until 2040.

So the way .name 3LDs worked, was that you had to pay for it. Not a free subdomain that’s handed out in return for the domain owner injecting ads into your site.

2: The other thing I meant by a) but that I failed to state explicitly is that in scenario a) I am imagining that doe.name and some other 2LDs with highly common last names had been bought by a third-party, similar to how the Freewebs company was owning freewebs.com and giving out subdomains of that to people. See also https://en.wikipedia.org/wiki/Webs_(web_hosting) for details on how Freewebs worked if interested and not familiar with them.

I would not have guessed that the .name registry itself was running a 3LD setup for everyone across all of .name, because it is so different from how all other TLD registries I know of manage the domain name hierarchies. For example .co.uk which is also 3LD was much more straightforward to understand and recognise historically because the 2nd level was a category (alongside a few other categories like .gov.uk, .ac.uk, .org.uk).

A few years ago, .uk opened to second level registration also, which somewhat similarly makes domains under .uk more confusing to me as someone outside the UK who knew about .co.uk and the likes because now I can no longer know if a 3LD under .uk is the way it is because it’s under an official category or not. For example, say that there is a 3LD domain manchester.autos.uk. I wouldn’t know if .autos.uk was an official category domain or not without specifically looking it up, now that 2LD registrations under .uk are open to others.


That's what we thought when we applied for .name, especially coupled with mail forwarding at doe.name so jane and john could get jane@doe.name and john@doe.name respectively.

In practice the demand was lacklustre.

We ran a webmail provider prior to that, with 60k domains or so, and the demand was higher for that, basically. To get a decent return out of it, you'd probably have to package it up with services on top, and our investors made us sell off the webmail service when we got .name... It turned out to be the more profitable of the two services. Doh.


> This is my theory because, a priori, 3LDs should be more profitable than 2LDs,

3LDs are less valuable. In a market of many different tlds, why register foo.bar.name when you could get foobar.name or foobar.something_else


Because your name is John Doe and not JohnDoe.


Your name is also not John.Doe.

Mr. Fraser registered neil.fraser.name in 2002, when 2nd level registration under .name was unavailable; fraser.com had been registered in 1996 and neilfraser.com in 2000; he may have been able to get .org or .net, their registration dates are later, but they may have been registered and there was a gap --- my personal domain shows a creation date of 2003, but I registered it much earlier and abandoned it, but got it back after it was registered and then abandoned by someone else.

.name added 2nd level registration in 2004 and it seems to be vastly preferred. .us added 2nd level registration in 2002 and it was vastly preferred to the locality based naming. People don't want to have to educate their contacts about "weird" domains, which includes having an "extra" dot in your hostname.


> The same ambiguity can and always will exist with tim-apple.com and tim.apple.com

Similarly, I recently got a scam email that linked to de-apple.com (not a domain owned by APPLE) and also used apple.com-18221.com (also not apple.com).

I reported those domains to the registrar, but apparently it is not impersonating enough to take action.


It's exceedingly charitable of you to try to infer a good reason for what they're proposing. I say "exceedingly" because in their proposal they had the opportunity to present a good reason, and they chose not to use that opportunity.


Was it even possible to register just a second level .name domain name? It sounds like it wasn't, so therefore no one would be using john-doe.name and there'd be no ambiguity.


It was initially not possible, then later opened up, though a large collection of known surnames and personal names are reserved and cannot be registered as 2LDs. As far as I know the list of reserved names is unavailable, but you can run a whois query on any one of them to see it is reserved. E.g. check whois baxter.name and you get a response saying, "Not available for second level registration. Third level registrations may be available on this shared name."

I have the .name zone file and can confirm that no records for baxter.name appear therein, so it is not reserved only because a 3LD registration has ever taken place, it is reserved proactively just in case someone with that surname might want to register a 3LD under it.


Not at the very beginning, but then it became possible.


Yes it has been. I have had a second level .name for 20 years.


It was, I have one.


That would be so cool and would make these limited hot commodities.

.name was one of the very first expansions of gTLDs back in the very early 2000s. It's a shame that it's being shut down as it was spearheaded by the ICANN itself rather than some registrar / investor like Donuts, Inc.

I suppose this is impractical as someone has to run the registry and there are costs associated with that. But don't the domain fees cover it?


From having worked in that space what feels another lifetime ago, I vaguely recall that you can just offload the registry work to a registry that would manage this together with a mountain of other TLDs.


Yes, that's what Verisign does here - they also host many of the other big generic TLDs like .com.


As I recall it. This was mostly a money scam that targeted private users with ads like "make sure to claim to your .name domain so no one else does it and use it to impersonate you". It was stupid from the beginning and never took off.


I'm surprised they don't just do that, and maybe even to go a little further, disallow renewals so you can phase people out and reclaim domains you can sell.


Whether disallowing renewals or terminating them tomorrow, there's still the same core problems, only the date of the offense changes: (1) seizing people's names that they've established, breaking innumerable things including email and server hostnames, and (2) the possible resale of the 2LD fraser.com to a third party who will be free to do malicious things like reading OP's email, redirecting his traffic, or extorting him, to sell continued access at any price demanded.


There's one less core problem: those who just bought/renewed their domain e.g. yesterday are fucked out of both their money and forced to migrate sooner than they could have reasonably planned for. People's who registrations expire and they are unable to renew is a very different level of unfairness and inconvenience.

In either case, the security concern should be directly addressed.


Well, I'm guessing that Verisign will throw people a bone in terms of refunds just to avoid getting repeatedly hit with justifiably spiteful lawsuits that (I hope) would be trivially easy for customers to win.

That will cost them very little in terms of cash, as I doubt that many people register that many years ahead, plus in terms of accounting, they won't have accrued that revenue anyway so it wouldn't even hurt their books. Not that a couple hundred K would even matter on the financial statements of a giant, money-printing corporation like that.

The reason why they wouldn't go the route of waiting for expiry is that at least a few have nearly a decade left, and clearly they really want these gone, not just reduced in number. By 2036 when they would finally get to that point, I doubt whatever's driving this concern would even matter.


If hosting a zone and handling the odd customer transaction is "too much work", giving a refund to avoid all the aggravation of getting sued seems a lot like the easiest and best option


Having a mix of both 2LD and 3LD registrations under the same TLD is a bit of a nightmare in terms of public-suffix list [0], which is kind of important thing when enrolling your domain for some services, cloudflare among them.

[0] https://publicsuffix.org/


The PSL is a giant hack that gives the PSL maintainers authority over something that should be a hierarchical delegation. It's an affront to the DNS system and should not be considered to have any relevance by ICANN or any standards bodies.


Yeah, that’s why RFC 9989 replaced use of PSL with a dns signifier.


(That's DMARC, to save others the trouble.)

The problem DMARC solves is different than the problem the PSL solves, though. DMARC prevents a 3LD from pretending to be a different 3LD on the same 2LD. But the PSL handles things like what it means to make a "cross-site request" or how to handle cookies.

I mean now I'm thinking if DMARC _could_ solve that... but I don't think it could, unless I'm missing some extension or rare use case.


Yes, DMARC isn't solving the same problem — but DMARC is showing how the category of PSL problems can be solved with DNS. With HTTP/3 now fully expecting browsers to be able to benefit from transparent-upgrade record responses, i.e. `www IN HTTPS 1 . alpn="h3,h2"`, then it is possible for the style of solution shown by DMARC to be applied to other problems that PSL solves today.

CAA isn't a good fit as-is either, because the subdomain has top precedence over the parent domain — precisely the inverse relationship needed here. But having worked with the PSL for quite some time operationally and seeing the direction of trends away from it and towards structural DNS declarations rather than a centralized list, I think the 3LD-2LD-CRSF problem would be far better off solved with DNS than PSL.

Basically, just adding `co.uk. IN TLD subs=independent` as an SVCB record would fully deprecate the need for the PSL versus cross-site and other such ownership-changes-hands boundary problems with both A.co.uk being allowed cross-site with B.co.uk, and with co.uk being treated as equivalent to B.co.uk by password managers, cookie repositories, and so on. It would also benefit CAA by defining whether the boundary exists — if TLS is hosted by the provider, then any CAA records published by the subdomain should be disregarded; if the subdomains are fully independent, then any CAA records published by the parent should be disregarded — which simply isn't possible today without either referring to the PSL or implementing DMARC-style DNS solutions.

(I don't formally suggest that exact record as structured or written but it's sufficient a napkin sketch of what I mean by gesturing at that RFC to be considered.)


I think DMARC works well because email tends to blindly trust DNS (opportunistic encryption). On the web we expect authenticated TLS, often strictly enforced (organization policy, HSTS). So it would feel weird if a website changes how it handles HTTPS cookies based on an insecure DNS record, perhaps delivered by the resolver on an untrustworthy WiFi router.

Specifically, if I register subdomain attack.co.uk and set up a malicious WiFi router, I trick some *.co.uk cookies to get set on co.uk and then steal them from attack.co.uk by tampering with the (proposed) SVCB record.

I think the signal needs to be secure, which means DNSSEC. Adding a hard requirement for DNSSEC validation in all web browsers is a huge change from where we are now.


The SVCB HTTPS rfc considers downgrade attacks here: https://www.rfc-editor.org/info/rfc9460/#name-handling-resol...

And essentially boils it down to ‘either the client implements wire-security to a known dns server using DoH or DoT, implements dnssec to verify the untrusted response as legitimate, or the client risks being mitm’d to attacker addresses’. They ultimately sidestepped the problem by structuring it to be hints rather than guarantees and thus allowing DNSSEC to be optional, and so as of today, it’s definitely not sufficient to implement this.

I think that adding a CORS rejection to DNS — declaring subdomains independent of a TLD, that is — does not require DNSSEC, so long as clients adhere to the steps to prohibit attacker interference described. But it still asks a great deal of DNS that I’m unsure is possible today, not just in DNSSEC but in ripple-subward records that somehow tie into client responses.

More likely, I assume browsers will simply permanently end all service to the concept of subdomains at all; no cookie sharing across domains at all, no inherent cross-origin just because tld and www.tld share a few characters, etc. rather than either depending on the PSL or having to implement strange and complex DNS anything. Admins will throw their hands up about it, but the net is no longer a place where control of a TLD defines the trust of its subordinates, so it’s certainly time to rip that bandaid off if they haven’t yet.


> simply permanently end all service to the concept of subdomains at all

That doesn't sound simple at all.


In the tech industry of yore, corporations having tech ecosystem stewardship duties was a quaint necessary evil to placate the developer crowd so you could hire them. Today, c-suites consider that indulgent soft-hearted hippie nonsense utterly gauche.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: