I remember back when we had to write mechanize scripts to drive a browser through the renewal process, because if you had dozens, hundreds, or thousands of domains there was no nonmanual way, especially if you wanted extended verification or something silly like that.
So what I'm saying is, agreed and that has always been true.
The main problem with the Internet today is that we didn't destroy ICANN when they started this TLD sell off crap. A replacement institution may have at least told Verisign a TLD they can't run transfer to someone who can meet its promises can only be destroyed.
It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com
In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com
edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule
The .name subdomain rules are not very well known anywhere.
"Here's a list of things that look like subdomains for you to treat as 3LDs instead of subdomains" sounds exactly like the solution to an edge case to me.
Another poster raised the point of hosting services which is valid. But at present outside of that example and the above I really can't think of an example where you have a link to entity.com and you have any significant cause to verify the identity beyond the 2LD.
(Aside, I always see "owned" and "bought" but you can only ever "lease" under the ICANN system as the present situation so clearly demonstrates.)
*: I realize that “owned” is a loaded word here, but (1) I’m referring to a registrar/issuer, which makes it yet more complicated as to how much “ownership” (de facto or otherwise) a given entity may have, and (2) I really don’t give a fuck about pedantic word choice if the meaning is unambiguous.
> but (1) I’m referring to a registrar/issuer, which makes it yet more complicated
We're also talking about a ccTLD which makes it even more complicated. AFAIK those fall entirely under the jurisdiction of the respective UN recognized government although I don't know how strong that agreement is in practice (treaty versus something else).
So at that point I guess we've roughly got ICANN -> US federal government -> CA state government -> registrar -> private party -> sublet.
This isn’t how things are done these days; names visible to the public are pretty much always in the form {domain}.{tld} or sometimes {name}.{domain}.{tld} (e.g. my own https://samboy.github.io). Registration is now done by bots and companies that spam you to death to try and get more money from you (the Internet wasn’t like that in the beach.santa-cruz.ca.us days). Domain names with multiple levels of delegation aren’t around they way they used to be.
* rented/leased/had control over/whatever
The old locality domains still exist, and in many localities you can still register them today by the same "email a request to some sysadmin" process. https://news.ycombinator.com/item?id=48122635
Your beach.santa-cruz.ca.us domain is still in DNS, just with a broken delegation chain. You could reclaim it right now by setting up a nameserver at reality.samiam.org.
https://beach.santa-cruz.ca.us/
Thanks for checking the zone files of the parent domain to verify it’s still there.
I think geocities had this as well?
A lot of hosting services offer this in general. (eg render)
Tumblr? (Might not count as the control over the page is more limited. The subdomains "are" still tumblr.)
For reddits subdomains are redirects to subreddits of the same name, so I guess that doesn't count.
Also I would not consider the examples of tumblr and reddit to be relevant. A person's blog on myprofile.tumblr.org is still the tumblr organization. This would be true for reddit even if they didn't redirect. Reddit admins moderate content on all subreddits.
When I read > I have been taught and tell my users to check the domain to verify a website is real.
I was thinking more of control of the content as "ownership" of the domain.
In the US, once upon a time, elementary/middle/highschools might be attached to something like schoolname.district.state.gov. But now, even my local area school now has a .com. It seems that older hierarchy style is falling out of fashion for smaller/shorter domains across public services, schools, government agencies, etc.
Now here it seems to be either a .com, .gov, .org, or a totally different and newer tld. Even .net has fallen out of fashion.
Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with.
Then when you consider DNS is fundamental infrastructure and people build secure things on top of it, (ahem DNS challenges for certs), it's remarkable that anyone would want or desire edge cases.
What you should know, and what your browser does know and automatically applies cookie policy and colouring your URL bar, is the Public Suffix List: https://en.wikipedia.org/wiki/Public_Suffix_List
It will let you know that, for example, one does not need to own .co.uk to own the subdomain foo.co.uk.
https://github.com/publicsuffix/list/issues/2306 for more discussion.
This is my theory because, a priori, 3LDs should be more profitable than 2LDs, because with 3LDs John Doe and Jane Doe don’t have to compete over doe.name, but instead can each separately purchase john.doe.name and jane.doe.name. Apparently, however, that’s not a benefit of 3LDs in practice, which leads me to conclude that john-doe.name and jane-doe.name just sell better.
To me, prior to knowing how it works, I would have assumed that either
a) john.doe.name would be a subdomain that someone who was just starting out had gotten for free supported by ads. Similar to having johndoe.freewebs.com back in the day. Not something most people would use for anything professional.
or,
b) doe.name was registered by one of the people in a family of Doe’s where every Doe is pretty closely related. For example, John of john.doe.name and Jane of jane.doe.name are husband and wife, or third cousins, or what have you. Most of the content, I would assume, is mostly about things that relate to the family. Like maybe one guy is doing a family genealogy project tracing the roots of this little cluster of Doe’s back in time and has made a site covering the findings from his research. And another one probably has some photo albums with pictures of like previous Thanksgivings and other family get togethers. In other words, nothing I would care about unless I was in their family or a very close friend of the family.
I would not have guessed that .name 3LDs worked the way that it did if I hadn’t read about it.
And on the other hand, if I saw just www.doe.name or johndoe.name, I would not make such assumptions. It would be not much different than seeing www.doe.com or johndoe.com respectively. I would just assume that .com was already taken and therefore they used .name, or that they happened to like the .name TLD because it emphasises that their site has their name as domain name.
3LDs are less valuable. In a market of many different tlds, why register foo.bar.name when you could get foobar.name or foobar.something_else
Mr. Fraser registered neil.fraser.name in 2002, when 2nd level registration under .name was unavailable; fraser.com had been registered in 1996 and neilfraser.com in 2000; he may have been able to get .org or .net, their registration dates are later, but they may have been registered and there was a gap --- my personal domain shows a creation date of 2003, but I registered it much earlier and abandoned it, but got it back after it was registered and then abandoned by someone else.
.name added 2nd level registration in 2004 and it seems to be vastly preferred. .us added 2nd level registration in 2002 and it was vastly preferred to the locality based naming. People don't want to have to educate their contacts about "weird" domains, which includes having an "extra" dot in your hostname.
Can someone explain why a product "registered and paid for until 2040" can be unilaterally voided like this without compensation?
> As your .name can be registered for up to 10 years and ownership is renewable, your .name really can be yours for life.
It seemed like there was an offer of renewable registration at least for a life term.
[1] https://web.archive.org/web/20020609132126/http://nic.name/c...
In either case, the security concern should be directly addressed.
That will cost them very little in terms of cash, as I doubt that many people register that many years ahead, plus in terms of accounting, they won't have accrued that revenue anyway so it wouldn't even hurt their books. Not that a couple hundred K would even matter on the financial statements of a giant, money-printing corporation like that.
The reason why they wouldn't go the route of waiting for expiry is that at least a few have nearly a decade left, and clearly they really want these gone, not just reduced in number. By 2036 when they would finally get to that point, I doubt whatever's driving this concern would even matter.
The problem DMARC solves is different than the problem the PSL solves, though. DMARC prevents a 3LD from pretending to be a different 3LD on the same 2LD. But the PSL handles things like what it means to make a "cross-site request" or how to handle cookies.
I mean now I'm thinking if DMARC _could_ solve that... but I don't think it could, unless I'm missing some extension or rare use case.
CAA isn't a good fit as-is either, because the subdomain has top precedence over the parent domain — precisely the inverse relationship needed here. But having worked with the PSL for quite some time operationally and seeing the direction of trends away from it and towards structural DNS declarations rather than a centralized list, I think the 3LD-2LD-CRSF problem would be far better off solved with DNS than PSL.
Basically, just adding `co.uk. IN TLD subs=independent` as an SVCB record would fully deprecate the need for the PSL versus cross-site and other such ownership-changes-hands boundary problems with both A.co.uk being allowed cross-site with B.co.uk, and with co.uk being treated as equivalent to B.co.uk by password managers, cookie repositories, and so on. It would also benefit CAA by defining whether the boundary exists — if TLS is hosted by the provider, then any CAA records published by the subdomain should be disregarded; if the subdomains are fully independent, then any CAA records published by the parent should be disregarded — which simply isn't possible today without either referring to the PSL or implementing DMARC-style DNS solutions.
(I don't formally suggest that exact record as structured or written but it's sufficient a napkin sketch of what I mean by gesturing at that RFC to be considered.)
.name was one of the very first expansions of gTLDs back in the very early 2000s. It's a shame that it's being shut down as it was spearheaded by the ICANN itself rather than some registrar / investor like Donuts, Inc.
I suppose this is impractical as someone has to run the registry and there are costs associated with that. But don't the domain fees cover it?
> Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems.
https://www.icann.org/resources/pages/about-icann
Arbitrary termination of service is not stability.
Enabling name hijacking is not security.
The answer cannot be a rival name scheme based on decentralization or crypto or whatever. Those are never going to help normal non-wizard users. The answer has to be to make the regulators do their job.
> There will not be any effect on the life cycle of domain names. While the Requestor may disagree with Verisign’s response, the Requestor has not shown that ICANN relied upon false or inaccurate material information. The life cycle of a domain name begins when the domain is registered, then moves through various stages before ultimately coming to a close. Early termination of a domain registration does not impact the life cycle of the domain, as the domain can still go through the various stages of a standard life cycle. Moreover, as stated above, ICANN was aware that discontinuation of these registry services in the .NAME gTLD would result in the termination of approximately 22,000 third-level domain registrations and of email services/addresses.
I don't agree. If I have a domain registered for 10 years the expected life cycle is for deletion to occur 10 years from now, not 90 days from now. They've changed the life cycle by changing the agreed upon deletion date for the current registration term.
I could maybe see if they stop accepting renewals and delete the domains as they expire. It's not a good look, but at least people are getting what they've been promised.
1. https://www.icann.org/resources/pages/reconsideration-26-2-s...
According to ICANN cutting the life cycle short doesn't have any effect on the life cycle?
ICANN corruption is at the level of FIFA corruption.
How about the fact that you paid for a service for 10 years and they decided to stop providing it midway? Will you at least get a refund? If not, that's surely illegal right?
I own lastname.name and use it for email only like this: firstname@lastname.name
I always thought as owner of lastname.name, I'm the only one able to add subdomain.lastname.name. Is this wrong??
1) Can anyone "buy" scam.lastname.name without my authorization on .name??
2) Can anyone owning not.lastname.name then steal my emails going to: firstname@*.lastname.name or even firstname@lastname.name??
BUT: If someone ONLY bought not.lastname.name and doesn't own lastname.name, they'll get terminated. Would that be 'good' as it would stop 1) and 2) ??
I'm really concerned. My family is using first@lastname.name as the personal email, I'm hosting and paying for since many years.
TFA mentions that `.name` was unique in that it sold a good amount of third-level domain names directly from the registry.
Still a crappy thing for people, but it does not affect owned second-level domains.
But I didn't think about the 1st level competitors. There'd still need a mechanism to resolve that...
1. First come first serve? (e.g. whoever registered a y.name first, whether x is bob or sue is determined by the earliest registrant on record) 2. Lottery/random selection? 3. Bidding war?
I think the problem is 2nd level domains who have the same name will be a problem when they find out all these other 3rd level are now expiring and can run a route to spoof? Likely wouldn't happen, but with the fuckery in the DNS that can happen... This is such a rash and weird decision to push through so quickly just because engineers find it "easier" while ignoring the implications of the move, seemingly when it comes to larger scale security.
I assume there would have to be some method to prevent routing of third level domains to subdomains of two-levels... (or is that just me being a fool yet again, assuming we have competent administration of our systems).
Yes. I've been asking VeriSign for this for years, and they always refused.
I have myname .name - so I thought that was going away. Granted I barely use it, but still it would be annoying. I didn't recall there were 3rd level domains there.
There is no subdomain/TLD bit
What I understand would be the following:
1- Verisign manages the TLD registry for .name (and others), which includes managing the authoritative DNS servers (as pointed to by the .name NS and A records on the root DNS servers), 2- as well as for updating the NS records of .name records it is authoritative at the request of registrars (like, say GoDaddy), which act on behalf of domain owners. 3- one or some of the domain owners, for example for fraser.name, acted as a registry themselves managing authoritative DNS servers for NS records of .fraser.name domains, these third level DNS servers being pointed to by the name. NS records.
4- Upon registration of a .name domain, verisign charged a fee, (in the case of .coms this is around 10$ currently I believe, not sure how much they charge), and ICANN charges a much lesser fee (like 20 cents).
5- Upon registration of a .fraser.name domain, the fraser.name domain owner charged a fee, and they kept the totality of that fee (potentially paying a fee to ICANN, but definitely not to verisign.)
6- Verisign issues this request, requesting registrars of second level domains (domain.tld) like GoDaddy, to stop selling third level domains of this TLD (domain.2ld.tld).
This is my understanding of the situation, and in that case, verisign was not billing for the domain. This might (a bit cynically) provide a commercial motivation for the actions of verisign.
It's worth noting that this is not at all a weird or shady practice, multi-level domains are the very ethos of the domain system, it's built for that, I'm not saying any domain is obligated to do that on the basis that it can, but it's not some esoteric illegal activity, it's normal.
Still, I'm not sure there's any easy technical fix for the .name debacle.
It's safe to ignore altogether, but it can come in handy as a starting domain block/allowlist.
>Still, I'm not sure there's any easy technical fix for the .name debacle.
I think that it's gonna be ok, the owner of the 2ld is still the owner, so they are free to allow the 3ld domain owners to continue "owning" their domains and updating them on the authoritative 2ld DNS. It's just that verisign is no longer sanctifying it by allow vendors of other 2ld to sell 3ld with the 2ld together.
This might explain the whole situation, many of us are interpreting that the domains are deleted, but in reality, they may more likely be prohibited from being represented as official .name domains in registrars .
i.e. I own john.doe.name, you own george.joe.name. Once this change goes through, only "doe.name" can be owned, so who gets it?
* .name is open for everybody
* a company called "Global Name Registry" scooped up a BUNCH of common last names, including fraser.name
* Global Name Registry then sold access to neil.fraser.name for far cheaper than the fraser.name domain would cost on its own; someone else could also buy john.fraser.name or jane.fraser.name, so the single fraser.name domain that they owned could have dozens of customers associated to it. They worked with ICANN to allow each domain to have its own registered owner.
* The article in the OP bought neil.fraser.name and has used it for years
* Verisign bought Global Name Registry; later they realized, hey, we're sorta not making a lot of money on this idea, and we're spending a lot of time/resources maintaining these domains "for cheap" and chasing renewals, and not scooping up more customers. Let's just stop it and stop paying for fraser.name and the potentially hundreds of other domains we own.
* Neil Fraser, not the only Fraser in the world, is upset because he might lose the domain he's had forever
So one CAN buy the mwai.name domain, as you have, and continue using vpn.mwai.name just fine. It's just you can't "officially" start selling out these subdomains as a separate registrar entry.
I guess in practice it doesn't make much of a difference for me anymore, I registered mwai.name 20 years after they began allowing second-level registrations and more than 15 years after GNR was sold to Verisign. So presumably GNR's concept was long-abandoned by the time I made my registration (which was, to be truthful, mostly based on mwai.name being the cheapest domain with the initialism). I was more curious about the implications of having held a second-level domain, whether it could have caused trouble for me or for a different person who held a tertiary domain. But also my registrar at least doesn't seem to allow tertiary domain registration for .name.
Any any case, nothing in OP or any of its referenced sources suggest Verisign is giving up .name. rather they will stop accepting and serving tertiary registrations, so if Neil wants to keep his domain he or another beneficent Fraser will need to register the fraser.name domain and register the subdomains for neil, joe, jill, or whichever other fraser currently owns a tertiary domain. The same would be the case for anyone else who still held a tertiary domain. Perhaps Verisign or the registrars who work with them might be able to migrate the registrations of anyone with these domains, particularly in what I suspect are most cases where there is a single tertiary registration under a secondary domain. Perhaps offer fraser.name to Neil and he can add his own subdomains.
I was intending to replying to a different comment on the above thread, sorry if this made my previous reply a bit incoherent.
This is an ostensibly uncharacteristic move for verisign, but the customers that bought these 2ld did so from a non-verisign vendor, it is only after verisign bought the 2ld holder that they became the holders and are now proceeding to extinguishing them after embracing and extending.
Might be an anti-trust case. Like textbook clear-cut case. IANAL, this is not legal advice.
Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.
I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.
I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.
What's your account tied to?
E-mail? That's usually on a mail server owned by someone else. If not, it's still on a domain owned by someone else.
Phone number? Definitely owned by someone else.
The only account that's reliably "yours" is one that asks for a login, a password, maybe a TOTP, and absolutely nothing else. Because everything else is introducing "things owned by a third party" into the equation.
Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?
> do browsers have a wildcard suffix list
Yes: https://publicsuffix.org/ and they have discussed this situation here: https://github.com/publicsuffix/list/issues/2306
> We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't.
So does that mean that in practice, .name domains were always treated by browsers like regular 2LDs, meaning the cookie and origin protection was always broken for those domains?
Doesn't sound like good news for the guy in the OP...
IIRC orgs like letsencrypt also use the PSL for rate limits, so there are probably more issues that are not browser-based.
But letting arbitrary customers take arbitrary 3 level domains, and others take 2 level domains, seems like a mistake as it's not very reasonable for every 3LD customer to put the 2LD on the public suffix list, but mixing 3LD and 2LD registrations means you can't public suffix *.name.
Seems the whole idea of having both was always misguided.
The issue is that .jp registered outside of a few Japanese registrars are legally not allowed to offer Whois privacy.
But that was simply the easiest way to market your website as a trusted government entity. And now nobody has ever heard of .us domains in active use.
This is a bug, not a feature.
There was an effort to properly handle the .name 2LDs, but it was never resolved because there’s no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name: https://github.com/publicsuffix/list/issues/2306
So yes, this TLD’s setup is in fact pretty insane.
In a world without advertising, there's no reason why google.com couldn't also allow *.youtube.com to set cookies for it, but of course that would cause a tremendous privacy freakout. Though in practice they can and do just send every login/logout through a 302 redirect roundtrip to take care of the cookies on youtube.com.
That said I don't know about making cookies shareable across TLDs. That seems like allowing more privacy nightmares; at least today if you want to share you need complicated redirect dances that make you question if the user perf hit is worth it. I think there was some proposal for a mechanism for allowing non partitioned 3rd party cookies which seemed more sane to me, forget what the details were and if it ever made it beyond just a proposal.
Maybe it could be opt-in or opt-out via some markers at the DNS level, though? The public suffix list having to exist at all is bizarre.
Surely a better solution would involve an actual request. login.foo.com could send a request to foo.com with Origin: login.foo.com asking to set a cookie, and foo.com could make its own decision.
If you require domain wide cookies be set from a webserver on the domain apex, the domain apex (for high volume destinations) needs to be set up for high volume webserving. High volume webserving often means at least geotargetted DNS, maybe a CDN, often anycast in today's reality.
Back in the day, it was common for high traffic domains to run their DNS with a normal DNS server and then delegate (typically via CNAME) high volume subdomains off to a 3rd party DNS server for geotargetting (usually Akamai DNS, but there were others). But you can't CNAME the apex domain away. You'd have to delegate the whole domain to your DNS provider and then you have no way to manage an outage of your fancy DNS provider. Especially if you go back to the days where NetworkSolutions did a single daily zone update for .com ... if you wanted to switch to a new DNS provider for your domain, you would submit the change request and hope it happened in the 24 hours, but sometimes you'd miss the window (or there would be some process error) and it would happen much later.
Less of a problem in today's world, where registries typically update the glue records in near real time (although many TLD servers have a 2 day TTL for glue, so you can't switch off a dead provider very quickly) and lots of domains seem comfortable with delegating the whole thing to their CDN.
That said the dumbest thing with cookies is not sending their attributes in the cookie header which makes it impossible to distinguish expected cookies from tampered cookies set by insecure subdomains. __Host prefix is basically a workaround for this but took more than a decade to get into browsers. Samesite similarly was bolted on after the fact.
Cookies aren't the only web security feature that follow sites instead of origins but they are the only one that was clearly designed without thinking through the consequences.
And that's one reason why the public-ness of a hierarchy level belongs on a DNS record on that level and not some separately-distributed side list.
I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP.
Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...
Really hard to understand why that hasn't happened yet!
There would be no issue at all if Verisign, or maybe Global Name Registry, decided to stick to the 3rd level registrations exclusively. Problem is, the chucklefucks over there decided it was a good idea to also hand out 2nd level registrations. Those 2nd level registrations outnumber the 3rd level registrations by an order of magnitude, so the PSL decided to just let joe.smith.name and john.smith.name share cookies. Which, IMO, was not a good decision, but it is what it is.
Yup. The original statement was dangerous FUD which should be urgently corrected.
Needing to be familiar with all the special cases (like the VERY special case of x.y.name which I previously knew nothing about) kind of ruins everything and introduces yet more security risk.
I'm sorry, what ? Admit ? Confusion ?
In the case of .co.uk it has been around since 1996. HN is a technical forum, most people here should be well aware it is a serious SLD. I honestly can't believe it even needs clarifying.
Hell, if you use AWS Route 53 you'll see they use co.uk as one of their nameserver suffixes[1].
[1] https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/SO...
It's been around for years. I seem to remember this issue coming up around 2001 where originally .name was for third level registration (i.e. john.doe.name) and changed to second level it a few years later and caused some problems... https://publicsuffix.org/ talks about it in light of architectural limitations of domain names.
> can Joe set a cookie on all of .smith.name?
That can happen. I seem to remember ancient browsers made it so .name (and other non-generic TLDs) required three periods. I think country code domains and new generic TLDS caused the browsers to change it.
It's pretty screwed up, but a lot of the people with .name domains have had them for a very long time. Sad to see them all lose their identity online that way.
Imho email is missing a feature for nameless email addresses for when somebody just buys their full name as a domain name. If I get "firstname-lastname.name", having the email be "firstname@firstname-lastname.name' kinda ruins it.
they'll grumpily sign up to gmail just so they can get a verification email, and that'll be all it gets used for. Messaging their irl friends will be done in apps like Discord.
lol I ran a sizeable team around 2020 and I had to educate a couple of our new hires straight from college that they actually needed to check their work email, after they missed important HR related stuff and they had just completely not realized it was an avenue for company communication, with an assumption that everything was available on our heavily used slack.
If email was a commercial product, the company would have done something about that. Email died because it was an open platform, with nobody to address this systematic issue.
I've successfully renamed an old account with an email address I no longer liked. It works quite well on everything 1st party, but does have the potential of causing issues with OAuth on poorly-coded websites that key on email instead of user ID (ie. most of them). You do get to keep your old email address though, so it still ends up working fine in practice.
edit: apparently not all second level domains in .name are public suffixes anymore, so a wildcard addition wouldn't be correct.
It has to be a money problem. Something they want to do will be simpler if this is no longer a quirky registry. And they know they'll get the money back that they lose from not having bob.smith pay -- probably by throwing all the "last names" once registered this way into some "premium name" bucket and selling them for $1000 and up instead of the ~$10 that zyzgdhaf234.name fetches.
In fact, I'm not sure that scheme isn't the reason itself.
Different from .co.uk.
> The first appearance of reversed DNS strings predated the Internet domain name standards. The UK Joint Academic Networking Team (JANET) used this order in its Name Registration Scheme, before the Internet domain name standard was established. For example, the name `uk.ac.bris.pys.as` was interpreted as a host named `as` within the UK (top level domain .uk)
from the History section of https://en.wikipedia.org/wiki/Reverse_domain_name_notation
But I don’t know if uk.co.somethingsomething did or did not exist at that time. Or if it was only introduced after the Internet domain name standards we use today existed and so was .co.uk from the beginning.
Back then the code in various pieces of software had hand-written exceptions for domain processing. The joke was that all Computer Science departments in the UK (uk.ac.university-name.cs) ended up in Czechoslovakia.
.uk was opened up relatively recently.
If .gov and .mil and .com make sense, then .gov.cc and .mil.cc and .com.cc make sense.
Of course, I think having more than one non-cc TLD was a mistake, but that's just me. If it makes sense to have topical TLDs for international and US institutions, it make sense to have national ones.
Nominet and therefore .co.uk has been around since 1996.
.co.uk is not going anywhere, and neither is Nominet.
The only "problem" is the original poster did not do their homework. I suspect they were inferring `uk.co` which is a completely different kettle of fish. The original poster should urgently correct their post.
I don't have some nefarious desire to scare people away from the TLD of their choosing. Really I'm bringing it up to be like "why would you even, like, want some 3rd rate domain instead of getting a .com" so I don't think there's anything to correct
It's not reverence? I think that you're missing that it was a requirement. Basically every country (that followed ICANN's original rules) does this: .com.au, .co.nz, .co.jp, .com.mx, .co.ke (+ the org/net variants for each country)
The US is the only country where registering .com was allowed by ICANN (and not .com.us or something).
ICANN relaxed these rules in the 2010s I think, so now you can register 2LDs at most/all of those country TLDs.
Its not hard to tell for things like ".uk" or other serious suffixes.
It only (maybe) becomes hard(er) to tell for all the vanity ccTLDs that came along in the 2000s. But even then 10 seconds on WHOIS and Google should fix any doubt.
> about the reverence of `co.uk`
What are you on about ? Lots of other countries do it too. Japan is one example given already here, but there are dozens. It is very common practice for country tlds.
5 seconds on wikipedia or google would have stopped them spreading completely dangerous FUD about .co.uk.
Implying lack of trust in `co.uk`
Implying `co.uk` may suffer the same fate at `.name`
Complete FUD.
;)
(Edit: although I should add that I'm hopeful that things have improved there over the last few years).
No.
Oversimplified summary:
There was a period around 2010 when the management at the time wanted to follow a more commercial route with various unrelated "investments".
Nominet members made it impeccably clear in a very loud manner to management that it would not be tolerated.
Management insisted on a vote which they inevitably lost.
Management departed.
TL;DR Don't piss off Nominet members
ICANN, a 501(c)(3), proposed to remove the price cap on .org registration, commonly used for non profits, so PIR, the 501(c)(3) registrar for .org, could then announce it planned to sell .org operations to private equity investment firm Ethos Capital.
Thankfully the overwhelming response caused the proposal to be scrapped.
https://news.ycombinator.com/item?id=48426337 was apparently the final straw.
I wonder how long that'll last. If the regulators in Califonrnia keep forcing them to act in the public's interest, won't they just move to a more favorable jurisdiction?
You only get a first name and a last name and a .name though. You can't be robert.louis.stevenson.name - just louis.stevenson.name.
(Incidentally, this was a Claude suggestion. The change only took a couple minutes but figuring out what mechanism in the code could do this would have taken me a lot longer.)
Well, it's still not affecting me, personally, but wow, seeing articles like this makes it feel just a tiny bit more real.
In short, AI identities were just a happy accident that comes with the system/architecture. It's not tied to AI at all.
But if anyone is interested in talking about what we're doing more, happy to connect at hn@sepositus.com.
Alice registers `alice.dntls` and Bob registers `bob.dntls` on the DNTLS network. During the registration process, they generate PQ key pairs that are registered along with the name. Alice's and Bob's name are hashed before being stored on the network. Bob knows Alice's name, so he can perform the necessary hash computation to look up Alice's public key material on the network. Likewise, Alice can do the same for Bob.
Bob wants to send a file to Alice. Bob takes his name key and signs the document with it and sends it to Alice. Alice looks up Bob's public key material on the network and verifies the signature.
Bob now stands up a new website, but he only wants Alice to access it. He sets up a standard HTTP server but slightly modifies it to be "DNTLS native." He does this by requiring mTLS on incoming TLS connections. The connecting party must identify themselves with a signed certificate. Each name has what we call a "name record" that allows publishing arbitrary metadata signed by the name key. Bob publishes a standard "HTTP" record in his own name record that points to the IP address. Alice now goes to connect to Bob's website. She opens her "special" browser and types in bob's name. The special browser looks up Bob's name record, finds the published IP address, and attempts an mTLS connection. Bob's server is configured to _only_ allow connections from Alice. Since Alice signed her TLS connection with her own name, the connection is allowed, while every other is rejected.
Alice now wants to communicate with Bob's agent. Bob publishes a subname called `agent.bob.dntls`. In that subname's record he publishes an A2A packet that contains the information for connecting to his agent. But, like the website, the agent is listening on a TLS connection that rejects anyone except Alice. She uses an A2A tool to initiate a connection using her name key and is allowed to make a mutually secured connection to Bob's agent.
Bob wants to connect to a VM he purchased that runs the website. He configures SSH with his name key as one of the recognized users. His SSH connection simply leverages the name key to authenticate him to the machine. But he shares the machine with another person and wants to share a secret with them. So he creates a SOPS encrypted file with his name and this other person's names as the only recipients. They both securely access the secret using their respective name keys.
I'll leave it there, but hopefully that's descriptive enough.
Names are valid for one year and range from $10/yr up like current domain names. Letting a name expire opens it back up to being registered again.
We have quite a few other "tools" in play behind the scenes that make name trading/squatting extremely impractical, but I won't go into those details here :)
but you lose the ability to have short domains.
also until such a time that pkarr is widely adopted, you are better off using .onion domains anyway. it becomes a question of requiring custom DNS client vs. Tor browser.
both approaches use a DHT.