5 ms·
> I don't know why people thought they could start using random TLD's on their own, there was always the risk they could be delegated officially. If a company
by adrian17 9y ago
> I don't know why people thought they could start using random TLD's on their own, there was always the risk they could be delegated officially.
If a company has its own internal network with its own DNS, does it still need to conform to ICANN's name assignments? I thought it doesn't...?
- mzzter 9y agoChrome as a browser doesn't follow internal name assignments. Running in a sandbox won't fix the issue that Chrome will redirect perceived TLDs to HTTPS.
- CydeWeys 9y agoChromium is open source. You could always compile a version with your desired HSTS preload list, if you wished. Probably better to just use real globally delegated domain names though.
- ge0rg 9y agoThere is no "DNS police" entity to force them, but just using a random domain will cause issues if that domain ever gets registered. First, you will begin leaking internal data by means of DNS requests, server connections, maybe even internal emails - e.g. when a client attempts to connect to the intranet outside of VPN. Second, you obviously won't be able to communicate with the new owners of that domain.
- CydeWeys 9y agoYou're free to do whatever you want on your local network. If you have collisions with resources on the global Internet, however, and you local network is connected to the Internet, them you're setting yourself up for problems. Hence why it's a best practice to not do that.
- xg15 9y agoExcept for things like this issue, where you'd be affected when using Chrome or Firefox - even if your local network were completely disconnected from the internet.
- CydeWeys 9y agoChrome and Firefox are primarily designed for use on the World Wide Web. If you're going to use a locally modified network you may need to use locally modified browsers as well, just as you'll need your locally configured DNS.
- adrian17 9y ago> If you're going to use a locally modified network Except (correct me if I'm wrong), this is not a "modified network", it can be another disconnected network that's just as "correct" in the standard conformance aspect as the Internet. It's more like Chrome is "modified" to support one network better than others - or rather, to possibly break on other networks. In fact, it seems to me like the very idea of HSTS preload list isn't friendly with UAs working on multiple separate networks. But yeah, you're right that this is what they are designed for after all. (I'm also probably slightly biased, since some of our test environments use .dev domain in our LAN.)
- CydeWeys 9y agoChrome is primarily an Internet browser though, not a random network browser. It wouldn't be a good idea to prioritize random network browsing at the expense of useful security features to secure browsing on the Internet.
- tinus_hn 9y agoYou can do whatever you want on your own network but if it breaks, you get to keep the pieces. ICANN can't keep names unique if people just take them.