5 ms·
This type of scheme comes up what, every year? Except this time somebody sunk $9 Million into it? Guys. Listen. .com is, has been, and always will be the st
by blhack 14y ago
This type of scheme comes up what, every year? Except this time somebody sunk $9 Million into it?
Guys. Listen. .com is, has been, and always will be the standard. It's the brand name. It's the default.
There is never not going to be a chase.com. It will either be run by JP Morgan Chase, or it will be run by a scammer, either way the overwhelming majority of internet users will think "chase" and associate "chase.com" with it.
Imagine a non-technical family member getting a phishing email with chase.com in it. Do you honestly think that they're going to think to themselves "bah! the .com tld isn't secure! I should be looking for a .secure website!"
What is even the point of this? Regardless of if people jump on to .secure, the entire .com internet still exists.
- SquareWheel 14y agoDo you honestly think that they're going to think to themselves "bah! the .com tld isn't secure! I should be looking for a .secure website!" I don't agree. I've seen people decline to do online business because the payment page wasn't https. This was not that tech savy of a person, and it actually impressed me. People adapt quicker than we realize.
- coopdog 14y agoI agree, putting https on an ecommerce site actually does increase conversion. Even a silly ' this site is secure' increases conversion, so people do notice and care The problem is the classic tld one. With https you know it's the same domain, but who's to say chase.secure is run by the same people as chase.com? Both could own a trademark relating to the word chase, both have verified (and different) addresses, but they're not necessarily the same I know it ruins the tld extortion model, but I think for this to fly the .secure address should be linked to .com, so only the owner of the .com is eligible to buy the .secure and has been vetted as owning it Otherwise I'm pretty certain the consumer uncertainty of the tld issue will destroy all trust in the .secure brand. No one argues that https is less secure, but when people have their geek friends put caveats on the .secure domain that they don't quite understand, I think that consumers will eventually avoid it
- jerf 14y ago"There is never not going to be a chase.com." No, but it might exist only to 301 to chase.secure. Still preferable to type it directly but potentially better than nothing. If this scheme is going to founder it's because nobody pays attention to the URL despite the best efforts of browsers, not because any of the rest of the scheme is bad.
- alexchamberlain 14y agoThat's a very US centric view.
- secalex 14y agoThis is why we are proposing an extension to HSTS that would make the redirect from one TLD to another permanent, which could help all of the new gTLDs.