7 ms·
DNS allows search so we really should have started rejecting everything that isn't qualified with an end dot as punishment to ICANN.. Instead random common name
by postquantumfax 1y ago
DNS allows search so we really should have started rejecting everything that isn't qualified with an end dot as punishment to ICANN.. Instead random common names might be treated differently on every network to make sure these people can't issue certs that will be trusted for them in your own network, etc.
Now prioratizing unambiguos naming would be somewhat acceptable if ICANN was tacobell and just a steward of naming on the side.
- ahoka 1y agoHot take: TLDs should not exist but parking domains should not be allowed.
- hsbauauvhabzb 1y agoAnd cost if domains should increase near exponentially with the more you own. One domain? $10/year, two domains: $50, three: $250, etc.
- kmoser 1y agoWithout rigorous ID requirements, that restriction can be circumvented easily.
- postquantumfax 1y agoWith rigorous ID requirements, that restriction can be circumvented easily.
- hsbauauvhabzb 1y agoI think the problem is they domain sales are for-profit, there’s no incentive to prevent squatting as it’s presumably a huge profit centre.
- 9dev 1y agoWith AI churning out a pretend blog or news site or web shop in a few minutes, that would be hard to enforce. I’m with you on the necessary death to TLDs, though.
- dc396 1y agoI'm not sure what you mean by "DNS allows search" -- by the usual definition of "search", the DNS doesn't: it is a lookup mechanism. I'm also not sure who "we" are in your idea or what you mean by "qualified with an end dot": all domains that get looked up implicitly have a "." (a zero length label that signifies the end of the query name) if it isn't explicit.
- postquantumfax 1y agoresolv.conf-> search If you are not a consumer on an ISP emulating dialup it is quite likely that a popular name in a naming convention I.e. 'mercury' resolves to something for you and something for someone at a different firm (mercury.intranet.[firm].not-so-stupid-tld). A cert is possibly not a fully qualified one so when ICANN gives away mercury you need to append .asshat to everything ICANN names. (Two firms have an unambiguous situation because they don't trust each others private roots but they both trust a cert issued for the public trust as a fqdn which is why TLDs expanding is a form of theft/breakage against every intranet..)
- arcfour 1y agoRun your own DNS then, if you're using your own DNS? Why are your queries for internal systems leaking out to the internet?
- postquantumfax 1y agoIf icann sells www as a tld domain then your use of www as a machine name you may refer to unqualified is a risk because virtually every piece of software in the world respects public issuance until you delete it all if you can. The DNS naming confusion was largely dealt with by having a small number of TLDs and rarely referring to complex things like partially specified subdomains, but every once in a while a fool named their machine com, org, or net. (Though these as subdomains were far more toxic.)
- dc396 1y ago
- sidewndr46 1y agoall the ISPs I've used just resolve any possible DNS query to an IP anyways, so I'm not really sure what it matters