11 ms·
.name Termination
- doublepg23 23d agoI didn't even know I was using .name incorrectly...
- xyst 23d agoVerisign is the worst. Hope author wins
- xiaoyu2006 23d agoMay I ask what is wrong with Verisign?
- swiftcoder 23d agoThat's pretty shit. You'd think changes like this would need to go through a public comment period with the affected users (much like city planning decisions do)
- eleventen 23d ago> Minutes after my daughter was born, I also registered beverly.fraser.name. ...minutes?
- layer8 23d agoHe didn’t say how many minutes.
- mcmcmc 23d agoPresumably less than 60
- Evidlo 23d agoDon't want to get scooped by GoDaddy when they hear the good news.
- tasty_freeze 23d agoIt was more than one minute.
- xiaoyu2006 23d agojust a figure of speech
- kotaKat 23d agoTo be faiiiir, when your partner is absolutely zonked out in the minutes post-delivery, what else is there to do when you're by their side and still half-asleep? Time to start announcing your pride and joy to the world, starting with a domain zone file.
- ipython 23d agoI mean, you've already had 10 months to come up with some name ideas. It's not like it's a huge surprise when it happens. You could even register the names before they're born.
- buzzy_hacker 23d agoI registered a domain name for my son the day he was born... whois firstlast.com | grep 'Creation Date' shows his birthday, which I found amusing!
- mchesters 23d agoWow, they were extremely laziest in the request form too. Most answers are just a few words. > 3.6. Have you communicated with any of the entities whose products or services might be affected... > "No. Not applicable."
- MadameMinty 23d agoThe nerve.
- mchesters 23d agoSeriously. > 7.3. Provide any other relevant information to include with the request. If none, respond with “N/A.” > None.
- fetzu 23d agoAlso note that their response is the exact length of the shortest allowed one, and yet still wrong.
- chrismorgan 23d agoI want to hear you justify, with perfect gravity, “N/A.” being the exact same length as “None.” Pictures of handwriting or specific fonts accepted. :D
- 23d ago
- xyzzy_plugh 23d ago> Despite the fact that it's registered and paid for until 2040 How is this possible? I thought there was a 10 year limit.
- elashri 23d agoI think it was figure of speech. The domain is registered until 2036 > Registry Expiration: 2036-01-29 00:00:00 UTC Updated: 2026-09-03 08:12:27 UTC Created: 2002-01-23 14:41:45 UTC
- leni536 23d agoWill they get a refund?
- swiftcoder 23d agoit's probably a 10 year registration, plus a pre-paid renewal at the registrar
- ipython 23d agoFrom the Verisign application [0] for this change: > 2.1. What effect, if any, will the proposed service have on the life cycle of domain names? > None. There will not be any effect on the life cycle of domain names. ehhh, how is that possibly true? This change (deleting all third level names) by definition affects the lifecycle of domain names ... by terminating them! Many years ago I wrote articles bringing attention to the negative effects of Verisign's SiteFinder [1] - if you don't remember this, it's when Verisign hijacked NXDOMAIN by redirecting any unresolvable domain to a site they owned and controlled. [0] https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2026013-name-request-15-04-2026-en.pdf https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2... [1] https://en.wikipedia.org/wiki/Site_Finder https://en.wikipedia.org/wiki/Site_Finder
- politician 23d ago"Well, it doesn't affect the lifecycle of domain names. The lifecycle is defined in some RFC somewhere, and this change doesn't modify that. Now, these particular domain name instances might be adversely affected, but you didn't ask about that." -- lawyers, probably.
- donmcronald 23d agoYou're closer than you think. Big companies and institutions just change the definition of words they don't like. In this case, they could argue that a domain's lifecycle is registration, renewal (optional), deletion. Deletion is part of the expected lifecycle, so this doesn't change it. The ambiguity is a feature so they can do whatever they want. We all know it's bullshit, but it gives the parties involved the ability to disenfranchise one group to benefit another while claiming they're following the rules.
- donmcronald 23d agoHere's an example of someone genuinely making that argument in another hacker news post. I'm having a laugh about how spot on I was. > Changes to the life-cycles of domains is a question meant to ask if this seeks to modify the life cycle policy, which is a separate type of change from termination of the service as a whole. I.e. this does not seek to change the life cycle policy, it seeks to terminate the service offering completely - making the life cycle policy irrelevant.
- noja 23d agoICANN approved this.
- Ecco 23d agoOk I don’t get it. Why not register `fraser.nameˋ directly? Or pick any TLD and register ˋ a 2nd-level domain (ˋfraser.tld`)? It just feels easier, plus this way you don’t have to pay for any new member of your family?
- orra 23d agoThere will other people with the Fraser surname in the exact same position.
- deleted 23d ago[deleted]
- deleted 23d ago[deleted]
- djoldman 23d agoIf aaa.bbb.name is registered, then bbb.name cannot be registered. bbb.name can ONLY be registered if it is not already registered AND there are no 3rd levels registered on bbb.name currently. https://manage.whois.com/kb/servlet/KBServlet/faq1485.html https://manage.whois.com/kb/servlet/KBServlet/faq1485.html
- iminatx 22d agoNot even then, necessarily. A great number of recognized personal names and surnames are proactively reserved and cannot be registered even if there are no 3LD registrations under it. I've confirmed that in the history of .name there has never been a third-level registrant under maxwell.name other than myself, and yet I was not able to register maxwell.name directly when I first got my .name 3LD in 2013.
- p4bl0 23d agoAt the beginning of the existence of the .name TLD you couldn't do that, you were forced to register firstname.lastname.name and provide an ID to justify registering this specific domain. With it you got an email redirection from firstname@lastname.name to the address of your choice. At some point this feature was discontinued (I assume when VeriSign took control of the .name TLD), a bit after it was decided (again by VeriSign) to allow registering first level .name domain. My main email address stopped working from one day to another without me being warned in any way. When this happened I've emailed VeriSign and my registrar at the time, and tried several time since then, to be able to register the first level domain I'm the only one using, but they categorically refuse, despite recognizing that a single subdomain has ever been registered. They kept saying that I could just let the domain expire, wait for the grace period, and register it once it's liberated, hoping that no one does it before me, and without any solution for the downtime in the mean time… And now this… fuck VeriSign -_-
- NewJazz 23d agoYou might want to write to the CA attorney general. Former AG Xavier Becerra was able to dissuade ICANN from letting the .org fuckery happen, maybe Bonta could try to strong arm ICANN in this case.
- qrobit 23d agoWhat was the deal with .org? EDIT: seems like Ethos Capital private equity firm wanted the .org registry, and Xavier Becerra (Attorney General of California at the time) wrote a letter that played major role in transaction being rejected > Dear Messrs. Botterman and Marby: > > I urge ICANN to reject the transfer of control over the .ORG registry to Ethos Capital. > The proposed transfer raises serious concerns that cannot be overlooked. (from https://itp.cdn.icann.org/en/files/correspondence/becerra-to-botterman-marby-15apr20-en.pdf https://itp.cdn.icann.org/en/files/correspondence/becerra-to...)
- NewJazz 23d agoThanks yeah was too lazy to go searching for a link.
- Apocryphon 23d agoI wonder which tech nonprofit would be best to champion this cause. Doesn't seem quite the EFF's domain.
- akersten 23d agoIt kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.). Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?
- orra 23d agoNobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.
- traceroute66 23d ago> Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk. Yup. The original statement was dangerous FUD which should be urgently corrected.
- BHSPitMonkey 23d agoYes, but you have to admit that the existence of these SLDs (like co.uk) is always going to be a point of confusion for anyone with a basic knowledge of how the domain hierarchy _usually_ works. Needing to be familiar with all the special cases (like the VERY special case of x.y.name which I previously knew nothing about) kind of ruins everything and introduces yet more security risk.
- traceroute66 23d ago> but you have to admit that the existence of these SLDs (like co.uk) I'm sorry, what ? Admit ? Confusion ? In the case of .co.uk it has been around since 1996. HN is a technical forum, most people here should be well aware it is a serious SLD. I honestly can't believe it even needs clarifying. Hell, if you use AWS Route 53 you'll see they use co.uk as one of their nameserver suffixes[1]. [1] https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/SOA-NSrecords.html https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/SO...
- nubinetwork 23d ago> Once the 3rd-level domains are terminated, it is assumed that the now vacant 2nd-level domains will become available for registration. Should someone (other than me) scoop up fraser.name (...) What's to stop someone from doing that, and keeping the status quo? Sure, it might be expensive, but pool together a few frasers for the initial buy, and make the money back on the sublets.
- theandrewbailey 23d agoDepends on how much one trusts whoever's running fraser.name. Is it more or less than Verisign?
- bityard 23d agoWell, nothing, but it does assume that Verisign doesn't have an unstated plan to do something else with .name. Domain registration is the real estate of the Internet and very little has happened in the last 30 years of domain name policy that has been for the benefit of anyone outside the the registrars. For all we know, this is simply the first step in a series of moves for Verisign to better monetize the .name TLD in some novel fashion. My evidence for this is that Verisign's own arguments for terminating the third-level domains are highly dubious. They claim that the third-level domains are too hard for them to manage. Bollocks: there are only 22,000 of them in use. That is a VERY small database that practically fits on a calculator and I refuse to believe that any manual labor around it is an outsized burden compared to pretty much any other semi-popular TLD. The second claim is that "the majority of those are not in use." Okay, if that's true, then where is the management burden coming from? That means tens of thousands of people are giving them money and getting nothing in return, isn't that the definition of an ideal business model? It just doesn't pass the sniff test. And finally, having read both of the linked documents, it sounds like people who have registered their .name for years in the future are not getting their money back. Are they likely to pay a second time, to a sub-registrar with no history?
- deleted 23d ago[deleted]
- wmf 23d agoDiscussion from yesterday: https://news.ycombinator.com/item?id=49516047 https://news.ycombinator.com/item?id=49516047
- pmdr 23d ago> I had history with Verisign and did not trust them. I don't know what that history is, but did it really make a tld used by only 22k people more appealing?
- decimalenough 23d agoThat's 22k people with third level domains like first.last.name. There are close to 100,000 second level last.name registrations, which are not going anywhere. https://www.icann.org/resources/pages/name-2014-03-03-en https://www.icann.org/resources/pages/name-2014-03-03-en
- cormorant 23d agoAccording to Wikipedia, "Verisign was the outsourced operator for .name since the .name launch in 2002". That makes the reasoning yet more puzzling.
- swiftcoder 23d agoThey ran the backend services, but didn't set the policies (until they acquired the operator in 2008-2009)
- jawns 23d agoSurely the author must have anticipated some heightened level of risk in pegging important parts of his personal and business life on a nonstandard TLD like this. It's a pretty bizarre exception to the normal, intuitive ways that domains work. I'll admit that it's a crappy situation and I would be frustrated in his place. But if I were in his place, I probably would have also thought it prudent to have a backup plan.
- swiftcoder 23d ago> nonstandard TLD What exactly is non-standard about an ICANN-approved TLD? Yes, the multi-level structure is a little odd, but given that ICANN approved it in the first place, one has a reasonable expectation that they would work as advertised.
- jawns 23d agoI have a .science domain and a .com domain. Even though .science was launched in 2014 (more than a decade ago), I still consider it a non-standard TLD and still deal regularly with difficulties around its use. (For instance, you wouldn't believe how many online services reject email addresses than end in .science because they use regexes that exclude TLDs with 7 letters.) Likewise, I've registered .lol and .fun domains but never would have assumed that just because they're available now, they will be available in perpetuity. In that sense, .name as a third-level TLD is even more non-standard, because the standard way domain registration works is by choosing a single "second level" domain name, then adding subdomains.
- angoragoats 23d ago> Likewise, I've registered .lol and .fun domains but never would have assumed that just because they're available now, they will be available in perpetuity. Why wouldn't you assume this? > the standard way domain registration works is by choosing a single "second level" domain name, then adding subdomains The entire ccTLD systems of the UK, China, Germany, France, Japan, and many others would beg to differ.
- chanux 23d agoI kind of assumed .name was a product of relatively new TLD explosion [1] [1] https://blog.asmartbear.com/free-markets-bad/ https://blog.asmartbear.com/free-markets-bad/ Gotta wonder what other possible disasters introduced with gTLDs.
- vidarh 23d agoNo, we were in fact part of the very first batch of "new" TLDs
- arjie 23d agoWe were rescued from that dot org scam by the fact that ICANN is a California non profit. I wonder if the AG can lean on them again. This is an outrageous thing to do.
- MagicMoonlight 23d ago[dead]
- patcon 23d agoThis is the comment I was looking for. Thank you
- zamadatix 23d agoMagicMoonlight was [dead]ed for not knowing what "dot org scam" refers to. Since I can't reply there right now and it's not reasonable to expect everyone to know what this refers to: ICANN, a 501(c)(3), proposed to remove the price cap on .org registration, commonly used for non profits, so PIR, the 501(c)(3) registrar for .org, could then announce it planned to sell .org operations to private equity investment firm Ethos Capital. Thankfully the overwhelming response caused the proposal to be scrapped.
- NewJazz 23d agoMM looks to be shadowbanned, I don't think anyone downed/flagged their comment.
- 22d ago
- decimalenough 23d agoI've had a .name domain forever and I had no idea first.last.name was even a thing, meaning that it was possible to register this without owning last.name. That said, my domain is simply unusual.name, and everybody in my family has email addresses in the form first@unusual.name. So this is a no-op for me, and I gather www.unusual.name will also continue to work, since I own the 2nd level outright.
- febusravenga 23d agoThis is silly question, but is your family managing trust in you as lone guy - cousin, father, brother - having potentially access to all their emails? I feel that I more trust some corpo (Google, etc) that one particular person. I don't imagine setup where you can effictevely guarantee them full privacy.
- decimalenough 23d agoI don't store their emails, I use forwardemail.net and they have a pretty reasonable privacy policy: https://forwardemail.net/en/privacy https://forwardemail.net/en/privacy Some people in my family use it as their main address, others don't, it's entirely their call. But yes, ultimately I control the domain and could be nefarious if I wanted to. But there's a certain baseline level of trust as a family, I'm reasonably certain my wife won't poison the milk in the fridge and she's reasonably certain I'm not going to read her emails.
- sunnybeetroot 23d agoHow do you manage the bus factor? You die tomorrow and what happens to management of the domain and therefore access to their emails?
- decimalenough 22d agoThere's a document explaining how it all works, and I have Google's Inactive Account Manager setup to transfer credentials to my trusted contacts if I go permanently offline. https://support.google.com/accounts/answer/3036546?hl=en https://support.google.com/accounts/answer/3036546?hl=en
- mococa 23d agoI never bet in any other than .com, .org, .net?
- CodesInChaos 23d ago.org almost got screwed in 2019 too: > In April 2019, ICANN proposed an end to the price cap of .org domains and effectively removed it in July in spite of having received 3,252 opposing comments and only six in favor. A few months later, the owner of the domain, the Public Interest Registry, proposed to sell the domain to investment firm Ethos Capital. After intense criticism from nonprofit groups and significant figures in Internet history, the proposal was scrapped. Surprisingly not by Verisign, who gave up .org in 2003.
- r_lee 23d agoI love that name, "Ethos Capital", it's so wholesome it'd fit like a PE firm focusing on chemical weapons
- jeroenhd 23d agoThose are all controlled by companies in and subject to the demands of the USA, which has been proving for many years that they cannot be trusted. Also, all common names with any of those prefixes have been registered a long time ago.
- nneonneo 23d agoIt seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3LD registered on top). It’s a bit insane that they can decide to just terminate all existing 3LD registrations. One would hope that they’d at least continue to reserve the 2LDs for some period to avoid domain squatting, but this isn’t mentioned in the proposal and I doubt Verisign would graciously do so.
- giancarlostoro 23d agoI'm surprised they don't just do that, and maybe even to go a little further, disallow renewals so you can phase people out and reclaim domains you can sell.
- xp84 23d agoWhether disallowing renewals or terminating them tomorrow, there's still the same core problems, only the date of the offense changes: (1) seizing people's names that they've established, breaking innumerable things including email and server hostnames, and (2) the possible resale of the 2LD fraser.com to a third party who will be free to do malicious things like reading OP's email, redirecting his traffic, or extorting him, to sell continued access at any price demanded.
- zamadatix 23d agoThere's one less core problem: those who just bought/renewed their domain e.g. yesterday are fucked out of both their money and forced to migrate sooner than they could have reasonably planned for. People's who registrations expire and they are unable to renew is a very different level of unfairness and inconvenience. In either case, the security concern should be directly addressed.
- xp84 22d agoWell, I'm guessing that Verisign will throw people a bone in terms of refunds just to avoid getting repeatedly hit with justifiably spiteful lawsuits that (I hope) would be trivially easy for customers to win. That will cost them very little in terms of cash, as I doubt that many people register that many years ahead, plus in terms of accounting, they won't have accrued that revenue anyway so it wouldn't even hurt their books. Not that a couple hundred K would even matter on the financial statements of a giant, money-printing corporation like that. The reason why they wouldn't go the route of waiting for expiry is that at least a few have nearly a decade left, and clearly they really want these gone, not just reduced in number. By 2036 when they would finally get to that point, I doubt whatever's driving this concern would even matter.
- cjjuice 23d agoI really think ENS is on to something with blockchain based domain registration and management
- Aachen 23d agoFamily of ESR or who is this?
- johnplatte 23d agoWow! Years ago I initially bought my firstname.lastname.name, then I let it expire and then bought lastname.name. So glad I did! Never dreamed that such a supposedly durable thing would just disappear. How hard is it really to preserve a global resource like this that exists only in software?
- bix6 23d agoFuck verasign. TLDs should be run as an actual public utility. Can these economic parasites be expelled already…
- allthetime 22d agoSomething tells me we ain’t seen nothing yet
- psychoslave 23d agoBreaking trust, one TLD at a time. So, where is our fully decentralized TLD alternative, free of ICANN or any central authority to handle how we grant names by conventions, without any money scheme in the game that attracts malevolent actors moving only through greed strings? Also, this time let’s make it like usenet, so "person:named:Neil Fraser" or even "::Neil Fraser" (harder to type but less culturally entangled into English).
- CodesInChaos 23d agoNamecoin (.bit) was an attempt to create naming system without a central authority using a blockchain. But from what I remember, they fucked up the pricing function and it got overrun by domain grabbers.
- toast0 23d ago> So, where is our fully decentralized TLD alternative, free of ICANN or any central authority to handle how we grant names by conventions, without any money scheme in the game that attracts malevolent actors moving only through greed strings? We can all edit our hosts file. The problem with a lack of a central authority is domain names are most useful if they follow the highlander principle. There can only be one neil.fraser.name ... otherwise it's not usable for routing traffic if every webserver a Neil Fraser runs uses that address. (Yes, there are useful ways for one name to resolve to different webservers, but almost always those are webservers under at least loose control of a single entity or very exceptional cases)
- aeternum 23d agoHow would the avg person know that ..name is different and somehow more trustworthy than ..uk Overall this seems like the right move, either they all are trusted or none.
- drnick1 23d ago> Second, my email address also disappears. Third, all the IoT devices that use services on this domain become bricks. Basically, I disappear from the Internet. While changing email is inconvenient, I don't understand the point about IoT devices. IoT devices should not depend on the Internet at all for obvious privacy and security reasons. If you are using IoT devices with "cloud" accounts, then this is a blessing in disguise. Put that garbage in the trash and rebuild around HomeAssistant, Zigbee, RTSP, etc. I find it hard to believe that someone hosting their own website would fall for the cloud IoT scam.
- jmuguy 23d agoPlenty of people and businesses have their own (DIY, etc) devices that need to use DNS. I mean it wouldn't really be the internet of things, if it didn't actually use the internet... For instance, I own a .house domain that I use for a bunch of stuff that I've programmed. It would be a pain in the ass to go change that domain out. Now take that to next level and you're a business that's deployed a few thousand devices that need to call home. I guess all this is to say - IoT doesn't just mean cheap botnet honeypot IP cameras. Take a look at https://www.balena.io/cloud https://www.balena.io/cloud for instance
- Sharlin 23d agoIt's dubious whether the Internet of Things was ever a good idea in any sense. Especially given how, famously, the "S" in "IoT" stands for security.
- drnick1 23d ago"Internet" in this context usually means IP, and in any case it should be restricted to a LAN. If you actually own the device changing the domain or IP should be trivial, I don't think this is what the article refers to.
- monkeyfacebag 23d agoIt sounds to me like you understand the point perfectly well, you just cared to make a different point.
- jmuguy 23d agoI can't be the only one that assumed based on the domain that this was some bizarre DMCA action by Paramount.
- Aachen 23d agoWhat does Paramount have to do with the last name Frazer?
- mminer237 23d agohttps://www.paramountplus.com/shows/frasier/ https://www.paramountplus.com/shows/frasier/
- Aachen 22d agoThat... has an i in it? Someone whose last name is Oppenheimer should also not have a problem registering their last name at any TLD so long as it's still available (first come first serve, and both have a reasonable claim to it so it won't be taketh away from either one), much less if yours is actually a different word
- willwade 23d agoI worked for .name briefly right at the beginning of their entry into the world. Interesting but very odd part of my career.. Ill give it that.. I personally found the product at first a great idea but somewhat crippled by execution..
- 1970-01-01 23d agoInstead of giving up, why can't all 22k .name owners move on to OpenNIC? They will not say no, you can't have that.
- notahacker 23d agoThe ability to register fraser.geek so a very small number of OpenNIC users can access that new URL doesn't really solve the OP's problem with his family's long-established URLs disappearing and their emails being directed to whichever scammer buys up the fraser.name domain.
- 1970-01-01 23d agoThat isn't the correct problem. The 3rd level domain is going away, which can be reconqured via OpenNIC and mass re-adoption. There will surely be new problems, but owning will not be among those problems.
- Macha 23d agoThe problem is everyone else (such as email providers...) recognising your ownership.
- 1970-01-01 23d agoThat's why you form leverage with 22k others that are in the same boat as you. The root with the users is the root that becomes trusted, which then becomes the root that resolves. Rolling-over and allowing ICANN to quietly get away with this is exactly what they want.
- j16sdiz 22d ago22k is nothing on the internet. A random youtube channel have way more than that.
- sigbottle 23d agoThere's a DNS wizard at my job (not doing DNS stuff currently; but in his past life), and while he was talking to me about certain topics my eyes glazed over, and I thought, "Man, surely that won't affect me, right?" Well, it's still not affecting me, personally, but wow, seeing articles like this makes it feel just a tiny bit more real.
- AtNightWeCode 23d agoThings like this happens from time to time and yet people insists on using stupid TLD:s just because of "cool" suffixes.
- r_lee 23d agoI would not use a 2nd level tld for a "stable presence". it seems like a gimmick
- lacoolj 23d agoDude, this is one of the craziest things I think I've read on HN First, that a legit dealer could/did(does?) sell third-level domains at all (Verisign, no less) Second, that the top-level is staying available, allowing for second-levels to be bought/sniped like you mention. If you do lawyer up and need help with legal fees, I think this would be a worthy cause.
- aliasxneo 23d agoThis is why I am building DNTLS. These organizations no longer deserve our trust and they have inadvertently gained too much power over the last two decades of massive internet expansion. Names need to be fully owned by individuals and a shared, decentralized trust system must be in place for resolution. The more I see actions like this, the more convinced I am that a solution is long overdue.
- theK 23d agoNever heard of DNTLS, thanks for sharing. I skimmed the Website and am a bit uncertain what the ai angle is. Shouldnt naming be, well, just naming?
- aliasxneo 23d agoYeah, the website is a holdover from when we were pitching AI VCs a few months ago. We quickly determined that the whole system is now "Cancer Capital" (see the other front page HN thread) and have pivoted to just bootstrapping from a close syndicate of like minded individuals. We plan to update the website this month, sorry it's a bit behind. In short, AI identities were just a happy accident that comes with the system/architecture. It's not tied to AI at all. But if anyone is interested in talking about what we're doing more, happy to connect at hn@sepositus.com.
- xur17 23d agoDo you have a brief explanation of what DNTLS is that you could post here?
- aliasxneo 23d agoSure, happy to put something here as a comment. Alice registers `alice.dntls` and Bob registers `bob.dntls` on the DNTLS network. During the registration process, they generate PQ key pairs that are registered along with the name. Alice's and Bob's name are hashed before being stored on the network. Bob knows Alice's name, so he can perform the necessary hash computation to look up Alice's public key material on the network. Likewise, Alice can do the same for Bob. Bob wants to send a file to Alice. Bob takes his name key and signs the document with it and sends it to Alice. Alice looks up Bob's public key material on the network and verifies the signature. Bob now stands up a new website, but he only wants Alice to access it. He sets up a standard HTTP server but slightly modifies it to be "DNTLS native." He does this by requiring mTLS on incoming TLS connections. The connecting party must identify themselves with a signed certificate. Each name has what we call a "name record" that allows publishing arbitrary metadata signed by the name key. Bob publishes a standard "HTTP" record in his own name record that points to the IP address. Alice now goes to connect to Bob's website. She opens her "special" browser and types in bob's name. The special browser looks up Bob's name record, finds the published IP address, and attempts an mTLS connection. Bob's server is configured to _only_ allow connections from Alice. Since Alice signed her TLS connection with her own name, the connection is allowed, while every other is rejected. Alice now wants to communicate with Bob's agent. Bob publishes a subname called `agent.bob.dntls`. In that subname's record he publishes an A2A packet that contains the information for connecting to his agent. But, like the website, the agent is listening on a TLS connection that rejects anyone except Alice. She uses an A2A tool to initiate a connection using her name key and is allowed to make a mutually secured connection to Bob's agent. Bob wants to connect to a VM he purchased that runs the website. He configures SSH with his name key as one of the recognized users. His SSH connection simply leverages the name key to authenticate him to the machine. But he shares the machine with another person and wants to share a secret with them. So he creates a SOPS encrypted file with his name and this other person's names as the only recipients. They both securely access the secret using their respective name keys. I'll leave it there, but hopefully that's descriptive enough.
- anominal 23d agoI am also one of the 22,000 people who have a third-level .name domain and I am livid about this, not least because Verisign flat-out lied in their proposal to ICANN: (https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2026017-name-request-01-05-2026-en.pdf https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2...) : "2.1. What effect, if any, will the proposed service have on the life cycle of domain names? None. There will not be any effect on the life cycle of domain names. ... 2.3. Explain how the proposed service will affect the throughput, response time, consistency or coherence of responses to Internet servers or end systems. There will be no effect on the throughput, response time, consistency or coherence of responses to Internet servers or end systems." My registrar is also suggesting that they are going to just keep the money I pre-paid for years of registration, which is a minor annoyance compared to the loss of my entire online identity but an annoyance nonetheless. Since ICANN is a non-profit that is required to operate in the public interest I do hope there can be some pushback on this. I will be writing to the CA AG myself.
- khalic 23d agoAh! verisign! Proving the world over and over what kind of scum they are
- dvt 23d agoI freaked out for a second because I've owned `dvt.name` for like 15 years. `.name` is not getting terminated, so it's important to be precise here. The third-level x.y.name (where you're the `x`) is getting terminated, and the respective `y.name` domains are going to be released. Still a crappy thing for people, but it does not affect owned second-level domains.
- wormius 23d agoThere should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level. But I didn't think about the 1st level competitors. There'd still need a mechanism to resolve that... 1. First come first serve? (e.g. whoever registered a y.name first, whether x is bob or sue is determined by the earliest registrant on record) 2. Lottery/random selection? 3. Bidding war? I think the problem is 2nd level domains who have the same name will be a problem when they find out all these other 3rd level are now expiring and can run a route to spoof? Likely wouldn't happen, but with the fuckery in the DNS that can happen... This is such a rash and weird decision to push through so quickly just because engineers find it "easier" while ignoring the implications of the move, seemingly when it comes to larger scale security. I assume there would have to be some method to prevent routing of third level domains to subdomains of two-levels... (or is that just me being a fool yet again, assuming we have competent administration of our systems).
- deleted 23d ago[deleted]
- mulmen 23d agoOr just honor the deal. The only reason for doing this is Verisign’s bottom line.
- p4bl0 23d ago> There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level. Yes. I've been asking VeriSign for this for years, and they always refused.
- Henchman21 23d agoHow is it that they can just nullify the contracts they had with people they were providing services for?
- nikanj 23d agoI wrote to ICANN support and got a template-AI answer wholly unrelated to my complaint about this: ”Greetings from ICANN Global Support. I am sorry to hear you are experiencing this domain access issue after your registrar's transfer. I will happy to provide you with relevant information and guidance. Please note that, ICANN accredits companies as domain name registrars and works to ensure contractual compliance with the terms and conditions of the 2009 and 2013 Registrar Accreditation Agreements (RAAs). ICANN does not provide domain name registration or manage domain accounts. As a result of that ICANN is not able to perform domain management for you. If you need help to access and manage your domain, you will need to contact your domain service provider or registrar for assistance. You may check who your registrar is by doing a domain search at lookup.icann.org.” Absolutely infuriating
- underdeserver 23d agodang and team, perhaps it makes sense to special-case .name domains in the domain hint, like you do for GitHub and Ex-Twitter.
- aidenn0 22d agoPer TFA, that won't be necessary for much longer.
- ClarityJones 23d agoIf this proves to be a viable business strategy, then verisign could equally use it to re-sell google.com, ycombinator.com, etc. to the highest bidder.
- bawolff 23d agoI feel like TLDs as a concept are more trouble than they are worth. We should just have .com and get rid of the rest (except special purpose tlds).
- jonhohle 23d agoOne of the reasons I stick with Big Email for my primary email is cases similar to this. If I host email and lose the domain one day, I’ve lost two factor on a thousand different services (the single factor on some). Big Email’s policy is to not reissue my address, should I lose it or die. The .name scenario is even worse. One domain gives you access to tens of thousands of users email. It seems like a privacy nightmare. I’m not sure how future auth and privacy will work, but my child lost a tracfone phone and some mixup had separated it from my account. There was no way to recover the number. If that was my personal phone, how difficult would it be to restore banking, medical, and government access to things that assume I’ll always have that number. Doing the same with personal email seems like too big of a risk.
- sunnybeetroot 23d agoYou can look through my history how many times I’ve brought this up to people and they just don’t seem to care. A defence is that they’ll buy the domain for a century and not care once they’re dead which is fair but the situation in this article is a valid one. I will always stick with Big Email for accounts.
- famfamfam 23d agoI moved to a third-level .name domain in 2005 precisely because one of the Big Email providers (Google) locked me out of my account with no recourse; presumably because I had a very common email address that was getting a large number of login attempts from other people which had triggered some abuse automation. At the time - before the explosion of new gLTDs - third-level .name domains were advertised as the 'correct' domain to register for individuals wanting personal email addresses.
- sandcat_ 22d agoYour response seems to imply those people are irrational, but it's really just different priorities. Yeah, you need to make sure you don't lose the domain. With Google/etc, you need to make sure you don't break any of their usage policies across their suite of apps, etc. Neither are super likely to happen. Neither are impossible, either. (Update: as it happens… https://news.ycombinator.com/item?id=49548452 https://news.ycombinator.com/item?id=49548452) Personally I like having a custom domain as I like the idea of being able to move between providers. So far, over the past decade, I've hosted my email with Google, Fastmail, Hey.com and then Fastmail again. I like being able to move it around if I find one provider better than another. Others won't care, that's fine too.
- johnnyApplePRNG 23d agoThey deserve to lose their control of all domains over this. This is ridiculous.
- xp84 23d agoI don't think it's hyperbolic to say that this is the most careless, disruptive change to anything to do with DNS or internet names I have ever seen. > "will increase efficiency for the operation of the .name TLD." What a preposterous excuse -- especially for something already up and running. Sounds like they probably want to change the backend in some way - or adopt some kind of off-the-shelf software - which doesn't jive so well with this unique TLD, and they figure "Ehh, fuck 'em, let's just pull the plug on these tens of thousands of people."
- TLDRisk 23d agoI thought I knew a lot about the policies and expectations when it comes to domains. I was surprised to see 3rd level domains called out in the .name registry agreement and I’m stunned that ICANN allowed this. It’s incredibly one sided. The registry gets to cut costs and the detriment to registrants is extreme. ICANN is supposed to act on behalf of all participants. The flagrant disregard for DNS stability in this case is jaw dropping.
- sandcat_ 22d agoAgreed. If you don't want to care about backwards compatibility, there's plenty of space for you in tech. Just not at a domain registry!!
- TZubiri 23d agoI wonder if this could constitute a violationiof article 6 of the UN declaration of human rights. It has been established that national identifiers are protected by it, and a domain works as a sort of international identifier, in this case a personal one. No one is obligated to give you a domain, but by contracting an obligation to provide that identifier until 2040, they would at least be liable for those damages, but there's an argument that depriving you of an identifier already granted is a more fundamental violation of a right to a name, an identifier and recordkeeping of them.
- MagicMoonlight 23d ago[dead]
- padjo 23d agoWho is running the show over at ICANN? How can this possibly be a reasonable thing for a registrar to do?
- troyrollo 18d agoRegrettably, the ICANN board has little if any technical talent and probably was not clued in enough to realise the consequences of approving this.
- notorandit 23d agoIt's just money. Nothing else. Just money.
- rburhum 23d agoLawyer up and fight it. This is bs.
- mig4ng 23d agoAnd that kids is why it's always DNS fault. Again, you're security is only as strong as your DNS.
- econ 23d agoI don't like the way domains work in general. It's really quite expensive if you are wise enough to buy everything that looks to much like your website. Did buy https://ycombinator.us https://ycombinator.us Didn't buy https://ycombinator.co.uk https://ycombinator.co.uk https://ycombinator.de https://ycombinator.de What useful functionality is there in selling these domains? Expiring domains is bad for the web and selling them to someone else is as terrible as the article makes it out to be.
- zamadatix 23d agoYou're also never going to register e.g. xcombinator.* nor is that necessarily a domain which should never be sold on the basis it's similar to ycombinator.*. Rather than buy everything, buy the ones most likely to be accidentally entered for only the most common tlds so you can set up redirects or the like and then enforce and protect your trademark like you have to in any other situation.
- jacobgkau 23d ago> Expiring domains is bad for the web Short-term, it might seem like it would make sense for domain registrations to be permanent, but long-term, it introduces at least two insurmountable problems: 1. Unless some other cleanup mechanism is in place, eventually (like, hundreds of years into the future) domains will need to get longer and longer as people who owned old ones disappear and new people need new ones. 2. The infrastructure costs (while nominal) to keep existing domains functioning would not be sustainable in perpetuity without relying on the assumption of more and more domains always being sold.
- econ 22d ago1) that has to be the worse case of premature optimization. 2) just solve the puzzle? The existing domain name system was wonderful when it was introduced. I'll do a crude solution that shouldn't make it to the short list of goodness: Just make the commercial part into a web directory with all registered businesses. Have some of those filters we are now all familiar with. It might even smoothly transition into a product catalog. Sell placement rather than some random name no one will accidentally bump into. Let's also do a nice tag based web directory for personal websites. Extra points if there is opml <link rel="outline" type="text/x-opml" href="webdir://hotel" title="Hotels"> It's not really my problem to solve under technofeudalism but it should be possible to make something modern.
- strenholme 23d agoThe correct way to handle this mess is to simply keep things messy. BGP tables are a big mess, for example, because a lot of companies keep their IPs when going from ISP to ISP. But, assuming that Verisign can’t keep third level domains (as a DNS implementer, I don’t think third level domains is a huge deal; see thread below): * Third level names where only one person has the second level domain should be transferred to whoever owns that single third level name. * Third level names where multiple people have the same second level domain should be put up for closed bidding: Only current owners of .name domains with a given second level domain name (e.g. last name) will be able to bid for the second-level domain. So, if one has john.smith.name and joe.smith.name, Joe Smith and John Smith will be in a bidding war for smith.name. If the issue of .name not being in public suffix is a real issue, Verisign can handle that by disabling new third-level .name registrations, and provide Public Suffix with a list of those registrations (just send all the owners a privacy notice, making it clear that the existence of the name will be made public for security reasons). More reading: https://github.com/publicsuffix/list/issues/2306 https://github.com/publicsuffix/list/issues/2306 (There seems to be issues with this list being too long to keep in the Public Suffix because there’s too much software out there which can’t handle it. That seems strange to me: Even here in 2026 where RAM costs far too much, Deadwood can store a list of 240,000 blacklisted entries in under 10 megs; there are about 22,000 three-level .name domains and I could store that list in a way that could be very quickly looked up in about a meg of memory) Now, personally, I think Verisign can keep these messy third level names, and are doing things this way so that Neil Fraser has to compete with every single 2-bit cybersquatter out there for the rights to fraser.name. As an aside, it’s trivial to have DNS servers handle multi-level domains without having to have a zone file for every level; e.g. https://this.is.a.long.name.maradns.org https://this.is.a.long.name.maradns.org works, and there’s no zone file for name.maradns.org, long.name.maradns.org, a.long.name.maradns.org, and so on. Also, since people have brought up the “org fuckery” without providing details: https://bluecatnetworks.com/press/the-org-domain-sale-explained/ https://bluecatnetworks.com/press/the-org-domain-sale-explai... You know dang well if .org was owned by an investment entity, they would had jacked up the prices as much as they could get away with.
- xp84 23d agoThe auction plan is gross. It is unfair to say "This thing you thought you were buying the right to exclusively control (subject to continued renewal payments)? We're gonna transfer it next week to whichever Fraser pays us the most. Happy bidding!" It wouldn't be any more fair to do that than to announce to all .com owners that there will now be an auction between them and everyone who ever typed that name into a search at the registrar. What they should do, is nothing.
- aff-vasileva 23d agoTurns out “buying your name on the internet” was technically just renting a room in someone else’s last name.
- mzajc 23d agoIn this case the registry itself (Verisign) was the owner of the second-level domain, and they most certainly shouldn't be allowed to just drop your registration whenever they please.
- akulbe 23d agoI don't get the concept of 3LD. We own kulbe.name - does this news mean it's going to go away entirely?
- cpach 23d agoOuch. IMHO, this whole TLD seems kind of messed up from the start: https://en.wikipedia.org/wiki/.name https://en.wikipedia.org/wiki/.name
- nanolith 23d agoThis risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices used were entirely disconnected from domain names, and why the discovery protocol I put together did not rely on registered domains, but could use these as an untrusted part of discovery. Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity. I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be. I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.
- fh67 22d agoCan you share how the discovery worked?
- ACCount37 22d ago"Online identity" seems like a castle built on quicksand in every single case. What's your account tied to? E-mail? That's usually on a mail server owned by someone else. If not, it's still on a domain owned by someone else. Phone number? Definitely owned by someone else. The only account that's reliably "yours" is one that asks for a login, a password, maybe a TOTP, and absolutely nothing else. Because everything else is introducing "things owned by a third party" into the equation.
- remuskaos 22d agoYou've hit the nail on the head. That's why I strongly preferred email and password login, backed by a keepass(xc) store to hold the data. Owned by me, backed up, impossible to take from me, the works. Sure, most of the time I have to verify my mail address, but after that the account is mine. Well, okay. On some services, I have to "confirm the new device" I'm loggin in from, so I still need access to my mail. Weeeell... Some services I use seem to have switched to a magic link EVERY TIME for login. No password anymore at all. And all of a sudden, my mail account is the single point of compromise for these accounts. And there is absolutely nothing that I can do. If the mail is hosted by someone else, they may terminate my account at a whim. Or give it to someone else who happens to have convinced my phone provider to hand them a sim card with my number on it. If I do self host I still need a domain, and I can never really own a domain, only rent it from somewhere. So, whenever that lease goes up, my account is compromised by default. I really hate that this problem seems still unsolvable. Keybase had the right idea, but no one used it and they got aquihired by zoom during the pandemic...
- Glyptodon 23d agoIt's kind of crazy to me that the whole domain was originally set up so that people would buy 2nd and 3rd level pairs. But it also seems really obvious that backtracking is going to be a disaster.
- 0xbadcafebee 23d agoPrediction: In 20 years, ICANN, IANA, ARIN become increasingly abandoned by nations wary of The Imperialist States of America's control over global communication & commerce, and the internet becomes an uber-net of nationalist internets, subverted by satellites.
- morissette 23d agoIt seems as if only 40 people are needed for a class action suit. Me, not a lawyer. Gemini says chances are you could only get a refund. But maybe worth the fight for some.
- marbleotter115 23d ago.name is the part I keep having to relearn, so seeing it spelled out helps.
- jl6 23d agoI can only assume somebody was asleep on the job when this scheme was approved, because the outcome is in direct contradiction to ICANN’s mission statement: > Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems. https://www.icann.org/resources/pages/about-icann https://www.icann.org/resources/pages/about-icann Arbitrary termination of service is not stability. Enabling name hijacking is not security. The answer cannot be a rival name scheme based on decentralization or crypto or whatever. Those are never going to help normal non-wizard users. The answer has to be to make the regulators do their job.
- ALLTaken 22d agoSorry, I don't understand this rule, would someone kindly explain? I own lastname.name and use it for email only like this: firstname@lastname.name I always thought as owner of lastname.name, I'm the only one able to add subdomain.lastname.name. Is this wrong?? 1) Can anyone "buy" scam.lastname.name without my authorization on .name?? 2) Can anyone owning not.lastname.name then steal my emails going to: firstname@*.lastname.name or even firstname@lastname.name?? BUT: If someone ONLY bought not.lastname.name and doesn't own lastname.name, they'll get terminated. Would that be 'good' as it would stop 1) and 2) ?? I'm really concerned. My family is using first@lastname.name as the personal email, I'm hosting and paying for since many years.
- deleted 22d ago[deleted]
- judge2020 22d ago> I always thought as owner of lastname.name, I'm the only one able to add subdomain.lastname.name. Is this wrong?? TFA mentions that `.name` was unique in that it sold a good amount of third-level domain names directly from the registry.
- iminatx 22d agoNo, that's not how it works. If you have registered the 2LD you have exclusive control of it, and only you can delegate a subdomain under it. However, a great number of common first and last names are reserved as 2LDs by the registry and cannot be registered by anyone; instead, third-level registrations under those 2LDs are available. Also, if someone does register a 3LD under a previously non-reserved 2LD, the 2LD will be reserved reactively so that no one can register it.
- projectileboy 23d agoWe keep expecting for-profit organizations to behave as governments. And this is an especially easy sell in the US, where government has been vilified for decades as part of a long propaganda game run by those who wish to privatize and steal those things which should rightfully exist in the public domain. But for-profit organizations, by design, will never ever ever behave in the public interest, and it’s foolish to expect otherwise. This is not a criticism of the author; this is a criticism of ICANN, and the subcontracting of governance.
- crabmusket 22d agoAmen to this. I don't know why we put up with this for infrastructure in particular.
- xbar 22d agoI can only assume ICANN was co-opted by Verisign some decades ago.
- niraj-agarwal 22d ago22,000 people affected. Link up and lawyer up is right. To have identity and existence taken away is a no go.
- basilikum 22d agoI seriously wonder what ICANN is good for.
- account42 22d agoTheir purpose is to provide cushy rubber stamping jobs.
- thbb123 22d agoWtf, I have been using my x.y.name domain for everything, haven't been notified of this. Should I rush to reserve y.name so my email address and personal website can stay online?
- kronodeus 22d agoBased on my understanding of the situation, the 2LDs are getting sold, so yes, you should try to acquire the 2LD if you want to retain control of your subdomain(s).
- baylisscg 22d agoWhat's wild is that when initially launched you could only register 3LD domains. If you were quick out the gate and registered one in 2002 and have been using 10 year renewals you're about to have a domain you've owned for almost a quarter century with 6 years left on its registration nuked.
- TZubiri 22d agohttps://itp.cdn.icann.org/en/files/consensus-policies/rsep-2026013-name-request-15-04-2026-en.pdf https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2... >2.1. What effect, if any, will the proposed service have on the life cycle of domain names? >None. There will not be any effect on the life cycle of domain names. >2.2. Does the proposed service alter the storage and input of Registry Data? >No. There will not be an alteration to the storage and input of Registry Data. This sounds wrong? Is this just a knee-jerk form-filler reaction? It seems to me that the admitted "Upon discontinuation, no new third level domain names will be registered and existing third level domain names will be terminated." In general this sounds like a grotesque misplay that is wildly uncharacteristic for the entity behind the timeless .com
- NAR8789 22d ago@dang can you update the domain extraction logic for hn titles to include the 3rd level domain for .name domains? It's a little too poetically unfortunate that HN lists the domain on this article as `fraser.name`
- dang 22d agoSure. We have this for countries, like "example.co.uk", so I made "name" be a country and it...just works (maybe). You only get a first name and a last name and a .name though. You can't be robert.louis.stevenson.name - just louis.stevenson.name. (Incidentally, this was a Claude suggestion. The change only took a couple minutes but figuring out what mechanism in the code could do this would have taken me a lot longer.)
- epaga 22d agoWhile we have you here - I've seen this discussion multiple times - does @dang "do" anything to get your attention, or did you just happen to see it because you were scanning the comments manually, and therefore email is better for letting you know something?
- dang 22d agoWe don't monitor @dang. We only monitor emails. Someone emailed me in this case.
- NAR8789 21d agothanks!
- Maxforever 22d agoI saw it
- OtomotO 22d agoHoly f*ck... you had me there for a moment. I thought they would end the top level .name domain. Everything business related runs over such a domain. So I totally get you! It's like someone pulled the ruck from under your feet.
- m4tthumphrey 22d agohttps://neil.fraser.name/news/2002/02/19/ https://neil.fraser.name/news/2002/02/19/ > Time to move to a new domain, one that will not obsolesce quite so quickly: neil.fraser.name. I guess it wasn't quick, but eventual. :'(
- nirui 22d agoWonder what's up with the GNUnet (https://www.gnunet.org https://www.gnunet.org). Apparently there's still activity on it's development, but I didn't see adaptation/integration, even in free software like Linux. Sure it's not 1.0 yet, but the open source world is filled with sub 1.0 software that works great. A stable online identify is important, that's maybe why you rent those domains etc. But after rent and forego quite a few, I slowly realized that domain at it's current format isn't a stable presence, instead it's more like branding instead of an identify. If an identify can be operated by different people without it's previous operator agreeing, is it truly an identify? But I do need an identify, always under my control as much as possible, so people can trust the content and service running on it without having to guess if it's still me operating it.
- summm 18d agoGnunet was and is incredibly advanced technology, solving many problems better than most p2p systems that came after, who never bothered to even look at those ideas, and implemented worse concepts from scratch (IPFS, veilid, libp2p...) However, it is exclusively academic, and the authors let themselves be distracted too much. The system was mainly developed by grad students who mostly leave after they have completed a barely working proof of concept for their thesis. It never had enough functionality running smoothly enough to attract a meaningful community, which would have been a prerequisite for a p2p network. It is so sad.
- nirui 15d agoHmmm, I was wondering who were the "volunteers or people paid to do fundamental research" (in their project docs), it turned out to be new grads LOL. But I wouldn't blame Torrent or IPFS, these project maybe less shiny, but they actually work, so :)
- menzoic 22d agoThis is the first time I’ve remembered decentralized domains exist in a while
- haebom 22d agoWho would buy a domain name in the form of a meme these days?
- SJA7 22d agoThe .name third level domain is an interesting artifact of early 2000s internet. Sad to see it go.
- hoppp 22d agoFraser.name is taken so I really hope he took it
- Unified-Mentor 22d ago[dead]
- chriscjcj 22d agoIn 1992, I got myself an AT&T EasyReach 700 number. It was going to be my phone number for life. They killed that a couple years later. Then I got an AT&T True Connections 500 number. It was going to be my phone number for life. That died a few years later too.
- Yizahi 22d agoSo basically a managing company for the apartment block is forcibly evicting every single home owner via some toilet paper exemption by the government, and not only that, but they will tell you that after eviction happens at some unspecified day and time, the first person to get to a city council and claim apartment, will become legally its owner. And they also stealing any and all advance payments, just because. Nice policing there :)
- hackrmn 22d agoThis points to a more general problem with some of the Internet infrastructure -- since real people don't actually own domain names, much less e-mail addresses (assuming they use e.g. @gmail.com), they're always at the mercy of a third party, which is normally tolerable except that with prevalence of user accounts at various Internet services, for any given person, tied to an e-mail that receives password reset instructions and what not, ultimately ownership of the service account is in the hands of whomever owns the e-mail. Although Google doesn't read your e-mail to order pizza on your behalf and bill, and even if your crypto-savvy brethren encrypt their communication to you, services you more or less depend on do _not_ send you e-mail that only _you_ can open -- regardless of the mail transfer or storage system (read: the e-mail is plaintext). In light of this particular situation, I think a secret key shared between you and the service, at least, could guarantee that even in the event the e-mail address is stolen (or otherwise taken) from you, the service account remains in your hands. I know I am not breaking new ground here, but I don't think the Internet is getting healthier for the human, it's at least going to get worse before it may get better. So maybe we need to adjust our assumptions and mitigate accordingly.
- CM30 22d agoThis feels insane to me. Like, they're just terminating existing registrations? As the article says, this is a massive security problem waiting to happen, and there will be a lot of untoward consequences if things aren't handled very carefully. Let's not forget the SEO or marketing consequences either. If you've got a business with this sort of domain, you're basically screwed. If existing third level registrations are terminated, and you can't get the relevant second level domain, your SEO/marketing work has literally been shot to pieces. I wouldn't be surprised if Verisign got sued for this. There's no reason not to honour existing registrations while discontinuing new ones here, and the fact they're not feels completely at odds with how the internet should work as a whole.
- cute_boi 21d agoI think ICANN has become too much monopoly.
- sillygoatdev 20d ago[flagged]