5 ms·
It kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part,
by akersten 1mo ago
It kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.).
Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?
- orra 1mo agoNobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.
- traceroute66 1mo ago> Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk. Yup. The original statement was dangerous FUD which should be urgently corrected.
- BHSPitMonkey 1mo agoYes, but you have to admit that the existence of these SLDs (like co.uk) is always going to be a point of confusion for anyone with a basic knowledge of how the domain hierarchy _usually_ works. Needing to be familiar with all the special cases (like the VERY special case of x.y.name which I previously knew nothing about) kind of ruins everything and introduces yet more security risk.
- traceroute66 1mo ago> but you have to admit that the existence of these SLDs (like co.uk) I'm sorry, what ? Admit ? Confusion ? In the case of .co.uk it has been around since 1996. HN is a technical forum, most people here should be well aware it is a serious SLD. I honestly can't believe it even needs clarifying. Hell, if you use AWS Route 53 you'll see they use co.uk as one of their nameserver suffixes[1]. [1] https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/SOA-NSrecords.html https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/SO...
- BHSPitMonkey 29d agoI'm not referring to the HN audience; I mean the larger evergreen cohort of people in the world who are still building their mental model of how the web works. They will each eventually be doomed to the same misconceptions because it's a system full of inconsistencies and special cases.
- deleted 1mo ago[deleted]
- CodesInChaos 1mo agoSurprisingly the public suffix list doesn't list `*.name`. So they're indeed not properly isolated from each other. https://publicsuffix.org/ https://publicsuffix.org/ edit: apparently not all second level domains in .name are public suffixes anymore, so a wildcard addition wouldn't be correct.
- gpvos 1mo agoIt wouldn't surprise me if that is (maybe even a large) part of the reason for this change.
- xp84 1mo agoWhat does Verisign care though? It's been that way for way over a decade since they started allowing 2LD registrations. I very highly doubt they are suddenly so worried about random individuals' personal internet security. It has to be a money problem. Something they want to do will be simpler if this is no longer a quirky registry. And they know they'll get the money back that they lose from not having bob.smith pay -- probably by throwing all the "last names" once registered this way into some "premium name" bucket and selling them for $1000 and up instead of the ~$10 that zyzgdhaf234.name fetches. In fact, I'm not sure that scheme isn't the reason itself.
- gpvos 1mo agoFair. That would indeed be more in character.
- SahAssar 1mo ago.co.uk is run by the same people as .uk. There is no additional org that you trust when you register a .co.uk: https://en.wikipedia.org/wiki/.uk#Second-level_domains https://en.wikipedia.org/wiki/.uk#Second-level_domains > do browsers have a wildcard suffix list Yes: https://publicsuffix.org/ https://publicsuffix.org/ and they have discussed this situation here: https://github.com/publicsuffix/list/issues/2306 https://github.com/publicsuffix/list/issues/2306
- akersten 1mo agoI know about the public suffix list - I was wondering about the wildcard specifically. In the very issue you linked to, as of 2025, it seems this was still unresolved...: > We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't.
- SahAssar 1mo agoI'm just saying that they have discussed the situation. They seem to have no answer and for cookies and similar things the answer probably is "maybe don't run security critical web stuff in the third level under .name". IIRC orgs like letsencrypt also use the PSL for rate limits, so there are probably more issues that are not browser-based.
- xg15 1mo agoYeah, apparently they both (used to) offer unbounded registrations of 3LDs and unbounded registrations of 2LDs? So if I see j.doe.name, the only way to find out if "doe.name" is a public suffix or not, i.e. if I should (not) be able to set a cookie on it, would be to email the registrar? So does that mean that in practice, .name domains were always treated by browsers like regular 2LDs, meaning the cookie and origin protection was always broken for those domains? Doesn't sound like good news for the guy in the OP...
- deleted 1mo ago[deleted]
- 1mo ago
- QuantumNomad_ 1mo agoNote that the posted link talks about .uk.co, which currently does not exist but I guess may have in the past. Where .co is the ccTLD of Colombia. Different from .co.uk.
- kevin_thibedeau 1mo agoOriginally there was uk.co.orgname.
- cpach 1mo agoHuh? I don’t follow.
- QuantumNomad_ 1mo agoThey might be referring to this kind of thing: > The first appearance of reversed DNS strings predated the Internet domain name standards. The UK Joint Academic Networking Team (JANET) used this order in its Name Registration Scheme, before the Internet domain name standard was established. For example, the name `uk.ac.bris.pys.as` was interpreted as a host named `as` within the UK (top level domain .uk) from the History section of https://en.wikipedia.org/wiki/Reverse_domain_name_notation https://en.wikipedia.org/wiki/Reverse_domain_name_notation But I don’t know if uk.co.somethingsomething did or did not exist at that time. Or if it was only introduced after the Internet domain name standards we use today existed and so was .co.uk from the beginning.
- zvr 1mo agoOh, uk.co definitely existed for companies. The other 2nd-level domain (besides the academic uk.ac and uk.co) was uk.mod (Ministry of Defence), equivalent to the US .mil. And then, because life is never this simple, things appeared that were neither universities nor companies nor military, so uk.bl was given to the British Library. There might have been others as well, I don't remember. Back then the code in various pieces of software had hand-written exceptions for domain processing. The joke was that all Computer Science departments in the UK (uk.ac.university-name.cs) ended up in Czechoslovakia.
- nneonneo 1mo agoSince neither smith.name nor the wildcard *.name appear in the Public Suffix List (https://publicsuffix.org/ https://publicsuffix.org/), browsers would likely allow any page on a *.smith.name domain to set cookies for .smith.name. There was an effort to properly handle the .name 2LDs, but it was never resolved because there’s no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name: https://github.com/publicsuffix/list/issues/2306 https://github.com/publicsuffix/list/issues/2306 So yes, this TLD’s setup is in fact pretty insane.
- rwmj 1mo agoI think this says more about how the cookies security model is stupid. They should always have been scoped to the single, exact name they were set from and nothing else. Websites would have had to be designed a bit more thoughtfully.
- lxgr 1mo agoIt’s not nearly just cookies, and I think interpreting domain hierarchies as administrative structure generally does make sense. Maybe it could be opt-in or opt-out via some markers at the DNS level, though? The public suffix list having to exist at all is bizarre.
- markhahn 1mo agothat seems strange to me: why shouldn't policy leverage name resolution? sort of like dkim, but taken further. for instance, for site.com, I'd much rather retrieve its public key from DNS (some DNS++ version, of course).
- amluto 1mo agoAn “administrative structure” seems fine, but the fact that a subdomain gets any sort of privilege over the parent has always seemed absurd to me. Surely a better solution would involve an actual request. login.foo.com could send a request to foo.com with Origin: login.foo.com asking to set a cookie, and foo.com could make its own decision.
- omnibrain 1mo agoAbout 20 year ago I registered {lastname}.name and have dozens third level domains below it. So there are "privately owned" second level domains under .name for quite some time...
- Pxtl 1mo agoI'm working on same for my family since I want to properly degoogle a bit. One thing I think long term - if I give my kids first-name @ last name , that means that I forever hold power over their email. Which isn't great. But what's the alternative? Register one full domain name per kid? Even ignoring the cost, the ergonomics are awful. Imho email is missing a feature for nameless email addresses for when somebody just buys their full name as a domain name. If I get "firstname-lastname.name", having the email be "firstname@firstname-lastname.name' kinda ruins it.
- skinfaxi 1mo agoFrom what I can tell most people do something like me@myname.whatever or hi@domain.
- deleted 1mo ago[deleted]
- londons_explore 1mo agoA child born today sees email like we see the telegraph... they'll grumpily sign up to gmail just so they can get a verification email, and that'll be all it gets used for. Messaging their irl friends will be done in apps like Discord.
- peezd 1mo agoTruth. lol I ran a sizeable team around 2020 and I had to educate a couple of our new hires straight from college that they actually needed to check their work email, after they missed important HR related stuff and they had just completely not realized it was an avenue for company communication, with an assumption that everything was available on our heavily used slack.
- pushcx 1mo agoIt wasn't obviously wrong in 2001. .pro started with a similar structure around the same time.
- traceroute66 1mo ago[flagged]
- stronglikedan 1mo agogeez, dude, someone woke up on the wrong side of the bed this morning...
- traceroute66 1mo ago> geez, dude, someone woke up on the wrong side of the bed this morning... 5 seconds on wikipedia or google would have stopped them spreading completely dangerous FUD about .co.uk.
- dokyun 1mo ago[flagged]
- yreg 1mo agoWhat's so dangerous about it?
- traceroute66 1mo ago> What's so dangerous about it? Implying lack of trust in `co.uk` Implying `co.uk` may suffer the same fate at `.name` Complete FUD.
- gertrunde 1mo agoYou're absolutely right, when it's Nominet's actions that actually inspire a lack of trust in .co.uk, given they've been a bit of a hot mess since the early 2010's-ish. ;) (Edit: although I should add that I'm hopeful that things have improved there over the last few years).
- traceroute66 1mo ago
- Pxtl 1mo agoAgree that the .name 3rd level domains are silly, disagree on .co.uk being a problem. If .gov and .mil and .com make sense, then .gov.cc and .mil.cc and .com.cc make sense. Of course, I think having more than one non-cc TLD was a mistake, but that's just me. If it makes sense to have topical TLDs for international and US institutions, it make sense to have national ones.
- traceroute66 1mo ago> disagree on .co.uk being a problem Nominet and therefore .co.uk has been around since 1996. .co.uk is not going anywhere, and neither is Nominet. The only "problem" is the original poster did not do their homework. I suspect they were inferring `uk.co` which is a completely different kettle of fish. The original poster should urgently correct their post.
- gpvos 1mo agoThe 3rd level .name domains are the original ones. They didn't hand out 2nd level domains until three years after they started.
- OkayPhysicist 1mo agoSo, this kind of thing happens all the time, and there's the Public Suffix List for exactly this problem. There would be no issue at all if Verisign, or maybe Global Name Registry, decided to stick to the 3rd level registrations exclusively. Problem is, the chucklefucks over there decided it was a good idea to also hand out 2nd level registrations. Those 2nd level registrations outnumber the 3rd level registrations by an order of magnitude, so the PSL decided to just let joe.smith.name and john.smith.name share cookies. Which, IMO, was not a good decision, but it is what it is.
- dolmen 1mo ago.uk.co (mentioned in the blog) isn't .co.uk
- indymike 1mo ago> It kind of seems like an insane TLD structure to begin with, right? It's been around for years. I seem to remember this issue coming up around 2001 where originally .name was for third level registration (i.e. john.doe.name) and changed to second level it a few years later and caused some problems... https://publicsuffix.org/ https://publicsuffix.org/ talks about it in light of architectural limitations of domain names. > can Joe set a cookie on all of .smith.name? That can happen. I seem to remember ancient browsers made it so .name (and other non-generic TLDs) required three periods. I think country code domains and new generic TLDS caused the browsers to change it. It's pretty screwed up, but a lot of the people with .name domains have had them for a very long time. Sad to see them all lose their identity online that way.
- Ekaros 1mo agoTo me that sounds like reasonable structure. I hold that every single edu, gow and mil domains should be moved under respective ccTLDs. After this sort of move that doesn't seem unreasonable thing.
- zahllos 1mo agoIn the UK Nominet (the UK domain namr registrar - nic.uk) only permitted 3rd domains - co.uk. org.uk, me.uk. then there were "prove your status" ones such as ltd.uk, plc.uk and ac.uk plus ones like gov.uk, mod.uk, sch.uk, nhs.uk etc. .uk was opened up relatively recently.
- eterm 1mo agoI own a .uk and it still feels weird not having something in-between.
- megagpt1 1mo ago[dead]
- pumplekin 1mo ago.uk and .co.uk are both run by Nominet, the UK registry. Quirky stuff like .co.uk / .org.uk / .sch.uk 2nd level domains partly come around from .uk being the worlds first CCTLD outside the US (and as other parts of this thread say, .us isn't that popular a CCTLD). Everything was new and different people tried different hierarchy and structures to 2LD and 3LD's. .co.uk is also far from unique, I know this is common in many other places (UK/NZ/IN/ZA/KR/MX). The UK now allows directy foo.uk registrations as well, but many people still have SLD's registered and will continue to do so.
- preisschild 29d agoIt definitely makes sense for stuff like (non-US) gov domains. Have a federal agency control the `gov.<ccTLD>` domain and hand out subdomains to other agencies. See https://dachmarke.gov.de/ https://dachmarke.gov.de/ for example. But I agree it makes no sense for public sales to the wider world such as `co.uk`. At least have the registrar be the govt company register and hand out subdomains to each registered company.