23 ms·
It seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3
by nneonneo 1mo ago
It seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3LD registered on top). It’s a bit insane that they can decide to just terminate all existing 3LD registrations. One would hope that they’d at least continue to reserve the 2LDs for some period to avoid domain squatting, but this isn’t mentioned in the proposal and I doubt Verisign would graciously do so.
- giancarlostoro 1mo agoI'm surprised they don't just do that, and maybe even to go a little further, disallow renewals so you can phase people out and reclaim domains you can sell.
- xp84 1mo agoWhether disallowing renewals or terminating them tomorrow, there's still the same core problems, only the date of the offense changes: (1) seizing people's names that they've established, breaking innumerable things including email and server hostnames, and (2) the possible resale of the 2LD fraser.com to a third party who will be free to do malicious things like reading OP's email, redirecting his traffic, or extorting him, to sell continued access at any price demanded.
- zamadatix 1mo agoThere's one less core problem: those who just bought/renewed their domain e.g. yesterday are fucked out of both their money and forced to migrate sooner than they could have reasonably planned for. People's who registrations expire and they are unable to renew is a very different level of unfairness and inconvenience. In either case, the security concern should be directly addressed.
- xp84 1mo agoWell, I'm guessing that Verisign will throw people a bone in terms of refunds just to avoid getting repeatedly hit with justifiably spiteful lawsuits that (I hope) would be trivially easy for customers to win. That will cost them very little in terms of cash, as I doubt that many people register that many years ahead, plus in terms of accounting, they won't have accrued that revenue anyway so it wouldn't even hurt their books. Not that a couple hundred K would even matter on the financial statements of a giant, money-printing corporation like that. The reason why they wouldn't go the route of waiting for expiry is that at least a few have nearly a decade left, and clearly they really want these gone, not just reduced in number. By 2036 when they would finally get to that point, I doubt whatever's driving this concern would even matter.
- marysol5 1mo agoIf hosting a zone and handling the odd customer transaction is "too much work", giving a refund to avoid all the aggravation of getting sued seems a lot like the easiest and best option
- echelon 1mo agoThat would be so cool and would make these limited hot commodities. .name was one of the very first expansions of gTLDs back in the very early 2000s. It's a shame that it's being shut down as it was spearheaded by the ICANN itself rather than some registrar / investor like Donuts, Inc. I suppose this is impractical as someone has to run the registry and there are costs associated with that. But don't the domain fees cover it?
- ajmurmann 1mo agoFrom having worked in that space what feels another lifetime ago, I vaguely recall that you can just offload the registry work to a registry that would manage this together with a mountain of other TLDs.
- account42 1mo agoYes, that's what Verisign does here - they also host many of the other big generic TLDs like .com.
- AtNightWeCode 1mo agoAs I recall it. This was mostly a money scam that targeted private users with ads like "make sure to claim to your .name domain so no one else does it and use it to impersonate you". It was stupid from the beginning and never took off.
- layer8 1mo agoMaybe they want to avoid the ambiguity between john.doe.name versus john-doe.name, and I assume they prefer the latter scheme because it probably sells better. Nevertheless, discontinuing existing domains is disgraceful.
- xp84 1mo agoEven that doesn't pass basic scrutiny. The same ambiguity can and always will exist with tim-apple.com and tim.apple.com - there's nothing here that needs fixing.
- dpoloncsak 1mo agoI can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real. It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule
- marysol5 1mo agoPeople still fall for paypal.com.4385ht43987th34098rh34279h3.legitorg.ru
- dbt00 1mo agoThat is definitely not true. There are literally thousands if not tens of thousands of well known domains that do this. .co.uk is a very common example.
- desas 1mo agoI think the problem is that .co.uk, .gov.uk and so on are very well known in the UK. The .name subdomain rules are not very well known anywhere.
- p4bl0 1mo agoAnother thing that should be obvious and yet they refuse to do: when there is a single third-level customer for a given second-level, offer them a way to get the second level domain. I've been asking VeriSign this for 15+ years, they always said no, even if at some point they confirmed that there were no other third-level than mine under that second-level domain. They're insane and should not be in charge.
- jaggederest 1mo ago> They're insane and should not be in charge. I remember back when we had to write mechanize scripts to drive a browser through the renewal process, because if you had dozens, hundreds, or thousands of domains there was no nonmanual way, especially if you wanted extended verification or something silly like that. So what I'm saying is, agreed and that has always been true.
- account42 1mo agoThat actually sounds like a good thing. Why are you hording hundreds or thousands of domains?
- jaggederest 1mo agoI was working for a company that had hundreds and thousands of domains. It was a fortune 50 company, and they had a policy generally against wildcard domains.
- lqstuart 1mo agoI really wish I could be this stupid and have enough power to make such stupid policies
- jaggederest 1mo agoI felt the same way at the time. Now, I believe we have better things to spend our collective time and energy on.
- JumpCrisscross 1mo ago> the right thing they should do Can someone explain why a product "registered and paid for until 2040" can be unilaterally voided like this without compensation?
- lazide 1mo agoBecause they haven’t been sued enough yet?
- account42 1mo agoICANN should not approve such an obviously fraudulent move even without anyone being sued. Neither should Verisign even consider that they'll be able to get away with it. If you need to sue for this something else is already very wrong with the system.
- lazide 1mo agoA lack of consequences (getting sued and losing) is what leads to this. Is it corrupt? Yes. Is there a factor making corruption inevitable? Yes.
- JumpCrisscross 1mo agoI guess I’m confused why the author isn’t pursuing this legally.
- Toynbeeidea 1mo agoHe is.
- spider-mario 1mo agoThe post ends with: “Time to lawyer up...”
- toast0 1mo agoEspecially when the marketing was saying [1]: > As your .name can be registered for up to 10 years and ownership is renewable, your .name really can be yours for life. It seemed like there was an offer of renewable registration at least for a life term. [1] https://web.archive.org/web/20020609132126/http://nic.name/consumer/index.html https://web.archive.org/web/20020609132126/http://nic.name/c...
- deleted 1mo ago[deleted]
- kees99 1mo agoHaving a mix of both 2LD and 3LD registrations under the same TLD is a bit of a nightmare in terms of public-suffix list [0], which is kind of important thing when enrolling your domain for some services, cloudflare among them. [0] https://publicsuffix.org/ https://publicsuffix.org/
- altairprime 1mo agoYeah, that’s why RFC 9989 replaced use of PSL with a dns signifier.
- wlonkly 1mo ago(That's DMARC, to save others the trouble.) The problem DMARC solves is different than the problem the PSL solves, though. DMARC prevents a 3LD from pretending to be a different 3LD on the same 2LD. But the PSL handles things like what it means to make a "cross-site request" or how to handle cookies. I mean now I'm thinking if DMARC _could_ solve that... but I don't think it could, unless I'm missing some extension or rare use case.
- altairprime 1mo agoYes, DMARC isn't solving the same problem — but DMARC is showing how the category of PSL problems can be solved with DNS. With HTTP/3 now fully expecting browsers to be able to benefit from transparent-upgrade record responses, i.e. `www IN HTTPS 1 . alpn="h3,h2"`, then it is possible for the style of solution shown by DMARC to be applied to other problems that PSL solves today. CAA isn't a good fit as-is either, because the subdomain has top precedence over the parent domain — precisely the inverse relationship needed here. But having worked with the PSL for quite some time operationally and seeing the direction of trends away from it and towards structural DNS declarations rather than a centralized list, I think the 3LD-2LD-CRSF problem would be far better off solved with DNS than PSL. Basically, just adding `co.uk. IN TLD subs=independent` as an SVCB record would fully deprecate the need for the PSL versus cross-site and other such ownership-changes-hands boundary problems with both A.co.uk being allowed cross-site with B.co.uk, and with co.uk being treated as equivalent to B.co.uk by password managers, cookie repositories, and so on. It would also benefit CAA by defining whether the boundary exists — if TLS is hosted by the provider, then any CAA records published by the subdomain should be disregarded; if the subdomains are fully independent, then any CAA records published by the parent should be disregarded — which simply isn't possible today without either referring to the PSL or implementing DMARC-style DNS solutions. (I don't formally suggest that exact record as structured or written but it's sufficient a napkin sketch of what I mean by gesturing at that RFC to be considered.)
- DrewADesign 1mo agoIn the tech industry of yore, corporations having tech ecosystem stewardship duties was a quaint necessary evil to placate the developer crowd so you could hire them. Today, c-suites consider that indulgent soft-hearted hippie nonsense utterly gauche.
- gblargg 1mo agoIt seems insane because it seems like a big point was to have a permanent site for your name. This just devalues all domain names, showing that they can do a rug-pull at any time because they don't want to manage it (how about turn it over to a private company that can adjust costs so they can make a profit and keep it running?).
- asdfsa32 1mo agoThis is why new gTLDs are insane and stupid. It is about time there is some _yours for life_ DNS system. In this age, allowing domain names to be owned by other entities is almost like allowing a company business registration number or one's national id card number to be transferred to others. I think name squatting is a problem, but it is not like that current system has solved it.
- simiones 1mo agoDNS names are never permanent, they are in fact extremely im-permanent, always requiring periodic re-registration (though, to be fair, with pre-emption rights, so you have some guarantee of keeping your registration if you don't forget).