2 ms·
This risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices
by nanolith 1mo ago
This risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices used were entirely disconnected from domain names, and why the discovery protocol I put together did not rely on registered domains, but could use these as an untrusted part of discovery.
Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.
I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.
I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.
- fh67 1mo agoCan you share how the discovery worked?
- ACCount37 1mo ago"Online identity" seems like a castle built on quicksand in every single case. What's your account tied to? E-mail? That's usually on a mail server owned by someone else. If not, it's still on a domain owned by someone else. Phone number? Definitely owned by someone else. The only account that's reliably "yours" is one that asks for a login, a password, maybe a TOTP, and absolutely nothing else. Because everything else is introducing "things owned by a third party" into the equation.
- remuskaos 29d agoYou've hit the nail on the head. That's why I strongly preferred email and password login, backed by a keepass(xc) store to hold the data. Owned by me, backed up, impossible to take from me, the works. Sure, most of the time I have to verify my mail address, but after that the account is mine. Well, okay. On some services, I have to "confirm the new device" I'm loggin in from, so I still need access to my mail. Weeeell... Some services I use seem to have switched to a magic link EVERY TIME for login. No password anymore at all. And all of a sudden, my mail account is the single point of compromise for these accounts. And there is absolutely nothing that I can do. If the mail is hosted by someone else, they may terminate my account at a whim. Or give it to someone else who happens to have convinced my phone provider to hand them a sim card with my number on it. If I do self host I still need a domain, and I can never really own a domain, only rent it from somewhere. So, whenever that lease goes up, my account is compromised by default. I really hate that this problem seems still unsolvable. Keybase had the right idea, but no one used it and they got aquihired by zoom during the pandemic...
- sciyoshi 1mo agoIt's the same reason I was nervous moving our company domain to a .ai TLD; your entire presence, identity and trust is now beholden to the whims and political winds of a Caribbean island smaller than Topeka.
- paholg 1mo agoIt's a real risk. The British Indian Ocean Territory is going away, and by ICANN's rules, that means .io should as well.
- gwillen 29d agoIt's not anymore: "in April 2026 the implementation of the agreement was put on an indefinite hold due to opposition from US President Donald Trump." So whatever ICANN was going to do with .io, it's all on hold for now.