Comment by nneonneo
16 hours ago
It seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3LD registered on top). It’s a bit insane that they can decide to just terminate all existing 3LD registrations. One would hope that they’d at least continue to reserve the 2LDs for some period to avoid domain squatting, but this isn’t mentioned in the proposal and I doubt Verisign would graciously do so.
Another thing that should be obvious and yet they refuse to do: when there is a single third-level customer for a given second-level, offer them a way to get the second level domain. I've been asking VeriSign this for 15+ years, they always said no, even if at some point they confirmed that there were no other third-level than mine under that second-level domain. They're insane and should not be in charge.
> They're insane and should not be in charge.
I remember back when we had to write mechanize scripts to drive a browser through the renewal process, because if you had dozens, hundreds, or thousands of domains there was no nonmanual way, especially if you wanted extended verification or something silly like that.
So what I'm saying is, agreed and that has always been true.
That actually sounds like a good thing. Why are you hording hundreds or thousands of domains?
1 reply →
Why would they want to drop the possibility of selling some as premium domains? If they have their shells setup right they will probably be able to get a premium from some 3rd level domain owners wrongly afraid someone else is interested.
The main problem with the Internet today is that we didn't destroy ICANN when they started this TLD sell off crap. A replacement institution may have at least told Verisign a TLD they can't run transfer to someone who can meet its promises can only be destroyed.
The .name predates the TLD well-off crap. The first huge bulk of new TLDs happened in 2014, .name dates back from 2001, just like .info or .coop.
Also, .name filled an actual need for general non ccTLD: companies had .com, organizations had .org, Internet related stuff had .net, there was .gov, .edu, .mil, and ccTLDs, but nothing made for individuals. It filled this use case, it actually made sense.
Because it's not worth it financially. After icann is the tld registrar, and after that above. So, if anyone is destroying it, it's not the registrar, it's the tld.
It seems insane because it seems like a big point was to have a permanent site for your name. This just devalues all domain names, showing that they can do a rug-pull at any time because they don't want to manage it (how about turn it over to a private company that can adjust costs so they can make a profit and keep it running?).
This is why new gTLDs are insane and stupid. It is about time there is some _yours for life_ DNS system.
In this age, allowing domain names to be owned by other entities is almost like allowing a company business registration number or one's national id card number to be transferred to others.
I think name squatting is a problem, but it is not like that current system has solved it.
Squatting is purely a result of being able to resell domains.
Maybe they want to avoid the ambiguity between john.doe.name versus john-doe.name, and I assume they prefer the latter scheme because it probably sells better. Nevertheless, discontinuing existing domains is disgraceful.
Even that doesn't pass basic scrutiny. The same ambiguity can and always will exist with tim-apple.com and tim.apple.com - there's nothing here that needs fixing.
I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real.
It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com
In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com
edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule
40 replies →
True, they can’t outright prevent the ambiguity, but much fewer people will go to the trouble of establishing such subdomains when the option isn’t directly offered by the registrar.
This is my theory because, a priori, 3LDs should be more profitable than 2LDs, because with 3LDs John Doe and Jane Doe don’t have to compete over doe.name, but instead can each separately purchase john.doe.name and jane.doe.name. Apparently, however, that’s not a benefit of 3LDs in practice, which leads me to conclude that john-doe.name and jane-doe.name just sell better.
4 replies →
It's exceedingly charitable of you to try to infer a good reason for what they're proposing. I say "exceedingly" because in their proposal they had the opportunity to present a good reason, and they chose not to use that opportunity.
Was it even possible to register just a second level .name domain name? It sounds like it wasn't, so therefore no one would be using john-doe.name and there'd be no ambiguity.
Not at the very beginning, but then it became possible.
Yes it has been. I have had a second level .name for 20 years.
It was, I have one.
> the right thing they should do
Can someone explain why a product "registered and paid for until 2040" can be unilaterally voided like this without compensation?
Especially when the marketing was saying [1]:
> As your .name can be registered for up to 10 years and ownership is renewable, your .name really can be yours for life.
It seemed like there was an offer of renewable registration at least for a life term.
[1] https://web.archive.org/web/20020609132126/http://nic.name/c...
And lets be clear here, refunding the registration fees should NOT be considered even close to sufficient compensation as Neil and others like him have reasonable assumed they would control the name for that time and made choices that depend on that.
That's the crazy part - they can take your money, prorated to some future-period but, upon cancellation, the remaining future period of YOUR money becomes THEIR immediate revenue recognition. Is it fraud or theft? To me, it has to be one or the other...
Because they haven’t been sued enough yet?
ICANN should not approve such an obviously fraudulent move even without anyone being sued. Neither should Verisign even consider that they'll be able to get away with it. If you need to sue for this something else is already very wrong with the system.
I'm surprised they don't just do that, and maybe even to go a little further, disallow renewals so you can phase people out and reclaim domains you can sell.
Whether disallowing renewals or terminating them tomorrow, there's still the same core problems, only the date of the offense changes: (1) seizing people's names that they've established, breaking innumerable things including email and server hostnames, and (2) the possible resale of the 2LD fraser.com to a third party who will be free to do malicious things like reading OP's email, redirecting his traffic, or extorting him, to sell continued access at any price demanded.
There's one less core problem: those who just bought/renewed their domain e.g. yesterday are fucked out of both their money and forced to migrate sooner than they could have reasonably planned for. People's who registrations expire and they are unable to renew is a very different level of unfairness and inconvenience.
In either case, the security concern should be directly addressed.
1 reply →
Having a mix of both 2LD and 3LD registrations under the same TLD is a bit of a nightmare in terms of public-suffix list [0], which is kind of important thing when enrolling your domain for some services, cloudflare among them.
[0] https://publicsuffix.org/
The PSL is a giant hack that gives the PSL maintainers authority over something that should be a hierarchical delegation. It's an affront to the DNS system and should not be considered to have any relevance by ICANN or any standards bodies.
Yeah, that’s why RFC 9989 replaced use of PSL with a dns signifier.
(That's DMARC, to save others the trouble.)
The problem DMARC solves is different than the problem the PSL solves, though. DMARC prevents a 3LD from pretending to be a different 3LD on the same 2LD. But the PSL handles things like what it means to make a "cross-site request" or how to handle cookies.
I mean now I'm thinking if DMARC _could_ solve that... but I don't think it could, unless I'm missing some extension or rare use case.
1 reply →
That would be so cool and would make these limited hot commodities.
.name was one of the very first expansions of gTLDs back in the very early 2000s. It's a shame that it's being shut down as it was spearheaded by the ICANN itself rather than some registrar / investor like Donuts, Inc.
I suppose this is impractical as someone has to run the registry and there are costs associated with that. But don't the domain fees cover it?
From having worked in that space what feels another lifetime ago, I vaguely recall that you can just offload the registry work to a registry that would manage this together with a mountain of other TLDs.
Yes, that's what Verisign does here - they also host many of the other big generic TLDs like .com.
As I recall it. This was mostly a money scam that targeted private users with ads like "make sure to claim to your .name domain so no one else does it and use it to impersonate you". It was stupid from the beginning and never took off.
In the tech industry of yore, corporations having tech ecosystem stewardship duties was a quaint necessary evil to placate the developer crowd so you could hire them. Today, c-suites consider that indulgent soft-hearted hippie nonsense utterly gauche.