← Back to context

Comment by wormius

15 hours ago

There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level.

But I didn't think about the 1st level competitors. There'd still need a mechanism to resolve that...

1. First come first serve? (e.g. whoever registered a y.name first, whether x is bob or sue is determined by the earliest registrant on record) 2. Lottery/random selection? 3. Bidding war?

I think the problem is 2nd level domains who have the same name will be a problem when they find out all these other 3rd level are now expiring and can run a route to spoof? Likely wouldn't happen, but with the fuckery in the DNS that can happen... This is such a rash and weird decision to push through so quickly just because engineers find it "easier" while ignoring the implications of the move, seemingly when it comes to larger scale security.

I assume there would have to be some method to prevent routing of third level domains to subdomains of two-levels... (or is that just me being a fool yet again, assuming we have competent administration of our systems).

fraser.name does not seem to be currently registered, so it seems they could automatically give him that name, and hence solve the problem entirely.

But I wonder if there might be some competing names on the third level? Like, he's neil.fraser.name, but what if there's also bob.fraser.name and they'd both very much like to keep their domains?

  • I think the point is that currently if anyone.fraser.name is registered, then fraser.name cannot be registered.

    The change that Verisign is making is to deregister all the *.fraser.name domain registrations, which will then free up fraser.name for registration.

    So it becomes a race to register fraser.name and the winner gets to recreate all the *.fraser.name subdomains they want, for whatever purpose they want.

> There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level.

Yes. I've been asking VeriSign for this for years, and they always refused.

Or just honor the deal. The only reason for doing this is Verisign’s bottom line.