Remix.run Logo
greyface- 3 hours ago

https://hccf.onmy.cloud/wp-content/uploads/2026/06/dot-self....

> Everyone entitled to a subdomain at no cost

How are you going to pay for the (substantial) cost of running a TLD without registration fee revenue? Is this a loss leader for other services? Are you operating on a 100% donation model?

> No parking, squatting, or reselling

How do you plan to tell the difference between a parked/squatted domain and one in legitimate use but offering no public-facing services?

HumanCCF 3 hours ago | parent | next [-]

> How are you going to pay for the (substantial) cost of running a TLD without registration fee revenue? Is this a loss leader for other services? Are you operating on a 100% donation model?

We plan on operating the domain as a public good and are actively seeking sponsors to help fund us. Think of it as a similar model to ISRG and LetsEncrypt.

> No parking, squatting, or reselling

Our rule of one person per subdomain will hopefully prevent this at scale, though it will admittedly be more difficult to examine any particular domain so closely. We may have to implement some type of heartbeat where the owner of said domain has to respond within a certain amount of time.

SahAssar 3 hours ago | parent | next [-]

> Think of it as a similar model to ISRG and LetsEncrypt.

In that case it was started by an institution (mozilla) with a lot of heft in the area (mozilla's CA program is one of the most broadly used) and was backed by other orgs (google) that had a vested interest in it's success. I'd be interested to hear which potential sponsors you see in a similar situation here?

> rule of one person per subdomain

What is the plan to (without costly overhead or cost to the end user) validate who is an actual person? Even large corporations with loads of resources have problems with this without resorting to treating it as if a person equals a credit card number.

HumanCCF 2 hours ago | parent [-]

> In that case it was started by an institution (mozilla) with a lot of heft in the area (mozilla's CA program is one of the most broadly used) and was backed by other orgs (google) that had a vested interest in it's success. I'd be interested to hear which potential sponsors you see in a similar situation here?

We are reaching out to companies who operate in the self-hosted space, academia, ISPs, registars, as well as digital rights orgs. We believe they would be aligned with this mission and ultimately benefit from such a TLD existing!

> What is the plan to (without costly overhead or cost to the end user) validate who is an actual person? Even large corporations with loads of resources have problems with this without resorting to treating it as if a person equals a credit card number.

There are a few emerging technologies we are evaluating to help with this but have not settled on one just yet. Whatever we choose, we will start small and go from there. Worst-case scenario, we start with the credit card approach and iterate. This will ultimately all be a part of the evaluation process we go through with ICANN.

SahAssar an hour ago | parent | next [-]

To be honest it feels like these answers boil down to "we feel it'd be nice if this existed but we have no actual answers as to how to get it done".

---

To stick with your comparison: when letsencrypt and ISRG launched they had actual answers for how to deal with the hard challenges in their space:

A) how to get included in a trust roots (crossigning with IdenTrust at first and the knowledge and expertise of how to get included in the longer term)

B) Automated domain validation in a standardized way (ACME)

C) Long term commitments of sponsorships to ensure people could trust it would stick around

---

I wish you the best of luck, but I think this might have needed to bake a bit longer before publicizing.

DonHopkins 2 hours ago | parent | prev [-]

You need to find a benevolent selfless soul who will sponsor you.

al_borland 3 hours ago | parent | prev [-]

How is one person per subdomain enforceable? How is a person uniquely identified and tracked?

dom96 3 hours ago | parent [-]

My guess is by using ID verification similar to how I do it on https://onlyhumanhub.com/

kokanee 2 hours ago | parent | next [-]

I'm curious about how this works, but it doesn't look like I can find out without creating an account. I see that it says "Link your existing social accounts to prove you're not a bot." How does having social media accounts prove I'm not a bot?

SahAssar 2 hours ago | parent | prev | next [-]

So you have just built a wrapper around https://passportreader.app/, which itself is reading NFC enabled ID/passports from specific countries. The coverage map is here: https://passportreader.app/coverage.

Might be good to know that even in the US this approach would only work for ~50% of people, since a lot of people don't have passports. In most countries this does not work at all, since they don't issue NFC enabled ID/passports.

teraflop 36 minutes ago | parent [-]

The "how it works" page for that website says that the ID data is "digitally signed by the issuing government". But there doesn't seem to be anything in the docs about how to get or verify that signature. So it seems like they are just asking users to trust them to do the verification.

2 hours ago | parent | prev [-]
[deleted]
AnthonyMouse 2 hours ago | parent | prev | next [-]

> How are you going to pay for the (substantial) cost of running a TLD without registration fee revenue?

Is it actually a substantial expense? The TLD itself only has to publish the nameserver records, which generally have a TTL of about a day. A DNS response is a few hundred bytes. Big DNS providers like Google and Cloudflare would make requests for every actively used domain every day, but then cache them. Smaller providers wouldn't cache as well but also wouldn't each request every domain every day. For e.g. a million personal domains, ballpark estimate is somewhere in the few TB a month of traffic. Maybe a little over personal hobby project money but definitely not outrageous for a small non-profit organization.

> How do you plan to tell the difference between a parked/squatted domain and one in legitimate use but offering no public-facing services?

This is the easy one. Squatters buy domains because they want to sell them. To sell them they have to make it publicly known to prospective buyers that the domain is available for sale. So then if anyone lists the domain for sale anywhere, you make them prove that they own it (which any actual buyer would also have to do in order to not get scammed) and when they do the domain is forfeit.

It's kind of sad that we don't do that for all domains. Domain squatters can go to hell.

greyface- 2 hours ago | parent | next [-]

Much of the cost here comes from compliance with the ICANN gTLD program structure, not from running the underlying technical infrastructure (which is not limited to DNS - you also need EPP/RDAP/etc). See https://www.icann.org/en/registry-agreements for (hundred+ page) documents outlining registry responsibilities. Registries can outsource some of this to an ICANN-accredited "registry service provider", but should expect to pay upwards of hundreds of thousands of dollars yearly for the privilege.

madsushi 2 hours ago | parent | prev [-]

It costs ~$200,000 to apply for a TLD, and there's an ongoing renewal cost in the tens of thousands of USD.

HumanCCF 2 hours ago | parent | next [-]

For this application round, ICANN is running an Applicant Support Program, or ASP. The applicants seeking to apply for a TLD this round who qualify for the ASP will have a substantially reduced application fee, among other benefits. Our organization is one such org who has qualified for the ASP so we will not have to pay the full $227,000 application fee.

KomoD 12 minutes ago | parent [-]

How much is the reduced fee then? As I understand it's somewhere between 75%-85% less, which is still a lot of money.

Also, who is paying for the reduced fee, administrative and infra costs? And have you actually submitted gTLD application, or are you trying to crowdfund? Unclear to me.

AnthonyMouse 2 hours ago | parent | prev [-]

That's definitely not a cartel then.

pavel_lishin 3 hours ago | parent | prev | next [-]

It's not clear whether they're actually talking about domains or subdomains there, which is a worrying sign from a potential registrar.

favorited 3 hours ago | parent [-]

Any domain that isn't one of the Top Level Domains is also a subdomain.

maximilianthe1 an hour ago | parent [-]

Isn't the actual top level domain an empty one after TLD? Looking like «.com.» with trailing dot

prepend 2 hours ago | parent | prev | next [-]

Is it really that expensive to run a TLD? Name servers are notoriously long running on ancient spec servers.

I’m guessing, if designed well, the registration process could run on lightweight infrastructure. Maybe $1-5k total per year, not counting time. So it’s enough for a fun hobby project.

psychoslave 2 hours ago | parent | prev [-]

Might be a public service? I guess many countries already had such a thing with running cost several order higher than such a thing as a TLD, operating for centuries now.