Remix.run Logo
edent 3 days ago

I have some experience of dealing with this when working for .gov.uk

A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims.

By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists.

At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?

I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless.

tremon 3 days ago | parent | next [-]

On the other hand, I struggle to think of a reason how harm could come from delayed activation of a registered public name. Can you describe a use case that cannot be solved by opting for a subdomain of an already-existing domain?

edent 3 days ago | parent [-]

England have just scored the winning goal in the world cup and I want to celebrate by launching my personal tribute on Lionesses.rock

Why shouldn't that go live instantly?

A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.

I've had a brilliant idea for an eCommerce website but it is 1705 on a Friday night and, because no one works weekends, I have to wait until next week before the domain is agreed.

I agree that there's no great harm in having to wait a day, or a week, for registration to complete. But in a world of instant gratification, it feels old fashioned.

skrebbel 3 days ago | parent | next [-]

None of these require a domain to work. There’s plenty precedent of things taking off without having a domain, eg Wordle, all Neal.fun sites, Hacker News, and I’m probably forgetting a few obvious ones.

I know that “mystupidvibecodedidea.com” is all the rage but nobody cares if that’s instead on yourname.com/mystupidvibecoded idea except you.

edoceo 3 days ago | parent | next [-]

Back in the day (~2003) it was popular to get a domain name for every project. Loads of people I knew where holding a domain name for every idea they had. I even had a few (~40). But in like 2008 I think I switched over to using just sub-domains of my primary. If anything took off I could then find and buy the cool name. And if it dies (likely outcome) I've saved $30.

dasyatidprime 3 days ago | parent [-]

My impression is that one of the social effects of domain names being cheap and easy to get (at least among many vaguely technologist-adjacent cohorts) is that failing to invest in a 2LD for a new thing winds up seen as tacky, sort of an “if you weren't willing to invest enough to put a cover on it then what does that mean for whether it's any good” thing (you could see it as a counterparty good-faith deposit versus attentional costs if you like). In some cases this goes down to the level of individual publications. Additionally the way social technology has wound up around URLs seems to mean that both longer URLs and artificially shortened ones wind up losing secondary reach in unpredictable ways. I'm not that fond of this trend but I can see ways it winds up making sense in context. I don't know how widespread it is.

edent 3 days ago | parent | prev [-]

OK, so I have a legitimate domain. I can add any subdomain I want without recourse.

projects.example.com or new.cool.thing.example.com

So nothing stops me from registering a legitimate domain, using it for a bit, then launching the subdomain `pay-your-tax.gov.uk.official.example.com`

It must be legit - it has the .gov.uk in it!

IAmBroom 3 days ago | parent | prev | next [-]

In the world of spammers with zero accountability, it seems needed.

cucumber3732842 3 days ago | parent | prev | next [-]

>A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.

More likely:

Some flavor of shit has hit the fan. I need to register some viable short and to the point domain names to get the word out faster than BigCo or the government and their army of lawyers can buy those domains.

Would we have stuff like DeFlock if there was an objection period?

What about if some advocacy firm was trying to create a website for people harmed by a drug. The drug company would just object to all their attempted registrations and bog them down.

amluto 3 days ago | parent [-]

A delay doesn’t even really hurt this use case. The first person to register the domain would still get it, 24 hours later, unless there’s an actual objection.

edent 3 days ago | parent | next [-]

I think the "actual objection" is the hardest part.

The UK Government might legitimately object to the registration of `dwpgov-uk-payments.pizza` but should they be allowed to object to `dwp-gov-uk-stole-my-payments.fart`?

One might be obviously dodgy, the other is someone ranting about their experience. Do you think Governments should be able to object to domains complaining about them?

amluto 3 days ago | parent [-]

I'm not entirely sure. But we have have mechanisms like Google Safe Browsing, and I can imagine that a similar mechanism could be used. Or there could even be a new classification in Safe Browsing and similar databases for newly registered domains that look like they are misleaing, and this could actually be fast enough if there was a 24-hour hold on new domains.

cucumber3732842 3 days ago | parent | prev [-]

Who defines "actual objection"? The entrenched interests are really good at tilting such processes in their favor.

pessimizer 3 days ago | parent [-]

A delay wouldn't change that. You're talking about the difference of the site being up for a half day or not at all, which is admittedly infinity times longer, but not enough to make any sort of difference (as opposed to putting the anti-entrenched interests info up without its own domain name.)

BLKNSLVR 3 days ago | parent | prev [-]

... and nothing of value was lost

FromOmelas 3 days ago | parent | prev | next [-]

How would you decide what is legitimate ?

Better would be a "this site is suspiciously new" warning in browsers.

At $WORK, newly registered sites are blocked by default by the network appliance.

BLKNSLVR 3 days ago | parent | prev | next [-]

What legitimate users need something provisioned so quickly on no/short notice.

One of those "a lack of planning on your part does not constitute an emergency on my part" situations.

There could always be special dispensation for known entities to break the rules, if they've got an existing relationship / agreement (which essentially means they've already done the necessary KYC).

TLDRisk 3 days ago | parent | prev [-]

> At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?

I'd say "legitimate objections" is doing a lot of heavy lifting there and I don't like the idea. Having the time and resources to monitor registrations becomes a barrier and that makes it a time and resource based system. IE: Rich individuals and companies can pay a monitoring service that objects very broadly.

I've always been frustrated by systems like that and it seems like a lot of the tech industry is set up that way. I've had my personal, family name, 25 year old domain put on Google's safe browsing block list and being the collateral damage in a hugely scaled system isn't fun. Spending the time and resources needed to deal with it are far more of a burden for me than for a big company. I was able to get it removed, but why should I be forced to pay for their mistake?

Ultimately though, any system is going to cost money no matter how it's structured. If you're not paying directly, you're spending time or resources of some kind. I'd rather pay directly because it's easier to understand.

I don't think you can build an all or none system for handling abuse because so much of it is subjective. Even using what's legal vs illegal is difficult because a global system is going to have contradictions. Online gambling is a good example. Some countries would want the related domains banned for being illegal while others don't have a problem with it.

Domains are one of the core building blocks that makes a decentralized internet work. Adding strong moderation tools to that is a huge risk because moderation and censorship are closely related. Who determines what's trustworthy or legitimate or abuse or anything else? What happens if a newly appointed authority claims transparency will enable bad actors?

Highly transparent systems with independent trust ranking make the most sense to me. Any solutions need to be opt-in, or, at the very least, opt-out.