| ▲ | edent 3 days ago | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I have some experience of dealing with this when working for .gov.uk A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims. By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists. At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned? I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | tremon 3 days ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
On the other hand, I struggle to think of a reason how harm could come from delayed activation of a registered public name. Can you describe a use case that cannot be solved by opting for a subdomain of an already-existing domain? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | FromOmelas 3 days ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
How would you decide what is legitimate ? Better would be a "this site is suspiciously new" warning in browsers. At $WORK, newly registered sites are blocked by default by the network appliance. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | BLKNSLVR 3 days ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
What legitimate users need something provisioned so quickly on no/short notice. One of those "a lack of planning on your part does not constitute an emergency on my part" situations. There could always be special dispensation for known entities to break the rules, if they've got an existing relationship / agreement (which essentially means they've already done the necessary KYC). | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | TLDRisk 3 days ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
> At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned? I'd say "legitimate objections" is doing a lot of heavy lifting there and I don't like the idea. Having the time and resources to monitor registrations becomes a barrier and that makes it a time and resource based system. IE: Rich individuals and companies can pay a monitoring service that objects very broadly. I've always been frustrated by systems like that and it seems like a lot of the tech industry is set up that way. I've had my personal, family name, 25 year old domain put on Google's safe browsing block list and being the collateral damage in a hugely scaled system isn't fun. Spending the time and resources needed to deal with it are far more of a burden for me than for a big company. I was able to get it removed, but why should I be forced to pay for their mistake? Ultimately though, any system is going to cost money no matter how it's structured. If you're not paying directly, you're spending time or resources of some kind. I'd rather pay directly because it's easier to understand. I don't think you can build an all or none system for handling abuse because so much of it is subjective. Even using what's legal vs illegal is difficult because a global system is going to have contradictions. Online gambling is a good example. Some countries would want the related domains banned for being illegal while others don't have a problem with it. Domains are one of the core building blocks that makes a decentralized internet work. Adding strong moderation tools to that is a huge risk because moderation and censorship are closely related. Who determines what's trustworthy or legitimate or abuse or anything else? What happens if a newly appointed authority claims transparency will enable bad actors? Highly transparent systems with independent trust ranking make the most sense to me. Any solutions need to be opt-in, or, at the very least, opt-out. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||