Remix.run Logo
akersten 3 hours ago

It kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.).

Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?

SahAssar 3 hours ago | parent | next [-]

.co.uk is run by the same people as .uk. There is no additional org that you trust when you register a .co.uk: https://en.wikipedia.org/wiki/.uk#Second-level_domains

> do browsers have a wildcard suffix list

Yes: https://publicsuffix.org/ and they have discussed this situation here: https://github.com/publicsuffix/list/issues/2306

akersten 2 hours ago | parent | next [-]

I know about the public suffix list - I was wondering about the wildcard specifically. In the very issue you linked to, as of 2025, it seems this was still unresolved...:

> We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't.

xg15 an hour ago | parent | next [-]

Yeah, apparently they both (used to) offer unbounded registrations of 3LDs and unbounded registrations of 2LDs? So if I see j.doe.name, the only way to find out if "doe.name" is a public suffix or not, i.e. if I should (not) be able to set a cookie on it, would be to email the registrar?

So does that mean that in practice, .name domains were always treated by browsers like regular 2LDs, meaning the cookie and origin protection was always broken for those domains?

Doesn't sound like good news for the guy in the OP...

SahAssar 2 hours ago | parent | prev [-]

I'm just saying that they have discussed the situation. They seem to have no answer and for cookies and similar things the answer probably is "maybe don't run security critical web stuff in the third level under .name".

IIRC orgs like letsencrypt also use the PSL for rate limits, so there are probably more issues that are not browser-based.

eloisant 2 hours ago | parent | prev [-]

Yes, Japan does the same with .co.jp but also .ne.jp, ac.jp, etc.

adw an hour ago | parent [-]

There are many examples; k12.<state>.us is another.

eloisant 8 minutes ago | parent | next [-]

Except nobody uses the .us tld, but pretty much every every Japanese company is on a .co.jp

marcosdumay an hour ago | parent | prev [-]

It is (or was for a long time, IDK) a strongly recommended practice from ICANN. I imagine nearly all countries to do that.

dhosek 24 minutes ago | parent [-]

There end up being some weird edge cases where there are some countries which have both the equivalent of .co.uk but also allow registrations directly under the two-letter country code as well. .mx is one such case where most business are, e.g., costco.com.mx, but it’s also possible to register directly under .mx as well so Toyota Mexico is toyota.mx and not toyota.com.mx (the latter is registered, and ostensibly to Toyota, but the whois and nslookup records give very different results and the website doesn’t load when I try to visit it).

nneonneo 2 hours ago | parent | prev | next [-]

Since neither smith.name nor the wildcard *.name appear in the Public Suffix List (https://publicsuffix.org/), browsers would likely allow any page on a *.smith.name domain to set cookies for .smith.name.

There was an effort to properly handle the .name 2LDs, but it was never resolved because there’s no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name: https://github.com/publicsuffix/list/issues/2306

So yes, this TLD’s setup is in fact pretty insane.

rwmj 2 hours ago | parent | next [-]

I think this says more about how the cookies security model is stupid. They should always have been scoped to the single, exact name they were set from and nothing else. Websites would have had to be designed a bit more thoughtfully.

xp84 24 minutes ago | parent | next [-]

It seems like it would be easily resolvable with TXT records these days. Anyone could try, say, on www.google.com to set a cookie for all of google.com, and the browser can fetch TXT records on google.com to see what, if any subdomains, it wants to allow this privilege for. Google could return a list or a wildcard; co.uk wouldn't allow any.

In a world without advertising, there's no reason why google.com couldn't also allow *.youtube.com to set cookies for it, but of course that would cause a tremendous privacy freakout. Though in practice they can and do just send every login/logout through a 302 redirect roundtrip to take care of the cookies on youtube.com.

lxgr an hour ago | parent | prev [-]

It’s not nearly just cookies, and I think interpreting domain hierarchies as administrative structure generally does make sense.

Maybe it could be opt-in or opt-out via some markers at the DNS level, though? The public suffix list having to exist at all is bizarre.

amluto an hour ago | parent | next [-]

An “administrative structure” seems fine, but the fact that a subdomain gets any sort of privilege over the parent has always seemed absurd to me.

Surely a better solution would involve an actual request. login.foo.com could send a request to foo.com with Origin: login.foo.com asking to set a cookie, and foo.com could make its own decision.

markhahn an hour ago | parent | prev [-]

that seems strange to me: why shouldn't policy leverage name resolution? sort of like dkim, but taken further. for instance, for site.com, I'd much rather retrieve its public key from DNS (some DNS++ version, of course).

markhahn an hour ago | parent | prev | next [-]

I'm always mystified why we haven't leveraged DNS.

I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP.

Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...

quotemstr 2 hours ago | parent | prev [-]

> no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name

And that's one reason why the public-ness of a hierarchy level belongs on a DNS record on that level and not some separately-distributed side list.

indymike 30 minutes ago | parent | prev | next [-]

> It kind of seems like an insane TLD structure to begin with, right?

It's been around for years. I seem to remember this issue coming up around 2001 where originally .name was for third level registration (i.e. john.doe.name) and changed to second level it a few years later and caused some problems... https://publicsuffix.org/ talks about it in light of architectural limitations of domain names.

> can Joe set a cookie on all of .smith.name?

That can happen. I seem to remember ancient browsers made it so .name (and other non-generic TLDs) required three periods. I think country code domains and new generic TLDS caused the browsers to change it.

It's pretty screwed up, but a lot of the people with .name domains have had them for a very long time. Sad to see them all lose their identity online that way.

OkayPhysicist 2 hours ago | parent | prev | next [-]

So, this kind of thing happens all the time, and there's the Public Suffix List for exactly this problem.

There would be no issue at all if Verisign, or maybe Global Name Registry, decided to stick to the 3rd level registrations exclusively. Problem is, the chucklefucks over there decided it was a good idea to also hand out 2nd level registrations. Those 2nd level registrations outnumber the 3rd level registrations by an order of magnitude, so the PSL decided to just let joe.smith.name and john.smith.name share cookies. Which, IMO, was not a good decision, but it is what it is.

orra 3 hours ago | parent | prev | next [-]

Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.

traceroute66 2 hours ago | parent [-]

> Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.

Yup. The original statement was dangerous FUD which should be urgently corrected.

BHSPitMonkey an hour ago | parent [-]

Yes, but you have to admit that the existence of these SLDs (like co.uk) is always going to be a point of confusion for anyone with a basic knowledge of how the domain hierarchy _usually_ works.

Needing to be familiar with all the special cases (like the VERY special case of x.y.name which I previously knew nothing about) kind of ruins everything and introduces yet more security risk.

traceroute66 40 minutes ago | parent [-]

> but you have to admit that the existence of these SLDs (like co.uk)

I'm sorry, what ? Admit ? Confusion ?

In the case of .co.uk it has been around since 1996. HN is a technical forum, most people here should be well aware it is a serious SLD. I honestly can't believe it even needs clarifying.

Hell, if you use AWS Route 53 you'll see they use co.uk as one of their nameserver suffixes[1].

[1] https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/SO...

omnibrain 2 hours ago | parent | prev | next [-]

About 20 year ago I registered {lastname}.name and have dozens third level domains below it. So there are "privately owned" second level domains under .name for quite some time...

Pxtl 2 hours ago | parent [-]

I'm working on same for my family since I want to properly degoogle a bit. One thing I think long term - if I give my kids first-name @ last name , that means that I forever hold power over their email. Which isn't great. But what's the alternative? Register one full domain name per kid? Even ignoring the cost, the ergonomics are awful.

Imho email is missing a feature for nameless email addresses for when somebody just buys their full name as a domain name. If I get "firstname-lastname.name", having the email be "firstname@firstname-lastname.name' kinda ruins it.

skinfaxi 2 hours ago | parent | next [-]

From what I can tell most people do something like me@myname.whatever or hi@domain.

2 hours ago | parent [-]
[deleted]
kennywinker an hour ago | parent | prev | next [-]

Not to mention some of those kids may end up changing their names at some point if they get married and decide to take their partner’s last name.

Pxtl 19 minutes ago | parent [-]

Aside: I'm honestly bewildered that Google doesn't have the ability to handle that in gmail accounts. If somebody gets married or otherwise needs to change their name, their answer is "just make a new google account" when all your stuff is still tied to the old account.

londons_explore an hour ago | parent | prev [-]

A child born today sees email like we see the telegraph...

they'll grumpily sign up to gmail just so they can get a verification email, and that'll be all it gets used for. Messaging their irl friends will be done in apps like Discord.

peezd an hour ago | parent [-]

Truth.

lol I ran a sizeable team around 2020 and I had to educate a couple of our new hires straight from college that they actually needed to check their work email, after they missed important HR related stuff and they had just completely not realized it was an avenue for company communication, with an assumption that everything was available on our heavily used slack.

xp84 15 minutes ago | parent [-]

tbh I'm with the zoomers on this one. Work email is 99% junk. Newsletters from every SaaS product we use, "A meeting started", invitations for calendar events that I can just accept ON the calendar, notifications for every transaction on every system ("X posted a comment on Y,") and spam from salespeople, recruiters, etc. And then 1% of it is actionable important stuff that I don't get through Slack.

londons_explore 6 minutes ago | parent [-]

Email died because of the junk/spam issue. And it's self-fulfilling - when most emails are junk, nobody sends a love-letter or party invitation by email because the recipient probably won't notice it, which in turn lowers the usefulness even further.

If email was a commercial product, the company would have done something about that. Email died because it was an open platform, with nobody to address this systematic issue.

CodesInChaos 3 hours ago | parent | prev | next [-]

Surprisingly the public suffix list doesn't list `*.name`. So they're indeed not properly isolated from each other.

https://publicsuffix.org/

edit: apparently not all second level domains in .name are public suffixes anymore, so a wildcard addition wouldn't be correct.

gpvos 2 hours ago | parent [-]

It wouldn't surprise me if that is (maybe even a large) part of the reason for this change.

xp84 10 minutes ago | parent [-]

What does Verisign care though? It's been that way for way over a decade since they started allowing 2LD registrations. I very highly doubt they are suddenly so worried about random individuals' personal internet security.

It has to be a money problem. Something they want to do will be simpler if this is no longer a quirky registry. And they know they'll get the money back that they lose from not having bob.smith pay -- probably by throwing all the "last names" once registered this way into some "premium name" bucket and selling them for $1000 and up instead of the ~$10 that zyzgdhaf234.name fetches.

In fact, I'm not sure that scheme isn't the reason itself.

QuantumNomad_ 2 hours ago | parent | prev | next [-]

Note that the posted link talks about .uk.co, which currently does not exist but I guess may have in the past. Where .co is the ccTLD of Colombia.

Different from .co.uk.

kevin_thibedeau an hour ago | parent [-]

Originally there was uk.co.orgname.

traceroute66 2 hours ago | parent | prev | next [-]

> I always thought .co.uk

What the hell are you talking about ?

1. The Nominet rules are crystal clear about which 2LDs are managed by Nominet[1] (co.uk, sch.uk, gov.uk etc. etc.). `co.uk` has been a Nominet managed 2LD since 1996 and it is not going anywhere.

2. FUN FACT ... Nominet introduced the ability to register directly under `.uk` much, much later, in 2014. Before 2014 your only option was to register under the auspices of a Nominet managed 2LD, e.g. `co.uk`. Ownership of a third-party 2LD is validated in 10 seconds via the usual WHOIS.

I suspect you meant 'uk.co' and other such shenanigans. Please correct your post accordingly.

[1]https://nominet.uk and https://www.nominet.uk/wp-content/uploads/2025/03/UK-rules-o...

akersten an hour ago | parent | next [-]

Ok, co.uk was perhaps a bad example, because it's owned by the same registry as the TLD, but perhaps there are other 2nd level TLDs where that is not the case. My point is both that it's hard to tell, and more broadly why would anyone want their domain to be tacked on to some 3rd level subscript anyway, when there's so many plain top level domains available. Surely most of us (present company excluded perhaps) do not feel so passionately about the reverence of `co.uk`

I don't have some nefarious desire to scare people away from the TLD of their choosing. Really I'm bringing it up to be like "why would you even, like, want some 3rd rate domain instead of getting a .com" so I don't think there's anything to correct

drdexebtjl 12 minutes ago | parent | next [-]

Sovereignty? If you live in the UK, choosing a registry in the UK is a pretty good idea even if they only offered 3rd levels. You’ll have someone to contact and possibly sue locally. Your domain will be subject to UK law and standards, not those of a foreign registry.

traceroute66 36 minutes ago | parent | prev [-]

> My point is both that it's hard to tell,

Its not hard to tell for things like ".uk" or other serious suffixes.

It only (maybe) becomes hard(er) to tell for all the vanity ccTLDs that came along in the 2000s. But even then 10 seconds on WHOIS and Google should fix any doubt.

> about the reverence of `co.uk`

What are you on about ? Lots of other countries do it too. Japan is one example given already here, but there are dozens. It is very common practice for country tlds.

stronglikedan 2 hours ago | parent | prev [-]

geez, dude, someone woke up on the wrong side of the bed this morning...

traceroute66 2 hours ago | parent [-]

> geez, dude, someone woke up on the wrong side of the bed this morning...

5 seconds on wikipedia or google would have stopped them spreading completely dangerous FUD about .co.uk.

yreg an hour ago | parent | next [-]

What's so dangerous about it?

traceroute66 an hour ago | parent [-]

> What's so dangerous about it?

Implying lack of trust in `co.uk`

Implying `co.uk` may suffer the same fate at `.name`

Complete FUD.

gertrunde an hour ago | parent [-]

You're absolutely right, when it's Nominet's actions that actually inspire a lack of trust in .co.uk, given they've been a bit of a hot mess since the early 2010's-ish.

;)

(Edit: although I should add that I'm hopeful that things have improved there over the last few years).

traceroute66 27 minutes ago | parent [-]

> given they've been a bit of a hot mess since the early 2010's-ish

No.

Oversimplified summary:

There was a period around 2010 when the management at the time wanted to follow a more commercial route with various unrelated "investments".

Nominet members made it impeccably clear in a very loud manner to management that it would not be tolerated.

Management insisted on a vote which they inevitably lost.

Management departed.

TL;DR Don't piss off Nominet members

dokyun 2 hours ago | parent | prev [-]

[flagged]

Ekaros 24 minutes ago | parent | prev | next [-]

To me that sounds like reasonable structure. I hold that every single edu, gow and mil domains should be moved under respective ccTLDs. After this sort of move that doesn't seem unreasonable thing.

dolmen an hour ago | parent | prev | next [-]

.uk.co (mentioned in the blog) isn't .co.uk

pushcx 2 hours ago | parent | prev | next [-]

It wasn't obviously wrong in 2001. .pro started with a similar structure around the same time.

Pxtl 2 hours ago | parent | prev [-]

Agree that the .name 3rd level domains are silly, disagree on .co.uk being a problem.

If .gov and .mil and .com make sense, then .gov.cc and .mil.cc and .com.cc make sense.

Of course, I think having more than one non-cc TLD was a mistake, but that's just me. If it makes sense to have topical TLDs for international and US institutions, it make sense to have national ones.

gpvos 2 hours ago | parent | next [-]

The 3rd level .name domains are the original ones. They didn't hand out 2nd level domains until three years after they started.

traceroute66 2 hours ago | parent | prev [-]

> disagree on .co.uk being a problem

Nominet and therefore .co.uk has been around since 1996.

.co.uk is not going anywhere, and neither is Nominet.

The only "problem" is the original poster did not do their homework. I suspect they were inferring `uk.co` which is a completely different kettle of fish. The original poster should urgently correct their post.