Remix.run Logo
nneonneo 3 hours ago

It seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3LD registered on top). It’s a bit insane that they can decide to just terminate all existing 3LD registrations. One would hope that they’d at least continue to reserve the 2LDs for some period to avoid domain squatting, but this isn’t mentioned in the proposal and I doubt Verisign would graciously do so.

layer8 2 hours ago | parent | next [-]

Maybe they want to avoid the ambiguity between john.doe.name versus john-doe.name, and I assume they prefer the latter scheme because it probably sells better. Nevertheless, discontinuing existing domains is disgraceful.

xp84 2 hours ago | parent | next [-]

Even that doesn't pass basic scrutiny. The same ambiguity can and always will exist with tim-apple.com and tim.apple.com - there's nothing here that needs fixing.

layer8 2 hours ago | parent | next [-]

True, they can’t outright prevent the ambiguity, but much fewer people will go to the trouble of establishing such subdomains when the option isn’t directly offered by the registrar.

This is my theory because, a priori, 3LDs should be more profitable than 2LDs, because with 3LDs John Doe and Jane Doe don’t have to compete over doe.name, but instead can each separately purchase john.doe.name and jane.doe.name. Apparently, however, that’s not a benefit of 3LDs in practice, which leads me to conclude that john-doe.name and jane-doe.name just sell better.

QuantumNomad_ 4 minutes ago | parent | next [-]

Prior to reading the OP blog post, I had never looked into the particular rules that .name has.

To me, prior to knowing how it works, I would have assumed that either

a) john.doe.name would be a subdomain that someone who was just starting out had gotten for free supported by ads. Similar to having johndoe.freewebs.com back in the day. Not something most people would use for anything professional.

or,

b) doe.name was registered by one of the people in a family of Doe’s where every Doe is pretty closely related. For example, John of john.doe.name and Jane of jane.doe.name are husband and wife, or third cousins, or what have you. Most of the content, I would assume, is mostly about things that relate to the family. Like maybe one guy is doing a family genealogy project tracing the roots of this little cluster of Doe’s back in time. And another one probably has some photo albums with pictures of like previous Thanksgivings and other family get togethers. In other words, nothing I would care about unless I was in their family or a very close friend of the family.

I would not have guessed that .name worked the way that it did if I hadn’t read about it.

toast0 8 minutes ago | parent | prev [-]

> This is my theory because, a priori, 3LDs should be more profitable than 2LDs,

3LDs are less valuable. In a market of many different tlds, why register foo.bar.name when you could get foobar.name or foobar.something_else

dpoloncsak 2 hours ago | parent | prev [-]

I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real.

It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com

In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com

edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule

dbt00 an hour ago | parent | next [-]

That is definitely not true. There are literally thousands if not tens of thousands of well known domains that do this. .co.uk is a very common example.

ndiddy 42 minutes ago | parent | next [-]

.name is still a weird edge case because of the naming rules. Whether or not all subdomains under doe.name belong to the same person depends solely on whether the first person registered "doe.name" (in which case they do) or "john.doe.name" (in which case they don't, and "doe.name" is excluded from purchase as a standalone domain).

6 minutes ago | parent [-]
[deleted]
dpoloncsak 24 minutes ago | parent | prev | next [-]

The fact that multiple organizations need to keep a public list of known 3LDs proves it's the edge case, does it not?

"Here's a list of things that look like subdomains for you to treat as 3LDs instead of subdomains" sounds exactly like the solution to an edge case to me.

desas an hour ago | parent | prev | next [-]

I think the problem is that .co.uk, .gov.uk and so on are very well known in the UK.

The .name subdomain rules are not very well known anywhere.

davkan an hour ago | parent | prev | next [-]

I can’t think of any prominent ones outside of country code domains.

strenholme 14 minutes ago | parent | next [-]

I remember I had beach.santa-cruz.ca.us at one point registered to me. I owned beach.santa-cruz.ca.us, someone else owned santa-cruz.ca.us, yet someone else owned ca.us, and I believe Network Solutions took care of .us at the time.

bombcar an hour ago | parent | prev | next [-]

You can almost guess someone's age from that alone - they're more rare, but long domain names still appear that encode a city and a state, and you could just "grab" the first part when signing up.

davkan 24 minutes ago | parent [-]

Outside of the context of ccTLDs and city.state.gov etc, I struggle to think of examples 3LD+ domains where they are owned and operated by completely different concerns than the parent. If at some point you could just register your own mysite.state.gov domains willy nilly that's probably before my initial time online around 2000.

Another poster raised the point of hosting services which is valid. But at present outside of that example and the above I really can't think of an example where you have a link to entity.com and you have any significant cause to verify the identity beyond the 2LD.

ketzu an hour ago | parent | prev [-]

Github Pages is probably the most well known one (on here).

I think geocities had this as well?

A lot of hosting services offer this in general. (eg render)

Tumblr? (Might not count as the control over the page is more limited. The subdomains "are" still tumblr.)

For reddits subdomains are redirects to subreddits of the same name, so I guess that doesn't count.

davkan 39 minutes ago | parent [-]

None of these examples are of actual separate registration/ownership of a 3LD from the parent 2LD. Cloudflare owns the domain for myproject.pages.dev and hosts all the relevant infra. Not to say that there isn't a different entity represented by the 3LD than the 2LD but it's not exactly the same.

Also I would not consider the examples of tumblr and reddit to be relevant. A person's blog on myprofile.tumblr.org is still the tumblr organization. This would be true for reddit even if they didn't redirect. Reddit admins moderate content on all subreddits.

ketzu 26 minutes ago | parent | next [-]

I see, that's a valid way to think of domain ownership.

When I read > I have been taught and tell my users to check the domain to verify a website is real.

I was thinking more of control of the content as "ownership" of the domain.

davkan 18 minutes ago | parent [-]

The point on hosting providers is well taken. You do have to consider x.pages.dev as the wild west not cloudflare of course. One difference though is you will never receive an email from x.pages.dev asking you to do something. The domain ownership still does play a part.

megagpt1 28 minutes ago | parent | prev [-]

You can buy example.it.com on many registrars. Someone bought it.com and operates it like a TLD.

davkan 17 minutes ago | parent [-]

Interesting. I do wonder how many people outside scammers and squatters buy them. I'd rather have an .xyz or .biz address personally.

17 minutes ago | parent | prev [-]
[deleted]
amiga386 28 minutes ago | parent | prev | next [-]

Hello sysadmin. Good luck navigating the internet.

What you should know, and what your browser does know and automatically applies cookie policy and colouring your URL bar, is the Public Suffix List: https://en.wikipedia.org/wiki/Public_Suffix_List

It will let you know that, for example, one does not need to own .co.uk to own the subdomain foo.co.uk.

strenholme 12 minutes ago | parent | next [-]

The .name mess is not in the public suffix list.

https://github.com/publicsuffix/list/issues/2306 for more discussion.

dpoloncsak 23 minutes ago | parent | prev [-]

I appreciate this, and yeah the government/education ones slipped my mind, but I stand by the fact that the reason a list needs to be kept in the first place is because this is the edge case and not the norm.

veltas an hour ago | parent | prev | next [-]

Yet that is a problem the owner of such a domain has freely entered into by buying that domain, it's their right to keep it despite this apparent problem, if they wish.

dpoloncsak 11 minutes ago | parent [-]

Understood, and .name isn't being used enough in business to worry about 'the effect it will have on my users'. Just pointing out that it doesn't work like the 'norm' (although I guess it's not quite as unique as I thought, either)

gapan an hour ago | parent | prev [-]

There are still exceptions to this like .co.uk and many others.

joemi an hour ago | parent | prev [-]

Was it even possible to register just a second level .name domain name? It sounds like it wasn't, so therefore no one would be using john-doe.name and there'd be no ambiguity.

p4bl0 11 minutes ago | parent | next [-]

Not at the very beginning, but then it became possible.

anttihaapala an hour ago | parent | prev | next [-]

Yes it has been. I have had a second level .name for 20 years.

WesolyKubeczek an hour ago | parent | prev [-]

It was, I have one.

p4bl0 14 minutes ago | parent | prev | next [-]

Another thing that should be obvious and yet they refuse to do: when there is a single third-level customer for a given second-level, offer them a way to get the second level domain. I've been asking VeriSign this for 15+ years, they always said no, even if at some point they confirmed that there were no other third-level than mine under that second-level domain. They're insane and should not be in charge.

giancarlostoro 3 hours ago | parent | prev | next [-]

I'm surprised they don't just do that, and maybe even to go a little further, disallow renewals so you can phase people out and reclaim domains you can sell.

xp84 2 hours ago | parent [-]

Whether disallowing renewals or terminating them tomorrow, there's still the same core problems, only the date of the offense changes: (1) seizing people's names that they've established, breaking innumerable things including email and server hostnames, and (2) the possible resale of the 2LD fraser.com to a third party who will be free to do malicious things like reading OP's email, redirecting his traffic, or extorting him, to sell continued access at any price demanded.

zamadatix 13 minutes ago | parent [-]

There's one less core problem: those who just bought/renewed their domain e.g. yesterday are fucked out of both their money and forced to migrate sooner than they could have reasonably planned for. People's who registrations expire and they are unable to renew is a very different level of unfairness and inconvenience.

In either case, the security concern should be directly addressed.

echelon 3 hours ago | parent | prev [-]

That would be so cool and would make these limited hot commodities.

.name was one of the very first expansions of gTLDs back in the very early 2000s. It's a shame that it's being shut down as it was spearheaded by the ICANN itself rather than some registrar / investor like Donuts, Inc.

I suppose this is impractical as someone has to run the registry and there are costs associated with that. But don't the domain fees cover it?

ajmurmann 2 hours ago | parent | next [-]

From having worked in that space what feels another lifetime ago, I vaguely recall that you can just offload the registry work to a registry that would manage this together with a mountain of other TLDs.

AtNightWeCode 2 hours ago | parent | prev [-]

As I recall it. This was mostly a money scam that targeted private users with ads like "make sure to claim to your .name domain so no one else does it and use it to impersonate you". It was stupid from the beginning and never took off.