Remix.run Logo
dvt an hour ago

I freaked out for a second because I've owned `dvt.name` for like 15 years. `.name` is not getting terminated, so it's important to be precise here. The third-level x.y.name (where you're the `x`) is getting terminated, and the respective `y.name` domains are going to be released.

Still a crappy thing for people, but it does not affect owned second-level domains.

wormius an hour ago | parent | next [-]

There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level.

But I didn't think about the 1st level competitors. There'd still need a mechanism to resolve that...

1. First come first serve? (e.g. whoever registered a y.name first, whether x is bob or sue is determined by the earliest registrant on record) 2. Lottery/random selection? 3. Bidding war?

I think the problem is 2nd level domains who have the same name will be a problem when they find out all these other 3rd level are now expiring and can run a route to spoof? Likely wouldn't happen, but with the fuckery in the DNS that can happen... This is such a rash and weird decision to push through so quickly just because engineers find it "easier" while ignoring the implications of the move, seemingly when it comes to larger scale security.

I assume there would have to be some method to prevent routing of third level domains to subdomains of two-levels... (or is that just me being a fool yet again, assuming we have competent administration of our systems).

43 minutes ago | parent [-]
[deleted]
TZubiri 35 minutes ago | parent | prev [-]

I don't get the difference. If I acquire the y domain and make it work as a subdomain broker, it's the same thing no?

There is no subdomain/TLD bit

chuckadams 8 minutes ago | parent | next [-]

The Public Suffix List is the closest thing we have to the "subdomain/TLD bit", but afaik it doesn't include wildcards like `*.name`. It does influence TLS though (or possibly just browsers) in that a wildcard cert for an entire TLD or public suffix won't be honored, nor will a public CA issue such a cert.

Still, I'm not sure there's any technical fix for the kind of mismanagement that .name was subjected to.

mhink 11 minutes ago | parent | prev | next [-]

From what it sounds like, unlike domains under other TLDs, when you purchase a domain under .name you always purchase specifically the three-segment domain.

i.e. I own john.doe.name, you own george.joe.name. Once this change goes through, only "doe.name" can be owned, so who gets it?

dvt 14 minutes ago | parent | prev [-]

You are technically correct, but Verisign billed buying an x subdomain as if the y domain was part of a stable infrastructure. Which it kind of was until they decided to pull the rug.