logoalt Hacker News

.name Termination

1099 pointsby pavel_lishintoday at 2:54 PM326 commentsview on HN

Comments

nneonneotoday at 4:44 PM

It seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3LD registered on top). It’s a bit insane that they can decide to just terminate all existing 3LD registrations. One would hope that they’d at least continue to reserve the 2LDs for some period to avoid domain squatting, but this isn’t mentioned in the proposal and I doubt Verisign would graciously do so.

show 3 replies
jl6today at 8:48 PM

I can only assume somebody was asleep on the job when this scheme was approved, because the outcome is in direct contradiction to ICANN’s mission statement:

> Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems.

https://www.icann.org/resources/pages/about-icann

Arbitrary termination of service is not stability.

Enabling name hijacking is not security.

The answer cannot be a rival name scheme based on decentralization or crypto or whatever. Those are never going to help normal non-wizard users. The answer has to be to make the regulators do their job.

nanolithtoday at 8:12 PM

This risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices used were entirely disconnected from domain names, and why the discovery protocol I put together did not rely on registered domains, but could use these as an untrusted part of discovery.

Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.

I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.

I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.

dvttoday at 5:51 PM

I freaked out for a second because I've owned `dvt.name` for like 15 years. `.name` is not getting terminated, so it's important to be precise here. The third-level x.y.name (where you're the `x`) is getting terminated, and the respective `y.name` domains are going to be released.

Still a crappy thing for people, but it does not affect owned second-level domains.

show 2 replies
akerstentoday at 4:23 PM

It kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.).

Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?

show 12 replies
arjietoday at 4:38 PM

We were rescued from that dot org scam by the fact that ICANN is a California non profit. I wonder if the AG can lean on them again. This is an outrageous thing to do.

aliasxneotoday at 5:32 PM

This is why I am building DNTLS. These organizations no longer deserve our trust and they have inadvertently gained too much power over the last two decades of massive internet expansion. Names need to be fully owned by individuals and a shared, decentralized trust system must be in place for resolution. The more I see actions like this, the more convinced I am that a solution is long overdue.

show 2 replies
sigbottletoday at 5:21 PM

There's a DNS wizard at my job (not doing DNS stuff currently; but in his past life), and while he was talking to me about certain topics my eyes glazed over, and I thought, "Man, surely that won't affect me, right?"

Well, it's still not affecting me, personally, but wow, seeing articles like this makes it feel just a tiny bit more real.

econtoday at 6:54 PM

I don't like the way domains work in general. It's really quite expensive if you are wise enough to buy everything that looks to much like your website.

Did buy https://ycombinator.us

Didn't buy https://ycombinator.co.uk

https://ycombinator.de

What useful functionality is there in selling these domains?

Expiring domains is bad for the web and selling them to someone else is as terrible as the article makes it out to be.

show 2 replies
nubinetworktoday at 4:23 PM

> Once the 3rd-level domains are terminated, it is assumed that the now vacant 2nd-level domains will become available for registration. Should someone (other than me) scoop up fraser.name (...)

What's to stop someone from doing that, and keeping the status quo? Sure, it might be expensive, but pool together a few frasers for the initial buy, and make the money back on the sublets.

show 2 replies
willwadetoday at 5:15 PM

I worked for .name briefly right at the beginning of their entry into the world. Interesting but very odd part of my career.. Ill give it that.. I personally found the product at first a great idea but somewhat crippled by execution..

johnplattetoday at 4:50 PM

Wow! Years ago I initially bought my firstname.lastname.name, then I let it expire and then bought lastname.name. So glad I did!

Never dreamed that such a supposedly durable thing would just disappear. How hard is it really to preserve a global resource like this that exists only in software?

ipythontoday at 4:13 PM

From the Verisign application [0] for this change:

    > 2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
    > None. There will not be any effect on the life cycle of domain names.
ehhh, how is that possibly true? This change (deleting all third level names) by definition affects the lifecycle of domain names ... by terminating them!

Many years ago I wrote articles bringing attention to the negative effects of Verisign's SiteFinder [1] - if you don't remember this, it's when Verisign hijacked NXDOMAIN by redirecting any unresolvable domain to a site they owned and controlled.

[0] https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2... [1] https://en.wikipedia.org/wiki/Site_Finder

show 1 reply
padjotoday at 6:42 PM

Who is running the show over at ICANN? How can this possibly be a reasonable thing for a registrar to do?

cpachtoday at 7:57 PM

Ouch.

IMHO, this whole TLD seems kind of messed up from the start: https://en.wikipedia.org/wiki/.name

Glyptodontoday at 8:40 PM

It's kind of crazy to me that the whole domain was originally set up so that people would buy 2nd and 3rd level pairs. But it also seems really obvious that backtracking is going to be a disaster.

chanuxtoday at 4:39 PM

I kind of assumed .name was a product of relatively new TLD explosion [1]

[1] https://blog.asmartbear.com/free-markets-bad/

Gotta wonder what other possible disasters introduced with gTLDs.

show 1 reply
xyzzy_plughtoday at 4:09 PM

> Despite the fact that it's registered and paid for until 2040

How is this possible? I thought there was a 10 year limit.

show 2 replies
morissettetoday at 8:41 PM

It seems as if only 40 people are needed for a class action suit. Me, not a lawyer. Gemini says chances are you could only get a refund. But maybe worth the fight for some.

anominaltoday at 5:33 PM

I am also one of the 22,000 people who have a third-level .name domain and I am livid about this, not least because Verisign flat-out lied in their proposal to ICANN: (https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2...) :

"2.1. What effect, if any, will the proposed service have on the life cycle of domain names? None. There will not be any effect on the life cycle of domain names.

...

2.3. Explain how the proposed service will affect the throughput, response time, consistency or coherence of responses to Internet servers or end systems. There will be no effect on the throughput, response time, consistency or coherence of responses to Internet servers or end systems."

My registrar is also suggesting that they are going to just keep the money I pre-paid for years of registration, which is a minor annoyance compared to the loss of my entire online identity but an annoyance nonetheless.

Since ICANN is a non-profit that is required to operate in the public interest I do hope there can be some pushback on this. I will be writing to the CA AG myself.

jonhohletoday at 6:24 PM

One of the reasons I stick with Big Email for my primary email is cases similar to this. If I host email and lose the domain one day, I’ve lost two factor on a thousand different services (the single factor on some). Big Email’s policy is to not reissue my address, should I lose it or die.

The .name scenario is even worse. One domain gives you access to tens of thousands of users email. It seems like a privacy nightmare.

I’m not sure how future auth and privacy will work, but my child lost a tracfone phone and some mixup had separated it from my account. There was no way to recover the number. If that was my personal phone, how difficult would it be to restore banking, medical, and government access to things that assume I’ll always have that number.

Doing the same with personal email seems like too big of a risk.

xp84today at 6:25 PM

I don't think it's hyperbolic to say that this is the most careless, disruptive change to anything to do with DNS or internet names I have ever seen.

> "will increase efficiency for the operation of the .name TLD."

What a preposterous excuse -- especially for something already up and running. Sounds like they probably want to change the backend in some way - or adopt some kind of off-the-shelf software - which doesn't jive so well with this unique TLD, and they figure "Ehh, fuck 'em, let's just pull the plug on these tens of thousands of people."

decimalenoughtoday at 4:38 PM

I've had a .name domain forever and I had no idea first.last.name was even a thing, meaning that it was possible to register this without owning last.name.

That said, my domain is simply unusual.name, and everybody in my family has email addresses in the form [email protected]. So this is a no-op for me, and I gather www.unusual.name will also continue to work, since I own the 2nd level outright.

show 3 replies
nojatoday at 4:13 PM

ICANN approved this.

marbleotter115today at 8:44 PM

.name is the part I keep having to relearn, so seeing it spelled out helps.

ClarityJonestoday at 6:23 PM

If this proves to be a viable business strategy, then verisign could equally use it to re-sell google.com, ycombinator.com, etc. to the highest bidder.

mchesterstoday at 4:08 PM

Wow, they were extremely laziest in the request form too. Most answers are just a few words.

  > 3.6. Have you communicated with any of the entities whose products or services might be affected...
  > "No. Not applicable."
show 4 replies
Eccotoday at 4:19 PM

Ok I don’t get it. Why not register `fraser.nameˋ directly? Or pick any TLD and register ˋ a 2nd-level domain (ˋfraser.tld`)? It just feels easier, plus this way you don’t have to pay for any new member of your family?

show 7 replies
lacooljtoday at 5:32 PM

Dude, this is one of the craziest things I think I've read on HN

First, that a legit dealer could/did(does?) sell third-level domains at all (Verisign, no less) Second, that the top-level is staying available, allowing for second-levels to be bought/sniped like you mention.

If you do lawyer up and need help with legal fees, I think this would be a worthy cause.

akulbetoday at 7:23 PM

I don't get the concept of 3LD. We own kulbe.name - does this news mean it's going to go away entirely?

doublepg23today at 3:59 PM

I didn't even know I was using .name incorrectly...

aff-vasilevatoday at 7:21 PM

Turns out “buying your name on the internet” was technically just renting a room in someone else’s last name.

show 1 reply
NewJazztoday at 4:22 PM

You might want to write to the CA attorney general. Former AG Xavier Becerra was able to dissuade ICANN from letting the .org fuckery happen, maybe Bonta could try to strong arm ICANN in this case.

show 2 replies
mig4ngtoday at 6:46 PM

And that kids is why it's always DNS fault.

Again, you're security is only as strong as your DNS.

aeternumtoday at 5:02 PM

How would the avg person know that ..name is different and somehow more trustworthy than ..uk

Overall this seems like the right move, either they all are trusted or none.

drnick1today at 5:01 PM

> Second, my email address also disappears. Third, all the IoT devices that use services on this domain become bricks. Basically, I disappear from the Internet.

While changing email is inconvenient, I don't understand the point about IoT devices. IoT devices should not depend on the Internet at all for obvious privacy and security reasons. If you are using IoT devices with "cloud" accounts, then this is a blessing in disguise. Put that garbage in the trash and rebuild around HomeAssistant, Zigbee, RTSP, etc. I find it hard to believe that someone hosting their own website would fall for the cloud IoT scam.

show 3 replies
jmuguytoday at 5:05 PM

I can't be the only one that assumed based on the domain that this was some bizarre DMCA action by Paramount.

show 1 reply
delducatoday at 4:40 PM

I never bet in any other than .com, .org, .net?

show 2 replies
r_leetoday at 5:31 PM

I would not use a 2nd level tld for a "stable presence". it seems like a gimmick

Henchman21today at 6:00 PM

How is it that they can just nullify the contracts they had with people they were providing services for?

0xbadcafebeetoday at 8:40 PM

Prediction: In 20 years, ICANN, IANA, ARIN become increasingly abandoned by nations wary of The Imperialist States of America's control over global communication & commerce, and the internet becomes an uber-net of nationalist internets, subverted by satellites.

cjjuicetoday at 4:49 PM

I really think ENS is on to something with blockchain based domain registration and management

show 1 reply
johnnyApplePRNGtoday at 6:24 PM

They deserve to lose their control of all domains over this.

This is ridiculous.

underdeservertoday at 6:11 PM

dang and team, perhaps it makes sense to special-case .name domains in the domain hint, like you do for GitHub and Ex-Twitter.

bawolfftoday at 6:15 PM

I feel like TLDs as a concept are more trouble than they are worth. We should just have .com and get rid of the rest (except special purpose tlds).

1970-01-01today at 5:20 PM

Instead of giving up, why can't all 22k .name owners move on to OpenNIC? They will not say no, you can't have that.

show 1 reply
swiftcodertoday at 4:05 PM

That's pretty shit. You'd think changes like this would need to go through a public comment period with the affected users (much like city planning decisions do)

xysttoday at 4:02 PM

Verisign is the worst. Hope author wins

show 1 reply
bix6today at 4:52 PM

Fuck verasign. TLDs should be run as an actual public utility. Can these economic parasites be expelled already…

🔗 View 13 more comments