.name Termination
323 points by fancybone
323 points by fancybone
I am disgusted that the ICANN approved this. I hope the author has success challenging this legally.
This is nightmare fuel. Instead of selling the registry responsibility to someone who would care for it and profit from it, Verisign chose to murder it. And ICANN actively aided Verisign in doing this, proving (if there were any remaining doubt) who ICANN actually serves.
Strange, and sickening.
Wow, even if there was a legitimate reason for the termination of all these domains, I can't imagine not giving at least a few years for registrants to update their...well, everything. It's just irresponsible to close a namespace on such short notice.
I wonder if some organization could offer ICANN to take over management for all those existing second-level .name domains to avoid disruption of service.
I wonder if some organization could offer ICANN to take over management for all those existing second-level .name domains to avoid disruption of service.
Verisign's doc mentions "limited registrar support of the service and declining usage of third-level domains".
It's worth reminding ourselves the weirdness of .name: you can register surname.name unless any forename.surname.name is already registered. That's not how other TLDs work.
It's no wonder this TLD has limited registrar support.
If, as you suggest (and is reasonable to consider), we split the .name registry somehow by just the impacted names, that's yet more complexity.
The whole TLD also is a security problem because it's incompatible with the public suffix list. It does make sense to phase it out.
perhaps it's the public suffix list that's wilfully incompatible with the TLD?
It's unclear how the suffix list can be made compatible with the TLD. It would have been easy if whoever created .name would have made the rule that you can only register first.last.name but they permitted people to also register something.name and without knowing from the registry what is a top level registration and what is not, it's not clear how to solve it.
I would default to heuristic measures, ie. gather the domain list somehow, and compact it into some fast-lookup blob. At least as long as the current setup doesn't let two 3rd-level registrations see each other's cookies then it's not too bad.
From https://github.com/publicsuffix/list/issues/2306#issuecomment-2802970855 :
you are 1000% correct, it just gets REALLY bloated to represent these in the system here, and it would require a lot of cycles to set up and maintain these with Verisign (the registry) to isolate which are directly tied to them vs those operated by private parties that are simply registrants offering subspace.
So, we've awareness this is sub-elegant, but there's not been any clamoring to triple or quadruple the PSL filesize for this in the absence of the occasional pedant person like me who'd want it all represented explicitly
ICANN has an opportunity to reverse some of its bad reputation here. I hope they take that chance.
I think the last incident on this scale I remember was when UK citizens weren't allowed to keep their .eu domains with Brexit. Gotta love being subject to things you didn't support (and DNS centralization, of course).
I think the motivation there is that it's difficult to resolve domain disputes if you have no legal presence in a jurisdiction.
That said, I was impacted by this, as I posted in https://lobste.rs/s/9r9ozr/sudden_loss_domain
I occasionally tell this story and sometimes hear that I should have been aware that Brexit was a possibility, and just picked .uk.
Alas, I consider(ed?) myself as European almost as much as British.
And what of the people in Scotland, Catalonia, and WA happily using .uk, .es and .au?
I always said "ICANN is not so bad, they have not done so badly so far."
I'll go get some fries to eat with that.
In general I'm a fan of https://opennic.org/ but that's not something viable. I see no viable alternative.
Hopefully I have misunderstood what's happening here or this is fixed and not a sign of times to come.
I always said "ICANN is not so bad, they have not done so badly so far."
I'd have agreed with that 20 years ago, but when ICANN allowed the 'anyone who shows up with a pile of money to run a protection racket can do so' creation of TLDs I lost trust in them.
I know what you mean, but OTOH there's a demand for more TLDs and I'm not surprised they try to make a buck out of it. It's not good, but it's quite mild compared to these shenanigans.
(I have a .pub myself. I only use it for my ActivityPub instance that I currently consider throwaway. .org or .net would technically work too. My "important" domains are .net, but sincerely, I have no idea what's the best TLD to use for personal purposes. Probably I should start using my ccTLD or .eu.)
The problem is that each new TLD ends up requiring any established brand to defensively buy their existing names in that domain. So there's a guaranteed revenue stream for any new TLD, and that revenue stream is extortion: Nice trademark you've got there, shame if someone bought a domain for it and put porn on it. And this was obvious and was flagged in a huge number of objections before ICANN made the pay-to-play rule.
Ah, yes. I don't think so much of it. I'm aware that in some cases you need to defend proactively your trademarks, but honestly... I just tested with my bank and while they have .org, .net, etc. I couldn't find they had any of the newfangled TLDs.
Maybe it's different in other jurisdictions, but at least here it doesn't seem to be a huge concern.
But there's plenty of other stuff that I don't like about the domain name system, anyway.
Did you check DNS or WHOIS? They often don't bother with DNS entries, they just buy and park them to avoid someone else squatting.
Huh, that's a good point. I played a bit with whois and rdap- lately I have some issues figuring which tool to use, and they don't seem to provide the same results. Also for some TLDs I have to use the NIC's service? (Yeah, DNS is a mess.)
I checked with my "trusted" registrar; my bank's official name is a short four letter initialism and they list .best, .website, .xyz, .link, .auto... etc. as available.
Maybe my bank cares less than the average about that stuff, or perhaps in different places there are different obligations, though. In my head it still sounds strange that all companies are "forced" to buy SO many domains. (Still, if there's .bank and you're a bank, that might be more necessary to buy, but perhaps you don't need to buy the .christmas domain.)
Both the Verisign and ICANN documents are gloriously ambiguous when it comes to what happens to 2nd-level names that were once shadowed by a 3rd-level registration. I'm not at all surprised: I had a 3rd-level .name 25 years ago and got bit by registrar problems then.
Lobsters fairly often gets articles advocating self-hosting email. I always think it seems too risky because any Internet presence that I try to maintain seems definitely less likely to be consistently available for the next, say, 15 years than, say, Gmail. Keeping control of the domain name is definitely one of those availability risks.
I don't see the relevance to self-hosting. Sure, it's a risk there, but keeping control of the domain name is also of importance to any person, company and organisation not wanting to use their service provider's domain name (which could also disappear without recourse, by the way.)
which could also disappear without recourse, by the way
gmail.com disappearing is far, far less likely than essex-plumbers.xyz. I often see small businesses that have their email address as somebusinessname@gmail.com and honestly I don't think twice about it
Yeah but Google deciding to ban or delete your account is on the other hand much more likely than essex-plumbers.xyz disappearing.
I'd say that this is negligence on the part of ICANN.
Or you can get locked out of your account due to a bug. My oldest account is no longer accessible due to one day the password no longer being accepted. It doesn't say it's incorrect, it says something along the lines of "this authentication method is not secure enough to log in, try another option", but no other options are provided. I've spent some time trying to contact their support team, but I never got a response.
gmail.com disappearing is far, far less likely than essex-plumbers.xyz
True, but that's not the comparison. The comparison is, on one hand, your registrar, with whom you have a legal contract that involves paying them money and whose business depends on being perceived as a trustworthy entity for registering names deciding to cancel your domain registration. Crucially, domain registrations are portable: if a registrar gets a reputation for unilaterally cancelling domains, or even hiking their prices a lot, then you don't
On the other hand, you have a company with whom you have no contract, are not paying money to, and that has an explicit clause in their T&Cs that allows them to cancel their service to you for any reason without stating the reason, who exercises that clause on a fairly frequent basis, and which makes basically impossible to talk to a human customer services representative if this happens.
I'd consider that the second deleting your account is far more likely than your registrar deleting your domain or being unable to keep providing it. The article mentions that 22,000 people are affected by this. And that's a very unusual occurrence. Contrast this with the total number of registered domains and it's a rounding error. Look at how many stories there are of people having Google accounts deleted or suspended with no recourse and you'll see a very different risk profile.
I often see small businesses that have their email address as somebusinessname@gmail.com and honestly I don't think twice about it
I think 'this company is very bad at risk assessment, I probably don't want to employ them'.
I’m sure Google has closed more than 22,000 gmail accounts in the last 15 years
and they do it without any notice and without any fuss on lobste.rs.
This example is particularly rare, hence why it creates such drama. As long as you pay, keeping a domain is quite easy and, most importantly, under your control.
Trusting to keep your gmail address is, at best delusional. And even if you keep it, who knows what the service will be in 15 years, what price they will make you pay. I mean, your email are now officially used to train their LLMs.
Though I'm sure it's rare, it's not uncommon to see people complaining they've lost access to their Google/Gmail accounts for this or that reason. I would imagine Gmail will be around in 15 years. I am not certain that it's more or less risky to depend on Google, though, than to control your own .com, .net, .org, etc. domain.
I'd suggest it's slightly more likely that Gmail will be gone in 15 years than .net, for instance. (But I wouldn't wager any serious cash on either disappearing in 15 years. Plus it's more likely that I won't be around in 15 years than either of those... hopefully, though, I'll still be getting email to my .net domain hosted on not-Gmail even then.)
FWIW I think controlling your own domain name on one of the big three TLDs and hosting with a service like Fastmail is probably the least-risky option. I do not love running my own mail services, even though I often feel like I should for various reasons, but I can always point my domain at another provider if need arises or even start self-hosting if absolutely necessary.
I'd suggest it's slightly more likely that Gmail will be gone in 15 years than .net, for instance.
Interesting — why only slightly? :-)
One is owned and operated by a diversified conglomerate with many other lines of business; the other is about twice as old and operated and overseen by corporations specialized in operating and overseeing such things, and I struggle to imagine .net being decommissioned unless the whole Internet is being replaced.
FWIW I think controlling your own domain name on one of the big three TLDs and hosting with a service like Fastmail is probably the least-risky option.
I find that plausible on average, though I would expect the least-risky option to differ by person.
Keeping control of the domain name is definitely one of those availability risks.
Depends, what TLD and who you're registering it from. Honestly, the only real risk is if you pick a really shitty registrar. Going with ccTLDs (.eu, .fi), or some common TLDs is a good option.
I know you mean that, but for clarity: a ccTLD you are associated with. My pet peeve is using ccTLDs because of how they "look" instead of what they mean.
(But, .io was supposed to die and they saved it because it was "too big to fail". No such grace with current .name third-level domains.)
Honestly, the only real risk is ...
I consider forgetting to update my payment information when it (inevitably) changes, and thereby getting my domain name subscription cancelled, to be a real risk, even given reminder email messages. Every option has some risk, which I would expect to differ for different people.
+1.
https://lobste.rs/s/9r9ozr/sudden_loss_domain was my example of losing a domain through no fault of my own.
Picking a TLD is important. Though there's no guarantee you'll continue to be eligible for any TLD, perhaps .com is the safest bet, sadly.
Yeah I have a .email domain that I've been using for the past year...... I'm thinking it may be too risky to use it for everything.
Same. I have a .ink domain I had registered as a word play when I tried to get into blogging, that I have started using for email and other stuff as well. Perhaps it is time to reconsider where to put my internet presence. Then again using .com in the current times also doesn't seem entirely safe for non-US peoples; .org was already on the verge of becoming an issue, and using my own ccTLD doesn't seem logical either if I am thinking that I might be moving to a different country in the next few years. So what is the good option to go with today? .net maybe?
Yes, I registered my third-level .name domain specifically so I could "own" my email address. Joke's on me, my @gmail.com address is going to outlast my "owned" address.
I had the same scare when they decided to commercialize .org. My entire Internet presence has been tied to an .org domain for a quarter century as well.
Pretty much all questions asked about how and why can be answered by one word: profit.
They're not making enough. We can't have nice things because we can't have organizations that aren't all about profit run important things. When we have, they've generally worked well, but then someone gets the idea (or gets told the idea) that the thing can be privatized, and someone close to the decisionmakers can make profit, and perhaps some of that ends up flowing in the direction of decisionmakers.
Healthcare, for instance, shouldn't be a for profit business. Housing shouldn't be be for profit. How it ever came to pass that the DNS moved to a horribly exploitive for-profit system should be studied, and people vilified, and we all collectively should try to imagine ways we could have a system that's outside of that for-profit system run by real, actual non-profits that have real, actual computer geeks that aren't going to use or sell their influence.
The Internet, including the DNS, is a product of the USA. The USA, of course, disagrees with you and strongly values and advocates for-profit private enterprise. The product of course reflects the values of its maker.
Didn't the US military semi-famously just kind of turn a blind eye to the fact that people were using the network they'd set up in new and unexpected ways? I don't know if I'd attribute to the US all, or even most, of the value contained in the Internet.
ICANN is (allegedly) a non-profit and receives significant regulatory benefits in exchange for that disavowal of the profit motive.
If they wanted more profit, why didn't they raise rates instead of shutting it down?
My guess is that some underpants gnome decided that whatever takes its place will be more profitable.
Yikes, I was literally just about to start transitioning all my email to an address at my .name domain. Thankfully it is only level 2, but this definitely gives me pause.
I've gone through with it (on a non .name domain), and it's definitely a commit to owning that domain forever sort of thing. Also keep in mind that changing your email address with certain entities is near impossible, unfortunately.
Is there a good,central place for people not directly affected by this, i.e. not having any .name registrations, to complain to ICANN to help have this decision overturned?
Meanwhile, somebody has build a social media federation protocol where the user identity is based largely on ownership of a domain
You're just describing the Internet. If someone ever claims gmail.com for any reason and it's not Google, a world of hurt is in store for a lot of people.
Actually, the domain in atproto is just a handle. The relevant piece is the did, and one can change what domain points to a given (owned) did in a minute.
DIDs are the long-term persistent identifiers for accounts in atproto, but they can be opaque and unfriendly for human use. Handles are mutable and human-friendly account usernames, in the form of a DNS hostname.
did:web in particular is what I'm referencing. I was under impression that it is widely used?
did:plc is far more common; most bluesky users with their domain as their handles are did:plc as opposed to did:web. It's only really the hardcore atproto nerds who use did:web. An informative article: https://steveklabnik.com/writing/too-many-words-about-dids/
I read a few years back that atproto, on the protocol level, only really worked with a few centralized servers, as all the data for all users on a given server would automatically have to be stored by all servers on the same network. Am I remembering this correctly, and if so was that problem resolved at some point?
Yes and no. Personal data (like Bluesky posts) is stored on personal data servers (pds). To not have app views (like Bluesky) crawl each and every pds and to enable realtime features, they connect to the firehose instead, which are relay servers all data gets pushed to. In the past, these relays would also keep all data, but nowadays they just store the most recent few hours.
An app view will most likely cache a lot of that data too, but it can always fill in recent data from the firehose and older data from pds, depending on the app’s needs.
Still, Bluesky isn't capable full mesh semantics (each node can function fully independently, but can also federate with all other functional nodes).
I've considered building an atproto PDS/Relay/App View with activitypub semantics (see all the messages from local users, and all messages from users that anyone locally follows or has boosted).
But even if I built a server that only crawls followed users, that wouldn't be able to replicate the activitypub semantics, as atproto doesn't allow reverse lookups for quotes and comments.
So what you could do is add an extension that allows servers to inform one another about backlinks, and then you could finally build mastodon style decentralisation on atproto.
It was a bit hard to understand. So they have a huge catalog of xxxx.name domains (or they create these on request?) and they only would hand out third levels under those?
Yeah, I didn't understand that either. If I buy x.y.name, who owns y.name? Anyone? If so, are they prevented from making their own z.y.name subdomains? And why didn't OP buy y.name in the first place?
If I buy x.y.name, who owns y.name?
The TLD. The TLD also provides mail forwarding for x@y.name to the owner of x.y.name and trevor@y.name to the owner of trevor.y.name.
This was a decent alternative to x@x-y.com, or x@y.com (where you needed to own y.com)
And why didn't OP buy y.name in the first place?
Between 2001-2004, only x.y.name registrations were allowed.
In 2004, registering y.name became allowed, as long there was no x.y.name.
Once any third-level name of the form x.y.name is registered, the registry prohibits registration of the second-level y.name; z.y.name would remain up for grabs.