.name Termination (neil.fraser.name)

1530 points by pavel_lishin 14 hours ago

nneonneo 12 hours ago

It seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3LD registered on top). It’s a bit insane that they can decide to just terminate all existing 3LD registrations. One would hope that they’d at least continue to reserve the 2LDs for some period to avoid domain squatting, but this isn’t mentioned in the proposal and I doubt Verisign would graciously do so.

p4bl0 9 hours ago

Another thing that should be obvious and yet they refuse to do: when there is a single third-level customer for a given second-level, offer them a way to get the second level domain. I've been asking VeriSign this for 15+ years, they always said no, even if at some point they confirmed that there were no other third-level than mine under that second-level domain. They're insane and should not be in charge.

jaggederest 6 hours ago

> They're insane and should not be in charge.

I remember back when we had to write mechanize scripts to drive a browser through the renewal process, because if you had dozens, hundreds, or thousands of domains there was no nonmanual way, especially if you wanted extended verification or something silly like that.

So what I'm saying is, agreed and that has always been true.

palemoonsinking 6 hours ago

Why would they want to drop the possibility of selling some as premium domains? If they have their shells setup right they will probably be able to get a premium from some 3rd level domain owners wrongly afraid someone else is interested.

The main problem with the Internet today is that we didn't destroy ICANN when they started this TLD sell off crap. A replacement institution may have at least told Verisign a TLD they can't run transfer to someone who can meet its promises can only be destroyed.

abofh 4 hours ago

gblargg 3 hours ago

It seems insane because it seems like a big point was to have a permanent site for your name. This just devalues all domain names, showing that they can do a rug-pull at any time because they don't want to manage it (how about turn it over to a private company that can adjust costs so they can make a profit and keep it running?).

layer8 11 hours ago

Maybe they want to avoid the ambiguity between john.doe.name versus john-doe.name, and I assume they prefer the latter scheme because it probably sells better. Nevertheless, discontinuing existing domains is disgraceful.

xp84 10 hours ago

Even that doesn't pass basic scrutiny. The same ambiguity can and always will exist with tim-apple.com and tim.apple.com - there's nothing here that needs fixing.

dpoloncsak 10 hours ago

layer8 10 hours ago

joemi 10 hours ago

Was it even possible to register just a second level .name domain name? It sounds like it wasn't, so therefore no one would be using john-doe.name and there'd be no ambiguity.

p4bl0 9 hours ago

anttihaapala 10 hours ago

WesolyKubeczek 10 hours ago

brlewis 8 hours ago

It's exceedingly charitable of you to try to infer a good reason for what they're proposing. I say "exceedingly" because in their proposal they had the opportunity to present a good reason, and they chose not to use that opportunity.

JumpCrisscross 8 hours ago

> the right thing they should do

Can someone explain why a product "registered and paid for until 2040" can be unilaterally voided like this without compensation?

toast0 7 hours ago

Especially when the marketing was saying [1]:

> As your .name can be registered for up to 10 years and ownership is renewable, your .name really can be yours for life.

It seemed like there was an offer of renewable registration at least for a life term.

[1] https://web.archive.org/web/20020609132126/http://nic.name/c...

jayde2767 7 hours ago

That's the crazy part - they can take your money, prorated to some future-period but, upon cancellation, the remaining future period of YOUR money becomes THEIR immediate revenue recognition. Is it fraud or theft? To me, it has to be one or the other...

lazide 8 hours ago

Because they haven’t been sued enough yet?

giancarlostoro 12 hours ago

I'm surprised they don't just do that, and maybe even to go a little further, disallow renewals so you can phase people out and reclaim domains you can sell.

xp84 10 hours ago

Whether disallowing renewals or terminating them tomorrow, there's still the same core problems, only the date of the offense changes: (1) seizing people's names that they've established, breaking innumerable things including email and server hostnames, and (2) the possible resale of the 2LD fraser.com to a third party who will be free to do malicious things like reading OP's email, redirecting his traffic, or extorting him, to sell continued access at any price demanded.

zamadatix 9 hours ago

kees99 8 hours ago

Having a mix of both 2LD and 3LD registrations under the same TLD is a bit of a nightmare in terms of public-suffix list [0], which is kind of important thing when enrolling your domain for some services, cloudflare among them.

[0] https://publicsuffix.org/

altairprime 8 hours ago

Yeah, that’s why RFC 9989 replaced use of PSL with a dns signifier.

wlonkly 5 hours ago

echelon 12 hours ago

That would be so cool and would make these limited hot commodities.

.name was one of the very first expansions of gTLDs back in the very early 2000s. It's a shame that it's being shut down as it was spearheaded by the ICANN itself rather than some registrar / investor like Donuts, Inc.

I suppose this is impractical as someone has to run the registry and there are costs associated with that. But don't the domain fees cover it?

ajmurmann 11 hours ago

From having worked in that space what feels another lifetime ago, I vaguely recall that you can just offload the registry work to a registry that would manage this together with a mountain of other TLDs.

AtNightWeCode 11 hours ago

As I recall it. This was mostly a money scam that targeted private users with ads like "make sure to claim to your .name domain so no one else does it and use it to impersonate you". It was stupid from the beginning and never took off.

DrewADesign 7 hours ago

In the tech industry of yore, corporations having tech ecosystem stewardship duties was a quaint necessary evil to placate the developer crowd so you could hire them. Today, c-suites consider that indulgent soft-hearted hippie nonsense utterly gauche.

jl6 8 hours ago

I can only assume somebody was asleep on the job when this scheme was approved, because the outcome is in direct contradiction to ICANN’s mission statement:

> Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems.

https://www.icann.org/resources/pages/about-icann

Arbitrary termination of service is not stability.

Enabling name hijacking is not security.

The answer cannot be a rival name scheme based on decentralization or crypto or whatever. Those are never going to help normal non-wizard users. The answer has to be to make the regulators do their job.

TLDRisk 6 hours ago

It's been through the Ombuds and a reconsideration request [1]. ICANN says:

> There will not be any effect on the life cycle of domain names. While the Requestor may disagree with Verisign’s response, the Requestor has not shown that ICANN relied upon false or inaccurate material information. The life cycle of a domain name begins when the domain is registered, then moves through various stages before ultimately coming to a close. Early termination of a domain registration does not impact the life cycle of the domain, as the domain can still go through the various stages of a standard life cycle. Moreover, as stated above, ICANN was aware that discontinuation of these registry services in the .NAME gTLD would result in the termination of approximately 22,000 third-level domain registrations and of email services/addresses.

I don't agree. If I have a domain registered for 10 years the expected life cycle is for deletion to occur 10 years from now, not 90 days from now. They've changed the life cycle by changing the agreed upon deletion date for the current registration term.

I could maybe see if they stop accepting renewals and delete the domains as they expire. It's not a good look, but at least people are getting what they've been promised.

1. https://www.icann.org/resources/pages/reconsideration-26-2-s...

Calavar 5 hours ago

> Early termination of a domain registration does not impact the life cycle of the domain, as the domain can still go through the various stages of a standard life cycle.

According to ICANN cutting the life cycle short doesn't have any effect on the life cycle?

ICANN corruption is at the level of FIFA corruption.

disillusioned an hour ago

TZubiri 2 hours ago

bilkow 5 hours ago

Let's pretend it's OK for them to just drop your domain, ignoring the stability and security issues that arise from that (and how ICANN should prevent that, in theory).

How about the fact that you paid for a service for 10 years and they decided to stop providing it midway? Will you at least get a refund? If not, that's surely illegal right?

ALLTaken 6 hours ago

Sorry, I don't understand this rule, would someone kindly explain?

I own lastname.name and use it for email only like this: firstname@lastname.name

I always thought as owner of lastname.name, I'm the only one able to add subdomain.lastname.name. Is this wrong??

1) Can anyone "buy" scam.lastname.name without my authorization on .name??

2) Can anyone owning not.lastname.name then steal my emails going to: firstname@*.lastname.name or even firstname@lastname.name??

BUT: If someone ONLY bought not.lastname.name and doesn't own lastname.name, they'll get terminated. Would that be 'good' as it would stop 1) and 2) ??

I'm really concerned. My family is using first@lastname.name as the personal email, I'm hosting and paying for since many years.

judge2020 6 hours ago

> I always thought as owner of lastname.name, I'm the only one able to add subdomain.lastname.name. Is this wrong??

TFA mentions that `.name` was unique in that it sold a good amount of third-level domain names directly from the registry.

dvt 11 hours ago

I freaked out for a second because I've owned `dvt.name` for like 15 years. `.name` is not getting terminated, so it's important to be precise here. The third-level x.y.name (where you're the `x`) is getting terminated, and the respective `y.name` domains are going to be released.

Still a crappy thing for people, but it does not affect owned second-level domains.

wormius 11 hours ago

There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level.

But I didn't think about the 1st level competitors. There'd still need a mechanism to resolve that...

1. First come first serve? (e.g. whoever registered a y.name first, whether x is bob or sue is determined by the earliest registrant on record) 2. Lottery/random selection? 3. Bidding war?

I think the problem is 2nd level domains who have the same name will be a problem when they find out all these other 3rd level are now expiring and can run a route to spoof? Likely wouldn't happen, but with the fuckery in the DNS that can happen... This is such a rash and weird decision to push through so quickly just because engineers find it "easier" while ignoring the implications of the move, seemingly when it comes to larger scale security.

I assume there would have to be some method to prevent routing of third level domains to subdomains of two-levels... (or is that just me being a fool yet again, assuming we have competent administration of our systems).

p4bl0 8 hours ago

> There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level.

Yes. I've been asking VeriSign for this for years, and they always refused.

mulmen 9 hours ago

Or just honor the deal. The only reason for doing this is Verisign’s bottom line.

ShakataGaNai 7 hours ago

Yea. Super confused.

I have myname .name - so I thought that was going away. Granted I barely use it, but still it would be annoying. I didn't recall there were 3rd level domains there.

TZubiri 10 hours ago

I don't get the difference. If I acquire the y domain and make it work as a subdomain broker, it's the same thing no?

There is no subdomain/TLD bit

dvt 10 hours ago

You are technically correct, but Verisign billed buying an x subdomain as if the y domain was part of a stable infrastructure. Which it kind of was until they decided to pull the rug.

chuckadams 10 hours ago

TZubiri 2 hours ago

chuckadams 10 hours ago

The Public Suffix List is the closest thing we have to the "subdomain/TLD bit", but afaik it doesn't include wildcards like `*.name`. It does influence TLS though (or possibly just browsers) in that a wildcard cert for an entire TLD or public suffix won't be honored, nor will a public CA issue such a cert.

Still, I'm not sure there's any easy technical fix for the .name debacle.

TZubiri 2 hours ago

mhink 10 hours ago

From what it sounds like, unlike domains under other TLDs, when you purchase a domain under .name you always purchase specifically the three-segment domain.

i.e. I own john.doe.name, you own george.joe.name. Once this change goes through, only "doe.name" can be owned, so who gets it?

plorg 8 hours ago

nanolith 9 hours ago

This risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices used were entirely disconnected from domain names, and why the discovery protocol I put together did not rely on registered domains, but could use these as an untrusted part of discovery.

Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.

I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.

I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.

sciyoshi an hour ago

It's the same reason I was nervous moving our company domain to a .ai TLD; your entire presence, identity and trust is now beholden to the whims and political winds of a Caribbean island smaller than Topeka.

fh67 6 hours ago

Can you share how the discovery worked?

ACCount37 4 hours ago

"Online identity" seems like a castle built on quicksand in every single case.

What's your account tied to?

E-mail? That's usually on a mail server owned by someone else. If not, it's still on a domain owned by someone else.

Phone number? Definitely owned by someone else.

The only account that's reliably "yours" is one that asks for a login, a password, maybe a TOTP, and absolutely nothing else. Because everything else is introducing "things owned by a third party" into the equation.

akersten 13 hours ago

It kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.).

Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?

SahAssar 12 hours ago

.co.uk is run by the same people as .uk. There is no additional org that you trust when you register a .co.uk: https://en.wikipedia.org/wiki/.uk#Second-level_domains

> do browsers have a wildcard suffix list

Yes: https://publicsuffix.org/ and they have discussed this situation here: https://github.com/publicsuffix/list/issues/2306

akersten 12 hours ago

I know about the public suffix list - I was wondering about the wildcard specifically. In the very issue you linked to, as of 2025, it seems this was still unresolved...:

> We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't.

xg15 11 hours ago

SahAssar 11 hours ago

eloisant 12 hours ago

Yes, Japan does the same with .co.jp but also .ne.jp, ac.jp, etc.

adw 11 hours ago

joquarky 3 hours ago

Sure, it is right now. What if they decide to sell it off?

nneonneo 12 hours ago

Since neither smith.name nor the wildcard *.name appear in the Public Suffix List (https://publicsuffix.org/), browsers would likely allow any page on a *.smith.name domain to set cookies for .smith.name.

There was an effort to properly handle the .name 2LDs, but it was never resolved because there’s no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name: https://github.com/publicsuffix/list/issues/2306

So yes, this TLD’s setup is in fact pretty insane.

rwmj 11 hours ago

I think this says more about how the cookies security model is stupid. They should always have been scoped to the single, exact name they were set from and nothing else. Websites would have had to be designed a bit more thoughtfully.

xp84 10 hours ago

lxgr 11 hours ago

dgoldstein0 8 hours ago

quotemstr 11 hours ago

> no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name

And that's one reason why the public-ness of a hierarchy level belongs on a DNS record on that level and not some separately-distributed side list.

markhahn 11 hours ago

I'm always mystified why we haven't leveraged DNS.

I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP.

Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...

tptacek an hour ago

ambigious7777 7 hours ago

OkayPhysicist 12 hours ago

So, this kind of thing happens all the time, and there's the Public Suffix List for exactly this problem.

There would be no issue at all if Verisign, or maybe Global Name Registry, decided to stick to the 3rd level registrations exclusively. Problem is, the chucklefucks over there decided it was a good idea to also hand out 2nd level registrations. Those 2nd level registrations outnumber the 3rd level registrations by an order of magnitude, so the PSL decided to just let joe.smith.name and john.smith.name share cookies. Which, IMO, was not a good decision, but it is what it is.

orra 12 hours ago

Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.

traceroute66 12 hours ago

> Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.

Yup. The original statement was dangerous FUD which should be urgently corrected.

BHSPitMonkey 11 hours ago

indymike 10 hours ago

> It kind of seems like an insane TLD structure to begin with, right?

It's been around for years. I seem to remember this issue coming up around 2001 where originally .name was for third level registration (i.e. john.doe.name) and changed to second level it a few years later and caused some problems... https://publicsuffix.org/ talks about it in light of architectural limitations of domain names.

> can Joe set a cookie on all of .smith.name?

That can happen. I seem to remember ancient browsers made it so .name (and other non-generic TLDs) required three periods. I think country code domains and new generic TLDS caused the browsers to change it.

It's pretty screwed up, but a lot of the people with .name domains have had them for a very long time. Sad to see them all lose their identity online that way.

omnibrain 12 hours ago

About 20 year ago I registered {lastname}.name and have dozens third level domains below it. So there are "privately owned" second level domains under .name for quite some time...

Pxtl 12 hours ago

I'm working on same for my family since I want to properly degoogle a bit. One thing I think long term - if I give my kids first-name @ last name , that means that I forever hold power over their email. Which isn't great. But what's the alternative? Register one full domain name per kid? Even ignoring the cost, the ergonomics are awful.

Imho email is missing a feature for nameless email addresses for when somebody just buys their full name as a domain name. If I get "firstname-lastname.name", having the email be "firstname@firstname-lastname.name' kinda ruins it.

londons_explore 11 hours ago

skinfaxi 12 hours ago

kennywinker 11 hours ago

CodesInChaos 12 hours ago

Surprisingly the public suffix list doesn't list `*.name`. So they're indeed not properly isolated from each other.

https://publicsuffix.org/

edit: apparently not all second level domains in .name are public suffixes anymore, so a wildcard addition wouldn't be correct.

gpvos 11 hours ago

It wouldn't surprise me if that is (maybe even a large) part of the reason for this change.

xp84 10 hours ago

QuantumNomad_ 12 hours ago

Note that the posted link talks about .uk.co, which currently does not exist but I guess may have in the past. Where .co is the ccTLD of Colombia.

Different from .co.uk.

kevin_thibedeau 11 hours ago

Originally there was uk.co.orgname.

cpach 9 hours ago

zahllos 9 hours ago

In the UK Nominet (the UK domain namr registrar - nic.uk) only permitted 3rd domains - co.uk. org.uk, me.uk. then there were "prove your status" ones such as ltd.uk, plc.uk and ac.uk plus ones like gov.uk, mod.uk, sch.uk, nhs.uk etc.

.uk was opened up relatively recently.

eterm 9 hours ago

I own a .uk and it still feels weird not having something in-between.

dolmen 11 hours ago

.uk.co (mentioned in the blog) isn't .co.uk

pushcx 12 hours ago

It wasn't obviously wrong in 2001. .pro started with a similar structure around the same time.

Ekaros 10 hours ago

To me that sounds like reasonable structure. I hold that every single edu, gow and mil domains should be moved under respective ccTLDs. After this sort of move that doesn't seem unreasonable thing.

Pxtl 12 hours ago

Agree that the .name 3rd level domains are silly, disagree on .co.uk being a problem.

If .gov and .mil and .com make sense, then .gov.cc and .mil.cc and .com.cc make sense.

Of course, I think having more than one non-cc TLD was a mistake, but that's just me. If it makes sense to have topical TLDs for international and US institutions, it make sense to have national ones.

gpvos 11 hours ago

The 3rd level .name domains are the original ones. They didn't hand out 2nd level domains until three years after they started.

traceroute66 12 hours ago

> disagree on .co.uk being a problem

Nominet and therefore .co.uk has been around since 1996.

.co.uk is not going anywhere, and neither is Nominet.

The only "problem" is the original poster did not do their homework. I suspect they were inferring `uk.co` which is a completely different kettle of fish. The original poster should urgently correct their post.

arjie 12 hours ago

We were rescued from that dot org scam by the fact that ICANN is a California non profit. I wonder if the AG can lean on them again. This is an outrageous thing to do.

zamadatix 9 hours ago

MagicMoonlight was [dead]ed for not knowing what "dot org scam" refers to. Since I can't reply there right now and it's not reasonable to expect everyone to know what this refers to:

ICANN, a 501(c)(3), proposed to remove the price cap on .org registration, commonly used for non profits, so PIR, the 501(c)(3) registrar for .org, could then announce it planned to sell .org operations to private equity investment firm Ethos Capital.

Thankfully the overwhelming response caused the proposal to be scrapped.

NewJazz 8 hours ago

MM looks to be shadowbanned, I don't think anyone downed/flagged their comment.

shagie 7 hours ago

zamadatix 6 hours ago

donmcronald 9 hours ago

> ICANN is a California non profit

I wonder how long that'll last. If the regulators in Califonrnia keep forcing them to act in the public's interest, won't they just move to a more favorable jurisdiction?

NewJazz 8 hours ago

This crossed my mind too. At least such a move could serve as an indication to the international community that ICANN is not a good steward of name and number resources. If they're paying attention. I know our (the US) governance is full of crap like this.

patcon 9 hours ago

This is the comment I was looking for. Thank you

NAR8789 2 hours ago

@dang can you update the domain extraction logic for hn titles to include the 3rd level domain for .name domains? It's a little too poetically unfortunate that HN lists the domain on this article as `fraser.name`

dang an hour ago

Sure. We have this for countries, like "example.co.uk", so I made "name" be a country and it...just works (maybe).

You only get a first name and a last name and a .name though. You can't be robert.louis.stevenson.name - just louis.stevenson.name.

(Incidentally, this was a Claude suggestion. The change only took a couple minutes but figuring out what mechanism in the code could do this would have taken me a lot longer.)

projectileboy 7 hours ago

We keep expecting for-profit organizations to behave as governments. And this is an especially easy sell in the US, where government has been vilified for decades as part of a long propaganda game run by those who wish to privatize and steal those things which should rightfully exist in the public domain. But for-profit organizations, by design, will never ever ever behave in the public interest, and it’s foolish to expect otherwise. This is not a criticism of the author; this is a criticism of ICANN, and the subcontracting of governance.

crabmusket an hour ago

Amen to this. I don't know why we put up with this for infrastructure in particular.

sigbottle 12 hours ago

There's a DNS wizard at my job (not doing DNS stuff currently; but in his past life), and while he was talking to me about certain topics my eyes glazed over, and I thought, "Man, surely that won't affect me, right?"

Well, it's still not affecting me, personally, but wow, seeing articles like this makes it feel just a tiny bit more real.

aliasxneo 11 hours ago

This is why I am building DNTLS. These organizations no longer deserve our trust and they have inadvertently gained too much power over the last two decades of massive internet expansion. Names need to be fully owned by individuals and a shared, decentralized trust system must be in place for resolution. The more I see actions like this, the more convinced I am that a solution is long overdue.

theK 11 hours ago

Never heard of DNTLS, thanks for sharing. I skimmed the Website and am a bit uncertain what the ai angle is. Shouldnt naming be, well, just naming?

aliasxneo 11 hours ago

Yeah, the website is a holdover from when we were pitching AI VCs a few months ago. We quickly determined that the whole system is now "Cancer Capital" (see the other front page HN thread) and have pivoted to just bootstrapping from a close syndicate of like minded individuals. We plan to update the website this month, sorry it's a bit behind.

In short, AI identities were just a happy accident that comes with the system/architecture. It's not tied to AI at all.

But if anyone is interested in talking about what we're doing more, happy to connect at hn@sepositus.com.

xur17 10 hours ago

teravor 8 hours ago

the only real way to have a decentralized domain system is something like https://github.com/pubky/pkarr

but you lose the ability to have short domains.

also until such a time that pkarr is widely adopted, you are better off using .onion domains anyway. it becomes a question of requiring custom DNS client vs. Tor browser.

both approaches use a DHT.

delfinom 11 hours ago

There is already ENS.

aliasxneo 11 hours ago

The adoption has basically been non-existent. I have a lot of theories on where they've gone wrong. Being so heavily tied to a blockchain (Ethereum being the worst due to its state bloat) is probably the biggest mistake I think they made.

colordrops 11 hours ago

nubinetwork 13 hours ago

> Once the 3rd-level domains are terminated, it is assumed that the now vacant 2nd-level domains will become available for registration. Should someone (other than me) scoop up fraser.name (...)

What's to stop someone from doing that, and keeping the status quo? Sure, it might be expensive, but pool together a few frasers for the initial buy, and make the money back on the sublets.

bityard 11 hours ago

Well, nothing, but it does assume that Verisign doesn't have an unstated plan to do something else with .name. Domain registration is the real estate of the Internet and very little has happened in the last 30 years of domain name policy that has been for the benefit of anyone outside the the registrars.

For all we know, this is simply the first step in a series of moves for Verisign to better monetize the .name TLD in some novel fashion.

My evidence for this is that Verisign's own arguments for terminating the third-level domains are highly dubious. They claim that the third-level domains are too hard for them to manage. Bollocks: there are only 22,000 of them in use. That is a VERY small database that practically fits on a calculator and I refuse to believe that any manual labor around it is an outsized burden compared to pretty much any other semi-popular TLD. The second claim is that "the majority of those are not in use." Okay, if that's true, then where is the management burden coming from? That means tens of thousands of people are giving them money and getting nothing in return, isn't that the definition of an ideal business model?

It just doesn't pass the sniff test.

And finally, having read both of the linked documents, it sounds like people who have registered their .name for years in the future are not getting their money back. Are they likely to pay a second time, to a sub-registrar with no history?

xamde 10 hours ago

Also, someone managed to run all this 20 years ago. Has technology gotten so much worse? Is RAM now THAT expensive?

toast0 7 hours ago

theandrewbailey 12 hours ago

Depends on how much one trusts whoever's running fraser.name. Is it more or less than Verisign?

ZiiS 12 hours ago

You have to trust them and Verisign; which will always be less then just Verisign.

Y_Y 11 hours ago

jonhohle 10 hours ago

One of the reasons I stick with Big Email for my primary email is cases similar to this. If I host email and lose the domain one day, I’ve lost two factor on a thousand different services (the single factor on some). Big Email’s policy is to not reissue my address, should I lose it or die.

The .name scenario is even worse. One domain gives you access to tens of thousands of users email. It seems like a privacy nightmare.

I’m not sure how future auth and privacy will work, but my child lost a tracfone phone and some mixup had separated it from my account. There was no way to recover the number. If that was my personal phone, how difficult would it be to restore banking, medical, and government access to things that assume I’ll always have that number.

Doing the same with personal email seems like too big of a risk.

sunnybeetroot 10 hours ago

You can look through my history how many times I’ve brought this up to people and they just don’t seem to care. A defence is that they’ll buy the domain for a century and not care once they’re dead which is fair but the situation in this article is a valid one. I will always stick with Big Email for accounts.

famfamfam 10 hours ago

I moved to a third-level .name domain in 2005 precisely because one of the Big Email providers (Google) locked me out of my account with no recourse; presumably because I had a very common email address that was getting a large number of login attempts from other people which had triggered some abuse automation.

At the time - before the explosion of new gLTDs - third-level .name domains were advertised as the 'correct' domain to register for individuals wanting personal email addresses.

sandcat_ 2 hours ago

Your response seems to imply those people are irrational, but it's really just different priorities. Yeah, you need to make sure you don't lose the domain. With Google/etc, you need to make sure you don't break any of their usage policies across their suite of apps, etc. Neither are super likely to happen. Neither are impossible, either.

(Update: as it happens… https://news.ycombinator.com/item?id=49548452)

Personally I like having a custom domain as I like the idea of being able to move between providers. So far, over the past decade, I've hosted my email with Google, Fastmail, Hey.com and then Fastmail again. I like being able to move it around if I find one provider better than another. Others won't care, that's fine too.

drdexebtjl 10 hours ago

I don’t see the problem if you stick with .com or the ccTLD for the country you live in.

To me, the risk these registries screwing me over is smaller than Big Email deciding I broke their ToS and shutting down my account.

I wouldn’t use these novel TLDs either.

xp84 10 hours ago

By Big Email are you just referring to the biggest providers (e.g. Google and Microsoft)? or is there another meaning?

wiether 9 hours ago

If they're talking about Google or Microsoft, putting more trust in the worst tech companies than in the TLD of your country seems crazy to me.

ethanhawksley 9 hours ago

bluebarbet 9 hours ago

Came to the same conclusion. With primary email I do not need multiple points of failure. The optimal solution is a contractual - paid - relationship with a single reputable email provider. There are a bunch of them.

koeliga 9 hours ago

The risk of losing your big email account is higher than losing your domain. Furthermore, if you happen to lose your domain, it will in most cases be easier to recover than a restricted account.

DaiPlusPlus 7 hours ago

> if you happen to lose your domain, it will in most cases be easier to recover than a restricted account.

I used to think this, until I inadvertently let a registration fail to renew because I didn't update my expired credit-card's billing details with NameCheap - they did send me automated emails about it but I missed them, unfortunately. Their grace-period is only 30 days and I didn't notice the problem until 45 days had passed when my domain-name was bought-up by a spam-site-scammer and redirected the site to a porn/virus-downloader site (yes, those still exist).

I paid $1500 (uugghhh) for the UDRP process to get the domain-name back ($1000 UDRP fee, $500 for the lawyer to do the paperwork), and the UDRP panel ruled against me: their response reasoning made it clear that they never actually looked at my submitted evidence - and unfortunately that $1000 is nonrefundable, gaaaaah. I still haven't gotten that domain-name back. (I will say that my previous other UDRP cases all ruled in my favour; I don't know why/how I somehow drew a crappy arbiter in this case, I'm just vexed that they can rule against me without any right to appeal; I expected better).

noAnswer 4 hours ago

UltraSane 5 hours ago

one neat thing having your own domain lets you do is have ANY <string>@domainyouown be sent to your inbox so this gives you unlimited email aliases. I often prefix the SOURCE of the email, like toyota@domainIown

jonhohle an hour ago

I understand the advantages and have run email on my own domains for decades. Those aliases are used for business or partitioning senders. If they fail, my life goes on.

willwade 12 hours ago

I worked for .name briefly right at the beginning of their entry into the world. Interesting but very odd part of my career.. Ill give it that.. I personally found the product at first a great idea but somewhat crippled by execution..

wmf 12 hours ago

econ 10 hours ago

I don't like the way domains work in general. It's really quite expensive if you are wise enough to buy everything that looks to much like your website.

Did buy https://ycombinator.us

Didn't buy https://ycombinator.co.uk

https://ycombinator.de

What useful functionality is there in selling these domains?

Expiring domains is bad for the web and selling them to someone else is as terrible as the article makes it out to be.

zamadatix 9 hours ago

You're also never going to register e.g. xcombinator.* nor is that necessarily a domain which should never be sold on the basis it's similar to ycombinator.*. Rather than buy everything, buy the ones most likely to be accidentally entered for only the most common tlds so you can set up redirects or the like and then enforce and protect your trademark like you have to in any other situation.

jacobgkau 8 hours ago

> Expiring domains is bad for the web

Short-term, it might seem like it would make sense for domain registrations to be permanent, but long-term, it introduces at least two insurmountable problems:

1. Unless some other cleanup mechanism is in place, eventually (like, hundreds of years into the future) domains will need to get longer and longer as people who owned old ones disappear and new people need new ones.

2. The infrastructure costs (while nominal) to keep existing domains functioning would not be sustainable in perpetuity without relying on the assumption of more and more domains always being sold.

johnplatte 12 hours ago

Wow! Years ago I initially bought my firstname.lastname.name, then I let it expire and then bought lastname.name. So glad I did!

Never dreamed that such a supposedly durable thing would just disappear. How hard is it really to preserve a global resource like this that exists only in software?

ipython 13 hours ago

From the Verisign application [0] for this change:

    > 2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
    > None. There will not be any effect on the life cycle of domain names.
ehhh, how is that possibly true? This change (deleting all third level names) by definition affects the lifecycle of domain names ... by terminating them!

Many years ago I wrote articles bringing attention to the negative effects of Verisign's SiteFinder [1] - if you don't remember this, it's when Verisign hijacked NXDOMAIN by redirecting any unresolvable domain to a site they owned and controlled.

[0] https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2... [1] https://en.wikipedia.org/wiki/Site_Finder

semiquaver 9 hours ago

That document looks like the change tickets I see at work when investigating internal outages:

   Risk: none
   Rollback plan: N/A

politician 12 hours ago

"Well, it doesn't affect the lifecycle of domain names. The lifecycle is defined in some RFC somewhere, and this change doesn't modify that. Now, these particular domain name instances might be adversely affected, but you didn't ask about that." -- lawyers, probably.

donmcronald 9 hours ago

You're closer than you think. Big companies and institutions just change the definition of words they don't like. In this case, they could argue that a domain's lifecycle is registration, renewal (optional), deletion. Deletion is part of the expected lifecycle, so this doesn't change it.

The ambiguity is a feature so they can do whatever they want. We all know it's bullshit, but it gives the parties involved the ability to disenfranchise one group to benefit another while claiming they're following the rules.

donmcronald 7 hours ago

baylisscg 5 hours ago

What's wild is that when initially launched you could only register 3LD domains. If you were quick out the gate and registered one in 2002 and have been using 10 year renewals you're about to have a domain you've owned for almost a quarter century with 6 years left on its registration nuked.

decimalenough 12 hours ago

I've had a .name domain forever and I had no idea first.last.name was even a thing, meaning that it was possible to register this without owning last.name.

That said, my domain is simply unusual.name, and everybody in my family has email addresses in the form first@unusual.name. So this is a no-op for me, and I gather www.unusual.name will also continue to work, since I own the 2nd level outright.

NelsonMinar 12 hours ago

I'm sure Verisign would be thrilled to have a bidding war between the legitimate owners of fraser.name and a bunch of third parties they suddenly enabled.

febusravenga 12 hours ago

This is silly question, but is your family managing trust in you as lone guy - cousin, father, brother - having potentially access to all their emails?

I feel that I more trust some corpo (Google, etc) that one particular person.

I don't imagine setup where you can effictevely guarantee them full privacy.

decimalenough 12 hours ago

I don't store their emails, I use forwardemail.net and they have a pretty reasonable privacy policy: https://forwardemail.net/en/privacy

Some people in my family use it as their main address, others don't, it's entirely their call.

But yes, ultimately I control the domain and could be nefarious if I wanted to. But there's a certain baseline level of trust as a family, I'm reasonably certain my wife won't poison the milk in the fridge and she's reasonably certain I'm not going to read her emails.

sunnybeetroot 10 hours ago

cesarb 11 hours ago

> This is silly question, but is your family managing trust in you as lone guy - cousin, father, brother - having potentially access to all their emails?

I believe this is a very common setup: the "computer wizard" kid of the family manages the computers for the whole family. Not just emails, they have access to the whole computer (and have to fix when it breaks).

bityard 10 hours ago

I manage the email accounts for the others in my household because it's free for them and I'm happy to do it. Plus, they trust me more than they trust a random tech company. Maybe that is not a universal thing among all families or parts of the world.

sunnybeetroot 10 hours ago

vidarh 12 hours ago

It was deemphasized pretty early because people didn't understand it.

It made sense to us because our starting point was an email service letting people share lastname.sometld, but we never got close to as many registrants on .name as we had users on the webmail service (we had a couple of million accounts on that when it was sold to one of Marc Cubans companies for a relative pittance in the aftmath of the dot com bubble bursting)

anominal 11 hours ago

I am also one of the 22,000 people who have a third-level .name domain and I am livid about this, not least because Verisign flat-out lied in their proposal to ICANN: (https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2...) :

"2.1. What effect, if any, will the proposed service have on the life cycle of domain names? None. There will not be any effect on the life cycle of domain names.

...

2.3. Explain how the proposed service will affect the throughput, response time, consistency or coherence of responses to Internet servers or end systems. There will be no effect on the throughput, response time, consistency or coherence of responses to Internet servers or end systems."

My registrar is also suggesting that they are going to just keep the money I pre-paid for years of registration, which is a minor annoyance compared to the loss of my entire online identity but an annoyance nonetheless.

Since ICANN is a non-profit that is required to operate in the public interest I do hope there can be some pushback on this. I will be writing to the CA AG myself.

xyzzy_plugh 13 hours ago

> Despite the fact that it's registered and paid for until 2040

How is this possible? I thought there was a 10 year limit.

elashri 13 hours ago

I think it was figure of speech. The domain is registered until 2036

> Registry Expiration: 2036-01-29 00:00:00 UTC Updated: 2026-09-03 08:12:27 UTC Created: 2002-01-23 14:41:45 UTC

leni536 10 hours ago

Will they get a refund?

swiftcoder 13 hours ago

it's probably a 10 year registration, plus a pre-paid renewal at the registrar

chanux 12 hours ago

I kind of assumed .name was a product of relatively new TLD explosion [1]

[1] https://blog.asmartbear.com/free-markets-bad/

Gotta wonder what other possible disasters introduced with gTLDs.

vidarh 12 hours ago

No, we were in fact part of the very first batch of "new" TLDs

padjo 10 hours ago

Who is running the show over at ICANN? How can this possibly be a reasonable thing for a registrar to do?

xp84 10 hours ago

I don't think it's hyperbolic to say that this is the most careless, disruptive change to anything to do with DNS or internet names I have ever seen.

> "will increase efficiency for the operation of the .name TLD."

What a preposterous excuse -- especially for something already up and running. Sounds like they probably want to change the backend in some way - or adopt some kind of off-the-shelf software - which doesn't jive so well with this unique TLD, and they figure "Ehh, fuck 'em, let's just pull the plug on these tens of thousands of people."

sandcat_ 2 hours ago

Agreed. If you don't want to care about backwards compatibility, there's plenty of space for you in tech. Just not at a domain registry!!

TLDRisk 10 hours ago

I thought I knew a lot about the policies and expectations when it comes to domains. I was surprised to see 3rd level domains called out in the .name registry agreement and I’m stunned that ICANN allowed this.

It’s incredibly one sided. The registry gets to cut costs and the detriment to registrants is extreme. ICANN is supposed to act on behalf of all participants.

The flagrant disregard for DNS stability in this case is jaw dropping.

mchesters 13 hours ago

Wow, they were extremely laziest in the request form too. Most answers are just a few words.

  > 3.6. Have you communicated with any of the entities whose products or services might be affected...
  > "No. Not applicable."

mchesters 13 hours ago

Seriously.

  > 7.3. Provide any other relevant information to include with the request. If none, respond with “N/A.”
  > None.

fetzu 12 hours ago

Also note that their response is the exact length of the shortest allowed one, and yet still wrong.

chrismorgan 12 hours ago

chrismorgan 12 hours ago

I think the “not applicable” is to the elided second sentence of the question:

> 3.6. Have you communicated with any of the entities whose products or services might be affected by the introduction of your proposed service? [→ No.] If so, please describe the communications. [→ Not applicable.]

Gotta say that the entire form feels not applicable. The proposed service is the discontinuation of an existing service. I see from their website that other similar things do the same, but it feels broken when so many of the questions become nonsense.

wmf 12 hours ago

This is how you fill out an application when you know it's going to be rubber-stamped.

xp84 10 hours ago

Bingo. They just do whatever they want, and cash our checks.

jacobgkau 8 hours ago

I caught this one:

> 2.1. What effect, if any, will the proposed service have on the life cycle of domain names?

> None. There will not be any effect on the life cycle of domain names.

If they're dropping existing domain names, that seems like it has an effect on the life cycle of those domain names. I suspect I must be misunderstanding what they mean by that question, because it otherwise seems like it shouldn't have passed basic muster.

MadameMinty 13 hours ago

The nerve.

noja 13 hours ago

ICANN approved this.

Glyptodon 8 hours ago

It's kind of crazy to me that the whole domain was originally set up so that people would buy 2nd and 3rd level pairs. But it also seems really obvious that backtracking is going to be a disaster.

cpach 9 hours ago

Ouch.

IMHO, this whole TLD seems kind of messed up from the start: https://en.wikipedia.org/wiki/.name

thbb123 5 hours ago

Wtf, I have been using my x.y.name domain for everything, haven't been notified of this.

Should I rush to reserve y.name so my email address and personal website can stay online?

kronodeus 5 hours ago

Based on my understanding of the situation, the 2LDs are getting sold, so yes, you should try to acquire the 2LD if you want to retain control of your subdomain(s).

Ecco 13 hours ago

Ok I don’t get it. Why not register `fraser.nameˋ directly? Or pick any TLD and register ˋ a 2nd-level domain (ˋfraser.tld`)? It just feels easier, plus this way you don’t have to pay for any new member of your family?

djoldman 12 hours ago

If aaa.bbb.name is registered, then bbb.name cannot be registered.

bbb.name can ONLY be registered if it is not already registered AND there are no 3rd levels registered on bbb.name currently.

https://manage.whois.com/kb/servlet/KBServlet/faq1485.html

echoangle 12 hours ago

> Or pick any TLD and register ˋ a 2nd-level domain (ˋfraser.tld`)?

How would that help? The problem is that he's losing access to all the accounts currently tied to fraser.name, if he is changing that he can just use any arbitrary domain anyways.

Ecco 12 hours ago

I mean in the first place. Now it's too late indeed.

Aachen 11 hours ago

orra 13 hours ago

There will other people with the Fraser surname in the exact same position.

e_l 12 hours ago

Because only one lucky person can own `fraser.name` at any one time in your model. And whilst that lucky person might be able to register their family members for free. There will be countless more (unrelated) Frasers who won't be able to register (even for money) their own `FIRST.fraser.name`.

So the argument goes, society as a whole gains more if we prevent anyone from owning `fraser.name`.

A legitimate alternative though, is to register `FIRST-fraser.name`

p4bl0 12 hours ago

At the beginning of the existence of the .name TLD you couldn't do that, you were forced to register firstname.lastname.name and provide an ID to justify registering this specific domain.

With it you got an email redirection from firstname@lastname.name to the address of your choice. At some point this feature was discontinued (I assume when VeriSign took control of the .name TLD), a bit after it was decided (again by VeriSign) to allow registering first level .name domain. My main email address stopped working from one day to another without me being warned in any way.

When this happened I've emailed VeriSign and my registrar at the time, and tried several time since then, to be able to register the first level domain I'm the only one using, but they categorically refuse, despite recognizing that a single subdomain has ever been registered. They kept saying that I could just let the domain expire, wait for the grace period, and register it once it's liberated, hoping that no one does it before me, and without any solution for the downtime in the mean time…

And now this… fuck VeriSign -_-

antif 12 hours ago

This really sounds like VeriSign has no business owning .name … best possible outcome would be transferring it to somebody who will retain the originally intended services.

ZiiS 12 hours ago

xp84 10 hours ago

What a perfect example of the sort of fuckery Verisign would do. You have the simplest use case and they can't even help you transition onto the scheme THEY WANT everyone to use now.

anominal 11 hours ago

The firstname@lastname.name email forwarding is still working for me. I think only some registrars support it, though.

p4bl0 9 hours ago

NewJazz 13 hours ago

You might want to write to the CA attorney general. Former AG Xavier Becerra was able to dissuade ICANN from letting the .org fuckery happen, maybe Bonta could try to strong arm ICANN in this case.

qrobit 12 hours ago

What was the deal with .org?

EDIT: seems like Ethos Capital private equity firm wanted the .org registry, and Xavier Becerra (Attorney General of California at the time) wrote a letter that played major role in transaction being rejected

> Dear Messrs. Botterman and Marby:

>

> I urge ICANN to reject the transfer of control over the .ORG registry to Ethos Capital.

> The proposed transfer raises serious concerns that cannot be overlooked.

(from https://itp.cdn.icann.org/en/files/correspondence/becerra-to...)

NewJazz 11 hours ago

Thanks yeah was too lazy to go searching for a link.

Apocryphon 12 hours ago

I wonder which tech nonprofit would be best to champion this cause. Doesn't seem quite the EFF's domain.

ClarityJones 11 hours ago

If this proves to be a viable business strategy, then verisign could equally use it to re-sell google.com, ycombinator.com, etc. to the highest bidder.

lacoolj 11 hours ago

Dude, this is one of the craziest things I think I've read on HN

First, that a legit dealer could/did(does?) sell third-level domains at all (Verisign, no less) Second, that the top-level is staying available, allowing for second-levels to be bought/sniped like you mention.

If you do lawyer up and need help with legal fees, I think this would be a worthy cause.

doublepg23 13 hours ago

I didn't even know I was using .name incorrectly...

niraj-agarwal 6 hours ago

22,000 people affected. Link up and lawyer up is right. To have identity and existence taken away is a no go.

morissette 8 hours ago

It seems as if only 40 people are needed for a class action suit. Me, not a lawyer. Gemini says chances are you could only get a refund. But maybe worth the fight for some.

xbar 6 hours ago

I can only assume ICANN was co-opted by Verisign some decades ago.

aeternum 12 hours ago

How would the avg person know that ..name is different and somehow more trustworthy than ..uk

Overall this seems like the right move, either they all are trusted or none.

akulbe 10 hours ago

I don't get the concept of 3LD. We own kulbe.name - does this news mean it's going to go away entirely?

aff-vasileva 10 hours ago

Turns out “buying your name on the internet” was technically just renting a room in someone else’s last name.

mzajc 9 hours ago

In this case the registry itself (Verisign) was the owner of the second-level domain, and they most certainly shouldn't be allowed to just drop your registration whenever they please.

Maxforever 2 hours ago

I saw it

marbleotter115 8 hours ago

.name is the part I keep having to relearn, so seeing it spelled out helps.

delduca 12 hours ago

I never bet in any other than .com, .org, .net?

CodesInChaos 12 hours ago

.org almost got screwed in 2019 too:

> In April 2019, ICANN proposed an end to the price cap of .org domains and effectively removed it in July in spite of having received 3,252 opposing comments and only six in favor. A few months later, the owner of the domain, the Public Interest Registry, proposed to sell the domain to investment firm Ethos Capital. After intense criticism from nonprofit groups and significant figures in Internet history, the proposal was scrapped.

Surprisingly not by Verisign, who gave up .org in 2003.

r_lee 11 hours ago

I love that name, "Ethos Capital", it's so wholesome

it'd fit like a PE firm focusing on chemical weapons

jeroenhd 11 hours ago

Those are all controlled by companies in and subject to the demands of the USA, which has been proving for many years that they cannot be trusted.

Also, all common names with any of those prefixes have been registered a long time ago.

basilikum 6 hours ago

I seriously wonder what ICANN is good for.

jmuguy 12 hours ago

I can't be the only one that assumed based on the domain that this was some bizarre DMCA action by Paramount.

Aachen 11 hours ago

What does Paramount have to do with the last name Frazer?

mig4ng 10 hours ago

And that kids is why it's always DNS fault.

Again, you're security is only as strong as your DNS.

r_lee 11 hours ago

I would not use a 2nd level tld for a "stable presence". it seems like a gimmick

cjjuice 12 hours ago

I really think ENS is on to something with blockchain based domain registration and management

Aachen 11 hours ago

Family of ESR or who is this?

Henchman21 11 hours ago

How is it that they can just nullify the contracts they had with people they were providing services for?

TZubiri 3 hours ago

https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2...

>2.1. What effect, if any, will the proposed service have on the life cycle of domain names?

>None. There will not be any effect on the life cycle of domain names.

>2.2. Does the proposed service alter the storage and input of Registry Data?

>No. There will not be an alteration to the storage and input of Registry Data.

This sounds wrong? Is this just a knee-jerk form-filler reaction? It seems to me that the admitted "Upon discontinuation, no new third level domain names will be registered and existing third level domain names will be terminated."

In general this sounds like a grotesque misplay that is wildly uncharacteristic for the entity behind the timeless .com

swiftcoder 13 hours ago

That's pretty shit. You'd think changes like this would need to go through a public comment period with the affected users (much like city planning decisions do)

xyst 13 hours ago

Verisign is the worst. Hope author wins

xiaoyu2006 13 hours ago

May I ask what is wrong with Verisign?

DaSHacka 12 hours ago

Well, the post in OP is a good start

gpvos 12 hours ago

They have been generally scummy throughout their existence. https://en.wikipedia.org/wiki/Verisign#Controversies is a good start.

johnnyApplePRNG 10 hours ago

They deserve to lose their control of all domains over this.

This is ridiculous.

underdeserver 11 hours ago

dang and team, perhaps it makes sense to special-case .name domains in the domain hint, like you do for GitHub and Ex-Twitter.

aidenn0 5 hours ago

Per TFA, that won't be necessary for much longer.

bix6 12 hours ago

Fuck verasign. TLDs should be run as an actual public utility. Can these economic parasites be expelled already…

bawolff 11 hours ago

I feel like TLDs as a concept are more trouble than they are worth. We should just have .com and get rid of the rest (except special purpose tlds).

1970-01-01 12 hours ago

Instead of giving up, why can't all 22k .name owners move on to OpenNIC? They will not say no, you can't have that.

notahacker 11 hours ago

The ability to register fraser.geek so a very small number of OpenNIC users can access that new URL doesn't really solve the OP's problem with his family's long-established URLs disappearing and their emails being directed to whichever scammer buys up the fraser.name domain.

1970-01-01 11 hours ago

That isn't the correct problem. The 3rd level domain is going away, which can be reconqured via OpenNIC and mass re-adoption. There will surely be new problems, but owning will not be among those problems.

Macha 10 hours ago

0xbadcafebee 8 hours ago

Prediction: In 20 years, ICANN, IANA, ARIN become increasingly abandoned by nations wary of The Imperialist States of America's control over global communication & commerce, and the internet becomes an uber-net of nationalist internets, subverted by satellites.

khalic 11 hours ago

Ah! verisign! Proving the world over and over what kind of scum they are

TZubiri 10 hours ago

I wonder if this could constitute a violationiof article 6 of the UN declaration of human rights.

It has been established that national identifiers are protected by it, and a domain works as a sort of international identifier, in this case a personal one.

No one is obligated to give you a domain, but by contracting an obligation to provide that identifier until 2040, they would at least be liable for those damages, but there's an argument that depriving you of an identifier already granted is a more fundamental violation of a right to a name, an identifier and recordkeeping of them.

AtNightWeCode 11 hours ago

Things like this happens from time to time and yet people insists on using stupid TLD:s just because of "cool" suffixes.

psychoslave 12 hours ago

Breaking trust, one TLD at a time.

So, where is our fully decentralized TLD alternative, free of ICANN or any central authority to handle how we grant names by conventions, without any money scheme in the game that attracts malevolent actors moving only through greed strings?

Also, this time let’s make it like usenet, so "person:named:Neil Fraser" or even "::Neil Fraser" (harder to type but less culturally entangled into English).

toast0 12 hours ago

> So, where is our fully decentralized TLD alternative, free of ICANN or any central authority to handle how we grant names by conventions, without any money scheme in the game that attracts malevolent actors moving only through greed strings?

We can all edit our hosts file.

The problem with a lack of a central authority is domain names are most useful if they follow the highlander principle. There can only be one neil.fraser.name ... otherwise it's not usable for routing traffic if every webserver a Neil Fraser runs uses that address. (Yes, there are useful ways for one name to resolve to different webservers, but almost always those are webservers under at least loose control of a single entity or very exceptional cases)

CodesInChaos 12 hours ago

Namecoin (.bit) was an attempt to create naming system without a central authority using a blockchain.

But from what I remember, they fucked up the pricing function and it got overrun by domain grabbers.

eleventen 13 hours ago

> Minutes after my daughter was born, I also registered beverly.fraser.name.

...minutes?

Evidlo 13 hours ago

Don't want to get scooped by GoDaddy when they hear the good news.

cxr 12 hours ago

Consider whether you'd be questioning this if the author had written that within minutes of his daughter being born, her photo was on Facebook. The only thing it suffers from is not being normalized and taking marginally more* effort, while being nowhere nearly as creepy.

* or arguably the same amount or less; for additional context: the author is an ex-Googler

kotaKat 13 hours ago

To be faiiiir, when your partner is absolutely zonked out in the minutes post-delivery, what else is there to do when you're by their side and still half-asleep? Time to start announcing your pride and joy to the world, starting with a domain zone file.

gpvos 12 hours ago

I even suspect that the name of the child was dependent on the domain name being free... but then, it shouldn't be too hard to set up the request in advance and just press the button once the child is born. Maybe there was some rule that names could only be registered for living (i.e., born) persons?

rationalist 11 hours ago

Maybe they wanted the Created Date for the domain to match the birth date.

cpach 8 hours ago

And maybe she was born like five minutes before midnight, so he couldn’t just wait an hour or two (:

xp84 9 hours ago

That's actually really cute.

advisedwang 12 hours ago

Pretty crazy to be focused on anything other than your immediate family in after a birth... but not exactly unprecedented when you look at social media posts!

ipython 13 hours ago

I mean, you've already had 10 months to come up with some name ideas. It's not like it's a huge surprise when it happens. You could even register the names before they're born.

buzzy_hacker 12 hours ago

I registered a domain name for my son the day he was born...

  whois firstlast.com | grep 'Creation Date'
shows his birthday, which I found amusing!

Aachen 11 hours ago

echoangle 12 hours ago

I thought there might have been a need to send an ID to prove that you actually have the name you're registering for so you would need to wait for the birth certificate but from wikipedia it doesn't seem like that's the case.

alaithea 12 hours ago

layer8 13 hours ago

He didn’t say how many minutes.

mcmcmc 12 hours ago

Presumably less than 60

tasty_freeze 13 hours ago

It was more than one minute.

xiaoyu2006 13 hours ago

just a figure of speech

bossyTeacher 12 hours ago

Priorities. /s

notorandit 10 hours ago

It's just money. Nothing else. Just money.

rburhum 10 hours ago

Lawyer up and fight it. This is bs.

nikanj 11 hours ago

I wrote to ICANN support and got a template-AI answer wholly unrelated to my complaint about this:

”Greetings from ICANN Global Support.

I am sorry to hear you are experiencing this domain access issue after your registrar's transfer. I will happy to provide you with relevant information and guidance.

Please note that, ICANN accredits companies as domain name registrars and works to ensure contractual compliance with the terms and conditions of the 2009 and 2013 Registrar Accreditation Agreements (RAAs).

ICANN does not provide domain name registration or manage domain accounts. As a result of that ICANN is not able to perform domain management for you.

If you need help to access and manage your domain, you will need to contact your domain service provider or registrar for assistance.

You may check who your registrar is by doing a domain search at lookup.icann.org.”

Absolutely infuriating

strenholme 10 hours ago

The correct way to handle this mess is to simply keep things messy. BGP tables are a big mess, for example, because a lot of companies keep their IPs when going from ISP to ISP.

But, assuming that Verisign can’t keep third level domains (as a DNS implementer, I don’t think third level domains is a huge deal; see thread below):

* Third level names where only one person has the second level domain should be transferred to whoever owns that single third level name.

* Third level names where multiple people have the same second level domain should be put up for closed bidding: Only current owners of .name domains with a given second level domain name (e.g. last name) will be able to bid for the second-level domain. So, if one has john.smith.name and joe.smith.name, Joe Smith and John Smith will be in a bidding war for smith.name.

If the issue of .name not being in public suffix is a real issue, Verisign can handle that by disabling new third-level .name registrations, and provide Public Suffix with a list of those registrations (just send all the owners a privacy notice, making it clear that the existence of the name will be made public for security reasons). More reading: https://github.com/publicsuffix/list/issues/2306 (There seems to be issues with this list being too long to keep in the Public Suffix because there’s too much software out there which can’t handle it. That seems strange to me: Even here in 2026 where RAM costs far too much, Deadwood can store a list of 240,000 blacklisted entries in under 10 megs; there are about 22,000 three-level .name domains and I could store that list in a way that could be very quickly looked up in about a meg of memory)

Now, personally, I think Verisign can keep these messy third level names, and are doing things this way so that Neil Fraser has to compete with every single 2-bit cybersquatter out there for the rights to fraser.name.

As an aside, it’s trivial to have DNS servers handle multi-level domains without having to have a zone file for every level; e.g. https://this.is.a.long.name.maradns.org works, and there’s no zone file for name.maradns.org, long.name.maradns.org, a.long.name.maradns.org, and so on.

Also, since people have brought up the “org fuckery” without providing details: https://bluecatnetworks.com/press/the-org-domain-sale-explai...

You know dang well if .org was owned by an investment entity, they would had jacked up the prices as much as they could get away with.

xp84 9 hours ago

The auction plan is gross. It is unfair to say "This thing you thought you were buying the right to exclusively control (subject to continued renewal payments)? We're gonna transfer it next week to whichever Fraser pays us the most. Happy bidding!" It wouldn't be any more fair to do that than to announce to all .com owners that there will now be an auction between them and everyone who ever typed that name into a search at the registrar.

What they should do, is nothing.

strenholme 9 hours ago

I agree.

As a DNS implementer, the action plan is unnecessary. There are, what, only 22,000 or so .name domains. One can write code to do two lookups for firstname.lastname.name: If firstname.lastname.name is found, return the NS delegation. Otherwise, if lastname.name is found, return that NS delegation. Finally, if neither is found, return NXDOMAIN.

One argument is that this is hard to implement in the real world (it’s about one day, at most one week for a skilled DNS developer to pull off; probably half a day to be honest, and yes I have written code like this), so then yeah if that’s a real concern let’s have a closed auction. I’m opposed to the auction, based on my experience that this isn’t hard to implement.

If it’s an issue, just stop all new firstname.lastname.name registrations, and only allow lastname.name new registrations. Then we only need to deal with this corner case for about 22,000 domains, which we can keep in a special hash and would take about four megs to store.

xp84 4 hours ago

pmdr 12 hours ago

> I had history with Verisign and did not trust them.

I don't know what that history is, but did it really make a tld used by only 22k people more appealing?

decimalenough 12 hours ago

That's 22k people with third level domains like first.last.name. There are close to 100,000 second level last.name registrations, which are not going anywhere.

https://www.icann.org/resources/pages/name-2014-03-03-en

cormorant 12 hours ago

According to Wikipedia, "Verisign was the outsourced operator for .name since the .name launch in 2002". That makes the reasoning yet more puzzling.

swiftcoder 12 hours ago

They ran the backend services, but didn't set the policies (until they acquired the operator in 2008-2009)

drnick1 12 hours ago

> Second, my email address also disappears. Third, all the IoT devices that use services on this domain become bricks. Basically, I disappear from the Internet.

While changing email is inconvenient, I don't understand the point about IoT devices. IoT devices should not depend on the Internet at all for obvious privacy and security reasons. If you are using IoT devices with "cloud" accounts, then this is a blessing in disguise. Put that garbage in the trash and rebuild around HomeAssistant, Zigbee, RTSP, etc. I find it hard to believe that someone hosting their own website would fall for the cloud IoT scam.

jmuguy 12 hours ago

Plenty of people and businesses have their own (DIY, etc) devices that need to use DNS. I mean it wouldn't really be the internet of things, if it didn't actually use the internet...

For instance, I own a .house domain that I use for a bunch of stuff that I've programmed. It would be a pain in the ass to go change that domain out. Now take that to next level and you're a business that's deployed a few thousand devices that need to call home.

I guess all this is to say - IoT doesn't just mean cheap botnet honeypot IP cameras. Take a look at https://www.balena.io/cloud for instance

drnick1 12 hours ago

"Internet" in this context usually means IP, and in any case it should be restricted to a LAN. If you actually own the device changing the domain or IP should be trivial, I don't think this is what the article refers to.

Sharlin 12 hours ago

It's dubious whether the Internet of Things was ever a good idea in any sense. Especially given how, famously, the "S" in "IoT" stands for security.

rahimnathwani 12 hours ago

He didn't say his IoT devices relied on 'cloud' accounts. He said there are IoT that use services on this domain.

Imagine he's set up some IoT devices at his parents' home, and those devices use services that he hosts somewhere on the internet. It would be silly to hard code the IP addresses in there, right (unless he operates his own ASN)? So he would use DNS to allow those devices to find his server(s). This would be the case whether the servers are at his home, at his office, or in a rack at a data centre.

monkeyfacebag 12 hours ago

It sounds to me like you understand the point perfectly well, you just cared to make a different point.

jawns 12 hours ago

Surely the author must have anticipated some heightened level of risk in pegging important parts of his personal and business life on a nonstandard TLD like this.

It's a pretty bizarre exception to the normal, intuitive ways that domains work.

I'll admit that it's a crappy situation and I would be frustrated in his place. But if I were in his place, I probably would have also thought it prudent to have a backup plan.

userbinator an hour ago

Anything other than .com, .net, .org, and well-known ccTLDs I see in search results subconsciously get skipped over as "probably SEO spam or other useless content". These new weird TLDs are like the .tk and .us of old.

swiftcoder 12 hours ago

> nonstandard TLD

What exactly is non-standard about an ICANN-approved TLD? Yes, the multi-level structure is a little odd, but given that ICANN approved it in the first place, one has a reasonable expectation that they would work as advertised.

jawns 12 hours ago

I have a .science domain and a .com domain.

Even though .science was launched in 2014 (more than a decade ago), I still consider it a non-standard TLD and still deal regularly with difficulties around its use. (For instance, you wouldn't believe how many online services reject email addresses than end in .science because they use regexes that exclude TLDs with 7 letters.)

Likewise, I've registered .lol and .fun domains but never would have assumed that just because they're available now, they will be available in perpetuity.

In that sense, .name as a third-level TLD is even more non-standard, because the standard way domain registration works is by choosing a single "second level" domain name, then adding subdomains.

angoragoats 11 hours ago

efreak 8 hours ago

zamadatix 9 hours ago

Non-standard as in "it's not up to my usual standards" not "is not part of a technical standard". I.e. it's a gTLD rather than a "standard" (in the previous sense) TLD.

avazhi 11 hours ago

> What exactly is non-standard about an ICANN-approved TLD?

Uh, 99% of people would assume a .name address is a scam. Hate to break it to you.

swiftcoder 8 hours ago

angoragoats 12 hours ago

.name is in no way a "nonstandard TLD." It has been in existence for a quarter of a century and was part of the first batch of new gTLDs approved after the dot-com boom had begun, in 2000.

For the first couple of years of .name's existence, it only allowed registration of third-level domains, and the ability to register second-level domains was added later (and only if no third-level domains existed for that second-level domain).

The author is in no way at fault here, and I don't think I would have assumed there was a heightened level of risk if I were him.