FR version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
52% Positive
Analyzed from 1759 words in the discussion.
Trending Topics
#domain#should#don#registrars#system#domains#more#industry#need#seems

Discussion (28 Comments)Read Original on HackerNews
https://view.officeapps.live.com/op/view.aspx?src=https%3A%2...
> The community should instead consider whether contractual and operational arrangements adequately enable registries and registrars...
Those are things that are easy to say and hard to do. From the perspective of a good faith registrant, the enforcement is already too complex. There are hundreds of registries and thousands of registrars, all enforcing their own interpretation of the rules, so you end up with massive inconsistency.
No one wants their 10+ year old domain revoked for DNS abuse if they've been the victim of a security incident and it got misused, but dealing with that is hard and the economic structure of the industry isn't conducive to "intelligent" handling of complaints. Any solutions will scale the same as big tech with massive, automated systems that turn good faith participants into collateral damage.
A big problem for the domain industry is the way registries are shielded from liability and registrants. The registrars operate on thin margins and take on all the liability and customer support.
I don't think the registries will be given more responsibility. That's based on a personal bias though. I think the industry is set up to benefit the registries at the expense of registrars and registrants.
The registrars are the most likely party to be saddled with extra responsibility and I don't think that's a good solution because they have an economic incentive to look the other way. It's also a weakest link industry so, even if Porkbun, etc. are working overtime to keep bad actors off their platform, there's always someone willing to onboard a scammer for a few dollars.
In my opinion, there should be more talk about a centralized system funded by fees that ICANN collects. As a good faith registrant I want consistent, well defined rules with an appeals process, transparency etc.. I also don't care if I have to pay an extra dollar or two a year for my domains if it improves the industry overall.
Semi-related, does anyone know if there are any lists or decent sources for finding domains that have previously been suspended or put on block lists? That would be useful info for would-be registrants. No one wants to get surprised with a tainted domain.
Stats about the block list are good (10% of gtld domains are blocked) but thay requires comparing it with a baseline. How many of non gtld domains are blocked?
Yeah, I wondered about that too. Any young people I know can barely tell you what a domain is. They're not directly visiting websites AFAIK and I don't think any of the platforms require a domain to participate.
> 9% experience online sexual extortion before the age of 18
That's an astronomical number and I'd assume it has to be an overall total. I hate those kinds of statistics because they're not telling you what you really need to know to make an informed decision. What's the percentage that involved a gTLD?
To me, this smells a bit like another effort at usurping control of the flow of information. Domains are an incredible tool for independence and the fact they've been co-opted by bad actors provides a great opportunity for a select few to seize control over what we're allowed to do with them :-(
They've made no effort to give normal participants an edge over the scammers and jump straight to censorship / control.
For example, consider that person on here with 'web.one' the other day. Why doesn't their expensive, premium domain include an increased level of trust and reputation?
If they want to do KYC, I think that's fine, but it should be an opt in system like the old EV certificates used to be. I don't need KYC and a bunch of controls to self-host things that no one else uses.
The problem with EV certificates is they became a money printing scam for the CAs. Plus, and this is an opinion, I think the platforms like Google and Facebook went out of their way to kill EV because damaging a trust indicator for domains benefits them when there are scams everywhere (as we're seeing now) and people need the platforms to "protect them" rather than having a fundamental understanding of how to evaluate risks on their own.
These days especially it seems like nearly every measure relating to "cybersecurity" or regulation in the online space in any way is always hitching itself loudly to some form of child sex abuse - I don't blame these various lobbyists for trying, since it's obviously a winning formula. Bring up a universally loathed offense, explain that your new scheme is somehow "needed" to cut down on it, then shout down your opposition as "soft on child abuse."
It's the playbook used in 2001 when it was The Terrorists. I suspect that since moral relativism has resulted in many people being unsure if even the sickest terrorists, who behead their prisoners on camera with a dull sword, might actually just be misunderstood freedom-fighters, now there's a new favorite bogeyman, this one more resistant to political reframing.
A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims.
By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists.
At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?
I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless.
Better would be a "this site is suspiciously new" warning in browsers.
At $WORK, newly registered sites are blocked by default by the network appliance.
I'd say "legitimate objections" is doing a lot of heavy lifting there and I don't like the idea. Having the time and resources to monitor registrations becomes a barrier and that makes it a time and resource based system. IE: Rich individuals and companies can pay a monitoring service that objects very broadly.
I've always been frustrated by systems like that and it seems like a lot of the tech industry is set up that way. I've had my personal, family name, 25 year old domain put on Google's safe browsing block list and being the collateral damage in a hugely scaled system isn't fun. Spending the time and resources needed to deal with it are far more of a burden for me than for a big company. I was able to get it removed, but why should I be forced to pay for their mistake?
Ultimately though, any system is going to cost money no matter how it's structured. If you're not paying directly, you're spending time or resources of some kind. I'd rather pay directly because it's easier to understand.
I don't think you can build an all or none system for handling abuse because so much of it is subjective. Even using what's legal vs illegal is difficult because a global system is going to have contradictions. Online gambling is a good example. Some countries would want the related domains banned for being illegal while others don't have a problem with it.
Domains are one of the core building blocks that makes a decentralized internet work. Adding strong moderation tools to that is a huge risk because moderation and censorship are closely related. Who determines what's trustworthy or legitimate or abuse or anything else? What happens if a newly appointed authority claims transparency will enable bad actors?
Highly transparent systems with independent trust ranking make the most sense to me. Any solutions need to be opt-in, or, at the very least, opt-out.
Why shouldn't that go live instantly?
A disgraced pop star has just been found guilty. I couldn't register Bob-The-Builders-Crimes.uk before the verdict and I want to get my story out now.
I've had a brilliant idea for an eCommerce website but it is 1705 on a Friday night and, because no one works weekends, I have to wait until next week before the domain is agreed.
I agree that there's no great harm in having to wait a day, or a week, for registration to complete. But in a world of instant gratification, it feels old fashioned.
I know that “mystupidvibecodedidea.com” is all the rage but nobody cares if that’s instead on yourname.com/mystupidvibecoded idea except you.
More likely:
Some flavor of shit has hit the fan. I need to register some viable short and to the point domain names to get the word out faster than BigCo or the government and their army of lawyers can buy those domains.
Would we have stuff like DeFlock if there was an objection period?
What about if some advocacy firm was trying to create a website for people harmed by a drug. The drug company would just object to all their attempted registrations and bog them down.
That seems beyond any reasonable due process and legal standards. Or am I missing some international legal standard and judicial oversight that would play a role here? I'm genuinely confused.
Much like micropayments could solve the text spam problem.
If your TLD is location based for example, consider verifying and linking the TLD to an identity, by local means, like a national ID.