This is nightmare fuel. Instead of selling the registry responsibility to someone who would care for it and profit from it, Verisign chose to murder it. And ICANN actively aided Verisign in doing this, proving (if there were any remaining doubt) who ICANN actually serves.
Wow, even if there was a legitimate reason for the termination of all these domains, I can't imagine not giving at least a few years for registrants to update their...well, everything. It's just irresponsible to close a namespace on such short notice.
I wonder if some organization could offer ICANN to take over management for all those existing second-level .name domains to avoid disruption of service.
I wonder if some organization could offer ICANN to take over management for all those existing second-level .name domains to avoid disruption of service.
Verisign's doc mentions "limited registrar support of the service and declining usage of third-level domains".
It's worth reminding ourselves the weirdness of .name: you can register surname.name unless any forename.surname.name is already registered. That's not how other TLDs work.
It's no wonder this TLD has limited registrar support.
If, as you suggest (and is reasonable to consider), we split the .name registry somehow by just the impacted names, that's yet more complexity.
I think the last incident on this scale I remember was when UK citizens weren't allowed to keep their .eu domains with Brexit. Gotta love being subject to things you didn't support (and DNS centralization, of course).
Both the Verisign and ICANN documents are gloriously ambiguous when it comes to what happens to 2nd-level names that were once shadowed by a 3rd-level registration. I'm not at all surprised: I had a 3rd-level .name 25 years ago and got bit by registrar problems then.
Lobsters fairly often gets articles advocating self-hosting email. I always think it seems too risky because any Internet presence that I try to maintain seems definitely less likely to be consistently available for the next, say, 15 years than, say, Gmail. Keeping control of the domain name is definitely one of those availability risks.
I don't see the relevance to self-hosting. Sure, it's a risk there, but keeping control of the domain name is also of importance to any person, company and organisation not wanting to use their service provider's domain name (which could also disappear without recourse, by the way.)
which could also disappear without recourse, by the way
gmail.com disappearing is far, far less likely than essex-plumbers.xyz. I often see small businesses that have their email address as somebusinessname@gmail.com and honestly I don't think twice about it
Or you can get locked out of your account due to a bug. My oldest account is no longer accessible due to one day the password no longer being accepted. It doesn't say it's incorrect, it says something along the lines of "this authentication method is not secure enough to log in, try another option", but no other options are provided. I've spent some time trying to contact their support team, but I never got a response.
and they do it without any notice and without any fuss on lobste.rs.
This example is particularly rare, hence why it creates such drama. As long as you pay, keeping a domain is quite easy and, most importantly, under your control.
Trusting to keep your gmail address is, at best delusional. And even if you keep it, who knows what the service will be in 15 years, what price they will make you pay. I mean, your email are now officially used to train their LLMs.
Though I'm sure it's rare, it's not uncommon to see people complaining they've lost access to their Google/Gmail accounts for this or that reason. I would imagine Gmail will be around in 15 years. I am not certain that it's more or less risky to depend on Google, though, than to control your own .com, .net, .org, etc. domain.
I'd suggest it's slightly more likely that Gmail will be gone in 15 years than .net, for instance. (But I wouldn't wager any serious cash on either disappearing in 15 years. Plus it's more likely that I won't be around in 15 years than either of those... hopefully, though, I'll still be getting email to my .net domain hosted on not-Gmail even then.)
FWIW I think controlling your own domain name on one of the big three TLDs and hosting with a service like Fastmail is probably the least-risky option. I do not love running my own mail services, even though I often feel like I should for various reasons, but I can always point my domain at another provider if need arises or even start self-hosting if absolutely necessary.
I'd suggest it's slightly more likely that Gmail will be gone in 15 years than .net, for instance.
Interesting — why only slightly? :-)
One is owned and operated by a diversified conglomerate with many other lines of business; the other is about twice as old and operated and overseen by corporations specialized in operating and overseeing such things, and I struggle to imagine .net being decommissioned unless the whole Internet is being replaced.
FWIW I think controlling your own domain name on one of the big three TLDs and hosting with a service like Fastmail is probably the least-risky option.
I find that plausible on average, though I would expect the least-risky option to differ by person.
Keeping control of the domain name is definitely one of those availability risks.
Depends, what TLD and who you're registering it from. Honestly, the only real risk is if you pick a really shitty registrar. Going with ccTLDs (.eu, .fi), or some common TLDs is a good option.
I know you mean that, but for clarity: a ccTLD you are associated with. My pet peeve is using ccTLDs because of how they "look" instead of what they mean.
(But, .io was supposed to die and they saved it because it was "too big to fail". No such grace with current .name third-level domains.)
I consider forgetting to update my payment information when it (inevitably) changes, and thereby getting my domain name subscription cancelled, to be a real risk, even given reminder email messages. Every option has some risk, which I would expect to differ for different people.
Same. I have a .ink domain I had registered as a word play when I tried to get into blogging, that I have started using for email and other stuff as well. Perhaps it is time to reconsider where to put my internet presence. Then again using .com in the current times also doesn't seem entirely safe for non-US peoples; .org was already on the verge of becoming an issue, and using my own ccTLD doesn't seem logical either if I am thinking that I might be moving to a different country in the next few years. So what is the good option to go with today? .net maybe?
Yes, I registered my third-level .name domain specifically so I could "own" my email address. Joke's on me, my @gmail.com address is going to outlast my "owned" address.
I had the same scare when they decided to commercialize .org. My entire Internet presence has been tied to an .org domain for a quarter century as well.
Pretty much all questions asked about how and why can be answered by one word: profit.
They're not making enough. We can't have nice things because we can't have organizations that aren't all about profit run important things. When we have, they've generally worked well, but then someone gets the idea (or gets told the idea) that the thing can be privatized, and someone close to the decisionmakers can make profit, and perhaps some of that ends up flowing in the direction of decisionmakers.
Healthcare, for instance, shouldn't be a for profit business. Housing shouldn't be be for profit. How it ever came to pass that the DNS moved to a horribly exploitive for-profit system should be studied, and people vilified, and we all collectively should try to imagine ways we could have a system that's outside of that for-profit system run by real, actual non-profits that have real, actual computer geeks that aren't going to use or sell their influence.
The Internet, including the DNS, is a product of the USA. The USA, of course, disagrees with you and strongly values and advocates for-profit private enterprise. The product of course reflects the values of its maker.
Didn't the US military semi-famously just kind of turn a blind eye to the fact that people were using the network they'd set up in new and unexpected ways? I don't know if I'd attribute to the US all, or even most, of the value contained in the Internet.
Yikes, I was literally just about to start transitioning all my email to an address at my .name domain. Thankfully it is only level 2, but this definitely gives me pause.
I've gone through with it (on a non .name domain), and it's definitely a commit to owning that domain forever sort of thing. Also keep in mind that changing your email address with certain entities is near impossible, unfortunately.
Is there a good,central place for people not directly affected by this, i.e. not having any .name registrations, to complain to ICANN to help have this decision overturned?
You're just describing the Internet. If someone ever claims gmail.com for any reason and it's not Google, a world of hurt is in store for a lot of people.
Actually, the domain in atproto is just a handle. The relevant piece is the did, and one can change what domain points to a given (owned) did in a minute.
DIDs are the long-term persistent identifiers for accounts in atproto, but they can be opaque and unfriendly for human use. Handles are mutable and human-friendly account usernames, in the form of a DNS hostname.
AP has more problems than just relying on domain names. Relatedly, there being no option to switch providers while keeping all the content would come to mind…
did:plc is far more common; most bluesky users with their domain as their handles are did:plc as opposed to did:web. It's only really the hardcore atproto nerds who use did:web. An informative article: https://steveklabnik.com/writing/too-many-words-about-dids/
I read a few years back that atproto, on the protocol level, only really worked with a few centralized servers, as all the data for all users on a given server would automatically have to be stored by all servers on the same network. Am I remembering this correctly, and if so was that problem resolved at some point?
pmc | 13 hours ago
I am disgusted that the ICANN approved this. I hope the author has success challenging this legally.
cpurdy | 12 hours ago
This is nightmare fuel. Instead of selling the registry responsibility to someone who would care for it and profit from it, Verisign chose to murder it. And ICANN actively aided Verisign in doing this, proving (if there were any remaining doubt) who ICANN actually serves.
Strange, and sickening.
bdn | 12 hours ago
Wow, even if there was a legitimate reason for the termination of all these domains, I can't imagine not giving at least a few years for registrants to update their...well, everything. It's just irresponsible to close a namespace on such short notice.
I wonder if some organization could offer ICANN to take over management for all those existing second-level
.namedomains to avoid disruption of service.tuxes | 2 hours ago
Verisign's doc mentions "limited registrar support of the service and declining usage of third-level domains".
It's worth reminding ourselves the weirdness of
.name: you can registersurname.nameunless anyforename.surname.nameis already registered. That's not how other TLDs work.It's no wonder this TLD has limited registrar support.
If, as you suggest (and is reasonable to consider), we split the
.nameregistry somehow by just the impacted names, that's yet more complexity.junon | 12 hours ago
ICANN has an opportunity to reverse some of its bad reputation here. I hope they take that chance.
calvin | 12 hours ago
I think the last incident on this scale I remember was when UK citizens weren't allowed to keep their .eu domains with Brexit. Gotta love being subject to things you didn't support (and DNS centralization, of course).
tuxes | 4 hours ago
I think the motivation there is that it's difficult to resolve domain disputes if you have no legal presence in a jurisdiction.
That said, I was impacted by this, as I posted in https://lobste.rs/s/9r9ozr/sudden_loss_domain
I occasionally tell this story and sometimes hear that I should have been aware that Brexit was a possibility, and just picked
.uk.Alas, I consider(ed?) myself as European almost as much as British.
And what of the people in Scotland, Catalonia, and WA happily using
.uk,.esand.au?jmtd | 12 hours ago
Both the Verisign and ICANN documents are gloriously ambiguous when it comes to what happens to 2nd-level names that were once shadowed by a 3rd-level registration. I'm not at all surprised: I had a 3rd-level .name 25 years ago and got bit by registrar problems then.
koala | 11 hours ago
I always said "ICANN is not so bad, they have not done so badly so far."
I'll go get some fries to eat with that.
In general I'm a fan of https://opennic.org/ but that's not something viable. I see no viable alternative.
Hopefully I have misunderstood what's happening here or this is fixed and not a sign of times to come.
5d22b | 11 hours ago
Lobsters fairly often gets articles advocating self-hosting email. I always think it seems too risky because any Internet presence that I try to maintain seems definitely less likely to be consistently available for the next, say, 15 years than, say, Gmail. Keeping control of the domain name is definitely one of those availability risks.
jmiven | 10 hours ago
I don't see the relevance to self-hosting. Sure, it's a risk there, but keeping control of the domain name is also of importance to any person, company and organisation not wanting to use their service provider's domain name (which could also disappear without recourse, by the way.)
WilhelmVonWeiner | 9 hours ago
gmail.comdisappearing is far, far less likely thanessex-plumbers.xyz. I often see small businesses that have their email address assomebusinessname@gmail.comand honestly I don't think twice about itatk | 8 hours ago
Yeah but Google deciding to ban or delete your account is on the other hand much more likely than
essex-plumbers.xyzdisappearing.I'd say that this is negligence on the part of ICANN.
lpil | 6 hours ago
Or you can get locked out of your account due to a bug. My oldest account is no longer accessible due to one day the password no longer being accepted. It doesn't say it's incorrect, it says something along the lines of "this authentication method is not secure enough to log in, try another option", but no other options are provided. I've spent some time trying to contact their support team, but I never got a response.
doctor_eval | 5 hours ago
Pretty sure that’s what people said about Google reader.
altano | 9 hours ago
I’m sure Google has closed more than 22,000 gmail accounts in the last 15 years
ploum | 8 hours ago
and they do it without any notice and without any fuss on lobste.rs.
This example is particularly rare, hence why it creates such drama. As long as you pay, keeping a domain is quite easy and, most importantly, under your control.
Trusting to keep your gmail address is, at best delusional. And even if you keep it, who knows what the service will be in 15 years, what price they will make you pay. I mean, your email are now officially used to train their LLMs.
jzb | 9 hours ago
Though I'm sure it's rare, it's not uncommon to see people complaining they've lost access to their Google/Gmail accounts for this or that reason. I would imagine Gmail will be around in 15 years. I am not certain that it's more or less risky to depend on Google, though, than to control your own .com, .net, .org, etc. domain.
I'd suggest it's slightly more likely that Gmail will be gone in 15 years than .net, for instance. (But I wouldn't wager any serious cash on either disappearing in 15 years. Plus it's more likely that I won't be around in 15 years than either of those... hopefully, though, I'll still be getting email to my .net domain hosted on not-Gmail even then.)
FWIW I think controlling your own domain name on one of the big three TLDs and hosting with a service like Fastmail is probably the least-risky option. I do not love running my own mail services, even though I often feel like I should for various reasons, but I can always point my domain at another provider if need arises or even start self-hosting if absolutely necessary.
5d22b | 5 hours ago
Interesting — why only slightly? :-)
One is owned and operated by a diversified conglomerate with many other lines of business; the other is about twice as old and operated and overseen by corporations specialized in operating and overseeing such things, and I struggle to imagine .net being decommissioned unless the whole Internet is being replaced.
I find that plausible on average, though I would expect the least-risky option to differ by person.
samuelhautamaki | 10 hours ago
Depends, what TLD and who you're registering it from. Honestly, the only real risk is if you pick a really shitty registrar. Going with ccTLDs (.eu, .fi), or some common TLDs is a good option.
koala | 7 hours ago
I know you mean that, but for clarity: a ccTLD you are associated with. My pet peeve is using ccTLDs because of how they "look" instead of what they mean.
(But, .io was supposed to die and they saved it because it was "too big to fail". No such grace with current .name third-level domains.)
5d22b | 5 hours ago
I consider forgetting to update my payment information when it (inevitably) changes, and thereby getting my domain name subscription cancelled, to be a real risk, even given reminder email messages. Every option has some risk, which I would expect to differ for different people.
mccd | 9 hours ago
Yeah I have a .email domain that I've been using for the past year...... I'm thinking it may be too risky to use it for everything.
siru | 7 hours ago
Same. I have a .ink domain I had registered as a word play when I tried to get into blogging, that I have started using for email and other stuff as well. Perhaps it is time to reconsider where to put my internet presence. Then again using .com in the current times also doesn't seem entirely safe for non-US peoples; .org was already on the verge of becoming an issue, and using my own ccTLD doesn't seem logical either if I am thinking that I might be moving to a different country in the next few years. So what is the good option to go with today? .net maybe?
tuxes | 4 hours ago
+1.
https://lobste.rs/s/9r9ozr/sudden_loss_domain was my example of losing a domain through no fault of my own.
Picking a TLD is important. Though there's no guarantee you'll continue to be eligible for any TLD, perhaps
.comis the safest bet, sadly.enn | 3 hours ago
Yes, I registered my third-level .name domain specifically so I could "own" my email address. Joke's on me, my @gmail.com address is going to outlast my "owned" address.
singpolyma | 3 hours ago
I dunno. Google kills things all the time. Gmail isn't magically safe
5d22b | 2 hours ago
I agree (but neither is anything else).
isagalaev | 12 hours ago
I had the same scare when they decided to commercialize .org. My entire Internet presence has been tied to an .org domain for a quarter century as well.
johnklos | 7 hours ago
Pretty much all questions asked about how and why can be answered by one word: profit.
They're not making enough. We can't have nice things because we can't have organizations that aren't all about profit run important things. When we have, they've generally worked well, but then someone gets the idea (or gets told the idea) that the thing can be privatized, and someone close to the decisionmakers can make profit, and perhaps some of that ends up flowing in the direction of decisionmakers.
Healthcare, for instance, shouldn't be a for profit business. Housing shouldn't be be for profit. How it ever came to pass that the DNS moved to a horribly exploitive for-profit system should be studied, and people vilified, and we all collectively should try to imagine ways we could have a system that's outside of that for-profit system run by real, actual non-profits that have real, actual computer geeks that aren't going to use or sell their influence.
5d22b | 4 hours ago
The Internet, including the DNS, is a product of the USA. The USA, of course, disagrees with you and strongly values and advocates for-profit private enterprise. The product of course reflects the values of its maker.
nil | an hour ago
Didn't the US military semi-famously just kind of turn a blind eye to the fact that people were using the network they'd set up in new and unexpected ways? I don't know if I'd attribute to the US all, or even most, of the value contained in the Internet.
enn | 3 hours ago
ICANN is (allegedly) a non-profit and receives significant regulatory benefits in exchange for that disavowal of the profit motive.
janus | 7 hours ago
If they wanted more profit, why didn't they raise rates instead of shutting it down?
doctor_eval | 5 hours ago
My guess is that some underpants gnome decided that whatever takes its place will be more profitable.
tinsnail | 12 hours ago
Yikes, I was literally just about to start transitioning all my email to an address at my .name domain. Thankfully it is only level 2, but this definitely gives me pause.
danlamanna | 9 hours ago
I've gone through with it (on a non
.namedomain), and it's definitely a commit to owning that domain forever sort of thing. Also keep in mind that changing your email address with certain entities is near impossible, unfortunately.siru | 6 hours ago
Is there a good,central place for people not directly affected by this, i.e. not having any .name registrations, to complain to ICANN to help have this decision overturned?
hjvt | 12 hours ago
Meanwhile, somebody has build a social media federation protocol where the user identity is based largely on ownership of a domain
Halkcyon | 12 hours ago
You're just describing the Internet. If someone ever claims
gmail.comfor any reason and it's not Google, a world of hurt is in store for a lot of people.diktomat | 11 hours ago
Actually, the domain in atproto is just a handle. The relevant piece is the did, and one can change what domain points to a given (owned) did in a minute.
~ https://atproto.com/specs/handle
liberty | 9 hours ago
Unfortunately, afaiu ActivityPub doesn't have an equivalent and is entirely reliant on domain names.
diktomat | 8 hours ago
AP has more problems than just relying on domain names. Relatedly, there being no option to switch providers while keeping all the content would come to mind…
hjvt | 8 hours ago
did:web in particular is what I'm referencing. I was under impression that it is widely used?
novedevo | 7 hours ago
did:plc is far more common; most bluesky users with their domain as their handles are did:plc as opposed to did:web. It's only really the hardcore atproto nerds who use did:web. An informative article: https://steveklabnik.com/writing/too-many-words-about-dids/
siru | 6 hours ago
I read a few years back that atproto, on the protocol level, only really worked with a few centralized servers, as all the data for all users on a given server would automatically have to be stored by all servers on the same network. Am I remembering this correctly, and if so was that problem resolved at some point?