.name Termination
- nneonneo - 47532 sekunder sedanIt seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3LD registered on top). It’s a bit insane that they can decide to just terminate all existing 3LD registrations. One would hope that they’d at least continue to reserve the 2LDs for some period to avoid domain squatting, but this isn’t mentioned in the proposal and I doubt Verisign would graciously do so.
- jl6 - 32903 sekunder sedanI can only assume somebody was asleep on the job when this scheme was approved, because the outcome is in direct contradiction to ICANN’s mission statement:
> Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems.
https://www.icann.org/resources/pages/about-icann
Arbitrary termination of service is not stability.
Enabling name hijacking is not security.
The answer cannot be a rival name scheme based on decentralization or crypto or whatever. Those are never going to help normal non-wizard users. The answer has to be to make the regulators do their job.
- dvt - 43497 sekunder sedanI freaked out for a second because I've owned `dvt.name` for like 15 years. `.name` is not getting terminated, so it's important to be precise here. The third-level x.y.name (where you're the `x`) is getting terminated, and the respective `y.name` domains are going to be released.
Still a crappy thing for people, but it does not affect owned second-level domains.
- nanolith - 35047 sekunder sedanThis risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices used were entirely disconnected from domain names, and why the discovery protocol I put together did not rely on registered domains, but could use these as an untrusted part of discovery.
Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.
I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.
I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.
- akersten - 48827 sekunder sedanIt kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.).
Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?
- arjie - 47911 sekunder sedanWe were rescued from that dot org scam by the fact that ICANN is a California non profit. I wonder if the AG can lean on them again. This is an outrageous thing to do.
- projectileboy - 27544 sekunder sedanWe keep expecting for-profit organizations to behave as governments. And this is an especially easy sell in the US, where government has been vilified for decades as part of a long propaganda game run by those who wish to privatize and steal those things which should rightfully exist in the public domain. But for-profit organizations, by design, will never ever ever behave in the public interest, and it’s foolish to expect otherwise. This is not a criticism of the author; this is a criticism of ICANN, and the subcontracting of governance.
- NAR8789 - 12353 sekunder sedan@dang can you update the domain extraction logic for hn titles to include the 3rd level domain for .name domains? It's a little too poetically unfortunate that HN lists the domain on this article as `fraser.name`
- sigbottle - 45333 sekunder sedanThere's a DNS wizard at my job (not doing DNS stuff currently; but in his past life), and while he was talking to me about certain topics my eyes glazed over, and I thought, "Man, surely that won't affect me, right?"
Well, it's still not affecting me, personally, but wow, seeing articles like this makes it feel just a tiny bit more real.
- aliasxneo - 44646 sekunder sedanThis is why I am building DNTLS. These organizations no longer deserve our trust and they have inadvertently gained too much power over the last two decades of massive internet expansion. Names need to be fully owned by individuals and a shared, decentralized trust system must be in place for resolution. The more I see actions like this, the more convinced I am that a solution is long overdue.
- nubinetwork - 48799 sekunder sedan> Once the 3rd-level domains are terminated, it is assumed that the now vacant 2nd-level domains will become available for registration. Should someone (other than me) scoop up fraser.name (...)
What's to stop someone from doing that, and keeping the status quo? Sure, it might be expensive, but pool together a few frasers for the initial buy, and make the money back on the sublets.
- jonhohle - 41534 sekunder sedanOne of the reasons I stick with Big Email for my primary email is cases similar to this. If I host email and lose the domain one day, I’ve lost two factor on a thousand different services (the single factor on some). Big Email’s policy is to not reissue my address, should I lose it or die.
The .name scenario is even worse. One domain gives you access to tens of thousands of users email. It seems like a privacy nightmare.
I’m not sure how future auth and privacy will work, but my child lost a tracfone phone and some mixup had separated it from my account. There was no way to recover the number. If that was my personal phone, how difficult would it be to restore banking, medical, and government access to things that assume I’ll always have that number.
Doing the same with personal email seems like too big of a risk.
- willwade - 45685 sekunder sedanI worked for .name briefly right at the beginning of their entry into the world. Interesting but very odd part of my career.. Ill give it that.. I personally found the product at first a great idea but somewhat crippled by execution..
- wmf - 48288 sekunder sedanDiscussion from yesterday: https://news.ycombinator.com/item?id=49516047
- johnplatte - 47176 sekunder sedanWow! Years ago I initially bought my firstname.lastname.name, then I let it expire and then bought lastname.name. So glad I did!
Never dreamed that such a supposedly durable thing would just disappear. How hard is it really to preserve a global resource like this that exists only in software?
- econ - 39745 sekunder sedanI don't like the way domains work in general. It's really quite expensive if you are wise enough to buy everything that looks to much like your website.
Did buy https://ycombinator.us
Didn't buy https://ycombinator.co.uk
What useful functionality is there in selling these domains?
Expiring domains is bad for the web and selling them to someone else is as terrible as the article makes it out to be.
- ipython - 49381 sekunder sedanFrom the Verisign application [0] for this change:
ehhh, how is that possibly true? This change (deleting all third level names) by definition affects the lifecycle of domain names ... by terminating them!> 2.1. What effect, if any, will the proposed service have on the life cycle of domain names? > None. There will not be any effect on the life cycle of domain names.Many years ago I wrote articles bringing attention to the negative effects of Verisign's SiteFinder [1] - if you don't remember this, it's when Verisign hijacked NXDOMAIN by redirecting any unresolvable domain to a site they owned and controlled.
[0] https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2... [1] https://en.wikipedia.org/wiki/Site_Finder
- decimalenough - 47887 sekunder sedanI've had a .name domain forever and I had no idea first.last.name was even a thing, meaning that it was possible to register this without owning last.name.
That said, my domain is simply unusual.name, and everybody in my family has email addresses in the form first@unusual.name. So this is a no-op for me, and I gather www.unusual.name will also continue to work, since I own the 2nd level outright.
- baylisscg - 20806 sekunder sedanWhat's wild is that when initially launched you could only register 3LD domains. If you were quick out the gate and registered one in 2002 and have been using 10 year renewals you're about to have a domain you've owned for almost a quarter century with 6 years left on its registration nuked.
- anominal - 44605 sekunder sedanI am also one of the 22,000 people who have a third-level .name domain and I am livid about this, not least because Verisign flat-out lied in their proposal to ICANN: (https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2...) :
"2.1. What effect, if any, will the proposed service have on the life cycle of domain names? None. There will not be any effect on the life cycle of domain names.
...
2.3. Explain how the proposed service will affect the throughput, response time, consistency or coherence of responses to Internet servers or end systems. There will be no effect on the throughput, response time, consistency or coherence of responses to Internet servers or end systems."
My registrar is also suggesting that they are going to just keep the money I pre-paid for years of registration, which is a minor annoyance compared to the loss of my entire online identity but an annoyance nonetheless.
Since ICANN is a non-profit that is required to operate in the public interest I do hope there can be some pushback on this. I will be writing to the CA AG myself.
- xyzzy_plugh - 49647 sekunder sedan> Despite the fact that it's registered and paid for until 2040
How is this possible? I thought there was a 10 year limit.
- chanux - 47838 sekunder sedanI kind of assumed .name was a product of relatively new TLD explosion [1]
[1] https://blog.asmartbear.com/free-markets-bad/
Gotta wonder what other possible disasters introduced with gTLDs.
- padjo - 40493 sekunder sedanWho is running the show over at ICANN? How can this possibly be a reasonable thing for a registrar to do?
- xp84 - 41468 sekunder sedanI don't think it's hyperbolic to say that this is the most careless, disruptive change to anything to do with DNS or internet names I have ever seen.
> "will increase efficiency for the operation of the .name TLD."
What a preposterous excuse -- especially for something already up and running. Sounds like they probably want to change the backend in some way - or adopt some kind of off-the-shelf software - which doesn't jive so well with this unique TLD, and they figure "Ehh, fuck 'em, let's just pull the plug on these tens of thousands of people."
- mchesters - 49717 sekunder sedanWow, they were extremely laziest in the request form too. Most answers are just a few words.
> 3.6. Have you communicated with any of the entities whose products or services might be affected... > "No. Not applicable." - noja - 49374 sekunder sedanICANN approved this.
- Glyptodon - 33370 sekunder sedanIt's kind of crazy to me that the whole domain was originally set up so that people would buy 2nd and 3rd level pairs. But it also seems really obvious that backtracking is going to be a disaster.
- cpach - 35988 sekunder sedanOuch.
IMHO, this whole TLD seems kind of messed up from the start: https://en.wikipedia.org/wiki/.name
- Ecco - 49021 sekunder sedanOk I don’t get it. Why not register `fraser.nameˋ directly? Or pick any TLD and register ˋ a 2nd-level domain (ˋfraser.tld`)? It just feels easier, plus this way you don’t have to pay for any new member of your family?
- thbb123 - 21490 sekunder sedanWtf, I have been using my x.y.name domain for everything, haven't been notified of this.
Should I rush to reserve y.name so my email address and personal website can stay online?
- NewJazz - 48871 sekunder sedanYou might want to write to the CA attorney general. Former AG Xavier Becerra was able to dissuade ICANN from letting the .org fuckery happen, maybe Bonta could try to strong arm ICANN in this case.
- ClarityJones - 41625 sekunder sedanIf this proves to be a viable business strategy, then verisign could equally use it to re-sell google.com, ycombinator.com, etc. to the highest bidder.
- lacoolj - 44686 sekunder sedanDude, this is one of the craziest things I think I've read on HN
First, that a legit dealer could/did(does?) sell third-level domains at all (Verisign, no less) Second, that the top-level is staying available, allowing for second-levels to be bought/sniped like you mention.
If you do lawyer up and need help with legal fees, I think this would be a worthy cause.
- doublepg23 - 50240 sekunder sedanI didn't even know I was using .name incorrectly...
- morissette - 33324 sekunder sedanIt seems as if only 40 people are needed for a class action suit. Me, not a lawyer. Gemini says chances are you could only get a refund. But maybe worth the fight for some.
- niraj-agarwal - 24770 sekunder sedan22,000 people affected. Link up and lawyer up is right. To have identity and existence taken away is a no go.
- aeternum - 46480 sekunder sedanHow would the avg person know that ..name is different and somehow more trustworthy than ..uk
Overall this seems like the right move, either they all are trusted or none.
- xbar - 25433 sekunder sedanI can only assume ICANN was co-opted by Verisign some decades ago.
- akulbe - 37990 sekunder sedanI don't get the concept of 3LD. We own kulbe.name - does this news mean it's going to go away entirely?
- aff-vasileva - 38142 sekunder sedanTurns out “buying your name on the internet” was technically just renting a room in someone else’s last name.
- marbleotter115 - 33155 sekunder sedan.name is the part I keep having to relearn, so seeing it spelled out helps.
- delduca - 47807 sekunder sedanI never bet in any other than .com, .org, .net?
- jmuguy - 46289 sekunder sedanI can't be the only one that assumed based on the domain that this was some bizarre DMCA action by Paramount.
- mig4ng - 40200 sekunder sedanAnd that kids is why it's always DNS fault.
Again, you're security is only as strong as your DNS.
- basilikum - 24568 sekunder sedanI seriously wonder what ICANN is good for.
- r_lee - 44743 sekunder sedanI would not use a 2nd level tld for a "stable presence". it seems like a gimmick
- cjjuice - 47263 sekunder sedanI really think ENS is on to something with blockchain based domain registration and management
- Maxforever - 10487 sekunder sedanI saw it
- Henchman21 - 42995 sekunder sedanHow is it that they can just nullify the contracts they had with people they were providing services for?
- swiftcoder - 49888 sekunder sedanThat's pretty shit. You'd think changes like this would need to go through a public comment period with the affected users (much like city planning decisions do)
- xyst - 50051 sekunder sedanVerisign is the worst. Hope author wins
- johnnyApplePRNG - 41530 sekunder sedanThey deserve to lose their control of all domains over this.
This is ridiculous.
- TZubiri - 13730 sekunder sedanhttps://itp.cdn.icann.org/en/files/consensus-policies/rsep-2...
>2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
>None. There will not be any effect on the life cycle of domain names.
>2.2. Does the proposed service alter the storage and input of Registry Data?
>No. There will not be an alteration to the storage and input of Registry Data.
This sounds wrong? Is this just a knee-jerk form-filler reaction? It seems to me that the admitted "Upon discontinuation, no new third level domain names will be registered and existing third level domain names will be terminated."
In general this sounds like a grotesque misplay that is wildly uncharacteristic for the entity behind the timeless .com
- underdeserver - 42333 sekunder sedandang and team, perhaps it makes sense to special-case .name domains in the domain hint, like you do for GitHub and Ex-Twitter.
- bix6 - 47069 sekunder sedanFuck verasign. TLDs should be run as an actual public utility. Can these economic parasites be expelled already…
- bawolff - 42086 sekunder sedanI feel like TLDs as a concept are more trouble than they are worth. We should just have .com and get rid of the rest (except special purpose tlds).
- 1970-01-01 - 45389 sekunder sedanInstead of giving up, why can't all 22k .name owners move on to OpenNIC? They will not say no, you can't have that.
- 0xbadcafebee - 33357 sekunder sedanPrediction: In 20 years, ICANN, IANA, ARIN become increasingly abandoned by nations wary of The Imperialist States of America's control over global communication & commerce, and the internet becomes an uber-net of nationalist internets, subverted by satellites.
- khalic - 43996 sekunder sedanAh! verisign! Proving the world over and over what kind of scum they are
- TZubiri - 41265 sekunder sedanI wonder if this could constitute a violationiof article 6 of the UN declaration of human rights.
It has been established that national identifiers are protected by it, and a domain works as a sort of international identifier, in this case a personal one.
No one is obligated to give you a domain, but by contracting an obligation to provide that identifier until 2040, they would at least be liable for those damages, but there's an argument that depriving you of an identifier already granted is a more fundamental violation of a right to a name, an identifier and recordkeeping of them.
- AtNightWeCode - 44798 sekunder sedanThings like this happens from time to time and yet people insists on using stupid TLD:s just because of "cool" suffixes.
- psychoslave - 46885 sekunder sedanBreaking trust, one TLD at a time.
So, where is our fully decentralized TLD alternative, free of ICANN or any central authority to handle how we grant names by conventions, without any money scheme in the game that attracts malevolent actors moving only through greed strings?
Also, this time let’s make it like usenet, so "person:named:Neil Fraser" or even "::Neil Fraser" (harder to type but less culturally entangled into English).
- - 48755 sekunder sedan
- eleventen - 49752 sekunder sedan> Minutes after my daughter was born, I also registered beverly.fraser.name.
...minutes?
- notorandit - 40461 sekunder sedanIt's just money. Nothing else. Just money.
- rburhum - 40442 sekunder sedanLawyer up and fight it. This is bs.
- nikanj - 42723 sekunder sedanI wrote to ICANN support and got a template-AI answer wholly unrelated to my complaint about this:
”Greetings from ICANN Global Support.
I am sorry to hear you are experiencing this domain access issue after your registrar's transfer. I will happy to provide you with relevant information and guidance.
Please note that, ICANN accredits companies as domain name registrars and works to ensure contractual compliance with the terms and conditions of the 2009 and 2013 Registrar Accreditation Agreements (RAAs).
ICANN does not provide domain name registration or manage domain accounts. As a result of that ICANN is not able to perform domain management for you.
If you need help to access and manage your domain, you will need to contact your domain service provider or registrar for assistance.
You may check who your registrar is by doing a domain search at lookup.icann.org.”
Absolutely infuriating
- strenholme - 39717 sekunder sedanThe correct way to handle this mess is to simply keep things messy. BGP tables are a big mess, for example, because a lot of companies keep their IPs when going from ISP to ISP.
But, assuming that Verisign can’t keep third level domains (as a DNS implementer, I don’t think third level domains is a huge deal; see thread below):
* Third level names where only one person has the second level domain should be transferred to whoever owns that single third level name.
* Third level names where multiple people have the same second level domain should be put up for closed bidding: Only current owners of .name domains with a given second level domain name (e.g. last name) will be able to bid for the second-level domain. So, if one has john.smith.name and joe.smith.name, Joe Smith and John Smith will be in a bidding war for smith.name.
If the issue of .name not being in public suffix is a real issue, Verisign can handle that by disabling new third-level .name registrations, and provide Public Suffix with a list of those registrations (just send all the owners a privacy notice, making it clear that the existence of the name will be made public for security reasons). More reading: https://github.com/publicsuffix/list/issues/2306 (There seems to be issues with this list being too long to keep in the Public Suffix because there’s too much software out there which can’t handle it. That seems strange to me: Even here in 2026 where RAM costs far too much, Deadwood can store a list of 240,000 blacklisted entries in under 10 megs; there are about 22,000 three-level .name domains and I could store that list in a way that could be very quickly looked up in about a meg of memory)
Now, personally, I think Verisign can keep these messy third level names, and are doing things this way so that Neil Fraser has to compete with every single 2-bit cybersquatter out there for the rights to fraser.name.
As an aside, it’s trivial to have DNS servers handle multi-level domains without having to have a zone file for every level; e.g. https://this.is.a.long.name.maradns.org works, and there’s no zone file for name.maradns.org, long.name.maradns.org, a.long.name.maradns.org, and so on.
Also, since people have brought up the “org fuckery” without providing details: https://bluecatnetworks.com/press/the-org-domain-sale-explai...
You know dang well if .org was owned by an investment entity, they would had jacked up the prices as much as they could get away with.
- MagicMoonlight - 40601 sekunder sedan[dead]
- pmdr - 48224 sekunder sedan> I had history with Verisign and did not trust them.
I don't know what that history is, but did it really make a tld used by only 22k people more appealing?
- drnick1 - 46540 sekunder sedan> Second, my email address also disappears. Third, all the IoT devices that use services on this domain become bricks. Basically, I disappear from the Internet.
While changing email is inconvenient, I don't understand the point about IoT devices. IoT devices should not depend on the Internet at all for obvious privacy and security reasons. If you are using IoT devices with "cloud" accounts, then this is a blessing in disguise. Put that garbage in the trash and rebuild around HomeAssistant, Zigbee, RTSP, etc. I find it hard to believe that someone hosting their own website would fall for the cloud IoT scam.
- jawns - 47978 sekunder sedanSurely the author must have anticipated some heightened level of risk in pegging important parts of his personal and business life on a nonstandard TLD like this.
It's a pretty bizarre exception to the normal, intuitive ways that domains work.
I'll admit that it's a crappy situation and I would be frustrated in his place. But if I were in his place, I probably would have also thought it prudent to have a backup plan.
Nördnytt! 🤓