.name Termination

1538 points396 comments14 hours ago
nneonneo

It seems like the right thing they should do is discontinue new registrations but continue to honour existing ones (+ continuing to reserve any 2LD that has a 3LD registered on top). It’s a bit insane that they can decide to just terminate all existing 3LD registrations. One would hope that they’d at least continue to reserve the 2LDs for some period to avoid domain squatting, but this isn’t mentioned in the proposal and I doubt Verisign would graciously do so.

show comments
jl6

I can only assume somebody was asleep on the job when this scheme was approved, because the outcome is in direct contradiction to ICANN’s mission statement:

> Its enduring mission is to ensure the stable, secure operation of the Internet's unique identifier systems.

https://www.icann.org/resources/pages/about-icann

Arbitrary termination of service is not stability.

Enabling name hijacking is not security.

The answer cannot be a rival name scheme based on decentralization or crypto or whatever. Those are never going to help normal non-wizard users. The answer has to be to make the regulators do their job.

show comments
dvt

I freaked out for a second because I've owned `dvt.name` for like 15 years. `.name` is not getting terminated, so it's important to be precise here. The third-level x.y.name (where you're the `x`) is getting terminated, and the respective `y.name` domains are going to be released.

Still a crappy thing for people, but it does not affect owned second-level domains.

show comments
nanolith

This risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices used were entirely disconnected from domain names, and why the discovery protocol I put together did not rely on registered domains, but could use these as an untrusted part of discovery.

Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.

I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.

I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.

show comments
akersten

It kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.).

Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?

show comments
arjie

We were rescued from that dot org scam by the fact that ICANN is a California non profit. I wonder if the AG can lean on them again. This is an outrageous thing to do.

show comments
NAR8789

@dang can you update the domain extraction logic for hn titles to include the 3rd level domain for .name domains? It's a little too poetically unfortunate that HN lists the domain on this article as `fraser.name`

show comments
projectileboy

We keep expecting for-profit organizations to behave as governments. And this is an especially easy sell in the US, where government has been vilified for decades as part of a long propaganda game run by those who wish to privatize and steal those things which should rightfully exist in the public domain. But for-profit organizations, by design, will never ever ever behave in the public interest, and it’s foolish to expect otherwise. This is not a criticism of the author; this is a criticism of ICANN, and the subcontracting of governance.

show comments
sigbottle

There's a DNS wizard at my job (not doing DNS stuff currently; but in his past life), and while he was talking to me about certain topics my eyes glazed over, and I thought, "Man, surely that won't affect me, right?"

Well, it's still not affecting me, personally, but wow, seeing articles like this makes it feel just a tiny bit more real.

aliasxneo

This is why I am building DNTLS. These organizations no longer deserve our trust and they have inadvertently gained too much power over the last two decades of massive internet expansion. Names need to be fully owned by individuals and a shared, decentralized trust system must be in place for resolution. The more I see actions like this, the more convinced I am that a solution is long overdue.

show comments
nubinetwork

> Once the 3rd-level domains are terminated, it is assumed that the now vacant 2nd-level domains will become available for registration. Should someone (other than me) scoop up fraser.name (...)

What's to stop someone from doing that, and keeping the status quo? Sure, it might be expensive, but pool together a few frasers for the initial buy, and make the money back on the sublets.

show comments
jonhohle

One of the reasons I stick with Big Email for my primary email is cases similar to this. If I host email and lose the domain one day, I’ve lost two factor on a thousand different services (the single factor on some). Big Email’s policy is to not reissue my address, should I lose it or die.

The .name scenario is even worse. One domain gives you access to tens of thousands of users email. It seems like a privacy nightmare.

I’m not sure how future auth and privacy will work, but my child lost a tracfone phone and some mixup had separated it from my account. There was no way to recover the number. If that was my personal phone, how difficult would it be to restore banking, medical, and government access to things that assume I’ll always have that number.

Doing the same with personal email seems like too big of a risk.

show comments
willwade

I worked for .name briefly right at the beginning of their entry into the world. Interesting but very odd part of my career.. Ill give it that.. I personally found the product at first a great idea but somewhat crippled by execution..

wmf
johnplatte

Wow! Years ago I initially bought my firstname.lastname.name, then I let it expire and then bought lastname.name. So glad I did!

Never dreamed that such a supposedly durable thing would just disappear. How hard is it really to preserve a global resource like this that exists only in software?

econ

I don't like the way domains work in general. It's really quite expensive if you are wise enough to buy everything that looks to much like your website.

Did buy https://ycombinator.us

Didn't buy https://ycombinator.co.uk

https://ycombinator.de

What useful functionality is there in selling these domains?

Expiring domains is bad for the web and selling them to someone else is as terrible as the article makes it out to be.

show comments
ipython

From the Verisign application [0] for this change:

    > 2.1. What effect, if any, will the proposed service have on the life cycle of domain names?
    > None. There will not be any effect on the life cycle of domain names.
ehhh, how is that possibly true? This change (deleting all third level names) by definition affects the lifecycle of domain names ... by terminating them!

Many years ago I wrote articles bringing attention to the negative effects of Verisign's SiteFinder [1] - if you don't remember this, it's when Verisign hijacked NXDOMAIN by redirecting any unresolvable domain to a site they owned and controlled.

[0] https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2... [1] https://en.wikipedia.org/wiki/Site_Finder

show comments
baylisscg

What's wild is that when initially launched you could only register 3LD domains. If you were quick out the gate and registered one in 2002 and have been using 10 year renewals you're about to have a domain you've owned for almost a quarter century with 6 years left on its registration nuked.

decimalenough

I've had a .name domain forever and I had no idea first.last.name was even a thing, meaning that it was possible to register this without owning last.name.

That said, my domain is simply unusual.name, and everybody in my family has email addresses in the form first@unusual.name. So this is a no-op for me, and I gather www.unusual.name will also continue to work, since I own the 2nd level outright.

show comments
anominal

I am also one of the 22,000 people who have a third-level .name domain and I am livid about this, not least because Verisign flat-out lied in their proposal to ICANN: (https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2...) :

"2.1. What effect, if any, will the proposed service have on the life cycle of domain names? None. There will not be any effect on the life cycle of domain names.

...

2.3. Explain how the proposed service will affect the throughput, response time, consistency or coherence of responses to Internet servers or end systems. There will be no effect on the throughput, response time, consistency or coherence of responses to Internet servers or end systems."

My registrar is also suggesting that they are going to just keep the money I pre-paid for years of registration, which is a minor annoyance compared to the loss of my entire online identity but an annoyance nonetheless.

Since ICANN is a non-profit that is required to operate in the public interest I do hope there can be some pushback on this. I will be writing to the CA AG myself.

xyzzy_plugh

> Despite the fact that it's registered and paid for until 2040

How is this possible? I thought there was a 10 year limit.

show comments
chanux

I kind of assumed .name was a product of relatively new TLD explosion [1]

[1] https://blog.asmartbear.com/free-markets-bad/

Gotta wonder what other possible disasters introduced with gTLDs.

show comments
padjo

Who is running the show over at ICANN? How can this possibly be a reasonable thing for a registrar to do?

xp84

I don't think it's hyperbolic to say that this is the most careless, disruptive change to anything to do with DNS or internet names I have ever seen.

> "will increase efficiency for the operation of the .name TLD."

What a preposterous excuse -- especially for something already up and running. Sounds like they probably want to change the backend in some way - or adopt some kind of off-the-shelf software - which doesn't jive so well with this unique TLD, and they figure "Ehh, fuck 'em, let's just pull the plug on these tens of thousands of people."

show comments
mchesters

Wow, they were extremely laziest in the request form too. Most answers are just a few words.

  > 3.6. Have you communicated with any of the entities whose products or services might be affected...
  > "No. Not applicable."
show comments
noja

ICANN approved this.

Glyptodon

It's kind of crazy to me that the whole domain was originally set up so that people would buy 2nd and 3rd level pairs. But it also seems really obvious that backtracking is going to be a disaster.

cpach

Ouch.

IMHO, this whole TLD seems kind of messed up from the start: https://en.wikipedia.org/wiki/.name

thbb123

Wtf, I have been using my x.y.name domain for everything, haven't been notified of this.

Should I rush to reserve y.name so my email address and personal website can stay online?

show comments
Ecco

Ok I don’t get it. Why not register `fraser.nameˋ directly? Or pick any TLD and register ˋ a 2nd-level domain (ˋfraser.tld`)? It just feels easier, plus this way you don’t have to pay for any new member of your family?

show comments
NewJazz

You might want to write to the CA attorney general. Former AG Xavier Becerra was able to dissuade ICANN from letting the .org fuckery happen, maybe Bonta could try to strong arm ICANN in this case.

show comments
ClarityJones

If this proves to be a viable business strategy, then verisign could equally use it to re-sell google.com, ycombinator.com, etc. to the highest bidder.

lacoolj

Dude, this is one of the craziest things I think I've read on HN

First, that a legit dealer could/did(does?) sell third-level domains at all (Verisign, no less) Second, that the top-level is staying available, allowing for second-levels to be bought/sniped like you mention.

If you do lawyer up and need help with legal fees, I think this would be a worthy cause.

doublepg23

I didn't even know I was using .name incorrectly...

niraj-agarwal

22,000 people affected. Link up and lawyer up is right. To have identity and existence taken away is a no go.

morissette

It seems as if only 40 people are needed for a class action suit. Me, not a lawyer. Gemini says chances are you could only get a refund. But maybe worth the fight for some.

xbar

I can only assume ICANN was co-opted by Verisign some decades ago.

aeternum

How would the avg person know that ..name is different and somehow more trustworthy than ..uk

Overall this seems like the right move, either they all are trusted or none.

akulbe

I don't get the concept of 3LD. We own kulbe.name - does this news mean it's going to go away entirely?

aff-vasileva

Turns out “buying your name on the internet” was technically just renting a room in someone else’s last name.

show comments
marbleotter115

.name is the part I keep having to relearn, so seeing it spelled out helps.

delduca

I never bet in any other than .com, .org, .net?

show comments
Maxforever

I saw it

jmuguy

I can't be the only one that assumed based on the domain that this was some bizarre DMCA action by Paramount.

show comments
basilikum

I seriously wonder what ICANN is good for.

mig4ng

And that kids is why it's always DNS fault.

Again, you're security is only as strong as your DNS.

r_lee

I would not use a 2nd level tld for a "stable presence". it seems like a gimmick

cjjuice

I really think ENS is on to something with blockchain based domain registration and management

show comments
Henchman21

How is it that they can just nullify the contracts they had with people they were providing services for?

TZubiri

https://itp.cdn.icann.org/en/files/consensus-policies/rsep-2...

>2.1. What effect, if any, will the proposed service have on the life cycle of domain names?

>None. There will not be any effect on the life cycle of domain names.

>2.2. Does the proposed service alter the storage and input of Registry Data?

>No. There will not be an alteration to the storage and input of Registry Data.

This sounds wrong? Is this just a knee-jerk form-filler reaction? It seems to me that the admitted "Upon discontinuation, no new third level domain names will be registered and existing third level domain names will be terminated."

In general this sounds like a grotesque misplay that is wildly uncharacteristic for the entity behind the timeless .com

swiftcoder

That's pretty shit. You'd think changes like this would need to go through a public comment period with the affected users (much like city planning decisions do)

xyst

Verisign is the worst. Hope author wins

show comments
johnnyApplePRNG

They deserve to lose their control of all domains over this.

This is ridiculous.

underdeserver

dang and team, perhaps it makes sense to special-case .name domains in the domain hint, like you do for GitHub and Ex-Twitter.

show comments
bix6

Fuck verasign. TLDs should be run as an actual public utility. Can these economic parasites be expelled already…

bawolff

I feel like TLDs as a concept are more trouble than they are worth. We should just have .com and get rid of the rest (except special purpose tlds).

1970-01-01

Instead of giving up, why can't all 22k .name owners move on to OpenNIC? They will not say no, you can't have that.

show comments
0xbadcafebee

Prediction: In 20 years, ICANN, IANA, ARIN become increasingly abandoned by nations wary of The Imperialist States of America's control over global communication & commerce, and the internet becomes an uber-net of nationalist internets, subverted by satellites.

khalic

Ah! verisign! Proving the world over and over what kind of scum they are

TZubiri

I wonder if this could constitute a violationiof article 6 of the UN declaration of human rights.

It has been established that national identifiers are protected by it, and a domain works as a sort of international identifier, in this case a personal one.

No one is obligated to give you a domain, but by contracting an obligation to provide that identifier until 2040, they would at least be liable for those damages, but there's an argument that depriving you of an identifier already granted is a more fundamental violation of a right to a name, an identifier and recordkeeping of them.

AtNightWeCode

Things like this happens from time to time and yet people insists on using stupid TLD:s just because of "cool" suffixes.

psychoslave

Breaking trust, one TLD at a time.

So, where is our fully decentralized TLD alternative, free of ICANN or any central authority to handle how we grant names by conventions, without any money scheme in the game that attracts malevolent actors moving only through greed strings?

Also, this time let’s make it like usenet, so "person:named:Neil Fraser" or even "::Neil Fraser" (harder to type but less culturally entangled into English).

show comments
eleventen

> Minutes after my daughter was born, I also registered beverly.fraser.name.

...minutes?

show comments
notorandit

It's just money. Nothing else. Just money.

rburhum

Lawyer up and fight it. This is bs.

nikanj

I wrote to ICANN support and got a template-AI answer wholly unrelated to my complaint about this:

”Greetings from ICANN Global Support.

I am sorry to hear you are experiencing this domain access issue after your registrar's transfer. I will happy to provide you with relevant information and guidance.

Please note that, ICANN accredits companies as domain name registrars and works to ensure contractual compliance with the terms and conditions of the 2009 and 2013 Registrar Accreditation Agreements (RAAs).

ICANN does not provide domain name registration or manage domain accounts. As a result of that ICANN is not able to perform domain management for you.

If you need help to access and manage your domain, you will need to contact your domain service provider or registrar for assistance.

You may check who your registrar is by doing a domain search at lookup.icann.org.”

Absolutely infuriating

strenholme

The correct way to handle this mess is to simply keep things messy. BGP tables are a big mess, for example, because a lot of companies keep their IPs when going from ISP to ISP.

But, assuming that Verisign can’t keep third level domains (as a DNS implementer, I don’t think third level domains is a huge deal; see thread below):

* Third level names where only one person has the second level domain should be transferred to whoever owns that single third level name.

* Third level names where multiple people have the same second level domain should be put up for closed bidding: Only current owners of .name domains with a given second level domain name (e.g. last name) will be able to bid for the second-level domain. So, if one has john.smith.name and joe.smith.name, Joe Smith and John Smith will be in a bidding war for smith.name.

If the issue of .name not being in public suffix is a real issue, Verisign can handle that by disabling new third-level .name registrations, and provide Public Suffix with a list of those registrations (just send all the owners a privacy notice, making it clear that the existence of the name will be made public for security reasons). More reading: https://github.com/publicsuffix/list/issues/2306 (There seems to be issues with this list being too long to keep in the Public Suffix because there’s too much software out there which can’t handle it. That seems strange to me: Even here in 2026 where RAM costs far too much, Deadwood can store a list of 240,000 blacklisted entries in under 10 megs; there are about 22,000 three-level .name domains and I could store that list in a way that could be very quickly looked up in about a meg of memory)

Now, personally, I think Verisign can keep these messy third level names, and are doing things this way so that Neil Fraser has to compete with every single 2-bit cybersquatter out there for the rights to fraser.name.

As an aside, it’s trivial to have DNS servers handle multi-level domains without having to have a zone file for every level; e.g. https://this.is.a.long.name.maradns.org works, and there’s no zone file for name.maradns.org, long.name.maradns.org, a.long.name.maradns.org, and so on.

Also, since people have brought up the “org fuckery” without providing details: https://bluecatnetworks.com/press/the-org-domain-sale-explai...

You know dang well if .org was owned by an investment entity, they would had jacked up the prices as much as they could get away with.

show comments
pmdr

> I had history with Verisign and did not trust them.

I don't know what that history is, but did it really make a tld used by only 22k people more appealing?

show comments
drnick1

> Second, my email address also disappears. Third, all the IoT devices that use services on this domain become bricks. Basically, I disappear from the Internet.

While changing email is inconvenient, I don't understand the point about IoT devices. IoT devices should not depend on the Internet at all for obvious privacy and security reasons. If you are using IoT devices with "cloud" accounts, then this is a blessing in disguise. Put that garbage in the trash and rebuild around HomeAssistant, Zigbee, RTSP, etc. I find it hard to believe that someone hosting their own website would fall for the cloud IoT scam.

show comments
jawns

Surely the author must have anticipated some heightened level of risk in pegging important parts of his personal and business life on a nonstandard TLD like this.

It's a pretty bizarre exception to the normal, intuitive ways that domains work.

I'll admit that it's a crappy situation and I would be frustrated in his place. But if I were in his place, I probably would have also thought it prudent to have a backup plan.

show comments