<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: TLDRisk</title><link>https://news.ycombinator.com/user?id=TLDRisk</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 04 Sep 2026 08:53:32 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=TLDRisk" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by TLDRisk in ".name Termination"]]></title><description><![CDATA[
<p>It's been through the Ombuds and a reconsideration request [1].  ICANN says:<p>> There will not be any effect on the life cycle of domain names. While the Requestor may disagree with Verisign’s response, the Requestor has not shown that ICANN relied upon false or inaccurate material information. The life cycle of a domain name begins when the domain is registered, then moves through various stages before ultimately coming to a close. Early termination of a domain registration does not impact the life cycle of the domain, as the domain can still go through the various stages of a standard life cycle. Moreover, as stated above, ICANN was aware that discontinuation of these registry services in the .NAME gTLD would result in the termination of approximately 22,000 third-level domain registrations and of email services/addresses.<p>I don't agree.  If I have a domain registered for 10 years the expected life cycle is for deletion to occur 10 years from now, not 90 days from now.  They've changed the life cycle by changing the agreed upon deletion date for the current registration term.<p>I could <i>maybe</i> see if they stop accepting renewals and delete the domains as they expire.  It's not a good look, but at least people are getting what they've been promised.<p>1. <a href="https://www.icann.org/resources/pages/reconsideration-26-2-spiridonov-request-2026-06-04-en" rel="nofollow">https://www.icann.org/resources/pages/reconsideration-26-2-s...</a></p>
]]></description><pubDate>Thu, 03 Sep 2026 22:44:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=49558150</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=49558150</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49558150</guid></item><item><title><![CDATA[New comment by TLDRisk in ".name Termination"]]></title><description><![CDATA[
<p>I thought I knew a lot about the policies and expectations when it comes to domains. I was surprised to see 3rd level domains called out in the .name registry agreement and I’m <i>stunned</i> that ICANN allowed this.<p>It’s incredibly one sided.  The registry gets to cut costs and the detriment to registrants is extreme. ICANN is supposed to act on behalf of <i>all</i> participants.<p>The flagrant disregard for DNS stability in this case is jaw dropping.</p>
]]></description><pubDate>Thu, 03 Sep 2026 18:54:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49554892</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=49554892</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49554892</guid></item><item><title><![CDATA[New comment by TLDRisk in "DNS abuse and criminal infrastructure"]]></title><description><![CDATA[
<p>> If you're starting a new commercial venture, something that cost $1000 and took a week would still be one of the cheapest and fastest parts of that process.<p>That's highly dependent on where you live.<p>I don't agree with the 3rd level domain structure.  In fact, I don't think ICANN should allow registrars to sell those without clear disclosure informing registrants they're not ICANN domains.  At the very least, registrars shouldn't be doing that to their customers.<p>In terms of abuse handling, you don't want to be a sibling to some unknown person or entity.<p>> Under the 'modern' system, the problem of "who do we need to contact about an obvious scam site" has been pushed up to the largest possible scale - the GTLD registries, whereas a scammer abusing a "free subdomain" would be shut down by the admins at that second level.<p>But I <i>want</i> my legitimate domain pushed up to the largest possible scale with a clear set of rules and independence from other registrants.  In terms of governance, the average registrant couldn't tell you the difference between a 2nd level domain and a 3rd level domain and the 3rd level domain comes along with additional risk.<p>As soon as you add 3rd level domains, that's an extra party that can drop your domain.  The 3rd level domain providers don't have a standard abuse handling mechanism.  I <i>think</i> most of them try to defer to ICANN's rules, but there's nothing that says they <i>must</i> do that.  As far as I know, ICANN only deals in TLDs [1].<p>What happens if you're on a 3rd level domain, there's an influx of abusive behavior by sibling domains, and the 2nd level owner doesn't do a good job of handling it?  Does the 2nd level domain get banned by the gTLD?  What kind of collateral damage does that cause?<p>Maybe you create something like the public suffix list, but then it's the same problem with more complexity regarding responsibilities.<p>I do agree with the general sentiment of letting people pay to prove trust.  I think it's really hard to come up with a number that makes sense, but I'd be willing to pay $X into an abuse handling fund if it bought me extra trust for my domain(s).<p>1. <a href="https://www.icann.org/en/contracted-parties/registry-operators/resources/list-of-top-level-domains" rel="nofollow">https://www.icann.org/en/contracted-parties/registry-operato...</a></p>
]]></description><pubDate>Mon, 31 Aug 2026 19:25:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49513858</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=49513858</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49513858</guid></item><item><title><![CDATA[New comment by TLDRisk in "DNS abuse and criminal infrastructure"]]></title><description><![CDATA[
<p>> At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?<p>I'd say "legitimate objections" is doing a lot of heavy lifting there and I don't like the idea.  Having the time and resources to monitor registrations becomes a barrier and that makes it a time and resource based system.  IE: Rich individuals and companies can pay a monitoring service that objects very broadly.<p>I've always been frustrated by systems like that and it seems like a lot of the tech industry is set up that way.  I've had my personal, family name, 25 year old domain put on Google's safe browsing block list and being the collateral damage in a hugely scaled system isn't fun.  Spending the time and resources needed to deal with it are far more of a burden for me than for a big company.  I was able to get it removed, but why should I be forced to pay for their mistake?<p>Ultimately though, any system is going to cost money no matter how it's structured.  If you're not paying directly, you're spending time or resources of some kind.  I'd rather pay directly because it's easier to understand.<p>I don't think you can build an all or none system for handling abuse because so much of it is subjective.  Even using what's legal vs illegal is difficult because a global system is going to have contradictions.  Online gambling is a good example.  Some countries would want the related domains banned for being illegal while others don't have a problem with it.<p>Domains are one of the core building blocks that makes a decentralized internet work.  Adding strong moderation tools to that is a huge risk because moderation and censorship are closely related.  Who determines what's trustworthy or legitimate or abuse or anything else?  What happens if a newly appointed authority claims transparency will enable bad actors?<p>Highly transparent systems with independent trust ranking make the most sense to me.  Any solutions need to be opt-in, or, at the very least, opt-out.</p>
]]></description><pubDate>Mon, 31 Aug 2026 17:22:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49512310</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=49512310</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49512310</guid></item><item><title><![CDATA[New comment by TLDRisk in "DNS abuse and criminal infrastructure"]]></title><description><![CDATA[
<p>> Any additional measures should not require ICANN to assume the role of a global content regulator or criminal-law authority.<p>> The community should instead consider whether contractual and operational arrangements adequately enable registries and registrars...<p>Those are things that are easy to say and hard to do.  From the perspective of a good faith registrant, the enforcement is already too complex.  There are hundreds of registries and thousands of registrars, all enforcing their own interpretation of the rules, so you end up with massive inconsistency.<p>No one wants their 10+ year old domain revoked for DNS abuse if they've been the victim of a security incident and it got misused, but dealing with that is hard and the economic structure of the industry isn't conducive to "intelligent" handling of complaints.  Any solutions will scale the same as big tech with massive, automated systems that turn good faith participants into collateral damage.<p>A big problem for the domain industry is the way registries are shielded from liability and registrants.  The registrars operate on thin margins and take on all the liability and customer support.<p>I don't think the registries will be given more responsibility.  That's based on a personal bias though.  I think the industry is set up to benefit the registries at the expense of registrars and registrants.<p>The registrars are the most likely party to be saddled with extra responsibility and I don't think that's a good solution because they have an economic incentive to look the other way.  It's also a weakest link industry so, even if Porkbun, etc. are working overtime to keep bad actors off their platform, there's always someone willing to onboard a scammer for a few dollars.<p>In my opinion, there should be more talk about a centralized system funded by fees that ICANN collects.  As a good faith registrant I want consistent, well defined rules with an appeals process, transparency etc..  I also don't care if I have to pay an extra dollar or two a year for my domains if it improves the industry overall.<p>Semi-related, does anyone know if there are any lists or decent sources for finding domains that have previously been suspended or put on block lists?  That would be useful info for would-be registrants.  No one wants to get surprised with a tainted domain.</p>
]]></description><pubDate>Mon, 31 Aug 2026 16:06:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=49511376</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=49511376</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49511376</guid></item><item><title><![CDATA[New comment by TLDRisk in "Google Workspace thinks my domain is an email provider (2025)"]]></title><description><![CDATA[
<p>Both .com and .net are price controlled.  I think for the rest of the gTLDs it would be allowed.  There’s a lot of nuance to it.  The registry agreement never mentions premium domains, only pricing rules, so being accurate about the rules takes a long explanation.  That’s why I made the site I linked.</p>
]]></description><pubDate>Mon, 24 Aug 2026 11:39:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=49418304</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=49418304</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49418304</guid></item><item><title><![CDATA[New comment by TLDRisk in "Google Workspace thinks my domain is an email provider (2025)"]]></title><description><![CDATA[
<p>> Just for context, this is a premium domain with a very high premium renewal fee, no history of abuse obviously.<p>The registry premium domains on the new TLDs have several issues.  The biggest IMO is a lack of price protection.  Non-premium domains at least get the cohort based protection from section 2.10c of the registry agreement.<p>So, in addition to being treated as a 2nd rate domain, there’s nothing stopping the registry from cranking up the price if a domain gets popular.  I don’t think it’s ever happened, but have never found contractual terms that forbid it.<p>I made a website about it a while ago after a registry reclassified one of my domains from standard to premium.<p><a href="https://tldrisk.com/beyond-basics/premium-domains/" rel="nofollow">https://tldrisk.com/beyond-basics/premium-domains/</a></p>
]]></description><pubDate>Sun, 23 Aug 2026 22:53:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=49413394</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=49413394</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49413394</guid></item><item><title><![CDATA[New comment by TLDRisk in "Never buy a .online domain"]]></title><description><![CDATA[
<p>It's the registry, not the registrar.  I made a website that tries to help explain some of the lesser known nuances and risks relating to domains.  The section about domain reclassification is based on first hand experience and is especially interesting IMO:<p><a href="https://tldrisk.com/beyond-basics/reclassification/" rel="nofollow">https://tldrisk.com/beyond-basics/reclassification/</a><p>> This basically makes the entire TLD unviable for serious use.<p>It doesn't just make the TLD in question unusable.  I think it makes most of the new gTLDs unusable.  Registries can enact policies and systems like this, regardless of the detriment to registrants, due to a lack of oversight and registrant consideration by ICANN.  That creates uncertainty and makes it pragmatic for registrants to simply choose the gTLDs with lots of history and precedence; .com, .org, etc..<p>The only two TLDs I'd personally rely on are .com (gTLD) and .ca (ccTLD).</p>
]]></description><pubDate>Wed, 25 Feb 2026 22:51:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=47159191</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=47159191</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47159191</guid></item><item><title><![CDATA[New comment by TLDRisk in "From .com to .anything: Top-Level Domain (TLD) Insights on Cloudflare Radar"]]></title><description><![CDATA[
<p>It's almost impossible to judge based on the pricing alone.  Paying top dollar doesn't guarantee anything extra and low prices don't always mean low quality service.<p>$6.99 looks like a first year discount at dynadot with renewals at $10.88 USD.<p>> Why such a huge difference?<p>A lot of registrants don't know what the wholesale pricing looks like and the difference between $10 or $25 / year for a business isn't a factor.  The risk that comes along with transferring to a cheaper registrar isn't worth it to save $15 / year.</p>
]]></description><pubDate>Tue, 28 Oct 2025 00:09:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=45727894</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=45727894</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45727894</guid></item><item><title><![CDATA[New comment by TLDRisk in "From .com to .anything: Top-Level Domain (TLD) Insights on Cloudflare Radar"]]></title><description><![CDATA[
<p>> And what happens if your domain gets popular, are they going to just jack up your rent from $25/yr to $500/yr or more?<p>As long as your domain is in the standard fee class, aka non-premium, they can't target it for a price increase if it's a gTLD.  They have to raise the price of all standard domains at the same time.<p>Everyone will tell you they can't reclassify a domain from standard to premium, but that's not technically correct.  They can change the classification to whatever they want, but they have to charge you standard renewal fees if the domain had a standard classification when you registered it, as long as you haven't let it expire.<p>I created a website that has some info about domain reclassification.<p><a href="https://tldrisk.com/beyond-basics/reclassification/" rel="nofollow">https://tldrisk.com/beyond-basics/reclassification/</a></p>
]]></description><pubDate>Mon, 27 Oct 2025 22:42:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=45727190</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=45727190</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45727190</guid></item><item><title><![CDATA[New comment by TLDRisk in "PyPI Preventing Domain Resurrection Attacks"]]></title><description><![CDATA[
<p>The ERRP only covers gTLDs, right?  Have you seen any ICANN policies requiring ccTLDs to adopt the same grace periods.  As far as I know, ccTLDs can do whatever they want.</p>
]]></description><pubDate>Tue, 19 Aug 2025 21:58:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=44956649</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=44956649</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44956649</guid></item><item><title><![CDATA[New comment by TLDRisk in "PyPI Preventing Domain Resurrection Attacks"]]></title><description><![CDATA[
<p>Domain expiration is something that's more complicated than most people realize.  As an example, I'm not sure if there's a definitive source stating that auto-renew grace is part of the ERRP.  In my opinion it's not and the ERRP typically won't trigger for high value domains because they'll be sold or auctioned by the registrar instead.<p>As far as I know, the ERRP rules describe the policies for the <i>deletion</i> of expired domains, which isn't required, so working off the auto-renew grace status was a good choice here.  Most people don't realize that expired domains aren't guaranteed to go through the ERRP lifecycle [1].<p>> You should be aware that during the auto-renew period, the domain name <i>may be available to third parties for registration</i>, depending on your registrar's terms of service. You may also run the risk of having your domain name auctioned to a third party by your registrar during this period (depending on your terms of service)<p>The process described here sounds like a pretty reasonable approach to a hard problem.  It won't catch everything, but it's a good approach and it's nice to see some effort put into the issue.<p>1. <a href="https://www.icann.org/resources/pages/registrant-about-errp-2018-12-07-en" rel="nofollow">https://www.icann.org/resources/pages/registrant-about-errp-...</a></p>
]]></description><pubDate>Tue, 19 Aug 2025 21:47:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=44956571</link><dc:creator>TLDRisk</dc:creator><comments>https://news.ycombinator.com/item?id=44956571</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44956571</guid></item></channel></rss>