I can see something like `iphone.apple` and `ipad.apple` etc..
I can see something like `iphone.apple` and `ipad.apple` etc..
I can give you some benefits of brand TLDs, though. For starters, the entire .google TLD is HSTS preloaded, so every new site launched on that TLD is instantly HTTPS-only from its very first moments, rather than waiting for potentially many months for users to upgrade their browsers to incorporate new additions of individual domains to the list (which would be your only recourse if you launched a new domain on e.g. .com). And secondly, the .google TLD is closed, meaning no external registrations, so if you see an unfamiliar product.google domain then you immediately know that it's actually Google running it, whereas if you saw an unfamiliar googleproduct.com domain then you'd want to do some due diligence to ensure that you aren't being phished.
(I should probably at this point disclose that I run .google, but had no involvement in the larger process at ICANN that resulted in the creation of brand TLDs in the first place. But, given that brand TLDs exist, of course companies would defensively secure the TLDs for their largest brands, and once you have said TLDs, why not use them?)
because it pollutes the root domain, which means:
1. More phishing opportunities. Aunt Barbara can barely tell the difference between chase.com and chase-secure-login.com. Allowing baddies to register chase-login.security is only going to make things worse.
2. I can't tell what's a domain anymore. In the past I can reasonably use the heuristic that any string matching the pattern[1] was a domain name. Now I have no idea. Is foobar.technology an actual website or just a brand name? Who knows! Come to think of it, I couldn't remember whether it was foobar.tech or foobar.technology. Or maybe they hit it big and now they're just blog.foobar?
>I can give you some benefits of brand TLDs, though. [...]
Every benefit you've listed can be had by having all your websites run off your main domain (eg. blog.google.com vs blog.google).
[1] https://regexper.com/#%5Ba-z0-9-%5D%7B3%2C%7D%5C.%28%5Ba-z%5...
There's already an effectively infinite number of phishing opportunities just on .com alone; having more available TLDs doesn't make it appreciably worse. Indeed, Chase having .chase and .jpmorgan (which they do) makes things better, because if you see a .chase domain name then you know for sure that it's actually Chase. Any random .com could just be any random .com.
> I can't tell what's a domain anymore.
Try resolving it? You never could tell conclusively what was a domain name without resolving it anyway. Is asdfhjasdflkghasdgf.com a real domain name? Hell if I know. I sure can't tell just from looking at it. Is asdfhjasdflkghasdgf.technology a real domain name? Again, try resolving it.
> Every benefit you've listed can be had by having all your websites run off your main domain (eg. blog.google.com vs blog.google).
There's lots of downsides to running everything off one domain name. For example, big potential security vulnerabilities from cookie leaks between your more secure sites and your less secure sites. Google's blogs for example used to be hosted on googleblog.com, blogspot.com, and blogger.com. They already never shared the same domain as google.com for security reasons that long pre-date the existence of .google.
And as for your heuristic regex:
[a-z0-9-]{3,}\.([a-z]{2}|com|org|net)
You should like the new gTLDs then, because the state of things now is even simpler and can be expressed as: [a-z0-9-]{3,}\.[a-z]{2,}
Also, your previous heuristic was already incorrect because it excludes a variety of common legacy gTLDs such as .gov, .edu, .mil, .info, .biz, etc. that all pre-date the most recent gTLD expansion. It also already included TLDs that don't exist anyway (not all 2-letter combinations are valid ccTLDs), so in that sense it's not any different from the simpler one.There's an infinite amount, yes, but in the past the amount that plausibly looked liked your domain was small. You also don't have the ambiguity of chase.com or chase.bank, although this is a bigger issue with smaller companies than it is with bigger ones.
>Indeed, Chase having .chase and .jpmorgan (which they do) makes things better, because if you see a .chase domain name then you know for sure that it's actually Chase. Any random .com could just be any random .com.
Is this significantly better than trusting that jpmorgan.com or chase.com is the "legit" address (basically, treating .com as the "root" domain)? There are some instances where this heuristic is wrong (nissan.com), but at worst you land on the wrong website. Phishers probably won't bother spending tens of thousands of dollars on a .com domain just to phish some credentials. It's probably cheaper for the company as well: buying a .com from a squatter is probably cheaper than paying ICANN the $200k application fee + $25k annual fee of a gTLD.
>Try resolving it? You never could tell conclusively what was a domain name without resolving it anyway.
This isn't in the context of "checking whether a domain is valid", it's in the context of "is this string referencing a website or not?". If I see a billboard with "foobar.com" at the bottom, there's very little doubt that it's a website. If it's foobar.technology, I'm not so sure.
> There's lots of downsides to running everything off one domain name. For example, big potential security vulnerabilities from cookie leaks between your more secure sites and your less secure sites.
While that's true, getting a whole new TLD seems like overkill, not to mention that you can get the same amount of isolation by enrolling in the public suffix list.