.org doesn't mean credible
dotorgdoesntmeancredible.org
dotorgdoesntmeancredible.org
If I start a new taco truck company and put "burrito.services" or "burrito.catering" or "burrito.ai" in a huge font on the side of the trucks, a fairly large number of people aren't going to immediately recognize that as a web site address.
On the other hand, if I'm lucky enough to get the domain burrito.net , most people will recognize that as something they can type into a web browser address bar.
www.burrito.ai or https://burrito.ai is obviously a website to any layman.
Yes -- a server admin will tell you they are all different but generally speaking it will redirect to a preferred naming convention.
wit.ai
www.wit.ai
Well, unless you put "http(s)://" in front of it.
Go with "https://www.burrito.services/" and make it blue and underlined, just to be safe. I'm kind of kidding, but I also kind of suspect the blue font and underline would probably be more immediately recognizable for many people than the HTTPS protocol prefix.
On the other hand, I guess most people probably aren't typing the url out anyway but googling it instead.
"BURRITO.CONSULTING"
I'm going to think, "uhhh, is that a website? Well, I recognize .consulting as a TLD. I guess it must be. But that's weird..."
but then if i see the same sign
"WWW.BURRITO.CONSULTING"
I'm going to think: "Well that's definitely somebody's website, but what a weird and anachronistic way of printing it, and why is it using one of those new long generic TLDs anyways..."
People outside tech generally don't realise that domain.tld and www.domain.tld are two separate hostnames, and adding www. makes it much more recognizable to the general public.
So for subdomain.burrito.com, we redirect the wwww.subdomain.burrito.com
People are just so used to it.
1. Avoiding the relatively common pairing of {a host whose IP address changes without warning so you need to CNAME it; a DNS provider that doesn't offer CNAME flattening a.k.a. ALIAS a.k.a. ANAME}.
2. Scoping session cookies so user agents don't also send them to your subdomains.
And maybe even more stuff I'm forgetting.
Humanity is great at this stuff. Natural language is enervated with side channels everywhere. At some point, people may converge on "what a TLD looks like" and new TLDs will often have an ineffable TLD-ness about them.
too late.
EDIT: In case it's not obvious, the fact is that most people don't type the website address in the URL bar. They type it in the Google search bar.
The effect is that people have to now remember two generic dictionary words. "burrito" and ".catering", or wait, wasn't it "tacos" and ".food" or something? And like you said, I'm sure most people don't even recognize that ".catering" is a TLD, whatever that is, and the domain name just looks like `<genericword>.<genericword>` making it all the more confusing and arbitrary.
It's like having to remember where the periods went in "del.icio.us" and, if you couldn't, googling "delicious" (until it caught on) was incredibly unhelpful. Just like googling "burrito catering" doesn't necessarily take you to "https://burrito.catering".
I think even a random brand name + ".com" is still preferable to most of these new TLDs.
Like Qdoba, choose something unique. The domain caterrito.com is a little overspecific, but memorable, unique, easily trademarked, and available.
All we need now is to create a syntax for "internet identifiers" which is instantly recognizable as such. Enter ... drumroll ... @burrito.catering?
The choice of generic words like "burrito" and "catering" is a marketing decision. The original example was mostly a placeholder.
I've also tried explaining to her that the address box doubles as a search box, but she still goes to google.com to search. ¯\_(ツ)_/¯
Ugh. Lesson learned.
Also ultimately your domain name and wherever its MX record points to is the start of authority for setting up official business accounts with all of the popular social media promotion channels (you sure aren't letting your social media people run the company instagram page from an account linked to their personal gmail accounts, are you?)
By no means would I say that people should ignore all the other ways of driving traffic to a company's online marketing presence, via all other modern means of social media (instagram, tiktok, facebook, twitter, whatever is the new hot thing of the current year). And having a dedicated app, partnership with third party food ordering services if you're something like a burrito delivery service.
If you're running a burrito truck, there's a good chance this is exactly what's happening.
Many of them have companyname@gmail.com business email addresses and while I hope their social media accounts are at least registered from that email account, I wouldn't be surprised if many are linked to a personal account. That is, if they have a dedicated email account for the business at all. Especially with older non-tech-savvy small business owners, there's a chance they just use whatever email address someone made for them.
I already suspected that reliably sending an email from an .xyz domain is very difficult, but I learned the hard way that that lots of enterprise filters also block emails that contain links to any domain ending with .xyz, so we had to use something less fancy, so a longer .com was it.
- Ben Shapiro was not the secret 7th member of Monty Python
- wildebeest did not solve Fermat's Last Theorem
- Joey from New Kids on the Block is not the real author of Bach's Toccata and Fugue in D minor (BWV 565)
The appropriate counter is: "learn to think critically"; replacing one narrow blindly-followed fallacy with another isn't progress.
Credibility cannot be inferred from tlds.
I asked my two sisters, in their 20s (not in tech): they both had this misconception from school. A friend (not in tech) did too, but only until he tried registering a domain of his own and saw he could get .org. My mother (also not tech savvy) trusts .gov more than .edu or .org, but didn't realize that anyone can purchase the latter ones.
I asked her why she trusted .gov over the others, she paused and laughed as she said "well the government wouldn't lie to you!" :)
Therefore, I am forced to fall back to my default position that `.org` sites are inherently credible.
With that in mind, I object to all the points the author makes.
In conclusion, we should cut off the oxygen to all astronauts currently in hibernation.
Wait... RecursionError: maximum recursion depth exceeded
Also wanted to add that for sites you go on a lot, Amino seems to be a pretty good browser extension for saving modifications persistently.
Then I realized the site name is in a thin red font on a dark background.
... and to stay on topic, .org may not be credible, but the indistinguishable-at-a-glace .ong is absolutely vetted. So keep an eye our for that ;)
I think my highlight color is set at the OS level, at least on my Mac.
https://www.google.com/search?q=abry+partners+donuts+dot+org
(There is some sparse discussion that the gs_lcp parameter may contain an encoded form of your physical location. "When in doubt, leave it out" is a good policy to follow for such things.)
I guess the fact that I was heavily involved in open source (where every single project used .org domain if available) never made me think they were in any more "reputable" than eg. .com.
So, how did anyone ever get the notion that they were restricted to non-profits? I know that "choosing your domain name" guides at the time mentioned how .org is a good candidate for non-profits, but how did that evolve into "only registered non-profits can get a .org domain"?
I believe RFC 920 [1] was the guiding document when .org was established in 1985. It cites no restrictions on .org second level registrations, merely that "ORG = Organization, any other domains meeting the second level requirements."
If you look at the provided examples of .org miseducation, they seem to be quite old.
> Instead, we should be providing everyone with the critical thinking tools they need to evaluate and assess sources themselves.
This kind of thinking is incredibly important. Many believe in only following one or two "credible" news sources instead of trying to get the point of view from a variety of outlets. Others like to block a list of websites which someone decided was fake news.
There is no easy way to determine what is true and what is false. In fact, most of the time there is no definite "right" and "wrong" - instead, both sides of an issue will have important pieces to consider. In fact, there's hardly ever just two sides to an issue, rather, a wide range of opinions.
I was not taught this in school. I was taught to trust .org websites.
A trouble with trusting news that's true instead of fake is it misses the point that even true news gives a false feeling even if all the facts are true. They use scary language, omitting inconvenient facts, subjective exaggerated sounding words, quoting real people stating false facts, etc. Those feelings have actual consequences on how people vote and what decisions they make. For example, the great Pacific garbage patch was shown dramatically on TV a so dense you could just about walk on it and led to people not wanting to put plastic bags in the landfill. They were so overwhelmed by the demonization of plastic, they didn't pay attention to the facts. That whole Trump thing was filled with it too. They didn't really lie but they made all his actions sound bad so people hated him.
He certainly did some really bad things like mismanaging Covid, but most of the hate was about things he said, not things he did like invading Iraq or wiretapping his political opponents' headquarters like previous widely hated presidents have done.
Some of the hate was even about his physical appearance - the color of his skin, his hairstyle, the shape of his hands, etc. That absolutely wasn't earned. It was just hateful people spreading hate.
Let's talk about the border: Trump literally campaigned on the slogan "I'll build a wall and have Mexico pay for it." And what did he do in reality? When attempts to make Mexico pay for it failed miserably, as predicted by anyone with common sense, he begged and bullied congress (to the point of a government shutdown, no less) to put aside American taxpayer dollars for it. When that too failed, he attempted to pilfer money from various other government departments like homeland security and defense. By comparison, Biden has shut down construction and returned that money for its original uses. And I'm not even sure what you're talking about with that "open borders" nonsense. Nobody has ever actually advocated for that other than the bogeymen from the fevered nightmares of Fox News commentators. You're buying into your own propaganda.
As for North Korea, they were antagonized by Biden calling their nuclear program a "serious threat" to American and world security. What did Trump say again? Oh yeah, he called Kim Jong Un "Little Rocket Man" and said that North Korea "will be met with fire and fury like the world has never seen". I consider us all lucky that so much of Trump's administration turned out to be all talk and no action.
And yes, Covid. How many hundreds of thousands of Americans are dead because he refused to acknowledge reality and continued to lie and undermine public caution towards the pandemic? What other moron could possibly turn something so simple, easy, and painless to do as wearing a mask in public into a full blown culture war? Now we have grown adults whining and crying like petulant toddlers when asked to put on a fucking mask.
Yes, now I'm starting to lose my temper and ramble, but fuck it. That's how angry I get when I see people try to minimize the monstrous idiocy of the Trump presidency as just being the big bad news media out to get poor Trump. I could go on and on like this, but instead maybe I'll just call him a fat, orange, tiny handed imbecile with the world's most absurd combover - not because I hate him for these things (honestly, I couldn't care less about his appearance) - but because it relieves a little bit of the anger caused by him constantly running the country into the ground while claiming that he's making it great.
Then I show them http://www.dhmo.org/ and a .edu hosted anti-science web site from a religious university to prove it isn't true. Then on the test they still say you can tell if a site is credible because it is a .org or .edu...
Got the link to this one, I’m curious on the specific topics they argue against and if I know the university.
Focused on acting in the public interest: Whether in support of education or health, the environment or human rights, members of the community work for the good of humankind and/or the preservation of the planet and do not promote discrimination or bigotry. Non-profit making/non-profit-focused entities: While many NGOs and ONGs engage in commercial activities or generate revenue in support of their missions, members of the community do not recognize profits or retain earnings.
Limited government influence: Recognizing that many NGO and ONG organizations have important interactions with government, not least for reasons of funding (which may include receipt of some government funding in support of their programs) members of the community decide their own policies, direct their own activities and are independent of direct government or political control.
Independent actors: Members of the community should not be political parties nor should be a part of any government. Participation in the work of a NGO/ONG is voluntary.
Active Organizations: Members of the community are actively pursuing their missions on a regular basis.
Structured: Members of the community, whether large or small, operate in a structured manner (e.g., under bylaws, codes of conduct, organizational standards, or other governance structures.)
Lawful: Members of the .NGO and .ONG community act with integrity within the bounds of law.
Even if that were true, how would it indicate any credibility? Being a nonprofit (a) is defined differently in every country and (b) in the US, just means that the organization advances some sort of social purpose (may or may not be one you agree with) and does not accrue profit on behalf of its members. It in no way means they are trustworthy nor that they are qualified to speak on the issue at hand.
No, it doesn’t even mean that, unless “social” is defined away to meaninglessness, since a nonprofit can serve virtually any imaginable human purpose; it.can’t return a profit, but it can exist to drive on for a group of firms (trade associations are a valid class of tax-exempt nonprofits.)
Some categories of nonprofits, particularly donation-deductible charities, are defined by social purpose, but the category as a whole is not.
Which meant that the Red Cross did not qualify - that application quickly got kicked out I seem to recall
I had a similar point that ".com" doesn't need to be a commercial entity.
She continued to berate me in front of the class. I got detention and was told that all my .com domains were illegal.
Ah - the educational system at it's finest.
1) Those who can, do.
2) Those you can't do, manage. (partially "Peter Principle" imho)
3) Those who can't (even) manage, teach.
4) Those who can' (even) teach, audit.
Is it running some Javascript triggered by the scroll event? I've blocked that with a ublock rule.
We were being taught about the internet. The teacher made a weirdly specific rant about how wikipedia was unsafe. Two slides later and we were told that org domains were more trustable than com. I pointed out that wikipedia was an org domain. I was sent to the principal's office.
Fun times.
As for .com versus .org, I think we may have been told that .org was somewhat more trustworthy than .com. But we were generally told to favor .gov over both anyways; outside of that, it was a matter of understanding the webpage context to know who was publishing the content and attempting to assess their biases and how that affects the trustworthy content. Definitely would have been something about how even a .edu page might not reflect academic research anyways (since students might have their own personal webspaces on a .edu site).
Not necessarily. Consider a good textbook or paper on, say, physics, for example. The textbook will not just tell you things, perhaps with a bunch of references. It will actually construct the theoretical model(s) it is going to use, step by step, starting with premises that are either common knowledge or are supported by experiments (an example of the latter is the premise that the speed of light is the same in all inertial frames, which Einstein used to construct the theoretical model of special relativity in his famous 1905 paper). You don't have to already be knowledgeable about the topic to evaluate what you're reading. You can evaluate it on its merits: are the premises true, or at least reasonable? Is the construction of the model valid?
There are some articles on Wikipedia that actually try to do this; but the ones that do it correctly, that I've seen, aren't on topics that are at all disputed. That's why I put that qualifier in my statement.
> The thing about Wikipedia is that for most popular topics that you aren't knowledgeable about you can be sure they've been reviewed by thousands of users and kept somewhat reliable and up to date
You must be joking. Most articles on Wikipedia have only been reviewed by a small number of people. And for any topic that is at all disputed, those people are all partisans, and usually they are mostly partisans of one side, who revert or overwrite any contributions they disagree with. In some cases, when there are vociferous partisans on both sides, the whole process breaks down and it's basically impossible to get any useful content into an article.
Yes, agreed.
Usually it’s just a strangely worded sentence (common on biographies of not-famous people). Every now and then I’ll find completely fabricated information with sources that either a) don’t exist at the URL or b) say something completely different.
Wikipedia at least has some level of review.
I never bothered to take it further, so the plagurist's book is still available and has been used as a citation in other Wikipedia articles [2].
[1] https://en.wikipedia.org/wiki/Talk:Jindalee_Operational_Rada...
[2] https://www.google.com/search?q=Joseph+Babatunde+Fagoyinbo+s...
I've definitely run into a few cases where this loop exists already, the most annoying one being the age of the Susquehanna River (whose current cite for age is a publication which explicitly cites Wikipedia).
https://en.wikipedia.org/wiki/Wikipedia:List_of_citogenesis_...
There are also some bots that help auto tag articles with these issues
On the other hand, I still have an almost instinctive aversion to all the sites with new TLDs that I come across in search results, because they almost always seem to contain SEO spam or similarly vapid content.
Likewise, .ws and .us used to be the TLD of choice for cracks, warez, and all the "fun" stuff.
Either way, I think all TLDs do have an implicit bias associated with them. For me, .com .org and .net are a neutral connotation. They don't mean "credible", but also don't "stick out like a sore thumb" unlike some of the other newer ones.
for SEO stuffers, spams, scams and phishes, a lot of these new TLDs are popular because they're used in a disposable fashion. Many of them have first year promotional pricing of $2 to $6 to register the domain (as compared to $9-10 for a .com), but the price goes up to $25/year for all subsequent years. People using the domain names like a throw away paper towel, registering dozens or hundreds of them, only care about the first year cost, because there's no way they're going to keep using the same one beyond 12 months.
In other news: content author fails to provide sources for claims.
Also, I own a .org , and I'm not sure I'm credible at all, so quod erat demonstrandum, I guess.
Correct is was intended for non-profits, while I don't know that was ever enforced.
However when .org was created nobody was thinking about ads. They appeared maybe ten years later.
So, for .org.x domains for certain x at least, it does mean credible.
Restricting access to .org to just registered non-profits would be just pointless, because there are some notable parties that may not ever receive official recognition, e.g. human right activism in Belarus.
Unless .org would be restricted to US-based organizations only, that would make a whole lot more sense.
While I took advantage of this as a high school student, I assume faculty and non-teaching staff, as well as alumni, could have done likewise.
At this point, TLDs matter about as much as your area code. They ceased being useful in the mid-2000s.
Someone tell that to in-addr.arpa, lol. It's certainly still around https://www.iana.org/domains/arpa
The author really should've checked later RFCs.
.org is a great way for low-income websites to stay on the internet. I run a tiny organization, so I use .org.
Their mission statement:
> ICANN's mission is to help ensure a stable, secure, and unified global Internet.
>... I still have an almost instinctive aversion to all the sites with new TLDs that I come across in search results ...
(Among some other comments, that was just the nearest one.)
So, the likely answer is, "All sorts of people."
If I'm just browsing, I don't really notice them. I have a bunch of domains, and many are .us because it's nice and short with many names available.
At a small town bank, whose risk tolerance is maybe one major loss event per decade? Where a given complaint is never more than 3 people removed from the CEO? Who'se antifraud resources are just normal bankers that also have some extra tasks assigned to them?
Being able to get homoglyph attacks off the risk board at the cost of a few of my billable hours and a week of effort from the marketing person is a no-brainer to them.
> $ host -t ds bankofamerica.com
bankofamerica.com has no DS recordI am unaware of any similar (ab)use of .gov or .mil, however.
And .org never ever meant anything at all.
.mil and .gov have always been controlled by the US government,.and since 2013 local governments in the US may register a .gov domain.
> The URL had been registered back in 1999, before 2001 regulations restricted the “.edu” designation to accredited higher educational institutions. “[D]espite its misleading top level domain,” noted Kathleen Fitzpatrick (2015), head of scholarly communication at the Modern Language Association, “Academia.edu is not an educationally-affiliated organization, but a dot-com.” Like other prior domain filings, Academia.edu was grandfathered in, granting the startup a time-sealed patina of nonprofit credibility
Why is it slashdot.org and not slashdot.com? Because .org addresses were $10 and .com were $40 at the time
NO .org is not that at all - I used to work for a registry who bid for the .org
>.COM
>This domain is intended for commercial entities, that is companies. This domain has grown very large and there is concern about the administrative load and system performance if the current growth pattern is continued.
SSL is important but a valid SSL certificate doesn't mean a site is safe.
An invalid (or nonexistent) SSL/TLS certificate doesn't mean a site is illegitimate.
A site without a user facing login really doesn't need SSL. And SSL is pointless on said site if it's for instance a Let's Encrypt.
An example of misleading info (highlighted): https://www.cloudflare.com/learning/ssl/what-is-domain-spoof...
Unfortunately this is not the case. Site security serves not only the purpose of protecting user input, but also ensuring that the data you are receiving has not been altered, ammended or replaced.
At the low level it stops an ISP injecting their own ads or tracking, at the high level it prevents the injection of malicious code downstream from the site itself.
Things like link-replacement, javascript injection, altered text, and so on make even read-only style sites untrustworthy over plain http.
This is not a theoretical issue which could technically become real, it's actually being done.
Depending on the ISP is trust worthy. In this day and age, none is trust worthy. Any network between server and browser can alter the content if it is NOT ssl encrypted. In US it is very often you see Verizon (not to single them out) modify the http content before they deliver to you. I guess it all comes down to if you want to get the actual content that is unmodified by the network routes between you and the server.
That isn't pointless SSL. Let's Encrypt isn't going to protect you from nation states, but cyber criminals aren't going to be invested or necessarily sophisticated enough to get Let's Encrypt's CA keys. Also, if you are worried someone will take over your Let's Encrypt automation and generate new certificates, they probably could use the same RCE to get at your private keys or directly sniff traffic from the compromised system.
If you qualified this statement with "if the business is large cap", everyone would agree but then again that's why BigCo uses traditional CAs or roll their own.
Depends what you mean by need. SSL/TLS still provides benefits like privacy (from third parties) on what you're viewing on the site, as well as no malicious content being injected. It's not just useful to protect your POST requests of username and password.