Government URLs that don't end in .gov
github.com
github.com
It just seems to me that it would be more secure, and more reassuring to citizens and visitors that they are on the correct site it's under a cctld that's clearly affiliated to and managed by that government.
0: https://www.gov.uk/apply-for-and-manage-a-gov-uk-domain-name
--
Edit: turns out .gov is exclusively for the US, not sure I feel good about that, particularly as .com and .net are very much not just for the US.
The possibility of the US government creating a .gov specifically to confuse uses in a foreign country isn't ideal.
I get it, you invented the internet, but the special status you have over it is a little frustrating.
https://www.whitehouse.gov/wp-content/uploads/2023/02/M-23-1...
Or .edu vs. .ac.uk; .mil vs. .mod.uk.
They got there first and just spread over TLDs before consigning other nations to fit under one I suppose.
Maybe this is my latent American nationalism showing, but isn't .gov "clearly affiliated to and managed by" the US government?
I think this bit was added as an edit or maybe I just missed it:
> an inherently international .gov domain
.gov is not inherently international for all the reasons in this subthread (and probably others as well)
I think the poster wasn't talking of the US government but of knowing which government a domain is related to by just looking at it. ".gov" is not clear while ".gov.uk" is clear due to the ccTLD.
> but isn't .gov "clearly affiliated to and managed by" the US government
I would say no. What makes it clear to you?
Not the OP, but also American. For me it's clear because I've never seen a US government site on a non-.gov domain (though apparently some obscure ones exist as this submission points out), nor have I ever seen a non-US-government site on .gov.
The submission includes over 400 domains for the federal only list. That is more than "some obscure ones"
> nor have I ever seen a non-US-government site on .gov
How often are you going to non-US-government government sites? Being an American I could imagine you hardly if ever interact with any other government sites so maybe that could be attributed to selection bias.
The number has nothing to do with how obscure they are.
> Being an American I could imagine you hardly if ever interact with any other government sites
I have interacted with them many times. (1) to fill out various Covid-related entry forms when those were widely required, (2) to apply for visas, (3) purely out of curiosity (e.g. I’m sometimes curious what travel warnings/advisories other countries’ foreign ministries put out and how they compare with our own).
I won't go so far as to say that the internet is an American invention but it was certainly primarily American in origin. .gov has been managed by the US government since the beginning.
The us also has .mil locked up for mostly purposes.
Load any name on the TLD, lol, what?
I understand the point you're arguing for, and mostly agree!, but the end-around is...weird.
Plenty of exceptions abound, though: https://en.wikipedia.org/wiki/.gov#Use
Come to find out that the k12.ca.us. domain is completely defunct! There is no SOA for it, and WHOIS indicates it's inactive. k12.ny.us. seems to be in the same condition. However, there are still k12.<state>.us. domains in other parts of these USA. If you search for them, you can find websites and email addresses under that hierarchy.
https://en.m.wikipedia.org/wiki/.gov (Which seems to make my guess right, .gov is operated by the US Government)
For how many decades is this going to be a reasonable argument?
In 100 years, will it still be reasonable for the USA to say "we built the thing, so it is appropriate for us to continue to be the default country in domain names. The rest of you must use your ccTLDs, but we remain special."
In 200 years?
The only non-pathetic option is for the United States to transition to using its .us ccTLD for governmental and military domains in particular, with .edu and probably some others not far behind. The only question is how gradual the process is, and when it starts.
The real answer is that it’s way too much work to change now for essentially no benefit, so it will probably continue indefinitely unless a new system supplants the current internet.
Cool, here's a $50,000 firm fixed contract for you to go fix all the hardcoded .gov references in every single federal website, knowing how many of them will fail to handle redirects gracefully.
Just because you don’t like that the US government has first mover advantage isn’t a good reason to change this.
It's a pretty simple matter to register a corresponding .gov.us domain for each existing .gov domain. Then each .gov domain owner would have to configure their web server properly, and can phase in a redirect from the old .gov to the new .gov.us.
Prior to this happening, the .gov site could have a big banner across the top of the page informing visitors of the change. This could remain for as long as seems reasonable before changing, even multiple years.
> Just because you don’t like that the US government has first mover advantage isn’t a good reason to change this.
As an American, I think the current setup with .gov (and .mil) is super weird. The fact that there are so many US government websites that are under .com, .org, and even .us, is weird too. The US shouldn't hold any kind of privileged place when it comes to TLDs; it's clearer for everyone concerned -- including Americans -- to put all these under .gov.us.
Do you have the US Government doing it quicker? The only way it ever occurs is if they effectively CNAME .gov to .gov.us to run them both side-by-side.
Edit: I’ve been in stacks of microservices for a while, and it just occurred to me that I’m not sure how cookies can be migrated between domains.
> Why doesn't the United Kingdom have the name of the country on its stamps?
> Because the United Kingdom had the privilege of being the first country in the world to introduce postage stamps, meaning that they did not need to be identified as coming from that country, especially when used domestically.
I get it, you invented the internet, but the special status you have over it is a little frustrating."
I bet America having +1 as our country code bothers you too :P
America numba 1! /S
[0]: https://en.wikipedia.org/wiki/Telephone_numbers_in_Canada
What if a dept lets theirs lapse and some squatter swoops in and takes it?
We'll start the bidding at $1B USD...
If you have a .com domain, you're renewing with VeriSign, the company that owns the com TLD.
> a fixed fee of US$6,250 per calendar quarter; (b) and a transaction fee of US$0.25. [1]
.gov is not a gTLD, I'm not sure what financial relationship exists, if any.
[1] https://newgtlds.icann.org/en/applicants/global-support/faqs...
.mil is also US only.
The real hotness is to host on .arpa - https://blog.fhrnet.eu/2019/03/13/fun-with-arpa-domains/
That’s no longer required, but still there was a big fight a few years ago when the .org registrar was set to be sold to a private equity firm. It’s the TLD of choice for nonprofits, as an echo of that early restriction.
I might be way off here, but I think that means either domain could set a gov.tld cookie which is sent to all domains, and if one of them is reading cookies without checking scope it could be a way to send whatever to another server. Or even worse, if one of the sites is using gov.uk cookies for something sensitive, then any of the others could read it.
Does anyone know if browsers have special cookie scope considerations for things like .gov.uk and .co.uk?
You can even get your own domains added to it, typically because you allow users to host their own content on a subdomain (like github.io for github pages).
That's the same reason the US is +1 country code and holds .gov
[1] https://en.wikipedia.org/wiki/Postage_stamps_and_postal_hist...
https://en.wikipedia.org/wiki/ISBN & https://en.wikipedia.org/wiki/List_of_ISBN_registration_grou...
It is mentioned in the Wikipedia link, but buried a little. I realise ISBN history is the epitome of super-nerdy, but the evolution path from $just_some_retailer through to the Bookland "country" is really quite interesting from an interoperability perspective.
Even if it's not exactly ".gov" they still mimicked it.
There's .INT if you have a use for one.
> turns out .gov is exclusively for the US, not sure I feel good about that, particularly as .com and .net are very much not just for the US.
This goes back to when the DNS was designed in the late 70s. Things were different back then (remember the big-endian british addresses, gb.corp.foo IIRC).
And I see you haven't learnt about .MIL yet either...
america music intensifies
Edit: I was mostly commenting on this.
> In fact, the most difficult part is convincing management that we should make the full migration to the .gov
It sounds like the most difficult part of getting a .gov is having a legitimate government entity and having a purpose that needs one.
Lots of small towns have dot coms when they could have dot gov.
So apparently the Irish Post Office wants to be seen as an international player?
Turns out it’s not a USDA campaign, but is associated with a CISA campaign to explain foreign influence operations focused on divisiveness.
CISA produced a quite good one pager: https://www.cisa.gov/sites/default/files/publications/19_100...
Sadly the domain is inactive, but they helpfully included an archive.org to show some of the additional content (how the CISA director executed a pineapple op on Twitter): https://web.archive.org/web/20190726194709/https:/twitter.co...
And for the record- pepperoni pineapple jalapeño pizza is delicious.
However the government created a separate Section 8 company called Digital India corporation that runs a separate group of websites for Citizen Outreach called MyGov, which runs a separate subdomain for these: mygov.in. Unfortunately, they haven’t gotten around to registering it as a public suffix, so there are concerns around security (cookies are shared between completely separate sites). The public suffix list doesn’t accept contributions without authorisation anymore, so it’s unlikely to be fixed.
There’s also the interesting case of some government sites preferring .org.in to showcase independence from government interference- RBI, for eg (the central bank) runs at rbi.org.in.
I wrote a few more findings when I created a list back in 2020: https://twitter.com/captn3m0/status/1301613472615030784
Because it was possible, maybe better now!
- A US Government controlled CA root preinstalled on computers. Privacy advocates would be in arms. - Constant untrusted CA warnings when trying to access any government site.
Which is a problem with the root cA design.
This is how dn42 does it: https://dn42.dev/services/Certificate-Authority.md
Before Certificate Transparency, I'm pretty sure they already could do that relatively easily by forcing a private CA to make them a cert. (National Security Letters and all that fun)
Even now, with CT, I think they'd be more inclined to use a private or at least an "unofficial" CA, instead of basically leaving "your's truly, The Government" in the CT log. If you already know you'll leave a trace, why would you want to make that trace extra obvious?
Regardless, this puts you back at a US Government controlled CA being on your machine.
Do you really trust the turkish government with the ability to sign for any domain.
Some days I consider tearing out the whole thing and rebuilding with the 3 CA's I actually care about. but then I usually give up as too much hassle.
Annoyingly, it doesn't have my country's national CA hierarchy (https://bugzilla.mozilla.org/show_bug.cgi?id=438825).
Why is it annoying? Because it means you have to add it manually, and manually added root certificates have more power than the root certificates that come with the browser! In particular, they can bypass HPKP (security.cert_pinning.enforcement_level defaults to 1).
No, but I don’t have to. To be included in the root CA list, they have to participate in cert transparency logging. So I can just pick a log to monitor, and check to make sure they haven’t issued a cert for one of my domains.
edit: I just read the spec. the cert needs to be logged to be considered valid by the browser. which has fun connotations where google is effectively monitoring everything you access. basically the mother of all analytics. well... I mean... that is.. if they were not already monitoring everything you do on the web. so it's ok I guess.
[1] https://ccadb.my.salesforce-sites.com/mozilla/IncludedCACert... [2] There seems to be a Mozilla applied constraint for .tr only
https://service-service.canada.ca/sign-up-sinscrire.aspx
.ca is open for registration by anyone, and people are used to seeing that TLD. Combine that with the bilingual super long domain names and every once in a while you’ll see a phishing scam like: https://service-service-canada.ca/sign-up-sinscrire.aspx
CIRA could set up a .gov.ca second level or something if they really wanted to keep the .ca, but I don’t think that will happen at this point.It’s at least consistant in looking like a phishing scam!
I believe the canada.ca thing relates to the centralization of federal government IT under Shared Services Canada (SSC) in 2011. SSC is an attempt to make a "one stop shop" for government IT services, and Canada.ca is an extension of that philosophy to web presence.
As an aside, SSC is very controversial in the Canadian federal government. They have a reputation for glacially slow delivery of services and inflexibility in IT policies. The head of StatCan actually resigned in 2016 in protest as a result of problems with SSC [1]. They have gotten better since then but it's still rocky.
[1] https://www.cbc.ca/news/politics/statistics-canada-interview...
As has been noted elsewhere in the thread, Canada wouldn't be eligible to use bare .gov if they wanted to, because it's only for US government entities.
[0]: https://github.com/GSA/govt-urls/blob/main/2_govt_urls_feder...
Seems a bit odd to use a Montenegro domain, doesn't it?
GSA has since developed login.gov, but there hasn't been a mandate that other agencies have to use it over third-parties.
It got rather messy when the Feds started letting states get delegations under .gov and .us was opened to registration of second level domains and new multilevel delegates became discouraged or disallowed.
The net result is that the Comptroller's new program trying to get everyone their missing funds is sending email that exclusively arrive in people's spam folders.
It reads as very low-rent considering it's the printing press of the US Dollar. If they reached out to me I'd think it was a weak scam.
In any case, moneyfactory.com is just a redirect to bep.gov, so I'm not sure what the big deal is. The average person's interaction with the BEP, aside from handling paper money, is probably at their gift shop. Having a cutesy name probably made sense at some level.
You can still find the URL in older press releases on treasury.gov, other US government sites, and older news sites, and all I meant is that it reads very a little naïve and "off brand" to me these as a modern reader:
https://home.treasury.gov/news/press-releases/20035137475911137
https://money.cnn.com/2003/09/16/pf/banking/marketing_new_money/index.htm
https://www.dailynebraskan.com/local-businesses-prepare-for-new-20-bill/article_6a2ea77f-60e4-52aa-8217-731a6cdf9114.html[puts that list at a non dot gov website]
Also, this is a US centric site run by a US based company. The "American" part is implied unless explicitly stated otherwise.
Like the world-wide-web we're all using to discuss this topic via? Oh, wait.
> Also, this is a US centric site run by a US based company. The "American" part is implied unless explicitly stated otherwise.
It is unfortunate that the point you are trying to express here has been worded in a way which does nothing but to reinforce stereotypes that Americans are arrogant and excessively nationalistic, since I'm sure that wasn't your intention.
As dang has pointed out previously, Americans only make up about half of the audience here - and they may even be a minority today (this comment and the data referenced within it is a good 3 months old): https://news.ycombinator.com/item?id=35464697
No. https://gov.uk is a "government URL" and it's one that doesn't end in ".gov".
The title should be "US government URLs that don't end in .gov"
I'd personally suggest the opposite, the US switching to .gov.us and .edu.us, but consensus in this thread seems to be that "everyone" already knows those are US-only anyway, where "everyone" of course means Americans; even "too late to change" is a better argument than that, IMO.
They instead prefer using a SLD (like .gouv.fr) because they’re complete owner of their ccTLD. ccTLDs are not affiliated in anyway with ICANN. I’m guessing .gov is a special case nowadays, and probably considered like a ccTLD from the ICANN point of view, I’ll have to look into it
Edit: it seems like gov is considered as a Sponsored TLD[1] (sTLD). Not sure what it implies.
ccTLDs delegations are managed by IANA, who are owned by ICANN
While it might be technically possible for ICANN to make certain adjustments to the ccTLD system or the registration requirements, politically its much much harder and gets harder still with time. Imagine the response from most soverign states etc if their own ccTLD was meddled with in a manner they didn't appreciate.
ICANN has slowly tried to move more and more of the ccTLD stuff to international working groups ("Governmental Advisory Committee") to put clean air between the US and ccTLDs, but the link is still there:
https://gac.icann.org/principles-and-guidelines/public/princ...
"Federal executive branch agencies must ensure their non-.gov or .mil domains are on the list."
Also on this page, there is an "out of scope" list which only includes 4 things: SaaS, cloud resources, SNS sites, and code repos. I take the govt at its word--it has never lied before--so naturally covert ops must be "in-scope".
> ... Don't be snarky. ... Edit out swipes.
Definitely not.
It could just be that I'm meeting with more educated folks, granted.
Generally, I'll answer with "The place so nice, they named it twice."[0]
[0] I wasn't sure if I wanted to include an actual reference to define that, but here you go[1].
[1] https://www.barrypopik.com/index.php/new_york_city/entry/new...
Edit: Fixed typo.