ICANN's list of abandoned vanity TLDs
icann.org
icann.org
And it arrived! The shortest fully qualified email address in the world!
Against policy tho. I took out the MX record. It was a fun nerd moment.
∴dig ai MX
; <<>> DiG 9.10.6 <<>> ai MX
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 40166
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;ai. IN MX
;; ANSWER SECTION:
ai. 3600 IN MX 10 mail.offshore.ai.
;; Query time: 5 msec
;; SERVER: 192.168.1.1#53(192.168.1.1)
;; WHEN: Sun Jul 07 17:19:47 PDT 2024
;; MSG SIZE rcvd: 63dang. i hope he invested
I know who Ian Goldberg is, but didn't associate them with n@ai.
They saw .google and .mcdonalds and thought "we should have our own one of those"..
And I guess after a while of paying the non-trivial gTLD fees to ICANN, companies eventually looked at the ROI and realized they actually didn't need their own one of those...
Funny how different brands in the same industries figured it out many years before others did.
$185k is a rounding error in the marketing budget of many companies
The domain for my work project was over $400k. Buying a gTLD would have been way cheaper, but wouldn't have managed to get us the cool domain we have.
edit: on the other hand, we're hostage to a country who could ruin everything. I guess someone above my pay grade rolled the dice
There's probably ten or twenty domains (not counting my own or my work's) that I can type from memory, the rest I just search for.
The other killer is that "clownfarts.com" looks like a website but www.mcdonalds looks like a typo, even to non-tech people who don't understand any TLD besides the big three.
By being a registry instead of a registrant you get an extra layer of protection that helps to ensure your domain is untouchable. I think it makes a lot of sense to use for long term infrastructure if, again, the costs aren't prohibitive.
1: "SRT® Hellcat Redeye Jailbreak" actually. I think the marketing department is staffed with 12 year olds.
Thanks for the correction!
Another "ghost mining town" left behind from the wild west that was the first decades of the commercial internet.
B. Much better to have it and not need it, than need it and not have it.
As it turns out, they didn't need it, and lost a bit of their marketing budget.
I'm too lazy to research them all here, but I recognize a number of them here from their initial applications, which would have all happened at the same time as the two you mentioned.
But nope. ICANN turned the whole thing into another disgraceful money grab... taken to a new level. Now that it has flopped, we can just hope that someday we'll be able to end a domain name with any valid string.
DNS is hierarchical, and I don't think devolving into a semi-flat namespace is a good idea at all.
ICANN could certainly afford to run servers for a "flat" TLD system.
The problem for ICANN is that it will sour relations with all the existing TLD registrars, and there are security problems with allowing any TLD. For example, I might be able to redirect traffic for a particular local network host name (e.g. "router", "fileserver", "raspberrypi", "linksys", etc.) to an external IP address of my choosing. Or I can make something that is normally a local file (e.g. "cmd.exe") and make it also a valid hostname.
Not necessarily a reason not to do it, just a reason to be a little careful in rollout.
Interesting idea. Can you give an example of how that would actually happen? Also the cmd.exe one. So what if it's a valid hostname?
CMD.exe is either a program accepts either a filename or URL in the same context (VLC does this), or the user is confused about the URL/file distinction. The .ZIP TLD was concerning for this reason.
I was looking more for specific dangerous use cases; for example, "The user types such-and-such in the address bar, and instead of getting this he gets that." In other words, how is this a problem in actual practice.
An example:
The attacker posts a message to a forum, chatroom, etc. like:
Download: 2024YourCompanySalaryData.zip
When the user clicks "2024YourCompanySalaryData.zip", it is actually a domain name, and loads that website. This website then asks you to enter your corp credentials, or executes a 0-day on the victim's browser, etc.
The forum doesn't need to allow file downloads (i.e. a real .zip might not even work), and even if it does, client or server side virus scanning doesn't have a .zip to inspect.
The user is less wary of phishing, having never seen the .zip TLD. They assume they are downloading a file.
https://blog.talosintelligence.com/zip-tld-information-leak/
In terms of the user going to a site instead of a zip file: If a user is willing to unpack and run a random file he downloaded and give it credentials to something... what's the difference? Not being argumentative, but this seems like a stretch.
Now "foo.zip" is a valid URL.
You could have a forum or chat program that you think is quite safe, since it doesn't allow file uploads, and doesn't allow arbitrary link text, and this would upend that.
Some of the entries in there are... interesting. Who the hell thought ".travelersinsurance" is a good buy?
Browsers don't like to route directly to TLDs. In theory, Amazon could have a web site at
amazon
but browsers interpret that as a search request, not a request for a rooted domain name. Even amazon.
which means to treat that as a fully qualified domain name doesn't work in browsers any more.(That's what the trailing "." means. Relative domain names were a thing. If you're on a machine within "bigu.edu", and you want "ourteam.bigu.edu", you can supposedly just use "ourteam" as a domain. This rarely works right, because few clients have domain names any more. Is it even still implemented in most DNS lookup clients?)
Maps is a little weird because while originally they were bundling maps and search and a bunch of products together they have had to back off on that strategy due to the recent antitrust concerns and bundling so now they are purposefully separating the products and the domains further.
$ curl -v maps.google.com
[...]
< HTTP/1.1 302 Found
< Location: http://maps.google.com/maps
[...]For example, I can type “opnsense” and hit enter, which loads https://opnsense, whose FQDN is opnsense.home.my.domain. This works on all machines on my network; most are configured to use home.my.domain as the primary search domain (through DHCP), but my DNS server also properly responds to queries for just the host portion. And, I’ve configured opnsense to hijack all (standard) DNS traffic on my network, so even if a device is specifically ignoring the DHCP-provided search domain and DNS server, it should be able to query all local hosts.
Bonus fact: https://. works on Firefox (triggers an A/AAAA DNS query for root) but not Chrome.
hence under a properly set up DNS and application: system with search domain for `.internal` and a host named `amazon` will be hit the internal host for `https://amazon` and `https://amazon.internal` but not `https://amazon.`
I liked alway having a rule in the web server to redirect to the fully qualified hostname on requests to the internal ones, so links could be shared and would always work even if the search domain wasn’t set up (could happen on the VPN for example).
They got .travelers and .travelersinsurance , maybe some others.
https://en.wikipedia.org/wiki/The_Travelers_Companies - with a 32 billion dollar yearly revenue, they can afford a lot of boondoggle nonsense projects. They probably assigned a bunch of people with insufficient technical knowledge and a vague project scope the objective of updating their cloud and web presence.
Your link says Travelers Companies had ~$3 billion of net income (profit) on ~$42 billion in revenue.
That’s still not enough information to say what they can “afford” because opportunity cost exists.
Project managers and MBAs get to rationalize their degrees and theories, because after all, they wouldn't be getting paid by ABCXYZ, Inc and managing million dollar budgets if their project wasn't top-class and 100% justified. You might have to keep firing new hires that mention anything about the whole TLD thing being ridiculous, but they were just negative energy anti-social people who wouldn't have fit the company culture anyway.
Basically no one outside of big tech has the volume of domain names to justify paying for their own gTLD, Fortune 500 or not.
How much money did they light on fire to have a tld and what utility does it provide?
I could see a world where GTLDs were given extreme preference by search engines and browsers, but that world isn't ours.
It's not even a rounding error on their income statement so they don't care. ICANN, in their infinite wisdom, somehow couldn't foresee corporations squatting on TLDs.
Have you ever participated in ICANN? My company did. ICANN's mailing-list traffic was pathetic; never accomplishing anything, as members endlessly bickered about procedure. I don't recall that we ever made a single decision on anything.
They registered oui.sncf initially during their rebrand. Once the guy who initiated that left, they switched back to .com domain (https://www.sncf-connect.com/).
On one library I work on, we ended up writing a bot to fetch the list for us and open a pr in order to maintain it. I suspect anyone having to validate TLDs faces a similar problem.
We have something similar that keeps it updated on a regular basis as well. We used to wait until someone complained, but it changes so often it’s the only reasonable way to deal with it.
https://github.com/Respect/Validation/blob/main/bin/update-d... https://github.com/Respect/Validation/blob/main/bin/update-d...
If I were a GTLD registrar I'd make it so that (for example) all .works domains were also aliased by .worksdomain.com or something similar as a backup.
* The name of the person who inserted them is rendered when clicking on the black boxes.
* Even basic PDF readers will allow modifying and deleting the boxes, you don't even need Acrobat or another PDF editor.
There you can get a list of all delegated second-level domain names of most vanity TLDs. Most are quite small (less than 10 entries, most or all technical like nic.<whatever>), i.e. the domain is basically unused.
(They, however, sometimes also contains obviously internal domains which sometimes resolve to public IPs. One company also allows an enumeration of all sales staff, as everyone gets their own domain. ¯\_(ツ)_/¯)
That seems like a scurrilous end-run around default search behaviour that one could hardly believe the major browsers would allow it. (For example, only treating your text as a domain lookup if the location had a dot in it, and was free of spaces or other punctuation.)
And it's another (legacy) reason .com was so popular / important being the one the browser would default to.
https://web.archive.org/web/20240205121324if_/https://www.ic...
You should be able to register something.whatever at the same registrar you'd use for something.com.
https://www.icann.org/en/blogs/details/next-steps-for-the-we...
Maybe ICANN had a heart and decided not to break unsuspecting people's wedding sites lol
xn--mgbaakc7dvf
(Emirates Telecommunications Corporation (trading as Etisalat))
Anyone have any idea why that would be a TLD? I'm assuming it displays in Arabic somehow?
This was part of the panic of similar looking Unicode characters being used in phishing attacks.
wonder how much 八号店 is going for
I would hazard to guess that plenty of spam filters would nope these too.
Most people use both apps and websites.
Websites haven't gone anywhere. How do you use the internet from your laptop or desktop?
So I don't understand what you're trying to say. The domain name is actually more prominent, to help a little bit against phishing.