EDIT: The link has been changed to the blog post describing the phenomenon. Good riddance!
EDIT: The link has been changed to the blog post describing the phenomenon. Good riddance!
Or, you could buy one regular domain and then ask to be put on the public suffix list. I'm guessing that would have the same effect for less money.
More information:
http://publicsuffix.org/submit/ (and the rest of the site, obviously)
[1] http://mxr.mozilla.org/mozilla-central/source/netwerk/dns/ef...If you are, say, the North Korean government, or have a close relationship with some small island registrar, you can register any number of domains you like for peanuts.
It's nice that this exploit is presented openly as a proof of concept, and includes a button to undo the damage. Many people, upon finding this, would try to use it for shadier ends.
Is there some generic way to know when a domain should be treated as a subdomain or do they basically hardcode the exceptions?
Example: does domain1.co.uk and domain2.co.uk share the same limit in Firefox? Probably not, but how does it know to treat them as separate?
I imagine these lists will become a real headache when the recent TLD auction is over. Is there any work being done on a more dynamic system (DNS TXT fields?)