logoalt Hacker News

nanolithyesterday at 8:12 PM3 repliesview on HN

This risk factor is similar to one I brought up during architectural review of an IoT company I helped to build. It's why the identity certificates our devices used were entirely disconnected from domain names, and why the discovery protocol I put together did not rely on registered domains, but could use these as an untrusted part of discovery.

Domain names are leased. Things that are leased can disappear. The company leasing these assets could go bankrupt. They could weasel their way out of agreements as Verisign has done here. Any identity that is grounded in leased assets is built on shaky ground. It's also why I'm dubious of the way that e-mail addresses have become tied to online identity.

I'm not saying that what Verisign has done is right, but this behavior is expected. Those of us who went through the (dot) bomb era remember just how shaky this infrastructure can be.

I'm sorry that .name people are going through this. Even though it's a risk I expected, that doesn't make this okay.


Replies

sciyoshitoday at 3:43 AM

It's the same reason I was nervous moving our company domain to a .ai TLD; your entire presence, identity and trust is now beholden to the whims and political winds of a Caribbean island smaller than Topeka.

fh67yesterday at 11:10 PM

Can you share how the discovery worked?

ACCount37today at 1:14 AM

"Online identity" seems like a castle built on quicksand in every single case.

What's your account tied to?

E-mail? That's usually on a mail server owned by someone else. If not, it's still on a domain owned by someone else.

Phone number? Definitely owned by someone else.

The only account that's reliably "yours" is one that asks for a login, a password, maybe a TOTP, and absolutely nothing else. Because everything else is introducing "things owned by a third party" into the equation.