Hacker Newsnew | past | comments | ask | show | jobs | submit | dpoloncsak's commentslogin

There are a lot of people who would say that is exactly what Reuters is. Any American news outlet, really.

It was a real world event. The guy is still dead unfortunately. If Sputnik or Pravda are more your style they reported on the same event.

Obligatory relevant xkcd: https://xkcd.com/538/

It's a forever-fresh reminder about security versus your own government, but for malicious hackers and bots: the physical trip to visit you costs more than half their infrastructure.

Encryption matters, even if I would divulge everything long before the wrench appeared.


...with the risk of getting banned, you can't reasonably use this for anything 'important'.

In order to make my life easier, it probably needs to be doing important stuff.

You can't hide behind 'other apps are doing it too', if my 'important business account' or whatever gets banned from using your tool, I'd be upset at you.

How do you guarantee your uptime SLA if my account may get banned any second?


This can be used locally, no?

And you typically use them for business, not on private accounts.

Most of the use cases in the page are personal, like Family Group, Sports Group and so on.

"Pick members and send them a personal direct message".


It’s a cloud product

Sorry, I may has misphrased what I meant. Can I use this with a local model? Or is it locked to Claude

It's well detailed and easy to follow.

If you're targeting beginners, do you think it's valuable to explain the .env concept a bit, and generally what an API call is? Or do you think your average reader is familiar enough with Python that they would have come across these concepts already, and are just looking to prompt LLMs?


I would assume, if I'm reviewing the cameras for a valid reason, that it may end up in court. If it ends up in court, I'd want my logs to show I atleast did the bare minimum, yes.

Just because there isn't a coded requirement doesn't mean there hasn't been directions to state valid requirements. This isn't a Jira ticket, this is a tax-payer funded government official supposedly doing his job, and should 'bother' to give valid reasons.

Do you need to predict all the ways the model might misbehave? Your 'hack everything you see for our internal research lab' agent should be airgapped. You don't need to come up with every reason why, one is enough.

If you're working with these companies, you should reasonably be able to get the code to perform offline audits. If you can't get the code, you probably shouldn't try to pen test it.


I can say, as a SysAdmin, I have been taught and tell my users to check the domain to verify a website is real.

It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com

In every other case that I know about, to own the Joe subdomain of Doe.com, you would need to own Doe.com

edit: I guess I've gotten so used to the government 3LDs I just don't even see them anymore, or just see something like .co.uk or .edu.us as a TLD by itself, but yeah those exist too. Still the exception to the rule


That is definitely not true. There are literally thousands if not tens of thousands of well known domains that do this. .co.uk is a very common example.


.name is still a weird edge case because of the naming rules. Whether or not all subdomains under doe.name belong to the same person depends solely on whether the first person registered "doe.name" (in which case they do) or "john.doe.name" (in which case they don't, and "doe.name" is excluded from purchase as a standalone domain).


The fact that multiple organizations need to keep a public list of known 3LDs proves it's the edge case, does it not?

"Here's a list of things that look like subdomains for you to treat as 3LDs instead of subdomains" sounds exactly like the solution to an edge case to me.


I think the problem is that .co.uk, .gov.uk and so on are very well known in the UK.

The .name subdomain rules are not very well known anywhere.


How familiar are you with Serbian co.rs, org.rs, in.rs (individuals) and top-level .rs too? Will you confuse it with iz.rs giving free subdomains to individuals too ("iz" means from in Serbian)?

How about all the other 200+ country TLDs and rules for non-country TLDs?


This seems largely country dependent with some exceptions.

In the US, once upon a time, elementary/middle/highschools might be attached to something like schoolname.district.state.gov. But now, even my local area school now has a .com. It seems that older hierarchy style is falling out of fashion for smaller/shorter domains across public services, schools, government agencies, etc.

Now here it seems to be either a .com, .gov, .org, or a totally different and newer tld. Even .net has fallen out of fashion.


The writing was on the wall when Pennsylvania switched their license plates from www.state.pa.us to visitpa.com


Good article on this by a fellow hner

https://computer.rip/2025-11-11-dot-us.html


I can’t think of any prominent ones outside of country code domains.


You can almost guess someone's age from that alone - they're more rare, but long domain names still appear that encode a city and a state, and you could just "grab" the first part when signing up.


Outside of the context of ccTLDs and city.state.gov etc, I struggle to think of examples 3LD+ domains where they are owned and operated by completely different concerns than the parent. If at some point you could just register your own mysite.state.gov domains willy nilly that's probably before my initial time online around 2000.

Another poster raised the point of hosting services which is valid. But at present outside of that example and the above I really can't think of an example where you have a link to entity.com and you have any significant cause to verify the identity beyond the 2LD.


Many services today support vanity domains - Google even has special support for it: https://publicsuffix.org/list/public_suffix_list.dat


Tangential, but why call out Google specifically? PSL is widely used: https://publicsuffix.org/learn/


All Indian banks use bankname.bank.in as their domain. I’m not sure who owns bank.in but this is a common suffix which is different from the .co.uk pattern.


IDRBT Institute for Development and Research in Banking Technology


I remember I had beach.santa-cruz.ca.us at one point registered to me. I owned beach.santa-cruz.ca.us, someone else owned santa-cruz.ca.us, yet someone else owned ca.us, and I believe Network Solutions took care of .us at the time.


You say "registered" to you as though this was via an official registrar but surely you mean that someone rented ca.us and decided on their own to lease out subdomains to people?

(Aside, I always see "owned" and "bought" but you can only ever "lease" under the ICANN system as the present situation so clearly demonstrates.)


Historically, xx.us (where xx is a two letter state code) domains have been owned* by the named US state, which then would issue subdomains on top. I believe this was originally planned and set up by ICANN themselves.

*: I realize that “owned” is a loaded word here, but (1) I’m referring to a registrar/issuer, which makes it yet more complicated as to how much “ownership” (de facto or otherwise) a given entity may have, and (2) I really don’t give a fuck about pedantic word choice if the meaning is unambiguous.


My aside wasn't intended to be pedantic, rather observing the apparent inconsistency in how it appears people think about these matters versus what the present situation illustrates the reality to be.

> but (1) I’m referring to a registrar/issuer, which makes it yet more complicated

We're also talking about a ccTLD which makes it even more complicated. AFAIK those fall entirely under the jurisdiction of the respective UN recognized government although I don't know how strong that agreement is in practice (treaty versus something else).

So at that point I guess we've roughly got ICANN -> US federal government -> CA state government -> registrar -> private party -> sublet.


The way it worked is that someone nominally representing the CA State Government had* ca.us, and they in turn gave* san-jose to someone who nominally represented San Jose, los-angeles to someone who nominally represented Los Angeles, santa-cruz to someone who nominally represented Santa Cruz, and so on. city-name.ca.us domains were still free (and charging for .com and .org domains was a new thing at the time); you would look in the zone file to see who owned* a given domain, email them with your nameserver names and IP, and they would add it to their zone.

This isn’t how things are done these days; names visible to the public are pretty much always in the form {domain}.{tld} or sometimes {name}.{domain}.{tld} (e.g. my own https://samboy.github.io). Registration is now done by bots and companies that spam you to death to try and get more money from you (the Internet wasn’t like that in the beach.santa-cruz.ca.us days). Domain names with multiple levels of delegation aren’t around they way they used to be.

* rented/leased/had control over/whatever


> This isn’t how things are done these days

The old locality domains still exist, and in many localities you can still register them today by the same "email a request to some sysadmin" process. https://news.ycombinator.com/item?id=48122635

Your beach.santa-cruz.ca.us domain is still in DNS, just with a broken delegation chain. You could reclaim it right now by setting up a nameserver at reality.samiam.org.


I’m amazed beach.santa-cruz.ca.us is still around. I’ve given it some SSL certs and have reclaimed it:

https://beach.santa-cruz.ca.us/

Thanks for checking the zone files of the parent domain to verify it’s still there.


Wait what haha. Do you also own samiam.org?


Judging by his username (strenholme) and the contents of https://samiam.org/ (Sam Trenholme's webpage), he does indeed!


  > AFAIK those fall entirely under the jurisdiction of the respective UN recognized government
How does that work for e.g. Taiwan, where the UN recognises the mainland government's claim to sovereignty in practice?


It's complicated and political, like always. Officially, the ISO 3166-1 alpha-2 country code list is used to decide who gets a ccTLD. (And Taiwan is included there.) But for example ".su" still exists for historical reasons, even though the Soviet Union is long gone (and its code is listed as "exceptionally reserved", which I assume translates as "we have no fucking idea what to do here.")


This raises an interesting question. If they aren't strictly following UN recognition then would it be possible for ICANN to award control to one party while the UN recognizes an opposing party as the legitimate government?


Github Pages is probably the most well known one (on here).

I think geocities had this as well?

A lot of hosting services offer this in general. (eg render)

Tumblr? (Might not count as the control over the page is more limited. The subdomains "are" still tumblr.)

For reddits subdomains are redirects to subreddits of the same name, so I guess that doesn't count.


None of these examples are of actual separate registration/ownership of a 3LD from the parent 2LD. Cloudflare owns the domain for myproject.pages.dev and hosts all the relevant infra. Not to say that there isn't a different entity represented by the 3LD than the 2LD but it's not exactly the same.

Also I would not consider the examples of tumblr and reddit to be relevant. A person's blog on myprofile.tumblr.org is still the tumblr organization. This would be true for reddit even if they didn't redirect. Reddit admins moderate content on all subreddits.


I see, that's a valid way to think of domain ownership.

When I read > I have been taught and tell my users to check the domain to verify a website is real.

I was thinking more of control of the content as "ownership" of the domain.


The point on hosting providers is well taken. You do have to consider x.pages.dev as the wild west not cloudflare of course. One difference though is you will never receive an email from x.pages.dev asking you to do something. The domain ownership still does play a part.


You can buy example.it.com on many registrars. Someone bought it.com and operates it like a TLD.


Interesting. I do wonder how many people outside scammers and squatters buy them. I'd rather have an .xyz or .biz address personally.


When someone defames at SEO-optimized large-company.it.com, then Large Company gets interested.

Or, more succinctly, when money gets involved.


>It's a strange edgecase that the owner of John.Doe.com does not need to own Doe.com

I think you meant to say "the owner of John.Doe.name does not need to own Doe.name" since .com just works under the 'normal' rules you're used to.

But it's worth pointing out that under the current system (that Verisign is destroying), no registrant owns (e.g.) fraser.name just as no one (but the registry itself) owns co.uk. So, if someone checks who owns fraser.name they wouldn't have found a scenario, for instance, that fraser.name belongs to, say, Simon Fraser University, with admissions.fraser.name belonging to some phishing site.

> I have been taught and tell my users to check the domain to verify a website is real.

Anyway, having seen enough eyes glaze over at the most basic tutorials of this sort, I'm afraid you're wasting your time. Given that this edge case is on nobody's radar, I don't think it's what's preventing 80% of Internet users from being able to get a passing score on a basic quiz on the hierarchial DNS. As evidenced by all the government entities that gave up and registered literal ".coms"


Yet that is a problem the owner of such a domain has freely entered into by buying that domain, it's their right to keep it despite this apparent problem, if they wish.


Understood, and .name isn't being used enough in business to worry about 'the effect it will have on my users'. Just pointing out that it doesn't work like the 'norm' (although I guess it's not quite as unique as I thought, either)


That's actually the point of the .name TLD is that it's not for businesses, it's for individuals. This whole situation demonstrates ICANN is more for businesses than individuals. It should just be there for everyone and every organisation that's trying to use URI's, shame that it's not worked out that way. This is exactly what the big tech companies want, they might as well hand ICANN over to Facebook or Google, they wouldn't do much worse.


Looking at the threads below, very few people are discussing technical things in dns terms like zone or nameserver.

Yeah. The way how most things on the internet prove ownership make the assumption that the 3ld is owned by the 2ld. Extend it once out for country specific ones and you cover most cases that people have to work with.

Then when you consider DNS is fundamental infrastructure and people build secure things on top of it, (ahem DNS challenges for certs), it's remarkable that anyone would want or desire edge cases.


There is a list called the Public Suffix List, which is used for most purposes to make determinations about which 2lds do not own/manage the corresponding 3lds. It's maintained by Mozilla as a public service, which isn't exactly where you'd expect to find it. But it's mostly important for web security / "same origin" stuff, so it makes sense.

In addition to all the country codes TLDs that do 3rd-level registration, the PSL does also include stuff like github.io. (Maintenance of the list involves manual volunteer labor, so scaling is a real problem...)

(And of course the PSL wouldn't work well for the .name situation, where it's sometimes 2 and sometimes 3, and it can change over time. But that's no excuse for this clusterfuck of just suddenly dropping a bunch of domains that are paid up years in advance.)


This doesn't seem like a problem if you exclusively support 3LDs and don't let anyone register 2LDs.


This wasn't really a consideration for anyone back when we applied for .name, and it already wasn't true back then (.us, and .uk were both prominent examples where it didn't hold)


Problem is, all these systems we still use were never designed to be like this.

Hell DNS used to be one woman in an office who updated the zone if you e-mailed her.


People still fall for paypal.com.4385ht43987th34098rh34279h3.legitorg.ru


There are still exceptions to this like .co.uk and many others.


Hello sysadmin. Good luck navigating the internet.

What you should know, and what your browser does know and automatically applies cookie policy and colouring your URL bar, is the Public Suffix List: https://en.wikipedia.org/wiki/Public_Suffix_List

It will let you know that, for example, one does not need to own .co.uk to own the subdomain foo.co.uk.


The .name mess is not in the public suffix list.

https://github.com/publicsuffix/list/issues/2306 for more discussion.


The public suffix list is a half assed bandaid over a fundamentally broken system.


I appreciate this, and yeah the government/education ones slipped my mind, but I stand by the fact that the reason a list needs to be kept in the first place is because this is the edge case and not the norm.


Supposing it were not an edge case and were typical, how exactly would you implement the same thing without keeping a list?


>agentic payments provider

The LAST thing you want to be non-deterministic is a payment system, right? What is the possible use of AI in the payment process? I fill in fields and that gets whisked away to an API somewhere to verify. Why do I possibly need Claude involved?


I think the way that reads is payments originated from an agentic flow, the payment gateway itself is still done through old fashion plumbing.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: