Hacker News new | ask | show | jobs
by maxwell 1737 days ago
The .app TLD is owned by Google, requires HTTPS, and I haven't run into any issues in practice. Whereas my corporate VPN blocks all .xyz domains.
2 comments

> requires HTTPS

I've always felt conflicted about this. I generally support moving everything to HTTPS, and requiring it for new TLDs isn't a terrible idea because there's no chance of breaking anything legacy.[1]

On the other hand, Google owns the TLD, controls the HSTS preload list, controls the most popular browser. The idea that an entire TLD could be added to the HSTS preload list was a completely unilateral decision by Google. It makes me uneasy.

[1] ...unless you were using the domain internally assuming it would never be added to the root zone, which bit some people when they did this with .dev

Ya, these issues seem to be on a case-by-case basis. If the owner of a TLD is careless, it can get a bad rap and become useless.