Treating something you rent as though you own it was the first mistake here. Owning a domain name was always a lie, even if in the early days it was treated in every way like it wasn’t.
The lead is a bit misleading. They’re not exactly terminating a TLD like you might think. For .name, they allow people to become sub-registrars, so this guy could own fraser.name, then sell domains with his and his daughter’s names.
But still, it’s shitty for them to terminate this with no recourse for people who currently hold the domains.
Despite the fact that it’s registered and paid for until 2040.
I can believe that Verisign might have some route to terminate service (even in cases where there is some contractual obligation to provide a service for a given period of time, someone can typically break the contract, just having to pay some sort of penalty for doing so), but I also suspect that they are legally required to issue you some sort of refund.
You generally cannot just sell someone a service and then refuse to provide it; that’ll violate consumer protection laws.
That probably won’t make the author happy—he probably wants the domain, not the money. But at the minimum, I will say that he probably doesn’t have to pay for service that he doesn’t get.
It might be that they are doing that; he doesn’t specify.
But it gets much worse. Once the 3rd-level domains are terminated, it is assumed that the now vacant 2nd-level domains will become available for registration. Should someone (other than me) scoop up fraser.name they would be able to recreate and control neil.fraser.name. They’d be able to hijack hundreds of accounts that are linked to that address. They could commit code with my authentication. They could seize control of IoT devices. There is no way to enumerate all accounts (online and offline) which have been opened using this email address over the past quarter century.
Yeah, personally I’d rather have some kind of key-based mechanism, at least as an alternative to the X.509-based system. Think of what PGP or SSH do. Like, the key is your identifier, not the endorsement of some centralized registrar.
Hyphanet does something like this, can do key-based addresses.
That has some drawbacks too—I mean, you are the ultimate authority here, and thus responsible for keeping that key safe, and that’s a big responsibility. If you think of all the attacks on cryptocoin wallets and stuff, I think that personal computers are not incredibly-well-suited for that—if we’re going to do that, we probably want something more like hardware-based keystores, like YubiKeys or similar, where a key cannot be exfiltrated if a PC is compromised, as PCs have a big attack surface. And it’s harder for humans to remember a key as an identifier, which means that they probably have to have a computer somewhere store a list of known and trusted keys (though doing so solves a lot of existing attacks, like phishing emails with look-alike URLs that attack the limited human ability to remember names, so there are pros and cons). And it avoids the risk that someone with access to a certificate authority’s key can compromise your security.
I worked for a company that sold third level domains. The company got bought out a few times as it kept going bust and the market consolidated, but unfortunately, the final owners did not understand what they had - I’d long left by that point - and they let the root domain lapse.
Perhaps as a saving grace, no-one had been maintaining the infrastructure (I was one of the last), and it ceased to function at a technical level long before the domain ended up lapsing. That gave people an unpleasant kick up the rear end to move their important stuff elsewhere if they hadn’t already. (The price we sold it at compared to actual domains ought to have been a hint that it wasn’t for important stuff, to be fair.)
I heard talk of a potential lawsuit against the ultimate asset holders, but I don’t think anything came of it.
Theoretically, the current owners of the domain could do what this guy talks about in order to try to collect mail for those accounts, but they’d have to know which subdomains to set up in order to do that.
I had one of those domains, and yes I got my stuff onto a proper domain not long after I left.
I also had a couple of accounts with a non-Google free e-mail provider that went under. Unrelated to my employer. The domain ended up belonging to an individual who probably gets a heck of a lot of email for former users of that service.


