upvote
I know about the public suffix list - I was wondering about the wildcard specifically. In the very issue you linked to, as of 2025, it seems this was still unresolved...:

> We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't.

reply
Yeah, apparently they both (used to) offer unbounded registrations of 3LDs and unbounded registrations of 2LDs? So if I see j.doe.name, the only way to find out if "doe.name" is a public suffix or not, i.e. if I should (not) be able to set a cookie on it, would be to email the registrar?

So does that mean that in practice, .name domains were always treated by browsers like regular 2LDs, meaning the cookie and origin protection was always broken for those domains?

Doesn't sound like good news for the guy in the OP...

reply
deleted
reply
I'm just saying that they have discussed the situation. They seem to have no answer and for cookies and similar things the answer probably is "maybe don't run security critical web stuff in the third level under .name".

IIRC orgs like letsencrypt also use the PSL for rate limits, so there are probably more issues that are not browser-based.

reply
Yes, Japan does the same with .co.jp but also .ne.jp, ac.jp, etc.
reply
There are many examples; k12.<state>.us is another.
reply
It is (or was for a long time, IDK) a strongly recommended practice from ICANN. I imagine nearly all countries to do that.
reply
There end up being some weird edge cases where there are some countries which have both the equivalent of .co.uk but also allow registrations directly under the two-letter country code as well. .mx is one such case where most business are, e.g., costco.com.mx, but it’s also possible to register directly under .mx as well so Toyota Mexico is toyota.mx and not toyota.com.mx (the latter is registered, and ostensibly to Toyota, but the whois and nslookup records give very different results and the website doesn’t load when I try to visit it).
reply
This isn't so bad as .com.mx and .mx should be on the public suffix list then.

But letting arbitrary customers take arbitrary 3 level domains, and others take 2 level domains, seems like a mistake as it's not very reasonable for every 3LD customer to put the 2LD on the public suffix list, but mixing 3LD and 2LD registrations means you can't public suffix *.name.

Seems the whole idea of having both was always misguided.

reply
uk is one example - they opened up x.uk later, and gave x.co.uk registrations first dibs.
reply
Except nobody uses the .us tld, but pretty much every every Japanese company is on a .co.jp
reply
It used to be that only Japanese corporations could register a .co.jp while anyone else anywhere could register for a .jp. So I had several .jp domains registered through Gandi.net.

The issue is that .jp registered outside of a few Japanese registrars are legally not allowed to offer Whois privacy.

reply
The .us domain should’ve been universally useful for state and municipal governments, but most of those began registering directly under .gov, and not even in an orderly hierarchy under .st.gov

But that was simply the easiest way to market your website as a trusted government entity. And now nobody has ever heard of .us domains in active use.

reply
.us was primarily a hierarchy structure which in practice made confusing and hard to remember domain names, whereas .gov addresses hand out single domains which are generally easy to remember.
reply
Schools use it!
reply
Based on my small sample of schools, all of the ones that were using locality based names under ca.us have migrated elsewhere, including to 2nd level domains under .us.
reply
> Except nobody uses the .us tld

This is a bug, not a feature.

reply
Sure, it is right now. What if they decide to sell it off?
reply