[HN Gopher] Mali Government takes back .ml domain, brings down o...
___________________________________________________________________
Mali Government takes back .ml domain, brings down one of largest
Lemmy servers
Author : rglullis
Score : 100 points
Date : 2023-07-21 18:00 UTC (5 hours ago)
(HTM) web link (very.bignutty.xyz)
(TXT) w3m dump (very.bignutty.xyz)
| Terr_ wrote:
| > brings down one of the largest Lemmy servers
|
| To repeat a past comment with a little bit of "I Told You So"
| cynical feeling:
|
| > I think the barrier [to joining] would be lower if I knew I
| could migrate my identity to another instance if the first one
| became sketchy or shut down or de-federated.
|
| > Instead AFAICT I have to choose not just what community to join
| and where the content will initially live, but also which of
| these random groups to trust with my identity indefinitely going
| forward.
| rglullis wrote:
| Your identity _can_ be separate from the community servers.
| xenomachina wrote:
| How?
| rglullis wrote:
| You can follow a community from any software that speaks
| ActivityPub. So you can be on Mastodon and post/comment to
| any Lemmy community.
|
| Alternatively, if you want to use lemmy's interface, you
| can create your own instance and use it only to subscribe
| to remote communities. This way, your identity is one place
| but the commuities is in another.
| throwanem wrote:
| If similar to other fediverse services, by running your
| own.
| Terr_ wrote:
| AFAIK the only option is to run your own instance, which is a
| rather high bar.
|
| In contrast, imagine a system where you could use a private
| key to sign things, thus proving "author Bob on Instance X is
| the same as the prior author Bob on now-defunct Instance Y".
| You'd still be sunk if you lose the key (or it gets leaked)
| but at least your identity as an author wouldn't be at the
| mercy of the Mali government.
| rglullis wrote:
| > imagine a system where you could use a private key to
| sign things
|
| This _is_ how things work now, the issue is that most (if
| not all) of existing AP software the server is generating
| and abstracting the keys away from the users. But (in
| theory) there is nothing stopping a system where the server
| (e.g, mastodon.example.com) works for clients (actor in AP
| vocabulary) with a different domain, and requesting the
| actor to sign the messages before accepting in the inbox.
| guerrilla wrote:
| > > I think the barrier [to joining] would be lower if I knew I
| could migrate my identity to another instance if the first one
| became sketchy or shut down or de-federated.
|
| This is pretty much standard for all fediverse apps...
|
| > > Instead AFAICT I have to choose not just what community to
| join and where the content will initially live, but also which
| of these random groups to trust with my identity indefinitely
| going forward.
|
| Nope, not remotely. That's part of the point!
| NikkiA wrote:
| Oddly lemmy.ml is still running, perhaps they arranged some deal?
| josephcsible wrote:
| Why doesn't ICANN or IANA have a rule against TLD operators
| unilaterally and suddenly stealing other people's subdomains?
| CameronNemo wrote:
| Because ICANN does not have sovereignty over ccTLDs, which are
| considered nation-state assets.
|
| The customer protections are much better for generic TLDs.
| wccrawford wrote:
| I noticed the first 2 Lemmy servers that I signed up for are also
| down today. They aren't on a .ml domain, though.
|
| I noticed that lemmy.ml was still up, but it has some error
| messages as I was browsing, too.
|
| I can't imagine this is all related, but maybe?
| jeroenhd wrote:
| This specific problem should only directly influence the .ml
| domain, but it's possible other instances are overloaded
| because of .ml shutting down.
|
| Lemmy.ml still seems to work for me, I wonder why that is
| exactly. Perhaps the administrators have bought the domain from
| .ml's new owners?
| c-linkage wrote:
| Side note: its best not to put easter eggs in your app,
| especially when you think no one will see them.
|
| Visiting the link with scripts disabled gives me a "damon is g*y"
| banner.
|
| Not only can the message be construed as hate speech (could be an
| inside joke but I'm not "inside") but it could also be that you
| outed someone who didn't want to be out.
| boondoggle16 wrote:
| that is not in any way hate speech, and you are reading way too
| much into this
| bshipp wrote:
| What is it then?
| valianteffort wrote:
| I see it more often being used in place of dumb/wild. I
| think it's pretty rare that people use it to refer to
| someone as a homosexual.
| c-linkage wrote:
| I didn't say that I found it to be hate speech, only that it
| could be interpreted as such.
| raspyberr wrote:
| Doesn't this situation keep occuring? Feels like it's no longer
| surprising
| jeroenhd wrote:
| ml/tk/gq were all resold by Freenom, which was sued by
| Facebook. I'm pretty sure this is all part of the same domain
| name saga.
| juujian wrote:
| What other instances did I miss?
| RobotToaster wrote:
| Similar happened with .af I think.
| rubatuga wrote:
| .tk
| joecool1029 wrote:
| They didn't take back their ccTLD nor is it unavailable.
| The (Dutch) company Freenom managing it was sued by
| Facebook for not policing their free domains used in
| phishing attacks.
|
| This is a very different case. I would point out maybe it's
| not a super great idea to pick a ccTLD in a country with a
| decade long war internally. I've seen Haiti's (.ht) used a
| decent amount (notably as a secondary for sourcehut, sr.ht)
| and would think this one is a particularly vulnerable one
| as well.
| allarm wrote:
| I wonder if the same can happen to .sh - it's widely used by
| Schleswig-Holstein (a German state), but originally it's a tld
| for the Saint Helena islands.
| ssivark wrote:
| Maybe actually a good thing in the long run -- would be great for
| an application aiming for a federated architecture to be
| reasonably robust to things of this sort.
| brrtbrrt wrote:
| Rightly so - don't peruse country-specific TLDs for your app or
| service vanity BS. This especially concerns .io!
| hanniabu wrote:
| So one owned by a company is better? No. This is why .eth
| domains are great. Ethereum solving yet another problem that HN
| complains about on the daily, but will still claim it has no
| usecase.
| pmlnr wrote:
| You don't understand: most cctlds are in the relevant
| country's hand, but there are exceptions, like .io.
|
| The ones like .eth or .bit are a bad joke. If you want
| something that's truly yours, generate a .onion.
| rglullis wrote:
| Even if it is in the country's hands, it can be taken from
| a legitimate owner or be abused. That's what parent is
| talking about. ENS are fully permissionless, _no one_ can
| take it from you.
| eropple wrote:
| Nobody can take it from you. Nobody would, either,
| because they are valueless and nobody uses them.
|
| "Use an .onion" is genuinely better advice. (I wouldn't
| do that either, but an .onion at least has a reason to
| exist.)
| rglullis wrote:
| > nobody uses them.
|
| If by _nobody_ you mean "no one outside of the
| mainstream", sure. But I don't need a lot of work to have
| my .eth domain resolving to an IPFS file, and there are
| browser extensions that will let you query ethereum
| blockchain and use it to resolve IP addresses based on
| ENS.
| redox99 wrote:
| > they are valueless
|
| A lot of them clearly have value, as the "desirable" eth
| domains sell for thousands of dollars.
|
| > "Use an .onion" is genuinely better advice. (I wouldn't
| do that either, but an .onion at least has a reason to
| exist.)
|
| You seem to be extremely biased against anything related
| to cryptocurrencies
| mrguyorama wrote:
| And popular NFTs "sold for" millions, until they only
| sold for like a hundred bucks. It's all wash trades.
| rglullis wrote:
| Unlike "monkey JPEGs", a ENS domain has actual utility.
| People are not (necessarily) buying it to speculate. They
| can buy it to use it.
| DANmode wrote:
| This is rude, and valueless.
| pmlnr wrote:
| What, stating a fact? Who is using .eth and .bit then?
| hanniabu wrote:
| Many are using it, you can see here
| https://esteroids.eth.limo/#/
| DANmode wrote:
| Regardless of what you or I may think of this
| web3/Ethereum communities and adjacent, millions have
| adopted ENS.
|
| It's leaking out into normal DNS.
| pmlnr wrote:
| >It's leaking out into normal DNS.
|
| No, it isn't. I'd never seen a .eth link anywhere on the
| normal web, yet I've seen plenty of Gemini:// urls, just
| to throw in something niche for comparison.
| riffic wrote:
| no one's going to an unresolvable namespace buddy.
| jeroenhd wrote:
| What DNS provider supports .eth? Is this one of those
| Handshake domains?
| redox99 wrote:
| .eth domains are supported out of the box with Brave, and
| on other browsers (like Chrome) if you have Metamask
| installed.
| WeylandYutani wrote:
| There are dozens of us. DOZENS
| wwtdtgotiatl wrote:
| Smarmy reddit-esque comments like this don't belong on
| HN. Please read the guidelines.
|
| As for numbers:
|
| > In April 2023, Brave Browser reported 57.27 million
| monthly active users.
| hanniabu wrote:
| It's different than handshake, it's built on Ethereum
| https://docs.ens.domains/contract-api-reference/dns-
| registra...
| eatonphil wrote:
| I understand the warning in general. But isn't .io,
| specifically, connected with the British government? And isn't
| the British government fairly stable/pro-business?
|
| https://en.m.wikipedia.org/wiki/.io
| joemi wrote:
| The article you linked to makes it sound like the future of
| .io is up to debate and not necessarily stable, IMO.
| jlund-molfese wrote:
| For now! But you probably read about the territorial dispute
| at the end of the article. Totally possible that the British
| government won't be controlling that domain at some point in
| the next 10-20 years.
| mod50ack wrote:
| It's really quite unlikely that the management of the .io
| domain will change. There are currently negotiations about
| the Chagos Archipelago. They involve mostly the right to
| return (for the Chagossians) and the rent on the military
| base (for Mauritius). There have been calls for the
| Chagossians to receive whatever portion of the domain fees
| go to the UK government (how much that is isn't really
| known), but nobody has called for the .io domain to stop
| existing or be changed in management.
|
| The resulting arrangement would virtually certainly be
| something like Tuvalu and .tv. Nobody is suggesting that
| they go into a Freenom-style domain mess like .ml and a few
| other domains (which some countries decided to just give
| away for free).
| jlund-molfese wrote:
| Hey, who knows.
|
| But if you choose .io, you're gambling on the future of
| your internet property in a way that the owners of
| traditional domains like .com simply don't have to worry
| about.
|
| What if someone decides to start a media campaign for
| divestiture of .io domains? It's not particularly likely,
| but it's a risk to weigh against the benefits of a cool
| domain.
| ARandomerDude wrote:
| > Rightly so
|
| Why?
| NovemberWhiskey wrote:
| I think the premise is something like "you wouldn't
| incorporate your startup in a West African dictatorship, why
| would you let the same country govern your domain name?"
| gnulinux wrote:
| Because TLD is the property of a sovereign. A sovereign that
| does not report to the US Government. For US business to use
| their property as their face to the world (such as pm.me)
| they need to understand and accept that they're putting their
| business fate in the hands of a sovereign. Things like OP (X
| Government takes back .xy TLD) happen, people need to pay
| attention to power, and geopolitics.
| ARandomerDude wrote:
| That may be a good reason for a company to avoid certain
| TLDs but it certainly doesn't make it right for a
| government to just cancel a legitimate business.
|
| So if Mali confiscates a TLD "rightly so" seems like an
| unreasonable response. "This is a warning to all of us"
| makes sense however.
| gnulinux wrote:
| Do you understand that there is no such thing as
| "illegal" in international "law"? Sovereigns can
| _literally_ do anything, and everything, and absolutely
| everything they want. So it is "right", maybe not
| ethically, but certainly legally. "The Government of
| Mali" does not report to anyone [1], so there is no
| institution to rule this as wrong, or a human process
| that can overrule the decision.
|
| Other sovereigns -- hopefully one of them counts you as a
| citizen and involves you in its processes through
| democracy -- can simply boycott, or embargo them, or
| dissuade them through diplomacy, or armed forces. Unless
| you understand this, you don't have a good model of what
| "the Government of Mali" means, and thus it doesn't make
| sense to make business with "the Government of Mali".
|
| [1] Well, except maybe to the people of Mali, or the
| constitution of Mali, but that's an internal
| "implementation detail" that's abstracted away from you,
| unless you're a citizen of Mali.
| smsm42 wrote:
| Strictly speaking you are right, but people commonly use
| "illegal" as "in violation of international treaties".
| Since there's no super-national sovereign to enforce
| those, it's not the same sort of illegal as we usually
| mean, but it is functionally close.
|
| That said, from what I understand, ccTLDs are owned by
| countries they are allocated to (maybe with some corner
| cases, but irrelevant here), so Mali is certainly not
| doing anything wrong even in the above "legal" sense by
| asserting their ownership.
| throwanem wrote:
| What does "sovereign" mean to you?
| Pet_Ant wrote:
| Because TLDs are supposed to mean things.
| NoMoreNicksLeft wrote:
| But how will they signal to the world their devout
| adherence to Marxist-Leninist principles?!?!
| rvnx wrote:
| They can use .su domains
| nocoiner wrote:
| I always found it hilarious when .ly was a trendy domain and
| people were literally building businesses on it. Like, you're
| going to put your fate in the hands of Muammar Gaddafi?
| dylan604 wrote:
| Hasn't he been dead since 2011? So, whose hands are they
| actually putting that fate in is what you should be concerned
| since your boogeyman is no more dangerous than the Freddy
| Krueger.
| 0x0 wrote:
| According to wikipedia, bitly started in 2008 and was in
| fact twitter's default url shortener in 2009, at which
| point Gaddafi was very much still in charge.
| carabiner wrote:
| [flagged]
| tiltowait wrote:
| Until this thread, I didn't even realize that .me and .io were
| ccTLDs. (I should have realized with .me, because I've seen it
| long enough, but I didn't start noticing .io until after the
| TLD explosion).
|
| I wouldn't be surprised if many were in the same boat.
| Registrars should probably warn if buying a ccTLD.
| writeslowly wrote:
| I assumed .io was still under the UK government, which is
| pretty stable as far as central governments go, but it's hard
| to actually tell whether it's them or some sort of venture
| capital thing from wikipedia.
| CameronNemo wrote:
| Using ccTLDs when you have no relationship with the country is
| just asking for trouble. Comes across as naive and
| unprofessional, although I've seen many serious infrastructure
| built upon .co and .io names.
| dylan604 wrote:
| i wonder how small the number of people that actually
| understand what ccTLD means in the first place, let alone how
| geopolitical turmoil could negatively impact their cute little
| domain name.
| tough wrote:
| lmao as a holder of a .me domain hope montenegro is fine
| Storm-Bringer wrote:
| Or .me like Proton Mail (pm.me)...
| neilv wrote:
| Mailfence.com offers `mf.me`. Mailfence could go even further
| by offering email addresses under `@ba.mf.me`.
|
| If someone secured the `.mf` ccTLD, they could grab other
| Pulp Fiction fans who want to be `<name>@bad.mf`.
| rvnx wrote:
| Says a lot when you had to make a choice between a beautiful
| domain name, or having to trust the government of Montenegro
| for all your lifetime for a super sensitive e-mail service.
|
| At least Montenegro is managing their own ccTLD, not like
| some mysterious islands (.io, .pw, etc).
| qingcharles wrote:
| But Montenegro has had hundreds of years of sovereign
| instability, i.e. it has been swallowed several times by
| other entities. I guess it was on .yu until the 21st
| century. It's probably stable for now, but nothing to say
| it won't get swallowed again and lose its TLD.
| riffic wrote:
| The misuse (off-label use perhaps, to use a term from medicine)
| of ccTLDs in the tech industry is a widespread practice and I
| doubt anyone's going to change anytime soon.
| WhereIsTheTruth wrote:
| Well, looks like the Mali government disagree with you
| DANmode wrote:
| Like seeing someone's social media post of their breakfast,
| I'm happy these signals exist.
| paulgb wrote:
| I've heard enough horror stories lately (including[1]) that
| I'm considering moving a container registry off of a cctld.
| Container registries for whatever reason use .io by
| convention (docker.io, gcr.io, ghcr.io) so our public-facing
| registry does too, but I've been thinking that it's not worth
| the risk. .io is probably safer than most just because of how
| load-bearing it's become, though.
|
| [1] https://www.youtube.com/watch?v=9Bg9XUEM82E
| nneonneo wrote:
| You're _hoping_ .io is safer than most. It's not exactly
| operated by a big or stable country. Ownership could change
| and the new owners could be arbitrarily capricious.
| paulgb wrote:
| Yep, that's a fair point. I do think that the more
| popular ccTLDs are probably slightly safer than less
| popular ones all else being equal because there is more
| riding on not "killing the golden goose", but stability
| of the country (or territory) is also a factor.
| slowmovintarget wrote:
| The Wikipedia entry on the .io TLD is interesting [1].
|
| The .io TLD is assigned to the British Indian Ocean
| Territories, and there's currently an ongoing international
| legal dispute over whether the territories even exist, or
| they just belong to Mauritius. If the U.N. "wins" the .io
| domain would be slated for removal (technically).
|
| [1] https://en.wikipedia.org/wiki/.io
| smsm42 wrote:
| Given that top-level domain does not have to be
| geographical, they can easily just keep it, just somebody
| else would be making money from it.
| bshipp wrote:
| I can't imagine .io would ever be removed. if anything,
| it'll be categorized like .org or .com if it loses its
| geographic justification.
| valianteffort wrote:
| But aren't two letter TLD's reserved for country codes?
| gary_0 wrote:
| There will definitely be complaints if we colonize
| Jupiter's moons but the .io TLD has been commandeered by
| open source projects.
| qingcharles wrote:
| And there is a lot of precedent for removing ccTLDs for
| countries that no longer exist, regardless of what is
| using them, e.g. East Germany, USSR etc.
| smsm42 wrote:
| .su still alive. Given it's controlled by Russia and
| widely used for scams I wouldn't recommend going to any
| site registered in that domain necessarily, but it has
| not been removed and likely won't be anytime soon.
| SpecialistK wrote:
| Especially when they're using .ml to refer to "Marxist-
| Leninist"...
| stickfigure wrote:
| Also, the organizations that run the nameservers are not
| necessarily as competent as the ones running .com. I had an 8
| hour outage when the entire .st domain went offline.
|
| My blog entry about it from 10 years ago:
|
| https://github.com/stickfigure/blog/wiki/Beware-cutesy-two-l...
| croes wrote:
| How would the trouble be different if you are a citizen of the
| country?
| paulgb wrote:
| The rule could probably be generalized to not building a
| business on a ccTLD, but there are instances where being
| unconnected to the country could directly be a problem. For
| example, .so (Somalia) domains have become popular as a
| generic ccTLD (because "so" is a generic English word, I
| guess?) used by companies like Notion, but technically it is
| against their terms to own one if you don't have a bona fine
| connection to Somalia.
|
| (Policy: https://sonic.so/wp-content/uploads/2018/11/dotso-
| domain-nam...)
| menus wrote:
| I don't understand how it's naive and unprofessional?
|
| twitch.tv, goo.gl, youtu.be, etc. is the tip of the iceberg.
| Twitch and Google probably are unlikely to have bases in Tuvalu
| and Greenland respectively.
| tough wrote:
| twitch.com -> twitch.tv redirect
|
| goo.gl is a link shortener like youtu.be aint it?
|
| I dunno, It's just asking for trouble needlessly
| reaperducer wrote:
| _Twitch and Google probably are unlikely to have bases in
| Tuvalu and Greenland respectively._
|
| And bit.ly probably isn't working out of Lybia.
| qingcharles wrote:
| Amazon and Google can probably buy off some of these Third
| World dictatorships to ensure ongoing use of the TLDs. (or
| pay for a coup)
| martin8412 wrote:
| Google already lost the right to use goo.gl for their link
| shortening service. I'm not sure who would be a part of a
| potential coup, but it seems unlikely since Greenland has
| no military of their own, the military being provided by
| Denmark(a NATO member) who has already in the past allowed
| the US to station nuclear weapons on Greenland, despite
| being a party to the NPT.
| nolok wrote:
| While I would certainly love to see google try to buy off
| Belgium for the entertainement value of the following ECJ
| case, I think you're exaggerating a bit too much
| CameronNemo wrote:
| Amazon and Google may not have bases in those countries, but
| they have a lot more weight than the typical company or
| individual.
|
| Hitching your wagon to their success seems unwise. They won't
| make sure you make it to the end
|
| Just buy a gTLD domain. You probably don't even need a
| separate domain for your link shortener...
| menus wrote:
| Forget gTLD, Google has their own TLD (1)
|
| (1) https://blog.google/
| mc32 wrote:
| When Libya was in turmoil years ago this issue came up. Looks
| like people forget.
| sitzkrieg wrote:
| of course. techbros been doing circles on all sorts of stuff
| sebmellen wrote:
| I think this remains the biggest long-term risk with using
| bit.ly links. I have seen so much hard copy media with bit.ly
| links, especially technical books, that I shudder to think of
| how many dead links there will be if Lybia takes it offline.
| jrmg wrote:
| It was never actually more than a theoretical problem then
| though, right? The .ly domain remained (and remains) stable
| and functioning IIRC.
| edent wrote:
| Nope.
| https://www.theguardian.com/technology/2010/oct/08/bitly-
| lib...
| jrmg wrote:
| Thanks. Bit.ly remained - but that article does indeed
| show at least one .ly domain (vb.ly) being cancelled.
|
| From the article:
|
| _That follows the abrupt enforced shutdown of vb.ly, a
| "link shortening" site run by Ben Metcalfe and Violet
| Blue, after it was declared that the content of the site
| was "against Sharia law"._
|
| _An image of Violet with bare arms, drinking from a
| bottle of lager, was emblazoned across the front page of
| the site when the government-owned Libya Telecom &
| Technology got in touch earlier this month. "Pornography
| and adult material aren't allowed under Libyan law,
| therefore we removed the domain," the letter said,
| adding: "The issue of offensive imagery is quite
| subjective, as what I may deem as offensive you might
| not, but I think you'll agree that a picture of a
| scantily clad lady with some bottle in her hand isn't
| exactly what most would consider decent or family
| friendly at the least."_
| WeylandYutani wrote:
| Probably thought they could get away with it since it's a poor
| African country.
| WoahNoun wrote:
| More worryingly, typos to US military addresses from external
| address will now be routed to Mali. From Matt Levine this week:
|
| >Millions of US military emails have been misdirected to Mali
| through a "typo leak" that has exposed highly sensitive
| information, including diplomatic documents, tax returns,
| passwords and the travel details of top officers.
|
| >Despite repeated warnings over a decade, a steady flow of email
| traffic continues to the .ML domain, the country identifier for
| Mali, as a result of people mistyping .MIL, the suffix to all US
| military email addresses.
|
| >The problem was first identified almost a decade ago by Johannes
| Zuurbier, a Dutch internet entrepreneur who has a contract to
| manage Mali's country domain.
|
| >Control of the .ML domain will revert on Monday from Zuurbier to
| Mali's government, which is closely allied with Russia. When
| Zuurbier's 10-year management contract expires, Malian
| authorities will be able to gather the misdirected emails. The
| Malian government did not respond to requests for comment.
|
| >"Much of the email flow is spam and none is marked as
| classified," and apparently if you work in the US military and
| you email someone else in the US military, the system prevents
| this typo. But if you are an outside contractor, or an Army
| officer emailing from your personal account, all bets are off.
| "Around a dozen people mistakenly requested recovery passwords
| for an intelligence community system to be sent to Mali."
| rvnx wrote:
| A solution would be Google + Amazon + Microsoft + Whatever
| security company to be block outgoing emails going to
| army.ml/navy.ml and the problem is solved.
|
| This is one of the rare good sides of having near-monopolies.
| neilv wrote:
| Related HN: "Typo leak" exposes millions of US military emails
| to Mali web operator (ft.com) | 150 points by cafemachiavelli 4
| days ago | 70 comments |
| https://news.ycombinator.com/item?id=36756201
| voytec wrote:
| .ga TLD was "nationalized" as well[1] after the fall of Freenom
|
| [1] https://www.afnic.fr/wp-media/uploads/2023/05/ga-domain-
| name...
| eikenberry wrote:
| Why doesn't everyone run their own Lemmy server and federate?
| Seems to me this would be the only way to avoid all the various
| server problems.
| paxys wrote:
| Because not everyone wants to host and maintain a server?
| rglullis wrote:
| It doesn't have to be "everyone", but imagine how much
| healthier the internet would be if 0.1% of the users of any
| social media network self-hosted and went on to provide the
| services for their friends/family.
|
| To add to that, imagine if every small business that
| wants/needs to have a web presence (basically, everyone)
| could have many different hosting providers where they could
| have their own Mastodon server, Web Page, online support and
| calls via Matrix, etc. This doesn't need to cost more than
| $50/month, i.e, probably less than what people pay in their
| cellphone bill.
|
| Just that would make - almost by definition - that no server
| would house more than 1000 people. It would be completely
| resilient.
___________________________________________________________________
(page generated 2023-07-21 23:02 UTC)