I haven't seen anyone talk about it, but there is another important implication of all these new TLD's: security.
This will give malware purveyors a whole new plethora of vectors to exploit insofar as social engineering goes.
Imagine regular user 'A' is surfing, looking for a cool new pair of shoes. They know that kewlShoes is their fav shoe company evar. Some entity has paid the huge fee to acquire the .shoes TLD in order to sub-let domains at whatever nominal fee they decide.
User 'A' browses to kewl.shoes instead of kewlshoes.kshoes and unwittingly becomes the latest drive-by-download victim happily handing over their credentials to who-knows-who.
I know this is broad and speculative, but think it is worth consideration.
Has there been other discussion about this out there that I haven't seen?
I think the vector itself is an issue; but I don't think this will make it significantly worse. For any domain, there's already hundreds or thousands of possible similar domains across the existing TLDs - adding a few more TLDs won't make much of a difference.
I also doubt that the future owner of .shoes - whoever that may be - will be stupid enough to devalue his own TLD by selling second-level domains like candy. There's probably more money to be made by banking on its exclusivity.
No, this is ~2000 TLD applications. We have no idea how many of those will ICANN approve.
But many of these new TLD's have been applied for by entities who plan on sub-letting the TLD to others.
My point wasn't that they won't sell domains, but that many or most won't sell them to any random shmoe like .com/.net/etc are sold, but only to businesses in the fields and how are willing to pay a lot more for the privilege, which doesn't describe scammers.
>but only to businesses in the fields and how are willing to pay a lot more for the privilege
Here's to hoping you're right.
Though, I doubt anybody would be surprised to find the bar vastly lower than you expect--especially when it comes time for these purchasers to recover some of the cost and find these fields are smaller than anticipated.
Comments
I haven't seen anyone talk about it, but there is another important implication of all these new TLD's: security.
This will give malware purveyors a whole new plethora of vectors to exploit insofar as social engineering goes.
Imagine regular user 'A' is surfing, looking for a cool new pair of shoes. They know that kewlShoes is their fav shoe company evar. Some entity has paid the huge fee to acquire the .shoes TLD in order to sub-let domains at whatever nominal fee they decide.
User 'A' browses to kewl.shoes instead of kewlshoes.kshoes and unwittingly becomes the latest drive-by-download victim happily handing over their credentials to who-knows-who.
I know this is broad and speculative, but think it is worth consideration.
Has there been other discussion about this out there that I haven't seen?
That already happened with second-level domains, it's not a new vector.
True, but now it's a much, much larger vector.
OK, sorry. But it greatly increases the surface area, no?
Would you say it really isn't an issue?
I think the vector itself is an issue; but I don't think this will make it significantly worse. For any domain, there's already hundreds or thousands of possible similar domains across the existing TLDs - adding a few more TLDs won't make much of a difference.
I also doubt that the future owner of .shoes - whoever that may be - will be stupid enough to devalue his own TLD by selling second-level domains like candy. There's probably more money to be made by banking on its exclusivity.
True, there are tons of similar TLD's out there already. But this ins't a "few more TLDs". This is ~2,000 new TLD's.
Indeed, 'shoes' was a bad example. But many of these new TLD's have been applied for by entities who plan on sub-letting the TLD to others.
This is ~2,000 new TLD's.
No, this is ~2000 TLD applications. We have no idea how many of those will ICANN approve.
But many of these new TLD's have been applied for by entities who plan on sub-letting the TLD to others.
My point wasn't that they won't sell domains, but that many or most won't sell them to any random shmoe like .com/.net/etc are sold, but only to businesses in the fields and how are willing to pay a lot more for the privilege, which doesn't describe scammers.
Fair point about the approval.
>but only to businesses in the fields and how are willing to pay a lot more for the privilege
Here's to hoping you're right.
Though, I doubt anybody would be surprised to find the bar vastly lower than you expect--especially when it comes time for these purchasers to recover some of the cost and find these fields are smaller than anticipated.