Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Jeff – Jev-compatible 0.8B decision models, trained at home, ~30 ms (github.com/firelex)
    144comments
  2. 1996 chat room simulator connected to Win95 and System 7 web desktops (lolchat.rip)
    34comments
  3. Pirating the Pirates (mubi.com)
    239comments
  4. MicroLLM Lab – Try 7 tiny LLM's in the browser (stateofutopia.com)
    68comments
  5. 12,000-year-old Göbeklitepe burials explain scattered bones (archaeologymag.com)
    27comments
  6. Tank Body Problem (jimsitu.com)
    9comments
  7. California farmers are struggling to sell grapes as demand for wine drops (kqed.org)
    251comments
  8. ESP32S3 cluster running 1.58-bit (BitNet) Language model (github.com/low-zi-hong)
    7comments
  9. Show HN: Pac-Bench – How well can models one-shot a Pac-Man game? (jonclegg.github.io)
    5comments
  10. Sonnet 5.5 (anthropic.com)
    440comments
  11. Scientists solve 1840s space weather mystery (arstechnica.com)
    39comments
  12. Hijacking the PS5's RTMP stream (yashgarg.dev)
    69comments
  13. World Labs Is Joining AMD (worldlabs.ai)
    90comments
  14. Phyllotaxis: An audio-reactive LED display (jagi.studio)
    —discuss
  15. Who Killed Paulina Borsook's Career? (wired.com)
    —discuss
  16. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    194comments
  17. How to win a beer with high-dimensional statistics (jamiesimon.io)
    5comments
  18. Bluegraph – Explore NOAA buoy data, rebuilt in 3D from measured spectra (bluegraph.io)
    2comments
  19. What is the best shape of a city? Modelling effect of urban form on distance (sagepub.com)
    12comments
  20. Updated Google Maps shows destruction of the city of Rafah (twitter.com/aliabunimah)
    171comments
  21. Does Reddit have an astroturfing problem? What the data suggests (petervijeh.com)
    178comments
  22. Nvidia wants to put a watchdog chip next to every AI agent (cnbc.com)
    160comments
  23. The Art Forger Who Became a National Hero (priceonomics.com)
    4comments
  24. It's Time to Investigate the AI Labs (calnewport.com)
    133comments
  25. Show HN: HN.watch – Videos of all Hacker News posts (hn.watch)
    86comments
  26. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    58comments
  27. U.S. Strategic Petroleum Reserve Falls to Lowest Level Since 1982 (oilprice.com)
    114comments
  28. Profit Margins of the Largest Companies (visualcapitalist.com)
    2comments
  29. What reversing, modernising old games tells us about the economic impact of AI (isfine.org)
    38comments
  30. Behold the pawpaw (cbc.ca)
    26comments

No, that dot in the domain name of the URL is not a mistake (2004)

148 pointsby 6y agojdebp.info.
77 comments
6y agoHN ↗

Joke's on you. Once spent a whole morning failing to obtain a signed SSL certificate from one of the certificate authorities. The field description in a web form was clearly stating to enter the FQDN, yet the form was not passing through with a very general error description (it appeared later that the URL with a dot at the end was not validating, someone copy-pasted a regex of an URL?). On help request, the IT operations guys looked with disdain at the webdev unable to produce "a stupid certificate". The disadvantages of reading the instructions and field hints ¯\_(ツ)_/¯

6y agoHN ↗

I get the following error when I add a dot at the end of the address for a virtual host in Apache:

Misdirected Request

The client needs a new connection for this request as the requested host name does not match the Server Name Indication (SNI) in use for this connection.

Apache/2.4.25 (Debian) Server at example.com Port 443

6y agoHN ↗

You don't add dots in the config file.

If you configure the virtual host to be e.g. "example.com", Apache will listen at "example.com" and "example.com."

6y agoHN ↗

He makes a 'technically correct' case for fully qualified domain names, but I'm not sure this a real problem. Under what circumstances are things really improved by using them? If your DNS server is untrustworthy, this doesn't help. If your DNS server is trustworthy, do fully qualified domain names help you?

There's almost nothing on the web about 'Common Internet Scheme'. [0]

Also, it's a little ironic that we're reading a page on spoofing, from a site which doesn't support HTTPS.

[0] https://www.google.com/search?q="Common+Internet+Scheme"

6y agoHN ↗

> Also, it's a little ironic that we're reading a page on spoofing, from a site which doesn't support HTTPS.

Let's encrypt didn't exist in 2004.

6y agoHN ↗

But HTTPS did. You just had to pay to get a certificate.

6y agoHN ↗

You had to pay a fair bit of money back then for SSL.

And why does a static html site need https?

I’m all for encryption but we just HTTPS things pointlessly.

Why can’t I use my own self-signed certificate, it’s the same thing.

6y agoHN ↗

Because without HTTPS, the content can be modified in transit. Some free Wi-Fi access points and evil ISPs, for example, will inject ads and trackers.

6y agoHN ↗

HTTPS should be used even for static sites.

1. Privacy matters. A medical website, or indeed Wikipedia, should prevent a snooping ISP from finding out you have been reading about an embarrassing condition. This is similar to the way librarians are extremely protective of their loan records [0]. Netflix use HTTPS for their streams, for the same reason (it does nothing to aid their DRM, it's purely about privacy) [1].

2. As someone here already mentioned, it prevents ads/trackers/malware being injected into the page by unscrupulous ISPs (this really has happened [2])

3. Modern browsers will (rightly) warn users not to trust the site. This makes the site look bad.

4. Some fancy browser features are disabled if you use unencrypted HTTP. Likely irrelevant for a static site though.

5. Let's turn the tables and ask why you wouldn't use HTTPS for a public-facing web server. There are just two reasons: firstly, reduced admin overhead not having to bother with certs, and secondly, it enables caching web proxies, which is only relevant if you're running a serious distribution platform like Steam, or a Linux package-management repo [3]

Why can’t I use my own self-signed certificate, it’s the same thing.

It is not. I don't think you understand the role of CAs. Self-signed certs do not provide protection against connecting to an impersonator.

[0] https://www.theguardian.com/us-news/2016/jan/13/us-library-r...

[1] https://arstechnica.com/information-technology/2015/04/it-wa...

[2] https://doesmysiteneedhttps.com/

[3] https://whydoesaptnotusehttps.com/

6y agoHN ↗

I’ll agree to disagree, because otherwise the conversation would be moot.

I just disagree that we should “HTTPS” everything and that’s partly because of the overhead. A medical site is different to a static html site like listed in the post.

ISP regardless of SSL know which sites I’m visiting. It’s there in the HTTP host header regardless of SSL or not. And transit security can easily be encrypted without SSL but people are too lazy to encrypt their content within the application.

“run acme encryptbot” no thanks. When I want a pure server with nothing other than my application I don’t want to download a certificate bot, install (lang) and let it mess with my configuration.

I don’t dismiss that HTTPS is important but I feel platform is flawed. Owned by corporate greed. It’s security based upon pay us money or else model.

6y agoHN ↗

the overhead

The computational overhead is negligible. This simply isn't a credible argument against HTTPS.

Netflix send petabytes of data over HTTPS. There's no excuse for anyone else.

A medical site is different to a static html site like listed in the post.

Different in degree, but not in category. Your browsing habits on ordinary non-sensitive sites can still be used to profile you.

ISP regardless of SSL know which sites I’m visiting

They can still look at the destination IP, yes, and they can probably look at your DNS requests, as secure DNS is currently only rarely used. It's still worth doing. Knowing that someone went on Wikipedia tells you almost nothing. Knowing the specific pages they went to, tells you a great deal.

It’s there in the HTTP host header regardless of SSL or not.

That's not the case. HTTPS encrypts all headers.

transit security can easily be encrypted without SSL

The easy solution is HTTPS.

people are too lazy to encrypt their content within the application.

A universal principle in cyber-security: rolling your own crypto scheme is generally a terrible idea. As I said, Steam and Apt are the exceptions; they use plain HTTP for delivery, and implement secure file verification using hashes. Even here, with competent people running a simple delivery scheme, there can be serious security issues [0].

When it comes to web applications, you cannot implement your own secure delivery, for the obvious reason: an attacker can just replace your code. Sites like LastPass.com still have to use HTTPS to deliver the web app.

Even if it could be done, there would be no reason to. The browser offers you HTTPS, so you get a carefully designed, battle-tested protocol, and a carefully designed, battle-tested implementation. You are entirely shielded from all the complexities. You aren't going to do better in JavaScript.

When I want a pure server with nothing other than my application I don’t want to download a certificate bot, install (lang) and let it mess with my configuration.

It's additional configuration work, yes, but I don't accept that it's much of an argument against HTTPs. You still have totally free choice over your tooling and languages.

I don’t dismiss that HTTPS is important but I feel platform is flawed.

You've not presented a single good argument against the technical merits of HTTPS.

Owned by corporate greed. It’s security based upon pay us money or else model.

You can get certs for free. This isn't new. [1]

[0] https://justi.cz/security/2019/01/22/apt-rce.html

[1] https://en.wikipedia.org/wiki/Let%27s_Encrypt

6y agoHN ↗

You are grossly misinformed on this subject.

I just disagree that we should “HTTPS” everything and that’s partly because of the overhead.

The overhead in any modern CPU is negligible. If you're worried about negligible overhead then why are you using an entire operating system to serve up web pages?

ISP regardless of SSL know which sites I’m visiting. It’s there in the HTTP host header regardless of SSL or not.

The host header is encrypted over HTTPS. Furthermore, SSL isn't used in 2019 as it's insecure and was replaced with TLS. That might be pedantic but it seems to align with what this post is about so I'll mention it.

You're confusing the host header with the server name indication sent in the client hello. There is a huge difference between my ISP knowing I went to example.com (with TLS) or example.com/medical/how_to_deal_with_cancer.html (without HTTPS)

And transit security can easily be encrypted without SSL but people are too lazy to encrypt their content within the application.

I'm not sure what you're suggesting here. The industry standard transport security for HTTP is TLS. Trying to re-invent the wheel is counterproductive and dangerous.

“run acme encryptbot” no thanks. When I want a pure server with nothing other than my application I don’t want to download a certificate bot, install (lang) and let it mess with my configuration.

Then don't. The specification for the acme protocol is open and available to you. You could automate the entire process and even choose a DNS based challenge. Typical use of cerbot, should you choose to use it, does not "mess with your configuration".

I don’t dismiss that HTTPS is important but I feel platform is flawed. Owned by corporate greed. It’s security based upon pay us money or else model.

It literally isn't because Let's Encrypt gives out certs for free. Additionally, so does AWS, Azure, and GCP. If you're paying for a certificate you're doing it wrong.

You have always been free to use self-signed certificates, but then the challenge of convincing your visitors that your certificate really is from you and not someone else who created a self-signed certificate becomes your problem to manage.

6y agoHN ↗

I made all these points 2 hours ago.

6y agoHN ↗

You could get one for under $10/y which is not what I’d call a fair bit of money.

I think the problem with HTTPS/SSL was that it tried to solve two problems at once (trust and encryption) without a practical way to separate them. You can argue that’s justified (what’s the point knowing the connection is encrypted if you don’t know who is on the other side), but those panicky browser alerts made self signed SSL certificates all but useless. That’s why we need letsencrypt now.

6y agoHN ↗

Even with let's encrypt it still seems odd to me that you need a 3rd party to confirm you own a domain name(and issue a certificate for it). The web trust model is broken.

6y agoHN ↗

A similar thing happened where I work. Say our domain name was `example.com`, we had a fleet of hosts at `foo.build.example.com`, `bar.build.example.com`. The internal network handed out `example.com` as the DNS search string but web browsers always try the FQDN first. On the day the `.build` gTLD went live, people who use short names in their URLs (just about everyone) could no longer access these hosts and I was the one who got to figure out why.

6y agoHN ↗

His issue wasn't the domain they used becoming a TLD, his issue was a subdomain they used became a TLD and the DNS resolvers of his clients were not configured to append the parent domain first, probably the search list wasn't populated.

6y agoHN ↗

Oh. I misunderstood that. Thanks for clarifying.

6y agoHN ↗

..but I'm not sure this a real problem

If you are inside a large corporate network, that spans the globe and has many internal domain names, and a lot of DNS forwarding, it's a very real problem. Especially when trying to debug inconsistent name resolution.

6y agoHN ↗

Well congratulations, you're blocked by my adblocker because of that dot (uBlock Origin with EasyList Liste FR)

6y agoHN ↗

Why would that list be blocking fully qualified domain names? Seems more like a bug than a feature, but if there is a good reason for it I'd be interested to learn

6y agoHN ↗

I would imagine the reason is that some ad provider used a fqdn to get around some badly written rule, and then someone added an even worse rule to block all fqdn to negate that trick.

6y agoHN ↗

You should get that fixed because it‘s wrong

6y agoHN ↗

Works fine here with Firefox, uBlock Origin, and EasyList. Maybe the Fr version has a buggy rule?

6y agoHN ↗

Same here. Wrong filter: /^(https?|wss?):\/\/([0-9a-z\._-]+)\.(accountant|bid|cf|click|club|com|cricket|date|download|faith|fun|ga|gdn|gq|info|link|loan|men|ml|net|network|ovh|party|pro|pw|racing|review|rocks|ru|science|site|space|stream|tk|top|trade|webcam|win|xyz|zone)\.\/(.*)/$document

6y agoHN ↗

One issue I noticed is how browsers and sites handle the dot inconsistently; Edge browser used to "fix" the url, for example.

Google used to do a weird combination of rewriting and/or using the dot, depending on what part of the site you were on. What ended up happening roughly is that you could log into the FQDN, google would do logins for both dot/nodot, if you logged out of one, the other would still work (probably also a combination of Chrome keeping 2 sets of cookies)

I probably can't, but if I find my original notes I'll add a reply...I recall both Edge and Google fixing the problem, but there are other sites & browsers i'm sure that are still affected

6y agoHN ↗

"You've come to this page because you've asked a question similar to the following:

I omitted the trailing dot in the domain name in the http://example.com./ URL because it was a typographical error."

That is not a question, though.

6y agoHN ↗

I find it wonderful that a link to a page talking about stripping a trailing period from a domain has been linked to with descriptive text from which the trailing period has been stripped from the domain

6y agoHN ↗

It was present when it was posted; I suppose moderators removed it for consistency with HN style.

6y agoHN ↗

Firefox tells you that both connections are not secure... are you using Chrome?

6y agoHN ↗

Both show as Not Secure on my Chrome (78.0.3904.108)

6y agoHN ↗

Sadly many libraries get RFC and standards implementations wrong. I've run into similar edge cases before, and it's always frustrating to see it either not implemented at all (best case), or overlooked due to simplified implementation (e.g. regex instead of parsing), or that there's a bug report that's closed as wontfix because it would be too complicated to fix.

6y agoHN ↗

I feel dumber for having read this article. Tbf it’s from the early 2000s but it reads like a nasally academic trying to lecture people who work for a living about theory with little to no practical benefit.

6y agoHN ↗

The level of passive-aggression in the side-swipe at djb is quite impressive though.

6y agoHN ↗

I have been surprised that some domain registrars reject FQDNs when they ask for your DNS servers. Sad.

6y agoHN ↗

Glad to see that http://pn/ and http://pn./ are both apparently working.

I'm pretty sure that at one point I had to supply the trailing dot to make the browser (or resolver) believe it was a real hostname.

6y agoHN ↗

I'd guess it's the TLD of the Pitcairn Islands set to resolve to this random page. For example

    http://ca. 

resolves to the Canadian domain registrar.

6y agoHN ↗

Not necessarily a random page, but an “it works” page so you know your server works.

6y agoHN ↗

How perplexing that it works at all! I want to know how that works.

6y agoHN ↗

It’s just a TLD that actually resolves; Most don’t. For example, http://com./ doesn’t resolve even though it has “subdomains”.

This does though beg the question: can a second level domain (root website) have (what we call) subdomains and not resolve itself? For example, example.example.com would resolve, but example.com wouldn’t?

6y agoHN ↗

Should be easy to set up, especially if you have your own authoritative DNS server. Just don't publish an A record for your main domain.

6y agoHN ↗

Thanks for the clarification. I see, so an owner can choose to resolve the top-level domain by itself, I didn't know that.

When I visit "com.", indeed it doesn't resolve and the browser falls back to "www.com" (which exists).

That makes me wonder, if I wanted a TLD by itself to resolve to my own site, is it even feasible for a "regular person"?

What's served on "http://pn/" looks like someone's experiment, but I guess they must own the TLD (or have connections to the owner)..?

6y agoHN ↗

When I click on the first link in iOS Safari I get sent to a search results page served by my (read: my parents’) ISP. That’s pretty disturbing.

The second link appears to work. It’s a page that says “It works!” but it’s not HTTPS so of course I have no way of knowing whether that’s the ISP playing tricks as well. ;)

6y agoHN ↗

Time to change ISP's or check for malware :/

6y agoHN ↗

Why is that disturbing? For me, the name doesn't resolve (http://pn/).

Assuming you are using your parents' ISP's default DNS servers, isn't it a safe, though less-than-desirable, result for the ISP to forward you to a search page when resolution fails?

6y agoHN ↗

No, the DNS should return NXDOMAIN and that’s it.

6y agoHN ↗

Using a different DNS server not provided by the ISP would most likely solve the problem.

You can do so in either the router or your computer/phone. Two well known and performant public DNS servers are found at 1.1.1.1 (CloudFlare) and 8.8.8.8 (Google).