7 ms·
> How are you going to pay for the (substantial) cost of running a TLD without registration fee revenue? Is this a loss leader for other services? Are you opera
by HumanCCF 3mo ago
> How are you going to pay for the (substantial) cost of running a TLD without registration fee revenue? Is this a loss leader for other services? Are you operating on a 100% donation model?
We plan on operating the domain as a public good and are actively seeking sponsors to help fund us. Think of it as a similar model to ISRG and LetsEncrypt.
> No parking, squatting, or reselling
Our rule of one person per subdomain will hopefully prevent this at scale, though it will admittedly be more difficult to examine any particular domain so closely. We may have to implement some type of heartbeat where the owner of said domain has to respond within a certain amount of time.
- al_borland 3mo agoHow is one person per subdomain enforceable? How is a person uniquely identified and tracked?
- dom96 3mo agoMy guess is by using ID verification similar to how I do it on https://onlyhumanhub.com/ https://onlyhumanhub.com/
- kokanee 3mo agoI'm curious about how this works, but it doesn't look like I can find out without creating an account. I see that it says "Link your existing social accounts to prove you're not a bot." How does having social media accounts prove I'm not a bot?
- dom96 3mo agoIf you're interested in detail of how it works, I wrote about it here: https://blog.picheta.me/post/the-future-of-social-media-is-human/ https://blog.picheta.me/post/the-future-of-social-media-is-h...
- kokanee 2mo agoI see -- the statement "Link your existing social accounts to prove you're not a bot" is intended to mean that after you have verified your identity by scanning your passport, you can prove you're not a bot on your BlueSky account. The phrasing is misleading, and the home page seems to omit the most important part: you have to scan your passport.
- SahAssar 3mo agoSo you have just built a wrapper around https://passportreader.app/ https://passportreader.app/, which itself is reading NFC enabled ID/passports from specific countries. The coverage map is here: https://passportreader.app/coverage https://passportreader.app/coverage. Might be good to know that even in the US this approach would only work for ~50% of people, since a lot of people don't have passports. In most countries this does not work at all, since they don't issue NFC enabled ID/passports.
- teraflop 3mo agoThe "how it works" page for that website says that the ID data is "digitally signed by the issuing government". But there doesn't seem to be anything in the docs about how to get or verify that signature. So it seems like they are just asking users to trust them to do the verification.
- notpushkin 3mo ago> The coverage map is here: https://passportreader.app/coverage https://passportreader.app/coverage Oh, cool! Russia is not on the list. Another service that excludes me just becasue I got lucky with the colour of my (NFC-enabled, biometric) passport. On a less bitter note, I don’t think it’s that hard to build biometric passport validation. Face matching would be another thing, but for unregulated industries I don’t think you’ll need that, so why not grab some library from GitHub and be in control of the whole process? (You would still need to handle people without biometric passports somehow, of course.)
- dom96 3mo agoNo humanity verification is perfect. 50% of people is already pretty good. Really governments need to do better here, and make it possible to do this type of verification using zero knowledge proofs.
- deleted 3mo ago[deleted]
- SahAssar 3mo ago> Think of it as a similar model to ISRG and LetsEncrypt. In that case it was started by an institution (mozilla) with a lot of heft in the area (mozilla's CA program is one of the most broadly used) and was backed by other orgs (google) that had a vested interest in it's success. I'd be interested to hear which potential sponsors you see in a similar situation here? > rule of one person per subdomain What is the plan to (without costly overhead or cost to the end user) validate who is an actual person? Even large corporations with loads of resources have problems with this without resorting to treating it as if a person equals a credit card number.
- HumanCCF 3mo ago> In that case it was started by an institution (mozilla) with a lot of heft in the area (mozilla's CA program is one of the most broadly used) and was backed by other orgs (google) that had a vested interest in it's success. I'd be interested to hear which potential sponsors you see in a similar situation here? We are reaching out to companies who operate in the self-hosted space, academia, ISPs, registars, as well as digital rights orgs. We believe they would be aligned with this mission and ultimately benefit from such a TLD existing! > What is the plan to (without costly overhead or cost to the end user) validate who is an actual person? Even large corporations with loads of resources have problems with this without resorting to treating it as if a person equals a credit card number. There are a few emerging technologies we are evaluating to help with this but have not settled on one just yet. Whatever we choose, we will start small and go from there. Worst-case scenario, we start with the credit card approach and iterate. This will ultimately all be a part of the evaluation process we go through with ICANN.
- DonHopkins 3mo ago[dead]
- SahAssar 3mo agoTo be honest it feels like these answers boil down to "we feel it'd be nice if this existed but we have no actual answers as to how to get it done". --- To stick with your comparison: when letsencrypt and ISRG launched they had actual answers for how to deal with the hard challenges in their space: A) how to get included in a trust roots (crossigning with IdenTrust at first and the knowledge and expertise of how to get included in the longer term) B) Automated domain validation in a standardized way (ACME) C) Long term commitments of sponsorships to ensure people could trust it would stick around --- I wish you the best of luck, but I think this might have needed to bake a bit longer before publicizing.
- Galanwe 3mo ago> We may have to implement some type of heartbeat where the owner of said domain has to respond within a certain amount of time. A domain squatter is in an easier position to automate that than an amateur to not forget to respond.
- hk__2 3mo ago> Our rule of one person per subdomain will hopefully prevent this at scale No it won’t. Spammers will just pay thousands of random people in poor countries to create their domain.