Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding the domains to the Public Suffix List #118

Open
aeternesatiatus opened this issue Jun 5, 2022 · 8 comments
Open

Adding the domains to the Public Suffix List #118

aeternesatiatus opened this issue Jun 5, 2022 · 8 comments

Comments

@aeternesatiatus
Copy link

I suggest you add cluster.ws and wip.la to the Public Suffix List, in the likes of other similar free subdomain services like eu.org and js.org.

This would help against supercookies and other issues (i.e. per-domain rate limits)

@politician
Copy link
Member

I did try but it was rejected. I plan to retry later, if you or anybody else has more arguments to support our case, please comment here, I'll use this as a reference.

@BastelPichi
Copy link

Me sad 👎 lol
Please retry at some point. Also somehow therese seams to be a way to use subdomains?! Allthough that pretty much what I tried before...
https://support.cloudflare.com/hc/en-us/articles/360026440252-Understanding-Subdomain-Support#h_39a346bb-4726-4f69-969e-016fbacbb2c0

@aeternesatiatus
Copy link
Author

aeternesatiatus commented Jun 4, 2023

Sorry for such a late reply

I suppose, you could argue that eu.org, js.org are similar free subdomain services that have been previously accepted to the PSL @politician

Not to mention all these corporate domains that were included to the PSL as well.

@ririko5834
Copy link
Contributor

yeah, if it was on PSL, then I could use it with cloudflare DNS

@aeternesatiatus
Copy link
Author

aeternesatiatus commented Aug 2, 2023

Perhaps, but these are not acceptable reasons the PSL maintainers. As such, the point is that these domains are for a free subdomain service, whose users are mutually untrusted parties and as a de facto public suffix, it should be added to prevent cross-subdomain security issues.

While it may matter to you that you want to use LE or Cloudflare, to the eye of the PSL maintainers it is just a way to circumvent third-party limits if you mention these reasons.

You want to insist on the fact that it is a free subdomain service for independent users who are mutually-untrusting and that it is a free and public service and therefore a de facto public suffix that should be added to the PSL. You may also remind PSL maintainers that other free subdomain services are listed, and often also non-public domains are also added to the PSL.

@IncognitoTGT
Copy link
Contributor

Me sad 👎 lol Please retry at some point. Also somehow therese seams to be a way to use subdomains?! Allthough that pretty much what I tried before... https://support.cloudflare.com/hc/en-us/articles/360026440252-Understanding-Subdomain-Support#h_39a346bb-4726-4f69-969e-016fbacbb2c0

You have to pay for enterprise though

@IncognitoTGT
Copy link
Contributor

Tell that the domain is used exclusively for subdomains, and adding it to the PSL would make it work like a normal subdomain

@IncognitoTGT
Copy link
Contributor

Also since it prevents the entire domain from getting flagged by Safe Browsing, which happened

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants