Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider a non-io URL #15

Closed
iredelmeier opened this issue Jun 14, 2019 · 1 comment
Closed

Consider a non-io URL #15

iredelmeier opened this issue Jun 14, 2019 · 1 comment

Comments

@iredelmeier
Copy link
Member

tl;dr: There are a few significant issues with the .io TLD.

  • Political issues: There are some political concerns around the .io registry that many people feel strongly about. All debate about the actual concerns aside, it seems unnecessary to alienate users and potential users of OpenTelemetry by using a .io URL when we're in a great position to use something else, e.g., opentelemetry.dev.
  • Security: This article explains a vulnerability in which a researcher hijacked nameservers, which would allow rogue redirection
  • Support: As discussed here, it sounds like the registry itself has pretty rough support
@SergeyKanzhelev
Copy link
Member

I'm glad you brought it. It was raised as an issue and discussed in smaller forum before. We discussed that we want to keep it consistent to other projects even knowing of all the risks.

@tedsuo predicted this question in public. Quote (posting with his permission):

To address concerns, since they may be raised in public: It's not clear to me that bad domain management would effect this particular project significantly. We do not route production traffic through, or host code, at the .io domain. I do suggest we also keep opentelemetry.dev as a backup for the website. Though I'd love to have a long conversation over drinks about issues pertaining to national security and supply chain attacks on critical OSS software, I don't think that is the level we're talking about here. At least, I hope not. Because we are deeply screwed, in general, if that is the case.

So you can take him up for a conversation over drinks promise.

I suggest we open another issue like "Create a backup for the website on the domain in an alternative domain zone".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants