Query regarding domain on PSL

Hey infinityfree, Why don’t you submit your domain to PSL(Public Suffix List) like eu.org?

There are a few reasons for this:

  • Getting a domain added to the PSL is a rather slow and cumbersome process from what I’ve heard.
  • I don’t know what side effects the PSL registration might have. For example, would it prevent is from getting SSL certificates for *.ct.ws? Or would subdomains get inadvertently detected as valid top level domains?
  • I was told a few years ago that iFastNet looked into this some time ago and decided not to pursue it. But I don’t know exactly why that is.

All in all, it might be possible, but we have to be careful about this.

As far as I heard, if domain is added to the Public Suffix List, it will be treated like a top-level domain for many services. You could try submitting just one domain that infinityfree own, such as *.ct.ws, and see how it works. If everything goes well, subdomains like xyz.ct.ws should be accepted more easily by Google AdSense and other services that rely on the Public Suffix List, because many services don’t accept subdomain, but as soon as they are in PSL, they accept it, I would recommend trying it with one domain first.

PSL is divided into two parts: ICANN domains and private domains. ICANN domains are suffixes that is considered as regular TLDs and wildcard SSL certificates should not be issued to those domains directly.

Private domains, however, is different. Those domains are still considered as being owned by a private entity and wildcard certificates can be issued to them with one of the most famous example being github.io.

Since the three reasons you listed only includes this one actual potential drawback I don’t think it’s bad to try to submit at least InfinityFree owned free subdomains to the PSL. It might also help to mitigate the noisy neighbour effect.

I have independently looked into this a few years ago back before the SSL system was changed to the current wildcard system.

With that in mind, it was a good idea at the time for a number of reasons, mostly with security and how browsers manage cross-domain requests. It also had the side effect of heavily reducing let’s encrypt rate limiting and allowing users to signup for services like AdSense.

However, the PSL maintainers have a strict quality control process (and rightly so). The bad-neighbor effect that inclusion to the list would help solve is also the downfall, as the maintainers are not willing to accept subdomains that have a lot of spam websites and flags within Google safe browsing. Unfortunately this probably prevents any free subdomains from getting added to the list, or at least requires a fight to get them added.

Regarding the current SSL system, it would still be possible according this 2019 post: Wildcard certificates and Public Suffix List - Issuance Policy - Let's Encrypt Community Support

I think InfinityFree should try submitting its domain to the PSL. eu.org also has a large number of spam domains, but it has been accepted into the PSL. It may or may not be approved, but there is no harm in trying and seeing what the PSL maintainers decide.

I’m curious on how much the quality control process would be an issue.

Some degree of abuse is basically guaranteed to happen for any service that provides free subdomains, and the main reason you see many reports is because there are many domains. We frequently have more subdomains on our domain than there are registered domains under the extension.

And it’s not like our abuse handling is slacking. We respond faster than most registrars, and unlike those who provide domains, we control the hosting, which gives us a lot more opportunity to monitor for abuse.

Exactly. Since InfinityFree already has active abuse handling and controls both the hosting and the subdomains, it seems like a stronger position than many providers that are already on the PSL. The only way to know whether the quality-control requirements are actually an obstacle is to submit an application. If it’s accepted, it would benefit everyone using the free domains. If it’s rejected, at least we’d have an official answer instead of assumptions.

It’s been done before (not with InfinityFree specifically, but with a service that’s pretty much exactly the same in terms of abuse and abuse handling), and rejection due to abuse was the final answer.

It’s not my choice to submit the domain or not, but my opinion based on past experience is that it is a waste of time. I agree that inclusion would be useful, but I don’t think it’s feasible

That’s understandable, but I still think it’s worth trying. InfinityFree is one of the most popular providers of both free hosting and free subdomains, and its abuse handling is active and responsive. An application would only take a little time, and even if it isn’t accepted, the response could provide valuable feedback for the future.

I’m missing one thing from this discussion. We’ve been going on about the “why not”, but so far I have not yet seen someone saying “why”. Why should we add the domain to the PSL? What benefits does it bring?

I think I’m just gonna paste this ICANN document here

Part 3 describes what uses does the PSL have

I’m familiar with the PSL in general, but it’s good to have clear what benefit it brings to websites currently using our free subdomains.

The main benefits are:

  1. Reduces the noisy neighbour effect by isolating each subdomain.
  2. Improves compatibility and acceptance with services such as Google AdSense and other platforms that use the Public Suffix List.
  3. Prevents one subdomain from setting cookies that affect other users’ subdomains.
  4. Improves security by isolating each hosted website.
  5. Reduces the impact of cross-subdomain attacks and cookie abuse.
  6. Helps browsers treat each subdomain as an independent website, following modern web security standards.
  7. And many more security, privacy, and compatibility benefits recognised across the web ecosystem.

Did you use AI for that list? I struggle to find the difference between 3, 4, 5, and 6 - they seem like the same thing just worded differently.

Which also makes 7 look weird because you really only listed 3 things. What are those other benefits?

The points were collected by me and have only been rephrased by AI

Waiting for your post.

Here is the post. Not sue what you were waiting for to be in it though.

Regarding your last reply, like @Greenreader9 said: the 7 points you listed are not actually 7 different reasons. The only specific reasons I see there are the cookie isolation for security (3 and 5), and better recognition as being a “registered” domain (2).

Points 1, 4, 6 and 7 are just wave broad terms like “security”, “isolation” and “modern web standards” without actually describing actual effects. It probably just refers to the cookie isolation again.

While the reasons are valid, they seem like a justification after the fact instead of an actual issue you ran into that you need to have resolved.

So for now, I’m going to write this down as a “nice to have”, which means it will go into the backlog, somewhere near the button. I may do this at some point, but I have no idea when that would be.