⚠️ If someone buys the
bob.fun domain, do NOT log in with Internet Identity on
bob.fun or
launch.bob.fun.
The domain expired on September 3rd and currently no longer serves the app. Both apps are still live on-chain at their native links:
bob.fun ==>
ywiuf-vaaaa-aaaal-qjumq-cai.…
launch.bob.fun ==>
z4dkz-riaaa-aaaai-acrzq-cai.…
The apps themselves are fine. The problem is the domain. Internet Identity associates your account with the app's derivation origin. The canisters currently list:
bob.fun
launch.bob.fun
as alternative origins for the same account.
So if someone else acquires the domain and puts up an identical copy, Internet Identity can legitimately let you log in there. You would be approving the login yourself, and the cloned frontend could then act as you and submit transactions.
There's also a second risk:
bob.fun sessions can remain valid for up to 30 days and are stored in the browser under the domain. A new owner could potentially reuse that session when you visit the site, without requiring another login.
What we checked on the live deployment:
Both frontends use the same derivation origin, so the same account is used across
bob.fun,
launch.bob.fun and the native links.
Both canisters currently expose the same alternative-origin list.
Sessions last up to 29 days on
bob.fun and 30 days on
launch.bob.fun
- Both frontends are controlled by dmhsm-cyaaa-aaaal-qjrdq-cai/es7op-jmunh-yjj7x-t4fpo-o3cyu-mnaj2-uzron-t4qxd-f6w6y-ra4oo-pqe, which is where the alternative-origin list can be changed.
- The registry currently shows the domain as automatically renewed, but the registrar still shows the September 3 expiration and the domain is currently parked / not serving the app. So the registry status does not mean Robert / the team has control of the domain again.
Until the domain situation is confirmed, treat
bob.fun and
launch.bob.fun as untrusted.
Use the native links above instead.
If you've previously used either domain, clear the stored site data for
bob.fun and
launch.bob.fun in your browser to remove the saved sessions.
For Robert / the team: removing the two domains from the II alternative-origins list would eliminate the login risk for future logins. Existing sessions can remain valid for up to 30 days, so clearing them still matters.
Stay safe.