Live data from Hacker News

Handshake: Decentralizing DNS to Improve the Security of the Internet

namebase.io

41–50 of 86 posts

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#41
post #32

But how does this solve the problem of Trust on First Use? Blockchains can safeguard the integrity of the data, but how do we know that painting in the real world corresponds to the token that purports to represent it? How do we know that business on Google really is that business and not a guy in their basement? How does Google or anyone really verify it, whether they are a top-down corporation or a blockchain or a…

Proof of Work solves that by preventing Sybil attacks - it's costly to mine (which is equivalent to signing off on, because it wouldn't make sense to sign an invalid block, you would get rewarded). It's the only signature scheme known to be dynamic and allow for an arbitrary participant size. The point is that you can trust the chain with the most proof of work. As long as you maintain a diverse set of peers and validate blocks, you can know the state of the network.

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#42
I find this trend of applications packing their own resolver concerning. If nothing else, it widens greatly the attack surface to name resolution. I also foresee mayhem with perimeter firewalls and stuff. It should be possible to block this at the OS level.

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#43
It still seems bizarre to me that this system lets people register arbitrary TLDs. If nothing else, sooner or later a new ICANN gTLD will conflict with a Handshake registration. At that point, Handshake will no longer be a backwards compatible extension of the existing DNS, so systems will have to choose one or the other. Maybe the Handshake authors think that when that day comes (and it's probably not that far off), Handshake will already have achieved enough popularity that operating systems and browsers will choose Handshake instead of ICANN. Somehow, I doubt it...

Imagine IPv6, but if it was somehow designed to squat on top of the IPv4 namespace, so that switching to IPv6 would cause existing addresses to start pointing somewhere else. That's pretty much the situation Handshake has chosen to be in.

Not to mention that allocating TLDs

- confuses non-technical users ("what do you mean, there's no dot in the address?")

- conflicts with the choice of most browsers to unify the address and search bar (if I type refrigerators and press enter, I want a search results page, not the homepage of whoever registered the TLD 'refrigerators')

- may conflict with other non-standard domain name systems, including special-purpose TLDs like .onion – though they've at least reserved the existing ones, so it would only be a problem for not-yet-developed systems

It's strange, because I want to support decentralized name systems, and Handshake seems better designed than some of the previous attempts, but that one decision makes it seemingly guaranteed to fail.

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#46
post #43

It still seems bizarre to me that this system lets people register arbitrary TLDs. If nothing else, sooner or later a new ICANN gTLD will conflict with a Handshake registration. At that point, Handshake will no longer be a backwards compatible extension of the existing DNS, so systems will have to choose one or the other. Maybe the Handshake authors think that when that day comes (and it's probably not that far off),…

This paragraph from the blog post doesn't completely address your comment (or even most of it), but it seems useful to have as a reference as I've almost always missed it:

> How Handshake conflicts with ICANN > All 1500 of the existing ICANN TLDs are blacklisted on Handshake for backwards-compatibility. This means that end-users resolving their DNS through Handshake can still access .com domains as normal. New ICANN TLDs can theoretically conflict with Handshake TLDs, but ICANN isn't issuing new TLDs for another few years. When ICANN does issue new TLDs, they’ll only allow at most 500 new TLDs per year. The likelihood of conflict is low even though conflicts can technically happen. In the future, it's up to the community to decide which names take precedence. We believe Handshake names will take precedence because people will find them more useful, and I’ll cover why I think Handshake can gain adoption even in the face of ICANN’s network effects in another blog post.

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#47

Earlier quoted context omitted.

There are many instances where an intolerant minority is able to get a neutral majority to adopt their will. Nassim Taleb describes this as the minority rule. It’s the same reason why all lemonade is kosher* A small minority of people NEED censorship-resistant and seizure-resistant DNS, and the bet is that they can get the majority to adopt Handshake. The key is that Handshake is backwards compatible with existing DN…

It’s true that a single static IP address is easy to block, but what is stopping an oppressive regime from building tech specifically designed to block Handshake? Correct me if I’m wrong, but Handshake still functions over IP and as such a government could potentially block all IPs associated with Handshake via similar mechanisms that are used to block a single IP. If there exists some kind of public list of all Hand…

>Handshake still functions over IP and as such a government could potentially block all IPs associated with Handshake via similar mechanisms that are used to block a single IP

Blockchains are decentralized. Sometimes a fixed set of bootstrapping nodes is used to improve user experience (rapid connection to the network when opening the app), but if these nodes are blocked it is quite easy to rotate them (and even to make it less easy for an attacker to know the identities of all nodes). A legitimate website that cannot be blocked because it has an unrelated focus can even be used as a shield (some sort of partnership).

>And DNS as it stands is fairly seizure resistant as long as you use secure passwords and the customer services folks don’t get tricked into resetting your account or something.

You do not know what you are talking about I'm afraid. The internet is censored like hell, and I am not talking about living in China or other authoritative regimes. Activists not agreeing with what you are saying try to censor you like hell these days and registrars bow under the pressure. This is not about right-wing hate speech. Just try to start a political platform about a sensitive topic and see how it goes.

Do you want to advocate to allow the marriage of young children and start a democratic discussion about it? Or do you want to host a community of consenting adults believing in a family arrangements in which the man is the lead of the woman and providing practical life advice including how to spank your wife? You'll spend your life wondering when your registrar will take your website down. And these topics really are just examples.

I have seen countless websites disappear (and forums where activists organize themselves to pressure registrars). If you confront them and put them in a corner, they admit that they are censoring just because they do not agree, but they invoke the notion of "higher social interest", and "the ends justify the means", and in essence "this is a holy war, they will be collateral damages but we need to prevent irresponsible speech" (which really is the new way to justify intolerance - a very sickening rhetoric).

For example with the example of wife spanking among consenting adults (there is not even a knowledge asymmetry between the woman and the man in these communities, the methods and psychology behind this arrangement is discussed openly, and they actually choose this lifestyle because they want the psychological outcomes - they want to program themselves at a subconscious level so to speak. This is totally consensual), I know that many people here think that only a vulnerable and exploited woman could agree with that. And I could point you to women advocating for this, and even animating YouTube channels about it - that may be taken down anytime. And this was only to provide a graphic example, but this not limited to this category of topic.

My point is that every majority begins with a minority, and like-minded people, not hating anyone and not propagating hate should be free to live freely even if they lifestyle and values are sickening for some people.

Not so long we tries to look for a registrar who not having vague TOS allowing to them to take down your website if their disagree with the content. Wording providing them large flexibility to censor. After over 1 week of research, we have only found one. But even this was actually based in a country where a legal action can easily be taken to force them to terminate service. Ironically, we then looked into Russia and we found that hosting there would be our best option if the situation gets heated, because of the politics between them and the West. When it gets to that point, you know something is wrong.

The reality is the internet is very censored. Extremely censored nowadays, but there is a lot of propaganda going on to justify this environment. People enjoy censorship until they are the ones being censored. It is like religion, people love seeing they opinion win and others be destroyed. 90% of people happily close their eyes if they opinion and interests are the ones being unfairly and oppressively favored. Handshake is solving a real and serious problem much deeper than what you and most people understand. Handshake is absolutely needed and the problem they solve is REAL, very real and very serious.

If you live a normal life, you always think that there is no problem about anything. But if you try to drive change in the world and be a thought leader, then you see things differently and you are confronted to the problems and frictions that prevented your innovation from emerging naturally without your help.

The problem faced by democracies these days is that laws are made for those voting from their sofas and "having nothing to hide". However, if there is one thing we should have learned by now (but that nobody seems to have learned) it is that laws and society can only be sound if they are focused on creating the environment that those who create democratic value, intellectual value and economic value need. Not the one that those who want to feel safe, and have everything while doing as little effort as possible want. Giving power to this type of people will always screw a society. But ignoring and oppressing them flat out as was done in the past is not good either. So we started of on the extreme right (monarchy), we moved to the extreme left (populism), so now is the time to find a middle ground. We need to have a conversation about limiting the political influence of most passive "citizens", who maybe should not be considered citizens, until they up their intellectual game. Intellectual-meritocracy-like citizenship system, that would need to be appropriately designed not to elevate one school of thought, philosophical premise or opinion as the only acceptable starting point. But this getting out of topic.

If you are interested in this conversation and want in hearing more about these ideas, and even to contribute and share your thoughts, there is a fast-growing international political movement. The mailing list is not public yet but drop me a line and I'll ask them to add you: samuel233[---at---]protonmail.com.

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#48
post #18

"Blockchain-based alternative to CAs" has been discussed before there even was the word blockchain (it was called sovereign keys, at least it's pretty close to a blockchain). I'd expect someone trying at least discussing why that didn't make it. Also I'm really annoyed by the "there was a problem with CAs in 2011, this system is really bad"-tune ignoring what has been changed since then. (E.g. the "You don’t know who…

It's actually pretty difficult to enumerate all trusted CAs (or even just what organizations are running CAs). Certificate Transparency certainly helps there, but it's not fully required, and doesn't solve all problems. The DigiNotar attack (from 2011) was mainly chosen because it's well known and easy to convey. It wasn't even that technically effectively because Chrome had Google's keys pinned, so it was immediatel…

> It's actually pretty difficult to enumerate all trusted CAs (or even just what organizations are running CAs).

Sure, but somebody else already did that so you can just rely on their work.

https://wiki.mozilla.org/CA/Intermediate_Certificates

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#49

isn't dns already decentralised? (apart form everyone basically using the same server(s) / google ?) you can just set up your own dns if you want to have your own mappings of ip->dn and vice versa. just set your dns to the server you prefer?

The root DNS servers are distributed widely and operated by different organizations.

But it’s a single root, and it is administered by ICANN directly who decide who can be a root name operator. So there is central control there.

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#50
post #46
post #43

It still seems bizarre to me that this system lets people register arbitrary TLDs. If nothing else, sooner or later a new ICANN gTLD will conflict with a Handshake registration. At that point, Handshake will no longer be a backwards compatible extension of the existing DNS, so systems will have to choose one or the other. Maybe the Handshake authors think that when that day comes (and it's probably not that far off),…

This paragraph from the blog post doesn't completely address your comment (or even most of it), but it seems useful to have as a reference as I've almost always missed it: > How Handshake conflicts with ICANN > All 1500 of the existing ICANN TLDs are blacklisted on Handshake for backwards-compatibility. This means that end-users resolving their DNS through Handshake can still access .com domains as normal. New ICANN…

> When ICANN does issue new TLDs, they’ll only allow at most 500 new TLDs per year. The likelihood of conflict is low even though conflicts can technically happen.

Oh, "only" 500? Out of which a substantial fraction will be common words and therefore likely to be squatted on if Handshake is even remotely popular? I wondered if Handshake was at least trying to reserve English words, but apparently not, judging by this:

    Names which were added _after_ the final snapshot:

    - `charity` - A new gTLD added on ICANN's system.
    - `inc` - A new gTLD added on ICANN's system.
- https://github.com/handshake-org/hs-names/blob/master/README...

Please tell me there's something I'm missing...

Post reply on HN