Live data from Hacker News

Handshake: Decentralizing DNS to Improve the Security of the Internet

namebase.io

51–60 of 86 posts

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#51

I find this trend of applications packing their own resolver concerning. If nothing else, it widens greatly the attack surface to name resolution. I also foresee mayhem with perimeter firewalls and stuff. It should be possible to block this at the OS level.

Mainstream OSs are slow to evolve. While I agree that embedded DNS resolvers in browsers and the like should have an off switch, I think embedding in widely adopted software is the only solution to push adoption of these new privacy-focused protocols.

Pushing updates to ever-green browsers is the key to change how millions of people use their computer - since browsing the web is almost all they do!

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#54
post #43

It still seems bizarre to me that this system lets people register arbitrary TLDs. If nothing else, sooner or later a new ICANN gTLD will conflict with a Handshake registration. At that point, Handshake will no longer be a backwards compatible extension of the existing DNS, so systems will have to choose one or the other. Maybe the Handshake authors think that when that day comes (and it's probably not that far off),…

Its just one example of the entire governance problem thats conspicuously absent from the post. How is dispute resolution handled? Identity verification? Attestation?

Reasonable answers to those questions are generally counter to the raison d’etre of setups like this. And without it you have a spam and scam goldrush to squat the most “valuable” entries and pretty big gap in _human_ trust in the system.

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#55
post #43

It still seems bizarre to me that this system lets people register arbitrary TLDs. If nothing else, sooner or later a new ICANN gTLD will conflict with a Handshake registration. At that point, Handshake will no longer be a backwards compatible extension of the existing DNS, so systems will have to choose one or the other. Maybe the Handshake authors think that when that day comes (and it's probably not that far off),…

> I want to support decentralized name systems

This isn't a coherent thought, which illustrates why they fail. A name _system_ is something you have exactly _one_ of, because otherwise they conflict. To support more than one is to give up altogether, it might actually be slightly worse than just not caring at all.

So you'd need to pick one and then, even if clearly better alternatives are subsequently proposed, you _must_ stick by your choice or you destroy the value of choosing at all. That's clearly a bad idea, you're more or less guaranteeing a sub-optimal outcome for yourself.

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#56

Earlier quoted context omitted.

There are many instances where an intolerant minority is able to get a neutral majority to adopt their will. Nassim Taleb describes this as the minority rule. It’s the same reason why all lemonade is kosher* A small minority of people NEED censorship-resistant and seizure-resistant DNS, and the bet is that they can get the majority to adopt Handshake. The key is that Handshake is backwards compatible with existing DN…

It’s true that a single static IP address is easy to block, but what is stopping an oppressive regime from building tech specifically designed to block Handshake? Correct me if I’m wrong, but Handshake still functions over IP and as such a government could potentially block all IPs associated with Handshake via similar mechanisms that are used to block a single IP. If there exists some kind of public list of all Hand…

As far as I can see, I could run a Handshake recursive resolver myself, either for my own internal network, or I could publicise it.

It's not clear to me how a third party could verify that my resolver was returning answers based on blockchain data, though. I suppose the blockchain could be contrived to return DNSSEC signatures, which could in turn be sent by the resolver; so if you trust the blockchain root's DNSSEC signature, then you can trust an arbitrary resolver. But the article didn't mention DNSSEC, or how you establish trust in an arbitrary resolver.

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#57
Handshake is a blockchain protocol that aims to solve the issue of trusting hundreds of CAs. It's a protocol that's similar to Bitcoin, except instead of using coins as money, you use Handshake coins to register names on the Handshake blockchain. These names are top-level domains (TLDs) like .com, .org, .net. Handshake decentralizes the root zone file, which is the ICANN-controlled file that determines who owns what TLD. Anyone can register their own TLD on the Handshake blockchain.

We need some form of DNS decentralization not only for security but also to improve availability.

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#58
post #43

It still seems bizarre to me that this system lets people register arbitrary TLDs. If nothing else, sooner or later a new ICANN gTLD will conflict with a Handshake registration. At that point, Handshake will no longer be a backwards compatible extension of the existing DNS, so systems will have to choose one or the other. Maybe the Handshake authors think that when that day comes (and it's probably not that far off),…

Its just one example of the entire governance problem thats conspicuously absent from the post. How is dispute resolution handled? Identity verification? Attestation? Reasonable answers to those questions are generally counter to the raison d’etre of setups like this. And without it you have a spam and scam goldrush to squat the most “valuable” entries and pretty big gap in _human_ trust in the system.

What inherently requires an identity to register a domain name?

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#59
post #18

"Blockchain-based alternative to CAs" has been discussed before there even was the word blockchain (it was called sovereign keys, at least it's pretty close to a blockchain). I'd expect someone trying at least discussing why that didn't make it. Also I'm really annoyed by the "there was a problem with CAs in 2011, this system is really bad"-tune ignoring what has been changed since then. (E.g. the "You don’t know who…

Author of the post here. My aim was to keep this post focused and cover the differences between Handshake and previous blockchain DNS attempts in a separate post. The keyword here is attempts: previous projects like Namecoin and ENS haven't really taken off. I think the reason has to do with the underlying technology and the go-to-market strategy (or lack thereof) of the projects. On the technology front, Handshake i…

I haven't looked into this yet, but one question I always ask for new blockchains is: Why use your own blockchain? Security is expensive, and it's trivial to 51% attack new chains with minimal hash power. This would make sense if you were using a shared security model (i.e. building on Ethereum). That being said, what kind of consensus algorithm are you using?

Re: Handshake: Decentralizing DNS to Improve the Security of the Internet

#60
post #53

> Verify Your Identity to buy/sell Are there any ways to acquire HNS without sending a photo ID to a centralized party?

In order to comply with US laws we need to verify people’s identity before they can buy/sell HNS, but fortunately it will be possible to register names without identify verification.
Post reply on HN