Live data from Hacker News

Decentralized Naming and Certificate Authority

handshake.org

61–70 of 128 posts

Re: Decentralized Naming and Certificate Authority

#61
This is a great idea with one easily correctable but nonetheless fatal flaw: it's an all-or-nothing preposition. If users choose to use Handshake as their DNS roots, they will no longer be able to access websites which only exist on ICANN's root zone.

Assuming I'm not mistaken and that really is how Handshake is set up (someone please correct me if I'm wrong), then IMO the whole project is essentially dead on arrival. There's no chance they're going to be able to convince millions of large websites to register on a new DNS root overnight. And even if they did somehow managed to convince 80% of websites move to the new system, users _still_ wouldn't switch over because doing so would effectively break 20% of the internet for them.

It's a real shame, because this problem would be trivially avoidable if they simply allowed the existing TLDs use the ICANN roots and confined Handshake domains to their own TLD (.handshake maybe). That way, adoption could happen slowly over time and users could switch over to the Handshake roots with no downsides. As-is though this is simply unworkable.

Re: Decentralized Naming and Certificate Authority

#62
post #61

This is a great idea with one easily correctable but nonetheless fatal flaw: it's an all-or-nothing preposition. If users choose to use Handshake as their DNS roots, they will no longer be able to access websites which only exist on ICANN's root zone. Assuming I'm not mistaken and that really is how Handshake is set up (someone please correct me if I'm wrong), then IMO the whole project is essentially dead on arrival…

> If users choose to use Handshake as their DNS roots, they will no longer be able to access websites which only exist on ICANN's root zone.

This is not true. You can setup Handshake to be your resolver, and it will resolve both domains on handshake, and legacy domains from icann.

Re: Decentralized Naming and Certificate Authority

#63
post #60

Went through the FAQ's, but still didn't understood much about how this is supposed to work alongside ICANN/current DNS system. Well, I didn't got Bitcoin the first 2 times either. 1. "Browsing the web with human readable names is what Internet users have gotten acclimated to." => give me an example of a "handshake" domain name in this case 2. I have some domains/sites not so popular (not in the first 100k Alexa doma…

Own answer to 2: So all existing TLDs are by default "pre-reserved".

Secondly, the 100k top Alexa sites refers to the inability to register a ".whatever" if that "whatever.some_tld" is in top 100k Alexa. So, basically this is "pre-reserving" "gTLD".

In my first impression, these 2 things were somehow correlated.

Re: Decentralized Naming and Certificate Authority

#64

First impression: Great another ICO. Second impression: Not a wildly outlandish idea but im not sure if it's a good idea either. Decentralized and automated registrar with a concept of renewals. Nifty. I'm not really sure how the economics here work out.. Could I scoop up a few million names early on and then hold them forever? Has that already happened? Could this enable anonymous registration? Would these things ma…

Handshake didn't do an ICO. They raised $10.2m from institutional investors like A16Z, Sequoia, Greylock, and Founders Fund, and then donated all the money they raised to non-profits and open-source projects. Here's a notice from the free software foundation when they received $1m from Handshake https://www.fsf.org/news/free-software-foundation-receives-1...

Another:

> Handshake donates $300,000 USD to Debian [0]

[0]: https://www.debian.org/News/2019/20190329

Re: Decentralized Naming and Certificate Authority

#65

Earlier quoted context omitted.

- Names are released over the course of 52 weeks. Determined by hash(name) % 52. So at worst the name you want to register will not be available until ~51 weeks from now (Handshake launched last week!). - Names have to be renewed bi-annually. You don't need to pay a fee, you just need to submit a transaction to prove you still have access to the private key. I don't think this will be any different than the existing…

If I'm understanding you, the 52 week release is a one time thing, not a continual thing? So it's not that names will be continually trickle-released it's that for the next 52 (51) weeks, they'll be trickle-released, and then everything will be out there and this will work just like normal domain registration? I was under the impression that the trickle release was just how registration would work in general. That do…

Additionally to combat squatting, to register a name, one needs to go thru a Vickrey auction and bid on a name after it is released. Bidding continues for about 5 days thereafter and there are 10 days to reveal the bids.

The winner pays the second highest bid.

Re: Decentralized Naming and Certificate Authority

#66
post #61

This is a great idea with one easily correctable but nonetheless fatal flaw: it's an all-or-nothing preposition. If users choose to use Handshake as their DNS roots, they will no longer be able to access websites which only exist on ICANN's root zone. Assuming I'm not mistaken and that really is how Handshake is set up (someone please correct me if I'm wrong), then IMO the whole project is essentially dead on arrival…

In blockchains, there is a difference between consensus and policy. The way that the Handshake recursive resolver works is not based on consensus. This means that people can insert rules for delegating a particular request to ICANN or to the Handshake authoritative resolver. It currently checks the Handshake authoritative resolver first, then falls back to ICANN.

If this behavior is easily configurable/shared and open source, then people can opt into whatever configuration that best suites their needs.

Re: Decentralized Naming and Certificate Authority

#67
post #62
post #61

This is a great idea with one easily correctable but nonetheless fatal flaw: it's an all-or-nothing preposition. If users choose to use Handshake as their DNS roots, they will no longer be able to access websites which only exist on ICANN's root zone. Assuming I'm not mistaken and that really is how Handshake is set up (someone please correct me if I'm wrong), then IMO the whole project is essentially dead on arrival…

> If users choose to use Handshake as their DNS roots, they will no longer be able to access websites which only exist on ICANN's root zone. This is not true. You can setup Handshake to be your resolver, and it will resolve both domains on handshake, and legacy domains from icann.

Then what's this paragraph in the FAQ about?

> Existing TLDs and over 100,000 Alexa websites are reserved on the Handshake blockchain. Upon removing collisions, generic, and exclusions (e.g. 1 or 2 character names), approximately 80,000 names remain. Using the root key and DNSSEC, domain owners can cryptographically prove ownership to the Handshake blockchain to claim names.

Does Handshake control existing (`.com`, `.org`, etc.) domain names or don't they? If they do, then what happens when a DNS entry in Handshake's roots contradicts what's in the ICANN roots? If Handshake wins conflicts, then that breaks the internet for existing users.

Re: Decentralized Naming and Certificate Authority

#68
post #42

> mail became Gmail, usenet became reddit, blog replies became facebook and Medium, pingbacks became twitter, squid became Cloudflare, even gnutella became The Pirate Bay. Centralization exists because there is a need to manage spam, griefing, and sockpuppet/sybil attacks. No, centralization exists because users don't care about the protocol. Users care about the brand. It's way easier to use FB than it is to say "ch…

> No, centralization exists because users don't care about the protocol. Users care about the brand.

Brand is a proxy for the level of functionality delivered by that brand.

People didn't switch to GMail because it was a "cool" brand, they switched because the spam filtering worked, Google gives you a ton of free space (a problem at the time), and it didn't have obtrusive banner ads. This was passed on by word of mouth, and now GMail is popular.

> It's way easier to use FB than it is to say "choose your hosting provider. Each one has a slightly different set of features. Then link with other people you care about, all of whom may be using different providers that you need to pay special attention to." With FB, I click "send a friend request" and then move on with my day. And that's just one example.

Exactly my point, the UX is better and the network effect ensures that many/most of your friends are already there. It's not about branding, it's about ease of use.

Re: Decentralized Naming and Certificate Authority

#69

First impression: Great another ICO. Second impression: Not a wildly outlandish idea but im not sure if it's a good idea either. Decentralized and automated registrar with a concept of renewals. Nifty. I'm not really sure how the economics here work out.. Could I scoop up a few million names early on and then hold them forever? Has that already happened? Could this enable anonymous registration? Would these things ma…

Anyone participating in the GooSig airdrop [1] can technically register names anonymously as their keys will not be exposed in terms of having received the coins.

Additionally, anyone who can obtain HNS anonymously can thus register anonymously.

[1] https://github.com/handshake-org/goosig

Re: Decentralized Naming and Certificate Authority

#70
post #60

Went through the FAQ's, but still didn't understood much about how this is supposed to work alongside ICANN/current DNS system. Well, I didn't got Bitcoin the first 2 times either. 1. "Browsing the web with human readable names is what Internet users have gotten acclimated to." => give me an example of a "handshake" domain name in this case 2. I have some domains/sites not so popular (not in the first 100k Alexa doma…

> I have some domains/sites not so popular (not in the first 100k Alexa domains). I will only hear about "Handshake" in 5 years time when Handshake completely replaced what we are using today, by which time, someone else might have "registered my domain names". What do I do? Obviously I can prove I own my .com/.net.

This is one part that Handshake does not explain very well. The existing domains and tlds that icann owns will continue to work moving forward. The top 100k Alexa domains bit works like this:

For the top 100k alexa domains, the owner receives the root of the domain as a domain in Handshake (ex: the owner of `example.com` receives the domain `example` in Handshake). All `*.com`, etc domains continue to operate as they have in the past.

Post reply on HN