Live data from Hacker News

Decentralized Naming and Certificate Authority

handshake.org

71–80 of 128 posts

Re: Decentralized Naming and Certificate Authority

#71
post #59

Earlier quoted context omitted.

All the existing TLDs like .com and .net are blacklisted so that only the TLD owners can register them. The claiming process for blacklisted TLDs uses DNSSEC so there are no third parties involved in the process. In addition, the top 100k Alexa domains are pre-registered so that only the domain owners can register those domains as TLDs (only google.com can register .google). That is done through DNSSEC as well.

This is useful info and should really, really be in the FAQ. Like, right at the top, because I don't think it's clear right now at all what happens to regular domain holders using them for email, their own services, intranets and so forth. If those in the current registrar system have a reliable path to transition/try it out at some point that's a good start. Edit to add: your namebase.io FAQ seems a lot more useful…

> This is useful info and should really, really be in the FAQ. Like, right at the top, because I don't think it's clear right now at all what happens to regular domain holders using them for email, their own services, intranets and so forth. If those in the current registrar system have a reliable path to transition/try it out at some point that's a good start.

Seconding this. I did not pick up on that at all.

Re: Decentralized Naming and Certificate Authority

#72

This has been tried. It's called Namecoin and it failed to get much traction. I suspect that using Bitcoin instead would improve adoption dramatically instead of creating yet another token. This can be done using sidechains or something similar.

Handshake is very different than Namecoin. Its possible to come to this conclusion by doing any amount of research. Please consider thinking before speaking in tribalism. There is no good trustless sidechain technology. Sovereign names can exist in parallel to sovereign money and both can benefit from each other.

Also HNS is a coin, not a token.

Re: Decentralized Naming and Certificate Authority

#73
post #66
post #61

This is a great idea with one easily correctable but nonetheless fatal flaw: it's an all-or-nothing preposition. If users choose to use Handshake as their DNS roots, they will no longer be able to access websites which only exist on ICANN's root zone. Assuming I'm not mistaken and that really is how Handshake is set up (someone please correct me if I'm wrong), then IMO the whole project is essentially dead on arrival…

In blockchains, there is a difference between consensus and policy. The way that the Handshake recursive resolver works is not based on consensus. This means that people can insert rules for delegating a particular request to ICANN or to the Handshake authoritative resolver. It currently checks the Handshake authoritative resolver first, then falls back to ICANN. If this behavior is easily configurable/shared and ope…

Awesome, that's good to hear! Sounds like a pretty easy fix then. Users just need to configure the recursive DNS resolver to delegate existing TLDs to ICANN and that fixes the compatibility issue. I might actually give that a try at some point.

Re: Decentralized Naming and Certificate Authority

#74
post #67
post #62

Earlier quoted context omitted.

> If users choose to use Handshake as their DNS roots, they will no longer be able to access websites which only exist on ICANN's root zone. This is not true. You can setup Handshake to be your resolver, and it will resolve both domains on handshake, and legacy domains from icann.

Then what's this paragraph in the FAQ about? > Existing TLDs and over 100,000 Alexa websites are reserved on the Handshake blockchain. Upon removing collisions, generic, and exclusions (e.g. 1 or 2 character names), approximately 80,000 names remain. Using the root key and DNSSEC, domain owners can cryptographically prove ownership to the Handshake blockchain to claim names. Does Handshake control existing (`.com`, `…

I have a longer answer here [0], but in short, Handshake does not control existing domain names. They are giving the top 100k existing domain name owners control of a gtld based on the domain they own. Ex `example.com` receives `example` in Handshake's system.

[0] https://news.ycombinator.com/item?id=22312059

Re: Decentralized Naming and Certificate Authority

#75

I know the handshake devs/maintainers are active on here. I've heard explanations from y'all about how handshake tries to solve the squatter problem. As far as I understand those explanations: - Names are released at a trickle, meaning no one can buy all of them in one go. - Names have to be constantly renewed (it's not a buy-once-keep-forever scheme), and (correct me if I'm wrong), you can't buy 10 years out in adva…

- Names are released over the course of 52 weeks. Determined by hash(name) % 52. So at worst the name you want to register will not be available until ~51 weeks from now (Handshake launched last week!). - Names have to be renewed bi-annually. You don't need to pay a fee, you just need to submit a transaction to prove you still have access to the private key. I don't think this will be any different than the existing…

>- Names are released over the course of 52 weeks. Determined by hash(name) % 52. So at worst the name you want to register will not be available until ~51 weeks from now (Handshake launched last week!).

Can you clarify on what "names" means here? Common names, dictionary, every single name that exists in current DNS? If someone has a unique non-word domain right now do they have to submit that? Wait a year?

>- Names have to be renewed bi-annually. You don't need to pay a fee, you just need to submit a transaction to prove you still have access to the private key. I don't think this will be any different than the existing DNS in terms of link rot.

That sounds decent on the face of it but it depends on how automated that can be made, what the window is like, etc. Right now I can renew every 10 years, or do so for 10 years and add on more time every year so that if I ever forget or have trouble once I still have a huge window, and have automated billing/warnings etc. Not free, but pretty reliable. If namebase.io or the like are needed to handle this by most users I also don't see how decentralized that can actually end up being though I guess the infrastructure can help. How are transfers to different registrars handled?

Re: Decentralized Naming and Certificate Authority

#76
post #74
post #67

Earlier quoted context omitted.

Then what's this paragraph in the FAQ about? > Existing TLDs and over 100,000 Alexa websites are reserved on the Handshake blockchain. Upon removing collisions, generic, and exclusions (e.g. 1 or 2 character names), approximately 80,000 names remain. Using the root key and DNSSEC, domain owners can cryptographically prove ownership to the Handshake blockchain to claim names. Does Handshake control existing (`.com`, `…

I have a longer answer here [0], but in short, Handshake does not control existing domain names. They are giving the top 100k existing domain name owners control of a gtld based on the domain they own. Ex `example.com` receives `example` in Handshake's system. [0] https://news.ycombinator.com/item?id=22312059

Okay, that's much better. Thanks for the clarification. I assume "com", "org", "net", "ninja", etc are also reserved then?

Re: Decentralized Naming and Certificate Authority

#77
post #42

> mail became Gmail, usenet became reddit, blog replies became facebook and Medium, pingbacks became twitter, squid became Cloudflare, even gnutella became The Pirate Bay. Centralization exists because there is a need to manage spam, griefing, and sockpuppet/sybil attacks. No, centralization exists because users don't care about the protocol. Users care about the brand. It's way easier to use FB than it is to say "ch…

> No, centralization exists because users don't care about the protocol. Users care about the brand. Brand is a proxy for the level of functionality delivered by that brand. People didn't switch to GMail because it was a "cool" brand, they switched because the spam filtering worked, Google gives you a ton of free space (a problem at the time), and it didn't have obtrusive banner ads. This was passed on by word of mou…

> People didn't switch to GMail because it was a "cool" brand

In the early days of gmail when you needed an invite code, it definitely was a status symbol to have that @gmail.com on your email address.

And at the time, the actual functionality of gmail was far less significant than the fact it was free and decoupled from your internet provider, although you're right the storage capacity on a free email was unheard of at the time.

Re: Decentralized Naming and Certificate Authority

#78
post #76
post #74

Earlier quoted context omitted.

I have a longer answer here [0], but in short, Handshake does not control existing domain names. They are giving the top 100k existing domain name owners control of a gtld based on the domain they own. Ex `example.com` receives `example` in Handshake's system. [0] https://news.ycombinator.com/item?id=22312059

Okay, that's much better. Thanks for the clarification. I assume "com", "org", "net", "ninja", etc are also reserved then?

Yes, they are. The list can be found here: https://raw.githubusercontent.com/handshake-org/hsd/1c2d1036...

Re: Decentralized Naming and Certificate Authority

#79

Earlier quoted context omitted.

> No, centralization exists because users don't care about the protocol. Users care about the brand. Brand is a proxy for the level of functionality delivered by that brand. People didn't switch to GMail because it was a "cool" brand, they switched because the spam filtering worked, Google gives you a ton of free space (a problem at the time), and it didn't have obtrusive banner ads. This was passed on by word of mou…

> People didn't switch to GMail because it was a "cool" brand In the early days of gmail when you needed an invite code, it definitely was a status symbol to have that @gmail.com on your email address. And at the time, the actual functionality of gmail was far less significant than the fact it was free and decoupled from your internet provider, although you're right the storage capacity on a free email was unheard of…

Gmail invites were at some point a joke. Everyone had them and I wouldn't be able to give them out quickly enough. Maybe at the very beginning they were exclusive a bit, but soon anyone interested could post online and get an invite in minutes.

Re: Decentralized Naming and Certificate Authority

#80

Earlier quoted context omitted.

> No, centralization exists because users don't care about the protocol. Users care about the brand. Brand is a proxy for the level of functionality delivered by that brand. People didn't switch to GMail because it was a "cool" brand, they switched because the spam filtering worked, Google gives you a ton of free space (a problem at the time), and it didn't have obtrusive banner ads. This was passed on by word of mou…

> People didn't switch to GMail because it was a "cool" brand In the early days of gmail when you needed an invite code, it definitely was a status symbol to have that @gmail.com on your email address. And at the time, the actual functionality of gmail was far less significant than the fact it was free and decoupled from your internet provider, although you're right the storage capacity on a free email was unheard of…

> And at the time, the actual functionality of gmail was far less significant than the fact it was free and decoupled from your internet provider

If that was the real draw, then people would have just stuck with Hotmail, Yahoo, and the dozen other e-mail providers.

Post reply on HN