Live data from Hacker News

Decentralized Naming and Certificate Authority

handshake.org

101–110 of 128 posts

Re: Decentralized Naming and Certificate Authority

#101

Earlier quoted context omitted.

The auctions are semi-blind. You bid, and can optionally add a blind to your bid. The network sees your combined total bid + blind, but won't know your true bid value until the reveal period. So if you want to guarantee you win an auction, just make sure your bid is greater than the highest existing total.

> if you want to guarantee you win an auction, just make sure your bid is greater than the highest existing total. How do I do that if other people's bids can contain blinds? How do I know what the highest existing total is -- I still have to guess everyone else's total, right? And even if the auction wasn't partially sealed, even if it was completely public -- I don't see how my concerns above would go away. Isn't i…

> How do I do that if other people's bids can contain blinds?

You're right, you can't. I'm not sure what "just make sure your bid is greater than the highest existing total" means when blinds are in the mix.

> If I'm China and I want to censor this system, what stops me from monitoring the auctions and throwing a measly $2000 at any domain name that sounds critical of me in any way?

Nothing, but there are quite a few(TM) domain names. Everything that isn't an ICANN TLD (or a future ICANN TLD, I guess--not sure how that would work) is available. I don't think a government could reliably censor all objectionable TLD's.

Furthermore, once you own a Handshake TLD, you become the registrar for that TLD. So every subdomain is yours to sell, no auction necessary. So as long as someone purchases some simple TLD and is willing to sell you some relevant subdomain, you're good. It's not really necessary to have censorthis/; you can just buy censorthis.sometld. Of course, then you do depend on the owner of sometld as a registrar, but that's not very significant given the space of TLD's available. It wouldn't be difficult to find a new registrar if something happened.

Re: Decentralized Naming and Certificate Authority

#103

PSA if you had over 15 followers on GitHub by August 2018 you were likely included in the Handshake airdrop. Basically they developed a way to give each dev in the airdrop 4662 coins each (worth a lot since current market price is $0.50[1]). These instructions walk through what the claiming process is like, which can only be done after block 2016 in a day or so https://namebase.io/airdrop . [1] https://namebase.io

I hope it updates the ssh keys, because I’m pretty sure I roll mine every couple of years.

Re: Decentralized Naming and Certificate Authority

#104
post #70
post #60

Went through the FAQ's, but still didn't understood much about how this is supposed to work alongside ICANN/current DNS system. Well, I didn't got Bitcoin the first 2 times either. 1. "Browsing the web with human readable names is what Internet users have gotten acclimated to." => give me an example of a "handshake" domain name in this case 2. I have some domains/sites not so popular (not in the first 100k Alexa doma…

> I have some domains/sites not so popular (not in the first 100k Alexa domains). I will only hear about "Handshake" in 5 years time when Handshake completely replaced what we are using today, by which time, someone else might have "registered my domain names". What do I do? Obviously I can prove I own my .com/.net. This is one part that Handshake does not explain very well. The existing domains and tlds that icann o…

What happens if someone gets “amazing/“ and then I pay icann to get .amazing?

Re: Decentralized Naming and Certificate Authority

#105

Earlier quoted context omitted.

The auctions are semi-blind. You bid, and can optionally add a blind to your bid. The network sees your combined total bid + blind, but won't know your true bid value until the reveal period. So if you want to guarantee you win an auction, just make sure your bid is greater than the highest existing total.

> if you want to guarantee you win an auction, just make sure your bid is greater than the highest existing total. How do I do that if other people's bids can contain blinds? How do I know what the highest existing total is -- I still have to guess everyone else's total, right? And even if the auction wasn't partially sealed, even if it was completely public -- I don't see how my concerns above would go away. Isn't i…

> Don't I still need to wait 5 days to do something that I can do today in less than an hour?

It takes months to years to get a tld today with a 185k deposit and no guarantee you'll actually get through the process [1].

[1] https://newgtlds.icann.org/en/applicants/global-support/faqs...

Re: Decentralized Naming and Certificate Authority

#106

PSA if you had over 15 followers on GitHub by August 2018 you were likely included in the Handshake airdrop. Basically they developed a way to give each dev in the airdrop 4662 coins each (worth a lot since current market price is $0.50[1]). These instructions walk through what the claiming process is like, which can only be done after block 2016 in a day or so https://namebase.io/airdrop . [1] https://namebase.io

I hope it updates the ssh keys, because I’m pretty sure I roll mine every couple of years.

It doesn't update with SSH keys because the tree is static, but it was updated within a few months ago, so if you claim now (in 1-2 days when claiming is enabled on the mainnet) it should work with your existing keys.

Re: Decentralized Naming and Certificate Authority

#107

First impression: Great another ICO. Second impression: Not a wildly outlandish idea but im not sure if it's a good idea either. Decentralized and automated registrar with a concept of renewals. Nifty. I'm not really sure how the economics here work out.. Could I scoop up a few million names early on and then hold them forever? Has that already happened? Could this enable anonymous registration? Would these things ma…

The project raised $10M and then gave 100% of it away to open source projects. They receive some HNS tokens in return. There is a massive airdrop of coins to hundreds of thousands of guthub users, spreading out the money supply to people who might be the most interested in using the system. In other words, this is the least ICO-y new blockchain in a decade. Names roll out over 52 weeks: HashName(name) % 52 = week num…

Well. That's a nice publicity stunt. lets see how they get their investment back. It's nice that this project does some good. https://github.com/handshake-org/hsd/blob/56c83ca7344def512e...

So if I read this right

Creators get: 102mi coins

Sponsors get: 102mi coins

they are airdropping about 952mi coins to users on github to the tune of 4,246 per user.

So they're collecting about 20% of all coins initially dropped. That's slightly more then some. And at the value listed on https://www.namebase.io/ that adds up to some 102,000,000 * $0.44 = $44mi.

Ok, so it's not an ICO exactly, instead they raised VC funds which is expecting a return by selling coins.

I've just spent a few minutes looking through the website, docs, and a little code. And I have no idea how an end user will use these names. Everything polished about it is for trading coins not real world usage. Sounds like every other crypto coin.

Re: Decentralized Naming and Certificate Authority

#108

Earlier quoted context omitted.

> People didn't switch to GMail because it was a "cool" brand In the early days of gmail when you needed an invite code, it definitely was a status symbol to have that @gmail.com on your email address. And at the time, the actual functionality of gmail was far less significant than the fact it was free and decoupled from your internet provider, although you're right the storage capacity on a free email was unheard of…

> And at the time, the actual functionality of gmail was far less significant than the fact it was free and decoupled from your internet provider If that was the real draw, then people would have just stuck with Hotmail, Yahoo, and the dozen other e-mail providers.

Hotmail and to a lesser extent Yahoo were perceived as toxic, due to spam mostly. There is still a website I frequent which requests customers email to be 'preferably not a @hotmail.com address'. All the other email providers were either restricted (companies, universities, clubs/guilds etc.), poorly run, or tied you to fees (ISP provided, paid email providers, AOL).

Re: Decentralized Naming and Certificate Authority

#109
post #101

Earlier quoted context omitted.

> if you want to guarantee you win an auction, just make sure your bid is greater than the highest existing total. How do I do that if other people's bids can contain blinds? How do I know what the highest existing total is -- I still have to guess everyone else's total, right? And even if the auction wasn't partially sealed, even if it was completely public -- I don't see how my concerns above would go away. Isn't i…

> How do I do that if other people's bids can contain blinds? You're right, you can't. I'm not sure what "just make sure your bid is greater than the highest existing total" means when blinds are in the mix. > If I'm China and I want to censor this system, what stops me from monitoring the auctions and throwing a measly $2000 at any domain name that sounds critical of me in any way? Nothing, but there are quite a few…

> Nothing, but there are quite a few(TM) domain names. Everything that isn't an ICANN TLD (or a future ICANN TLD, I guess--not sure how that would work) is available. I don't think a government could reliably censor all objectionable TLD's.

If I understand correctly (and maybe I don't), the domain being auctioned is public. With the current system, a government can't censor everything because doing so would require them to pre-emptively grab the entire space, which is economically infeasible. With public auctions, my understanding is they only need to pay attention to the domains someone actually tries to register. So if I'm China, I don't need to preemptively register the entire space of `/tiananmen/g`. I only need to download the list of auctions every day and run a regex on that finite space.

Of course, they can't restrict subdomains, so maybe that allows people to sneak stealth TLDs through without getting censored. But (see below) it seems like actually owning TLDs is really important, so I still need to navigate a space where every troll and every government and every fortune 500 company is given the opportunity to snipe every TLD I want, and it seems like that's at least an opportunity for wild price increases on TLDs.

> Of course, then you do depend on the owner of sometld as a registrar, but that's not very significant given the space of TLD's available. It wouldn't be difficult to find a new registrar if something happened.

Can you expand on this?

Right now, if I lose a .com domain, I can find a new registrar and set up a different domain. But all of the links to my current domain will be broken, and if I'm using that domain for email I'll have lost control of all the emails being sent there, and I'll basically be starting over from scratch.

Part of the reason I've avoided "novelty" TLDs like `.tech`, `.party`, `.amazon`, etc... in the current system is because many of them are completely privatized. The owners of those TLDs can raise prices however they want, and can kick anyone off for any reason. And if I'm tying my entire business or (even worse) my entire online identity to one of those domains, that would catastrophic.

If a registrar behind a top level Handshake domain goes bad, is there a mechanism where I can switch registrars and keep myself as a subdomain of the original TLD? If not, won't I be in the same position?

The thing that's attractive to me about Handshake is owning TLDs -- being able to own something that can't be arbitrarily taken away from me by a centralized authority. Otherwise I haven't gained anything as a user over the current system, I've just lost any regulatory price caps that might exist.

----

I guess I can register an innocuous TLD like `danshumway`, hope the trolls don't notice and outbid me, and then use it as a private TLD I control. Realistically, to preserve privacy and avoid linking everything I do together under a single identity, I'll likely want at least 4 or 5 TLDs, possibly more. I don't think I'm atypical there. Anyone who's using a domain for their email or an identity server will want to own that TLD. Is the system designed to scale to that?

Direct question to the people behind Handshake: what do you expect the average cost of a generic 2-3 word TLD to be? A while ago I registered the domain `animalsareignorant.com` for a personal art project I'm still working on. It costs $10 a year. Are we expecting a TLD like `animalsareignorant` to cost $100? $1000? A million? I assume you've done market research on this and you're not just jumping in blind.

This isn't a theoretical question. When (at this point, if) I ever start using Handshake, at some point I'm going to register a TLD and you're going to ask me how much I want to bid for that domain. So if you expect people like me to be able to guess on the spot what the market value of a TLD is, you need to be able to point to some kind of measure that will keep that guess from being a purely blind shot in the dark.

Re: Decentralized Naming and Certificate Authority

#110

Earlier quoted context omitted.

> if you want to guarantee you win an auction, just make sure your bid is greater than the highest existing total. How do I do that if other people's bids can contain blinds? How do I know what the highest existing total is -- I still have to guess everyone else's total, right? And even if the auction wasn't partially sealed, even if it was completely public -- I don't see how my concerns above would go away. Isn't i…

> Don't I still need to wait 5 days to do something that I can do today in less than an hour? It takes months to years to get a tld today with a 185k deposit and no guarantee you'll actually get through the process [1]. [1] https://newgtlds.icann.org/en/applicants/global-support/faqs...

Sure, but owning my own TLD is the only value proposition I see in Handshake. If only big companies can register TLDs, and if I end up renting subdomains from another registrar, what is the benefit to me that the TLD system is decentralized?

I can already rent `.com` subdomains today, and they have price caps. The worst case scenario for a `.com` domain right now is that the current ICANN proposal goes through and the cost jumps up to maybe $20 a year. That's nothing compared to the rent-seeking that can happen on a purely privatized TLD with no oversight.

As a user, buying a subdomain controlled by a single source is not decentralization. I'll still have a single company that can do anything it wants to my domain, and by extension, anything it wants to my online identity. It'll still be trivial for governments to pressure that company into transferring my domain. I won't get to manage my own keys or set up my own security. I won't be able to renew the domain for free.

Unless I'm missing something really big, the only benefit I see from Handshake is democratizing TLDs for ordinary, everyday people.

Post reply on HN