Earlier quoted context omitted.
This appears to be just another commercialisation of domain names, trying to create another "Gold Rush" for the most sought after "vanity" names. Winner-take-all. A few profit at the expense of the many. It perpetuates that problem of ICANN DNS becoming a "business" instead of solving it. (ICANN DNS domain names were originally free.) The potential for censorship is only one problem of ICANN DNS. Also, this project i…
> This appears to be just another commercialisation of domain names, trying to create another "Gold Rush" for the most sought after names. Winner-take-all. A few profit at the expense of the many. This is a major problem that the project has made a sincere attempt to address. Through scarcity certain sybil protections are afforded, which has been inherently architected into the consensus protocol [1]. Additionally, a…
Here is a different idea. The intent is not "world-takeover" or "winning" any imaginary popularity contest but just a different kind of DNS service, because, well who needs a reason. Because we feel like it, how's that. The idea is: Start a registry that only allows djb-designed per-packet encrypted DNS to be used. That is, all persons running authoritative nameservers must follow some rules. They must publish public keys in subdomains of the nameserver's domain. For an example of how this looks, do an NS query to ianix.com. All authoritative nameservers in this imaginary registry would be required to offer per-packet encypted DNS. It would not be that difficult to start something like this at least on a small scale. People running authoritative nameservers simply need to run a CurveDNS forwarder in front of their preferred authoritative nameserver implementation. The CurveDNS forwarder is a small piece of free, open-source software. This type of encryption is different from DNSSEC, so this is not a "replacement" or even an "alternative" to that movement. It is something totally different. The purpose is not to address risk associated with shared DNS caches (e.g., poisoning and other tricks) as DNSSEC is intended to address, it is not to distinguish an "approved" domainname versus an "unapproved" one by creating some "chain of trust" to a "root". The purpose is just to encyrpt DNS packets. The focus is authoritative DNS, the folks that actually own the web resource, not recursive DNS, third party DNS cache providers, etc. There are couple of reference implementations of the DNSCurve-enabled cache and one of a dig-like client users would run on their home/own networks to send encypted queries and decrypt responses. This whole system for encrypting DNS has been around for over a decade and IMHO is easily as "battle-tested" as anything DNSSEC. Does that mean everyone should use it. No. But it means anyone could use it. For no other reason that because they feel like it.
The main problem something like Handshake is purportedly aimed at solving, namely centralisation of who controls "the" DNS, is IMO caused by the commercialisation and making a "market" for names. There is no way anyone is going to solve the centralisation problem by offering a commercial alternative that replays the "Gold Rush" of the first DNS (not to mention all the corruption that followed, culminating in "new gTLDs" for $185,000+). If we want to level the DNS playing field, then IMO we would have to take the money out of it. That might mean "vanity" names are not as important. Who knows, public keys might play a more important role. I am thinking of those Facebook workers who "brute-forced/mined" some .onion name they thought was more recognisable. Silly. "Decentralised" would seem to imply more equality across the namespace, not "I snagged the best names before everyone else" (using x kilowatts in the process) or "That name sucks."
Just an opinion. Good luck with the blockchain.