People have been trying to make alternate-root DNS systems a thing for 20+ years, it has never caught on.
I'm not a blockchain fan but "somebody tried this once and it didn't work" is hardly a dismissal of an entire class of ideas. Beanz didn't catch on but bitcoin seems to have.
Opera adds native support for blockchain domain names
21–30 of 166 posts
Re: Opera adds native support for blockchain domain names
#22Domain name/identity and key pinning has always been the only useful use of NFTs that I can think of. Today, to encrypt your communications with people, you use something like PGP or Signal which rely on "trust on first use (TOFU) but verify", in practice people don't really verify so it's more like TOFU. This means that if someone compromised the session at the moment where it was created (or re-created), then your…
This fact has been irritating me for a long time. Because no one should believe that every single certificate authority is tolerant to any attempts to steal the private keys. But that is exactly the underlying assumption behind HTTPS being the only way to use HTTP in a more secure manner than exchanging in plaintext.
Let's think about this scenario: Suppose that I built a web service for my personal use and hosted it in public cloud. I don't trust any certificate authorities, so I created my own TLS certificate without using them. I installed my own certificates on the machine from which to connect to my web service. Now the server for my web service is serving in HTTPS using my own certificate. Am I safe? No. Because any entity with access to the private key of any of the certificate authorities trusted by my machine, is capable of intercepting the communication between my machine and my server, simply by MITM.
The problem of being forced to trust certificate authorities can be solved by adding the feature to embed a public key in a url. For example, it would be wonderful to have a url like httpsecure://rsa:PUBLICKEY/example.com/ to make sure example.com always responds using the key PUBLICKEY. IIRC, the Tor onion services is an instance of this -- the .onion domains include public keys.
Re: Opera adds native support for blockchain domain names
#23More fragmentation. I use Nextdns for my router's DNS, which theoretically allows me to access any domains on the competing Handshake crypto protocol, but I've never actually some across any so far.
Re: Opera adds native support for blockchain domain names
#24Opera is beyond rescue. As someone who spent a decade working there it saddens me to say so, but please don't use it. Actual, executive day-to-day control over the browser tech has progressed sort of like this: 1995: Oslo, Norway 2008: Linköping, Sweden 2014: Wrocław, Poland 2020: Beijing, PRC (the sale happened in 2016, but they were hands-off for quite some time; I think they were being busy with shady fintech stuf…
Re: Opera adds native support for blockchain domain names
#25Opera is beyond rescue. As someone who spent a decade working there it saddens me to say so, but please don't use it. Actual, executive day-to-day control over the browser tech has progressed sort of like this: 1995: Oslo, Norway 2008: Linköping, Sweden 2014: Wrocław, Poland 2020: Beijing, PRC (the sale happened in 2016, but they were hands-off for quite some time; I think they were being busy with shady fintech stuf…
Are you saying it's beyond rescue because it's controlled by China?
Re: Opera adds native support for blockchain domain names
#26Domain name/identity and key pinning has always been the only useful use of NFTs that I can think of. Today, to encrypt your communications with people, you use something like PGP or Signal which rely on "trust on first use (TOFU) but verify", in practice people don't really verify so it's more like TOFU. This means that if someone compromised the session at the moment where it was created (or re-created), then your…
> Today, to encrypt your communication to websites, you use HTTPS which rely on a vast network of certificate authorities. This fact has been irritating me for a long time. Because no one should believe that every single certificate authority is tolerant to any attempts to steal the private keys. But that is exactly the underlying assumption behind HTTPS being the only way to use HTTP in a more secure manner than exc…
You're probably more safe than you'd think. Certificate Transparency is now required for Chrome, Firefox, or Safari or you'll get an error message during the TLS connection, before any private data is sent to the (potentially MITM'd) site.
Given that all certificates are logged, site operators can use some of the many CT alert websites to let them know if and when a new certificate is issued for their domain, so if some random authority they haven't heard of before issues a cert or it's done at a time they know they didn't need to renew their certs, it'd be time to raise major alarms about the occurrence and thus would mean instant loss of all business for that authority; plus, shockwaves would be sent across the internet as this would be a huge event, especially if it's against a company worth burning a CT for (eg. Google which houses so many fortune 500 companies' secrets).
> the .onion domains include public keys.
The .onion domain is, in itself, a public key. The side effects of your proposed solution are:
A) it would mean you HAVE to trust whoever sent you a link
A) 1) for web-based referrals, this would mean you trust your (possibly state-sponsored) search engine to never MITM you (this is currently mitigated by CT which would expose Google's GTS issuing a random domain's cert)
A) 2) for IRL events, this would mean you have to trust that the business themselves put up a certain QR code with the public key and not some malicious actor
B) This would mean site.com could never rotate their private key without changing all of their backlinks to one with the correct public key.
These are all problems Tor already faces - you have no idea if the onion site you're linked to is actually the site it says it is if it perfectly mimics it and/or reverse proxies the real site. You're currently always advised to get URLs from a trusted source once then only use bookmarks to access them to prevent reverse engineering. And you can't rotate your private key without doing this domain change.
Re: Opera adds native support for blockchain domain names
#27Opera is beyond rescue. As someone who spent a decade working there it saddens me to say so, but please don't use it. Actual, executive day-to-day control over the browser tech has progressed sort of like this: 1995: Oslo, Norway 2008: Linköping, Sweden 2014: Wrocław, Poland 2020: Beijing, PRC (the sale happened in 2016, but they were hands-off for quite some time; I think they were being busy with shady fintech stuf…
Re: Opera adds native support for blockchain domain names
#28Opera is beyond rescue. As someone who spent a decade working there it saddens me to say so, but please don't use it. Actual, executive day-to-day control over the browser tech has progressed sort of like this: 1995: Oslo, Norway 2008: Linköping, Sweden 2014: Wrocław, Poland 2020: Beijing, PRC (the sale happened in 2016, but they were hands-off for quite some time; I think they were being busy with shady fintech stuf…
Are you saying it's beyond rescue because it's controlled by China?
I was their user since version 5 or 6 (this was before everyone started the crazy version system, back them they released a major version about once a year).
The biggest things that I loved about the browser you couldn't get by extension, they could do many things because they could directly update the engine.
Now learning that they are owned by PRC there's even less reasons for me to use it.
Opera could have done a lot of good if they would open sourced their old browser (kind of line what Netscape did). Someone leaked the original source code, but because it was leaked and not officially published, no one wants to touch it. Anyway now it's too late, because it's way behind the current browsers.
Re: Opera adds native support for blockchain domain names
#29Opera is beyond rescue. As someone who spent a decade working there it saddens me to say so, but please don't use it. Actual, executive day-to-day control over the browser tech has progressed sort of like this: 1995: Oslo, Norway 2008: Linköping, Sweden 2014: Wrocław, Poland 2020: Beijing, PRC (the sale happened in 2016, but they were hands-off for quite some time; I think they were being busy with shady fintech stuf…
It was dead to me the moment they switched to chromium
Google had very purposely raised the bar by putting like 5x-8x more competent engineers than the Opera core (non-platform/UI-specific stuff) team had, working on inventing and implementing random new web standards that they then promptly started using on google.com properties. Think e.g. 500-800 engineers compared to 100. We simply couldn't do the same. Then this ratio started growing until it was obvious that it would eventually become an existential threat.
They used their financial success in one business area (search ads) to become dominant in another area (browsers) in a clever and perhaps not entirely legal way.
Re: Opera adds native support for blockchain domain names
#30Opera is beyond rescue. As someone who spent a decade working there it saddens me to say so, but please don't use it. Actual, executive day-to-day control over the browser tech has progressed sort of like this: 1995: Oslo, Norway 2008: Linköping, Sweden 2014: Wrocław, Poland 2020: Beijing, PRC (the sale happened in 2016, but they were hands-off for quite some time; I think they were being busy with shady fintech stuf…