Handshake – Decentralized naming and certificate authority
21–30 of 104 posts
Re: Handshake – Decentralized naming and certificate authority
#22Re: Handshake – Decentralized naming and certificate authority
#23A very big security problem with current domain certificates is that browsers accept any certificate for any domain, as long as they trust the issuer. There is no concept or notion of who is supposed to have issued the certificate.
Re: Handshake – Decentralized naming and certificate authority
#24Earlier quoted context omitted.
Sadly namecheap bought into this, so it’s being forced down the throats of people who don’t quite realize that the domains they can buy on the service can not, and will not ever be usable. It’s pretty obvious to even the most casual of observers that this is just yet another cryptocurrency scheme designed to fleece as many people as possible.
This is very unfair to namecheap: 1. The search bar on their homepage returns no handbrake results 2. To get to those results in the first place you have to click on a 'Handbrake' tab (leaving the 'Domains' tab) 3. The search results link to an info page that clearly states "It's also important to note that handshake domains do not resolve in regular browsers without additional setup." For the record, I think Handbra…
That's sadly not correct.
https://www.namecheap.com/domains/registration/results/?doma...
For example using "beast mode" on the front page search, a good portion of the domains are "handshake" entries with only a tiny little (i) button to distinguish them from actual domain names which could be used in the real world.
I can add them to my cart with no other mention that the product I am buying is a sham, I can even add a SSL certificate along with my purchase- which can't actually be issued because it's not a real domain name.
> "It's also important to note that handshake domains do not resolve in regular browsers without additional setup."
This feels like an incredible understatement. They will never be accessible by anybody who doesn't install software explicitly with that goal, they will never be able to receive email, nobody is going to issue SSL certificates for them.
Re: Handshake – Decentralized naming and certificate authority
#25> Handshake uses proof-of-work mining Uh, no thanks. If you insist on using a blockchain at least don't make it proof-of-work. It's 2022, and there are plenty of production-ready non-PoW chains out there already. Please stop killing the planet.
Wrt to non-PoW system, so far governance for those chains looks closer to a federation (where a few agents control the majority of the network) than to a really decentralised network. In that sense, a proof-of-stake DNS network wouldn't be that different from the current implementation. If such network ever takes off, I wouldn't be surprised if major ISPs, Cloudfare, Google, and a few other players end up owning the majority of the tokens.
[1] Adam Back's 1997 Hashcash, designed to fight email spam and DDOS attacks was based on PoW.
Re: Handshake – Decentralized naming and certificate authority
#26It's very interesting to see Namecheap, Gateway.io, Encirca, etc use it and its very surprising to see some ICANN TLDs being claimed on Handshake.
Re: Handshake – Decentralized naming and certificate authority
#27A very big security problem with current domain certificates is that browsers accept any certificate for any domain, as long as they trust the issuer. There is no concept or notion of who is supposed to have issued the certificate.
CAA records provide some extra defence (https://en.m.wikipedia.org/wiki/DNS_Certification_Authority_...).
It’s not perfect, but it’s getting better.
Re: Handshake – Decentralized naming and certificate authority
#28> Handshake uses proof-of-work mining Uh, no thanks. If you insist on using a blockchain at least don't make it proof-of-work. It's 2022, and there are plenty of production-ready non-PoW chains out there already. Please stop killing the planet.
Re: Handshake – Decentralized naming and certificate authority
#29> Handshake uses proof-of-work mining Uh, no thanks. If you insist on using a blockchain at least don't make it proof-of-work. It's 2022, and there are plenty of production-ready non-PoW chains out there already. Please stop killing the planet.
Yeah. Like Solana, Polygon, Helium, Celo, etc? Which they went down. Why would something that operates like a CA, DNS or TLDs be suitable on those 'production-ready' chains? PoW makes sense for this use case.
> Please stop killing the planet.
I agree. I'd rather have something useful burning the planet and is an improvement than something that is burning the planet for the benefit of more surveillance, censorship and spyware (Deep Learning, Machine Learning systems on user data) or something that is not useful at all to the current system. (Bitcoin)
So perhaps we also should look at stopping running broken machine learning / deep learning models continuously on many data centers for 10+ years which that is also incinerating the planet.
Re: Handshake – Decentralized naming and certificate authority
#30I think name servers is one of the best applications for a decentralized ledger. It _can_ work without a central party, and I think it might be better without one. Something like .org controversy might not have happened without a central party.
Frankly, considering how critical the name server infrastructure is, I think it's been remarkably reliable and well run. The .org controversy was a big deal, but for the thirty years I've been online those types of problems stand out because they are so rare.