Live data from Hacker News

DNS-on-Blockchain is the next step after DNS-over-HTTPS

diode.io

51–60 of 69 posts

Re: DNS-on-Blockchain is the next step after DNS-over-HTTPS

#51
post #25

DoB will have to deal with some problems, especially bad actors; people will squat on domains, register typos (fscebook.com) or even bitflips (fabebook.com, b is one bitflip from c). Malware owners will run their C&C servers on domains. Malicious domains will require someone removing them or blocking them even, unless you want the DoB namespace to turn into a cesspool of malware, phishing and nazis. Not something the…

Yeah, why even let the Nazis have IP addresses? In fact, if we took away their computers, pens, and papers, surely that would make them less likely to lash out violently.

Re: DNS-on-Blockchain is the next step after DNS-over-HTTPS

#52

So every DNS change is stored into the blockchain, forever? Will you have to download terabytes and terabytes of the blockchain in order to serve as a node? Why is that kind of audit history necessary? Why is the solution to every problem "blockchain" these days?

You'd only need to put the NS records in for each domain.

Re: DNS-on-Blockchain is the next step after DNS-over-HTTPS

#53
post #25

DoB will have to deal with some problems, especially bad actors; people will squat on domains, register typos (fscebook.com) or even bitflips (fabebook.com, b is one bitflip from c). Malware owners will run their C&C servers on domains. Malicious domains will require someone removing them or blocking them even, unless you want the DoB namespace to turn into a cesspool of malware, phishing and nazis. Not something the…

Nazis and malware authors are out there using email right now. What are we going to do about it?

Re: DNS-on-Blockchain is the next step after DNS-over-HTTPS

#54
post #51
post #25

DoB will have to deal with some problems, especially bad actors; people will squat on domains, register typos (fscebook.com) or even bitflips (fabebook.com, b is one bitflip from c). Malware owners will run their C&C servers on domains. Malicious domains will require someone removing them or blocking them even, unless you want the DoB namespace to turn into a cesspool of malware, phishing and nazis. Not something the…

Yeah, why even let the Nazis have IP addresses? In fact, if we took away their computers, pens, and papers, surely that would make them less likely to lash out violently.

Seems to have worked with 8chan, last I checked it's still offline on the clearnet.

Re: DNS-on-Blockchain is the next step after DNS-over-HTTPS

#55
There's some interesting work on this going on in W3C, in the Verifiable Claims Working Group [1] and in the newly minted Decentralized Identifier Working Group [2]. I'm a member of the W3C Credentials Community Group (CCG) [3], which is where those two WGs started.

There are also a number of other valuable efforts. Both in other Standards Development Organizations (SDOs), such as Decentralized Identity Foundation (DIF) [4], Apache HyperLedger projects like Aries [5], etc. And in working conferences/unconferences like Rebooting Web of Trust (RWOT) [6], and Internet Identity Workshop (IIW) [7]. On a tangential note, Unconferences are an interesting concept [8].

[1] https://www.w3.org/2017/vc/WG/ [2] https://www.w3.org/2019/08/did-wg-charter.html [3] https://w3c-ccg.github.io/ [4] https://identity.foundation/ [5] https://www.hyperledger.org/projects/aries [6] https://www.weboftrust.info/ [7] https://internetidentityworkshop.com/ [8] http://unconference.net/

Re: DNS-on-Blockchain is the next step after DNS-over-HTTPS

#56
post #22
post #11

Earlier quoted context omitted.

Ipfs.io can solve this easily.

Ipfs requires a DNS server to bootstrap the P2P network, not a good idea. Plus, Ipfs isn't that good when it comes to authentic data, if it's signed, there is only one key, so it's centralized again.

You have to keep in mind ipfs is content-addressed. Instead of resolving names you can resolve certificates by their content addressed thumbprint.

1) boostrap 2) find the cert thumbprint for site.com 3) find the cert by the thumbprint and connect to one if IP SAN records

Re: DNS-on-Blockchain is the next step after DNS-over-HTTPS

#57
post #56
post #22

Earlier quoted context omitted.

Ipfs requires a DNS server to bootstrap the P2P network, not a good idea. Plus, Ipfs isn't that good when it comes to authentic data, if it's signed, there is only one key, so it's centralized again.

You have to keep in mind ipfs is content-addressed. Instead of resolving names you can resolve certificates by their content addressed thumbprint. 1) boostrap 2) find the cert thumbprint for site.com 3) find the cert by the thumbprint and connect to one if IP SAN records

How do you securely get the cert thumbprint?

Re: DNS-on-Blockchain is the next step after DNS-over-HTTPS

#58
post #25

DoB will have to deal with some problems, especially bad actors; people will squat on domains, register typos (fscebook.com) or even bitflips (fabebook.com, b is one bitflip from c). Malware owners will run their C&C servers on domains. Malicious domains will require someone removing them or blocking them even, unless you want the DoB namespace to turn into a cesspool of malware, phishing and nazis. Not something the…

Then Facebook can buy the space of typos around their name? Just because Facebook (or Twitter, Instagram, et al) are popular sites, doesn't mean registrars should give them special treatment. What happens when they stop being popular?

Re: DNS-on-Blockchain is the next step after DNS-over-HTTPS

#59
post #25

DoB will have to deal with some problems, especially bad actors; people will squat on domains, register typos (fscebook.com) or even bitflips (fabebook.com, b is one bitflip from c). Malware owners will run their C&C servers on domains. Malicious domains will require someone removing them or blocking them even, unless you want the DoB namespace to turn into a cesspool of malware, phishing and nazis. Not something the…

Then Facebook can buy the space of typos around their name? Just because Facebook (or Twitter, Instagram, et al) are popular sites, doesn't mean registrars should give them special treatment. What happens when they stop being popular?

Most larger registrars give you the same protection if you run any type of business. Though below certain threshold typo-squatting will simply not happen, but atleast in my jurisdiction I can actually sue the owner of the typosquat for the ownership of the domain.

Re: DNS-on-Blockchain is the next step after DNS-over-HTTPS

#60
post #25

DoB will have to deal with some problems, especially bad actors; people will squat on domains, register typos (fscebook.com) or even bitflips (fabebook.com, b is one bitflip from c). Malware owners will run their C&C servers on domains. Malicious domains will require someone removing them or blocking them even, unless you want the DoB namespace to turn into a cesspool of malware, phishing and nazis. Not something the…

We girls at your pub will truck and stuck you right off, just drink a beer or two, and come down to the pub. It'll be fantastic.

I guarantee you will have luck. Let's truck it. Have some self-hope. It'll be grand <3

Post reply on HN