Earlier quoted context omitted.
Certificate Transparency Logging allows you to view the issuances of certificates. CAA records provide some extra defence ( https://en.m.wikipedia.org/wiki/DNS_Certification_Authority_... ). It’s not perfect, but it’s getting better.
Specifically the purpose of CAA is to enable a subscriber (say, the owner of ycombinator.com) to tell trustworthy Certificate Authorities thanks, but no thanks. It is not a message for anybody else. If you're not a CA you don't need to read CAA records. For example, say you're Facebook, you've got an arrangement with DigiCert where on top of the Ten Blessed Methods of the Baseline Requirements, DigiCert promises to g…
Handshake – Decentralized naming and certificate authority
71–80 of 104 posts
Re: Handshake – Decentralized naming and certificate authority
#72The person who forced themselves into ownership of freenode is closely associated with this dumpster fire.
Wonderful. Using a guilt by association to discredit a project due to someone else's involvement rather than critiquing the technology and its goals.
Facebook have been involved with allowing the spread of misinformation, hate crimes, etc and have built systems that use Rust to aid this and are also a platinum member (Amongst other surveillance big tech companies like Microsoft, Google, Amazon, etc) involved with funding the Rust Foundation.
Given that deep association, does that mean you should stop learning and using Rust?
Re: Handshake – Decentralized naming and certificate authority
#73Re: Handshake – Decentralized naming and certificate authority
#74The person who forced themselves into ownership of freenode is closely associated with this dumpster fire.
Merely supporting it or in leadership role? Either way...
Re: Handshake – Decentralized naming and certificate authority
#75Earlier quoted context omitted.
Specifically the purpose of CAA is to enable a subscriber (say, the owner of ycombinator.com) to tell trustworthy Certificate Authorities thanks, but no thanks. It is not a message for anybody else. If you're not a CA you don't need to read CAA records. For example, say you're Facebook, you've got an arrangement with DigiCert where on top of the Ten Blessed Methods of the Baseline Requirements, DigiCert promises to g…
Do browsers not check CAA? They could .
CAA combined with this CT requirement means that businesses serious about issuance can set up a service to watch CT logs and get notified every time a certificate is issued, so any would-be CA attacker would have to be pretty quick with their attack if they wanted to impersonate fb.com, and that CA would be questioned by the CA/B community pretty quickly for breaking CAA policies.
Re: Handshake – Decentralized naming and certificate authority
#76The person who forced themselves into ownership of freenode is closely associated with this dumpster fire.
Re: Handshake – Decentralized naming and certificate authority
#77The person who forced themselves into ownership of freenode is closely associated with this dumpster fire.
Re: Handshake – Decentralized naming and certificate authority
#78Earlier quoted context omitted.
Except that the examples I listed after more than 10 years of operation, especially the use of Deep Learning and training on tons of new data, have NO efficient alternatives, and still require tons of data centers to the point where some of them literally caught fire and their use is worse for society. Unless you want more surveillance, spyware, etc who would be happy with that? The end result to all that wasteful tr…
> Either way, it is pointless to outline a comment as 'This is a false dilemma' without countering my claims... It's pointless to counter a fallacy. Trying to pretend machine learning and Bitcoin are of equal uselessness is dishonest.
As soon as that deep learning or machine learning model gets confused or attacked with erroneous / junk input, garbage noise or performs badly on new data, that model is useless. What do you do next? More training, re-training, fine tuning? That problem is unavoidable and evergreen.
The end result is the same and either way, that is used for surveillance, spyware on user data which not only that is a waste of energy, CO2 and time, that is worse for both for society and the planet and the methods to improve these models have been known to be inefficient and have not changed for 10+ years and always require tons of data centers. On that, Bitcoin is the same with mining. There is no benefit or useful improvement for it in the current system for payments (it's original intended purpose) and it also burns up the planet with PoW.
No idea why you had to deliberately ignore deep learning as that is also part of the planet incinerating problem.
Re: Handshake – Decentralized naming and certificate authority
#79This is the only rare valid use case and need for a blockchain given the seizure of TLDs like what happened to .org [0] recently. It's very interesting to see Namecheap, Gateway.io, Encirca, etc use it and its very surprising to see some ICANN TLDs being claimed on Handshake. [0] https://news.ycombinator.com/item?id=21611677
I agree. I'm not very convinced about the upside-downside ratio of this implementation though But it has the merit of being a blockchain use that isn't complete non-sense.
Re: Handshake – Decentralized naming and certificate authority
#80I think name servers is one of the best applications for a decentralized ledger. It _can_ work without a central party, and I think it might be better without one. Something like .org controversy might not have happened without a central party.
From a technical perspective it can. But how would you take down domains, resolve disputes like when your domain is taken over by attackers or a lookalike domain is defrauding users that are trying to get to your site. It isn't commercially viable without an authority everyone accepts for name revocation.