Live data from Hacker News

Handshake – Decentralized naming and certificate authority

handshake.org

91–100 of 104 posts

Re: Handshake – Decentralized naming and certificate authority

#91
post #84

Earlier quoted context omitted.

Yea but that is opt-in not opt-out. For example there are botnets that use specific domains, they get disrupted until they spread again when a domain or IP is taken down. The longer a credential phish stays up the more people are affected by it as well. If there is no way to ensure by default a domain is inaccessible when revoked it isn't a workable system for commerical applications.

You can build decentralized domain name systems with revocation. Many of the people building such things wouldn't be big into adding deplatforming into the base layer, though. These projects are about a more free internet, not about a more easily controlled internet.

Completely agree with you on all points and that is why their work will never gain mass adoption. Even DoH struggles to be adopted in corporate and restricted environments.

Everyone wants to start a protocol but no one wants to maintain the network. They want it to run itself. They don't want to separate centralization of authority from centralization of platform/network. The former lets you circumvent blocks if removed and the latter avoids registry's, payments, corporate run internet,etc... you can't have your cake and eat it too.

Re: Handshake – Decentralized naming and certificate authority

#92
post #43

Earlier quoted context omitted.

That's a Nonargument https://www.merriam-webster.com/dictionary/nonargument . Giving examples of technologies that can also be considered "a waste of energy" is a valid argument. Why is using energy playing graphics intensive games with high-end graphics cards not considered a "waste of energy"? It's a value judgment that lacks perspective. Dismissing some technology for its energy usage without providing a better al…

Just tax everything the amount it costs to clean up the pollution it causes, then you can do whatever you want without a problem

How do you calculate that price? How would you enforce it globally?

Re: Handshake – Decentralized naming and certificate authority

#93

> Email became Gmail, usenet became reddit, blog replies became facebook and Medium, pingbacks became twitter, squid became Cloudflare, even gnutella became The Pirate Bay How is that even remotely related to creating a new domain name service? Does the author really believe in good faith that the centralization of platforms would somehow be reduced or disappear entirely by introducing a new domain name service? This…

It is worth pointing out the distributed systems tend towards centralization over time. Keeping things decentralized is always going to be an active effort. Fundamentally decentralized vs centralized is also robustness vs efficiency. Anybody with a short returns horizon that hasn't been burned yet prefers efficiency.

It is also worth pointing out that centralized systems tend to drive people towards wanting decentralization over time, since it's only a matter of time until individuals get burned by the arbitrary whims of the rulers over centralized systems.

I never took such arguments seriously myself until my bank refused service to me without giving me any reason for it. Treating honest customers like criminals is exactly how people start distrusting centralized systems and their untrustworthy authority. In the dns/icann sphere there are also countless factors[0] that are evidence of this, not even talking about the dns hacks[1] or clear cut corruption of icann or censorship attempts.[2]

So it's not only about robustness vs efficiency, but also about additional factors like ownership and freedom + security et cetera.

[0] https://www.politico.com/news/2022/04/09/website-domain-more...

[1] https://threatpost.com/unprecedented-dns-hijacking-attacks-l...

[2] https://arstechnica.com/tech-policy/2022/03/ukraine-wants-ru...

Re: Handshake – Decentralized naming and certificate authority

#94

Earlier quoted context omitted.

Specifically the purpose of CAA is to enable a subscriber (say, the owner of ycombinator.com) to tell trustworthy Certificate Authorities thanks, but no thanks. It is not a message for anybody else. If you're not a CA you don't need to read CAA records. For example, say you're Facebook, you've got an arrangement with DigiCert where on top of the Ten Blessed Methods of the Baseline Requirements, DigiCert promises to g…

Do browsers not check CAA? They could .

They shouldn't. CAA controls issuance, but the browser isn't performing issuance.

It's completely allowed (a bit paranoid, but allowed) to set CAA to forbid everybody from issuing except when you are actually getting new certificates.

But now your hypothetical "CAA checking" browser thinks the certificates issued this way aren't valid, because when it visited, hours, weeks or even months later, the CAA record did not allow the certificate it saw.

Re: Handshake – Decentralized naming and certificate authority

#95

Earlier quoted context omitted.

It is worth pointing out the distributed systems tend towards centralization over time. Keeping things decentralized is always going to be an active effort. Fundamentally decentralized vs centralized is also robustness vs efficiency. Anybody with a short returns horizon that hasn't been burned yet prefers efficiency.

It is also worth pointing out that centralized systems tend to drive people towards wanting decentralization over time, since it's only a matter of time until individuals get burned by the arbitrary whims of the rulers over centralized systems. I never took such arguments seriously myself until my bank refused service to me without giving me any reason for it. Treating honest customers like criminals is exactly how p…

> So it's not only about robustness vs efficiency, but also about additional factors like ownership and freedom + security et cetera.

Id argue those are part of centralization vs decentralization

Plenty of systems that look decentralized at first glance really just have human organization as the central failure point. This is a great example of why most cryptocurrency is centralized (centralized development and management)

Re: Handshake – Decentralized naming and certificate authority

#96
post #90

Application-level protocols should not be attempting to secure their own consensus mechanisms - it ties the security of the application to the base token. If you are seeking decentralized naming and certificate authorities you can look at Ethereum and ENS. Besides the eventual transition to Proof-of-Stake, building an application on top of an existing consensus mechanism means that your application will inherit the s…

It's not possible to make a lightweight ENS resolver that doesn't fully trust the Ethereum node it's using.

True, even though a current "light client" can run on Raspberry Pi, really there should be even lighter clients for validating on-chain state. See [1] which is an area of development.

[1] https://nimbus.team/docs/fluffy.html

Re: Handshake – Decentralized naming and certificate authority

#97

Earlier quoted context omitted.

It is also worth pointing out that centralized systems tend to drive people towards wanting decentralization over time, since it's only a matter of time until individuals get burned by the arbitrary whims of the rulers over centralized systems. I never took such arguments seriously myself until my bank refused service to me without giving me any reason for it. Treating honest customers like criminals is exactly how p…

> So it's not only about robustness vs efficiency, but also about additional factors like ownership and freedom + security et cetera. Id argue those are part of centralization vs decentralization Plenty of systems that look decentralized at first glance really just have human organization as the central failure point. This is a great example of why most cryptocurrency is centralized (centralized development and manag…

One can always infinitely shift the goal post and nitpick if one has an axe to grind. The point is aiming for as little or as much decentralization possible to realize certain properties, it's not about having decentralization for the sake of decentralization. it's not a goal but a means to an end. we fundamentally want more ownership, freedom & security.

Priorities are also important: Unrealistic levels of decentralization make no sense before securing survival and increased usage. In addition, we don't need absolutely everything to be decentralized, but merely those components that help us manifest those properties we desire.

Re: Handshake – Decentralized naming and certificate authority

#98
post #47
post #6

Another similar and interesting project, and which is not blockchain-based, is the GNU Name System: https://www.gnunet.org/en/gns.html

Out of the gate from [0], as soon as one tries to install it, they are met with this: Notice: GNUnet is still undergoing major development. It is largely not yet ready for usage beyond developers. On top of the Linux-focused attitude to this project (GNUnet, GNS, etc) which that is already limiting its usefulness and user friendliness to the average joe, if it is not available on other systems like Windows or macOS h…

It's available for macOS via Homebrew. That option isn't even the last one on the list. I don't yet want to, but if I did, I could install this for macOS in minutes.

Re: Handshake – Decentralized naming and certificate authority

#99
post #22

The person who forced themselves into ownership of freenode is closely associated with this dumpster fire.

Quoted post unavailable.

Projects moving forward towards obscurity and uselessness? What's going on with the website for freenode?

Regarding lies, your story seems highly unlikely, and the communities have already made a decision. Sleep well knowing that having access to boundless finances does not make one a useful and well regarded person.

Re: Handshake – Decentralized naming and certificate authority

#100
post #72
post #22

The person who forced themselves into ownership of freenode is closely associated with this dumpster fire.

> themselves into ownership of freenode is closely associated Wonderful. Using a guilt by association to discredit a project due to someone else's involvement rather than critiquing the technology and its goals. Facebook have been involved with allowing the spread of misinformation, hate crimes, etc and have built systems that use Rust to aid this and are also a platinum member (Amongst other surveillance big tech co…

By close association, I mean the co-founder of Handshake is also responsible for the downfall of freenode, personally. Even disregarding the hostile takeover of a community, it was rasengans ineptitude that fueled the massive exodus.
Post reply on HN