14 ms·
The process of mapping name=IP is not remotely technically difficult, and I'd dare say most people reading this message could implement the backend to such a sy
by byuu 7y ago
The process of mapping name=IP is not remotely technically difficult, and I'd dare say most people reading this message could implement the backend to such a system in a few days.
Setting up the peering replication and nameservers around the world is considerably harder, but it's definitely not a $10 billion+ problem (the current value of registrars and certificate authorities.) A startup funded by YC could handle that easily.
Dealing with all the companies trying to sue you over others squatting their domains and having to decide who has the better claim would be the most expensive part.
I really hate to say it because it's so cliche and overused, but a blockchain-like system could remove the central authority, the server costs, and the lawsuit risks. But it would introduce concerns over trust, most likely.
The really hard, unsolvable part is the unwillingness of the browser vendors to support an alternative domain name system. If Chrome, Firefox, and Safari all supported a new TLD outside of ICANN's control as a public service (let's call it "Let's Resolve" which would offer free domains and would be funded through donations), it would be very successful. If even one of them didn't support it, nobody would ever consider using it for their websites. Browser extensions, even if they allowed access to intercept domain name lookups, would not work. It would have to be supported out of the box in every major browser, and well, good luck with that. Anything failing to herd those three cats right out of the starting gate is absolutely dead on arrival.
Who knows though, maybe they'll raise .org prices just a bit too much, and piss off an established non-profit enough to start a huge campaign to create an alternative. But probably not.
- 22c 7y agonamecoin is one of the oldest altcoins around and probably predates the existence of the term altcoin. https://www.namecoin.org/ https://www.namecoin.org/
- oefrha 7y ago> The really hard, unsolvable part is the unwillingness of the browser vendors to support an alternative domain name system. If Chrome, Firefox, and Safari all supported a new TLD outside of ICANN's control as a public service (let's call it "Let's Resolve" which would offer free domains and would be funded through donations), it would be very successful. Not sure I understand your proposal. Say every single browser in the world supports Let's Resolve. byuu.org is registered with ICANN; but someone now wants to register byuu.org with Let's Resolve. Do you let them? What about the other way round? And what if someone attempts to register byuu.org with ICANN, while another attempts to register byuu.org with Let's Resolve at the same time, causing a race. Who wins? Also, unique, meaningful and memorable identifiers are a scarce resource. Offering free domains just open up the floodgate of squatting and hoarding (at unprecedented ease). Edit: Parent suggested a new TLD; I read it as a whole alternative system. Well, the new TLD idea was already implemented as .bit AFAIK, and it's pretty crap.
- pteraspidomorph 7y agoYou probably need a system that allows both roots to function together. Maybe a different URL scheme: http: and https: use ICANN, httplr: and httplrs: use LR If not specified, browser tries LR first, then falls back on ICANN. Doesn't feel as solid to me, but they could also register a placeholder TLD that would be use for redirecting requests to LR, or the other way around: google.com.lrns would tell the browser to resolve google.com in the LR root (hardcoded), or google.com.icann would tell the browser to resolve google.com in the ICANN root. When falling back from one to the other, the browser would display the hostname with the fallback TLD on it. Just some ideas off the top of my head, I haven't fully considered the implications yet.
- oefrha 7y agoPhishers would love that.
- clarry 7y agoI think by "TLD outside of ICANN's control", GP meant a unique TLD that (currently) does not exist under ICANN. So it's not going to be byuu.org under ICANN vs byuu.org under LR, it's going to be byuu.lr (under LR) versus byuu.org (under ICANN)?
- oefrha 7y agoYeah I misread. Then it's gonna be subject to good old squatting and hoarding (vastly more so if free) as I mentioned, and not really solve anything.
- clarry 7y agoI agree. As long as there's scarcity, there's someone trying to exploit it. I think it could be better to just accept that unique global names are not a great idea, and start identifying parties by certificates rather than name. Various chain of trust & reputation type arrangements can be used to ensure people won't confuse Their Bank (certificate issued by/for Their Bank) for Their Bank (certificate issued by & for scammer in Ukraine). Legit entities will have every reason to include information that minimizes likelihood of confusion. Come on, I can have more than one James Smith in my phone's contact book too.. let's stop fighting over names.
- hultner 7y agoBrowsers shouldn't be the entity deciding on address resolution, a domain system bound only to the web/httpx would be a huge leap backwards. This should be up to the os and whatever names resolution the os provides should be happily accepted by any network program, be it a browser, email client, ssh, irc or something completely different.
- byuu 7y agoUnfortunately, with at least Chrome and Firefox moving to DNS-over-HTTPS, they are the entities deciding on address resolution for 99% of average-user requests. I would agree with you in principle however, in which case there's an even more impossible goal: get Microsoft, Apple, Google, and every Linux/BSD distro to agree to a new OS-level alternate domain name resolver that functions out of the box. And also stop Google and Mozilla from rolling out browser-level DoH.
- justinclift 7y agoWonder if this means Cloudflare - and/or the other termination points for DNS-over-HTTPS - could be an interesting place to start adding an alternative DNS resolution system? Then it wouldn't need to be done by any browsers... if the DNS-over-HTTPS end point provider does the additional name resolution, it should "just work".
- syshum 7y agoYes because that is what the internet needs, to have CloudFlare in control over more and more of it
- mygo 7y agoWe’re here because a private company has taken over .ORG I see what you’re saying in theory, but it can’t be cloudflare or a private company or else it’s more of the same.
- justinclift 7y ago
- mrzool 7y agoI may be mistaken, but I always thought DNS resolution was handled by the underlying OS, and not by the browser through HTTP. Support from browser vendors would probably matter a great deal for this, but not at a technical/implementation level, right?
- 0xcde4c3db 7y agoConventionally, yes, but that's changing somewhat with the deployment of DNS over HTTPS.
- crb3 7y agoChrome already ignores OS-level name-resolution in favor of phoning home directly to Google DNS unless you block their IP#s at your border. I see it daily in etherape. Side-effect: Chrome users on my LAN have to type in IP#s to browse local resources because their browser ignores my dnsmasq, which resolves the split horizon.
- profmonocle 7y agoDo you mean Chrome or the Chromecast? The Chromecast totally ignores network-configured DNS and uses 8.8.8.8. The Chrome browser has its own DNS client, but it doesn't phone home to Google DNS - it still uses the DNS servers configured by the OS.
- arcticbull 7y agoAh perfect, not your keys, not your domain. I mean now domain jackings can be permanent and irreversible! Apple.com can literally be stolen by Tim Apple and there’s not a thing anyone could do about it. Another clear win for the blockchain. Resolving this kind of dispute is why we have central authorities in the first place.
- mopsi 7y agoThe dispute process is there to solve the kind of issues that do not exist in a fully automated domain name assignment systems. Fully automated system will only care about keys and cannot hand apple.com over from Apple Inc to Tim Apple because of his name.
- arcticbull 7y agoYou’ve got it backwards. When the keys are lost or stolen you’re SOL. The dispute resolution process would restore proper ownership via existing legal frameworks like it’s been done for hundreds of years.
- mopsi 7y ago> The dispute resolution process would restore proper ownership via existing legal frameworks like it’s been done for hundreds of years. Not if the owner lost all proof of ownership, which is the assumption your argument is based on.
- arcticbull 7y agoYou don't need proof of ownership to obtain a judgement in your favor. It would make the process easier to be sure but you can make the case based on historical ownership and other indirect proof that a judge will accept. You don't walk into a court and have the judge say "what you don't have the receipt?! case dismissed!!" -- the judge isn't a parking meter.
- troquerre 7y agoHandshake is trying to do exactly what you’re describing. It’s an alternative root of trust for DNS that uses a blockchain to secure names. One of the non-obvious security benefits is that you can store certs on the blockchain instead of relying on CAs, which is a source of failure in the security of the Internet today. Browsing adoption is tricky, but people can point their DNS to Handshake resolvers pretty easily — it’s equivalent to switching to ‘S 1.1.1.1 service which many people already do.
- jdnenej 7y agoHow could free domain names possibly work? Good domain names are scarce so of they were free someone could just write a script to register every good domain and then resell them. The yearly renewal fee means people tend to let go of domain names they no longer and never will use. The blockchain idea could work. There is a coin called namecoin which attempts to do this. I think on end user devices we should still use DNS so you don't have to store a 1tb blockchain on your device but the blockchain could be what the DNS servers source their data from.
- nine_k 7y ago(1) There exists a blockchain-based, decentralized DNS lookalike: https://handshake.org/ https://handshake.org/ (2) Every major OS has has a way to plug an alternative DNS resolver (except maybe iOS), and every major browser has a control to switch off the DNS-over-https resolver. With any goodwill from the major mobile OS vendors, a new resolver could be rolled out to 99% of consumer devices or so, and work transparently. (3) A new name resolution system should not clash with the DNS namespace. It could allow to copy established DNS domains (not parked) to the new namespace for a nominal fee. (4) Many DNS tricks, like load-balancing, could go away. Running your own name server can become harder. The transition, should it occur, would not be fast.
- byuu 7y agoAnything that doesn't work out-of-the-box is dead on arrival, though. I would never be willing to move my domain from .org to a system that people couldn't get to without installing additional software (eg OpenNIC.) But if every OS and/or every major browser supported OpenNIC, then I'd be willing to make the switch.
- nine_k 7y agoIndeed. My point is that supporting an additional name resolution system is mostly a political problem, and technically doable.without forcing people to even upgrade their OS, phone, or browser.
- vinniejames 7y ago"but a blockchain-like system could remove the central authority, the server costs, and the lawsuit risks" This already exists, check out [ENS domains](https://ens.domains/ https://ens.domains/) running on the Ethereum blockchain. They can be mapped to [IPFS](https://IPFS.io https://IPFS.io) hosted sites
- CodiePetersen 7y agoIn case anyone is wondering there is a blockchain that was made for such a reason. It's called namecoin. It spawned a project called chimera which was renamed xaya. In xaya the idea is you can reserve a name and the name has an alterable 2048 byte space for json data that you can update every block if you wish. Namecoin though has always been around to reserve names and in particular domain names.
- peterwwillis 7y agoYou're right that the technology is the very least of the difficulties. And that's the reason it won't change: nobody's going to do all the work of replicating all that bureaucracy just so there's even more organizations involved. The only way I can think to end the corruption is to take away the financial incentive, and AFAIK that would mean either the government runs anything that makes a profit, or to remove price completely.