3 ms·
What if no one gets "x3blah" and we each get some random string, e.g., an ed25519 public key. Handshake looks like it wants to create another "gold rush" for "
by x3blah 6y ago
What if no one gets "x3blah" and we each get some random string, e.g., an ed25519 public key.
Handshake looks like it wants to create another "gold rush" for "vanity" names. We have already had that. We have already seen how it plays out. It has been a while since I read through the Handshake docs. Are there limits on how many names a single applicant/organisation could register.
- tasuki 6y ago> What if no one gets "x3blah" and we each get some random string, e.g., an ed25519 public key. I think you end up with TOR! Names are just nicer, more convenient, easier to remember. > Handshake looks like it wants to create another "gold rush" for "vanity" names. I don't think that was the goal, but yes, this gold rush is already happening, even though it's not clear whether Handshake will ever receive any meaningful adoption. And I can understand why you find it distasteful. > Are there limits on how many names a single applicant/organisation could register. There aren't, and if there were, they would be easy to bypass.
- thinkmassive 6y agoHaha great point re: tor! You can even generate a vanity address using scallion. Of course, it’s subject to impersonation by a similar address if someone else wants it badly enough and has the hashpower to generate it. Personally I’m interested to see where Handshake goes. Thanks for your constructive comments on this article.
- oarsinsync 6y agoI can enter x3blah from memory. I can print it on a poster when promoting my service. I can't memorise AAAAC3NzaC1lZDI1NTE5AAAAIFwAU7Q9tccWIyPviJuzAatFIgQZVRr7mExznfbUR9Il. I can't print it on a poster when promoting my service. I can use a QR code, but that's ripe for exploitation. Someone can easily replace the QR code on my poster, and there's no way for anyone viewing the poster to know that it's not the correct QR code. What's the point of the name at all if it's not memorable? Or to put it another way, do you really want email address AAAAC3NzaC1lZDI1NTE5AAAAIFwAU7Q9tccWIyPviJuzAatFIgQZVRr7mExznfbUR9Il@gmail.com?
- squiggleblaz 6y ago> I can't memorise AAAAC3NzaC1lZDI1NTE5AAAAIFwAU7Q9tccWIyPviJuzAatFIgQZVRr7mExznfbUR9Il. I can't print it on a poster when promoting my service. I can use a QR code, but that's ripe for exploitation. Someone can easily replace the QR code on my poster, and there's no way for anyone viewing the poster to know that it's not the correct QR code. Which isn't a problem of the qr code, since you can't tell if someone replaced AAAAC3NzaC1lZDI1NTE5AAAAIFwAU7Q9tccWIyPviJuzAatFIgQZVRr7mExznfbUR9Il with AAAAC3NzaC1lZDI17TE5AAAAIFwAU7Q9tccWIyPviJuzAatFIgQZVRr7mExznfbUR9Il. At least you have a fighting chance of realising something is wrong when they say "x3blah has released a new album. Get it now from x4blah.com". Humans can only understand human understandable things.
- x3blah 6y agoIf the point of the domain name for you is marketing, then get one you think is "memorable" and use it as a CNAME. The point for me would be non-marketing uses, e.g., to get an SSL cert so I do not have to use a self-signed one when monitoring encrypted egress traffic from the local network. That name does not need to be memorable. I can get a free cert from Let's Encrypt but I cannot get free domain name. Best I can get for free is a subdomain of someone else's domain name. As you know, not every domain name is used for the purposes of email addresses or a website. To use a common example, AWS Cloudfront subdomains are not memorable but they are useful to AWS. Like subdomains, domain names can still be useful without being memorable.
- dependenttypes 6y agoThis is what tor/i2p do. It is honestly much better (it gets rid of CAs!) but you will get people screaming for "convenience", despite never typing a domain name themselves.