8 ms·
Zooko's Triangle
- deleted 6y ago[deleted]
- fsflover 6y ago> Several platforms implement refutations of Zooko's conjecture, including: Twister (which use the later Aaron Swartz system with a bitcoin-like system), Blockstack (separate blockchain), Namecoin (separate blockchain),Monero OpenAlias[5] and Ethereum Name Service. Another implementation is the I2P Address Book, https://geti2p.net/en/faq https://geti2p.net/en/faq.
- bitxbitxbitcoin 6y agoYet another is Handshake.[0] Which Zooko himself welcomed to the world.[1] [0] https://handshake.org/files/handshake.txt https://handshake.org/files/handshake.txt [1] https://twitter.com/zooko/status/1025211998840086528?s=21 https://twitter.com/zooko/status/1025211998840086528?s=21
- bob1029 6y agoHow would git not be a clear refutation of this conjecture? Sure, commit hashes are very high entropy identifiers, but we can still derive a lot of meaning from what they implicitly represent. Git is also a decentralized protocol. Perhaps the "authority" in these cases is whoever happens to be approving & merging a pull request? Has anyone reversed a SHA256 hash on a reliable basis yet? Does this count as secure & distributed? Perhaps my argument here is that high entropy and human meaning are not at odds with each other. This seems like a very subjective point on the triangle.
- zelly 6y agoYou still need some way to distribute the git commit hashes so it's TOFU and less secure than Bitcoin.
- garmaine 6y agoGit doesn’t have pull requests.
- bob1029 6y agoAgreed - Pull Request was a bad example to use. You can still effectively achieve the same thing in a decentralized manner (i.e. without GitHub).
- garmaine 6y agoI’m not sure you can achieve the same thing without some sort of external name/trust system, which is entirely the point.
- flotzam 6y agohttps://git-scm.com/docs/git-request-pull https://git-scm.com/docs/git-request-pull
- garmaine 6y agoThat generates an email, which you then have to send via MX records in the domain name system. Which pushes the "human-meaningful" part of the Zooko triangle onto another system. Now we're not having a conversation about git, but a conversation about DNS and email authentication (which has traded off decentralized).
- olah_1 6y agoIt’s clear to me that human-meaningful is the one to drop. Status messenger has a nice naming solution. They give everyone a three-random-word name when they join (an Ethereum pub key is under that of course). Then (1) your friends can assign to you their own nickname for you, or (2) you can buy an ENS name that is globally findable. I think of this basically like car license plates. You can optionally get a vanity plate. Another project that I love is BrightID. It really embodies the idea that we don’t actually need a global registry of names for most use cases. Most of the time we just want to know if someone is legit or not. A web of independent Rolodexes is enough to determine that.
- thingification 6y ago"your friends can assign to you their own nickname for you" is "petnames": http://skyhunter.com/marcs/petnames/IntroPetNames.html http://skyhunter.com/marcs/petnames/IntroPetNames.html Quote: Though no single name can have all three properties, the petname system does indeed embody all three properties.
- olah_1 6y agoYeah it's not a particularly groundbreaking concept. It has existed for as long as people have kept personal address books. Another implementation is in Secure-Scuttlebutt. But those "petnames" are actually gossiped around by default (which I would argue is not very intuitive for people).
- andrewflnr 6y agoBrightID is... interesting. The idea is to ensure that each physical human has at most one Bright ID account by using social verification, right? I can't figure out from a quick skim of https://brightid.gitbook.io/brightid/getting-started https://brightid.gitbook.io/brightid/getting-started how they prevent you from getting multiple accounts by getting verified through two or more disjoint social groups.
- olah_1 6y ago> I can't figure out how they prevent you from getting multiple accounts I'm not sure about that, to be honest. One thing to keep in mind though is the importance of validating identities in person. I think you get higher trust by scanning each other IRL. So a whole network of anonymous avatars could "connect", but it would be rare for them to scan each others' devices in person. I would imagine that most people would simply lack the energy to go through the whole process with two different devices. So on-the-whole, the anonymous avatar style network would be less trustworthy algorithmically. This is probably a question worth asking them https://twitter.com/BrightIDProject https://twitter.com/BrightIDProject
- flemhans 6y agoWhat is the generic name for these triangles where you can "select any two" but never have all three?
- StavrosK 6y ago"StavrosK's triangle".
- dTal 6y agoWho is to say that it isn't? If only we had a secure, decentralized system for mapping human-meaningful names to things...
- espadrine 6y agoA trilemma.
- sillysaurusx 6y agoThis is absolutely hilarious and made me laugh really hard for some reason. Thanks. I'm using this term forever.
- Jtsummers 6y agohttps://en.wikipedia.org/wiki/Trilemma https://en.wikipedia.org/wiki/Trilemma Coined in the 1600s, most likely. Can be used one of two ways: 1. A choice between 3 unfavorable options where you must choose one (lose your arm, your leg, or your other arm). 2. A choice between 3 favorable options where you can only choose two (the typical ones we see discussed/posted here).
- ovi256 6y agoOne can observe that the first is a special case of the second, through the transformation of negation ("choose which two of your arm, your leg or your other arm to keep"). We can unify both under this system.
- genpfault 6y ago> .onion addresses and bitcoin addresses are secure and decentralized but not human-meaningful I thought that's why you burned some CPU hunting for 'vanity' addresses[1]? [1]: https://opensource.com/article/19/8/how-create-vanity-tor-onion-address https://opensource.com/article/19/8/how-create-vanity-tor-on...
- bitxbitxbitcoin 6y agoA vanity address is only human-meaningful up to a certain point in the string. Not really memorizable.
- tialaramex 6y agoWhat matters in practice is mostly by whether people memorize it. People choose to memorize Pi and the list of dictionary headwords (to play Scrabble, you don't need to speak or even read the language, just know all the valid words) Once upon a time people would memorize telephone numbers of friends and people they call often, not so much now. During the pandemic my gaming group uses Google Meet, some things use Zoom, we began having Friday evenings in Jitsi and we moved them to Gather Town. Zoom is the only one that is resolutely impractical to memorize, every Zoom meeting gets a random huge ID and password, so you need to pass around lengthy nonsense URLs for each meeting and even then you might also need to share the password. This is done in the name of "security" although it isn't actually more secure than... Jitsi takes arbitrary long strings to distinguish one conference from another, defaulting to generating word salad. So you tell everybody you're in "CloudsEffortlesslyChaseMushrooms" and joining creates it. If you want to name one "SecretHackerNewsRoom" you can, but I think somebody might guess that name. Google Meet uses shorter, random IDs. You can't mint your own, and by contrast to word salad they're tricky to remember, but you can re-use them, and after a while your mind remembers ZWC-KLWL-CBMB or whatever because it's the same every week. Also your browser will auto-complete it, if you have that turned on. Gather Town allows you to build and name custom places. Since you're customising them anyway, you get to name them. If you call it "RedLionPub" I'm guessing you might get uninvited guests. If you instead reference an inside joke ("TerramicDragonHouseOFish" or "InstantMonkeyDispatch") not so much. However there is an ID number baked into the URLs, and I don't know if there's search, so you'll likely end up memorizing or bookmarking URLs for a place you go often.
- samdung 6y agoHuman-meaningful. Secure. Decentralized. Choose any TWO.
- PeterWhittaker 6y agoWell, we don't have human-meaningful names even now, at least not for most humans - for us technology types, sure, but if the names were truly human-meaningful, we'd have far less ...ibm.com.cn style of phishing, e.g. A few commenters make the point about phone numbers and IP addresses being somewhere between analogous and homologous. I think that's true for IPv4, but definitely not for IPv6. But that misses an unexpected benefit of the DNS: Traffic management based on geolocation. Even without human-meaningful names, nickname to address translation would have benefit for that reason alone. As others have pointed out, we don't so much need a name service, we want a reputation service. After all, most people get to web sites, e.g., via a bookmark or embedded URL or a search result. If we got rid of the DNS and had to enter IP(v4, not v6) addresses by hand, a lot of us would still get there via bookmarks or embedded URLs or search results. Little/nothing would change. I'm not suggesting redesigning the Internet with a dedicated search engine layer in our not-7-layer stack, but I do think the differences between current use and design intent are significant enough, even if sometimes subtle and unforeseen, that a rethink could take us to interesting places. (My favourite part of the article are the counter-examples. So the triangle is itself wrong, generally, and only correct, more or less, for specific technical approaches.)
- evbots 6y agoThere are a few blockchain based solutions to this problem. - Handshake - ENS - Namecoin My favorite so far is Handshake - a fork of the bitcoin protocol with added support for covenants, which is how arbitrary names can be registered and associated with some 512 bytes of data. Example: https://hnsnetwork.com/names/proofofconcept https://hnsnetwork.com/names/proofofconcept which shows TXT and other records. ENS was previously my favorite, but the root protocol is secured by only a 7 person multisig. Namecoin is old and poorly designed in my opinion.
- scubbo 6y agoIt was via Handshake that I came across this concept (though I heard it as "Zooko's Trilemma") a few months ago! Handshake indeed looks pretty cool and interesting. I bought-in enough to register both my real name (firstnamelastname) and commonest online handle, but I haven't found time to actually do anything with them. I should make a personal web site. I should do a lot of things.