9 ms·
Show HN: No Signup, Yet, Authenticated Posts
- deleted 5y ago[deleted]
- publiush 5y agoI was browsing Handshake repos on github and noticed a pull request that added sign/verify [1] on the Bob Extension [2] on Github. This piqued my interested, and of course, it was time to hack away again. The result is applause [3] which lets you post and applaud (sign) your and other people's messages. This website does not require a login or signup because it uses the decentralized Handshake [4] blockchain. It's open source on github [5] and mixes Web 2 and Web 3 together causing some interesting benefits. It supports drag and drop among other things! Hope you like it! MIT LICENSED! Do whatever you want with it! [1] https://github.com/kyokan/bob-extension/pull/15 https://github.com/kyokan/bob-extension/pull/15 [2] https://github.com/kyokan/bob-extension https://github.com/kyokan/bob-extension [3] https://applause.chat https://applause.chat [4] https://handshake.org/ https://handshake.org/ [5] https://github.com/publiusfederalist https://github.com/publiusfederalist
- deleted 5y ago[deleted]
- sneak 5y agoIs the domain brand (less than 24h) new? It's not resolving yet for me (I have extremely new domains blocked via NextDNS).
- phnofive 5y agoNot quite, but nearly: > Name: applause.chat > Internationalized Domain Name: applause.chat > Registry Domain ID: 1deb3f28409a44cb92dcf6ad12b77b70-DONUTS > Domain Status: > clientTransferProhibited > addPeriod > Nameservers: > ns1.linode.com > ns2.linode.com > ns3.linode.com > Dates > Registry Expiration: 2022-12-29 02:01:19 UTC > Updated: 2021-12-29 02:07:14 UTC > Created: 2021-12-29 02:01:19 UTC
- dopidopHN 5y agoI get a CRSF error on posting. At the same time my login is not present in the handshake chain, that would make sense.
- stavros 5y agoSemi-offtopic, does anyone know if I can hold my own Handshake domains (instead of using Namebase), perhaps with Ledger integration?
- wccrawford 5y agoSo is it just people shouting out to the void, and no way to respond to them? That makes it a neat tech demo, but doesn't seem very useful as-is.
- publiush 5y agoThis is an excellent question. This is different from a website like Hacker News or Reddit which aim to be social media websites and avenues to engage in discourse. Applause, instead, is as you might say, a tech demo, but also aims to, through UX and feature, create a different kind of environment than general social media networks. Instead, when a user engages in the act of 'signing' something, people can either agree in whole or not. If they agree in whole, they actually sign the original message itself. It's closer to a "shouting out to the void in a certified manner, and others can join in the shout" versus "shouting out to the void and debating."
- wongarsu 5y agoFrom the name I was expecting something like image boards (think 4chan) where you can add a username to your post by specifying a secret, which will set your username to substring(sha(secret)). Instant authentication with no signup. This isn't that, instead it seems to delegate the registration to some Namecoin-like thing, and I verify my identity but signing the content with my secret key? Did I get that right? I guess the advantage of that approach are human readable user names
- publiush 5y agoYou hit the nail pretty much on the head. While you're correct that a 4chan-like mechanism would provide a means of authentication, the hash would not be human-recognizable easily (basically, not meaningful). Using a naming block chain like Handshake, you essentially solve Zooko's Trilemma [1]. [1] https://en.wikipedia.org/wiki/Zooko%27s_triangle https://en.wikipedia.org/wiki/Zooko%27s_triangle
- sombremesa 5y ago> While you're correct that a 4chan-like mechanism would provide a means of authentication, the hash would not be human-recognizable easily (basically, not meaningful) This part can be addressed easily with avatars such as those Gravatar makes. Using a blockchain instead seems like a huge overkill, and also brings 'login' back into the equation, albeit with a different connotation than traditional login.
- deleted 5y ago[deleted]
- publiush 5y ago> This part can be addressed easily with avatars such as those Gravatar makes. Using a blockchain instead seems like a huge overkill, and also brings 'login' back into the equation because most websites will use something like Metamask, which you have to log into. A gravatar is great for a profile photo, but in the end, there's no guarantee that the message viewed by a user was actually written by the poster. A site admin could simply inject posts as that user. With signed messages, only those who possess the key could have created the signature for the signed message. Even a site admin cannot edit the message and get away with it (since the signature wouldn't validate).
- ramphastidae 5y agoWhat am I supposed to enter for the signature? Is there a help page?
- publiush 5y agoYou can either use Bob Wallet [1] or hsd RPC. You'll need a Handshake [2] name as well. There's a PR on the Bob Extension that streamlines this process (think metamask) [3]. [1] https://applause.chat/v/9 https://applause.chat/v/9 [2] https://handshake.org/ https://handshake.org/ [3] https://applause.chat/v/5 https://applause.chat/v/5
- afro88 5y agoSounds way more complex than a traditional sign up? What am I missing?
- publiush 5y agoI think where we're headed is a blend of Web 2 and Web 3 (Web 666). In this, Web 2 continues to live on in its current form, because it works quite well. However, there are some issues with Web 2 that Web 2 can't easily solve that are solved by Web 3. One of the biggest ones is decentralized identity which Handshake solves beautifully. With signed strings tied to the keys associated with the handshake name, every action taken on a Web 2 website can now benefit from being verifiable [1]. You don't need the blockchain outside of the identity. Secondly, the more I've been working with this technology, the more I've truly begun to understand how important it is to own one's name. There shouldn't be two afro88s. Imagine if there is an afro88 on reddit and this person starts acting a certain way -- and then someone comes here and they see your username and apply bias due to actions that were not your own? Web 666 is a silly name for blending the "stacks" if you can call them that, together, but then again... [2] [1] A reddit admin edited a user's comments. Imagine if that user was suddenly prosecuted on said "evidence?" What a shame, and cryptographic signatures really empower people on the internet, especially in a Web 2 world. [2] https://en.wikipedia.org/wiki/Lucifer_(cipher) https://en.wikipedia.org/wiki/Lucifer_(cipher)
- skybrian 5y agoMaybe it's not technically a sign up, but the new user flow needs some work. There are boxes for "handshake name" and "signature" but no indication of what you should put there. I tried leaving them blank and got an error message: "You need to include a valid Handshake name and signature generated with the key associated with the name." But it doesn't explain how you do that.
- publiush 5y agoI apologize for that. There was an assumption that most people were aware of the Handshake Naming system [1]. Handshake is a naming blockchain that's recently been gaining adoption quickly (Namecheap [2]) (Opera Browser [3]). Using this, you can control your name, which is your identity, on the internet. There's a lot of other cool benefits, but as it pertains to this project, it's the names, cryptographic proof of ownership of said names, and the cryptographic provability that the messages were written by the owners of said name. There are many ways to get Handshake names, but the easiest ways are to use Bob (non custodial) [4] or Namebase (custodial) [5]. [1] https://handshake.org/ https://handshake.org/ [2] https://www.reddit.com/r/handshake/comments/pt55vb/namecheap_the_second_largest_domain_registrar_in/ https://www.reddit.com/r/handshake/comments/pt55vb/namecheap... [3] https://twitter.com/opera/status/1476841607005622273 https://twitter.com/opera/status/1476841607005622273 [4] https://github.com/kyokan/bob-wallet https://github.com/kyokan/bob-wallet [5] https://namebase.io https://namebase.io
- jakear 5y agoSo handshake.org seems to be the authoritative source on everything handshake, and it has several lengthy posts describing how using anything but it and things it vouches for to interact with handshake is about the absolute dumbest thing a person could possibly do [1]. And while namebase.io looks like it might provide an incredibly intuitive "getting started with handshake" experience, it's not vouched for by handshake.org. Can you explain why using namebase.io to mint a handshake name isn't the dumbest thing I could possibly do? [1] https://handshake.org/claim/ https://handshake.org/claim/
- 5y ago
- andrewstuart 5y agoI once created a SAAS application that did not have the "ordinary" workflow that people expect these days - email/password or social login. People hated it and actually took the time to complain. The lesson for me - make your auth process precisely what people expect - if there's feedback, it should be about your product, not about the signup process. Signup process is not a feature - it's plumbing. In the case of this new product / service - I note the headline is almost unrelated to what the product does - it's a headline about how the auth works on this - the technology something is built with shouldn't be the marketing message.
- publiush 5y agoThis isn't a marketing message/post. This is a Hacker project to explore improved ways of doing things with the new primitives of our collective technology base. In this case, owning your own identity with a decentralized identity system. I think marketing posts are better suited for another forum, no?
- Handytinge 5y ago100%. I'm sure GP had good intentions here, but productisation of any project is a big part of what's wrong with tech today.
- publiush 5y agoI agree that the intentions were pure. That said, this isn't a product, but instead, a project with a specific goal of improving internet security by showcasing concepts to the HN community. The discussion within the thread, I think, is indication that it is helping to inch closer to that goal as more users on HN are made aware of the beneficial tools cryptography with Handshake provides.
- andrewstuart 5y ago>> I think marketing posts are better suited for another forum, no? No, Hacker News "Show HN" posts are often launch/marketing posts - totally accepted here.
- kc10 5y agoThis isn't truly no signup right? I only saw the handshake now, but isn't my handshakeName+signature my new username and password for posting? Instead of having a centralized auth provider, the blockchain is used to authenticate the signature? Just looking at Handshake - if I buy HNS and purchase a domain, sure I can use the handshakeName and signature to authenticate to supported websites. But if I want to host a website with the domain, the possible options are using hns.to domain or have my DNS point to a different DNS server. Both are not viable options for my end users to reach my website. Is the expectation that overtime Handshake gains popularity and all existing services would have a mechanism to integrate into this?
- deleted 5y ago[deleted]