4 ms·
The central criticism of ENS in this blog post - that the multisig (in the past) or the DAO (now) could take away your .ETH name - is not true. No one has the a
by bcmillegan 5y ago
The central criticism of ENS in this blog post - that the multisig (in the past) or the DAO (now) could take away your .ETH name - is not true. No one has the ability to take a .ETH name away from someone. The DAO (which launched Nov 8, not Nov 10 as it said), wasn't created to take over that power from the multisig because the multisig didn't have that power either. The multisig does manage the ENS root, but the .ETH TLD is permanently locked.
Re the fact the DAO controls the pricing and registration parameters of .ETH names, it's true that it would be possible for the DAO to change them to something that targets a specific user or name. The DAO cannot take away a .eth name that is registered (it could only make it difficult or practically impossible to extend or register anew). To guard against this, a user can pay ahead for as many years as they want, ensuring they have the name for that period (e.g. 100 years). Given that DAO proposals have required voting periods, it wouldn't be possible to surprise this on someone, and they'd be able to simply extend their registration for 100 years (or whatever period they want) before it went through. As you mention, the ENS constitution also prohibits it. I find this attack vector extremely unlikely to be attempted and near impossible to carry out successfully.
There's more I could say, but I think these were two main points.
- yanmaani 5y agoI responded to this by e-mail, but I'll put it here as well: > The central criticism of ENS in this blog post - that the multisig (in the past) or the DAO (now) could take away your .ETH name - is not true. No one has the ability to take a .ETH name away from someone. The DAO (which launched Nov 8, not Nov 10 as it said), wasn't created to take over that power from the multisig because the multisig didn't have that power either. The multisig does manage the ENS root, but the .ETH TLD is permanently locked. But I do not, in fact, state this: "ENS is censorship-resistant in the sense that nobody can directly seize your domain." > Re the fact the DAO controls the pricing and registration parameters of .ETH names, it's true that it would be possible for the DAO to change them to something that targets a specific user or name. The DAO cannot take away a .eth name that is registered (it could only make it difficult or practically impossible to extend or register anew). Now see, I would personally contend that "mak[ing] it difficult or practically impossible to extend or register" is a form of censorship. > To guard against this, a user can pay ahead for as many years as they want, ensuring they have the name for that period (e.g. 100 years). Well, if you assume that the registration fee never is increased above $5, sure. This also raises the question of why to even bother with expiration at all, other than as an opportunity to extract more rent. Likewise, if people will just go out and buy the names for two thousand years whenever the renewal fees go up, this raises the question of why you would even bother and not just grandfather the old names in. (I mean, I suppose for throwaway names or trivial fee hikes, but it's not entirely obvious) And I can still see some attacks about that business. For example, you start off by raising the fee to $6. Assuming this doesn't trigger them to buy it for 100 years, you raise it to $7, and so on. By the time the fee has reached let's say $100 p.a., hedging for 100 years would cost $10k, which is not exactly pocket money. And at that point, you can raise it even higher, etc. Also, on an aesthetic note, having to register names for 100 years because the renewal can be pulled out from under your feet at any time seems like somewhat of a kludge. (All this assumes nothing gets migrated, as happened in <https://docs.ens.domains/ens-migration-february-2020/technical-description https://docs.ens.domains/ens-migration-february-2020/technic...>. Based on the high degree of centralization inherent to ENS, my money is on this being an easier process than it ought to be.) > Given that DAO proposals have required voting periods, it wouldn't be possible to surprise this on someone, and they'd be able to simply extend their registration for 100 years (or whatever period they want) before it went through. If I'm reading this right, the voting period is either 9 or 14 days: https://docs.ens.domains/v/governance/process https://docs.ens.domains/v/governance/process Are you suggesting people keep a close eye on the voting process of the infrastructure that controls their domain? If so, would you say that them feeling necessitated to do so indicates confidence in this infrastructure? > As you mention, the ENS constitution also prohibits it. Ah yes, but does it prevent it? > I find this attack vector extremely unlikely to be attempted and near impossible to carry out successfully. Well, a lot of people thought it would be unlikely for Ethereum to pull of a hardfork to override the steadfast iron will of unstoppable code, but here we are. In the end, it's not about what you think, but about what actually happens. What happens when someone registers and actually starts using dailystormer.eth, causing a rash of bad headlines and the token price to drop precipitously? In the end, there's only one way to find out: Every man's work shall be made manifest: for the day shall declare it, because it shall be revealed by fire; and the fire shall try every man's work of what sort it is.