10 ms·
Handshake – Decentralized naming and certificate authority
- formerly_proven 4y agoMore salient question than "is blockchain DNS a good idea": How did they get this domain name?
- tnzk 4y agoI would have the same question if this was .com, but .org is somehow less dense.
- lionkor 4y agomoney
- RL_Quine 4y agoIf you think your scheme will result in a large return on investment you can spend a gigantic amount of money on a domain name and have it make sense. It’s how you have companies parading around with names like “crypto.com” and buying superbowl advertising.
- tiborsaas 4y agohandshake.org doesn't seem like a too rare find. It was unoccupied for a long time and nothing serious seems to be there before: https://web.archive.org/web/20220201000000*/handshake.org https://web.archive.org/web/20220201000000*/handshake.org My guess would be it was in the $3-8k range.
- daenney 4y ago> Handshake is a UTXO-based blockchain protocol which manages the registration, renewal and transfer of DNS top-level domains (TLDs). > The full node daemon, hsd, is written in Javascript and is a fork of bcoin. Personally, not the future I’m looking for.
- RL_Quine 4y agoSadly namecheap bought into this, so it’s being forced down the throats of people who don’t quite realize that the domains they can buy on the service can not, and will not ever be usable. It’s pretty obvious to even the most casual of observers that this is just yet another cryptocurrency scheme designed to fleece as many people as possible.
- cmeacham98 4y agoThis is very unfair to namecheap: 1. The search bar on their homepage returns no handbrake results 2. To get to those results in the first place you have to click on a 'Handbrake' tab (leaving the 'Domains' tab) 3. The search results link to an info page that clearly states "It's also important to note that handshake domains do not resolve in regular browsers without additional setup." For the record, I think Handbrake is a doomed project and a bad investment for Namecheap, but I don't think that means we can just accuse Namecheap of "forcing it down the throats of people".
- RL_Quine 4y ago> The search bar on their homepage returns no handbrake results That's sadly not correct. https://www.namecheap.com/domains/registration/results/?domain=&type=beast https://www.namecheap.com/domains/registration/results/?doma... For example using "beast mode" on the front page search, a good portion of the domains are "handshake" entries with only a tiny little (i) button to distinguish them from actual domain names which could be used in the real world. I can add them to my cart with no other mention that the product I am buying is a sham, I can even add a SSL certificate along with my purchase- which can't actually be issued because it's not a real domain name. > "It's also important to note that handshake domains do not resolve in regular browsers without additional setup." This feels like an incredible understatement. They will never be accessible by anybody who doesn't install software explicitly with that goal, they will never be able to receive email, nobody is going to issue SSL certificates for them.
- capableweb 4y ago
- p4bl0 4y agoAnother similar and interesting project, and which is not blockchain-based, is the GNU Name System: https://www.gnunet.org/en/gns.html https://www.gnunet.org/en/gns.html
- tux2bsd 4y ago> a secure, decentralized name system built on top of GNUnet. https://www.gnunet.org/en/install.html https://www.gnunet.org/en/install.html > It is largely not yet ready for usage beyond developers. Still in development, not ready for average joe.
- rvz 4y agoOut of the gate from [0], as soon as one tries to install it, they are met with this: Notice: GNUnet is still undergoing major development. It is largely not yet ready for usage beyond developers. On top of the Linux-focused attitude to this project (GNUnet, GNS, etc) which that is already limiting its usefulness and user friendliness to the average joe, if it is not available on other systems like Windows or macOS how does one even begin to use it? At the very least it should be accessible via a browser. For Handshake that is accessible with the Beacon Browser. [1] Ethereum Name Service (ENS) domains are accessible via Brave Browser, and Beacon Browser [1]. That gives the impression to general users that it actually works. [0] https://www.gnunet.org/en/install.html https://www.gnunet.org/en/install.html [1] https://impervious.com/beacon https://impervious.com/beacon
- eddieroger 4y agoIt's available for macOS via Homebrew. That option isn't even the last one on the list. I don't yet want to, but if I did, I could install this for macOS in minutes.
- fabco 4y agoThe problem they'll have is more and more TLDs are colluding with ICANN's, and Handshake chose to sell "TLDs", plus it is a proof of work blockchain. Dappy has a .d scoping at the top to avoid collisions, POS blockchain behind it, a co-resolution system (IP addresses and root certificates are always co-resolved), and it allows multi-ownership of names. Worth checking out https://dappy.tech/ https://dappy.tech/
- daenney 4y agoDid you mean colliding, as in overlapping? Colluding is cooperating in a secret/unlawful way.
- fabco 4y agoYes I meant colliding (sorry french here), Yes i'm lead developer of dappy project.
- jedimind 4y agoYou are missing a disclosure: "Disclosure: I'm the CEO/CTO of the project I am advertising"
- zokier 4y agoFor root replacement the biggest thing I would want is better use of the hierarchical nature of DNS. Trying to squeeze everything into mostly flat namespace is imho fundamentally intractable
- globalreset 4y agoHS is only for TLDs. After that it's a normal hierarchical DNS.
- lekevicius 4y agoI think name servers is one of the best applications for a decentralized ledger. It _can_ work without a central party, and I think it might be better without one. Something like .org controversy might not have happened without a central party.
- criddell 4y agoAfter watching what happened with cryptocurrencies, NFTs, etc... what gives you hope that building on a blockchain will go any better for name servers? Frankly, considering how critical the name server infrastructure is, I think it's been remarkably reliable and well run. The .org controversy was a big deal, but for the thirty years I've been online those types of problems stand out because they are so rare.
- _8j50 4y agoFrom a technical perspective it can. But how would you take down domains, resolve disputes like when your domain is taken over by attackers or a lookalike domain is defrauding users that are trying to get to your site. It isn't commercially viable without an authority everyone accepts for name revocation.
- 8organicbits 4y agoSome DNS revolvers filter results to protect against malware, malicious sites, or NSFW content. You can always add another layer on top of the blockchain that filters/censors based on your/your company's/your government's wishes.
- _8j50 4y agoYea but that is opt-in not opt-out. For example there are botnets that use specific domains, they get disrupted until they spread again when a domain or IP is taken down. The longer a credential phish stays up the more people are affected by it as well. If there is no way to ensure by default a domain is inaccessible when revoked it isn't a workable system for commerical applications.
- AndrianV 4y agoIf I could change one thing about root replacement, it would be for a more efficient use of the hierarchical structure of the DNS. The attempt to cram everything into a namespace that is mostly flat is, in my opinion, essentially intractable.
- andrew-jack 4y agoGood point about DNS.
- fabco 4y agoHandshake does use hierarchy like DNS (you can have any levels of subdomains behind the TLD), except it grants you access to the TLD level at affordable price, that is their main selling point. Whereas today you can only be under a TLD like .com or .us for an affordable price.
- kouteiheika 4y ago> Handshake uses proof-of-work mining Uh, no thanks. If you insist on using a blockchain at least don't make it proof-of-work. It's 2022, and there are plenty of production-ready non-PoW chains out there already. Please stop killing the planet.
- intothemild 4y agoI can't agree with this more.
- josu 4y agoPoW makes sense from a first principles approach [1]. I don't see Handshake growing into a trillion dollar network, so the security budget won't be that big, therefore I don't think it will be very energy intensive. Furthermore, if you calculate the economic impact of DNS hacks, the net impact of a decentralised PoW DNS implementation could even be positive. Wrt to non-PoW system, so far governance for those chains looks closer to a federation (where a few agents control the majority of the network) than to a really decentralised network. In that sense, a proof-of-stake DNS network wouldn't be that different from the current implementation. If such network ever takes off, I wouldn't be surprised if major ISPs, Cloudfare, Google, and a few other players end up owning the majority of the tokens. [1] Adam Back's 1997 Hashcash, designed to fight email spam and DDOS attacks was based on PoW.
- kenniskrag 4y agosmall PoW networks are prone to takeovers. E.g. one actor decidea to use his asics to take over the network for a few blocks.
- josu 4y agoThis is a solved issue with Merge mining. Here a primer: https://blog.bitmex.com/the-growth-of-bitcoin-merge-mining/ https://blog.bitmex.com/the-growth-of-bitcoin-merge-mining/
- 4y ago
- lizardactivist 4y agoA very big security problem with current domain certificates is that browsers accept any certificate for any domain, as long as they trust the issuer. There is no concept or notion of who is supposed to have issued the certificate.
- dotancohen 4y agoHow would that work? Add another DNS record? It would have to be out of band as the server cannot be trusted (see HPKP), and DNS itself could just as easily be MITMed as an HTTPS request, often even moreso.
- lizardactivist 4y agoUltimately I suppose it would have to involve some pre-shared key. It could be made tolerable with a browser addon holding entries for critical websites. But maybe the mentioned CAA has already solved this.
- aaomidi 4y agoThat’s what CAA records are for, and the enforcement is happening before it gets to the end user by the various root programs.
- rhyselsmore 4y agoCertificate Transparency Logging allows you to view the issuances of certificates. CAA records provide some extra defence (https://en.m.wikipedia.org/wiki/DNS_Certification_Authority_Authorization https://en.m.wikipedia.org/wiki/DNS_Certification_Authority_...). It’s not perfect, but it’s getting better.
- tialaramex 4y agoSpecifically the purpose of CAA is to enable a subscriber (say, the owner of ycombinator.com) to tell trustworthy Certificate Authorities thanks, but no thanks. It is not a message for anybody else. If you're not a CA you don't need to read CAA records. For example, say you're Facebook, you've got an arrangement with DigiCert where on top of the Ten Blessed Methods of the Baseline Requirements, DigiCert promises to go exclusively through a six man "Certificate management" team at Facebook for all .facebook.com and .fb.com names. Even if Marketing really wants coca-cola-advert.facebook.com they can't get a certificate without an OK from that six man team. Well, (and something similar really happened years ago) the deal you cut with DigiCert doesn't magically apply to every other CA. The Baseline Requirements do, but not your custom deal, so other CAs don't need to know about your rules and may issue coca-cola-advert.facebook.com certificates to the marketing guys who've set up the coca-cola-advert.facebook.com web site just obeying the Ten Blessed Methods. CAA records are in the Baseline Requirements, and so Facebook can write a CAA which says "Only DigiCert may issue". And if you look with your preferred DNS querying tool, that is exactly what they did. CAA for facebook.com is 0 issue "digicert.com" If you posit that there are crooks at some other CA issuing bogus certificates, CAA doesn't stop that. The crooks can ignore such a rule, the same way a crook can ignore the "Employees only" sign on a door. But, we can see what the public CAs are doing, so, if any of them are crooked we can notice that and kick them out. For the most part humans, including those running a CA, can be lazy and incompetent but they aren't malevolent.
- eptcyka 4y agoThe person who forced themselves into ownership of freenode is closely associated with this dumpster fire.
- rasengan 4y ago
- eptcyka 4y agoProjects moving forward towards obscurity and uselessness? What's going on with the website for freenode? Regarding lies, your story seems highly unlikely, and the communities have already made a decision. Sleep well knowing that having access to boundless finances does not make one a useful and well regarded person.
- superkuh 4y agohttps://www.linuxjournal.com/content/vcs-are-investing-big-new-cryptocurrency-introducing-handshake https://www.linuxjournal.com/content/vcs-are-investing-big-n... (https://archive.is/IK7w8 https://archive.is/IK7w8) >Just released, Handshake brings with it the much needed security and reliability on which we rely... The project and protocol has been led by Joseph Poon (creator of Bitcoin's Lightning Network), Andrew Lee (CEO of Purse), Andrew Lee (founder of Private Internet Access or PIA) and Christopher Jeffrey (CTO of Purse). This is far more than just someone who donated some money. The claims of guilt by association here are not just association. Andre Lee was 1 of the 4 people leading the project. He'll no doubt continue with the above disengenous BS but the facts are there for anyone that lived through it or who cares to look.
- deleted 4y ago[deleted]
- _8j50 4y agoMerely supporting it or in leadership role? Either way...
- judge2020 4y ago
- rvz 4y agoThis is the only rare valid use case and need for a blockchain given the seizure of TLDs like what happened to .org [0] recently. It's very interesting to see Namecheap, Gateway.io, Encirca, etc use it and its very surprising to see some ICANN TLDs being claimed on Handshake. [0] https://news.ycombinator.com/item?id=21611677 https://news.ycombinator.com/item?id=21611677
- noname120 4y agoI agree. I'm not very convinced about the upside-downside ratio of this implementation though But it has the merit of being a blockchain use that isn't complete non-sense.
- SkyMarshal 4y agoWhat do you mean by upside-down ratio?
- rajman187 4y agoA very similarly named startup that seeks to help college students find their first opportunities https://www.crunchbase.com/organization/handshake-2 https://www.crunchbase.com/organization/handshake-2 Meanwhile, the claims on this website: > Email became Gmail, usenet became reddit, blog replies became facebook and Medium, pingbacks became twitter, squid became Cloudflare, even gnutella became The Pirate Bay While not even accurate, these centralized services became popular and synonymous with their underlyings due to convenience and benefits (eg gmail offering massive storage when it first rolled out; FB deploying its newsfeed which other social media platforms didn’t have at the time; etc) > True decentralization, no official singular Foundation, Committee, Corporation, or entities in permanent unitary control of the protocol. And what happens when something inevitably goes wrong without any kind of oversight? Who can course-correct if it has succumbed to say a 51% attack > Economic incentives enable decentralized agreements to form via a transparent name auction process. And so beholden to the same hyperfinancialization principles we see now—bid higher to get your blocks mined quicker. Not to mention the 700% spike in fees we saw not long ago. Add in proof of work and you’ve now got potentially very long waiting times as well, further incentivizing the pay for speed mentality
- mavhc 4y agoMostly just shows that open systems require more resources to develop at as rapid a pace as closed systems. Email/Usenet were fossilised the day they were born pretty much, we're still living with stupid fixed width lines of text in 2022, people just gave up on replying correctly, and no one could fix usenet spam. Web apps have instant new version deployment, but are centralised, automatically updating docker containers are probably a half decent solution to a federated network. The most popular website creation system is Wordpress though, that's mostly open and decentralised
- deleted 4y ago[deleted]
- whatisweb3 4y agoApplication-level protocols should not be attempting to secure their own consensus mechanisms - it ties the security of the application to the base token. If you are seeking decentralized naming and certificate authorities you can look at Ethereum and ENS. Besides the eventual transition to Proof-of-Stake, building an application on top of an existing consensus mechanism means that your application will inherit the security of that blockchain.
- easrng 4y agoIt's not possible to make a lightweight ENS resolver that doesn't fully trust the Ethereum node it's using.
- whatisweb3 4y agoTrue, even though a current "light client" can run on Raspberry Pi, really there should be even lighter clients for validating on-chain state. See [1] which is an area of development. [1] https://nimbus.team/docs/fluffy.html https://nimbus.team/docs/fluffy.html
- substation13 4y agoWhatever happened to Namecoin?
- noname120 4y ago> Email became Gmail, usenet became reddit, blog replies became facebook and Medium, pingbacks became twitter, squid became Cloudflare, even gnutella became The Pirate Bay How is that even remotely related to creating a new domain name service? Does the author really believe in good faith that the centralization of platforms would somehow be reduced or disappear entirely by introducing a new domain name service? This will literally not change anything. It's not because Facebook started owning facebook.com that they magically became a dominant platform.
- heywoodlh 4y agoI wouldn't expect someone named noname120 to understand the need for a new naming service. (Just kidding, I totally agree with your point)
- noname120 4y agoHaha you made me laugh! My nickname comes from a throwaway account that I created when I was 8 years old. By an unfortunate series of events it sticked in :)
- blamestross 4y agoIt is worth pointing out the distributed systems tend towards centralization over time. Keeping things decentralized is always going to be an active effort. Fundamentally decentralized vs centralized is also robustness vs efficiency. Anybody with a short returns horizon that hasn't been burned yet prefers efficiency.
- jedimind 4y agoIt is also worth pointing out that centralized systems tend to drive people towards wanting decentralization over time, since it's only a matter of time until individuals get burned by the arbitrary whims of the rulers over centralized systems. I never took such arguments seriously myself until my bank refused service to me without giving me any reason for it. Treating honest customers like criminals is exactly how people start distrusting centralized systems and their untrustworthy authority. In the dns/icann sphere there are also countless factors[0] that are evidence of this, not even talking about the dns hacks[1] or clear cut corruption of icann or censorship attempts.[2] So it's not only about robustness vs efficiency, but also about additional factors like ownership and freedom + security et cetera. [0] https://www.politico.com/news/2022/04/09/website-domain-more-expensive-00023524 https://www.politico.com/news/2022/04/09/website-domain-more... [1] https://threatpost.com/unprecedented-dns-hijacking-attacks-linked-to-iran/140737/ https://threatpost.com/unprecedented-dns-hijacking-attacks-l... [2] https://arstechnica.com/tech-policy/2022/03/ukraine-wants-russia-cut-off-from-core-internet-systems-experts-say-its-a-bad-idea/ https://arstechnica.com/tech-policy/2022/03/ukraine-wants-ru...
- XorNot 4y agoGod why is this blockchain? If I want to decentralize naming then I want to get away from IANA as the exclusive authority top down, but what it means is I want a reputation/selective trust system not some PoW trash. i.e. "are you my bank?" It's a question I want answered specifically, in a cryptographically secure fashion by my local government well-known authority, and then my bank. "Are you the local resistance leaders?" is a question I want answered by a chain of signed pseudonyms with set of revocations being published frequently through anonymous channels. In both cases, details like "how are TLDs assigned?" should ultimately be in my control, with a convention to establish "normal" practice. One of those use cases shouldn't be wasting my money running GPU miners, and one of them can't.
- felixbennett 4y agoWhy you all dissing HNS? Shit's awesome
- mattwilsonn888 4y agoThe over specification of use case should be a big red flag. Any self-sustaining open and decentralized network capable of hosting a name service will be capable of pushing and storing arbitrary data around - the fact that data can have an owner is core to blockchain, so it's extremely dubious even without digging very deep that Handshake offers something you can't find in a more general platform. It is also worth noting that the coins behind this project have been mined since February 2020. https://e.hnsfans.com/blocks?page=6517 https://e.hnsfans.com/blocks?page=6517 Particularly for any use case where it is important that any user in all circumstances has access to data, it is really important to avoid centralizing forces present in Bitcoin and Ethereum - they were designed to secure blocks, not to secure open access, as plainly evident by their consensus mechanisms which do nothing explicit to reward the routing of data into the network. This results in sub-optimal outcomes for data routing, but optimal outcomes for producing hash power or collecting large staking pools. If you are seriously interested in a platform which incentivizes and is based around open access and leverages that to gain better security guarantees (time-stamping, public key cryptography, exchange of value) at scale than Bitcoin or Ethereum, read about Saito and its economic foundations.