3 ms·
Interesting you mention hijacking, only yesterday Curve’s .com DNS was hijacked and users lost funds as a result[1]. This is also possible with ENS but ownershi
by whatisweb3 4y ago
Interesting you mention hijacking, only yesterday Curve’s .com DNS was hijacked and users lost funds as a result[1]. This is also possible with ENS but ownership can be secured more easily, two ways this could be approached:
1. ENS ownership is held by a 5-of-7 multisig. Attacker would need to socially engineer 5 entities instead of just one, Namecheap. Users can also clearly see when ENS ownership changes as it’s broadcast to the network.
2. ENS is set to a 100 year expiry and ownership records are then set to the burn address. Now, short of faulty RPC or frontends, there is no way that the domain can point to a different address.
My previously linked example was that of Meta entering into a court battle with a domain name registrar, who has full control over these records and may decide to alter them to avoid paying the cost of defending themselves in court. See [2] which is loosely related to this discussion of centralized services exerting control over name aliases. In a hypothetical blockchain application where usernames are secured with ENS or another smart contract, there would be limited recourse for anybody except the owner of these aliases to be able to transfer ownership.
[1] https://coingape.com/crv-tanks-over-10-as-attackers-stole-570k-from-curve-finances-users-wallets/amp/ https://coingape.com/crv-tanks-over-10-as-attackers-stole-57...
[2] https://www.nytimes.com/2021/12/13/technology/instagram-handle-metaverse.html https://www.nytimes.com/2021/12/13/technology/instagram-hand...