Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
schanzen
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
31.
▲
by
schanzen
5y ago
The resolution mechanism is decentralized. Zones are published and resolved through a peer-to-peer mechanism with the goal of preventing censorship and allow for query/response privacy. Is the namespace decentralized? That depends on h
32.
▲
by
schanzen
5y ago
On the other hand what is the alternative? The current blockchain/dlt hype is built on top of technology that severely impacts its security promise ( https://btc-hijack.ethz.ch/ ). The reason why gnunet appears to be &qu
33.
▲
by
schanzen
5y ago
Well, there is a section where we note this as well: https://lsd.gnunet.org/lsd0001/#name-abuse-mitigation Abuse through name confusion is possible, of course. I do not think this can be solved while at the same time s
34.
▲
by
schanzen
5y ago
> - are you people open to the idea of an IRC/XMPP chan or a weblog/gemlog? following from afar (without being on the ML) looks like there's not a lot of activity, although i can see with my bare eyes the draft spec has ev
35.
▲
by
schanzen
5y ago
To 1) Yes, IF you know the zone key (which is a public key). You can perform a dictionary attack for common label values. This is discussed in the security considerations To 2) This is a governance issue. Theoretically, you could deploy GNS
36.
▲
by
schanzen
5y ago
We did receive feedback on the concept in general and draft in particular. We reworked the crypto significantly from the initial draft, both the key blinding as well as the symmetric encryption. Notably, the crypto is now more agile (you ca
37.
▲
by
schanzen
5y ago
Author here. The draft is currently in ISE review (there was not enough interest at IETF or IRTF). If you want to engage or need more info gnunet-developers@gnunet.org is a good place to start and ask questions. A lot of work has been going
38.
▲
by
schanzen
6y ago
Your comment does not make sense because it fundamentally says that the spec needs to define the DHT so that no 10 name systems exist. But that is simply nonsense. If you implement a new DNS stub resolver that follows the record wire format
39.
▲
by
schanzen
6y ago
This is not true. Please study, for example, https://tools.ietf.org/html/rfc6537 .
40.
▲
by
schanzen
6y ago
See 9.1. If ECDSA or Curve25519 are broken (e.g. because of quantum crypto), we can simply introduce a PKEY replacement (such as PKEY2) and migrate. EDIT: However, point well taken. This needs more space in the draft and is definitely a poi
41.
▲
by
schanzen
6y ago
That is actually a feature (zone privacy). The label should not be in plaintext anywhere.
42.
▲
by
schanzen
6y ago
Thanks, will be removed in -02 ;)