Decentralized Naming and Certificate Authority
handshake.org
handshake.org
- Names are released at a trickle, meaning no one can buy all of them in one go.
- Names have to be constantly renewed (it's not a buy-once-keep-forever scheme), and (correct me if I'm wrong), you can't buy 10 years out in advance.
- A large portion of the initial names are reserved for Open Source developers, under the assumption that squatting won't be so much of a problem if they get first pick.
It's still not clear to me how this solves resource scarcity.
- If names are released at a trickle, does this mean I might want to register a domain for a project and there literally won't be any able available for me to choose from?
- If names have to be renewed on a year-by-year basis, is there any mechanism for archival? Won't this be strictly worse for link rot?
- If names are released at a trickle, doesn't this create an even greater incentive for both good and bad actors to grab them as soon as they become available?
I'm mildly interested in Handshake because based on very limited research it seems in general to be an improvement over what we have. I get that perfect is the enemy of the good, I would take almost any improvement over the existing system. But at the same time, I still just don't understand how this helps solve the squatter problem -- every once and a while I ask and get an explanation, and then think about it for a while and end up having more questions.
My perspective is, we want everyone to be online. We want everyone to have their own blog, we want people to be able to create websites on impulse. And we want resilient, long-term links that can serve as permanent addresses for content. The idea of combating squatters is based on the assumption that domain names will continue to be a scarce resource. But you fundamentally can't have domains be a limited resource that are difficult to hoard if you also want random/poor elementary school kids to be able to buy them.
Handshake talks about solving Zooko's triangle: human-meaningful, decentralized, or secure. But the way I originally heard Zooko's triangle explained to me (which may have been wrong) was: human-meaningful, secure, high-availability. Am I correct in assuming that in the second version, Handshake is optimized for human-meaningful and secure at the expense of high-availability? That domains will continue to be a limited, scarce resource that are susceptible to hoarding by people with lots of money? Or are there other mechanisms here that I don't understand?
Disclaimer: I'm the ceo of Namebase.io, we built a registrar for Handshake domains and exchange for Handshake coins (HNS), so I'm pretty bullish on Handshake.
That doesn't seem to me at first glance like it's going to be that much of an improvement over squatting, but again, I get that there are multiple goals here worth accomplishing. And it is a much simpler system than needing to go into a queue to register a domain.
Just to make sure I understand -- am I correct in saying that Handshake is not designed to solve domain name scarcity, more to decentralize it so that an organization like ICANN can't rent-seek on top of that scarcity?
The winner pays the second highest bid.
That seems like it could have a lot of unintended consequences, to the point of invalidating all of the benefits from having tons and tons of new names. I have a lot of follow questions about the potential for abuse.
From the squatter/troll angle: if I'm a troll or I'm trying to steal good names before anyone else can get them, what stops me from monitoring the current auctions and stealing domains by bidding above the statistically most likely market price for that domain? Users have to guess in advance how much a domain will cost?
From the decentralized, anti-corporate angle: if I'm Comcast, what stops me from monitoring the current auctions, and blocking anyone who tries to register any variant of `comcastsucks`? With the current system, that's prohibitively expensive since there are tons of variations that I'd need to preemptively register. With the system you're describing, it costs me nothing until someone tries to register a domain that triggers my Regex, and then I just outbid them and block any domain that criticizes me, because as a company I'll always be able to trivially and safely outbid any single person.
From a general user angle: does this mean I have to wait 5 days to register a new domain? With the current system, I can set up a brand new website in a single evening, and all I need to do is find a name that isn't taken yet -- I don't have to worry someone else will see what I'm doing and snipe my purchase. With the system you're describing, I have to wait 5 days to discover whether or not I'm actually going to be able to buy the domain I want at all, and if I don't get it, then I need to repeat the entire process?
I have so many questions about this system now. There has to be something you're leaving out here. I can't imagine using a DNS registrar that made me wait 5 days to discover whether or not I got to have the domain, or that made me guess how much it would cost at the risk of losing the entire domain. If there aren't other details you're leaving out, that's a strictly worse system than what we have right now.
How do I do that if other people's bids can contain blinds? How do I know what the highest existing total is -- I still have to guess everyone else's total, right?
And even if the auction wasn't partially sealed, even if it was completely public -- I don't see how my concerns above would go away. Isn't it still possible for companies who can trivially outspend anyone else to do regex matches on all of the current auctions and dominate the entire domain space? Don't I still need to wait 5 days to do something that I can do today in less than an hour?
Learning about auctions pretty much entirely, just by itself, took me from thinking, "it's not perfect, but it still seems almost universally better than what we have" to, "no, this would be a massive downgrade from our current system." I thought the point was to stop rent-seeking, not to implicitly allow every fortune 500 company and government to personally vet/block every single domain transaction.
The auction system being described here doesn't just focus on other problems other than name scarcity, it makes the name scarcity problem way worse. If I'm China and I want to censor this system, what stops me from monitoring the auctions and throwing a measly $2000 at any domain name that sounds critical of me in any way? What's the point of having a distributed or decentralized protocol in that scenario?
You're right, you can't. I'm not sure what "just make sure your bid is greater than the highest existing total" means when blinds are in the mix.
> If I'm China and I want to censor this system, what stops me from monitoring the auctions and throwing a measly $2000 at any domain name that sounds critical of me in any way?
Nothing, but there are quite a few(TM) domain names. Everything that isn't an ICANN TLD (or a future ICANN TLD, I guess--not sure how that would work) is available. I don't think a government could reliably censor all objectionable TLD's.
Furthermore, once you own a Handshake TLD, you become the registrar for that TLD. So every subdomain is yours to sell, no auction necessary. So as long as someone purchases some simple TLD and is willing to sell you some relevant subdomain, you're good. It's not really necessary to have censorthis/; you can just buy censorthis.sometld. Of course, then you do depend on the owner of sometld as a registrar, but that's not very significant given the space of TLD's available. It wouldn't be difficult to find a new registrar if something happened.
If I understand correctly (and maybe I don't), the domain being auctioned is public. With the current system, a government can't censor everything because doing so would require them to pre-emptively grab the entire space, which is economically infeasible. With public auctions, my understanding is they only need to pay attention to the domains someone actually tries to register. So if I'm China, I don't need to preemptively register the entire space of `/tiananmen/g`. I only need to download the list of auctions every day and run a regex on that finite space.
Of course, they can't restrict subdomains, so maybe that allows people to sneak stealth TLDs through without getting censored. But (see below) it seems like actually owning TLDs is really important, so I still need to navigate a space where every troll and every government and every fortune 500 company is given the opportunity to snipe every TLD I want, and it seems like that's at least an opportunity for wild price increases on TLDs.
> Of course, then you do depend on the owner of sometld as a registrar, but that's not very significant given the space of TLD's available. It wouldn't be difficult to find a new registrar if something happened.
Can you expand on this?
Right now, if I lose a .com domain, I can find a new registrar and set up a different domain. But all of the links to my current domain will be broken, and if I'm using that domain for email I'll have lost control of all the emails being sent there, and I'll basically be starting over from scratch.
Part of the reason I've avoided "novelty" TLDs like `.tech`, `.party`, `.amazon`, etc... in the current system is because many of them are completely privatized. The owners of those TLDs can raise prices however they want, and can kick anyone off for any reason. And if I'm tying my entire business or (even worse) my entire online identity to one of those domains, that would catastrophic.
If a registrar behind a top level Handshake domain goes bad, is there a mechanism where I can switch registrars and keep myself as a subdomain of the original TLD? If not, won't I be in the same position?
The thing that's attractive to me about Handshake is owning TLDs -- being able to own something that can't be arbitrarily taken away from me by a centralized authority. Otherwise I haven't gained anything as a user over the current system, I've just lost any regulatory price caps that might exist.
----
I guess I can register an innocuous TLD like `danshumway`, hope the trolls don't notice and outbid me, and then use it as a private TLD I control. Realistically, to preserve privacy and avoid linking everything I do together under a single identity, I'll likely want at least 4 or 5 TLDs, possibly more. I don't think I'm atypical there. Anyone who's using a domain for their email or an identity server will want to own that TLD. Is the system designed to scale to that?
Direct question to the people behind Handshake: what do you expect the average cost of a generic 2-3 word TLD to be? A while ago I registered the domain `animalsareignorant.com` for a personal art project I'm still working on. It costs $10 a year. Are we expecting a TLD like `animalsareignorant` to cost $100? $1000? A million? I assume you've done market research on this and you're not just jumping in blind.
This isn't a theoretical question. When (at this point, if) I ever start using Handshake, at some point I'm going to register a TLD and you're going to ask me how much I want to bid for that domain. So if you expect people like me to be able to guess on the spot what the market value of a TLD is, you need to be able to point to some kind of measure that will keep that guess from being a purely blind shot in the dark.
Sure, but since it doesn't cost anything to lose a bid (I believe?) if anyone tried that it'd be pretty easy to force them to spend a _lot_ of money buying domains that they have no intention of using. It also wouldn't stop anyone from registering `tiananmen.massacre`, as you noted.
It takes months to years to get a tld today with a 185k deposit and no guarantee you'll actually get through the process [1].
[1] https://newgtlds.icann.org/en/applicants/global-support/faqs...
I can already rent `.com` subdomains today, and they have price caps. The worst case scenario for a `.com` domain right now is that the current ICANN proposal goes through and the cost jumps up to maybe $20 a year. That's nothing compared to the rent-seeking that can happen on a purely privatized TLD with no oversight.
As a user, buying a subdomain controlled by a single source is not decentralization. I'll still have a single company that can do anything it wants to my domain, and by extension, anything it wants to my online identity. It'll still be trivial for governments to pressure that company into transferring my domain. I won't get to manage my own keys or set up my own security. I won't be able to renew the domain for free.
Unless I'm missing something really big, the only benefit I see from Handshake is democratizing TLDs for ordinary, everyday people.
That's fair - may help to compare this with the current tld system, not just the regular domains (x.com). Right now, getting a new tld takes months and a six figure investment. Here it is 5+ days.
After that tld is claimed, it's up to the owner to administer it and make a profit on selling the names, or not.
When talking about email alternatives here, I see a lot of comments strongly suggesting owning a custom domain and using it. If the domain cannot be renewed and kept alive in advance for a few years, the bus factor of being the only technical person in the family could mean that they lose their emails very soon (worst case scenario where something bad happens to the technical person towards the end of the bi-annual period just before the renewal).
“You need to submit a transaction to prove you still have access to the private key” — “transaction”? “prove”? “private key”? There’s no way this is going to last if people use these domains for emails and mailboxes for their families. At least with the conventional system, it’s easy to note down simple instructions to go to a site, pay and renew. This system seems better suited for institutions that may be able to handle it (though it could be argued that even large companies fail in trivial ways, like it happened with a certificate expiry with Microsoft recently).
But my assumption is that there would still be registrars that can handle this sort of thing for you, in the same way that a service like Netlify can handle setting up a static site server and renewing LetsEncrypt certificates. It's just that if you wanted to do it manually, you could.
Can you clarify on what "names" means here? Common names, dictionary, every single name that exists in current DNS? If someone has a unique non-word domain right now do they have to submit that? Wait a year?
>- Names have to be renewed bi-annually. You don't need to pay a fee, you just need to submit a transaction to prove you still have access to the private key. I don't think this will be any different than the existing DNS in terms of link rot.
That sounds decent on the face of it but it depends on how automated that can be made, what the window is like, etc. Right now I can renew every 10 years, or do so for 10 years and add on more time every year so that if I ever forget or have trouble once I still have a huge window, and have automated billing/warnings etc. Not free, but pretty reliable. If namebase.io or the like are needed to handle this by most users I also don't see how decentralized that can actually end up being though I guess the infrastructure can help. How are transfers to different registrars handled?
But how does that square with the 52-week staggered release bit? If I wish to go register my domain right now, what happens? I don't see anything on namebase that would simply allow entry of an arbitrary domain, instead the "bid soon" seems to just be a bunch of dictionary words. There is an invitation to enter your handle or whatever, but does that mean all such handles and existing domains have been auto scanned already for entry? Or if I do a search, do you then take that and put it up for auction like so many typical registrars? This is a really basic thing and it's not clear.
>There's a spectrum of convenience and self-sovereignty. In traditional DNS the existing system makes that choice for you, whereas Handshake is creating a system where individuals get to choose based on their preferences. I place a lot of value on that freedom to choose.
No offense but this reads as boilerplate PR mush, it doesn't actually answer anything. Choose what? High level values are all well and good but they're not a substitute for nuts-and-bolts implementation specifics either.
It's random, but distributed over 52 weeks because the hash function has psuedo-random output. It's quite clever, IMO. That's what "Determined by hash(name) % 52" means. You want to register "meow" today? Well, then check if hash("meow") % 52 <= currentWeekIndex
That's my understanding, but I haven't actually read any docs.
Blockchains are good for timestamping. The records on chain can be tracked over time but this doesn't solve the problem of when the blockchain authoritative name server delegates to the tld's authoritative name server. Maybe the tld nameserver could index the records in a git like data structure and be able to serve queries with a time parameter
I don't think so - note that these are for tlds, so a lot of existing internet infrastructure can be used for Handshake names.
Someone who wants elementary school kids to be able to buy them would allow for the purchase (at low, no, or negative cost) of subdomains (traditional domains) - it may allow for a proliferation of hundreds of little self-sovereign registrars with different policies.
`${name}.namesforschoolkids`
No, centralization exists because users don't care about the protocol. Users care about the brand.
It's way easier to use FB than it is to say "choose your hosting provider. Each one has a slightly different set of features. Then link with other people you care about, all of whom may be using different providers that you need to pay special attention to." With FB, I click "send a friend request" and then move on with my day. And that's just one example.
Brand is a proxy for the level of functionality delivered by that brand.
People didn't switch to GMail because it was a "cool" brand, they switched because the spam filtering worked, Google gives you a ton of free space (a problem at the time), and it didn't have obtrusive banner ads. This was passed on by word of mouth, and now GMail is popular.
> It's way easier to use FB than it is to say "choose your hosting provider. Each one has a slightly different set of features. Then link with other people you care about, all of whom may be using different providers that you need to pay special attention to." With FB, I click "send a friend request" and then move on with my day. And that's just one example.
Exactly my point, the UX is better and the network effect ensures that many/most of your friends are already there. It's not about branding, it's about ease of use.
In the early days of gmail when you needed an invite code, it definitely was a status symbol to have that @gmail.com on your email address.
And at the time, the actual functionality of gmail was far less significant than the fact it was free and decoupled from your internet provider, although you're right the storage capacity on a free email was unheard of at the time.
If that was the real draw, then people would have just stuck with Hotmail, Yahoo, and the dozen other e-mail providers.
100% agreed.
> People didn't switch to GMail because it was a "cool" brand,
Less agreed on this. Brand is also a proxy for PR, marketing, and the general image of the company. Gmail had an awesome feature set - better than its competitors at the time, but also spread wildly by word of mouth. At that time, Google was an exciting company for most people (it still is by and large, but that's another discussion). Gmail's "invite-only" onboarding was done well and made it exclusive. FB did the same thing when they rolled out to one school at a time.
Ultimately, I think we're on the same page. People want good UX; they want a product/company that their friends recommend; they want something that just works.
1. "Browsing the web with human readable names is what Internet users have gotten acclimated to." => give me an example of a "handshake" domain name in this case
2. I have some domains/sites not so popular (not in the first 100k Alexa domains). I will only hear about "Handshake" in 5 years time when Handshake completely replaced what we are using today, by which time, someone else might have "registered my domain names". What do I do? Obviously I can prove I own my .com/.net.
To site failed to answer some basic questions/concerns or give some real world use case scenarios.
Secondly, the 100k top Alexa sites refers to the inability to register a ".whatever" if that "whatever.some_tld" is in top 100k Alexa. So, basically this is "pre-reserving" "gTLD".
In my first impression, these 2 things were somehow correlated.
This is one part that Handshake does not explain very well. The existing domains and tlds that icann owns will continue to work moving forward. The top 100k Alexa domains bit works like this:
For the top 100k alexa domains, the owner receives the root of the domain as a domain in Handshake (ex: the owner of `example.com` receives the domain `example` in Handshake). All `*.com`, etc domains continue to operate as they have in the past.
Usually the answer to that question reveals whether the system is A) not in fact decentralized, or B) not compatible with laws in most jurisdictions.
Anyway, not necessarily a specific critique of this system since I don't know the answer to the question in this case. More just a useful framework I've found to assess distributed systems without getting mired in execution details.
Edit to add: your namebase.io FAQ seems a lot more useful than the handshake one. For starters it clarifies that there is a confusing terminology difference, where I guess the handshake people are using "domain" to mean "TLD" and "subdomain" to refer to what everyone typically calls a domain. So a core offering of this system appears to be a blockchain based replacement to the $150k+ (or whatever it is these days) "get your own arbitrary TLD" thing ICANN did, "anyone" gets to register their own TLD. But that raises more questions, like where the actual hardware behind all this goes particularly for existing TLDs which are blacklisted.
Seconding this. I did not pick up on that at all.
----
But first - would like to +1 troquerre's answer - the DNSSEC proofs provide some degree of long-term primacy and compatibility/transferability to Handshake - it'll help minimize conflicts/disputes.
Adding to that answer: I think something often left unsaid is how Handshake is attempting to create incentives for everyone (not just the early devs) to work together and make the internet better. The wide distribution to FOSS developers and donations have been mentioned by the team in other replies, but I'd like to add more:
From the design notes: (source: https://handshake.org/files/handshake.txt)
``` ICANN has been the root namespace for the internet. ICANN (CA, US) is allocated 24,480,000 of the initial coin supply by the Handshake community.
Cloudflare, Inc. (DE, US) is a corporation doing fundamental research for naming, caching, and certificate authorities. They are allocated 6,800,000 of the initial token supply.
Namecoin is a decentralized naming blockchain. 10,200,000 of the initial supply was allocated to leading current and prior Namecoin developers.
Verisign, Inc. (VA, US) is the registrar for .com and .net. They are allocated 6,800,000 of the initial token supply. The .com and .net TLDs on Handshake will be given to Verisign with a DNSSEC proof.
Keybase has been innovating in the naming and certificate authority space. Keybase, Inc. (DE, US) are allocated 0.25% of the total token supply.
Public Internet Registry (VA, US) maintains the .org namespace. They are allocated 3,400,000 of the initial token supply. The .org TLD on Handshake will be given to PIR with a DNSSEC proof to pir.org.
Afilias plc (IE) has been the service provider for the .org namespace. They were allocated 3,400,000 of the initial supply to a DNSSEC proof of afilias.info. Note for both PIR and Afilias, this allocation was made before the proposed sale of the .org namespace. ```
These aren't trivial amounts for typical "ICO project marketing buzz / fake partnerships", they add up to percentages of total supply claimable by DNSSEC proof.
Because of this attempt to align incentives, I imagine there could be a world where community members (FOSS developers and wider mainstream 'internet' folks, not just 'crypto' folks) can get the best of both worlds, where any conflicts between ICANN and Handshake are minimized or the user pain mitigated by resolvers/other service providers.
----
*returning to the original question on cocacola -- the dnssec proof setup helps with .com domains where the holder wants to claim and use the Handshake tld there are a lot of situations where this is not enough.
What if someone registers cocacolacompany, or thecocacolacompany, or coke? It could totally happen:
Source: https://github.com/kyokan/namegrind ``` cocacolacompany,4032,2,false thecocacolacompany,22176,20,false coke,50400,48,false ``` Note: - that output is ${name},${blocknumber},${weeknumber},${reserved} - it can be generated with this tool https://github.com/kyokan/namegrind
If one puts together the pieces from some of the other posts from the team - someone can claim anonymously with GooSig and buy the above names, and the multinational that is "The Coca-Cola Company" will probably attempt to find and enforce trademark protections against the holder -- if they cannot find that person, and it is flagged as an infringing name -- resolvers or some other downstream service providers may have to block it. Of course, I am not condoning this - talk to your lawyer before you knowingly attempt to buy a name -- just pointing out that it is possible. From there, we could extrapolate various ways the legal system gets involved, or "pretty complicated governance models" attempt to protect The Company's claims, or the holder's privacy/control.
So, to answer your question: Handshake is definitely less centralized than existing systems (no entity to send a takedown request to), but it's also not clear if strictly incompatible with laws in most jurisdictions.
I don't think anything of this kind has been done before - my intent is to provide a bit of context and spark further discussion, but I'm not qualified to do more than speculate on how the legal stuff may play out.
That said, for some jurisdictions, "B)" may very well happen.
Humanity appears to be changing the public park infrastructure of the Internet into a paid-access theme park, with [them/someone else] writing the rules. It doesn't look like the righteous, tech illiterates, political manipulators or shareholder driven groups are going to relent.
The Internet used to be filled with raw data, but in the age of centralized, walled garden curating, the essence of the information superhighway has been lost.
It would be cool if they could pioneer a new way to replicate data in the age of autonomous vehicles or use the Internet to transfer volumes of data for offline nodes to broadcast and reimagine DNS and the other fundamental tools to make something like that resilient.
If they could remove most/all of the ads, marketing, monetization and censorship from the data, we might see another generation experience the raw data bliss many of use were raised on in the pre-dot.com era.
It was truly something special and felt like the world (of knowledge) was at your fingertips (instead of something slimey on the other end).
Edit: I see elsewhere there have been cash drops to Debian, Arch and probably some other projects. Which makes sense.
They also needed exposed public keys to airdrop to, which limited the airdrop to Github and the WoT strong set.
Then why not look how many stars one's repos have? That seems a much better metric to me.
A friend of mine has hundreds of stars on their repos but only 30 followers. I have around a hundred stars on my repos but only 20 followers. Conversely, I've seen people who are into networking, have a lot of GitHub followers, and no meaningful repos at all.
Time to read more about Handshake I guess?
Second impression: Not a wildly outlandish idea but im not sure if it's a good idea either. Decentralized and automated registrar with a concept of renewals. Nifty.
I'm not really sure how the economics here work out.. Could I scoop up a few million names early on and then hold them forever? Has that already happened? Could this enable anonymous registration? Would these things make users trust these names more or less?
Names roll out over 52 weeks: HashName(name) % 52 = week number that a name is available. So that should attenuate squatting. Also bidding on names locks up coins for something like 2 weeks, so it's hard to bid on too many names.
So if I read this right
Creators get: 102mi coins
Sponsors get: 102mi coins
they are airdropping about 952mi coins to users on github to the tune of 4,246 per user.
So they're collecting about 20% of all coins initially dropped. That's slightly more then some. And at the value listed on https://www.namebase.io/ that adds up to some 102,000,000 * $0.44 = $44mi.
Ok, so it's not an ICO exactly, instead they raised VC funds which is expecting a return by selling coins.
I've just spent a few minutes looking through the website, docs, and a little code. And I have no idea how an end user will use these names. Everything polished about it is for trading coins not real world usage. Sounds like every other crypto coin.
It’s aimed at open source developers who will be able to figure out how to use the system, not mainstream non-tech normies. As evidenced by the large airdrop to Github.
> Handshake donates $300,000 USD to Debian [0]
You can however see it as part of the monthly SPI reports;
Additionally, anyone who can obtain HNS anonymously can thus register anonymously.
I suspect that using Bitcoin instead would improve adoption dramatically instead of creating yet another token. This can be done using sidechains or something similar.
Handshake at it's core is a decentralized root zone of trust, the equivalent of ICANN. It's up to people building on it to create the registrars and such.
Previous experiments were for one TLD like .bit or .eth
With Handshake, every possible TLD is released over 52 weeks
Even more so, it works with existing DNS infrastructure and tools. All it is doing is allowing for all TLDs and resolving them (with preference for ICANN / HNS) where the overlap occurs. It was built from the start to exist along side today's systems.
- It's all public - It doesn't change that often - It is a data storage issue (as compared to processing) - On a per record basis it's pretty small (as compared to trying to store PNGs in the blockchain)
Also HNS is a coin, not a token.
First - I tend to think an idea with clear similarities being tried before and failing is default a non-negative (sometimes good) sign: shows us what didn't work, and deepens everyone's understanding/validation of the problem space.
I would also say that it's more similar to Bitcoin than most people would think. Looking at the software, I think it's pretty cool that handshake's first implementation is a fork of a bitcoin implementation that has seen production usage for years (bcoin), one important change is the addition of opcodes to support covenants, so that blinded vickery name auctions can be done fully on-chain.
Basically, Handshake can build on top of the security and reliability that Bitcoin-like systems have validated for us over the last few years: namely, UTXO systems, proof of work, user knowledge/habits around self-custody.
I think Bitcoiners could consider looking at Handshake from this perspective: there is a lot of core technology, architecture decisions, and spirit that is similar. Perhaps if you believe in the potential of public blockchains like many early Bitcoiners do, the solution might not be things like sidechains (which are mentioned as a potential scaling option in the design notes), but extending the core technology in a minimal, single-purpose way (to support auctions)?
Perhaps it is possible that Handshake goes down as one of the best examples of an ambitious new project actually "using Bitcoin" (albeit in a way most Bitcoiners would not immediately agree with) instead of creating "yet another token"?
----
p.s. I've been a fan of yours for years and your content was some of the first I ran into when I was entering crypto full-time. I guess at the end of the day I'm simply curious what you thought of the other projects so far (including Namecoin and ENS) - do you own any names on other decentralized naming systems?
What do you think prevented Namecoin from getting sufficient traction from your perspective?
https://www.cs.princeton.edu/~arvindn/publications/namespace...
Has ICANN said anything about .bit or .onion TLDs? I suspect TOR is big enough they won't touch .onion, but if they sell .bit, you'll then have some name overlap/conflicts.
Edit: I guess this is a replacement for ICANN not the inter-carrier routing protocols, which is, interesting. Is the point here that if DNS authorities switch to Handshake for authoritative DNS it will be harder to hijack routes? I would love an explanation, sorry it I'm being dense!!
As has been the pattern with all these decentralized DNS schemes, the FAQ doesn't cover the most utterly basic question: "I currently have one or more domains that I use extensively for my own life/work. How do I transfer those to try this new scheme? How much actual dollars/euros/yen/yuan/... does it cost, not mystery blockchain-whatevers but predictable real money? Does this new scheme harm me?"
Shouldn't an experimental system in particular want regular tech people with personal domains trying it out? We'd probably be more willing to give it a whirl (with fallbacks) since it's more for our own private use. But instead it's all about trademark holders and the Alexa 100k and so on, which is important too but it seems like most such domain holders would be a lot more conservative. And I've had a growing suspicion that the last part of the question doesn't get answered clearly because the answer is "you may get screwed, we are ideologues who think that people should be able to take your domain if you're not rich enough to defend it."
I mean, right now I don't in fact see the current DNS system as horrible. Cloudflare and others are pretty reliable registrars and companies to deal with. A .com is about $8, .net and .org both about $10. A known amount of $200 or so and I'm set for 10 years, and I consider that a good thing. I've had my domains for nearly 20 years now, they're core to my online identity and personal infrastructure. Same for most businesses, DNS sits at the center of everything. My concerns are about ICANN allowed price increases due to monopoly, and whether bad actors could somehow try to claim my domain and how I'd fight that as an individual. But I don't see answers in the FAQ to how this would help answer those. My personal domains aren't in Alexa top-whatever so it sounds like handshake will auction them off. There is a "renewal fee" after that but it's handwave-y:
>Renewals for names are annual and cost a standard network fee
A standard network fee of what? $1? $10? $100? It can vary by thousands of percent at random like so many cryptocurrencies? How long is the renewal window? Can it be paid upfront? What happens if it gets missed? Is any of this predictable?
I simply don't see any brass tacks implementation stuff here. It's a bunch of high level hoohah about the evils of centralization without any acknowledgement of how centralization can be useful and efficient too and how they deal with that. The word "federation" does not appear at all, which is another important approach/aspect. It sounds worryingly like a common "religious" approach where people take a tool (like decentralization) and turn it into a goal in and of itself.
The full node daemon, hsd, is written in Javascript.
A non type safe language with poor package management for consensus critical code. We also have a light client, hnsd, which is written in C
A non memory safe and error prone language for client code people would run on their systems as root.It promiscuously makes outgoing TCP connections to an unauthenticated P2P network, so given enough time you'll eventually interact with an attacker if there is one.
Re: JavaScript, you should take a look at the code in repo, it's excellent. There is a such thing as great Javascript code and bcoin/hsd are prime examples.
https://npm.anvaka.com/#/view/2d/bcoin
Many steps of indirection away we find things like this include.
https://github.com/juliangruber/isarray/blob/master/index.js
module.exports = Array.isArray || function (arr) {
return toString.call(arr) == '[object Array]';
};
Javascript is an absolute joke of a language.It's not a full node implementation yet, but will be there soon!
Assuming I'm not mistaken and that really is how Handshake is set up (someone please correct me if I'm wrong), then IMO the whole project is essentially dead on arrival. There's no chance they're going to be able to convince millions of large websites to register on a new DNS root overnight. And even if they did somehow managed to convince 80% of websites move to the new system, users _still_ wouldn't switch over because doing so would effectively break 20% of the internet for them.
It's a real shame, because this problem would be trivially avoidable if they simply allowed the existing TLDs use the ICANN roots and confined Handshake domains to their own TLD (.handshake maybe). That way, adoption could happen slowly over time and users could switch over to the Handshake roots with no downsides. As-is though this is simply unworkable.
This is not true. You can setup Handshake to be your resolver, and it will resolve both domains on handshake, and legacy domains from icann.
> Existing TLDs and over 100,000 Alexa websites are reserved on the Handshake blockchain. Upon removing collisions, generic, and exclusions (e.g. 1 or 2 character names), approximately 80,000 names remain. Using the root key and DNSSEC, domain owners can cryptographically prove ownership to the Handshake blockchain to claim names.
Does Handshake control existing (`.com`, `.org`, etc.) domain names or don't they? If they do, then what happens when a DNS entry in Handshake's roots contradicts what's in the ICANN roots? If Handshake wins conflicts, then that breaks the internet for existing users.
If this behavior is easily configurable/shared and open source, then people can opt into whatever configuration that best suites their needs.