The winner pays the second highest bid.
The winner pays the second highest bid.
That seems like it could have a lot of unintended consequences, to the point of invalidating all of the benefits from having tons and tons of new names. I have a lot of follow questions about the potential for abuse.
From the squatter/troll angle: if I'm a troll or I'm trying to steal good names before anyone else can get them, what stops me from monitoring the current auctions and stealing domains by bidding above the statistically most likely market price for that domain? Users have to guess in advance how much a domain will cost?
From the decentralized, anti-corporate angle: if I'm Comcast, what stops me from monitoring the current auctions, and blocking anyone who tries to register any variant of `comcastsucks`? With the current system, that's prohibitively expensive since there are tons of variations that I'd need to preemptively register. With the system you're describing, it costs me nothing until someone tries to register a domain that triggers my Regex, and then I just outbid them and block any domain that criticizes me, because as a company I'll always be able to trivially and safely outbid any single person.
From a general user angle: does this mean I have to wait 5 days to register a new domain? With the current system, I can set up a brand new website in a single evening, and all I need to do is find a name that isn't taken yet -- I don't have to worry someone else will see what I'm doing and snipe my purchase. With the system you're describing, I have to wait 5 days to discover whether or not I'm actually going to be able to buy the domain I want at all, and if I don't get it, then I need to repeat the entire process?
I have so many questions about this system now. There has to be something you're leaving out here. I can't imagine using a DNS registrar that made me wait 5 days to discover whether or not I got to have the domain, or that made me guess how much it would cost at the risk of losing the entire domain. If there aren't other details you're leaving out, that's a strictly worse system than what we have right now.
How do I do that if other people's bids can contain blinds? How do I know what the highest existing total is -- I still have to guess everyone else's total, right?
And even if the auction wasn't partially sealed, even if it was completely public -- I don't see how my concerns above would go away. Isn't it still possible for companies who can trivially outspend anyone else to do regex matches on all of the current auctions and dominate the entire domain space? Don't I still need to wait 5 days to do something that I can do today in less than an hour?
Learning about auctions pretty much entirely, just by itself, took me from thinking, "it's not perfect, but it still seems almost universally better than what we have" to, "no, this would be a massive downgrade from our current system." I thought the point was to stop rent-seeking, not to implicitly allow every fortune 500 company and government to personally vet/block every single domain transaction.
The auction system being described here doesn't just focus on other problems other than name scarcity, it makes the name scarcity problem way worse. If I'm China and I want to censor this system, what stops me from monitoring the auctions and throwing a measly $2000 at any domain name that sounds critical of me in any way? What's the point of having a distributed or decentralized protocol in that scenario?
You're right, you can't. I'm not sure what "just make sure your bid is greater than the highest existing total" means when blinds are in the mix.
> If I'm China and I want to censor this system, what stops me from monitoring the auctions and throwing a measly $2000 at any domain name that sounds critical of me in any way?
Nothing, but there are quite a few(TM) domain names. Everything that isn't an ICANN TLD (or a future ICANN TLD, I guess--not sure how that would work) is available. I don't think a government could reliably censor all objectionable TLD's.
Furthermore, once you own a Handshake TLD, you become the registrar for that TLD. So every subdomain is yours to sell, no auction necessary. So as long as someone purchases some simple TLD and is willing to sell you some relevant subdomain, you're good. It's not really necessary to have censorthis/; you can just buy censorthis.sometld. Of course, then you do depend on the owner of sometld as a registrar, but that's not very significant given the space of TLD's available. It wouldn't be difficult to find a new registrar if something happened.
If I understand correctly (and maybe I don't), the domain being auctioned is public. With the current system, a government can't censor everything because doing so would require them to pre-emptively grab the entire space, which is economically infeasible. With public auctions, my understanding is they only need to pay attention to the domains someone actually tries to register. So if I'm China, I don't need to preemptively register the entire space of `/tiananmen/g`. I only need to download the list of auctions every day and run a regex on that finite space.
Of course, they can't restrict subdomains, so maybe that allows people to sneak stealth TLDs through without getting censored. But (see below) it seems like actually owning TLDs is really important, so I still need to navigate a space where every troll and every government and every fortune 500 company is given the opportunity to snipe every TLD I want, and it seems like that's at least an opportunity for wild price increases on TLDs.
> Of course, then you do depend on the owner of sometld as a registrar, but that's not very significant given the space of TLD's available. It wouldn't be difficult to find a new registrar if something happened.
Can you expand on this?
Right now, if I lose a .com domain, I can find a new registrar and set up a different domain. But all of the links to my current domain will be broken, and if I'm using that domain for email I'll have lost control of all the emails being sent there, and I'll basically be starting over from scratch.
Part of the reason I've avoided "novelty" TLDs like `.tech`, `.party`, `.amazon`, etc... in the current system is because many of them are completely privatized. The owners of those TLDs can raise prices however they want, and can kick anyone off for any reason. And if I'm tying my entire business or (even worse) my entire online identity to one of those domains, that would catastrophic.
If a registrar behind a top level Handshake domain goes bad, is there a mechanism where I can switch registrars and keep myself as a subdomain of the original TLD? If not, won't I be in the same position?
The thing that's attractive to me about Handshake is owning TLDs -- being able to own something that can't be arbitrarily taken away from me by a centralized authority. Otherwise I haven't gained anything as a user over the current system, I've just lost any regulatory price caps that might exist.
----
I guess I can register an innocuous TLD like `danshumway`, hope the trolls don't notice and outbid me, and then use it as a private TLD I control. Realistically, to preserve privacy and avoid linking everything I do together under a single identity, I'll likely want at least 4 or 5 TLDs, possibly more. I don't think I'm atypical there. Anyone who's using a domain for their email or an identity server will want to own that TLD. Is the system designed to scale to that?
Direct question to the people behind Handshake: what do you expect the average cost of a generic 2-3 word TLD to be? A while ago I registered the domain `animalsareignorant.com` for a personal art project I'm still working on. It costs $10 a year. Are we expecting a TLD like `animalsareignorant` to cost $100? $1000? A million? I assume you've done market research on this and you're not just jumping in blind.
This isn't a theoretical question. When (at this point, if) I ever start using Handshake, at some point I'm going to register a TLD and you're going to ask me how much I want to bid for that domain. So if you expect people like me to be able to guess on the spot what the market value of a TLD is, you need to be able to point to some kind of measure that will keep that guess from being a purely blind shot in the dark.
Sure, but since it doesn't cost anything to lose a bid (I believe?) if anyone tried that it'd be pretty easy to force them to spend a _lot_ of money buying domains that they have no intention of using. It also wouldn't stop anyone from registering `tiananmen.massacre`, as you noted.
It takes months to years to get a tld today with a 185k deposit and no guarantee you'll actually get through the process [1].
[1] https://newgtlds.icann.org/en/applicants/global-support/faqs...
I can already rent `.com` subdomains today, and they have price caps. The worst case scenario for a `.com` domain right now is that the current ICANN proposal goes through and the cost jumps up to maybe $20 a year. That's nothing compared to the rent-seeking that can happen on a purely privatized TLD with no oversight.
As a user, buying a subdomain controlled by a single source is not decentralization. I'll still have a single company that can do anything it wants to my domain, and by extension, anything it wants to my online identity. It'll still be trivial for governments to pressure that company into transferring my domain. I won't get to manage my own keys or set up my own security. I won't be able to renew the domain for free.
Unless I'm missing something really big, the only benefit I see from Handshake is democratizing TLDs for ordinary, everyday people.
That's fair - may help to compare this with the current tld system, not just the regular domains (x.com). Right now, getting a new tld takes months and a six figure investment. Here it is 5+ days.
After that tld is claimed, it's up to the owner to administer it and make a profit on selling the names, or not.