ICANN delays .org selloff after California’s attorney general intervenes
theregister.co.uk
theregister.co.uk
In online debates a decade or more ago, I remember people, including myself, used to defend American control of the domain system by pointing out the altruistic and independent nature of the ICANN and their history of being good stewards of the DNS infrastructure thus far. That seems to no longer be the case. This whole deal calls into serious question their current integrity.
It’s not about making sense. It’s about making dollars.
Now it started making sense!
Wasn't Verisign a problem before ICANN became a non-government entity?
As long as the Internet namespace, or DNS, is governed by US (California state specifically) law, the Internet itself will be operating under the same jurisdiction as DNS is generally considered critical to the function of the Internet.
This is a very strong reason that, just like currency [2], the Internet namespace is also ripe to be decentralized to distributed ownership by the people [3].
The internet deserves to be owned by the people - not any single government.
There are definitely a lot of issues that aren’t working in the ICANN system as we all know [1][2][3].
What are the issues that can’t be handled in the Handshake blockchain ecosystem?
[1] https://www.google.com/amp/s/arstechnica.com/tech-policy/202...
[2] https://www.eff.org/deeplinks/2019/12/we-need-save-org-arbit...
[3] https://www.eff.org/deeplinks/2015/09/symantec-issues-rogue-...
You first need a system which works and scales to plausible levels before we can say anything about whether it’s a viable solution for anything. In particular, it’d be important to have real cost and control information to show that it wasn’t trading ICANN for a different group which has similar control — and the inherent inefficiency of a blockchain means that there’d be more of a likelihood that power would consolidate in a few major players.
(As an aside, Symantec screwing up does not seem relevant to a discussion about ICANN. Perhaps you could explain why you believe it to be?)
As someone following Bitcoin for a long time since just after genesis, I can assure you that replacing cash and credit cards was never on the original agenda but instead a byproduct of the goal. Make no mistake, the goal was always to decentralize currency and give the “power” of money back to the people. That said, in a decentralized system, there can be more than one goal and goals do not need to be unified across participants. That freedom is one of the beauties of decentralization.
As long as a third party central authority controls our money system, we will always be subject to the whims of the few. Bitcoin is helping to liberate us and it’s absolutely working.
> it’d be important to have real cost and control information to show that it wasn’t trading ICANN for a different group which has similar control
This exists by virtue of our trust in cryptography - which for me is absolute.
> As an aside, Symantec screwing up does not seem relevant to a discussion about ICANN. Perhaps you could explain why you believe it to be?
Less directly and more by way of overall system architecture, the separation of DNS and “truth” has caused many issues to the Internet. It’s relevant because Handshake finally combines DNS and truth [1] by essentially completing the once incomplete DNSSEC.
A bold claim without evidence. In fact, the opposite may be true [1]. This is but one counterpoint; another notable problem is the centralization of bitcoin mining in China [2].
[1]: https://www.bloomberg.com/news/articles/2017-12-08/the-bitco...
[2]: https://thebitcoinnews.com/study-argues-chinese-mining-centr...
> [1]: https://www.bloomberg.com/news/articles/2017-12-08/the-bitco...
The same can be said about any money system in a capitalist economy (e.g., 1% owns 40% of the wealth in the US [1.1]).
> This is but one counterpoint; another notable problem is the centralization of bitcoin mining in China [2].
I'm not sure this is 'looming' today as the article boldly claims, but centralization is definitely a risk. It's important for everyone to participate in the system as they can for a more equal distribution of ownership - akin to how one should exercise their vote in US elections.
[1.1] https://en.wikipedia.org/wiki/Wealth_inequality_in_the_Unite...
Bitcoin emerged from the Cypherpunks crowd; while nobody has positively IDed the 'real' author of the paper, the ideological motivations are rooted in anarcho-capitalist thought. The operative theory is really not that different than Grover Norquist's; attack the tax base and the state withers. Grover is just less ambitious.
The flaw in the bitcoin thesis is that the internet is powerful tool of centralized control and reinforces authoritarians, not the opposite.
The only thing I would disagree with is the disagreement about the claims about effectiveness.
While we may not have "replaced money," make no mistake, we have entered a new era - bitcoin was not stopped even though they tried.
Bitcoin has succeeded. It is our symbol of proof - proof that we the people can control our own money.
It's so volatile it's useless except for speculators.
Greed ruined it, I feel, like it does with everything else.
We probably disagree on other things bitcoin-related, but right here I think it is only about how we're defining 'success'. I agree that it is an existence-proof for decentralized currency, and am not trying to downplay the significance of that.
As someone who was also there, I stopped reading at this point. The things getting circulation were bold predictions about replacing cash and credit cards in daily life and anyone who questioned that inevitability was dismissed as not understanding it. Everyone knew it was an attempt to dress up “use your money to make me rich” in a more noble guise but that doesn’t mean it didn’t happen.
From the handshake FAQ: 'There are no social or technical guarantees with the renewability or ownership, this is an experimental system, please read the code to see details of how it currently works'. That's below the bit where they auction them off to the highest bidder. There are plenty of issues with ICANN, but it isn't a toy with a short term profit-maximization scheme attached...
The blockchain auctions domains off to the highest bidder thru a blind Vickrey auction [1] wherein the winner pays the amount of the second highest bid.
After the auction completes, the coins are burned (provably destroyed).
Both the legacy ICANN system and new TLDs on Handshake [2] are working together in harmony.
To be clear, everything on the internet including the internet itself started as an experiment.
[1] https://en.m.wikipedia.org/wiki/Vickrey_auction
[2] https://dns.live - Domain Adoption
The hns paid for winning an auction are destroyed.
> There are plenty of issues with ICANN, but it isn't a toy with a short term profit-maximization scheme attached.
Handshake is anything but a short term profit-maximization scheme! The Handshake developers took $10 million of VC money and donated it to free and open source foundations: https://handshake.org/grant-sponsors/
If for some reason the US thought ICANN shouldn't be subject to US law, they could do something similar. Being inside a country's borders doesn't always mean being subject to its laws.
Of course, the corruption in the .org selloff doesn't make me feel ICANN needs less oversight. And it's questionable whether the US can grant independence it cannot revoke, at least from an international realist perspective.
From https://www.washingtonpost.com/lifestyle/style/national-geog...
> On Wednesday, the iconic yellow-bordered magazine, beset by financial issues, entered its own uncharted territory. In an effort to stave off further decline, the magazine was effectively sold by its nonprofit parent organization to a for-profit venture whose principal shareholder is one of Rupert Murdoch’s global media companies.
I was buying the mag because I was happy that the profits went to the researchers in jungles all over the world etc.
I loved the nature and antiquity and exploring stories that used to dominate.
Steadily through the 2000s I found more and more stories that I skipped because they felt political and us-centric.
And then the sale? That was enough.
It was one of the sub-magazines that proliferated (probably as they were trying to keep the print business alive). Grabbed a couple in an airport, but they seemed more interesting and focused than the main one.
.org prints money - they have almost no overhead, and a basically guaranteed revenue stream. This isn't a public good that has no other options to survive - it's a bunch of shady board members attempting to enrich themselves at the expense of the public good.
1 .org is not a non profit and is not just for us style "non profits"
2 What ICANN (or ICANT as those of us that have had dealings with them call it) stinks to high heaven.
What should happen is a proper transparent biding process which is how it used to be done.
It makes sense for both parties because for the seller the investment gains from the capital they're getting from this transaction will be similar to what they're making from running the registry. But they no longer have the headaches of running the registry.
For the buyer, well, it's a monopoly so the sky is the limit. Even if current seller is able to raise the prices, they might not want it due to the backlash this would cause. Current buyer is less constrained by this.
Selling off some or all of an asset that has become unexpectedly valuable can fund the organisation’s wider mission with a windfall endowment.
No one buys such an argument in this case because, just as sports are a big part of school, so too is it ICANN’s core mission to provide equitable access to names in TLDs — or at least that’s what most people would say it is.
(Apologies if this ruffles the feathers of anyone fighting a school playing field sell off battle, especially if you also own yourschool.org too.)
with the possible exception of .gov (and local equivalents), people should not be encouraged to use TLDs as a positive signal of credibility. imo, the only things that matter are that domain should point to the expected entity (eg, wellsfargo.com points to the bank, not a phishing site) and that disputes over who gets to use a specific domain get handled in a reasonable way.
There is no perfect solution of course, but generally speaking ORG domains have been used to signal that you are an organization vs. a corporation, and potentially a non-profit.
That said, just like in the real world, individuals are encouraged to do their research and confirm that one is what they claim to be (just like door-to-door charity workers) before engaging.
this is the convention, but I don't think it's ever been enforced by the registrar. see questions 5, 7, and 8 on this archived faq: https://archive.is/20120716084313/http://pir.org/get/faq/gen...
what I'm getting at is: if ICANN never enforced the convention in the first place, and they are selling it to someone else who also doesn't intend to enforce it, what should I expect to change?
when it comes to security in particular, conventions that are usually (but not always) followed are often worse than having no convention at all. it sets dangerous expectations for lay people.
I think the biggest concern with this sale is around pricing more than "correctness of use", where I agree with you the ship has long sailed.
Selling PIR to a for-profit company, a private equity firm no less, means you can pretty much 100% guarantee that in the future pricing would be increasingly profit-driven.
Decentralization has so many downsides compared to centralization when things are going "right" that centralization has competitive advantages over decentralization.
Maybe even the .tld model is too old to help identify hosts. In the beginning of Internet com, edu, gov, mil, org were enough to group hosts. But now, that we have zillions of hosts, .tld might not be enough.
If IPv6 is a response to IPv4 limits, maybe we need something better than .tld, too.
opening up TLDs for sale seems like a (somewhat) logical way to expand the available namespace for domains. We have zillions of hosts, why require them to conform to one of a few random categories.
Certainly, I have issues with how TLDs are allocated and controlled, but that doesn't mean that the general idea of allowing essentially arbitrary top level domains the same the way we do with second level domains is inherently a bad thing.
Any of .onion, .bit, .coin, .eth, .crypto, .zil, can expect the .dev treatment, or, in time there won't be many nice available one for future developments. Similar issue might be with things like .ipfs, which don't resolve in the usual sense, but could cause confusion if there was an ICANN .ipfs domain.
Some domain trader will come and say those aren't "real" names, and you are supposed to rent them from ICANN, but that seems like a protection racket.
https://www.iana.org/assignments/special-use-domain-names/sp...
It does the reverse. There is only one root zone. Before the root was a free-for-all there were hundreds of different areas to set up shop in the namespace. Now there are exactly two: 1. have fuckloads of money to piss away on a vanity TLD, or 2. use someone else's TLD.
Every TLD has the same possibility space as the root zone, but we only get one root zone. There are no do-overs. Careful creation of TLDs allowed mistakes of previous TLDs models to not be repeated, experimentation with different implementations, business models or namespace allocation strategies. Now there's exactly one.
We used to have headroom at the top to sidestep "hope an existing brand isn't squatting the name" and try things like country code TLDs, .arpa, and .int. Or tack resolution experiment onto the side with .local or .onion.
If you wanted to do any of those now, it's impossible because the namespace has been reduced. Go back to options 1 and 2.
Some would say the new gTLDs have failed to increase the supply of useful domain names, because the only people who use the likes of .info and .biz are scammers, and that bad reputation scares users off.
It was also well known from the start that the gTLD program was going to extract a lot of rent from domain owners - that the likes of Volvo would end up paying $180k for the .volvo TLD and $300 for volvo.sucks and so on.
Some people see the fact gTLDs had none of the benefits and all of the costs, and yet ICANN keeps on issuing them, as a sign that it was never about the benefits to begin with - that it was about shaking people down for rent all along.
I tried to buy california.beer on the first day .beer was available to the public. It was always listed as unregistered but if I tried to buy it strange errors occurred.
After the time period where they were required to allow registrations for a set price, california.beer was listed for $1000+.
I fail to see alternative DNS as much better solution, as that still depends on having tlds.
For sure, identifying hosts in a "good for all purposes and all actors" manner it isn't a easy problem to solve, but it something that might makes lives of many easier.
And even if you come up with a great solution, how you convince most actors to use it?
If we had DNSSEC and DANE support in browsers, it would solve the security problems stemming from certificate authorities being able to issue certificates for any domain they like. Handshake would enable people to actually own their domains and bypass the CAs altogether.
Definitely a valid point - DNSSEC and DANE are incomplete without Handshake [1].
> quirky version of the DNS
It's the same DNS, simply the root was decentralized from ICANN to the commons.
> I don't understand why this project is taken seriously.
The reason the project is taken so seriously by so many is because the project improves our internet by improving security [2] and gives ownership of the internet back to the people where it originated, and where it belongs [3].
[1] https://github.com/handshake-org/hdns
[2] https://handshake.org/files/handshake.txt '### Proof of Work as a Trust Anchor'
[3] https://handshake.org/files/handshake.txt '# Stakeholders'
Rather than being a 'blockchain' project, Handshake is a project that makes use of blockchain technology to solve a real problem that the world has been trying to solve for some time [2].
Later:
Sure looks monetized:
https://www.coingecko.com/en/coins/handshake
Is this just someone stealing the Handshake project's name, or does the Handshake project really believe that a piece of Internet infrastructure will be run off a trading cryptocurrency --- and, not just that, but their trading cryptocurrency?
With that aside, to answer your question regarding monetized/cryptocurrency, here is an excerpt from the notes and there are far more details that can be found therein:
A blockchain is proposed which optimizes for correcting prior weaknesses around acknowledging stakeholders such as existing top-level domain (TLD) holders and optimizes for decentralization (while still allowing for n-of-m attestations). Users use the native token (coin) to register TLDs which are pinned to a specific certificate as the identity. A committed merkelized proof of all top-level names allow for compact, shareable inclusion and exclusion proofs. This blockchain exists to attempt to resolve the need for a globally unique namespace which is necessary to have an association with unique names and certificates. While it's possible to create a singular centralized globally unique association (DNSSEC), a decentralized system can be resolved by creating a blockchain with its own cryptoeconomic incentives (coin), including name auctions of a unique namespace and block creation. Scarce resources require sybil protection, usually managed by a central trusted authority (CAs, ICANN), but can be resolved by having a blockchain based mechanism for global consensus and resource allocation.
[1] https://handshake.org/files/handshake.txt (# Project Summary)
If so: it's a dead project. I don't know why anyone would take it seriously. I'm skeptical of the entire model for any application. But for Internet infrastructure? Never going to happen.
Handshake is based on the ideal that the internet belongs to the people.
> If so: it's a dead project. I don't know why anyone would take it seriously. I'm skeptical of the entire model for any application. But for Internet infrastructure? Never going to happen.
People will always strive for better. I believe it will be Handshake, but if not, something else will come. People find a way, that's how we all got here today. This very thread itself is proof that the current system doesn't fulfill the wishes of humanity and there is a need for change.
If you believe Handshake has faults, let's all work together and improve it!
The step seemed like it lacked any understanding of the mechanism design of handshake, and I realized it's because we skipped a step here. I like to start my count with 0:
Step 0: Please read the design notes document. Let's be constructive here.
Later:
In all seriousness, though, I urge you to read and understand how Handshake works and how different it is from these other 'cryptocurrency' projects that I am (and I'm sure many in the hn community) on the exact same page as you about. I trust you'll see why the community is moving in this direction.
Later 2:
Just incase you don't read the paper, the coin, and auction process, helps prevent sybil attacks among other things.
It’s clear you believe the usage of blockchain technology in Handshake is justified. But throughout this thread, whenever the question of ~“is your project backed by a cryptocurrency which is traded speculatively” has been posed, you’ve dodged answering it outright.
Later: My first response [1] included a direct answer pasted from the design notes - and it’s very clesr. Unfortunately, it won’t help if you don’t know what a Sybil Attack is. I incorrectly assumed that was basic knowledge in 2020 for anyone on Hacker News [2].
If you're saying B) I didn't explain to you what a sybil attack is, you're right, albeit I did provide a link.
In a global unique namespace that has no centralized control, there needs to be constraints and scarcity built into the system itself in order to prevent someone from launching a "sybil attack" which, in this context, means someone could register a trillion names without anything stopping them. By introducing a coin that in itself is a limited resource and including an auction process, essentially, there are a limited number of names since there are a limited number of coins, and, in addition, the auction process itself helps to prevent someone from getting a lot of coins and registering many names.
This explanation really just touches the surface as all the intricacies of the architecture are better detailed in full, in our project design notes [1] as I have continued to urge you to read.
Instead, you’re deflecting by insinuating that we haven’t read the spec, and thus refusing to answer the question we’re posing to you.
Perhaps if you're really short on time (aren't we all?), you might at least find it amusing that the Handshake developers took $10 million of VC money and donated it to Free and Open Source foundations [2]. That was actual cash donated, not just magical internet money.
It doesn't even matter what I think about this design. Speaking positively, not normatively: this is never going to happen. Everyone from billion dollar corporations to academic research labs to inexplicably influential Internet curmudgeons working out of basements will recoil from this.
You get 63 bytes (really, ASCII chars, fewer Unicode codepoints using IDNA) per-label in a DNS domainname, and you can have many labels per-domainname, which means we really can't run out of names the way we have run out of IPv4 addresses. The comparison you drew is just not valid.
By "tld" you seem to mean "DNS". DNS is basically irreplaceable at this point. We can replace the UDP port 53 protocol with, e.g., DoT (DNS over TLS) or DoH (DNS over HTTP), maybe nice RESTful APIs -- whatever, but we can't replace the DNS data model because it's too deeply embedded, and not exactly busted and in need of replacement.
That is, domainnames are here to stay. DNS Resource Records are here to stay. Access methods and representation on the wire can change, but their semantics can't.
Given that, more TLDs, or not, makes no difference whatsoever to availability of domains for all sorts of organizations, as well as individuals.
Something that is scalable, is easy to use from a technical perspective and also easy to use by humans?
The biggest thing to solve is that meaningful dictionary words are few and many people fight over them. But the current solution to that means thousands upon thousands of tlds, which nobody cares of, are hard to remember. Most people still fight over .com domains and prices got to insane levels.
To have the chance to use a decent .com name for your business, you have to first buy another tld, work for a few years, pile up some millions of USD and get it from the domain hoarders.
Having a .com domain with a name relevant to your business is still perceived as a big advantage.
We can, but every single solution is a set of trade-offs and even geeks will never agree on what's the right set of trade-offs. If the people who could give the tech widespread support don't agree, how is there ever any hope of rolling it out?
The only way I see to shatter the status quo is if big companies decide to push ahead with whatever they came up with and the rest of the world just has to follow. QUIC is a bit like that, I think.
Only problem is I don't there being big incentive for big companies to overthrow the system. It works well enough?
Of course, I would love to throw away DNS and start using a system where I can be John Smith and you can be John Smith and I can pass your fingerprint to my friend John Smith so that they won't accidentally connect to John Smith the rich prince from Nigeria.
I think one global namespace is a dumb idea.
That's exactly what we have right now.
This is a business/culture/government/economics problem—not a technical one. As long as the end goal of the system is "type in a string of text on any computer connected to the internet, and get the same result[1]", we're going to have issues like this.
When I got my first domain name, the cost was $100 for two years (and $50/year thereafter). At that price, no one thought of squatting on any but the most lucrative domain names—certainly not mass-registering thousands of domains and holding on to them for years. I don't want to go back to those prices, but those are the sorts of parameters that impact the domain name market.
[1] Yes, there non-public zones, geo-routing, etc. But as long as we define "result" as "exactly what the organization controlling that substring wants you to get" I think it works.
The amount of money businesses are willing to spend on branding is large enough that there is no price point that would allow me to both afford renewals on my email server's domain, but doesn't also enable squatting.
Also, some TLDs have prior rights and domain dispute processes for speculators. Namespaces can be handled much better than current .com situation.
You mean like DNS?
What we need is a simple, good technical solution that identifies hosts but removes money from the equation.
How is this legal and why isn't it being criminally investigated?
It opens with this:
My office has “responsibility for supervising charitable trusts in California, for ensuring compliance with trusts and articles of incorporation, and for protection of assets held by charitable trusts and public benefit corporations…” (Gov. Code, § 12598.) My office is tasked with the authority to “investigate transactions and relationships of corporations and trustees…for the purpose of ascertaining whether or not the purposes of the corporation or trust are being carried out in accordance with the terms and provisions of the articles of incorporation or other instrument.” (Gov. Code, § 12588). To that end, my office conducted an investigation of ICANN and its role in approving the transfer of the .ORG Registry Agreement from the Public Interest Registry (“PIR”) (the supporting organization to the Internet Society (“ISOC”)) to Ethos Capital...
and yes, ICANN is based in California, so it seems they could possibly have their charter revoked if they sell and the AG comes after them (IANAL).
Domain names will be one of the first major applications of global consensus algorithms.