Show HN: Beacon – a new open-source privacy and security-focused browser
impervious.com
impervious.com
If it's yet another clone of chromium, then it's not really anything new.
https://blog.apnic.net/2019/05/27/dns-oarc-30-bad-news-for-d...
An explainer:
> 3. An attacker with a valid certificate can strip dnssec-chain-extension out of a TLS handshake.
That's true but decentralized namespaces are at least starting with a clean slate they could require this extension no CA is issuing names for those anyway.
For names that rely on WebPKI this standard could be less strict about pinning initially (treating DNSSEC as just another CA). Once there's more adoption in a few years browsers should look for it and fallback to querying the DNSSEC chain (could be included with an edns option RFC7901).
The "decentralized namespaces" stuff is interesting, because, of course, it gives away that game that a substantial amount of DNSSEC/DANE advocacy is coming from people speculating on a premined crypto-token that purports to replace the DNS, linking to it (after a fashion) with DANE. Also not going to happen (but if it does, I'm going to pre-mine an ARP coin, so I win either way).
Doesn't this need a native browser implementation for the handshake and p2p to be secure?
[0] https://developer.apple.com/documentation/webkit/wknavigatio...
I was out the moment I read the project bets on DNSSEC/DANE (a bad idea because why would you put CA logic into DNS) on top of a terrible idea (Ethereum).
Saying that you can mine proof-of-work tokens with green energy is a red herring, since:
- Some miners are clearly re-establishing previously closed fossil fuel power plants to meet their energy needs: https://www.bostonherald.com/2021/10/17/bitcoin-miners-resur... We can argue about the frequency of this, but it is undeniably happening.
- It will be hard to establish the true amount of fossil fuels used, since miners steal power when they can: https://www.theguardian.com/technology/2021/may/28/police-fi... See also the attacks on CI platforms to steal CPU cycles: https://drewdevault.com/2021/04/26/Cryptocurrency-is-a-disas...
- Installing green energy itself causes emissions: https://solar.lowtechmagazine.com/2015/04/how-sustainable-is... That means there's a hard limit to how much green energy you can install without causing catastrophic warming. Well before that hard limit, you reach a point where the additional emissions created by installing green energy sources are more than they can pay off before deadlines like 2030 or 2050, which means they are serving as carbon sources rather than carbon sinks in the relevant timeframe. In other words, they are accelerating the climate crisis rather than slowing it down.
- Total energy use may matter more than the percentage of renewable energy, since if the absolute amount of fossil fuels increases the emissions from burning fossil fuels will increase: https://www.lowtechmagazine.com/2009/11/renewable-energy-is-...
- The internet as currently designed may use too much energy, so switching to a system that uses even more energy by design is probably a bad idea: https://solar.lowtechmagazine.com/2015/10/can-the-internet-r...
Yes I am obsessed with Low-Tech Magazine, but they have lots of citations and I could easily find less nerdy sources.