Show HN: No Signup, Yet, Authenticated Posts
applause.chat
applause.chat
I tried leaving them blank and got an error message: "You need to include a valid Handshake name and signature generated with the key associated with the name."
But it doesn't explain how you do that.
There are many ways to get Handshake names, but the easiest ways are to use Bob (non custodial) [4] or Namebase (custodial) [5].
[2] https://www.reddit.com/r/handshake/comments/pt55vb/namecheap...
[3] https://twitter.com/opera/status/1476841607005622273
The popular names are in the names folder.
I wouldn't recommend obtaining a new name from any random website. I don't think I did so. I'm going to avoid continuing this thread as gaslighting isn't usually something one would wish to engage in, obviously on the receiving end, but on the creator's end too.
I hope you are able to find peace in the next year.
Happy new year to you.
People hated it and actually took the time to complain.
The lesson for me - make your auth process precisely what people expect - if there's feedback, it should be about your product, not about the signup process.
Signup process is not a feature - it's plumbing.
In the case of this new product / service - I note the headline is almost unrelated to what the product does - it's a headline about how the auth works on this - the technology something is built with shouldn't be the marketing message.
This is a Hacker project to explore improved ways of doing things with the new primitives of our collective technology base. In this case, owning your own identity with a decentralized identity system.
I think marketing posts are better suited for another forum, no?
No, Hacker News "Show HN" posts are often launch/marketing posts - totally accepted here.
This isn't that, instead it seems to delegate the registration to some Namecoin-like thing, and I verify my identity but signing the content with my secret key? Did I get that right? I guess the advantage of that approach are human readable user names
This part can be addressed easily with avatars such as those Gravatar makes. Using a blockchain instead seems like a huge overkill, and also brings 'login' back into the equation, albeit with a different connotation than traditional login.
A gravatar is great for a profile photo, but in the end, there's no guarantee that the message viewed by a user was actually written by the poster. A site admin could simply inject posts as that user.
With signed messages, only those who possess the key could have created the signature for the signed message. Even a site admin cannot edit the message and get away with it (since the signature wouldn't validate).
If you think about it, this is also true for web3 — true enough that it's broken.
We don't live in a world where you can't take things from people, etc.
Ultimately, society works because we don't really need ironclad guarantees — and we don't have any.
You absolutely cannot fake a message being cryptographically signed without providing a broken verification function.
> We don't live in a world where you can't take things from people, etc.
The half glass empty approach is one method. The other method is to review the primitives we have in place today and explore different permutations that allow us to route around our adversities. That's the Hacker way. Of course, we do it with code.
> Ultimately, society works because we don't really need ironclad guarantees like that.
The society you live in is very different from mine. Fraud and impersonation are real. [1]
[1] https://www.theverge.com/2016/11/23/13739026/reddit-ceo-stev...
I think it might be wise to review what signing means to understand that I didn't "move the goalposts" at all [1], but thanks for the discussion, as I merit it will help a lot of people to better understand the power of cryptography as I'm guessing it's a new field here as of yet.
Happy New Year!
As always, there's a relevant XKCD https://xkcd.com/538/
If Person B published a message under Person A's name, that is, to the non-crypto world, a faked post. They're not going to be impressed by your argument that actually it isn't faked, it's real, Person B just had access to Person A's computer.
Happy new year.
I'm not making a comment out of pedantry, I'm telling you how I expect this is going to be seen by regular users. People on the whole are not interested in whether or not some particular security system is theoretically perfect, they're interested in whether or not it actually provides the security that they interpret it to promise. And they will interpret your claims as meaning that messages cannot come from anyone other than the signed user, which is going to be a problem the first time that assumption fails. And it will fail, because people aren't good at keeping secrets secret.
How about by obtaining the private key?
And getting access to private keys can happen by means other than the user volunteering them.
So if I wanted to make a post, I first generate a public-private key pair, and then sign posts using my public key?
Just looking at Handshake - if I buy HNS and purchase a domain, sure I can use the handshakeName and signature to authenticate to supported websites. But if I want to host a website with the domain, the possible options are using hns.to domain or have my DNS point to a different DNS server. Both are not viable options for my end users to reach my website. Is the expectation that overtime Handshake gains popularity and all existing services would have a mechanism to integrate into this?
This is different from a website like Hacker News or Reddit which aim to be social media websites and avenues to engage in discourse.
Applause, instead, is as you might say, a tech demo, but also aims to, through UX and feature, create a different kind of environment than general social media networks. Instead, when a user engages in the act of 'signing' something, people can either agree in whole or not. If they agree in whole, they actually sign the original message itself. It's closer to a "shouting out to the void in a certified manner, and others can join in the shout" versus "shouting out to the void and debating."
> Name: applause.chat
> Internationalized Domain Name: applause.chat
> Registry Domain ID: 1deb3f28409a44cb92dcf6ad12b77b70-DONUTS
> Domain Status:
> clientTransferProhibited
> addPeriod
> Nameservers:
> ns1.linode.com
> ns2.linode.com
> ns3.linode.com
> Dates
> Registry Expiration: 2022-12-29 02:01:19 UTC
> Updated: 2021-12-29 02:07:14 UTC
> Created: 2021-12-29 02:01:19 UTC
At the same time my login is not present in the handshake chain, that would make sense.
With signed strings tied to the keys associated with the handshake name, every action taken on a Web 2 website can now benefit from being verifiable [1]. You don't need the blockchain outside of the identity.
Secondly, the more I've been working with this technology, the more I've truly begun to understand how important it is to own one's name. There shouldn't be two afro88s. Imagine if there is an afro88 on reddit and this person starts acting a certain way -- and then someone comes here and they see your username and apply bias due to actions that were not your own?
Web 666 is a silly name for blending the "stacks" if you can call them that, together, but then again... [2]
[1] A reddit admin edited a user's comments. Imagine if that user was suddenly prosecuted on said "evidence?" What a shame, and cryptographic signatures really empower people on the internet, especially in a Web 2 world.
Handshake was purpose built to work with traditional DNS while ENS is something entirely different. I think that's why Handshake is gaining more adoption in the traditional DNS sector as well, but whatever the case, I've opted to work with this technology based on a number of factors:
1. The ENS project is great for creating human readable Ethereum wallets. However, it doesn't seem that it was initially suited to be used for DNS and that this was later patched on.
2. ENS is centrally controlled by a federation of key holders [1] while Handshake is decentralzed.
3. In Handshake, you truly own the name.
4. With blockchain already inheriting many inefficiencies when compared to more traditional systems, ethereum, while very cool, tries to be too much and the bloat has led to extreme fees for interacting with the blockchain.
That being said, I'm keeping my eye out on all of the naming projects. It's something I'm very interested in.
It's open source on github [5] and mixes Web 2 and Web 3 together causing some interesting benefits.
It supports drag and drop among other things!
Hope you like it!
MIT LICENSED! Do whatever you want with it!
[1] https://github.com/kyokan/bob-extension/pull/15