Petnames: A humane approach to secure, decentralized naming (2018)
github.com
github.com
It may be an entirely suitable approach, but it basically means there are no global short names. I can’t tell you Im at pfrazee dot com if there’s no global dot com registry.
The next step is to create a system for "peering agreements" between registries, or meta-registries.
Actually, this is handled pretty clearly in the example article.
Yes... or, not at all, depending on how you want to look at it. To use their phone book example, if I want to call my dad, I look up "dad", and I call him. I don't use his phone number (although obviously down in the internals of my phone it's going to use his phone number).
If you had a local mapping for a web site saved as "coolsite", you might post a link here on HN as "web://coolsite". Your browser would take care of translating that into a UUID under the covers, so the actual post would contain the UUID. When I read the post, though, I would probably see the link as "web://@pfraze => coolsite" (obviously your browser would need to post some metadata for that to happen - similar to how you can include a name with an email address) or if I already have the site in my local mapping I might see it as "web://thatawesomesite", or whatever name I'd chosen. Or perhaps my browser would go to something like DNS to reverse lookup the UUID.
I wouldn't try to think about this as "What if we implemented a browser plugin that supported this?" Instead, think about if this was "the standard". Imagine a world where there was excellent support for it in all software that we use, and browsers and/or sites would find ways to make it transparent and friendly. Like, what if VS Code made it so when you hovered over a URI in a piece of code, it would look it up in your local pet name database, and show it in a popover? If this were just "the way things are done", then you'd never put up with crappy software that showed you the UUID. It would be like web sites that don't let you highlight or copy text - software that didn't handle naming resources correctly would be obnoxious software you'd hate to use.
Previously, on HN (just this morning, still on the front page) https://news.ycombinator.com/item?id=32493946
so if I wanted to share a document about how much water we need in total per day, I could just share you the complete url... or at least that's what I was thinking earlier. As long as I don't have to type it by hand, it should be ok, right?
https://numpad.io?#text/O4ewTgNgJg+gDiOBXCBDALgSxAOwAQC8eA7A...
my rough estimate calculation if anyone is interested, a cube that is about one kilometer and half (under a mile) on each side is enough water for all the people in the world for a day.
<petname ref="pet:4f30b43ec38b43c3abad5d422125900f" proposed_name="Google" />
The browser would then display this in the same way mentioned in the OP; if you already have an entry locally it shows your local name, otherwise it shows the proposed name and marks it as such.Could you drop the petname and let the clients resolve it via the UUID of the Hacker News website?
Edit: I believe the article calls this "edge names".
A quick Google found "The .com and .net TLDs had a combined total of 174.7 million domain name registrations in the domain name base3 at the end of the first quarter of 2022" Twelve digits covers 40bits or 5bytes and should have more than enough space for all DNS entries.
A naming system that is both permissionless and globally unique will tend towards unreadable names. You'll see lots of Sybil attacks on these systems, with botnets squatting any decent name.
For DNS, you have many governance bodies that act as gatekeepers for domain registration. Repository hosts like GitHub avoid Zooko's triangle by having namespaces, and an appeal process if someone is squatting your trademark. Crates.io on Rust doesn't allow automated crate creation.
In many cases, naming systems are not permissionless, and gatekept by a central entity. Once you open the floodgates of permissionless-ness, you're dealing with a hostile environment that's difficult to control.
Petnames are one solution to this issue. Others are Handshake, Namecoin and ENS
The second piece to this is how the GUI works. Instead of showing long bit strings or hex encoding them in some pointless way, it allows you to assign names to these addresses as you come across them. When you see the address in some other page it will show up with the name you assigned and so you will recognize it.
A key point to this is that HTTPS does not actually cause you to know you are using the right domain name. Aside from the fact that HTTPS is untrustworthy due to the CA model, mybrand.com or mybrand.net or one of the other infinite number of legitimate sounding things could all be the correct domain for some brand, you would never know unless someone previously introduced you to the right domain name. Since you had to get it from somewhere, you may as well have received the public key at that point, which could be encoded in a QR code, or, on the internet, which is the main use case of petnames, trivially included as a link in some web 8.0[1] page or chat where you first heard of the brand.
1. I guess it will take them 6 more tries to get this right.
<a href="https://example.com/aresource">A resource</a>
In essence the anchor text becomes the petname and is human readable while the href points to the URL of the resource referenced by the link described by the petname.If you want a name authority, use URLs. What you alias them to is up to you since only you use the alias. If you need the alias also to be globally unique, tough luck! Use URLs there as well (or invent new naming schemes and try to get them adopted).
For example would something like a robocaller be able to reconstruct my social graph? What about work/life contacts leaking across boundaries I’d prefer they didn’t?
http://www.skyhunter.com/marcs/petnames/IntroPetNames.html
A pentane system actually protects you from phishing attacks and you don't really share your pentanes. You can use your petname as a nickname when introducing a key to someone else. One of the most important parts is to have a good UI/UX that does not confuse nicknames with pentanes or allow you to accidentally accept a nickname as pentane that is confusingly close to an already existing petname.
Nicknames are names that you propose using when introducing yourself or someone else. A pet name is the name you assign privately. So Lumberg could be a nickname but your petname might be "dickhead boss". You're free to introduce him to people you know either way you'd like.
To put it differently, no petname system built on top of unix / web crap will ever be good. Everyone (like posters here) will not understand what they're doing and just write code that breaks it on all layers of the OS and GUIs. Guaranteed if Android starts using petnames more there will just be issues like it copies someone's petnames all over yours, shares the ones you didn't want to share, etc.
This claim is unsupported.
If you have created or know of a better version of petnames, I'd love to hear about it.
Every uuid maps deterministically to an abstract avatar which can't be changed. It can be canonically 64 or 128 bits, but allow the user to see a 32 or even 24 bit visualisation if they please. If identities have significant cost (such as needing to subscribe to a provider or to be embedded in your local social graph) the smaller should suffice even as a default.
Allow saving with whatever name you please to a list or using the target's name for themselves.
Allow sending a contact with metadata including optionally the nickname
Allow lists to be published, and whole lists to be saved as entries.
Don't hide the uuid ever because that's condescending and introduces many vectors for bad things. People learned what phone numbers were, trust them to learn what a UUID is if you stop shifting the sand under them for a minute and hiding what is actually going on at every opportunity.