I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?
I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?
And ICAAN can hand your domain over to US law enforcement regardless of the TLD and your register.
Is that also part of your decision tree?
Is this accurate? Like, I know what you’re meaning, but I’m pretty sure it’s not ICANN doing it, and more so your domain registrar handing it over to the US government.
I think the most control that ICANN has over it is they could theoretically, if they wanted to, delete an entire top level domain. Since they do control the DNS root, but that is the most that they control from what I understand.
I don’t know if they have the ability to delete or transfer control over an individual domain on legal request. I think that’s outside of what their actual system allows for.
ICANN can (theoretically) not force anyone to deregister your domain. If your stack is all outside the US, and everyone collectively decided to disobey the US, the Internet’s decentralization would be true.
For the Internet, the centralization is hidden in the IP block and DNS Zone delegation. After this is done, that region is decentralized. A/I’s problem was that the registry for .org is a subsidiary of IANA. With EU servers, EU DNS and a EU domain, EU clients cannot be prevented from connecting solely from the outside. The US would need a collaborator.
That is all well and good, but we have many instances of domains being pulled from people because of court ruling and your register is not going to defy a court ruling for your €17/year domain.
Maybe it should be! We need non-fascis-adjacent DNS roots.
https://opennic.org/
I worked on the Yeti Project a while ago, which showed that an independent group of operators can run root servers.
Managing the contents of the root zone was out of scope… we used the ICANN root.
There are authorityless blockchain-backed name registration services. In general, it is important whether you can localize a resource. If you can easily find it, the name doesn’t have to human-readable.
The root (haha) of needing better DNSes is because the ones that are are tied to technofascists and their ilk: techbros, nazis, psycopaths. So using something with blockchain sounds quite missing the point.
You do understand that a P2P proof of work backed global store is just infrastructure? And as egalitarian as DNS servers? And it doesn’t have the storage/compute footprint of a full bitcoin node.
The space of human-readable names is quite small, so proof of work is needed to protect it from being flooded. An alternative is to have your servers have names to be or derived from their public keys, or dissolve content from its location. Which brings its own problems.
if its not human readable, how will people know its the place they want to go to? I don’t think bookmarked onionsites is a particularly good idea
In order to find content, we used to have webrings, directory services, and then search engines. Most people don’t enter URLs by hand.
Aren’t the .country domains managed by the countries?
Who all get that authority from ICAAN