Re: [therightkey] First public DNSChain server went online yesterday!

Tao Effect <> Sat, 08 February 2014 01:35 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id 0C46A1A058A for <>; Fri, 7 Feb 2014 17:35:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.334
X-Spam-Status: No, score=-1.334 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_SOFTFAIL=0.665] autolearn=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id ExV2pB1Yvpd8 for <>; Fri, 7 Feb 2014 17:35:08 -0800 (PST)
Received: from ( []) by (Postfix) with ESMTP id 3B4A31A01E6 for <>; Fri, 7 Feb 2014 17:35:08 -0800 (PST)
Received: from (localhost []) by (Postfix) with ESMTP id 9C96A25C06A; Fri, 7 Feb 2014 17:35:07 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed;; h= content-type:mime-version:subject:from:in-reply-to:date:cc :message-id:references:to;; bh=oFv3ALvlMX8oF7FtQ K9T623g2TU=; b=K39xYl/kT/TIf7vLbIwsFMFrkN+gnq8Keu0KRO1En/2W4QXtr tKBWfnjfMEFlezvDQbfKF5dYUWNf9VN4Sy/gbzZW1b5kRqf+R3nXCDYfxO2x+sHh a8CSaghj9l8CuG14sUZjjCdVqBL+4ZLgUk7yseTmFAoXCTkSCwCUuwQm5I=
Received: from [] ( []) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: by (Postfix) with ESMTPSA id CED5325C06D; Fri, 7 Feb 2014 17:35:06 -0800 (PST)
Content-Type: multipart/signed; boundary="Apple-Mail=_8D0250B6-DB3B-4BBD-A608-10BFB4CA6A51"; protocol="application/pgp-signature"; micalg="pgp-sha512"
Mime-Version: 1.0 (Mac OS X Mail 7.1 \(1827\))
From: Tao Effect <>
In-Reply-To: <>
Date: Fri, 07 Feb 2014 19:34:59 -0600
Message-Id: <>
References: <> <> <> <>
To: Andrew Sullivan <>
X-Mailer: Apple Mail (2.1827)
Subject: Re: [therightkey] First public DNSChain server went online yesterday!
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Sat, 08 Feb 2014 01:35:10 -0000

Hi Andrew,

Thanks for the feedback!

> Given that you're basically telling people to use these names in a
> context where DNS names are expected to go, I would like to suggest
> that you want to do something than make up a string that you think
> won't collide in the DNS, for two reasons: (1) these queries will
> sometimes leak by accident onto the public DNS, where they're "junk",
> and (2) a new TLD applicant of the future could ask for .dns, and
> there's no obvious reason why ICANN would have to say no.  This will
> represent a security risk to your users.

This equally applies to GNUnet's DNS system (.gnu?), to Namecoin's .bit, and to Tor's .onion links.

The public DNS is broken and insecure.

ICANN is an old, centralized, and insecure thing, that I personally feel, at this point, is more deserving of the label "junk". ;-)

> I would like to suggest some other domain name.  You can register any
> available thing you like.  It need not actually resolve in the public
> DNS, as long as it is registered so that nobody else can get it.

How do I register the .dns TLD?

Does it involve paying money to ICANN? I'd rather not pay them anymore than I'm already begrudgingly paying them.

Is it even possible? I doubt it. :-p

"Hey guys, I'd like to put you out of business and make the whole domain registration thing decentralized, could you please give me .dns?"



Please do not email me anything that you are not comfortable also sharing with the NSA.