[ZTCPP] Re: [hackathon] IETF 126 Hackathon project: OpenNHP — The Internet Is Becoming a Dark Forest

Benfeng Chen <benfeng@gmail.com> Sat, 18 July 2026 09:07 UTC

Return-Path: <benfeng@gmail.com>
X-Original-To: ztcpp@mail2.ietf.org
Delivered-To: ztcpp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 98FA9118C8474 for <ztcpp@mail2.ietf.org>; Sat, 18 Jul 2026 02:07:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784365624; bh=QFrLzWnd225c2RzqApyazGZl2vW+1j/HlmpqsoxctIs=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=ccD0GWt2ehn5f5CGBty3fjjP+I4JPX700gq7L+BOA9yiN2ZEPAmKreUmxwiVjei1B ndCMb97lwA5XIGin4eKCUWyuTkw5XK5jHXF0xuzwF4PBaI6/v1AngLsTDoDqLtgW8u 28iHRMtbL/KdFJdSuxwUBlf2zxpwAmHf6tbyY6fw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pIDO4VsWYCWD for <ztcpp@mail2.ietf.org>; Sat, 18 Jul 2026 02:07:03 -0700 (PDT)
Received: from mail-ej1-x636.google.com (mail-ej1-x636.google.com [IPv6:2a00:1450:4864:20::636]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D32C6118C846D for <ztcpp@ietf.org>; Sat, 18 Jul 2026 02:07:03 -0700 (PDT)
Received: by mail-ej1-x636.google.com with SMTP id a640c23a62f3a-c1670dad7a8so739028566b.3 for <ztcpp@ietf.org>; Sat, 18 Jul 2026 02:07:03 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784365623; cv=none; d=google.com; s=arc-20260327; b=VA101+OIEyCkv/naD4GT+gWDZL3NJrlGOTnIgqT8UYTkUCctyYM7YTp3K9IY7YCp1/ 97icv/DBg82jr/oa8sN+4SccONpaBo4RQraIfNe0pZMqnDCxFtA3zlA5tpBfsA1Sn2vz CxUZUdWF9d3BuIdZcBjW7miRvdByqLgkU+ZXd2dfVc87h9ppWA1Rbw/ho+OmDpkYIiyS Nk1NW1KATqjXLe7wDVCGpsG0hZzkTzBPHlnuFw5ag1DlAoKI9PfNQtE55Ua2IPnkgtmM DHL7npcyhq/nAP2Ls0s/6mA6fscK0VO/vL9d3ua2MzBZUXzZDkx7MpBGfahc37FSXn51 Ht0w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=q1Uu8xz4B0eylEThcASB7MFzTdtby4/11pvvYHik8S8=; fh=4a08NNXnvOWi4a5S3rN+Vf2LznykZsgsWTqEBTFpKxc=; b=DJkb4iBPvCCW9p5W3G7FcLvCwoFr8I4md/4p+fcoO/fSLlwBfZR2HcFyb5bRrcuhfw 9cQk02cVk9aG2uXJw8fzEiByOQPpV3sr79TfzZCqdUo0fbYbUoyj/ZR8Z7o1ofGEVjmu 4B1EwqYWn4TfdJLAZgKyNCmDutYtuJQNWuDfCssD9FF+AzkMrCGdSzsD7KCxozPwbBKs R8htwg17w6dQ1FEn2O9C5DOZtGGm1cXIxfkVSV/SE6CLulaP/wF0gUqCvIxWoUniBTSN YJUIP1nb8DOlVlDOAGKwveRCA6ep+/kEv+YA7Sj7nD0efbRIeRNmirL74CnPTsS6PX5G D8cw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784365623; x=1784970423; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=q1Uu8xz4B0eylEThcASB7MFzTdtby4/11pvvYHik8S8=; b=dmSSOz/arIJXfwuHgKGdFu2dbAAYFwhOP4i9546nGOngZdOrZ1t+1KGO94qNGTyMyq R+mu3dhZGny+aYydmRg69AMh6T7PpZbY/9uyg2t+krvCoN/smRy55HSujO2Mp1I5hpnm z9BaOd8b6I6tI4UbtrveZZho7Tww/gXBqGsHJMxOQckkCKYlRbo1BhzSUwk4i3EaSMvi cmfA0UXtJUv15VaL1WorCiIXJVIhVChADI/onHOvvTLmlBP0o9qpkedgKPpnEwr0liI7 /Dv+dBRo64hZT2P6j+5/Qa6mEkzSEGiIYXOxHBw5O0z8//F9BO9SZ/AsGNqpfLvFetJW EswQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784365623; x=1784970423; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=q1Uu8xz4B0eylEThcASB7MFzTdtby4/11pvvYHik8S8=; b=ZE1J/l6Nrsmb7zku/MzNdYQKDONDGGI4vBwJRVCrzgPK1QRntBFx6dUsheTpDMp91Q FB0cCaTVaDFz++VDrGaa2w/Ts6i0WjAiq2GFIngxwL8LQI3JIgtXqlHSb77QkaxPE/0s /Xxk7mhcMGJyjX1tgPxMmSIOSSxym5KIWEFba+CF0wi8afDaTTci5S5g5ibGkfNBmoFO 2Pfo4roSGMqmtvp2grcFlwRsRPXfUmhangNNa785YZQzyRifvWhcD1fkTi9Vwxw93A6P vyqu0wkDmEceSg8ILkgPOSZe83D67qjRu3aNdMjn4XhvkaG0bvbqSbDgHTiYt0JVArG7 OnJg==
X-Forwarded-Encrypted: i=1; AHgh+RpgncmSxC2Yql9Maqxg+DZ43ytXzRFTmCVbh5qYre9dS56YjIc4km2Q8Wlju++LKF/28v+ZJQ==@ietf.org
X-Gm-Message-State: AOJu0YydG8hGIjNNrDrdU4urr0d6U9xXSJVln0Fh22uWTPLRtlwzXc4T gOprjHiJPCAC70iK484ag4TNyaMtbpguK1pFp0j2r0xVDke6zCQLeifCXE3rsUpnyDERMUQrdMd S3kPoRPbZJhL0uFU0KLWMCSZOilKDMVA=
X-Gm-Gg: AfdE7cnmp/k5NIYEta2C3TkBCV6A4j++loDS903JdROi1DJlRVrUSBXmKlq60kUA+wG yhyabAOCi6z1lG4ZboFivzfSQvuHoAv+fTVj4Wu6O2Yi8qRgSQSbwaDqsRDub2D6sg5bUngQhrK IcUjEgERyAoNbCJ6CrOH9nAS1YWMVrwTINK7JPoZF/KulnHfXMhZHMJu6japNjGrYKbV5uIum6J ygEgiHynWFkCuoPFItPZ/un1Yl5RFFIfitlcY0OOlyMaWvDkkJyB9v7t2dZ3UZyYLAxhKyIyFiK 3E3DiA4UUnCDsX+w
X-Received: by 2002:a17:907:948c:b0:c12:45fc:c25 with SMTP id a640c23a62f3a-c16b47533c5mr295639466b.17.1784365622635; Sat, 18 Jul 2026 02:07:02 -0700 (PDT)
MIME-Version: 1.0
References: <CAPSJW7ALiwVfP16eTSd9pvPz4v_2xo0wxDaf37MU6mquZX2fLw@mail.gmail.com> <CA+syWAPSpdf7BK_-ux-h5rye+we_4jp1WtdhJ-9D_od8_cQCHw@mail.gmail.com>
In-Reply-To: <CA+syWAPSpdf7BK_-ux-h5rye+we_4jp1WtdhJ-9D_od8_cQCHw@mail.gmail.com>
From: Benfeng Chen <benfeng@gmail.com>
Date: Sat, 18 Jul 2026 02:06:51 -0700
X-Gm-Features: AUfX_mzwaCoj1I_YZmS1e8LnYQYEAx6rmhrVybAT8ueD97F8rijJOB0Ch98suRE
Message-ID: <CAPSJW7AhAKmb5k8khPqZ_gQmYWinmFDcO0SEOo__C_4Sgf3pwQ@mail.gmail.com>
To: guest271314 <guest271314@gmail.com>
Message-ID-Hash: 7UJ6U4RO4PHLSVNFDDZYAGO5OSDU6DUO
X-Message-ID-Hash: 7UJ6U4RO4PHLSVNFDDZYAGO5OSDU6DUO
X-MailFrom: benfeng@gmail.com
X-Mailman-Rule-Hits: member-moderation
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address
Content-Transfer-Encoding: base64
Content-Type: text/plain; charset="UTF-8"
X-Content-Filtered-By: Mailman/MimeDel 3.3.9rc6
CC: hackathon@ietf.org, "ztcpp@ietf.org" <ztcpp@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [ZTCPP] Re: [hackathon] IETF 126 Hackathon project: OpenNHP — The Internet Is Becoming a Dark Forest
List-Id: Zero Trust Control and Policy Protocol <ztcpp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ztcpp/5wZLPo42bHmNg6Ra3clCsmY93tM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ztcpp>
List-Help: <mailto:ztcpp-request@ietf.org?subject=help>
List-Owner: <mailto:ztcpp-owner@ietf.org>
List-Post: <mailto:ztcpp@ietf.org>
List-Subscribe: <mailto:ztcpp-join@ietf.org>
List-Unsubscribe: <mailto:ztcpp-leave@ietf.org>

OpenNHP is at *Table 14*. You are welcome to stop by.

On Mon, Jul 6, 2026 at 2:35 PM guest271314 <guest271314@gmail.com> wrote:

> > *Please try to break it.*
>
> I like it. All too often folks talk about "safety" and "security" within
> the scope of testing their own gear, in-house. That simply doesn't verify
> anything.
>
> I'll check out the details and pass around the idea
>
> von Braun believed in testing. I cannot
> emphasize that term enough – test, test,
> test. Test to the point it breaks.
> - Ed Buckbee, NASA Public Affairs Officer, Chasing the Moon
>
> On Mon, Jul 6, 2026 at 5:33 AM Benfeng Chen <benfeng@gmail.com> wrote:
>
>> Hi all,
>>
>> The recent concerns surrounding autonomous AI-driven cyberattacks,
>> including discussions around systems such as *Claude Mythos*, may be
>> signaling a fundamental shift in cybersecurity: autonomous AI agents are
>> turning the Internet into a “*Dark Forest,*” where anything visible can
>> be discovered, probed, and exploited at machine speed.
>>
>> As described in the “Dark Forest” theory from Liu Cixin’s *The
>> Three-Body Problem*, the only reliable survival strategy in such an
>> environment may be *invisibility*. Rather than continuing the
>> decades-long cycle of exposing services and then attempting to defend them,
>> we are exploring a different question:
>>
>> *What if network infrastructure were invisible by default?*
>>
>> To explore this idea, I’ve added a project to the IETF 126 Hackathon wiki:
>>
>> *OpenNHP — Network-infrastructure Hiding Protocol (NHP)*
>>
>>
>> https://wiki.ietf.org/en/meeting/126/hackathon#opennhp-network-infrastructure-hiding-protocol-nhp
>>
>>
>> OpenNHP is an open-source implementation of the emerging
>> Network-infrastructure Hiding Protocol (NHP), an
>> authenticate-before-connect Zero Trust protocol designed to make protected
>> infrastructure inaccessible—and ideally undiscoverable—to unauthorized
>> entities.
>>
>> Unlike traditional security architectures that attempt to protect visible
>> services, NHP seeks to prevent reconnaissance, scanning, DDoS, and
>> pre-authentication exploitation by hiding network resources until
>> cryptographic authentication succeeds.
>>
>> For the IETF 126 Hackathon, we’re inviting the community to do something
>> simple:
>>
>> *Please try to break it.*
>>
>> We welcome participation from security researchers, protocol designers,
>> cryptographers, network engineers, DNS/TLS/PKI experts, AI security
>> researchers, and anyone who enjoys attacking assumptions.
>>
>> Potential challenge areas include:
>>
>>    - Discovering protected services without authentication
>>    - Enumerating hidden ports, IP addresses, or domain names
>>    - Performing reconnaissance against NHP-protected infrastructure
>>    - Bypassing authentication or authorization mechanisms
>>    - Exploiting pre-authentication attack surfaces
>>    - Testing resistance to DDoS and scanning attacks
>>    - Finding cryptographic weaknesses or protocol design flaws
>>    - Evaluating AI-assisted attack techniques
>>    - Testing interoperability and performance characteristics
>>    - Demonstrating any attack path that violates the
>>    “authenticate-before-connect” security model
>>
>> The challenge outcome is straightforward:
>>
>>    - If you can discover or access protected resources without
>>    successful authentication, we want to understand the weakness and fix it.
>>    - If you cannot, we collectively gain additional confidence in the
>>    security properties of the protocol.
>>
>> We believe that public adversarial testing, peer review, and running code
>> remain the best tools available for building trustworthy Internet security
>> protocols.
>>
>> Resources:
>>
>>    - Project website: OpenNHP Website <https://opennhp.org/>
>>    - Source code: OpenNHP GitHub Repository
>>    <https://github.com/OpenNHP/opennhp>⁠
>>    - Live demo: OpenNHP Demo Environment <https://opennhp.org/demo/>⁠
>>    - Internet-Draft: draft-opennhp-ztcpp-nhp
>>    <https://datatracker.ietf.org/doc/html/draft-opennhp-ztcpp-nhp>⁠
>>
>> I’ll be participating in person at the Hackathon and would welcome
>> collaborators, critics, and especially skeptics.
>>
>> Thanks,
>>
>> Benfeng Chen
>> OpenNHP Project
>> _______________________________________________
>> hackathon mailing list -- hackathon@ietf.org
>> To unsubscribe send an email to hackathon-leave@ietf.org
>> Unsubscribe: mailto:hackathon-request@ietf.org?subject=unsubscribe
>
>