[ZTCPP] Re: [hackathon] IETF 126 Hackathon project: OpenNHP — The Internet Is Becoming a Dark Forest
Benfeng Chen <benfeng@gmail.com> Sat, 18 July 2026 09:07 UTC
Return-Path: <benfeng@gmail.com>
X-Original-To: ztcpp@mail2.ietf.org
Delivered-To: ztcpp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 98FA9118C8474 for <ztcpp@mail2.ietf.org>; Sat, 18 Jul 2026 02:07:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784365624; bh=QFrLzWnd225c2RzqApyazGZl2vW+1j/HlmpqsoxctIs=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=ccD0GWt2ehn5f5CGBty3fjjP+I4JPX700gq7L+BOA9yiN2ZEPAmKreUmxwiVjei1B ndCMb97lwA5XIGin4eKCUWyuTkw5XK5jHXF0xuzwF4PBaI6/v1AngLsTDoDqLtgW8u 28iHRMtbL/KdFJdSuxwUBlf2zxpwAmHf6tbyY6fw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pIDO4VsWYCWD for <ztcpp@mail2.ietf.org>; Sat, 18 Jul 2026 02:07:03 -0700 (PDT)
Received: from mail-ej1-x636.google.com (mail-ej1-x636.google.com [IPv6:2a00:1450:4864:20::636]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D32C6118C846D for <ztcpp@ietf.org>; Sat, 18 Jul 2026 02:07:03 -0700 (PDT)
Received: by mail-ej1-x636.google.com with SMTP id a640c23a62f3a-c1670dad7a8so739028566b.3 for <ztcpp@ietf.org>; Sat, 18 Jul 2026 02:07:03 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784365623; cv=none; d=google.com; s=arc-20260327; b=VA101+OIEyCkv/naD4GT+gWDZL3NJrlGOTnIgqT8UYTkUCctyYM7YTp3K9IY7YCp1/ 97icv/DBg82jr/oa8sN+4SccONpaBo4RQraIfNe0pZMqnDCxFtA3zlA5tpBfsA1Sn2vz CxUZUdWF9d3BuIdZcBjW7miRvdByqLgkU+ZXd2dfVc87h9ppWA1Rbw/ho+OmDpkYIiyS Nk1NW1KATqjXLe7wDVCGpsG0hZzkTzBPHlnuFw5ag1DlAoKI9PfNQtE55Ua2IPnkgtmM DHL7npcyhq/nAP2Ls0s/6mA6fscK0VO/vL9d3ua2MzBZUXzZDkx7MpBGfahc37FSXn51 Ht0w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=q1Uu8xz4B0eylEThcASB7MFzTdtby4/11pvvYHik8S8=; fh=4a08NNXnvOWi4a5S3rN+Vf2LznykZsgsWTqEBTFpKxc=; b=DJkb4iBPvCCW9p5W3G7FcLvCwoFr8I4md/4p+fcoO/fSLlwBfZR2HcFyb5bRrcuhfw 9cQk02cVk9aG2uXJw8fzEiByOQPpV3sr79TfzZCqdUo0fbYbUoyj/ZR8Z7o1ofGEVjmu 4B1EwqYWn4TfdJLAZgKyNCmDutYtuJQNWuDfCssD9FF+AzkMrCGdSzsD7KCxozPwbBKs R8htwg17w6dQ1FEn2O9C5DOZtGGm1cXIxfkVSV/SE6CLulaP/wF0gUqCvIxWoUniBTSN YJUIP1nb8DOlVlDOAGKwveRCA6ep+/kEv+YA7Sj7nD0efbRIeRNmirL74CnPTsS6PX5G D8cw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784365623; x=1784970423; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=q1Uu8xz4B0eylEThcASB7MFzTdtby4/11pvvYHik8S8=; b=dmSSOz/arIJXfwuHgKGdFu2dbAAYFwhOP4i9546nGOngZdOrZ1t+1KGO94qNGTyMyq R+mu3dhZGny+aYydmRg69AMh6T7PpZbY/9uyg2t+krvCoN/smRy55HSujO2Mp1I5hpnm z9BaOd8b6I6tI4UbtrveZZho7Tww/gXBqGsHJMxOQckkCKYlRbo1BhzSUwk4i3EaSMvi cmfA0UXtJUv15VaL1WorCiIXJVIhVChADI/onHOvvTLmlBP0o9qpkedgKPpnEwr0liI7 /Dv+dBRo64hZT2P6j+5/Qa6mEkzSEGiIYXOxHBw5O0z8//F9BO9SZ/AsGNqpfLvFetJW EswQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784365623; x=1784970423; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=q1Uu8xz4B0eylEThcASB7MFzTdtby4/11pvvYHik8S8=; b=ZE1J/l6Nrsmb7zku/MzNdYQKDONDGGI4vBwJRVCrzgPK1QRntBFx6dUsheTpDMp91Q FB0cCaTVaDFz++VDrGaa2w/Ts6i0WjAiq2GFIngxwL8LQI3JIgtXqlHSb77QkaxPE/0s /Xxk7mhcMGJyjX1tgPxMmSIOSSxym5KIWEFba+CF0wi8afDaTTci5S5g5ibGkfNBmoFO 2Pfo4roSGMqmtvp2grcFlwRsRPXfUmhangNNa785YZQzyRifvWhcD1fkTi9Vwxw93A6P vyqu0wkDmEceSg8ILkgPOSZe83D67qjRu3aNdMjn4XhvkaG0bvbqSbDgHTiYt0JVArG7 OnJg==
X-Forwarded-Encrypted: i=1; AHgh+RpgncmSxC2Yql9Maqxg+DZ43ytXzRFTmCVbh5qYre9dS56YjIc4km2Q8Wlju++LKF/28v+ZJQ==@ietf.org
X-Gm-Message-State: AOJu0YydG8hGIjNNrDrdU4urr0d6U9xXSJVln0Fh22uWTPLRtlwzXc4T gOprjHiJPCAC70iK484ag4TNyaMtbpguK1pFp0j2r0xVDke6zCQLeifCXE3rsUpnyDERMUQrdMd S3kPoRPbZJhL0uFU0KLWMCSZOilKDMVA=
X-Gm-Gg: AfdE7cnmp/k5NIYEta2C3TkBCV6A4j++loDS903JdROi1DJlRVrUSBXmKlq60kUA+wG yhyabAOCi6z1lG4ZboFivzfSQvuHoAv+fTVj4Wu6O2Yi8qRgSQSbwaDqsRDub2D6sg5bUngQhrK IcUjEgERyAoNbCJ6CrOH9nAS1YWMVrwTINK7JPoZF/KulnHfXMhZHMJu6japNjGrYKbV5uIum6J ygEgiHynWFkCuoPFItPZ/un1Yl5RFFIfitlcY0OOlyMaWvDkkJyB9v7t2dZ3UZyYLAxhKyIyFiK 3E3DiA4UUnCDsX+w
X-Received: by 2002:a17:907:948c:b0:c12:45fc:c25 with SMTP id a640c23a62f3a-c16b47533c5mr295639466b.17.1784365622635; Sat, 18 Jul 2026 02:07:02 -0700 (PDT)
MIME-Version: 1.0
References: <CAPSJW7ALiwVfP16eTSd9pvPz4v_2xo0wxDaf37MU6mquZX2fLw@mail.gmail.com> <CA+syWAPSpdf7BK_-ux-h5rye+we_4jp1WtdhJ-9D_od8_cQCHw@mail.gmail.com>
In-Reply-To: <CA+syWAPSpdf7BK_-ux-h5rye+we_4jp1WtdhJ-9D_od8_cQCHw@mail.gmail.com>
From: Benfeng Chen <benfeng@gmail.com>
Date: Sat, 18 Jul 2026 02:06:51 -0700
X-Gm-Features: AUfX_mzwaCoj1I_YZmS1e8LnYQYEAx6rmhrVybAT8ueD97F8rijJOB0Ch98suRE
Message-ID: <CAPSJW7AhAKmb5k8khPqZ_gQmYWinmFDcO0SEOo__C_4Sgf3pwQ@mail.gmail.com>
To: guest271314 <guest271314@gmail.com>
Message-ID-Hash: 7UJ6U4RO4PHLSVNFDDZYAGO5OSDU6DUO
X-Message-ID-Hash: 7UJ6U4RO4PHLSVNFDDZYAGO5OSDU6DUO
X-MailFrom: benfeng@gmail.com
X-Mailman-Rule-Hits: member-moderation
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address
Content-Transfer-Encoding: base64
Content-Type: text/plain; charset="UTF-8"
X-Content-Filtered-By: Mailman/MimeDel 3.3.9rc6
CC: hackathon@ietf.org, "ztcpp@ietf.org" <ztcpp@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [ZTCPP] Re: [hackathon] IETF 126 Hackathon project: OpenNHP — The Internet Is Becoming a Dark Forest
List-Id: Zero Trust Control and Policy Protocol <ztcpp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ztcpp/5wZLPo42bHmNg6Ra3clCsmY93tM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ztcpp>
List-Help: <mailto:ztcpp-request@ietf.org?subject=help>
List-Owner: <mailto:ztcpp-owner@ietf.org>
List-Post: <mailto:ztcpp@ietf.org>
List-Subscribe: <mailto:ztcpp-join@ietf.org>
List-Unsubscribe: <mailto:ztcpp-leave@ietf.org>
OpenNHP is at *Table 14*. You are welcome to stop by. On Mon, Jul 6, 2026 at 2:35 PM guest271314 <guest271314@gmail.com> wrote: > > *Please try to break it.* > > I like it. All too often folks talk about "safety" and "security" within > the scope of testing their own gear, in-house. That simply doesn't verify > anything. > > I'll check out the details and pass around the idea > > von Braun believed in testing. I cannot > emphasize that term enough – test, test, > test. Test to the point it breaks. > - Ed Buckbee, NASA Public Affairs Officer, Chasing the Moon > > On Mon, Jul 6, 2026 at 5:33 AM Benfeng Chen <benfeng@gmail.com> wrote: > >> Hi all, >> >> The recent concerns surrounding autonomous AI-driven cyberattacks, >> including discussions around systems such as *Claude Mythos*, may be >> signaling a fundamental shift in cybersecurity: autonomous AI agents are >> turning the Internet into a “*Dark Forest,*” where anything visible can >> be discovered, probed, and exploited at machine speed. >> >> As described in the “Dark Forest” theory from Liu Cixin’s *The >> Three-Body Problem*, the only reliable survival strategy in such an >> environment may be *invisibility*. Rather than continuing the >> decades-long cycle of exposing services and then attempting to defend them, >> we are exploring a different question: >> >> *What if network infrastructure were invisible by default?* >> >> To explore this idea, I’ve added a project to the IETF 126 Hackathon wiki: >> >> *OpenNHP — Network-infrastructure Hiding Protocol (NHP)* >> >> >> https://wiki.ietf.org/en/meeting/126/hackathon#opennhp-network-infrastructure-hiding-protocol-nhp >> >> >> OpenNHP is an open-source implementation of the emerging >> Network-infrastructure Hiding Protocol (NHP), an >> authenticate-before-connect Zero Trust protocol designed to make protected >> infrastructure inaccessible—and ideally undiscoverable—to unauthorized >> entities. >> >> Unlike traditional security architectures that attempt to protect visible >> services, NHP seeks to prevent reconnaissance, scanning, DDoS, and >> pre-authentication exploitation by hiding network resources until >> cryptographic authentication succeeds. >> >> For the IETF 126 Hackathon, we’re inviting the community to do something >> simple: >> >> *Please try to break it.* >> >> We welcome participation from security researchers, protocol designers, >> cryptographers, network engineers, DNS/TLS/PKI experts, AI security >> researchers, and anyone who enjoys attacking assumptions. >> >> Potential challenge areas include: >> >> - Discovering protected services without authentication >> - Enumerating hidden ports, IP addresses, or domain names >> - Performing reconnaissance against NHP-protected infrastructure >> - Bypassing authentication or authorization mechanisms >> - Exploiting pre-authentication attack surfaces >> - Testing resistance to DDoS and scanning attacks >> - Finding cryptographic weaknesses or protocol design flaws >> - Evaluating AI-assisted attack techniques >> - Testing interoperability and performance characteristics >> - Demonstrating any attack path that violates the >> “authenticate-before-connect” security model >> >> The challenge outcome is straightforward: >> >> - If you can discover or access protected resources without >> successful authentication, we want to understand the weakness and fix it. >> - If you cannot, we collectively gain additional confidence in the >> security properties of the protocol. >> >> We believe that public adversarial testing, peer review, and running code >> remain the best tools available for building trustworthy Internet security >> protocols. >> >> Resources: >> >> - Project website: OpenNHP Website <https://opennhp.org/> >> - Source code: OpenNHP GitHub Repository >> <https://github.com/OpenNHP/opennhp> >> - Live demo: OpenNHP Demo Environment <https://opennhp.org/demo/> >> - Internet-Draft: draft-opennhp-ztcpp-nhp >> <https://datatracker.ietf.org/doc/html/draft-opennhp-ztcpp-nhp> >> >> I’ll be participating in person at the Hackathon and would welcome >> collaborators, critics, and especially skeptics. >> >> Thanks, >> >> Benfeng Chen >> OpenNHP Project >> _______________________________________________ >> hackathon mailing list -- hackathon@ietf.org >> To unsubscribe send an email to hackathon-leave@ietf.org >> Unsubscribe: mailto:hackathon-request@ietf.org?subject=unsubscribe > >
- [ZTCPP] [hackathon] IETF 126 Hackathon project: O… Benfeng Chen
- [ZTCPP] Re: [hackathon] IETF 126 Hackathon projec… mohamed diallo
- [ZTCPP] Re: [hackathon] IETF 126 Hackathon projec… guest271314
- [ZTCPP] Re: [hackathon] IETF 126 Hackathon projec… Benfeng Chen