[ZTCPP] Re: [hackathon] IETF 126 Hackathon project: OpenNHP — The Internet Is Becoming a Dark Forest

guest271314 <guest271314@gmail.com> Mon, 06 July 2026 12:35 UTC

Return-Path: <guest271314@gmail.com>
X-Original-To: ztcpp@mail2.ietf.org
Delivered-To: ztcpp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 685F71100C95F for <ztcpp@mail2.ietf.org>; Mon, 6 Jul 2026 05:35:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783341358; bh=ccdjRWjxgxSv1pGlQfktvc/19fspM+f0HSkl82hRzAE=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=hOpgrBsGVnZ/ZU4GVZSWqh8nTb50BMC+FXDifHSCKACJc8YkvpUC9v0H+7SzS6/jJ LN7tlwX3dN8TpPCDWh0P21i25iTKo1oMtpggLOXrv/umFiVNA81mKYz8ArCzGTy+5t m7RCTnTzI/Z6DjRSQWPFwRzxP/gdjFSmLyI0Wa10=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.838
X-Spam-Level:
X-Spam-Status: No, score=-1.838 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id J9aHFYjyYHt6 for <ztcpp@mail2.ietf.org>; Mon, 6 Jul 2026 05:35:57 -0700 (PDT)
Received: from mail-pj1-x1029.google.com (mail-pj1-x1029.google.com [IPv6:2607:f8b0:4864:20::1029]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id B41941100C958 for <ztcpp@ietf.org>; Mon, 6 Jul 2026 05:35:57 -0700 (PDT)
Received: by mail-pj1-x1029.google.com with SMTP id 98e67ed59e1d1-384930ca5e2so1687736a91.3 for <ztcpp@ietf.org>; Mon, 06 Jul 2026 05:35:57 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1783341357; cv=none; d=google.com; s=arc-20260327; b=BdyxuRaSw2ST5bLNbk1J/M/LfTvAPbHaffgwz+AgQE9MrUp/g1NT+dmrvE3hmHDZI7 ny9X4D9QvciTfeMqyWBK2EJ6/fU1sbT8Fn5C24M49aqD+EZ1IBCwUOb4WvTdBdANjVD0 JJIz77M1fZ6kDrzE0lmdnyOj8Fk1gf3XctRbnmpBUf3FjxOuubCuOUkZYgx7NiOzqlW5 boKT/+ZFPzCpBVb/XC3KRmTXqiVxX5nQCfvrfhwJFPOYyZn9vwQmWjD66JcsCk2DRtWm C0lNFw0KQcb4J2+OnKmpbDT5wpP3sw+yzfj2e9R7OXZ7GKOf9G52GJOvJ8ETppDN4znR WeFQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=+4eD3bk+EaGIkk4718IsUoIe0i+Ix6pdlU2aaPy2WgQ=; fh=ZUyTfaaj9+Lp0u+3TDYXXCXKPsfcVZkVZp17grUkJMs=; b=QYs7Y1kmZmzVDw1tqnuoCr1eGLL/vJ03PX6Y/fCnMu5D5cIp/gYj2ALGH15cw89Nbj 3PTc+raCRw1CjAy2MdAKNRuOXJUADJUyjDS6pbVhFUh+V5g50iqw0uCO+RQCQYMA95dO KV+KjM4G/yzMgL3TQsLNT7hQezNJ1EZZ860BA9B91onqGJnsS+eG8QnYI4PSknAqUO/f OKAWGANjkrg9GmhEWJSosNZU4VFD4eWM7PNYhc3Fqsi4WTWmHHcFbnXRNXWB7S9G5wLQ AkUZDo8dG+RL47YswWPqjRo9N+SigcTsWMgsP0MGfdMGCCI2+JW+PhhRjS5DIJBHQo5L oZCg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783341357; x=1783946157; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=+4eD3bk+EaGIkk4718IsUoIe0i+Ix6pdlU2aaPy2WgQ=; b=b1WcSpsgStgRKIYJ6j34dpoLgDKh0INmZs9qhVh6gg0oLI6cOFxlITD7IH4ZrxbNP6 0zWEZECJ2vlsEzBweuBDZS94/27UaQShUQDWhToCDVZZxFSWFuArSSv4E9/OkQQuGFqZ Pz4KTUI3Lj93Ekd/HZW+Y/dEznauky41gFq+sYqlk0eC9xKi+yIJVHS947FBQ1vDpclP VEUxvX/JaxC9+I84nxuYN8wQ7W8k0sCamQgeqs7mDjMZK6sEiGaO1Gmhq/nMmC/d+S0j S8vg1+ncWYrpMB+iJKrFLvVAGKQoDMpoG+xijmwo3cqJJ+B8Yd6M9ESxaeBlC4JVmVZM Qb/Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783341357; x=1783946157; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=+4eD3bk+EaGIkk4718IsUoIe0i+Ix6pdlU2aaPy2WgQ=; b=Lsu5AQqHRlb1SfpuWMHvj3Dq/yFW027qs+ul/WnW2wXH/ETNsMzOcV1hszDyWl5LQc BgiPCdJjfLbDDMquG/nIN/uED7r8SuT51vCSMNbsox33JJrKUlXKQOAeqimdrqP1p1f9 dNYKaijCpQI313yYur0T5Vt3rPCPWkNETT5QAy7UPKB26JnQ9JiTtLbGMrA6kBLzOzDW pNXA9aR3cOmBTB5N7ZfxZTL0HXOnKABSupk+GMenhlN8DcJRKHEVOLl9yyxbzCrG1sdK y+D4NKy1VWHapA5xdGBVdIgQldqyoBjL/odUz5MY2cul0PtagxDKx6gpiJqt2ebMEHHO V8+Q==
X-Forwarded-Encrypted: i=1; AHgh+RoeE2t9v3OL7mAblJkdmhM85dMjOZ4uVgm8Pk5ksaPQ9YUxyRmU4Rwe4ket5Civ9HL3ehkDVw==@ietf.org
X-Gm-Message-State: AOJu0YxkvBIVDMR3Q4jTM7owfwswcrDzaRX/M2hJzejKGJp9/Kb8kPVn OWIZMsgOkBvGGD7OFZoxkZE6KLlQHdyJwWmQ8AzmAbcinFOHgR+db7AUglXv/CoG3diHShNZ6wc 4gv5VZJL8MdRURiSDJEN5x2LxarUm110=
X-Gm-Gg: AfdE7clI2KPbvPudqBMIxTVBwwHGxBSjCwGfpH7X8779QloOL+m+ggA7l+kJ204uycV 0xJr+duJZa7xZZf9AzQE3jFgr1jpAIfjWjv3ZyIEf0wjE3MCSDWH+k+2T8VvS9jqaf9MolsdnKG OUQCSnkqyX5TzvkIGiyNLx5pPeZHaNE9/AgWo3EzeJVsUTymbqQPjLPp0TWdYLaouQQg4eafgp5 tpRgd3jIhw3tgHodbhTkAms88CbAkwW28lERB7lwY67K5u7oy7h8u3xkBocdv1Ys1nw2e/J2N4=
X-Received: by 2002:a17:90b:2752:b0:36d:66d4:270e with SMTP id 98e67ed59e1d1-3875528befcmr205299a91.5.1783341356628; Mon, 06 Jul 2026 05:35:56 -0700 (PDT)
MIME-Version: 1.0
References: <CAPSJW7ALiwVfP16eTSd9pvPz4v_2xo0wxDaf37MU6mquZX2fLw@mail.gmail.com>
In-Reply-To: <CAPSJW7ALiwVfP16eTSd9pvPz4v_2xo0wxDaf37MU6mquZX2fLw@mail.gmail.com>
From: guest271314 <guest271314@gmail.com>
Date: Mon, 06 Jul 2026 12:43:20 +0000
X-Gm-Features: AVVi8CfBLk6GY1DldaeMN_CRGeHw1nvwf-92yByzbb73OXoq4tSgoOR3flvRHOY
Message-ID: <CA+syWAPSpdf7BK_-ux-h5rye+we_4jp1WtdhJ-9D_od8_cQCHw@mail.gmail.com>
To: Benfeng Chen <benfeng@gmail.com>
Message-ID-Hash: 4VAA6B5CT5GIO7XOSHL4IPIZHF7KUU66
X-Message-ID-Hash: 4VAA6B5CT5GIO7XOSHL4IPIZHF7KUU66
X-MailFrom: guest271314@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
Content-Transfer-Encoding: base64
Content-Type: text/plain; charset="UTF-8"
X-Content-Filtered-By: Mailman/MimeDel 3.3.9rc6
CC: hackathon@ietf.org, "ztcpp@ietf.org" <ztcpp@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [ZTCPP] Re: [hackathon] IETF 126 Hackathon project: OpenNHP — The Internet Is Becoming a Dark Forest
List-Id: Zero Trust Control and Policy Protocol <ztcpp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ztcpp/lPmm3_fpLWUot1hLTlkZe9FcAOg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ztcpp>
List-Help: <mailto:ztcpp-request@ietf.org?subject=help>
List-Owner: <mailto:ztcpp-owner@ietf.org>
List-Post: <mailto:ztcpp@ietf.org>
List-Subscribe: <mailto:ztcpp-join@ietf.org>
List-Unsubscribe: <mailto:ztcpp-leave@ietf.org>

> *Please try to break it.*

I like it. All too often folks talk about "safety" and "security" within
the scope of testing their own gear, in-house. That simply doesn't verify
anything.

I'll check out the details and pass around the idea

von Braun believed in testing. I cannot
emphasize that term enough – test, test,
test. Test to the point it breaks.
- Ed Buckbee, NASA Public Affairs Officer, Chasing the Moon

On Mon, Jul 6, 2026 at 5:33 AM Benfeng Chen <benfeng@gmail.com> wrote:

> Hi all,
>
> The recent concerns surrounding autonomous AI-driven cyberattacks,
> including discussions around systems such as *Claude Mythos*, may be
> signaling a fundamental shift in cybersecurity: autonomous AI agents are
> turning the Internet into a “*Dark Forest,*” where anything visible can
> be discovered, probed, and exploited at machine speed.
>
> As described in the “Dark Forest” theory from Liu Cixin’s *The Three-Body
> Problem*, the only reliable survival strategy in such an environment may
> be *invisibility*. Rather than continuing the decades-long cycle of
> exposing services and then attempting to defend them, we are exploring a
> different question:
>
> *What if network infrastructure were invisible by default?*
>
> To explore this idea, I’ve added a project to the IETF 126 Hackathon wiki:
>
> *OpenNHP — Network-infrastructure Hiding Protocol (NHP)*
>
>
> https://wiki.ietf.org/en/meeting/126/hackathon#opennhp-network-infrastructure-hiding-protocol-nhp
>
>
> OpenNHP is an open-source implementation of the emerging
> Network-infrastructure Hiding Protocol (NHP), an
> authenticate-before-connect Zero Trust protocol designed to make protected
> infrastructure inaccessible—and ideally undiscoverable—to unauthorized
> entities.
>
> Unlike traditional security architectures that attempt to protect visible
> services, NHP seeks to prevent reconnaissance, scanning, DDoS, and
> pre-authentication exploitation by hiding network resources until
> cryptographic authentication succeeds.
>
> For the IETF 126 Hackathon, we’re inviting the community to do something
> simple:
>
> *Please try to break it.*
>
> We welcome participation from security researchers, protocol designers,
> cryptographers, network engineers, DNS/TLS/PKI experts, AI security
> researchers, and anyone who enjoys attacking assumptions.
>
> Potential challenge areas include:
>
>    - Discovering protected services without authentication
>    - Enumerating hidden ports, IP addresses, or domain names
>    - Performing reconnaissance against NHP-protected infrastructure
>    - Bypassing authentication or authorization mechanisms
>    - Exploiting pre-authentication attack surfaces
>    - Testing resistance to DDoS and scanning attacks
>    - Finding cryptographic weaknesses or protocol design flaws
>    - Evaluating AI-assisted attack techniques
>    - Testing interoperability and performance characteristics
>    - Demonstrating any attack path that violates the
>    “authenticate-before-connect” security model
>
> The challenge outcome is straightforward:
>
>    - If you can discover or access protected resources without successful
>    authentication, we want to understand the weakness and fix it.
>    - If you cannot, we collectively gain additional confidence in the
>    security properties of the protocol.
>
> We believe that public adversarial testing, peer review, and running code
> remain the best tools available for building trustworthy Internet security
> protocols.
>
> Resources:
>
>    - Project website: OpenNHP Website <https://opennhp.org/>
>    - Source code: OpenNHP GitHub Repository
>    <https://github.com/OpenNHP/opennhp>⁠
>    - Live demo: OpenNHP Demo Environment <https://opennhp.org/demo/>⁠
>    - Internet-Draft: draft-opennhp-ztcpp-nhp
>    <https://datatracker.ietf.org/doc/html/draft-opennhp-ztcpp-nhp>⁠
>
> I’ll be participating in person at the Hackathon and would welcome
> collaborators, critics, and especially skeptics.
>
> Thanks,
>
> Benfeng Chen
> OpenNHP Project
> _______________________________________________
> hackathon mailing list -- hackathon@ietf.org
> To unsubscribe send an email to hackathon-leave@ietf.org
> Unsubscribe: mailto:hackathon-request@ietf.org?subject=unsubscribe