Naming service for the Invisible Internet Protocol
Hezekiah <[email protected]> Mon, 4 Aug 2003 04:12:28 -0400
| Newsgroups | gmane.comp.security.invisiblenet.iip.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, all! :) Well, I agree that the idea is cool, jrand0m. :) However, I would like to mention one thing about CA's. Have a central CA would be a "bad idea". If you want to know why, think about the IIP Trent service. I'm not sure you were around when we had all the problems, but flooding Trent with nickreg requests can be rather painful. That's why mids implemented a hashcash/realcash payment method for registering a nick. The reason this was required was interesting in a theoretical way. A nick entry in the Trent database takes up space, and mids had to pay for the space he used in that database. Thus, a virtual (i.e. via internet) DOS attack on trent would cost mids a real cost in the form on higher monthly payments for the hosting of the Trent database. We wouldn't want this kind of problem with an i2p CA. Also, think about the attacks on the root DNS servers on the internet. When these occurred it caused noticeable results accross the internet. And lots of geeks/nerds/hackers said one thing: Distributed DNS! So I think if we can manage it, some type of distributed CA would be ideal. Let's face it. When we make this network, people _will_ try DOS's and DDOS's just to see how resistant it is. So a distributed CA that can take that kind of attach would be a good idea. That's just my $.25. (I'm feeling special today, so it's up $.23.) ;-) -- Hezekiah
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) iD4DBQA/LhWAeHiZTMH32ioRAnAAAJQPLvdMlxBgQDsSJZ5dkFVpvZWUAJ9jB2mD dtKxEGxAsyecZWD9xDqZSw== =Yv2n -----END PGP SIGNATURE-----