Naming service for the Invisible Internet Protocol

Hezekiah <[email protected]> Mon, 4 Aug 2003 04:12:28 -0400
Newsgroups gmane.comp.security.invisiblenet.iip.devel
Message-ID <[email protected]>
Hi, all! :)
	Well, I agree that the idea is cool, jrand0m. :) However, I would like to 
mention one thing about CA's. Have a central CA would be a "bad idea". If you 
want to know why, think about the IIP Trent service. I'm not sure you were 
around when we had all the problems, but flooding Trent with nickreg requests 
can be rather painful. That's why mids implemented a hashcash/realcash 
payment method for registering a nick. The reason this was required was 
interesting in a theoretical way. A nick entry in the Trent database takes up 
space, and mids had to pay for the space he used in that database. Thus, a 
virtual (i.e. via internet) DOS attack on trent would cost mids a real cost 
in the form on higher monthly payments for the hosting of the Trent database. 
We wouldn't want this kind of problem with an i2p CA.
	Also, think about the attacks on the root DNS servers on the internet. When 
these occurred it caused noticeable results accross the internet. And lots of 
geeks/nerds/hackers said one thing: Distributed DNS!
	So I think if we can manage it, some type of distributed CA would be ideal. 
Let's face it. When we make this network, people _will_ try DOS's and DDOS's 
just to see how resistant it is. So a distributed CA that can take that kind 
of attach would be a good idea.

	That's just my $.25. (I'm feeling special today, so it's up $.23.) ;-)

	-- Hezekiah
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD4DBQA/LhWAeHiZTMH32ioRAnAAAJQPLvdMlxBgQDsSJZ5dkFVpvZWUAJ9jB2mD
dtKxEGxAsyecZWD9xDqZSw==
=Yv2n
-----END PGP SIGNATURE-----