The US has declared Autistici/Inventati, an Italian anarchist hacker (in the classic sense of the term) collective, a terrorist organization.
-
Using an out of band method to share host to IP addresses would work right now.
If the regime learns no one will listen to them, that should discourage them from trying in the future. If not, the part of the world that wants freedom needs to cut the us government and corporations out of their lives.
That's possible though would be an difficult transition period, but if they keep abusing their power they need to lose it
@alienghic @alice @cwebber Fight now, or they come for us anyway later.
-
@agowa338@chaos.social DNS infrastructure is relatively decentralized/redundant (just look at the diversity of root zone operators!), but control is not at all decentralized (though, it is hierarchical, as you say)
most significantly, the root zone is controlled by ICANN alone, and each TLD is controlled by a registry alone. to buy a domain, you have to go through that registry indirectly. that registry can take your domain away. and so can your registrar.
the decentralized and redundant infrastructure solves a real problem: there is no single technical point of failure the can take out the entire system. in decades of operation, DNS as a whole has never suffered a complete outage. the root zone has had 100% uptime, despite several large-scale attacks over its existence.
but the very centralized control of the same system presents a real problem: you're at the whims of Two Organizations (registry and registrar) to not take your domains away. you can never own a domain.
the hierarchical nature allows you to pick which organizations to be at the whims of, and this is good, because there's no single organizational point of failure for the entire system (besides ICANN, who does not have the power to take away individual second-level domains). if one registry or registrar is hostile, you can go to another one.
but you can never own a domain. you can never not be at the whims of one of the divine organizations.
in a decentralized system (in the sense we mean when we say "DNS is centralized"), you're not forced to trust a central entity. in DNS, you have a couple choices, but at the end of the day, you have to pick one to trust.
---
it sounds like what i just described may overlap with what you call an "authoritarian"/"libertarian" system? but you didn't explain these terms very well in the context of a distributed computer system. i'm not sure what you meant by them exactly. so i just avoided using them at all.Yea, decentralised and authoritarian.
decentralised and libertarian would be e.g. Tor with .onion addresses. Which has the issue of not being able to choose the domain name (in it's entirety at least).
centralised and libertarian would be .i2p, you (in theory) can choose who the central authority that provides the naming is yourself. Which has the issue of them potentially disagreeing (like early days when you c'n'p-ed host files)
-
Using an out of band method to share host to IP addresses would work right now.
If the regime learns no one will listen to them, that should discourage them from trying in the future. If not, the part of the world that wants freedom needs to cut the us government and corporations out of their lives.
That's possible though would be an difficult transition period, but if they keep abusing their power they need to lose it
@alienghic @alice @cwebber Well, payment could be things like Visa gift cards of any variety (in the US, non-reloadable) that does not need to be activated with ID.
-
Yea, decentralised and authoritarian.
decentralised and libertarian would be e.g. Tor with .onion addresses. Which has the issue of not being able to choose the domain name (in it's entirety at least).
centralised and libertarian would be .i2p, you (in theory) can choose who the central authority that provides the naming is yourself. Which has the issue of them potentially disagreeing (like early days when you c'n'p-ed host files)
And centralised and authoritarian would be when IANA had a full table and wouldn't have a concept of delegating.
-
@agowa338@chaos.social DNS infrastructure is relatively decentralized/redundant (just look at the diversity of root zone operators!), but control is not at all decentralized (though, it is hierarchical, as you say)
most significantly, the root zone is controlled by ICANN alone, and each TLD is controlled by a registry alone. to buy a domain, you have to go through that registry indirectly. that registry can take your domain away. and so can your registrar.
the decentralized and redundant infrastructure solves a real problem: there is no single technical point of failure the can take out the entire system. in decades of operation, DNS as a whole has never suffered a complete outage. the root zone has had 100% uptime, despite several large-scale attacks over its existence.
but the very centralized control of the same system presents a real problem: you're at the whims of Two Organizations (registry and registrar) to not take your domains away. you can never own a domain.
the hierarchical nature allows you to pick which organizations to be at the whims of, and this is good, because there's no single organizational point of failure for the entire system (besides ICANN, who does not have the power to take away individual second-level domains). if one registry or registrar is hostile, you can go to another one.
but you can never own a domain. you can never not be at the whims of one of the divine organizations.
in a decentralized system (in the sense we mean when we say "DNS is centralized"), you're not forced to trust a central entity. in DNS, you have a couple choices, but at the end of the day, you have to pick one to trust.
---
it sounds like what i just described may overlap with what you call an "authoritarian"/"libertarian" system? but you didn't explain these terms very well in the context of a distributed computer system. i'm not sure what you meant by them exactly. so i just avoided using them at all.@agowa338@chaos.social in particular for Autistici/Inventati, the relevant domains seem to all have been under
.org. this is operated by the Public Interest Registry which is based in Virginia, United States. that's the single point of failure that can take away those domains. and because they're based in the US, of course they will revoke domains relating to anyone its government declares as terrorists. like, sure, not all of DNS is centralized with PIR, but all of.orgis controlled by them alone.
one can play a game of whack-a-mole and find a new registry. check out sci-hub, which has done exactly this.
but it doesn't solve the problem. at some point, you can run out of registries or jurisdictions. you can be Kicked Off DNS entirely. centralized between N entities that have to agree to remove you, is still centralized. it's not that much different from 1 entity consisting of N members voting to control what the single entity does. (i think you already know this and agree with me? certainly this has to be what you meant by authoritarian) -
Autistici/Inventati's domains have now been revoked. I updated the link in the above post with a wayback machine copy.
Every now and then someone tells me, "We have a decentralized naming system, it's called DNS!" and I say, no we don't, DNS is extremely centralized? And if that wasn't clear to you before, hopefully it's clear to you today.
@cwebber DNS is "decentralized" because if one server removes a domain name, you can just use another one that still has it. However this is not at all how DNSs are operated in reality & it is completely centralized. There are a few alternative DNS networks, but those are also centralized!
What are people getting confused about here, the acronym? The "D" stands for "domain", not "decentralized".
-
Yea, decentralised and authoritarian.
decentralised and libertarian would be e.g. Tor with .onion addresses. Which has the issue of not being able to choose the domain name (in it's entirety at least).
centralised and libertarian would be .i2p, you (in theory) can choose who the central authority that provides the naming is yourself. Which has the issue of them potentially disagreeing (like early days when you c'n'p-ed host files)
centralised and libertarian would be .i2p, you (in theory) can choose who the central authority that provides the naming is yourself.
isn't i2p equivalent to Tor here? i2p addresses are just a public key or something?
yes, you can choose a central naming authority to give short memorable names. congratulations, you just reinvented DNS. you can also choose not to use the ICANN root zone. see: OpenNIC. that's still a centralized single point of institutional failure. so isn't DNS also "libertarian" by this logic?
(to my understanding, i2p short names are supposed to be more like personal bookmarks than a public registry. but you made it seem like it's DNS? and it's functionality similar for sure)
---
Tor and I2P are decentralized in the ways that matter: there's no single organization (or N organizations) that can kick you off the network as a whole. (well, unless the entire network conspires against you; but if literally anyone wants to talk to you, then you can be on the network). in exchange, they don't have anything like the DNS. there's no central naming authority. the central naming authority is the hard thing to solve. -
@cwebber @cararemixed this is one of the reasons I never want to enable HSTS on my website
the plan for it is to be a site about myself, meltcats (my species), all my tech projects (like Kittyscript), my political views and an Akkoma instance.
but all that the website is right now is two glorified hello world pages I wrote myself and a few redirects to them.
yay for ADHD executive dysfunction. I'm paying €23 every month for a server I completely underutilize because I can't make myself follow plans.
see http://lunatronex.net and http://luna.dragofelis.net@LunaDragofelis @cararemixed @cwebber
The HSTS mechanism should be reserved for sites like banking or others where exchange of sensitive information needs to be maximally secure. Question is, why even use TLS for a personal and public website made as a hobby and for fun in the first place?(Alright, I'd understand cases like SEO scoring and others, but that's not applicable here)
-
@LunaDragofelis @cararemixed @cwebber
The HSTS mechanism should be reserved for sites like banking or others where exchange of sensitive information needs to be maximally secure. Question is, why even use TLS for a personal and public website made as a hobby and for fun in the first place?(Alright, I'd understand cases like SEO scoring and others, but that's not applicable here)
@aronowski @cararemixed @cwebber ActivityPub (what fedi instances use between each other) requires TLS as far as I know -
@aronowski @cararemixed @cwebber ActivityPub (what fedi instances use between each other) requires TLS as far as I know
@LunaDragofelis @cararemixed @cwebber
Yeah, places where authentication is needed even to log in should have it. Though a read-only cool website you're making does not... or does it?
-
@aronowski @cararemixed @cwebber ActivityPub (what fedi instances use between each other) requires TLS as far as I know
@LunaDragofelis @aronowski @cwebber TLS has the benefit of cutting out involuntary meddling of middle boxes (remember ad injection?). There's also safety in larger numbers regarding traffic analysis. Lots of TLS traffic doesn't look suspicious because it's perfectly normal.
-
@cwebber “Antifascism and anticapitalism are not terrorism. Protesting is not terrorism. And everyone has the right to speak out and to struggle for humanity.
Autistic/Invented Collective — “Socializing knowledge without establishing power”
Stay human.”Yes, it’s worth reading the history of A/I at https://sabotmedia.noblogs.org/the-server-called-paranoia-defend-autistici-inventati-before-september-25/
-
-
-
"Take down the roots" - hahaha, all of them? how? They are distributed! Not only are there 13 root server names, but their IPs are anycast and served by so much more machines at so many locations that "taking down the roots" is something you would certainly not be able to accomplish.
-
J jeppe@uddannelse.social shared this topic