Post #2175086
2023-03-26 05:22 UTC
Replies (1)
-
@hallam@infosec.exchange 2023-03-28 17:54
@markd@hachyderm.io OK, now I see where you are coming from. Yes, I have that modality as well. Slightly different implementation but close. My plan is to support BOTH of alice.m3-- RWSHZ.JNY5E.YGYYL.6DUF5.MB2GK.m3-- As DNS domains derived from a Mesh account registration. The difference being: 1) alice.m3-- is much easier to type and to remember. It is 'forever' for as long as the callsign registration binding lasts which is normally forever but can change in certain circumstances. 2) ...MB2GK.m3-- is a pain to type but can be easily generated by an automated tool. It is forever for as long as the destination specified in the binding assertion points to the actual content. Neither is fully forever but can be used as the starting point for forever. So let us think about 100 years hence. Alice wrote a great deal of stuff and put it on her personal Web server and the DNS still points to that IP but that Web server hasn't been active for 30 years now and Alice is dead so the binding can't be updated. So the direct resolution isn't going to work in that particular case but there is enough there for someone with a subscription to some sort of persistence repository to reconstruct a link to some stored data which can then be authenticated using a signature. Incidentally, the reason for reversing the UDF to make the domain is same as for reverse DNS IP lookup, the UDF is Bigendian and DNS is little.