Decentralized Internet and Privacy

Namecoin and Tor as a Public Key Infrastructure

UD2.218A
Jeremy Rand
<p>Public certificate authorities in TLS are a security liability from both a censorship and MITM perspective. Conceptually, DNSSEC's idea of tying PKI to domain names should be a better replacement -- except that in the DNS, relying on the names means trusting the registrars, registries, and ICANN. But what if we had <em>self-authenticating</em> domain names? Could we build a PKI on top of those? Could such a PKI work with unmodified mainstream web browsers like Chromium, Firefox, and Tor Browser?</p> <p>We've done exactly that. Namecoin (a blockchain naming system providing the .bit TLD) and Tor (an anonymity network providing the .onion TLD) provide the self-authenticating domain names. This talk covers how we made the PKI. Topics to be discussed include:</p> <ul> <li>Why public certificate authorities are dangerous.</li> <li>Prior work on using DNS as a PKI (and why it's less useful for us than you might think).</li> <li>How we creatively used API's to get mainstream TLS implementations to use Namecoin to validate TLS certificates.</li> <li>Why you might want to use TLS with Tor onion services (and why onion service encryption might not be as secure as you think).</li> <li>How we generalized Namecoin TLS to work with Tor onion services.</li> <li>How we made TLS implementations that don't support Ed25519 work anyway with Tor onion services (which rely on Ed25519).</li> <li>How we can use TLS with Namecoin without putting a TLSA record on the blockchain (for better scalability).</li> <li>How Namecoin's smart contract functionality (allowing multisig and timelocks to control updating a name) interacts with PKI use cases.</li> <li>How we generalized Namecoin and Tor PKI to work with non-TLS protocols.</li> <li>How revocations can be handled securely.</li> <li>How we ensured anonymity (including Tor stream isolation) despite TLS implementations not providing API's for this.</li> </ul>

Additional information

Live Stream https://live.fosdem.org/watch/ud2218a
Type devroom
Language English

More sessions

2/1/26
Decentralized Internet and Privacy
Kevin Schulmeister
UD2.218A
<p>The Internet landscape is evermore on it’s steadfast course towards surveillance and centralization. Video content and streaming out of CDNs now account for half of all global traffic; splinternets are now a thing, from China to South Korea, from Russia to Iran; mandatory backdoors on communication platforms are just around the conner with EU’s Chat Control. In this scenario, where most Internet connected devices have become tools of imprisonment rather than liberation, reviving the old ...
2/1/26
Decentralized Internet and Privacy
Mosh Lee
UD2.218A
<p>Can we make the web more decentralized and more private without asking users to switch browsers? For the past five years, the IPFS ecosystem has pioneered multiple approaches to this challenge. This talk shares hard-won lessons about what works—and what doesn't.</p> <p>We'll cover three parallel strategies: (1) pushing for native protocol support in major browsers, (2) driving adoption of critical cryptographic building blocks (such as Ed25519 into WebCrypto API, a three-year standards ...
2/1/26
Decentralized Internet and Privacy
David Thompson
UD2.218A
<p>The massive size of browser engines has concentrated power over the web platform into a few large corporations. Creating a new browser engine that is sufficiently featureful to be an alternative to the Big Three is practically impossible. But what if we could shrink the footprint of a browser's core? What if a browser was little more than a WebAssembly (Wasm) runtime and nearly everything else was an extension? By breaking up the monolith we would have a chance to re-decentralize control over ...
2/1/26
Decentralized Internet and Privacy
Jah Kosha
UD2.218A
<p>In recent decades, the internet has increasingly become centralized, shifting from its hacker-driven origins into a cartel of advertising companies. It won't get better if we allow these same companies to drive the design of the web browsers and their protocols.</p> <p>Within hacker communities, many solutions have been developed to mitigate centralization, but their adoption has been limited, often because they require specialized expertise to be operated safely.</p> <p>In this talk I'll ...
2/1/26
Decentralized Internet and Privacy
Özcan Oğuz
UD2.218A
<p>For over a decade, critiques of OpenPGP and GnuPG have resurfaced in cycles: too complex, too fragile, too old, unfriendly, too “cryptonerd.” Modern messaging apps, "forward-secrecy-by-default" protocols, and crypto tools are frequently presented as decisive reasons to abandon GPG altogether. Yet these arguments often rely on a deeper and more troubling assumption: that ordinary users cannot and should not be expected to understand or control their own cryptographic identity.</p> <p>This ...
2/1/26
Decentralized Internet and Privacy
UD2.218A
<p>Nym is the first decentralized noise-generating mixnet to provision real-world network anonymity to Internet users even against nation-state adversaries. The aim here is to supersede existing VPNs in order to fight increasingly more powerful authoritarianism and surveillance. Unlike traditional centralized VPNs that can be de-anonymized by a global passive adversary - like the NSA - based on their traffic patterns, Nym adds noise (“cover traffic”) to existing Internet communications. ...
2/1/26
Decentralized Internet and Privacy
Hendrik
UD2.218A
<p>TLS has secured the internet for decades, but it has a major limitation: because TLS relies on symmetric encryption, data cannot simply be shared with a third party. As a result, most Web data remains locked inside centralized silos. HTTPS provides authenticity and confidentiality, but not verifiable provenance, leaving applications to rely on screenshots, scraped HTML, or centralized access control mechanisms such as OAuth.</p> <p>zkTLS changes this. Using MPC-TLS and zero-knowledge ...