Blockchain DNS от Пользователь Firefox 13228151
Resolves domains from decentralized blockchain name systems using BDNS public web API. Currently supported TLDs are: .bit (Namecoin), .lib .bazar .coin .emc (Emercoin).
Метаданные расширения
Используется
![]()
A doorway into alternative DNS roots.
This extension allows you to easily visit websites at domain names from Namecoin and Emercoin networks, as well as custom OpenNIC TLDs. There is no configuration — simply install the package and start browsing.
Namecoin and Emercoin are peer-to-peer networks using the same principles as Bitcoin with no central authority. OpenNIC is a community-driven domain authority with a more traditional layout.
Сообщить о нарушении правил этим дополнением
Если вы считаете, что это дополнение нарушает политики Mozilla в отношении дополнений, или имеет проблемы с безопасностью или приватностью, сообщите об этих проблемах в Mozilla, используя эту форму.
Не используйте эту форму, чтобы сообщать об ошибках или запрашивать новые функции в дополнении; это сообщение будет отправлено в Mozilla, а не разработчику дополнения.
Blockchain DNS: Is Blockchain The Future of Domain Names?

The DNS or, The Domain Name System, acts like a phonebook for the internet, translating easy-to-understand domain names, like google.com, into a specific Internet Protocol (IP Address). This allows web browsers, like Google’s Chrome and Microsoft’s Internet Explorer, to locate the correct website for the user.
The DNS system has been operating continuously since 1983 and is continuously evolving to suit the needs of an ever-growing internet. For the DNS to operate correctly, it must provide constant availability to users, must maintain data integrity to prevent data corruption, and needs to implement a certain degree of privacy to make it harder for the public to analyze the browsing history of individual users.
In general, DNS packets are unencrypted, so when users send requests to a DNS server, both the DNS server and all other parties on the route (including your internet provider and anyone else on your WiFi) know exactly what websites you are visiting.
Currently, the DNS system is fully centralized and is organized by ICAAN (The Internet Corporation for Assigned Names and Numbers), a non-profit organization based in the United States. DNS data is distributed worldwide but is managed by different organizations hierarchically, via a first-level, the root level, managed by registries, and a second-level system, which is operated by registrars.
Right now, giants like Cloudflare, GoDaddy, Amazon, Google, and Namecheap, among others, dominate the domain registration space, registering and renting domain names to users in a centralized manner that is neither private, democratized, or particularly secure. These services can, at any time, delete or remove a customer’s domain, and are also vulnerable to hacking.
All of this means that, while the DNS system is essential to our modern internet, it has a wide variety of vulnerabilities– vulnerabilities that could potentially be solved by the integration of blockchain technology into the current DNS system.
In this article, we’ll discuss both the current shortcomings of the existing DNS system, as well as the advances in blockchain technology that are providing the next generation of internet users more secure, flexible, decentralized, and censorship-proof domains.
DNS Hacks Demonstrate The Vulnerability of the Current DNS System
Currently, the DNS system is vulnerable to a wide variety of types of hacking and other methods of manipulation. One common attack is referred to as a DNS hijacking or redirection attack, which redirects a user from the expected web address to a different, typically malicious, website. This website may be intended to look like the real website, leading a user to enter personal information or to accidentally download a virus or malware onto their computer.
DDOS or Distributed Denial of Service attacks are another major vulnerability of the current DNS system. DDOS attacks work by overwhelming the target with a massive amount of internet traffic. DDOS attacks are often carried out by “bot farms,” or large networks of computers that have been compromised and are now controlled by a hacker.
DDOS attacks on one website are one thing, but a DDOS attack on the servers of a major registrar, or even ICANN itself, could take down a large portion of the internet, leading to economic losses and even political chaos.
Another type of DNS attack is DNS tunneling, which transmits additional information through the DNS protocol that typically resolves network addresses. Instead of only transmitting necessary data, DNS tunneling injects more data into the DNS pathway, and can often bypass firewalls and other security measures. DNS tunneling can allow a hacker to take control of the domain in question, and can also be used to steal large amounts of domain data. This method has been notoriously used by Iranian hackers to sabotage corporate and government websites in other countries, such as the U.S. and Israel.
A Decentralized, Blockchain DNS Could Increase Security of Domains, Internet Users

Blockchain DNS systems work via distributed networks, with many providing individual nodes equal voting authority over changes to the distributed ledger.
Modern blockchain technology involves the creation of a distributed network, via which a distributed ledger records transactions that are replicated on a series of independent, distributed nodes. Transactions are clustered into blocks, which must be validated by a substantial amount of nodes to be permanently added to the ledger.
Unlike some blockchain systems, in most cases, blockchain DNS providers provide each node with the same voting authority. In general, all nodes must participate in “voting” to approve new changes to the DNS system. While the system isn’t perfect, it helps prevent “whales,” or powerful groups of nodes, from dominating the system and making potentially harmful changes.
By decentralizing and distributing the DNS network, it could make it significantly more difficult for hackers to disrupt the system. It could also prevent DNS issues caused by natural disasters that could take servers offline at major registrars.
Since data on a blockchain ledger cannot be changed or modified after the fact, it would reduce or eliminate the need for current DNS security measures, such as the DNSSEC, or Domain Name System Security Extensions. Currently, this system requires a significant amount of maintenance and necessitates the re-signing of a DNS root zone’s public key information every three months as a security measure.
Blockchain DNS Can Reduce Censorship But Can Be Utilized By Cybercriminals
Another benefit of the decentralized nature of blockchain domain names is the fact that they are very difficult, if not impossible, to take down by government and corporate entities. This could be a massive benefit for journalists and activists, who constantly face the threat of content removal or “content moderation.” This issue is particularly salient in countries with limited or non-existent freedom of the press and significant online censorship, such as Russia, China, Vietnam, Saudi Arabia, and many countries in Africa.
However, the decentralized nature of blockchain domain names can be a double-edged sword. Since they are difficult or impossible to remove, blockchain domains are ideal for cybercriminals. This is particularly the case for cybercriminals who wish to sell illegal items to consumers– and it’s especially concerning for those criminals trafficking in stolen consumer data.
For example, in 2017, Joker’s Stash, a popular website utilized to purchase stolen payment card details, started using blockchain DNS to make it easier for customers to buy stolen data without needing to download a “dark web” browser such as Tor. Of course, there are downsides for criminals to use decentralized blockchain marketplaces since the fact that data is immutably stored on the blockchain could make it easier to track these criminals down.
The Current Status of Blockchain Domains
Blockchain domains currently exist, but they are somewhat more difficult to access than ordinary domains, as they generally require a specific browser extension or browser to access. Currently, blockchain domains are created via smart contracts, which create an easy-to-read web address. Usually, they must use unique extensions, such as .eth or .coin.
“Blockchain domains are far from being a significant portion of existing domains, as more than 99% of domains are currently registered with ICANN in the traditional fashion.”
Owners of domains will register these on the blockchain and will receive a private key. By using the key, they can fully control the domain and do not need to be approved or registered with outside, centralized organizations. These domains act like (and are effectively the same as) blockchain wallets, as they allow users to send cryptocurrency payments directly to the address.
Currently, Ethereum, Alibaba, Handshake, Aloaha blockchain DNS, Luxe, and NEM are among some of the most popular blockchain domain providers on the market. However, blockchain domains are far from being a significant portion of existing domains, as more than 99% of domains are currently registered with ICANN in the traditional fashion.
Common Browser Extensions for Blockchain DNS/Domain Access
Three of the most common browser extensions used to access blockchain domains are:
- FriGate: Designed for the Google Chrome browser, FriGate fully supports EmerDNS zones. EmerDNS, which we will mention later, is one of the largest decentralized DNS systems on the market today.
- Blockchain DNS: Designed for Firefox, Blockchain DNS is another versatile plugin that allows ordinary users to access blockchain domain names.
- PeerName: Available for Chrome, Firefox, and Opera, PeerName is an extension that also allows users to register .coin, .lib, .emc, and .bazar, and domain names via a user-friendly web interface.
Top Blockchain DNS Domain Providers
If you want a blockchain domain, there are a wide variety of providers you can use. Some of the top blockchain domain providers currently include:
- EmerCoin:Emercoin provides a decentralized DNS referred to as EMCDNS EMCSSL. Unlike some blockchain DNS providers, Emercoin utilizes a hybrid proof of ownership, proof of stake (PoS), and proof of work (PoW) system to reach consensus and secure decentralized blockchain domains. They have a variety of other services, as well, including EmerSSL, which provides encrypted, highly-secure access to websites and logins without utilizing a password via decentralized SSL certificates.
- NameCoin: The first blockchain DNS system, NameCoin allows users to register .bit domains using a specialized browser extension. Interestingly, NameCoin was also the first fork of the bitcoin blockchain itself.
- Stack:Stack’s DNS service creates a decentralized domain on a Bitcoin blockchain by merging DNS with a Public Key Infrastructure (PKI), eliminating the need for third-party ID systems, servers, and databases.
- Ethereum Name Service:Ethereum Name Service allows users to combine the benefits of blockchain domains with old-school DNS services. This allows owners of regular domains, like .com or .net, to transfer their domains to ENS, provided they have the DNSSEC registration to prove it. Their domain name service integrates blockchain-based DNS with the traditional DNS system. Thus it allows you to combine the benefits of both. ENS conducts auctions for .eth domains, as well as allowing users to create domains with .pid, .luxe. .xzy, and .kred extensions.
- Handshake:Handshake utilizes its own bespoke blockchain to allow for decentralized domain registration, allowing individual network participants to act as nodes to approve changes to the blockchain. New domain orders are provided an encrypted key that can be utilized to write ordered records.
- Unstoppable Domains:Unstoppable Domains allows the creation of an NFT domain stored in a user’s blockchain wallet. These domains are searchable without any extension on the browsers Opera and Brave and with an extension on major browsers like Chrome and Firefox. Unstoppable Domains is supported by Coinbase wallet, OpenSea, and MyEtherWallet, among many other wallets and services.
Blockchain Can Solve Many DNS Issues But Is Still In Its Infancy
As we mentioned at the beginning of this article, three of the major essential components of an effective DNS system are availability, integrity, and confidentiality. Blockchain DNS protocols are poised to address each of these issues. The immutable and distributed nature of blockchain ledgers prevents availability problems caused by hackers or natural disasters; it also helps ensure data integrity.
“In the future, it’s conceivable that blockchain domain access could be fully integrated into regular web browsers without additional software. Major domain providers, such as GoDaddy and Namecheap, may also begin to offer blockchain domains…”
By providing superior encryption via the issuance of a private key for each domain, these systems also help improve confidentiality for internet users and site creators, even though certain activities of site creators post-site creation may actually become more public.
Despite the great potential for blockchain technology to disrupt and improve how domains operate, the blockchain DNS industry is still in its infancy, with 0.1% or less of all domains currently on blockchains. Blockchain domain access and creation also rely on the use of special web extensions and small domain providers, a hurdle that could turn off ordinary web users.
In the future, it’s conceivable that blockchain domain access could be fully integrated into regular web browsers without additional software. Major domain providers, such as GoDaddy and Namecheap, may also begin to offer blockchain domains, expanding their exposure and popularity with typical consumers.
It’s also likely that it will be possible to easily register traditional domains, such as .com or .net, on blockchains, though this may involve more coordination between traditional registrars (or even ICANN) and blockchain domain providers. Further in the future, organizations like ICANN may even themselves transition to utilizing blockchain protocols, ushering in a new era of security for domains, and perhaps, the internet itself.
The Importance of Oracles for Blockchain Domains
By their nature, blockchains are closed systems, which means they face challenges when integrating outside, real-world information into the smart contracts that power blockchains themselves. Oracles, third-party services that provide off-chain data to blockchains, have become an essential part of the blockchain and DeFi ecosystem over the last few years.
Like other blockchain products and services, effective blockchain DNS/domain name provider services and the websites they host will often have to access outside information. Blockchain DNS services may store domains on the blockchain, but they are still businesses that need to interact with the outside world, meaning that they require powerful oracles to operate.
While blockchain domains and blockchain hosting are different, they are both parts of the push for decentralization in the Web 3.0 ecosystem. External data is also particularly important for websites hosted on blockchain platforms, which may need to pull information from a variety of outside sources, including financial information, news info, and weather and environmental data. As both blockchain DNS and hosting services evolve, this need for external data is only likely to increase.
SupraOracles is Positioned to Provide Secure, Accurate Data for Blockchain DNS Providers and Other Elements of the New Web 3.0 Ecosystem
Blockchain technology is poised to change the structure of the internet forever, and nothing is more core to the internet than the domains that websites are hosted on. Some of the changes that blockchain will provide to domains will be visible to the average internet user.
These may come in the form of the ability to use new domain extensions like .eth and send money directly to web addresses themselves. However, other changes will be less visible, including the potential replacement of ICANN and other organizations with decentralized DNS providers.
If blockchain DNS providers and the blockchain domains they provide are to deliver on their full potential, they’ll need a fast, secure data infrastructure, and SupraOracles is in an excellent position to provide that.
SupraOracles can provide blockchain DNS providers, blockchain hosting services, and other services in the internet domain and hosting space the secure, fast, and accurate information they need. With cross-chain interoperability, powerful decentralized consensus mechanisms, lightning-fast finality, and ultra-secure parallel processing cryptography, SupraOracles can help providers create and secure the next generation of internet domains.
DNSChain — блокчейн основанный на DNS

DNSChain позволяет быть уверенным, что вы общаетесь с тем, с кем хотите общаться, и подключаетесь к сайтам, к которым хотите подключиться, без какого-либо тайного прослушивания ваших разговоров. DNSChain обладает отличными от X.509 критериями безопасности. В X.509 чем больше центров сертификации существует, тем менее безопасны все соединения SSL / TLS. С другой стороны, чем больше DNSChain-серверов запрашивают запросы, тем больше вероятность, что они будут иметь достоверную информацию.
Скачать dnschain
В отличие от традиционных DNS-серверов, DNSChain поддерживает широкое развертывание сервера (в идеале, «по одному для каждой группы друзей», похожее на то, как люди полагаются на личные роутеры сегодня). Эта распределенная плоская топология устраняет необходимость в открытых преобразователях, делая ее практичной для ограничения клиентов небольшим доверенным множеством. Кроме того, в то время как традиционные DNS-преобразователи должны запрашивать другие DNS-серверы для ответа на запросы, у преобразователей DNS основанных на блочной цепочке нет такого требования, потому что все данные, необходимые для ответа на запросы, хранятся локально на сервере.
Соединения между DNSChain и клиентами, которые он обслуживает, защищены MITM с помощью известной технологии фиксации с открытым ключом (public-key pinning ). Главное отличие от DNSChain так это то, что одиночный pin — это все что необходимо для того, чтобы запустить MITM защиту для всех других интернет соединений:
- DNSChain работает бок о бок с полными узлами блок цепей, которые работают на одном и том же сервере. и частные лица хранят свой открытый ключ в блок-цепочке (DNSChain поддерживает несколько), и с этого момента этот ключ становится MITM-защищенным.
- Последний и самый правильный ключ отправляется клиентам через безопасный канал между DNSChain и его клиентами. Затем они могут установить дальнейшие MITM-защищенные соединения с владельцем (ами) этих ключа (ей).
Следует подчеркнуть, что сам сервер DNSChain может быть вредоносным, и поэтому пользователи должны запрашивать только сервер (или серверы), которым у них есть веские основания доверять. Если у них нет доступа к надежному серверу DNSChain, они должны запросить несколько серверов независимо друг от друга и проверить соответствие ответов.
Блок-цепь — это безопасная децентрализованная база данных. Информация, хранящаяся в нем, может быть прочитана в любом месте по всему миру, а DNSChain обеспечивает легкий доступ к ней с помощью агностического API-блока.
Что это такое DNSChain ?
- DNSChain заменяет X.509 PKI на цепь блоков (blockchain)
- Проверка подлинности MITM защиты
- Простое и безопасное распределение ключей GPG
- Безопасная, MITM-proof RESTful API для цепи блоков (blockchains)
- Доступны бесплатные сертификаты SSL
- Предотвращение DDoS атак
- Отзыв сертификата, который действительно работает
- Обход цензуры на основе DNS
- Другие свойства: набор тестов, ограничение скорости передачи данных и кеширование
Разработчики
- Защищаем ваши приложения вместе с DNSChain
- Делаем вклад в разработку DNSChain
- Добавляем поддержку для вашей любимой цепи блоков (blockchain)
- Запускаем тесты
Запуск вашей собственной версии
- Требования
- Давайте начнем
- Настройки
- Руководство: Настраиваем DNSChain сервер с Namecoin и PowerDNS
- Скоро опубликуется: защищаем HTTPS сайты с помощью DNSChain
Использование DNSChain
- Бесплатные публичные сервера DNSChain
- Доступ к blockchain доменам типа okturtles.bit
- Регистрация доменов и идентификаторов блочной цепочки (blockchain)
- Дешифровка коммуникаций непрерывной цепью, не полагаясь на ненадежных сторонних участников
- Разблокирование цензурированных веб-сайтов (уже скоро!)
- И многое другое!

Это интересно:
Оставьте ответ Отменить ответ
С 20 по 22 апреля пройдут незабываемые битвы среди кибер-гладиаторов в мире информационной безопасности!
Открыта регистрация команд по ссылке .
Blockchain Domains vs. Traditional DNS: Everything You Need to Know
![]()
The Domain Name System (DNS) is something that the average internet user has regularly interacted with, but rarely they have an idea of how it works under-the-hood.
Putting it on a silver platter, this integral piece of internet infrastructure is what allows you to type the namespace “linkedin.com” instead of the IP address “108.174.10.10” on your web browser. Imagine if you have to remember every single IP address of your favourite internet services — not too convenient, isn’t it?
With that said, there exist gross inefficiencies plaguing the traditional DNS value chain — giving rise to the narrative of blockchain domains as the next-generation solution towards IP address naming.
Before we get into it though, you will need to know some of the key concepts regarding how the traditional DNS actually works behind-the-scenes.
The Domain Name System (DNS)
The name “google.com” might be easily ‘remember-able’ for us humans, but for computers who are actually doing the grunt work, this alphabetical string is actually a pain in their (metal) ass.
We assign alphabetical names like “Joe” or “Jill” to people, mainly because it is easy for us to refer to people by these names. For computers however, it is easier for them to refer to each other with numerical names (or what we call as IP addresses) like “105.21.51.78”.
To address this difference in naming preference between humans and computers, we came up with something called the Domain Name System (DNS). In simplest terms, it allows humans to assign a human-readable name in place of a computer’s machine-readable name. These records are then stored on a huge lookup database.
From the user’s perspective, upon requesting “google.com” from the web browser, the text will be directed to this lookup database — which then determines whether “google.com” actually exists. If it does, the database will return its associated IP address, in which the web browser will use it to locate the server where the content is hosted on.
The whole process is analogous to asking a librarian where a certain book is located: 1) you tell the librarian (the lookup database) the name of the book that you’re looking for; 2) the librarian searches for the book’s location as per the library’s records; 3) if it exists, the librarian replies you with the book’s exact aisle, shelf, and row number, so that you can go and retrieve it.
This huge lookup database is collectively maintained by ICANN and its network of registries and registrars. ICANN (Internet Corporation for Assigned Names and Numbers) oversees maintenance of the root name server. Following on, registries are responsible for top-level domains (TLD), and registrars manage second-level domains (SLD) and its constituents.
Relating back to our library analogy, aisles will be the equivalent of the root name server, shelves will represent top-level domains, rows will be like second-level domains, and so forth.
The hierarchical design of the DNS means that only ICANN is able to add a new TLD into the root name server. To register a new TLD, registries must submit a paid application to ICANN, then wait for approval before the TLD is reflected on the root name server by ICANN.
Registries come in all shapes and sizes depending on the nature of the TLD. In the case of “.com” and “.net”, since they are meant for commercial purposes, they are maintained by Verisign, an American for-profit firm. There are also TLDs reserved for sovereign nations such as “.au” for Australia, or “.uk” for the United Kingdom — usually maintained by a government-sanctioned entity.
Going down the bottom of the food chain, just like how registries require ICANN’s approval to register a TLD on the root name server, registrars will also need to obtain a registry’s approval for the right to register SLDs on top of the registry’s ICANN-approved TLD. Fees will depend on the registry itself — but as a rule of thumb, commercial TLDs like “.com” will usually cost more.
Registrars are usually the first point-of-contact for most people: interfacing with the likes of GoDaddy when looking to buy domain names. Accordingly, registrars maintain SLD ownership records for their customers — where its main responsibility is to prevent ownership conflicts.
All in all, the DNS is essentially a unified view on world domain ownership, spearheaded by ICANN along with its network of registries and registrars.
Blockchain Domains: Disrupting Registries and Registrars in One Fell Swoop
Due to the nature of the traditional DNS, gross inefficiencies will emerge as a byproduct of the coordination overhead amongst participating intermediaries. Recall that the DNS involves at least three separate entities: ICANN, registries, and registrars.
With each layer of intermediary comes additional red tape to jump over when processing SLD registration requests, and more cuts taken from the “domain registration pie” to sustain each intermediary’s operations (along with some profits for its shareholders). As a consequence, these costs get directly passed down to us, the end-users buying up the SLDs in the first place.
Historically, there needs to exist a separation of powers on TLD and SLD registration. If not, rent-seeking practices would gradually ensue — a natural repercussion of centralized management. But now for the first time ever, TLD and SLD registration could be rearchitected into a single cohesive unit: the blockchain domain protocol.
Building on from the above, just like how DeFi has managed to disrupt the entrenched banks and financial institutions of our traditional financial system, blockchain domain protocols could potentially take on the roles of the registries and registrars of our traditional DNS in one fell swoop.
Instead of having Verisign and GoDaddy as the TLD registry and SLD registrar respectively, a smart contract could act as a “container” for a TLD, in which SLDs on top of this TLD would be represented as distinct NFTs — one NFT for each SLD. As such, anyone will be able to claim an unowned SLD for a fee anchored on supply and demand, wherein the fee determination algorithm would be enshrined within the protocol itself. This transparency ensures that instances of manipulation is highly unlikely, if not infeasible.
This “SLD NFT” would also be freely tradable, since it is an on-chain NFT. In terms of market dynamics on highly sought-after domain names, the same implications found on the traditional DNS would also carry over to blockchain domain protocols: the more lucrative an SLD is regarded (for instance, a short SLD with a catchy name), the higher price the SLD would command.
Underpinned by the blockchain’s properties of credible-neutrality and decentralized consensus, once a party claims a domain name via SLD NFTs, ownership of the domain will be irrevocable and immutable — assuming the owner pays its associated renewal fees in time throughout its tenure. Since SLD NFTs are transferrable just like regular tokens and NFTs, they would be able to be resold on secondary markets at the discretion of their owners.
In the event of domain name defaults, the smart contract will automatically update the subject domain name’s ownership status on its registry, such that it is available for purchase by interested parties. The SLD NFT belonging to this defaulted owner would become worthless — the smart contract will mint a new SLD NFT for the domain’s new owner upon verification of the purchase, which will then be reflected on its registry in place of the old SLD NFT.
In addition, it offers an additional benefit native to the crypto space: referencing a crypto address with a remember-able name. In this case, if the lookup database of the traditional DNS only contains two “columns” (namespace, IP address), the lookup database of blockchain domain protocols would consist of three “columns” (namespace, IP address, crypto address). As such, users will be able to send crypto transactions via remember-able domain names instead of having to input the full string of a crypto address.
In a nutshell, blockchain domain protocols safely combine the functions of registries and registrars under one unified umbrella. The deterministic nature of smart contracts, coupled with the blockchain’s inherent properties of credible-neutrality and decentralized consensus, eliminates the need for centralized intermediaries to step in and mediate world domain ownership.
The cost of domain ownership would significantly decrease: less intermediaries would mean less red tape and more efficiency across the board, eventually leading to cost-savings for the end-users.
Looking Forward
Currently, the utility of blockchain domain protocols is still restricted to referencing crypto addresses via human-readable names. For blockchain domains to be able to reference IP addresses (for hosting websites, etc.), the protocol needs to first obtain ICANN’s approval for its TLD, so that the TLD can be reflected on the root name server.
As blockchain domain protocols approach maturity, governance of the smart contract registry could be gradually handed over to a DAO, where its scope might include: adding a new TLD and creating a new registry for it, removing underutilized TLDs and deleting its associated registries, leading ICANN talks to register a new TLD to the root name server, altering the protocol’s value accrual model for its native token, protocol fiduciary elections, and other ad-hoc resolutions.
Disclaimer: The author @0x_delken is a Reitio core team member. The views and opinions expressed throughout are those of the author as an individual, and do not necessarily reflect the official policy or position of Reitio as a project.