FINDING · DEFENSE
Pseudo-TLDs (e.g., '.key' for cryptographic-identifier namespaces, '.pet' for petname systems) allow multiple censorship-resistant name systems with distinct security trade-offs to coexist transparently alongside DNS via Name Service Switch configuration, with system-specific resolution logic applied per TLD and no application reconfiguration required by users.
From 2013-wachs-feasibility — On the Feasibility of a Censorship Resistant Decentralized Name System · §4.1 · 2013 · Foundations \& Practice of Security
Implications
- Namespace censorship-resistant resolution under a dedicated pseudo-TLD so circumvention tools can offer an alternative name layer without breaking compatibility with DNS-dependent legacy applications.
- Build delegation support allowing pseudo-TLD resolution to fall back to authoritative DNS nameservers for uncensored subdomains, so censorship is bypassed only at the minimum necessary layer of the hierarchy.
Tags
Extracted by claude-sonnet-4-6 — review before relying.