Every revolution starts with a promise. The internet's promise, back in the days of ARPANET and the early TCP/IP experiments, was radical for its time: a network with no center, no single point of failure, and no single authority who could shut it off. Information would route around damage. Speech would route around censorship. That was the design.
The First Digital Revolution: A Network Without a King
In the late 1960s and 1970s, ARPANET connected a handful of university and government computers using packet switching — a method built specifically so the network could survive the loss of any single node. By the time TCP/IP became the standard in the early 1980s, the architecture was fundamentally distributed. No company owned the internet. No government fully controlled it. It was, by design, resilient to censorship because it was resilient to almost everything.
The Domain Name System (DNS) arrived in 1983 to solve a practical problem: numeric IP addresses are hard to remember. Names are easier. Paul Mockapetris's system mapped human-readable names onto machine addresses, and it worked beautifully — but it introduced something the original network design had tried to avoid: a hierarchy. At the top of that hierarchy sat (and still sits) a small number of root authorities, registries, and ultimately ICANN.
How Centralization Crept Back In
For a while, this didn't matter much. The internet was small, technical, and mostly outside the concerns of governments and corporations. That changed as the internet became the primary channel for commerce, media, and political speech. Domain names stopped being just addresses — they became identity, brand, and reach. Whoever controlled the naming layer controlled who could be found, and who could be made to disappear.
Today, a domain can be seized, suspended, or de-listed by a registrar, a registry, or a government order — often without a court hearing the domain owner ever gets to attend. Certificate authorities can revoke trust. App stores can delist. Platforms can shadow-ban. Each of these choke points sits on top of the same underlying pattern: a single administrative party sits between a speaker and their audience, and that party can be pressured, subpoenaed, hacked, or simply changes its mind. Some governments have taken this further still, building entire internet censorship regimes around control of the naming layer.
This is the quiet irony of the modern internet: the wires are still decentralized, but the naming and trust layer running on top of them is not. You can't be found, verified, or trusted online without going through a small number of gatekeepers. Even messaging platforms aren't immune — proposals like the EU's chat control framework show how quickly the message layer itself can become a chokepoint.
Handshake: Returning to the Original Architecture
Handshake is best understood as a correction, not a reinvention. It doesn't try to replace TCP/IP or rebuild the internet from scratch. It targets the specific layer that broke away from the internet's original decentralized design: the root zone and top-level domain registry.
Instead of a centralized list of TLDs controlled by ICANN and a handful of registry operators, Handshake uses a blockchain-based, decentralized auction system where anyone can bid on and own a top-level domain directly, with ownership enforced by a distributed UTXO ledger rather than a corporate database. No single company can revoke a Handshake TLD because no single company issued it in the first place. There's no registrar to subpoena, no central server to seize, no support ticket that leads to a takedown.
That has direct free speech implications, and the case for why that matters at a human level is worth reading on its own — decentralized naming is ultimately about who gets to be found and who gets to speak, which is the foundation of human freedom that HNS is built to defend. A publisher, journalist, or dissident who owns a Handshake name doesn't hold that name at the pleasure of a registrar's terms of service. The name is a cryptographically owned asset, not a rented listing. Combined with DNSSEC-style trust anchors like DANE/TLSA, a Handshake domain can also carry its own certificate trust — removing the need for a centralized certificate authority that could otherwise be pressured into revoking a site's credentials.
Why This Matters Beyond Crypto Circles
It's tempting to file this under "blockchain use case" and move on, but the stakes are broader than that. As more speech, journalism, and political organizing moves online, the naming and trust layer becomes a de facto speech regulator — whether or not anyone intended it to be. Every centralized choke point is a point where a court order, a policy change, or a bad actor can silence someone without touching a single server or line of code they wrote. This is really just one layer of a much bigger picture — for the fuller map of what's happening beneath the surface of today's internet, see the Iceberg of the Internet series.
Decentralized naming doesn't guarantee good speech will win, and it doesn't make abuse impossible. What it does is remove the single point of failure — the one phone call that can take a voice offline. That was the internet's original bet in the ARPANET era. Handshake is, in a real sense, an attempt to make good on it.
Resolving the Decentralized Web
None of this matters if ordinary users can't actually reach these names. Legacy DNS resolvers don't know how to look up Handshake TLDs, which is why resolution matters as much as ownership. SkyInclude Browser is built to resolve Handshake names natively — including validating DANE/TLSA certificate records directly against the Handshake root, rather than falling back to a centralized certificate authority. That means a Handshake domain's own cryptographic trust anchor is checked at the browser level, closing the loop between decentralized naming and decentralized trust, with no extra configuration or plugins required.
NIHON — Handshake Infrastructure & Web3 Identity.