Canonical silentmode.st URLs no longer carry a trailing slash (/tools, not /tools/). nginx (tracked now in VPS/SilentMode/silentmode-st.nginx) 301s the old form and serves <dir>/index.html; sub-sites deployed from other repos with relative asset paths (deviant, sirius-x, theseus-x, hephaestus.x, fly.x, code) keep their directory URLs. Every page's internal links are now site-root-relative, which resolves correctly both at /x on nginx and under the BNS gateway's injected <base href="/bns/silentmode.bch/"> — the old ../x/ links were already broken on the gateway route. /theseus becomes the Silent Mode-headered Theseus page (what it is, what's inside, Windows + Android downloads with manifest hashes, verify), linking out to the sovereign theseus.x whose VPS mirror moves to /theseus-x/, the same split as /sirius vs /sirius-x/. /tools is repurposed as the overview: every site, the on-chain twins, the other clients (relay, Firefox, the standalone Ariadne Resolver) and the machine endpoints. The old tools page carried stale APK and resolver hashes; the new pages use the manifest's, verified against the files on dl.silentmode.st. scripts/serve-site.mjs mirrors the nginx rules for local preview.
359 lines
19 KiB
HTML
359 lines
19 KiB
HTML
<!doctype html>
|
||
<html lang="en">
|
||
<head>
|
||
<meta charset="utf-8">
|
||
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||
<title>Sirius — names on the Bitcoin Cash chain — Silent Mode</title>
|
||
<meta name="description" content="Sirius is Silent Mode's naming registry: BNS1 domain names anchored by CashTokens certificates on Bitcoin Cash, records in OP_RETURN, discovery via a public beacon. No registrar, no ICANN, no DNS root — resolvers read the chain directly.">
|
||
<meta property="og:type" content="website">
|
||
<meta property="og:site_name" content="Silent Mode">
|
||
<meta property="og:title" content="Sirius — names on the Bitcoin Cash chain — Silent Mode">
|
||
<meta property="og:description" content="Sirius is Silent Mode's naming registry: BNS1 domain names anchored by CashTokens certificates on Bitcoin Cash, records in OP_RETURN, discovery via a public beacon. No registrar, no ICANN, no DNS root — resolvers read the chain directly.">
|
||
<meta property="og:url" content="https://silentmode.st/sirius">
|
||
<meta property="og:image" content="https://silentmode.st/brand/og.png">
|
||
<meta property="og:image:width" content="1200">
|
||
<meta property="og:image:height" content="630">
|
||
<meta name="twitter:card" content="summary_large_image">
|
||
<link rel="stylesheet" href="shared.css?v=20260910">
|
||
<link rel="icon" type="image/svg+xml" href="favicon.svg">
|
||
</head>
|
||
<body>
|
||
|
||
<nav class="topnav">
|
||
<a class="brand" href="./"><svg class="logo" viewBox="0 0 32 20" aria-hidden="true"><rect class="l1" x="1.5" y="3.5" width="17" height="13" rx="6.5" ry="6.5" fill="none" stroke-width="2.6"/><rect class="l2" x="13.5" y="3.5" width="17" height="13" rx="6.5" ry="6.5" fill="none" stroke-width="2.6"/></svg>Silent <span class="g">Mode</span></a>
|
||
<a href="theseus">Theseus</a>
|
||
<a href="prometheus">Prometheus</a>
|
||
<a href="sirius" class="here">Sirius</a>
|
||
<a href="hephaestus">Hephaestus</a>
|
||
<a href="helios">Helios</a>
|
||
<a href="hermes">Hermes</a>
|
||
<a href="tools">Tools</a>
|
||
</nav>
|
||
|
||
<header class="hero">
|
||
<div class="mark" style="font-size:52px">⭐</div>
|
||
<h1><span class="g">Sirius</span></h1>
|
||
<p class="tag">Home for decentralized domain names on the Bitcoin Cash chain. Names
|
||
that live as <b>CashTokens certificates</b> in a wallet you control, discovered
|
||
through a public <b>beacon address</b> any electrum server can read. No registrar,
|
||
no ICANN, no DNS root — resolvers read the chain directly. Named for the
|
||
brightest star: a fixed reference everyone sees the same way.</p>
|
||
<div class="cta">
|
||
<a class="btn acid" href="/sirius-x/#search-input">Open Sirius.X — register a name</a>
|
||
<a class="btn ghost" href="#how">How BNS1 works</a>
|
||
<a class="btn ghost" href="#tlds">Live TLDs</a>
|
||
</div>
|
||
<p style="margin:1.4rem 0 0;color:var(--dim);font-size:13px">
|
||
<b style="color:var(--mut)">Sirius.X</b> is the sovereign registrar site, served from its own name.
|
||
Mirror: <a href="/sirius-x/">silentmode.st/sirius-x/</a> ·
|
||
gateway: <a href="https://navigate.st/bns/sirius.x/">navigate.st/bns/sirius.x/</a> ·
|
||
native with a resolver: <a href="https://sirius.x/"><code class="inline">https://sirius.x/</code></a>
|
||
</p>
|
||
</header>
|
||
|
||
<div class="wrap">
|
||
|
||
<!-- ============ THE PROTOCOL IN THREE PARTS ============ -->
|
||
<section class="plain">
|
||
<h2>BNS1 — the protocol in three parts</h2>
|
||
<p class="lede">A minimal Namecoin-style name protocol on Bitcoin Cash. No fork, no
|
||
sidechain, no new blockchain — three ordinary mechanisms of BCH doing three
|
||
different jobs.</p>
|
||
|
||
<div class="grid">
|
||
<div class="card">
|
||
<span class="pill p-live">ownership</span>
|
||
<h3>CashTokens certificate</h3>
|
||
<p>An immutable NFT whose commitment is the UTF-8 name. Whoever holds the
|
||
certificate owns the name. Consensus guarantees nobody can mint another
|
||
output in the same category without spending it.</p>
|
||
</div>
|
||
<div class="card">
|
||
<span class="pill p-live">data</span>
|
||
<h3>OP_RETURN payload</h3>
|
||
<p>A tiny JSON payload prefixed <code class="inline">BNS1</code> — the name's
|
||
records (URL, inline HTML page, IPv4, cashaddr, Sia bucket, TLS
|
||
fingerprint). Total budget: <b>≤ 200 bytes</b>.</p>
|
||
</div>
|
||
<div class="card">
|
||
<span class="pill p-live">discovery</span>
|
||
<h3>Beacon dust output</h3>
|
||
<p>Every protocol transaction pays <code class="inline">600 sat</code> to a
|
||
well-known beacon address. Calling <code class="inline">get_history</code>
|
||
on that address enumerates every registration and update ever made — no
|
||
indexer to trust, no server between you and the answer.</p>
|
||
</div>
|
||
</div>
|
||
</section>
|
||
|
||
<!-- ============ RECORDS ============ -->
|
||
<section id="records">
|
||
<h2>What you can attach to a name</h2>
|
||
<p class="lede">Seven record types cover the space between "point at any URL" and
|
||
"the whole website lives in this transaction". Records travel in the same
|
||
<code class="inline">OP_RETURN</code> as the name itself; the total payload stays
|
||
inside 200 bytes.</p>
|
||
|
||
<table>
|
||
<tr><th>Record</th><th>What it holds</th><th>Used for</th></tr>
|
||
<tr><td><code>u</code></td><td>An HTTPS URL</td>
|
||
<td>Redirect the name at any existing site</td></tr>
|
||
<tr><td><code>h</code></td><td>Inline HTML</td>
|
||
<td>A tiny website served entirely from the transaction — no host, anywhere</td></tr>
|
||
<tr><td><code>a</code></td><td>A cashaddr</td>
|
||
<td>Payments — the "send to <code class="inline">alice.bch</code>" use case</td></tr>
|
||
<tr><td><code>ip</code></td><td>IPv4 address</td>
|
||
<td>Point DNS directly at a server you run for the name</td></tr>
|
||
<tr><td><code>p</code></td><td>An upstream URL</td>
|
||
<td>Reverse-proxy an existing site — address bar stays on the BNS name</td></tr>
|
||
<tr><td><code>s3</code></td><td><code>bucket/key</code> or <code>bucket/prefix/</code></td>
|
||
<td>A full multi-file site on the Sia storage network</td></tr>
|
||
<tr><td><code>tls</code></td><td>SHA-256 of the DER certificate</td>
|
||
<td>Pin your server's TLS cert so nobody can MITM the connection</td></tr>
|
||
</table>
|
||
</section>
|
||
|
||
<!-- ============ HOW REGISTRATION WORKS ============ -->
|
||
<section id="how">
|
||
<h2>How registration works</h2>
|
||
<ol class="steps">
|
||
<li><b>Pick a name.</b>
|
||
<span>Labels: <code class="inline">[a-z0-9-]{1,32}</code>. Any TLD you like —
|
||
the chain decides what exists, not a committee. Search availability on the
|
||
<a href="/sirius-x/#search-input">Sirius.X registration page</a>.</span></li>
|
||
<li><b>Mint the certificate (a REG transaction).</b>
|
||
<span>One BCH transaction simultaneously mints an immutable CashTokens
|
||
certificate whose commitment is your name, publishes the records as a
|
||
<code class="inline">BNS1</code>-prefixed OP_RETURN, and pays 600 sat to the
|
||
beacon so every resolver can find it. First valid <code class="inline">REG</code>
|
||
wins.</span></li>
|
||
<li><b>Update records at any time (a UPD transaction).</b>
|
||
<span>A signed transaction that spends and returns your certificate to
|
||
yourself, carrying the new records. Only the certificate holder can do this,
|
||
because a vout in a name's category is only possible if a vin held it.</span></li>
|
||
<li><b>Transfer by sending the certificate.</b>
|
||
<span>Sending the certificate to another wallet transfers the name. No beacon
|
||
transaction needed — the certificate <i>is</i> the ownership token.</span></li>
|
||
</ol>
|
||
|
||
<div class="cta" style="justify-content:flex-start;margin-top:1.6rem">
|
||
<a class="btn acid" href="/sirius-x/#search-input">Start with a name search on Sirius.X</a>
|
||
</div>
|
||
</section>
|
||
|
||
<!-- ============ WALLETS ============ -->
|
||
<section id="wallets">
|
||
<h2>Wallets that can register a name</h2>
|
||
<p class="lede">Registration is a normal Bitcoin Cash transaction shape with a small
|
||
protocol twist: the certificate's identity is derived from the outpoint spent at
|
||
input 0, so the buyer must choose the coin, not the wallet. Any wallet that can
|
||
build a transaction to that spec works.</p>
|
||
|
||
<div class="grid">
|
||
<div class="card">
|
||
<span class="pill p-live">works today</span>
|
||
<h3>Built-in browser wallet</h3>
|
||
<p>Generated in your browser, seed encrypted with PBKDF2 → AES-GCM in
|
||
<code class="inline">localStorage</code>, never transmitted. The registration
|
||
page can search, quote, sign and broadcast in one flow. Self-custody
|
||
throughout — the registrar never touches the certificate.</p>
|
||
</div>
|
||
<div class="card">
|
||
<span class="pill p-live">works today</span>
|
||
<h3>WizardConnect <span class="src s-tor">LGPL</span></h3>
|
||
<p>Pairs the registration page with an external wallet over NIP-17 gift-wrap
|
||
messages — pass-through signing, so the dApp builds the exact transaction
|
||
and the wallet's key just signs. Currently: <b>Cashonize v0.9+</b> on
|
||
chipnet.</p>
|
||
</div>
|
||
<div class="card">
|
||
<span class="pill p-designed">deferred</span>
|
||
<h3>CashConnect</h3>
|
||
<p>Wallet-orchestrated, not pass-through — the wallet auto-selects UTXOs. That
|
||
collides with the genesis-input rule that fixes the certificate's identity
|
||
to a specific coin. May return once its <code class="inline">bch_executeAction</code>
|
||
model ships.</p>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="note"><b>Self-custody by construction.</b> The certificate lands at the
|
||
buyer's own address in the same transaction as the fee payment, so the registrar
|
||
never <i>holds</i> the name. The acceptance test explicitly checks that no
|
||
certificate exists at the fee address after each registration.</div>
|
||
</section>
|
||
|
||
<!-- ============ TLDS ============ -->
|
||
<section id="tlds">
|
||
<h2>TLDs live on chipnet today</h2>
|
||
<p class="lede">BNS on BCH is deliberately TLD-agnostic — the rightmost label is
|
||
the registry. There is no pre-existing root; the first registration under a new
|
||
suffix is what makes that TLD exist. Below is the working set as of today.</p>
|
||
|
||
<table>
|
||
<tr><th>TLD</th><th>Note</th></tr>
|
||
<tr><td><code>.bch</code></td><td>The original TLD; bare on-chain names default to it</td></tr>
|
||
<tr><td><code>.p2p</code></td><td>Peer-to-peer software and services</td></tr>
|
||
<tr><td><code>.deviant</code></td><td>The Deviant division's namespace (Silent Mode's parent house)</td></tr>
|
||
<tr><td><code>.bit</code></td><td>Namecoin's legacy TLD, brought under BNS</td></tr>
|
||
</table>
|
||
|
||
<div class="note"><b>New TLDs.</b> Because there is no root registry to negotiate
|
||
with, a new TLD is simply the first registration under a new suffix. Silent Mode's
|
||
resolver clients will mint TLS certificates only for TLDs on a configured list
|
||
(the local CA is name-constrained) — adding a TLD to that trust list is a
|
||
resolver config change, not a chain change.</div>
|
||
</section>
|
||
|
||
<!-- ============ LIVE NAMES ============ -->
|
||
<section id="live">
|
||
<h2>Live names on chipnet</h2>
|
||
<p class="lede">These are actually registered on chipnet, right now, resolving
|
||
through the relay and every Silent Mode client. Each demonstrates one record type
|
||
from the list above.</p>
|
||
|
||
<table>
|
||
<tr><th>Name</th><th>Backing record</th></tr>
|
||
<tr><td><a href="https://navigate.st/bns/hello.bch"><code>hello.bch</code></a></td>
|
||
<td><span class="src s-chain">h</span> — a page inside the transaction itself</td></tr>
|
||
<tr><td><a href="https://navigate.st/bns/silentmode.bch"><code>silentmode.bch</code></a></td>
|
||
<td><span class="src s-chain">h</span> — this project's own on-chain demo</td></tr>
|
||
<tr><td><a href="https://navigate.st/bns/coinspectrum.bch"><code>coinspectrum.bch</code></a></td>
|
||
<td><span class="src s-srv">ip · p · tls</span> — a full site on an ordinary server, pinned by TLS fingerprint</td></tr>
|
||
<tr><td><a href="https://navigate.st/bns/coinspectrum.deviant.bch"><code>coinspectrum.deviant.bch</code></a></td>
|
||
<td><span class="src s-sia">s3</span> — a full multi-file site on the Sia storage network</td></tr>
|
||
<tr><td><a href="https://navigate.st/bns/siatest.bch"><code>siatest.bch</code></a></td>
|
||
<td><span class="src s-sia">s3</span> — earlier Sia test</td></tr>
|
||
<tr><td><a href="https://navigate.st/bns/argo.bch"><code>argo.bch</code></a></td>
|
||
<td><span class="src s-chain">h</span> — the future hosting-pact brand</td></tr>
|
||
<tr><td><a href="https://navigate.st/bns/theseus.bch"><code>theseus.bch</code></a></td>
|
||
<td><span class="src s-chain">h</span> — the browser's brand page</td></tr>
|
||
<tr><td><a href="https://navigate.st/bns/demo.p2p"><code>demo.p2p</code></a></td>
|
||
<td>Multi-TLD proof — same chain, different rightmost label</td></tr>
|
||
</table>
|
||
</section>
|
||
|
||
<!-- ============ VS ICANN ============ -->
|
||
<section id="vs">
|
||
<h2>Sirius vs an ordinary registrar</h2>
|
||
<table>
|
||
<tr><th>What you get</th><th>Ordinary registrar</th><th>Sirius</th></tr>
|
||
<tr><td>How ownership is proven</td>
|
||
<td>A row in the registry's database</td>
|
||
<td>A CashTokens NFT in your wallet</td></tr>
|
||
<tr><td>Who can revoke it</td>
|
||
<td>The registrar, the registry, ICANN, a court order to any of them</td>
|
||
<td>Nobody — the certificate is an immutable NFT</td></tr>
|
||
<tr><td>Renewal</td>
|
||
<td>Yearly — miss it and the name is auctioned</td>
|
||
<td>Never on chipnet BNS1; mainnet BNS2 will have a lifecycle (below)</td></tr>
|
||
<tr><td>Cost per registration</td>
|
||
<td>$8 – $30 / year, forever</td>
|
||
<td>Chipnet: worthless test coins. Mainnet BNS2 target: ~$10–20 to register & renew</td></tr>
|
||
<tr><td>Identity required</td>
|
||
<td>Email, sometimes phone, sometimes address, always payment method</td>
|
||
<td>A wallet — no email, no phone, no card, no KYC</td></tr>
|
||
<tr><td>DNS resolution</td>
|
||
<td>ICANN → TLD registry → registrar's nameservers → you</td>
|
||
<td>Any electrum server reads the chain; your resolver does the rest</td></tr>
|
||
<tr><td>Web presence</td>
|
||
<td>Depends on a hosting provider that can suspend you</td>
|
||
<td>Point <code>h</code> at inline HTML, <code>s3</code> at Sia, or <code>ip</code>/<code>p</code> at any server you run</td></tr>
|
||
</table>
|
||
</section>
|
||
|
||
<!-- ============ COMING NEXT — BNS2 ============ -->
|
||
<section id="bns2">
|
||
<h2>Coming next — BNS2 & the covenant registry</h2>
|
||
<p class="lede">BNS1 is the chipnet prototype. The mainnet version, BNS2, adds two
|
||
consensus-enforced pieces the prototype leaves as indexer policy. Both are
|
||
designed on paper — the specs live in
|
||
<code class="inline">Decentralized.DNS/</code> — and both wait on the mainnet cutover.</p>
|
||
|
||
<div class="grid">
|
||
<div class="card">
|
||
<span class="pill p-designed">designed</span>
|
||
<h3>Covenant-run registry</h3>
|
||
<p>Certificates live in a CashScript covenant that enforces one certificate per
|
||
name at consensus, not by indexer agreement. Same covenant enforces a
|
||
lifecycle: ACTIVE → (6–12 months) IDLE → OPEN. The owner's option to reclaim
|
||
during IDLE is 50–100× cheaper than a stranger's takeover, so the grace
|
||
period is real: a takeover only ever happens when the owner is genuinely gone.</p>
|
||
</div>
|
||
<div class="card">
|
||
<span class="pill p-designed">designed</span>
|
||
<h3>Commit–reveal (<code>CMT</code> op)</h3>
|
||
<p>A front-running defence. Publish a hash of your name first (with a 16-byte
|
||
salt), reveal the name later; the reveal that points at the oldest valid
|
||
commit wins. An attacker who sees the reveal cannot produce an older commit,
|
||
because blocks are already written.</p>
|
||
</div>
|
||
<div class="card">
|
||
<span class="pill p-designed">designed</span>
|
||
<h3>Trustless purchase</h3>
|
||
<p>Scan-to-sign registration for airgapped SPV wallets: the site builds an
|
||
unsigned transaction, the wallet signs it on a separate device via QR, the
|
||
buyer broadcasts. No relay, no connector, no third party at any point.</p>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="note warn"><b>Why lifecycle matters — the Namecoin lesson.</b> A study
|
||
of Namecoin found ~120,000 <code class="inline">.bit</code> names registered and
|
||
<b>28</b> in actual use. Names live forever mean the interesting ones get
|
||
squatted forever. BNS2's covenant expiry is the design that avoids that trap
|
||
without ever letting an active owner lose a name they still use.</div>
|
||
</section>
|
||
|
||
<!-- ============ HONEST LIMITS ============ -->
|
||
<section id="limits">
|
||
<h2>Honest limitations of the current chipnet build</h2>
|
||
<div class="grid">
|
||
<div class="card">
|
||
<h3>Uniqueness is indexer policy</h3>
|
||
<p>BNS1 depends on resolvers agreeing that "first valid <code class="inline">REG</code>
|
||
wins". Consensus does not enforce it yet — that is what the covenant registry
|
||
above adds for mainnet.</p>
|
||
</div>
|
||
<div class="card">
|
||
<h3>No front-running defence yet</h3>
|
||
<p>An observer of the mempool can copy your <code class="inline">REG</code> and
|
||
race it. Does not matter on chipnet; matters the instant names have value.
|
||
The commit-reveal spec above is written; not implemented on chipnet.</p>
|
||
</div>
|
||
<div class="card">
|
||
<h3>Names live forever (for now)</h3>
|
||
<p>BNS1 has no expiry. The covenant registry adds the ACTIVE → IDLE → OPEN
|
||
lifecycle; BNS1 keeps it flat because the mistake cost on chipnet is zero.</p>
|
||
</div>
|
||
<div class="card">
|
||
<h3>Records ≤ 200 bytes</h3>
|
||
<p>The whole payload including <code class="inline">BNS1</code> prefix and JSON
|
||
fits in one OP_RETURN. Enough for URLs, cashaddrs, IPs and Sia keys —
|
||
inline HTML (<code class="inline">h</code>) is a tiny page, not a full site.
|
||
Bigger sites use <code class="inline">s3</code>.</p>
|
||
</div>
|
||
<div class="card">
|
||
<h3>Beacon is a keyed address</h3>
|
||
<p>Prototype convenience — production would use a keyless constant script so no
|
||
one can be pressured over the beacon key.</p>
|
||
</div>
|
||
<div class="card">
|
||
<h3>Everything is chipnet</h3>
|
||
<p>Mainnet migration is a separate transaction and comes after BNS2 lands. All
|
||
names, coins and mistakes on chipnet are worthless — that is the point of
|
||
doing it there first.</p>
|
||
</div>
|
||
</div>
|
||
</section>
|
||
|
||
</div>
|
||
|
||
<footer>
|
||
<div>Silent Mode — a Deviant project.</div>
|
||
<div class="fine">Named for Sirius, the brightest star — a fixed reference everyone
|
||
sees the same way. Protocol: <code class="inline">Decentralized.DNS/PROTOCOL.md</code>
|
||
(BNS1) plus <code class="inline">DESIGN-covenant-registry.md</code> and
|
||
<code class="inline">PROTOCOL-ADDENDUM-commit-reveal.md</code> (BNS2 additions).</div>
|
||
</footer>
|
||
|
||
</body>
|
||
</html>
|