A New Layered Internet
The internet I build on for a living is getting worse, and I don't only mean the feeds. Imperva's latest bot report found that 53% of the web traffic it saw in 2025 was automated, and 40% came from bots it classifies as malicious. Graphite's ongoing crawl of newly published articles puts the share written mostly by AI at about half, and it has hovered there since early 2025. Underneath the content, the plumbing has concentrated. A 2020 study found that 89% of the top 100,000 websites critically depend on a third-party DNS (Domain Name System)The internet's address book. It turns a name like example.com into the numeric address of the server that answers for it., CDN (content delivery network)A company that keeps copies of websites on servers around the world so pages load quickly. Many large sites depend on the same few CDNs. or certificate provider, and that the top three providers alone could affect 50 to 70% of those sites.
So I've been running a thought experiment. Suppose a BotnetA network of hijacked computers or devices that an attacker controls remotely and uses together, for example to flood a target with traffic. effectively took over the internet we have. What would need to already exist for a second one to take its place?
My first answer was a stack: an independent system at each critical layer, with Content addressingNaming data by a cryptographic hash of its bytes instead of by where it is stored. Anyone can serve it, and anyone can check that it matches the name. as the keystone. Concretely, IPFS (InterPlanetary File System)A peer-to-peer network for storing and sharing files by content address instead of by server location. for content, a decentralized DNS for names and multipath transport underneath. All of it would be free of any central authority and, I assumed, would cost nothing in LatencyThe delay between asking for something and getting it back..
I spent some time checking that sketch against published measurements and incident reports. The keystone held up better than I expected. Several of the specific pieces I picked did not hold up as they stand, and one of them hits a deadline eight days from the day I'm writing this. Every one of those failures turned out to have a known fix, though, and the fixes all share the same shape. It starts from one idea:
Name things by what they are, and it stops mattering who delivers them. Once it stops mattering who delivers them, anyone can.
What a takeover would actually look like
"A botnet takes over the internet" sounds like a movie plot, so I tried to pin down what it would mean in practice. The record shows botnets getting there in two ways. They flood, and they move in.
Flooding is the familiar one. In October 2016 the Mirai botnet, built from hijacked IoT (Internet of Things)Everyday devices with network connections, such as cameras and smart TVs. Many ship with weak security and rarely get updates. devices, aimed its traffic at Dyn, a single DNS provider, and Twitter, Netflix, Reddit and GitHubA popular website for hosting code repositories, reviewing changes and running automated checks. became unreachable for many users across three waves of attack. Dyn estimated up to 100,000 malicious endpoints. The ceiling has risen a long way since then. The current public record is a 31.4 Tbps (terabits per second)A measure of data rate: one trillion bits every second. attack in late 2025 that Cloudflare attributes to the Aisuru-Kimwolf botnet, an estimated one to four million hosts made up primarily of Android TVs. It lasted 35 seconds.
Moving in is the part that changed how I think about this. The KV-botnet that the FBI disrupted in early 2024 lived on end-of-life Cisco and NetGear routers in homes and small offices. Those routers get no patches, and the operators later rebuilt the botnet. Salt TyphoonA hacking group that US agencies attribute to the Chinese government. It broke into major telecom carriers and the routers that run their networks. went further up the chain and targeted backbone, provider-edge and customer-edge routers at telecom carriers, with nine US carriers confirmed compromised by the end of 2024. That is an adversary living inside the network, and any design that assumes the pipes are neutral has to account for it.
Then there is the failure that needs no botnet at all. On November 18, 2025, a database permissions change doubled the size of a configuration file in Cloudflare's bot management system and crashed its proxies for hours. Cloudflare called it its worst outage since 2019. A month earlier, a race condition in the automation that manages DynamoDB's DNS records in AWS us-east-1 left an empty record behind, and the knock-on effects lasted about fifteen hours.
The common thread is concentration, and it sits higher in the stack than I first assumed. When cables in the Baltic Sea were cut in November 2024, RIPE LabsThe research publication of RIPE NCC, the organization that hands out IP addresses in Europe, the Middle East and parts of Central Asia. found that "the Internet managed to route around the damage," with a little added latency and no visible packet loss. The pipes have held up. The fragile part is the handful of services that everyone resolves names and fetches content through. That shifted where I think a new internet most needs to be independent.
Why content addressing is the keystone
A URLA web address, such as https://example.com/report.pdf. names a location. https://example.com/report.pdf means
"ask this server for whatever it currently calls report.pdf."
To trust the answer you have to trust the DNS that found the
server, the Certificate authorityAn organization that browsers trust to vouch that a website's encryption key really belongs to that site. that vouched for it, every
network in between and the server itself.
A content address names the bytes. The name is a Cryptographic hashA short fingerprint computed from data. Changing a single bit changes the fingerprint completely, and finding two inputs with the same fingerprint is practically impossible. of the content, so anyone can hand you the data and you can check it yourself:
/// Accept bytes from any peer, whether a cache or a stranger.
/// The name is the hash, so checking it needs nobody's permission.
fn verify(name: &blake3::Hash, bytes: &[u8]) -> bool {
blake3::hash(bytes) == *name
}That one comparison is why I think the keystone claim holds. Once verification happens at the edge, every layer underneath is allowed to be untrusted. A hostile router can drop your data but it can't swap it, and a copy on your neighbor's machine is exactly as good as the original. GitThe version control tool most software is written with. It records every change to a project as a commit, so history can be compared and undone. has worked this way for about twenty years: once you know a CommitA saved snapshot of changes in a repository, identified by a unique hash, so any past state of the code can be named and found again.'s hash, you can fetch it from any mirror without trusting whoever runs the mirror.
The broader version of the idea is what I'd put at the center. Content addressing is one case of a Self-certifying nameA name that proves its own claim, such as the hash of the content it names or a public key, so you can check it without trusting whoever handed it to you., a name that proves its own claim, and the same trick works at other layers. YggdrasilAn experimental overlay network in which every node's IPv6 address is derived from its public key, so nobody can claim an address without the matching private key. and cjdnsAn encrypted networking protocol, similar in spirit to Yggdrasil, that gives each node an IPv6 address derived from a hash of its public key. derive a node's IPv6The newer version of the internet's addressing scheme, with vastly more addresses than the original IPv4. address from its public key, so nobody can take over an address without the matching private key. The GNU Name SystemA decentralized naming system, published as RFC 9498 in 2023, where each zone is named by its public key and people attach their own nicknames, called petnames., published as RFC (Request for Comments)The numbered documents that define internet standards and practices. Most come from the IETF and are published by the RFC Editor. 9498 in 2023, does the same for naming: a zone's global name is its public key. If every layer names things this way, no layer has to take another's word for anything. Each one can check.
The through-line: trust problems become redundancy problems
Most of what makes today's internet fragile is that we have to trust specific parties, such as a particular DNS provider, CDN, certificate authority or origin server. Trust doesn't scale sideways. Adding a second resolver doesn't make the first one more honest, because the second one might lie too.
Verification changes that. Once a name proves its own content, a wrong answer costs nothing but the time it takes to check, so you can ask many sources at once and keep whichever one verifies first. A trust problem turns into a redundancy problem, and redundancy is something people already know how to build and pay for.
Redundancy has one blind spot. If an attacker can cheaply become most of your sources, adding sources stops helping, and a botnet is exactly that kind of attacker. For that case the design needs a second move, which is to lean on relationships. The 2006 SybilGuardA 2006 research design that limits fake identities by following real social connections, which are much harder for an attacker to create than keys. paper put the reason in one sentence: "Malicious users can create many identities but few trust relationships." A botnet can mint a million keys. It can't get a million people to vouch for them.
Those two moves are the through-line. Verify, then diversify, and where diversity runs out, trust relationships. Every fix below is one of the two, and most of them are already running in production somewhere.
Where the first sketch breaks, and how to fix it
Latency: real on a cold fetch, and payable
I wanted independence to be free. For content nobody nearby has, it costs seconds. The SIGCOMMThe flagship computer networking conference of the ACM, where much of the field's research is first published. 2022 measurement of IPFS put median retrieval at 2.90 seconds and found that most retrievals took at least four times as long as the equivalent HTTPS request. An NSDIThe USENIX Symposium on Networked Systems Design and Implementation, a leading venue for research on building distributed systems. 2024 paper co-written by Protocol LabsThe company that created IPFS and Filecoin and funded most of their development. engineers, titled "The Eternal Tussle: Exploring the Role of Centralization in IPFS," measured nearly the same thing, 2.72 seconds at the median. Part of that is by design: KuboThe main implementation of IPFS, written in Go. It was called go-ipfs until 2022. waits one second for already-connected peers before it starts searching the DHT (distributed hash table)A lookup table shared among many peers with no central server. Each peer stores the entries whose keys are closest to its own ID, so lookups hop toward the right peers.. Mutable names are slower again. ProbeLabA research team that continuously measures the performance of IPFS, libp2p and other peer-to-peer networks. reported median IPNS (InterPlanetary Name System)IPFS's system for names that can change. A record signed by a key points at the latest version of some content, and the name stays the same when the content is updated. resolution at around 11 seconds in 2025, because a lookup waits for 16 responses.
The fix is to stop making every fetch start from zero. Most links are shared by someone who already knows where the content lives, so the link can carry that knowledge along with the hash. BitTorrent Magnet linkA BitTorrent link that names a file by its content hash, optionally with hints about which trackers or peers to ask first. have done this for years. Alongside the content hash they can list trackers and peer addresses to try first:
magnet:?xt=urn:btih:<info-hash>&tr=<tracker-url>&x.pe=<host:port>An irohA peer-to-peer library written in Rust that connects devices directly by public key and moves content-addressed data over QUIC. ticket goes further and bundles a BLAKE3A modern cryptographic hash function released in 2020, designed to be very fast and to verify data in pieces as it streams in. hash with the public key and addresses of a node that has the data, so the fetcher can dial it directly with no lookup at all. A hint can be stale or even malicious and it doesn't matter, because the bytes still have to match the hash.
When there is no hint, race every route at once. Kubo already queries the DHT and the cid.contactA large public indexer for IPFS content. Kubo asks it alongside the DHT by default, which makes lookups faster and also makes it a central dependency. IndexerA service that keeps a large directory of which peers hold which content, so a node can ask once instead of searching the DHT step by step. in parallel and takes whichever answers first. The same pattern extends to local peers, friends' nodes and several independent indexers, the way Happy EyeballsA technique, described in RFC 8305, in which a device tries IPv4 and IPv6 connections at the same time and uses whichever answers first. (RFC 8305) races IPv4 against IPv6 so nobody waits on the slower one.
Mutable names get the same treatment. IPNS records are signed
and carry a sequence number where the highest one wins, so a
client doesn't need 16 peers to agree before it acts. It can
accept the first valid record, show the content and quietly
upgrade if a newer record turns up. Kubo already exposes the
pieces: ipfs name resolve --stream returns records as they
arrive, and --dht-record-count lowers the 16-response
default.
Caching finishes the job. Every node that fetches something can serve it, because a copy is as good as the origin, and the NSDI study shows what that buys: cached lookups at a Gateway (IPFS)An ordinary web server that fetches content-addressed data on your behalf so a regular browser can load it over HTTP. finished within 24 milliseconds at the 95th percentile, and at the median the gateway answered about a hundred times faster than the DHT. Optimistic provideA Kubo feature that announces new content to the DHT faster by estimating when it has reached enough of the right peers, instead of waiting for an exhaustive search., on by default since Kubo 0.39, also cut publishing from about 20 seconds to about 0.7 at the median.
What stays slow is a fetch for content that arrived without a hint and that no nearby node or indexer knows about. That case will keep costing seconds. I think that's a fair price for a network that keeps working when the fast paths are gone, and in the scenario I care about, whether something arrives matters more than how quickly.
Sybil attacks: detect them, then lean on relationships
This surprised me most. A distributed hash table like the one IPFS uses finds content by asking the peers whose IDs sit closest to the content's hash. If an attacker can place enough fake peers near a given hash, they control the answer. In 2024 researchers showed they could censor a specific piece of content on IPFS with 45 fake peers running on a single machine that cost about $4 on AWS. John Douceur named the underlying problem the Sybil attackAn attack where one party creates many fake identities to gain outsized influence over a network, for example by surrounding a piece of content with fake peers. in 2002: without some logically central authority vouching for identities, a peer-to-peer system can't stop one party from pretending to be many. A botnet is an enormous supply of cheap identities.
The first defense comes free with content addressing, because censorship is detectable. You know exactly what you asked for, so silence or a wrong answer is a signal to go somewhere else. The same 2024 paper built on that. Its detector flagged 99.6% of attacks from the pattern of peer IDs clustered around the target, and its region-based fallback raised the share of downloaders who got the content, against the same 45 fake peers, from 0.44% to 100%. It hasn't shipped in Kubo, and a paper posted in 2025 describes an attack that gets past it about 80% of the time, so it isn't the last word. It does show the problem responds to engineering.
Older defenses are sitting on the shelf too. The 2007 S/KademliaA 2007 hardened version of Kademlia, the DHT design IPFS uses, with defenses against attackers who flood the network with fake peers. paper proposed looking a key up along several disjoint paths, so that one poisoned neighborhood can't answer for all of them, and making node IDs expensive to generate with a crypto puzzle. The RustA programming language known for being fast and for catching whole classes of bugs before a program ever runs. implementation of libp2pThe networking toolkit underneath IPFS that finds peers and opens connections between them. It has implementations in Go, Rust, JavaScript and other languages. ships disjoint-path lookups as an option that is off by default. Turning on a defense that already exists is a configuration choice.
Some hardening doesn't transfer. Limiting how many peers can come from one IP range helps against a single attacker renting servers, and does little against a botnet whose members each sit on their own home connection. That is where relationships come in. SybilGuard's insight is that fake identities connect to the honest network through very few trust edges, because persuading real people to vouch is expensive. A node that prefers peers its owner knows, or peers vouched for by people they know, forces an attacker to compromise relationships instead of renting machines. Friend-to-friend routingRouting that only passes requests between peers whose owners know each other. It reaches strangers more slowly but resists fake identities. is slower at reaching strangers, so it belongs in the race as one more route, and it's the one route a botnet can't flood.
With every route raced, an attacker has to win all of them at once: the DHT, every indexer, every hint in every link and every friend's cache.
IPFS re-centralized, so make every piece replaceable
The IPFS network that exists today leans on the kind of concentration I was trying to escape. A 2023 measurement found about 80% of DHT servers running in cloud data centers, with the top three providers hosting just over half of them, and 96% of content-resolution requests coming from Amazon's network. A 2025 study found that 5% of peers now host more than 80% of the content. The public gateways at ipfs.io and dweb.link were serving more than 500 million requests a day earlier this year. In the Eternal Tussle paper, writing as the core maintainers, the authors said they had "begun to explore more hybrid approaches" in response to the performance they measured.
Then, on August 24, Interplanetary ShipyardThe nonprofit that maintained Kubo, Helia and other core IPFS software after spinning out of Protocol Labs in 2024. announced that Protocol Labs would not renew its funding. Shipyard is the nonprofit that has maintained Kubo, HeliaThe JavaScript and TypeScript implementation of IPFS, designed to run in browsers and in server runtimes. and most of the rest of the IPFS stack since it spun out of Protocol Labs in 2024. Its last day of IPFS work is September 30, 2026. On that day it stops operating ipfs.io, dweb.link, delegated-ipfs.dev and the Bootstrap nodeA well-known peer that a new node contacts first to discover the rest of the network. that new IPFS nodes use to find the network. Protocol Labs owns them and, in Shipyard's words, "will determine their future." As of mid-September nobody had named a successor.
The protocol will outlive this, and most of the fixes are already written down. The IPFS Trustless GatewayAn IPFS gateway that returns raw content-addressed blocks so the client verifies every byte itself instead of trusting the gateway. specification defines gateways that return raw blocks for the client to check, so it can verify the data "without delegating any trust to the gateway itself." The Service Worker Gateway does that verification inside the browser, and the IPFS project has started steering ipfs.io and dweb.link visitors to it at inbrowser.link. Once verification moves to the client, a gateway is just a cache, and anyone can run one.
Bootstrapping has a working model elsewhere. Bitcoin Core ships seven DNS seedA DNS name, run by an independent volunteer, that answers with the addresses of active Bitcoin nodes so a new node can find its first peers., each run by a different named person, and falls back to a hardcoded list of nodes if it hasn't found peers within a minute. Add local network discovery and peer exchange, and no single operator's shutdown can strand a new node.
The mirror model is older still. Debian's archive is served from 352 mirror sites, and none of them has to be trusted. A signed index lists the SHA-256A widely used cryptographic hash function that produces a 256-bit fingerprint of any data. of every package, so aptThe package manager on Debian and Ubuntu. It checks every download against hashes listed in an index signed by the distribution. rejects anything a compromised mirror slips in. That is content addressing with a signature on top, and it has worked quietly for years.
Plural implementations close the loop. Kubo, Helia and iroh already speak content addressing in different languages with different tradeoffs, and the keystone is the primitive they share. Two of those three lose their maintainer on the same day, which is exactly why the list needs to be longer. None of them individually has to survive for the primitive to survive.
Naming: DNS as the introduction, keys as the identity
Around 2001 Zooko Wilcox-O'Hearn observed that a naming system can be decentralized, secure and human-meaningful, but only two at once, a tradeoff now called Zooko's triangleThe observation that a name can be at most two of three things: decentralized, secure and meaningful to people. Petname systems work around it by pairing two kinds of names.. Blockchain naming tried to buy all three with a ledger, and the record is rough. When Princeton researchers studied NamecoinThe first fork of Bitcoin, launched in 2011, which stored domain names ending in .bit on its own blockchain. in 2015, 28 of roughly 120,000 registered names were not squatted and had nontrivial content. HandshakeA blockchain project launched in 2020 that aimed to replace the organizations running the DNS root with names auctioned on its own chain. is winding down in the market: Namecheap dropped support for Handshake domains in June 2026, and Namebase is sunsetting its legacy platform.
ENS (Ethereum Name Service)A naming system on the Ethereum blockchain, best known for names ending in .eth that point to wallets, websites and other records. is the success story, and it shows the other problem. Resolution always starts on Ethereum mainnet, which most clients reach through a few RPC providerA company such as Infura that runs blockchain nodes and answers queries for wallets and apps that do not run their own.. MetaMask connects through Infura by default, and Brave resolved .eth names through Infura until it moved to Chainstack in January 2026. In February ENS scrapped its planned Layer-2A separate system built on top of a blockchain like Ethereum to make transactions cheaper, while relying on the main chain for security. chain, and in March it announced plans to apply for .ens as a top-level domain in ICANNThe nonprofit that coordinates the DNS root and decides which top-level domains, like .com or .org, exist.'s 2026 round. The most successful alternative naming system is applying for a seat in the root it set out to route around.
The fix starts by giving up on global human-readable names as the identity. The GNU Name System gives every zone a self-certifying name derived from its key and lets each person attach their own PetnameA private nickname you give to a key or a name, like a contact in your phone. It only has to mean something to you. to the zones they care about, the way your phone's contacts map "Mom" to a number nobody else needs to agree on. The IETF (Internet Engineering Task Force)The open standards body that develops most of the protocols the internet runs on. reserved the .alt suffix in RFC 9476 so systems like this can coexist with DNS without colliding.
Friendly names still matter, so use the DNS we already have as
an introduction. Bluesky's AT ProtocolThe open protocol behind Bluesky. Accounts are identified by DIDs, and ordinary domain names serve as their human-friendly handles. works this way today. A
handle is an ordinary domain name, a DNS TXT record at
_atproto.<handle> points it at a DID (decentralized identifier)A W3C standard identifier that resolves to a document listing the public keys that control it, so ownership is proven by keys instead of by a registry., and the DID is the
account's real identity. The spec describes handles as mutable
and DIDs as "the long-term persistent identifiers." Once
you've resolved someone, you hold their key, much as SSH (Secure Shell)The standard tool for logging in to remote machines. It remembers each server's key and warns you if that key ever changes.
remembers a server's host key in known_hosts after the first
connection and warns you if it ever changes. If DNS later goes
down or gets hijacked, the key you already pinned keeps
working.
The last piece keeps any registry honest. Certificate TransparencyA system of public, append-only logs that record every publicly trusted TLS certificate, so a certificate wrongly issued for your domain can be caught. puts every publicly trusted TLS (Transport Layer Security)The encryption that protects web traffic, shown by the padlock in your browser's address bar. certificate into public append-only logs, and Chrome has required it since 2018, so a certificate authority can't quietly issue a certificate for your domain. WhatsApp and Apple's iMessage both applied the same idea to messaging keys in 2023. A naming service that has to publish every binding in a log like that can still be wrong, but it can't be wrong in secret.
Multipath works when the paths differ in kind
Multipath transport is real and useful. MPTCP (Multipath TCP)An extension to TCP that lets a single connection use several network paths at once, such as Wi-Fi and cellular. has been a standards-track RFC since 2020, and Multipath QUICAn extension to QUIC that lets a single connection use several network paths at once. The IETF approved it in 2026, and it is awaiting publication as an RFC. was approved by the IESG (Internet Engineering Steering Group)The group that gives final approval before an IETF document becomes a standard. in March and is waiting on publication. The catch is written into the MPTCP architecture document: the network does not expose path diversity, so the protocol can only infer it from having more than one address. The InterTubes study mapped US long-haul fiber in 2015 and found single conduits shared by as many as 19 ISPs. Two paths through one trench are one path.
The fix is to choose paths that can't share a trench. Apple has run Multipath TCP in production since iOS 7 for Siri, and since iOS 13 for Maps and Music, across Wi-Fi and cellular, two media that fail for different reasons. Linux has had initial MPTCP support upstream since kernel 5.6 in 2020. Stretch the same idea across fiber from one carrier, a cellular modem, a satellite dish and a mesh radio, and the links stop failing together.
Endpoints can also check instead of assuming. The IETF has already specified how to tell from delay and loss statistics whether flows share a bottleneck (RFC 8382, written for real-time media). SCIONA newer internet architecture in which senders choose the paths their packets take. It already carries the Secure Swiss Finance Network. goes further and lets the sender choose among paths the network publishes, grouped into isolation domains that each keep their own roots of trust. It carries the Secure Swiss Finance Network, roughly 300 institutions, and AMS-IXThe Amsterdam Internet Exchange, one of the world's largest meeting points where networks connect to exchange traffic. started a SCION experiment in April. Its specifications are still in the RFC Editor queue, and Anapaya is the main commercial vendor.
Abuse: moderation that composes
Anything that resists takedown resists every takedown. When Google disrupted the Glupteba botnet in December 2021, about a million Windows machines, the operators had a backup plan: new Command and controlThe servers a botnet's operators use to send instructions to infected machines, often shortened to C2. addresses encoded in Bitcoin transactions. Within days they used it. BazarLoaderMalware linked to the TrickBot gang, used to gain a foothold in corporate networks ahead of ransomware attacks. kept its fallback servers on Emercoin's blockchain DNS, where no registrar could seize them. Kaspersky counted almost 400,000 phishing emails pointing at IPFS-hosted pages in February 2023 alone and noted that "you cannot delete files uploaded by third parties from IPFS." Hash DenylistA list of content hashes that a node refuses to fetch or serve. Each operator chooses which lists to honor. help, though Kubo's own documentation calls them "whack-a-mole," and a 2024 study showed existing filters can be circumvented.
Email is the precedent that gives me the most confidence here. It has no center, it has been abused from the start, and it's still usable, largely because every mail operator chooses which DNS blocklistA list of addresses known to send spam or malware, published over DNS. Each mail server chooses which lists to consult. to consult (RFC 5782 describes the practice) and lists like SpamhausAn organization founded in 1998 that tracks spam and malware sources and publishes some of the most widely used blocklists., founded in 1998, compete on accuracy. Bluesky built the same shape into its moderation in March 2024: anyone can run a Labeling serviceIn Bluesky, an independent moderation service that tags posts or accounts. Each user chooses which labelers to subscribe to., and users stack the ones they subscribe to. Content addressing sharpens this, because a label attached to a hash applies to every copy everywhere.
Signing keys supply the rest. When every author signs, reputation accrues to keys, and a network can give brand-new keys very little reach until someone vouches for them. A botnet's keys are free to create and worth almost nothing to use.
This doesn't make the Glupteba problem disappear. A network nobody can shut down is one a determined operator can hide in. What composable moderation gives you is a network where every community can refuse to carry what that operator publishes.
The stack, assembled
Putting it back together, this is the stack I'd defend now. Every layer follows the same rule: it's independent of the layers around it, and it names things in a way that proves itself. Two layers that share a failure are one layer.
| Layer | Replacement | What proves itself | Weak point | What makes it viable |
|---|---|---|---|---|
| Physical | Community mesh, LoRa, satellite, sneakernet | Nothing, so treat it as hostile | Low bandwidth, patchy coverage | Media that fail differently, plus store-and-forward delivery (RFC 9171) |
| Addressing and routing | Key-derived overlays (Yggdrasil, cjdns, Reticulum), SCION | The address is a hash of a key | Young software | Run as an overlay on today's internet first while RPKI hardens BGP underneath |
| Transport | Multipath QUIC and MPTCP | Keyed, encrypted sessions | Paths that share a trench | Paths over different media, shared-bottleneck detection |
| Naming | Self-certifying zones with petnames | The name is a key | No global readable names | DNS as an introduction, pinned keys, transparency logs |
| Content | Content addressing | The name is a hash of the bytes | Cold-fetch discovery | Hints in links, raced routing, caching everywhere |
| Discovery | Open DHTs, several indexers, friend-to-friend routing | Signed provider records | Sybil attacks | Censorship detection, disjoint lookups, trust-weighted peers |
| Identity and provenance | Signing keys, web of trust, verifiable credentials | The author is a key | Key management | Passkey-style key handling, vouching by people you know |
| Moderation | Subscribable blocklists and labelers | Labels bound to hashes and keys | Whack-a-mole | Reputation on keys, operator-chosen lists as in email |
| Persistence | Pinning by communities and libraries | The hash | Someone pays for disks | Erasure coding across holders, library consortia like LOCKSS |
Inside a single node, the layers meet like this:
A few rows need more than a table cell.
The physical layer is the one no protocol fixes. NYC MeshA volunteer-run community network in New York City that links rooftop antennas to share internet access. has more than 2,000 active member nodes, and Guifi.netOne of the world's largest community networks, built by volunteers and local groups in Catalonia, Spain. in Catalonia reported more than 37,000 in 2021. LoRaA low-power radio technology that sends small messages over several kilometers at very low data rates, with no network infrastructure needed. radios running MeshtasticOpen-source firmware that turns inexpensive LoRa radios into an off-grid text messaging mesh. can carry text across kilometers with no infrastructure at all, at about one kilobit per second on the default preset. Starlink adds a physically different path to more than 12 million customers, though it is one company's network. No single option is enough, and it doesn't need to be, because nothing above this layer cares which link carried the bytes. For links that come and go, the Bundle ProtocolThe IETF protocol for delay-tolerant networking (RFC 9171). Nodes store messages and pass them on when a link becomes available, with no live end-to-end connection required. in RFC 9171 already defines store-and-forward delivery, and a hash is just as verifiable when it arrives a week late by SneakernetMoving data by physically carrying storage, such as a USB stick, from one place to another. on a USB stick.
BGP (Border Gateway Protocol)The protocol networks use to tell each other which addresses they can reach. It trusts announcements by default, which is how route hijacks happen. routing is improving on its own. About 69% of routed PrefixA block of IP addresses that is announced and routed as one unit. now have RPKI (Resource Public Key Infrastructure)Signed records that state which network may announce which IP addresses, so routers can reject hijacked routes. records saying who may announce them, but by APNICThe registry that hands out IP addresses in the Asia-Pacific region. It also publishes measurements of how the internet is deployed.'s measurement only about 27% of users sit behind networks that drop routes failing that check, and ASPAAutonomous System Provider Authorization, a proposed standard that lets networks publish who their upstream providers are, so routers can catch forged routing paths., which would validate the rest of the path, is still an IETF draft. Key-derived Overlay networkA network built on top of another one. Its nodes talk over the existing internet but use their own addresses and routing. sidestep the question for the traffic that uses them, because nobody can answer for an address without holding the key it was derived from. They can run on top of today's internet now and move onto other links as those appear.
Identity is the layer my original sketch was missing entirely, and it's where the degradation actually lives. A hash proves the bytes haven't changed since someone named them. It says nothing about whether a person wrote them. When most traffic is automated and half of new articles are generated, the scarce thing is knowing who stands behind a piece of content. Signing keys give content an author that can be checked, and a Web of trustTrust that spreads through people instead of a central authority. You trust a key because people you already trust vouch for it., the people I trust plus the people they vouch for, lets me decide which authors to listen to without a platform deciding for me. Where an institution's word is needed, W3C Verifiable CredentialsA W3C standard for digitally signed claims, such as a diploma or proof of age, that anyone can check without contacting the issuer. became a Recommendation in May 2025. For media, C2PAThe Coalition for Content Provenance and Authenticity, and its standard for attaching signed records of where a photo or video came from and how it was edited. content credentials attach signed ProvenanceThe record of where something came from and how it got to you. For a memory about code, that means the repository, commit and branch it was learned at. at capture, and Google's Pixel 10 signs every photo its camera app takes. Key management is the honest weak point, and PasskeyA password replacement built on public-key cryptography. Your device keeps the private key and unlocks it with a fingerprint, your face or a PIN. are the evidence that it can be made invisible to ordinary people.
Persistence is the quiet one. Content addressing makes every copy interchangeable, but someone still has to keep a copy, which IPFS calls PinningTelling an IPFS node to keep a copy of some content permanently instead of deleting it to free up space.. A 2023 study found the assets behind about a quarter of Ethereum NFT (non-fungible token)A blockchain record that points to a digital item, often an image stored somewhere else. If nobody keeps that file, the token points at nothing. contracts were no longer accessible. Libraries worked out a version of this problem long ago. LOCKSSLots of Copies Keep Stuff Safe, a program started at Stanford in 1999 in which libraries keep copies of the same material and compare them to repair damage., started at Stanford in 1999, has libraries hold copies of the same material and periodically vote on hashes of it, and a library whose copy is outvoted treats it as damaged and repairs it from the others. Tahoe-LAFSAn open-source storage system that encrypts files and spreads the pieces across many servers, so no single server can read them and losing a few servers loses nothing., which the same Zooko worked on with Brian Warner, uses Erasure codingSplitting data into pieces with added redundancy so it can be rebuilt from any large enough subset, for example any 3 of 10 pieces. to split each file into ten pieces so any three can rebuild it, and the storage providers can neither read nor alter what they hold. Spread pieces across many holders and let institutions choose what to keep, and no single host's failure or business decision can make a file disappear.
What's true today
None of this replaces the internet today, and I'd rather say that plainly. Yggdrasil describes itself as an alpha-level research project. SCION's specifications and Multipath QUIC are still waiting on publication. The most widely used content-addressed network loses its maintainers in eight days. A LoRa mesh moves text at about a kilobit per second, and a cold fetch with no hints still costs seconds.
What's missing is mostly assembly. Nearly every fix above already runs in production somewhere: signed mirrors at Debian, multipath on the iPhone, transparency logs enforced by Chrome, operator-chosen blocklists in email, hash voting among libraries, hash-plus-hint links in BitTorrent. Nobody has put them in one stack whose defaults don't point every new node at a single organization.
What I think is realistic is a network that degrades gracefully. On a good day it rides the existing internet as an overlay, and content addressing makes it faster there, because any nearby copy is as good as the origin. On a bad day it falls back to local peers and whatever links still work, slower but still verifiable. That second mode is the whole point, and it only works if the keystone is in place before the bad day comes.
I also have to be honest about my premise. The pipes have proven more resilient than the services built on them. Cables get cut and traffic routes around them. The outages that actually hit people, Dyn in 2016 and Cloudflare and AWS in 2025, came from concentration at the naming and hosting layers. That is where independence buys the most, and it happens to be where content addressing and self-certifying names do their work.
The idea outlasted the parts
I started with a list of products. Most of them turned out weaker than the idea underneath. IPFS drifted back toward the cloud providers it was meant to route around, and the blockchain naming systems either stalled or went looking for ICANN's approval.
The idea held, and it carried the fixes with it. If the name proves the content, the road stops mattering, so you can have as many roads as you're able to build. Where more roads stop helping, relationships take over, because those are the one thing a botnet can't manufacture. Every layer I'd build now applies one of those two moves. I don't know whether the internet we have gets taken over. I do know the next one can be built from parts that already work, and I want it to be the kind you can check.
Sources
The threat
- Imperva 2026 Bad Bot Report
- Graphite: AI now writes as many online articles as humans do
- Kashaf, Sekar and Agarwal, third-party dependencies of top websites (IMC 2020)
- Dyn's analysis of the October 21, 2016 attack
- Cloudflare DDoS threat report, Q4 2025
- US DOJ on the KV-botnet disruption
- CISA advisory AA25-239A on Salt Typhoon
- Cloudflare's November 18, 2025 outage post-mortem
- AWS us-east-1 October 2025 post-event summary
- RIPE Labs: does the Internet route around damage?
Content, latency and discovery
- Trautwein et al., Design and Evaluation of IPFS (SIGCOMM 2022)
- Wei et al., The Eternal Tussle: Exploring the Role of Centralization in IPFS (NSDI 2024)
- Kubo 0.39 changelog
- BEP 9, magnet URI format
- iroh-blobs BlobTicket
- RFC 8305, Happy Eyeballs Version 2
- IPNS record specification
- Kubo
ipfs name resolvereference - Sridhar et al., Content Censorship in the InterPlanetary File System (NDSS 2024)
- Douceur, The Sybil Attack (IPTPS 2002)
- Baumgart and Mies, S/Kademlia (ICPADS 2007)
- Yu et al., SybilGuard (SIGCOMM 2006)
- Balduf et al., cloud concentration in IPFS (IMC 2023)
- Shipyard: the end of IPFS at Shipyard
- IPFS Trustless Gateway specification
- IPFS Service Worker Gateway
- Bitcoin Core chain parameters and DNS seeds
- Debian repository format
- Debian mirror list
- iroh 1.0
Naming
- Kalodner et al., An empirical study of Namecoin (WEIS 2015)
- ENS docs on CCIP-Read
- RFC 9498, The GNU Name System
- RFC 9476, The .alt Special-Use Top-Level Domain
- AT Protocol handle specification
- OpenSSH ssh(1) manual
- RFC 6962, Certificate Transparency
- WhatsApp key transparency
- Apple iMessage Contact Key Verification
Transport and routing
- RFC 6182, Architectural Guidelines for Multipath TCP Development
- Durairajan et al., InterTubes (SIGCOMM 2015)
- draft-ietf-quic-multipath
- Apple WWDC19 session 712 on Multipath TCP
- Linux 5.6 release notes
- RFC 8382, Shared Bottleneck Detection
- SCION and the Secure Swiss Finance Network
- Hurricane Electric RPKI report
- APNIC on route origin validation coverage
- draft-ietf-sidrops-aspa-verification
- Meshtastic radio settings
- RFC 9171, Bundle Protocol Version 7