2週間前、私たちは IETF コミュニティを招待し、Network-infrastructure Hiding Protocol (NHP) のオープンソース実装である OpenNHP への攻撃をお願いしました。お願いはシンプルでした:認証なしで保護されたインフラを発見またはアクセスする方法を見つけることです。
ハッカソンが無事に終了したことをご報告できて嬉しく思います。参加し、プロトコルを検証し、鋭い質問を投げかけ、私たちの前提を公開の場で検証する手助けをしてくださったすべての方に感謝します。
ライブデモ環境はハッカソンの1か月前に公開され、誰でもどこからでも早期にテストを開始できるようにしました。ハッカソン当日の現地・リモート参加と合わせて、OpenNHP は継続的な公開敵対的テストにさらされてきましたが、本日時点で、有効な暗号認証なしに保護されたリソースを発見またはアクセスする方法を実証した人はいません。
このクリーンな結果が実際に何を示しているのか、正確にお伝えしたいと思います。これは OpenNHP が破られない、あるいはプロトコルが「完成した」ことを意味するわけではありません。「認証してから接続する」というセキュリティモデルが、セキュリティコミュニティによる本物の公開敵対的な精査の一巡を乗り越えたことを意味します — それは意義ある一つのデータポイントであり、ゴールではありません。
ハッカソンでのあらゆる試み、あらゆる質問、そして「〜は検討しましたか」という一つ一つが、プロトコルと仕様をより強固にします。これはまさに、インターネットセキュリティプロトコルが大規模に信頼される前に経るべきプロセスだと私たちは考えています。
記録のため、2026年7月6日に IETF の hackathon および ztcpp メーリングリストに送信され、この取り組み全体のきっかけとなった元の告知を掲載します:
[hackathon] IETF 126 Hackathon project: OpenNHP — The Internet Is Becoming a Dark Forest
Benfeng Chen <[email protected]> — Mon, Jul 6, 2026
to hackathon, [email protected]
Hi all,
The recent concerns surrounding autonomous AI-driven cyberattacks, including discussions around systems such as Claude Mythos, may be signaling a fundamental shift in cybersecurity: autonomous AI agents are turning the Internet into a “Dark Forest,” where anything visible can be discovered, probed, and exploited at machine speed.
As described in the “Dark Forest” theory from Liu Cixin’s The Three-Body Problem, the only reliable survival strategy in such an environment may be invisibility. Rather than continuing the decades-long cycle of exposing services and then attempting to defend them, we are exploring a different question:
What if network infrastructure were invisible by default?
To explore this idea, I’ve added a project to the IETF 126 Hackathon wiki:
OpenNHP — Network-infrastructure Hiding Protocol (NHP)
wiki.ietf.org/en/meeting/126/hackathon#opennhp-network-infrastructure-hiding-protocol-nhp
OpenNHP is an open-source implementation of the emerging Network-infrastructure Hiding Protocol (NHP), an authenticate-before-connect Zero Trust protocol designed to make protected infrastructure inaccessible—and ideally undiscoverable—to unauthorized entities.
Unlike traditional security architectures that attempt to protect visible services, NHP seeks to prevent reconnaissance, scanning, DDoS, and pre-authentication exploitation by hiding network resources until cryptographic authentication succeeds.
For the IETF 126 Hackathon, we’re inviting the community to do something simple:
Please try to break it.
We welcome participation from security researchers, protocol designers, cryptographers, network engineers, DNS/TLS/PKI experts, AI security researchers, and anyone who enjoys attacking assumptions.
Potential challenge areas include:
- Discovering protected services without authentication
- Enumerating hidden ports, IP addresses, or domain names
- Performing reconnaissance against NHP-protected infrastructure
- Bypassing authentication or authorization mechanisms
- Exploiting pre-authentication attack surfaces
- Testing resistance to DDoS and scanning attacks
- Finding cryptographic weaknesses or protocol design flaws
- Evaluating AI-assisted attack techniques
- Testing interoperability and performance characteristics
- Demonstrating any attack path that violates the “authenticate-before-connect” security model
The challenge outcome is straightforward:
- If you can discover or access protected resources without successful authentication, we want to understand the weakness and fix it.
- If you cannot, we collectively gain additional confidence in the security properties of the protocol.
We believe that public adversarial testing, peer review, and running code remain the best tools available for building trustworthy Internet security protocols.
Resources:
- Project website: OpenNHP Website
- Source code: OpenNHP GitHub Repository
- Live demo: OpenNHP Demo Environment
- Internet-Draft: draft-opennhp-ztcpp-nhp
I’ll be participating in person at the Hackathon and would welcome collaborators, critics, and especially skeptics.
Thanks,
Benfeng Chen
OpenNHP Project
ハッカソンの結果は IETF 126 ハッカソンセッションで発表されました。プロジェクト、挑戦内容、結果をまとめたスライドはダウンロード可能です:
OpenNHP への攻撃のお誘いはハッカソンで終わりません。ライブデモ環境は引き続きオンラインで公開され、ソースコードはオープンなままで、Internet-Draft は IETF 標準化プロセスを引き続き進んでいきます。もし弱点を見つけた場合は、静かに、責任を持って、できるだけ早くお知らせください。
登録し、仕様を読み、攻撃を実行し、廊下やチャットで難しい質問をし、あるいはただ見守ってくださったすべての方々に — ありがとうございました。プロトコルは、あなたのような方々が現れて破ろうと試みることでより良くなります。また次回お会いしましょう。
LayerV.ai にも感謝申し上げます。同社の協賛のおかげで、IETF 126 ハッカソンへの参加が実現しました。
元のメーリングリスト投稿には、IETF の新規参加者からベテランまで幅広く返信が寄せられました。その一つを、多少匿名化した上でご紹介します。反応の雰囲気がよく伝わる内容です:
Thank you for sharing this Benfeng!
This is my first time attending an IETF event, and I found NHP extremely interesting to read up on. I am currently prototyping a cloud-based application into which I'd love to integrate NHP for testing, so thank you for sharing this.
In return, I will attempt to do my best to break it!
Have an amazing week!
— A first-time IETF Hackathon participant
OpenNHP チームは、協力者、批評家、そして特に懐疑論者を歓迎します。


