两周前,我们邀请 IETF 社区攻击 OpenNHP——我们对网络基础设施隐藏协议(NHP)的开源实现。要求很简单:在未经认证的情况下找到发现或访问受保护基础设施的方法。
我们很高兴地宣布,黑客马拉松已圆满结束,我们要感谢所有抽出时间参与、测试协议、提出尖锐问题,并帮助我们在公开场合验证我们假设的人。
在线演示环境在黑客马拉松开始前整整一个月就已上线,让任何人都能提前开始探测。加上黑客马拉松期间的现场与远程参与,OpenNHP 一直处于持续的公开对抗性测试之中——截至今日,尚无人证明能在没有有效密码学认证的情况下发现或访问受保护的资源。
我们想准确说明这个"零突破"结果实际说明了什么。这并不意味着 OpenNHP 坚不可摧,也不意味着协议已经"完成"。这意味着"先认证后连接"的安全模型经受住了安全社区一轮真实的公开对抗性审查——这是一个有意义的数据点,而非终点。
黑客马拉松中的每一次尝试、每一个问题、每一个"你有没有考虑过……"都让协议和规范变得更强大。我们相信,这正是互联网安全协议在被要求大规模信任之前应该经历的过程。
作为存证,以下是 2026 年 7 月 6 日发送至 IETF hackathon 和 ztcpp 邮件列表、开启这整个行动的原始公告:
[hackathon] IETF 126 Hackathon project: OpenNHP — The Internet Is Becoming a Dark Forest
Benfeng Chen <[email protected]> — Mon, Jul 6, 2026
to hackathon, [email protected]
Hi all,
The recent concerns surrounding autonomous AI-driven cyberattacks, including discussions around systems such as Claude Mythos, may be signaling a fundamental shift in cybersecurity: autonomous AI agents are turning the Internet into a “Dark Forest,” where anything visible can be discovered, probed, and exploited at machine speed.
As described in the “Dark Forest” theory from Liu Cixin’s The Three-Body Problem, the only reliable survival strategy in such an environment may be invisibility. Rather than continuing the decades-long cycle of exposing services and then attempting to defend them, we are exploring a different question:
What if network infrastructure were invisible by default?
To explore this idea, I’ve added a project to the IETF 126 Hackathon wiki:
OpenNHP — Network-infrastructure Hiding Protocol (NHP)
wiki.ietf.org/en/meeting/126/hackathon#opennhp-network-infrastructure-hiding-protocol-nhp
OpenNHP is an open-source implementation of the emerging Network-infrastructure Hiding Protocol (NHP), an authenticate-before-connect Zero Trust protocol designed to make protected infrastructure inaccessible—and ideally undiscoverable—to unauthorized entities.
Unlike traditional security architectures that attempt to protect visible services, NHP seeks to prevent reconnaissance, scanning, DDoS, and pre-authentication exploitation by hiding network resources until cryptographic authentication succeeds.
For the IETF 126 Hackathon, we’re inviting the community to do something simple:
Please try to break it.
We welcome participation from security researchers, protocol designers, cryptographers, network engineers, DNS/TLS/PKI experts, AI security researchers, and anyone who enjoys attacking assumptions.
Potential challenge areas include:
- Discovering protected services without authentication
- Enumerating hidden ports, IP addresses, or domain names
- Performing reconnaissance against NHP-protected infrastructure
- Bypassing authentication or authorization mechanisms
- Exploiting pre-authentication attack surfaces
- Testing resistance to DDoS and scanning attacks
- Finding cryptographic weaknesses or protocol design flaws
- Evaluating AI-assisted attack techniques
- Testing interoperability and performance characteristics
- Demonstrating any attack path that violates the “authenticate-before-connect” security model
The challenge outcome is straightforward:
- If you can discover or access protected resources without successful authentication, we want to understand the weakness and fix it.
- If you cannot, we collectively gain additional confidence in the security properties of the protocol.
We believe that public adversarial testing, peer review, and running code remain the best tools available for building trustworthy Internet security protocols.
Resources:
- Project website: OpenNHP Website
- Source code: OpenNHP GitHub Repository
- Live demo: OpenNHP Demo Environment
- Internet-Draft: draft-opennhp-ztcpp-nhp
I’ll be participating in person at the Hackathon and would welcome collaborators, critics, and especially skeptics.
Thanks,
Benfeng Chen
OpenNHP Project
黑客马拉松的结果已在 IETF 126 黑客马拉松会议上展示。涵盖项目、挑战和结果的演示文稿可供下载:
攻击 OpenNHP 的邀请不会随着黑客马拉松结束而停止。在线演示环境将持续在线,源代码将持续开放,Internet-Draft 也将继续推进 IETF 标准化流程。如果你发现了弱点,我们希望尽快、负责任地、低调地了解到。
致所有注册、阅读规范、发起攻击、在走廊或聊天中提出尖锐问题,或只是默默关注的人们——谢谢你们。协议之所以变得更好,正是因为有像你们这样的人挺身而出尝试攻破它。下次再见。
我们还要感谢 LayerV.ai,正是他们的赞助帮助我们得以参与本次 IETF 126 黑客马拉松。
最初的邮件列表帖子既收到了 IETF 新人的回复,也收到了资深成员的回复。以下是其中一封(略作匿名处理),很能体现大家反馈的精神:
Thank you for sharing this Benfeng!
This is my first time attending an IETF event, and I found NHP extremely interesting to read up on. I am currently prototyping a cloud-based application into which I'd love to integrate NHP for testing, so thank you for sharing this.
In return, I will attempt to do my best to break it!
Have an amazing week!
— A first-time IETF Hackathon participant
OpenNHP 团队欢迎合作者、批评者,尤其是怀疑者。


