GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Luna :neofox_snug: (lunareclipse@snug.moe)'s status on Saturday, 25-May-2024 07:27:19 JST Luna :neofox_snug: Luna :neofox_snug:

    it's really funny how the chain of trust with TLS CAs is built in such a way where the security of the entire system is equal to the security of the worst CA your web browser trusts

    maybe I shouldn't learn more about how the web works, this is all so cursed

    In conversation about a year ago from snug.moe permalink
    • Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      anna (navi@social.vlhl.dev)'s status on Saturday, 25-May-2024 07:27:18 JST anna anna
      in reply to
      @lunareclipse i wonder how that would compare in practice to gemini which uses TOFU for certs

      always trust the worse CA chosen by your os or browser
      or periodically trust your connection to the site
      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Saturday, 25-May-2024 07:30:42 JST Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
      in reply to
      • anna
      @navi @lunareclipse Well TOFU is neat, except for server-to-arbitrary-server.
      Which is probably why one of the only actual use of DANE is email (DNSSEC being a bit more trustworthy than X.509, but sadly horrible in terms of error handling).
      In conversation about a year ago permalink
    • Embed this notice
      Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Saturday, 25-May-2024 07:36:06 JST Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
      in reply to
      • Haelwenn /элвэн/ :triskell:
      • anna
      @navi @lunareclipse Plus in the case where it's reasonable to expect different servers, I'd say TOFU lowers security because you'd have to copy private keys around (which should never happen), not to even mention that it tends to make you avoid rotating keys.
      It's why for me TOFU is only good for things like ssh.
      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.