@mcc I still have the Gemini icon in Gmail App for my company while I have Gemini disabled for the whole organization 🙃
Even reported it, ofc they don't really care
@mcc I still have the Gemini icon in Gmail App for my company while I have Gemini disabled for the whole organization 🙃
Even reported it, ofc they don't really care
Will "how to disable AI" overtake "how to disable SELinux"?
@GossiTheDog but it missed the house, so it's a "win"!?
@bagder @icing haven't looked at c-ares, but for the DNS if you go down the route with using libraries like getdnsapi (not sure how updated it is) or ldns, you could introduce proper client side DNSSEC validation for the HTTPS records also 🙂
@bagder @icing Woot! Nice! Let me know if you need help with the DNS part, kinda into that stuff 🙃
That's like comparing apples with oranges
TLS does not protect against cache poisoning or any other type of DNS data manipulation
@bagder @icing how can you be sure of that without validating the DNS data you get using DNSSEC.
Again, DNS-over-HTTPS only secures the communication, not the data!
You could be speaking to malicious/spoofed end-point or poisoned caches.
Only way to validate the DNS data you get is by using DNSSEC.
Happy to explain more the differences, you coming to Netnod spring meeting?
@bagder @icing and I'm sorry because it doesn't sound like you understand DNSSEC then. Maybe I'm missing a part but if you only relying on DoH to give you validated DNS data then you're doing it wrong. It should be DoH(/DoT/DoQ)+DNSSEC.
@bagder @icing that was unneeded.
We seem to have talked about different things.
I was only pointing the importance of validating DNS data, nothing to do with the HTTP TLS connection.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.