Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company

<- View Parent
neowutran@feddit.org ⁨22⁩ ⁨hours⁩ ago

Yes, this part is intentional to raise questions and remark :)

The certificate on my website is not valid using the WebPKI standard, but is valid using the DANE standard. It is related to my comment for this project sr.ht/~yukikoo/dane_without_root/ .

My issue with the WebPKI model is that any government or big company on the planet could do a MITM on your connection, generate a certificate valid for any website, and get a read/write access to all your webpki TLS communications. The DANE model is an improvement over webpki because instead of the “anyone (every ca / intermediate certificate) can generate a certificate valid for anyone” model, it bring a hierarchical trust structure.

original
Sort:hotnewtop