Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company
neowutran@feddit.org 22 hours agoYes, this part is intentional to raise questions and remark :)
The certificate on my website is not valid using the WebPKI standard, but is valid using the DANE standard. It is related to my comment for this project sr.ht/~yukikoo/dane_without_root/ .
My issue with the WebPKI model is that any government or big company on the planet could do a MITM on your connection, generate a certificate valid for any website, and get a read/write access to all your webpki TLS communications. The DANE model is an improvement over webpki because instead of the “anyone (every ca / intermediate certificate) can generate a certificate valid for anyone” model, it bring a hierarchical trust structure.
greyscale@lemmy.grey.ooo 15 hours ago
You missed my point
It doesn’t work for the user, so it doesn’t work.
Its about equivalent to the user as installing your own cert.
moonshine69@lemmy.nz 14 hours ago
DANE provides user friction…but as OP mentioned TLS doesn’t work
greyscale@lemmy.grey.ooo 3 hours ago
Which means I don’t care because nobody except myself will be able to use it.
I’d care a lot if Firefox and Chrome supported it OOTB
hirihit640@sh.itjust.works 2 hours ago
It works fine, just ignore the warning and don’t enter any sensitive info