TIL Chrome ignores CRL. Instead, it pushes out a curated list of invalidated certificates that it thinks are important enough to know about.

And no, we can't see the list.

So, if my web store is hacked and I invalidate the certificate, Chrome users will never know.

Excellent.

@mwlucas Hey, Certificate Transparency solves all 🤮 Have I introduced you to my lord and savior ? :)

@david

Dude, I wrote the book on DANE. :flan_wink:

Needs updating, mind you...

@mwlucas We need to get DANE adopted, all of these CA SSL workarounds just SUCK.

And with ESNI they're not even bothering to pretend that a DNS lookup per request or putting public key information in DNS is "bad" anymore,

@david @mwlucas

Mozilla does not want to work on that (integrating DANE validation in browser).

So no hope in sight. 😢​

@22decembre @mwlucas Yeah, and their arguments are totally BS, and their duplicity is laid bare by their own support of ESNI which.. puts public keys in DNS for SSL requests!

Google's take is likewise poor.

I think a grassroots campaign needs to be waged. Start embedding it in projects and libraries. For example imagine if mastodon for its federation protocol supported DANE.

@david @22decembre @mwlucas Wait, Mastodon federates but without DANE? How does that work without introducing "too big to fail" problems? I have DANE for my XMPP service, it's about the only sane choice (of the realistically available today options) for server<->server federated communication.

Follow

@philpennock @22decembre @mwlucas I just uses the standard CA infrastructure that everyone else uses. Is that 'too big to fail'? I think you HAVE to support the CA infrastructure; but that doesn't mean you need to ONLY support the CA infrastructure, and you get enough things ALSO supporting DANE, and you can slowly ween people off of the CAs... kinda like how we're trying to get IPv6, or ESNI, or even SNI in the first place

· · Web · 0 · 0 · 0
Sign in to participate in the conversation
Cross Family's Mastodon

The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!