4 ms·
How do you secure the DNS entries?
by makeworld 3y ago
How do you secure the DNS entries?
- stephenr 3y agoAs per DANE: you use DNSSEC.
- growse 3y agoI thought we were trying to decentralise?
- quickthrower2 3y agoDNS is not decentralised. You pay some rentseeker for your domain. You might be happier with NFT based domain names? Even then it is not decentralised because whoever wins that mind battle is then the defacto king of that DNS. Unless it is done carefully to avoid early squatting and premine.
- makeworld 3y agoWhich comes back to same CA problem the OP is trying to get rid of, no?
- stephenr 3y agoBecause you're reliant on the registrar and potentially a third party operator running the authoritative name servers? You're already reliant on those things, regardless of whether you want TLS or not. I am a very big proponent of building things yourself (rather than using an off-the-shelf/existing solution that's similar) - whether that is tooling, or applications, or hosting your own services, and I'm particularly vocal about not making your business be shackled to specific services run by others (e.g. I'm of the opinion that offering exclusively "social login" is a huge red flag), and even I don't start complaining about "well this stack isn't really self hosted, you're still relying on the registrar for your domain!"