Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Parodper
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
Parodper
4mo ago
What other choices are there? An international body might work, or just move the issue one step back.
32.
▲
by
Parodper
4mo ago
You obviously don't know how DNSSEC works. The DNS root of trust is ICANN, not a government.
33.
▲
by
Parodper
4mo ago
> every government will absolutely double-issue certificates to police, secret service and friends of goverment, and no one will have any recourse. Countries already have CA that issue certificates with more legal force than a handwritte
34.
▲
by
Parodper
4mo ago
We could, and should, switch to DANE. Or else, switch to how X.509 was supposed to be used, with each country running a CA for their nationals.
35.
▲
by
Parodper
5mo ago
It's funny to see that the issues with X.509 certificates, are being solved by what X.509 was intended to be used for: a directory system. It's DNS instead of X.500, but it's a start.
36.
▲
by
Parodper
5mo ago
> Allowing user to just generate a domain for themselves That's limited mostly by policy[1], the current PKI environment already allows delegating CA for a single domain. [1] https://community.letsencrypt.org/t/
37.
▲
by
Parodper
6mo ago
According to the court, the real reason is because ECH would make it impossible to block through DPI.
38.
▲
by
Parodper
6mo ago
ISP are blocking, because of a district judge's ruling.
39.
▲
by
Parodper
2y ago
The money one honestly sounds like a bug.
40.
▲
by
Parodper
3y ago
> The one thing I also wish would be better is discoverability... Just the other day I logged in into an irc server (LiberaChat?) but just didn't know where to go from there.. I got into my country's room, but it was very quiet