2.5 years ago, I migrated all my services hosted on a cloud provider to a homeserver.

This homeserver is also my workstation/gaming/dev/everything. I use QubesOS (an operating system based on the Xen hypervisor), and wrote some document about it: https://neowutran.ovh/qubes/articles/homeserver.pdf

Basically, I am hosting:

  • DNS
  • Matrix
  • Email
  • Jitsi
  • Mumble
  • Peertube
  • Screego
  • Nextcloud
  • Searxng
  • Tor
  • Wireguard VPN
  • Copy of wikipedia
  • Personal website And others.

And for TLS, to have better security, and to avoid relying on third party company/providers, I am using DANE.

https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities

https://sr.ht/~yukikoo/dane_without_root/

https://github.com/buffrr/letsdane

The "dane_without_root" is one of my projects and I am welcoming review / feedback on it

( I also posted about it on the QubesOS forum: https://forum.qubes-os.org/t/highlighting-neowutrans-technical-doc-about-qubes )

you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 14 hours ago (1 child)

You missed my point

It doesn't work for the user, so it doesn't work.

Its about equivalent to the user as installing your own cert.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 13 hours ago (1 child)

    DANE provides user friction..but as OP mentioned TLS doesn't work

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 hours ago (1 child)

    Which means I don't care because nobody except myself will be able to use it.

    I'd care a lot if Firefox and Chrome supported it OOTB

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 1 hour ago (1 child)

    It works fine, just ignore the warning and don't enter any sensitive info

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 1 hour ago (1 child)

    Ah yes, the windows method "just click okay and don't read it or think too hard"

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 1 hour ago*

    If you're just pushing for WebPKI without "thinking too hard" about perpretrating a security system with a large number of failure points, then you're following that windows method.

    SSL/TLS have very specific benefits. None of which matter that much for reading random articles on the web. So I don't see the problem with this website doing their own thing to bring attention to the potential issues of the current system.

  • source
  • parent