Elektrine lite

← Feed

@domi@donotsta.re

Post #1661628

2026-03-26 13:15 UTC

@Mae @april dnssec being different is actually cool. we already maintain that chain of trust for domains, why not use it here problem is, this is signing, not encryption

Replies (2)

  • @Mae@is.badat.dev 2026-03-26 13:21

    @domi @april signing without encryption doesn't seem problematic because you don't send data back

    Open ##1661629

  • @april@donotsta.re 2026-03-26 13:27

    @domi @Mae first of all, what domi already said. but to my actual thoughts: this is intended for static public content of any sort, think indie web pages etc. this is intended as backup behavior for normal user agents like browsers, this does mean tho that long term web pages could be dns only if they just dont have A or AAAA records, but that is outside of my control if thats actually deployed, even tho it would be practical for some. but that would first require wide spread browser support for encryption: its possible to serve encrypted content via this, but the protocol doesnt specify way of decryption or encryption

    Open ##1661630