Elektrine lite

← Feed

@SRAZKVT@tech.lgbt

Post #2447677

2026-05-08 21:00 UTC

@dalias@hachyderm.io i had never heard of DANE before but ... that just sounds like it would remove certificate authorities from existence which is good ?

Replies (3)

  • @SRAZKVT@tech.lgbt @dalias@hachyderm.io yes, and this is the exact reason why browsers won't adopt this, CAs probably pay browser vendors good money to ensure DANE is never supported in any serious capacity. see: how Windows kernel driver signing still requires you to procure an EV cert (remember those?) even when in the end, it's Microsoft that signs *all* modules that get loaded into the kernel these days.

    Open ##2447678

  • @SRAZKVT@tech.lgbt @dalias@hachyderm.io yes, exactly. And it's not particularly conspiratorial to think that there are huge financial incentives in DANE not being deployed. That said, the @dalias@hachyderm.io DANE counter is reset to 0, after two (2!) days of not mentioning it 😜

    Open ##2447679

  • @dalias@hachyderm.io 2026-05-08 21:18

    @SRAZKVT@tech.lgbt Yes, DANE makes the CA cartel middle-men obsolete. Rather than you proving to the CA that you own your domain via DNS entries you set (and can cryptographically protect), and the CA signing your key to say "yes this key belongs to the owner of the domain".. You just publish your own key in DNS, protected by DNSSEC, using the fact that you have authority over the contents of your own domain's DNS entries. Full adoption would eliminate so many layers of awfulness. And slimy middle-men's business models.

    Open ##2447681