Elektrine lite

← Feed

@stiiin@infosec.space

Post #2447683

2026-05-08 21:25 UTC

@dalias@hachyderm.io @SRAZKVT@tech.lgbt You're missing one more thing to be done server-side: support the TLS DNSSEC Chain Extension (IETF RFC 9102). Because a browser can't rely on the operating system (and/or whichever DNS resolver the computer ends up consulting) to verify or even supply DNSSEC signatures.

Replies (1)

  • @i@toot.pouyan.net 2026-05-08 21:30

    @stiiin@infosec.space to be honest, browsers could just integrate their own caching resolvers. Browsers do all kinds of crazy stuff (DRM, WebRTC, WASM, …), but when it comes to DNS, they are all like "oh no, how can i do this?" But I'm with you: that extension would be killer argument. @dalias@hachyderm.io @SRAZKVT@tech.lgbt

    Open ##2447684