2.5 years ago, I migrated all my services hosted on a cloud provider to a homeserver.

This homeserver is also my workstation/gaming/dev/everything. I use QubesOS (an operating system based on the Xen hypervisor), and wrote some document about it: https://neowutran.ovh/qubes/articles/homeserver.pdf

Basically, I am hosting:

  • DNS
  • Matrix
  • Email
  • Jitsi
  • Mumble
  • Peertube
  • Screego
  • Nextcloud
  • Searxng
  • Tor
  • Wireguard VPN
  • Copy of wikipedia
  • Personal website And others.

And for TLS, to have better security, and to avoid relying on third party company/providers, I am using DANE.

https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities

https://sr.ht/~yukikoo/dane_without_root/

https://github.com/buffrr/letsdane

The “dane_without_root” is one of my projects and I am welcoming review / feedback on it

( I also posted about it on the QubesOS forum: https://forum.qubes-os.org/t/highlighting-neowutrans-technical-doc-about-qubes )

  • greyscale@lemmy.grey.ooo
    link
    fedilink
    English
    arrow-up
    4
    ·
    4 days ago

    You missed my point

    It doesn’t work for the user, so it doesn’t work.

    Its about equivalent to the user as installing your own cert.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      8 hours ago

      the repo readme writes about this. Firefox does not yet support DANE, it needs a patch, included in the repo.

      • greyscale@lemmy.grey.ooo
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 days ago

        Which means I don’t care because nobody except myself will be able to use it.

        I’d care a lot if Firefox and Chrome supported it OOTB

            • hirihit640@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              2
              ·
              3 days ago

              If you’re just pushing for WebPKI without “thinking too hard” about perpretrating a security system with a large number of failure points, then you’re following that windows method.

              SSL/TLS have very specific benefits. None of which matter that much for reading random articles on the web. So I don’t see the problem with this website doing their own thing to bring attention to the potential issues of the current system.

              • WhyJiffie@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                1
                ·
                8 hours ago

                SSL/TLS have very specific benefits. None of which matter that much for reading random articles on the web.

                it is a huge benefit if a man in the middle cannot run scripts on your computer.

                So I don’t see the problem with this website doing their own thing to bring attention to the potential issues of the current system.

                there is no problem with that. this could work, with the required patch to firefox, also in the repo.

                • hirihit640@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  3 hours ago

                  IMO when reading random articles on the internet you already have to worry about untrusted scripts. I just use NoScript, and if the website requires Javascript I move on