-
agh
DANE is awesome. I use Unixes would rewrite gethostbyname to use it.
-
moparisthebest
Menel, also note you should pin your *key* (that never changes) with DANE and not your *cert* which changes every 60 days
-
moparisthebest
in fact it's up to the protocols which DANE profiles are supported and I believe XMPP should prohibit/discourage cert pinning :/
-
Lightning Bjornsson
> agh a écrit : > DANE is awesome. I use Unixes would rewrite gethostbyname to use it. ghbn sucks.
-
agh
Even more so without name integrity
-
moparisthebest
Anyway sadly DANE isn't something we can totally rely on because popular TLDs don't even support it, stop using .im I guess... 🙃
-
agh
Increase the DNSSEC adoption.
-
moparisthebest
Can you convince the .im TLD? It's not up to us
-
Martin
I wonder why they don't support it. Aren't most other popular TLDs supporting it?
-
moparisthebest
Well all new gtlds are required to support it, and the major old ones all do, org, com etc
-
moparisthebest
It's just these stuck in the middle that seem to have no interest
-
Licaon_Kter
Isn't that the actual Island of Man? Like a lighthouse and 4 house and 1637822 companies fleeing taxes?
-
Martin
And unfortunately the island of man is among them…
-
Martin
Licaon_Kter: And instant messaging. 🙃
-
Licaon_Kter
Just a coincidence