Updated recommendations regarding TOFU & TLS

> True. Especially because no one verifies the resulting certificate at 
all. Easy-peasy indeed.
> 
> Actually, one could not bother at all as there is no chain of trust to 
speak of. Even easier.
> 
> What's the point? Honest question.
> 
> What's the [threat|trust|usage] model?
>
> https://en.wikipedia.org/wiki/Threat_model

https://en.wikipedia.org/wiki/Trust_on_first_use

See also section 4.2 of the Gemini specification:

gemini://gemini.circumlunar.space/docs/specification.gmi

---

Previous in thread (6 of 47): 🗣️ Petite Abeille (petite.abeille (a) gmail.com)

Next in thread (8 of 47): 🗣️ Bradley D. Thornton (Bradley (a) NorthTech.US)

View entire thread.