💾 Archived View for rawtext.club › ~sloum › geminilist › 005774.gmi captured on 2023-09-08 at 17:13:26. Gemini links have been rewritten to link to archived content

View Raw

More Information

⬅️ Previous capture (2021-11-30)

-=-=-=-=-=-=-

<-- back to the mailing list

[spec] Certificate trust

Martin Keegan martin at no.ucant.org

Mon Mar 1 06:56:31 GMT 2021

- - - - - - - - - - - - - - - - - - - 

On Sun, 28 Feb 2021, Solene Rapenne wrote:

I’m failing to see how TOFU can provide any security, especially if
Does SSH provide any security?
With ssh you can use https://en.wikipedia.org/wiki/SSHFP_record
to improve the security for first connection.

We are using two different definitions of "security".

SSH, even without SSHFP, still provides security. The question is what is the threat model.

Mk

-- Martin Keegan, @mk270, https://mk.ucant.org/