▲ | tptacek 4 days ago | |||||||||||||||||||||||||||||||||||||||||||||||||
I don't understand any of this. If you want TOFU for TLS, just use self-signed certificates. That makes sense for your own internal stuff. For good reason, the browser vendors aren't going to let you do it for public resources, but that doesn't matter for your use case. | ||||||||||||||||||||||||||||||||||||||||||||||||||
▲ | jchw 4 days ago | parent [-] | |||||||||||||||||||||||||||||||||||||||||||||||||
Self-signed certificates have a terrible UX and worse security; browsers won't remember the trusted certificate so you'd have to verify it each time if you wanted to verify it. In practice, this means that it's way easier to just use unencrypted HTTP, which is strictly worse in every way. I think that is suboptimal. | ||||||||||||||||||||||||||||||||||||||||||||||||||
|