▲ | tptacek 4 days ago | |||||||||||||||||||||||||
TOFU is less secure than using a trust anchor. | ||||||||||||||||||||||||||
▲ | hedora 4 days ago | parent [-] | |||||||||||||||||||||||||
That’s only true if you operate the trust anchor (possible) and it’s not an attack vector (impossible). For example, TOFU where “first use” is a loopback ethernet cable between the two machines is stronger than a trust anchor. Alternatively, you could manually verify + pin certs after first use. | ||||||||||||||||||||||||||
|