toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

242
active users

#introducing

0 posts0 participants0 posts today

🚨 Fixing the PKI Mess: CAA + Your Own CA via DNS 🚨

Right now, any CA can issue a certificate for your domain. Even if you set a CAA record (`issue "letsencrypt.org"`), it only controls *who* can issue, not what cert is valid. This is broken.

🔐 What if we could fix this using DNS?

#Introducing CAA+CA Fingerprint: Self-Sovereign Certificate Authority
Instead of just saying *which CA can issue*, you publish your own CA's fingerprint in DNS. If your CA issues a cert for `awesomecars.com`, browsers should validate it against the DNS-published CA key.

🔥 How It Works
You run your own CA (because why trust the cartel?). You then publish:
1️⃣ A CAA record specifying your own CA (with a fingerprint! 🔥)
2️⃣ A DNS record with your CA’s public key (like DKIM but for TLS!)

🔹 Example DNS Setup for `awesomecars.com`:
```
awesomecars.com. IN CAA 0 issue "pki.awesomecars.com; sha256=abcd1234..."
pki.awesomecars.com. IN CERT 6 0 0 (--BEGIN CERTIFICATE-- ....)
```
Now, only certs signed by your CA are valid for `awesomecars.com`, even if another CA is tricked into issuing a rogue cert. No more CA hijacking!

🚀 Why Is This Better Than the Current CA Model?
✅ Self-Sovereign Identity: If you own the domain, you should own its PKI.
✅ Prevents Rogue Certs: No government or rogue CA can fake a cert for your domain.
✅ Works Like DKIM for Email: Your CA’s public key is stored in DNSSEC-protected records, just like DKIM keys for email signing.
✅ No More External Trust Issues: You control your CA entirely, instead of relying on Google’s CA store.
✅ Perfect for Self-Hosting & Internal Networks: No need for external CA trust—your DNS is your trust model.

🔥 Why Isn’t This a Thing Already?
Big Tech hates this idea because it removes their control:
❌ Google wants Certificate Transparency (CT), where they control which certs are logged.
❌ Commercial CAs make $$$ selling certs. This kills their business.
❌ DNSSEC adoption is intentionally kept low by the same companies who don’t want this to succeed.

Browsers refuse to support TLSA for the same reason—they want centralized CA trust, not self-hosted PKI.

🔗 Who Needs to Implement This?
🚀 Self-hosters & Homelabs: Use this for your own infrastructure.
🚀 Email providers: Stop relying on public CAs!
🚀 Privacy-focused projects (Tor, Matrix, XMPP, Fediverse, etc.): A true decentralized PKI alternative.
🚀 Fediverse devs: Let’s push for DNS-based CA validation!

What do you think? Would you trust your own CA in DNS over some random commercial CA?

🔁 Boost this if you want a decentralized PKI revolution!

🔥 This keeps the focus on self-hosting your own CA, highlights the security flaws of current PKI, and calls out Big Tech’s resistance to decentralized trust.

Introducing 𝐓𝐢𝐝𝐲 𝐒𝐞𝐚𝐫𝐜𝐡:⁣

Like the 𝐅𝐞𝐝𝐢𝐯𝐞𝐫𝐬𝐞 and 𝐗𝐌𝐏𝐏, The plan is to share the work on any platform (OS) and any environment. By using a "protocol" like 𝐀𝐜𝐭𝐢𝐯𝐢𝐭𝐲𝐏𝐮𝐛, the goal is to have a decentralize search engine and having multiple systems building the index. Possibly even your phone with your consent of course.⁣

With all the corporate systems using 𝐀𝐈, that is the last thing we want. We do not want 𝐒𝐤𝐲𝐧𝐞𝐭. We also, do not want any kind of tracking like the corporations nor advertising. Using the same concepts as XMPP and ActivityPub, this is how we at 𝐌𝐏𝐀𝐐 are 𝘵𝘢𝘬𝘪𝘯𝘨 𝘵𝘩𝘦 𝘪𝘯𝘵𝘦𝘳𝘯𝘦𝘵 𝘣𝘢𝘤𝘬, like it was back in the 𝐁𝐁𝐒 days.⁣

A couple weeks ago, I started writing in PHP for MySQL database. I'd love to see anyone else that knows other langues, that would like to build a version. You can use it at search.mpaq.org At this point, it needs an API that has "key" updating, but like the Fediverse, the data should be accessible with JSON code.⁣ Indexing 10 websites with over 3,000 pages and now adding #news sites.

Our popular longstanding beginners course, Introducing...Haiku will be starting again on 7th January 2025.

This course is suitable for complete beginners (at haiku, or at creative writing), but at the same time stimulating enough to introduce haiku as a new form to those who are already writing poetry or prose, or even as a refresher for experienced haiku writers.

callofthepage.org/courses/haik

www.callofthepage.orgCall of the Page - One-Line HaikuNew page
Replied in thread

@peakrill

Follow Friday is a thing in the FediVerse, and #FollowFriday and #introducing are where to look for that.

Other places to start are fedi.tips and hueyy.github.io/awesome-mastod .

Thousands of people can also be found on your local timeline, MastodonApp.UK/public/local (which is just 1 of 4 big sites in the U.K.), and in the timelines of interesting hashtags.

fedi.tipsFedi.Tips – An Unofficial Guide to Mastodon and the Fediverse
More from Fedi.Tips
Replied in thread

@Goldfigure

Since it is #FollowFriday, #introducing:

@wessexweather who has the occasional weather map, and @WessexWeather@metapixl.com who has the pictures.

@wood5y who points at #BadJournalism .

@tubemapper who uses cameras in tubes.

@cooraysmith who might mention Doctor Who from time to time. If pressed.

@SpennyH and @Tristananthony who play records.

@nicbest who paints and @keefeglise who occasionally visits London for work.

And everyone else from @CobleandKeel through @SPECR_cat to @botrhb.

Navalny Placed In Punitive Solitary Confinement For 17th Time In Less Than A Year

Imprisoned Russian opposition politician #Aleksei #Navalny has been placed in a punitive #solitary #confinement cell for the 17th time since last August, his lawyer Vadim Kobzev said on July 21.

According to Kobzev, his client was sent to solitary for 13 days for "improperly #introducing #himself to a guard."

Navalny, who has called all of his placements in punitive confinement "#politically #motivated," has served 180 days in solitary.

A day earlier, prosecutors requested a court sentence Navalny to #another 20 #years on charges including extremism.

rferl.org/a/russia-navalny-sol

Radio Free Europe / Radio LibertyNavalny Placed In Punitive Solitary Confinement For 17th Time In Less Than A YearBy RFE/RL's Russian Service

#introducing @lindasgoluppiart :

Every day, @lindasgoluppiart sets some simple-looking task at some wee small hour of the morning, as well as reminding us how many days it is, at most, until the next General Election.

The tasks always end up with a catch in my experience. For example: Today's one, to tiptoe around whilst imagining Henry Mancini's Pink Panther Theme playing, carried the theoretical risk of Kato leaping out of a cupboard, and the actual risk of stepping on a plug.

There's also the other side of the coin.

If you're a long-standing, or even medium-sitting, user of the FediVerse seeing this latest #TwitterMigration wave, some of the things that you can do, in addition to pointing to Awesome Mastodon and FediTips, are:

* Point to today's photograph hashtags, such as #SilentSunday .

* Let the #cricket fans know about the @cricket group.

* Do some introductions. #introducing

* Let people know that their local timelines exist.

Or just talk.