Re: EFF STARTTLS Everywhere project

2014-07-30 Thread Viktor Dukhovni
On Wed, Jul 30, 2014 at 03:38:41PM -0400, Jacob S Hoffman-Andrews wrote: > >The EFF folks behind this effort have reached out to me and we've > >discussed some of the issues. I am somewhat ambivalent about this, > >as it introduces a non-scalable registry that does fully address > >the problem, a

Re: EFF STARTTLS Everywhere project

2014-07-30 Thread Jacob S Hoffman-Andrews
The EFF folks behind this effort have reached out to me and we've discussed some of the issues. I am somewhat ambivalent about this, as it introduces a non-scalable registry that does fully address the problem, and perhaps reduces incentives to do it right and deploy DANE. On the other hand, DNS

Re: EFF STARTTLS Everywhere project

2014-07-29 Thread Robert Schetterer
Am 29.07.2014 um 17:23 schrieb Viktor Dukhovni: > On Tue, Jul 29, 2014 at 05:10:25PM +0200, Robert Schetterer wrote: > >> Hi Viktor, perhaps silly question, I sometimes asked myself why not use >> something like advanced SPF with i.e >> >> IN SPF "v=spf1 mx ip4:1.2.3.4/24 >> TLSPOLICY:r

Re: EFF STARTTLS Everywhere project

2014-07-29 Thread Viktor Dukhovni
On Tue, Jul 29, 2014 at 05:10:25PM +0200, Robert Schetterer wrote: > Hi Viktor, perhaps silly question, I sometimes asked myself why not use > something like advanced SPF with i.e > > IN SPF "v=spf1 mx ip4:1.2.3.4/24 > TLSPOLICY:require-valid-certificate -all" Well SPF records are for

Re: EFF STARTTLS Everywhere project

2014-07-29 Thread Robert Schetterer
Am 29.07.2014 um 16:14 schrieb Viktor Dukhovni: > On Tue, Jul 29, 2014 at 03:57:24PM +0200, Per Thorsheim wrote: > >> I don't know if this list is aware of this project? >> >> https://github.com/EFForg/starttls-everywhere > > The EFF folks behind this effort have reached out to me and we've > dis

Re: EFF STARTTLS Everywhere project

2014-07-29 Thread Patrick Ben Koetter
* Patrick Ben Koetter : > * Viktor Dukhovni : > > On Tue, Jul 29, 2014 at 03:57:24PM +0200, Per Thorsheim wrote: > > > > > I don't know if this list is aware of this project? > > > > > > https://github.com/EFForg/starttls-everywhere > > > > The EFF folks behind this effort have reached out to me

Re: EFF STARTTLS Everywhere project

2014-07-29 Thread Patrick Ben Koetter
* Viktor Dukhovni : > On Tue, Jul 29, 2014 at 03:57:24PM +0200, Per Thorsheim wrote: > > > I don't know if this list is aware of this project? > > > > https://github.com/EFForg/starttls-everywhere > > The EFF folks behind this effort have reached out to me and we've > discussed some of the issues

Re: EFF STARTTLS Everywhere project

2014-07-29 Thread Per Thorsheim
Den 29.07.2014 16:14, skrev Viktor Dukhovni: > On Tue, Jul 29, 2014 at 03:57:24PM +0200, Per Thorsheim wrote: > >> I don't know if this list is aware of this project? >> >> https://github.com/EFForg/starttls-everywhere > > The EFF folks behind this effort have reached out to me and we've > discus

Re: EFF STARTTLS Everywhere project

2014-07-29 Thread Viktor Dukhovni
On Tue, Jul 29, 2014 at 03:57:24PM +0200, Per Thorsheim wrote: > I don't know if this list is aware of this project? > > https://github.com/EFForg/starttls-everywhere The EFF folks behind this effort have reached out to me and we've discussed some of the issues. I am somewhat ambivalent about th

EFF STARTTLS Everywhere project

2014-07-29 Thread Per Thorsheim
I don't know if this list is aware of this project? https://github.com/EFForg/starttls-everywhere An intermediate effort before DNSSEC and DANE (hopefully) gets seriously deployed around the world and various TLDs. EFF will talk about this at PasswordsCon next week in Las Vegas, and I'll make refe