CAA, Key Pinning, certificate transparency all bring the risk of CA abuse way down without opening a huge new vector of ISP abuse.
CAA, Key Pinning, certificate transparency all bring the risk of CA abuse way down without opening a huge new vector of ISP abuse.
Gemini is all about reducing possibilities. If you want more possibilities, use the web IMO
But I think ">If you want more possibilities, use the web IMO" goes against the minimalist ethos of Gemini as well; I don't want something as bloated as the web, but perhaps I do want a comment section of my posts? I think that's not too bloated to be thrown in with the rest of the web. But it might very well be too bloated to throw into Gemini, which is reasonable.
Footnote: An email alongside the post + the author editing the post with meaningful and thoughtful contributions could perhaps be a substitute.
=> https://lists.sr.ht/~sircmpwn/public-inbox
Mailing lists are a bit out of vogue, but there's no reason not to bring them back into vogue, at least for people sympathetic to Gemini's ideals.
Of course, what's "added" and what's "simple" is a political value choice in an of itself.
Using a mailing list for comments sounds like "returning to the golden days when we didn't need to take non-techies people seriously but could tell them what to use their cognitive capacity for" i.e. to learn arcane UI that never even tried to really take into account all the learnings of Human-computer interaction about how learning and cognition works.
It really doesn't sound like there's been an actual critical discussion taking into account the needs of a substantial array of potential users. Instead the design seems like a reactive wish to return to olden days.
Which is okay of course, just how it's presentes seems skewed in a very particular way.
I fundamentally disagree here. There are ways that people waste their time on the web that are far more pernicious than "learning how to write gemtext markup"
The web is in a seriously messed up state, and in many ways, things are getting worse. I think it's far more dangerous to shrug our shoulders and just let things continue as they are than to work on projects that attempt to present an alternative.
Edit: A point I'd like to make here is that Gemini is not an alternative web and never will be, according to the designer's own statements. I share your frustration with some of the modern aspects of the web but the web also does a lot of things right that we may take for granted, let's not be so cynical as to forget that. I'm guilty of it myself in the past but no longer, and part of it was because people misled me.
Arguably there are worse things in society than techies making tech for themselves.
Ironically though ... , to me it seems that Gemini and Facebook, though culturally presented as opposites here, are really fruits of the same tree, just different gardens and different stages of growth.
This is one of those things that usually garners the response "normal people would never do that", but honestly I'm surprised that no-one has even tried.
Let's say that web browsers put a short hash of the certificate right in the URL bar. Amazon, for example, could print its hash on every shipping box. Banks could print their hashes on plaques in every branch. Newspapers on their, well, newspapers. Media organizations could occasionally add them to their TV logos and radio jingles. And so on. There's any number of out-of-band channels available.
For most sites, you actually wouldn't need to verify the hash anyway. You usually wouldn't care. But when you did care, I honestly think this isn't such a crazy idea.
This happens about as often as using PGP email. Approximately never.
The attack on things like onion domains would be finding another domain that to a human looks similar enough to be mistaken for the real deal. You'd do that by brute forcing (same as what Facebook did to get the "facebook" prefix in their onion domain) and for a sucessfull attack the space you need to brute force is limited by what humans can distinguish, which is smaller than the whole hash space.
Why would a bank's customer support agent know about encryption? Usually IT is a siloed function in most banks.
We only live without this because the bank can just reverse transactions when there is a problem and the police will fall pretty heavily on anybody that exploits the weakness. And also, because there are plenty of easier to exploit ones.
Doesn't have to be Gemini even, but I think getting buy in from browser vendors after the removal of HPKP is going to be a problem...
Or perhaps instead of a DHT, users could export all their certs to a file and combine/compare entries in a grassroots manner with each other and with devices on different networks.