Tofuproxy – Web proxy, TLS terminator, X.509 TOFU manager, WARC/gemini browser
tofuproxy.stargrave.org
tofuproxy.stargrave.org
Despite being an ISO standard [1] and the default archive format of the internet archive, and despite a handfull of lovingly crafted tools (such as webrecorder [2], warcprox etc.), it never seems to have caught on in a broader context.
Really a shame - I' deeply convinced that the ability to archive and replay requests is a technique for defending and strengthening user rights.
Links:
[1] https://www.iso.org/standard/44717.html
If you want to generate WARC from browsers, warcprox is relatively easy and fast - but setting up the proxy settings etc. is cumbersome if all you want is a single archive.
By the way, there are some great tools that use WARC under the hood such as perma [1]. They provide reliable snapshots of single documents with a stable URL.
Edit: I guess theyʼre philosophically opposed to PKI, and are promoting instead certificate pinning, Web-of-Trust: http://www.stargrave.org/Harmful.html
This makes me wonder if itʼs possible to get `Letʼs Encrypt` to cross-sign an HTTPS certificate issued by another CA?
[0] https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...
Eh, a public key plus information about its validity (date, subject) is a certificate? So when you "pin" a key to a domain, you've effectively made a (non-standard) certificate that you explicitly trust?