Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
LΞX/NØVΛ :lesbian_flag: 🇪🇺
LΞX/NØVΛ :lesbian_flag: 🇪🇺
@lexinova@toot.community  ·  activity timestamp last week

Of course @mollyim and @bitwarden both use Fastly, that don't have DNSSEC or RPKI validation.

Why did i expect security focussed project to care about the security of their domain / netowrk in the user release mechanism.

#cybersecurity #security #rpki #network

  • Copy link
  • Flag this post
  • Block
Molly
Molly
@mollyim@fosstodon.org replied  ·  activity timestamp last week

@lexinova Hey! Just to clarify, we don't use Fastly. Our releases are hosted on GitHub. If you have details on where you saw Fastly being used, we'd love to verify.

  • Copy link
  • Flag this comment
  • Block
LΞX/NØVΛ :lesbian_flag: 🇪🇺
LΞX/NØVΛ :lesbian_flag: 🇪🇺
@lexinova@toot.community replied  ·  activity timestamp last week

@mollyim https://bgp.tools/dns/molly.im (i checked it as we actually check all our repository), also have you considered a mirror (at the minimum) of github on service like codeberg.

That would allow us European and people that don"t like the AI push of Microslop to checkout your sources, and use your release outside of github.

thanks

Domain Lookup - bgp.tools

  • Copy link
  • Flag this comment
  • Block
Molly
Molly
@mollyim@fosstodon.org replied  ·  activity timestamp last week

@lexinova Thanks! We didn’t realize GitHub uses Fastly, and since we host molly.im there, that's shown in BGP. But DNSSEC/RPKI is not something we can enable ourselves.

Your point about mirrors is valid. We'll explore hosting and mirror alternatives.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct