BRB putting Rust crates into TXT records in my DNS.

Wait actually better a new record type: CODE pairs nicely with the HTTPS record type. Now we don't even need ANY server side execution the browser just looks up your service in DNS and executes it.

We can authenticate it with DKIM!

Let's add new DNS APIs so that code coming from CODE records can also mutate DNS records at their origin domain. This will a) fit in great with the kubernetes model, b) solve all storage concerns by offloading it to the least (best) suitable location for durable storage.

I wish DNSSEC hadn't been so thoroughly ruined on account of it solving too many problems compared to DoH which creates more problems while solving the same problems as DNSSEC.

Because like rly guys one of these solutions is an incremental improvement and the other is WHAT IF HTTP WAS THE ONLY THING.


Didn't cloudflare come up with DoH?

Follow

@amy not only did they come up with DoH, they also were the default and only initial provider. They just love gobbling up all your traffic regardless of what you do online.

@thufie good to have confirmation because I was pretty sure that was the case initially. Then google helpfully joined in so you can choose between two corporations built on spying to helpfully "protect" your DNS traffic.

@amy I made a very critical blog post around that time period on my old blog. Got a lot of heat from "self-hosting" guys who were CloudFlare customers.

Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.