this post was submitted on 27 Aug 2026
48 points (98.0% liked)

Selfhosted

62167 readers
358 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

2.5 years ago, I migrated all my services hosted on a cloud provider to a homeserver.

This homeserver is also my workstation/gaming/dev/everything. I use QubesOS (an operating system based on the Xen hypervisor), and wrote some document about it: https://neowutran.ovh/qubes/articles/homeserver.pdf

Basically, I am hosting:

  • DNS
  • Matrix
  • Email
  • Jitsi
  • Mumble
  • Peertube
  • Screego
  • Nextcloud
  • Searxng
  • Tor
  • Wireguard VPN
  • Copy of wikipedia
  • Personal website And others.

And for TLS, to have better security, and to avoid relying on third party company/providers, I am using DANE.

https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities

https://sr.ht/~yukikoo/dane_without_root/

https://github.com/buffrr/letsdane

The "dane_without_root" is one of my projects and I am welcoming review / feedback on it

( I also posted about it on the QubesOS forum: https://forum.qubes-os.org/t/highlighting-neowutrans-technical-doc-about-qubes )

top 23 comments
sorted by: hot top controversial new old
[–] stratself 9 points 3 weeks ago (1 children)

Hi, the sourcehut seems to be pretty interesting. If I understand it correctly, this DANE-without-root provides a TOFU model as an alternative to the normal case of verifying up all the parts of the domain levels, right? If feasible, maybe that could be nice to extend with other methods for OOB verification and key rollover

[–] neowutran@feddit.org 3 points 3 weeks ago

If I understand it correctly, this DANE-without-root provides a TOFU model as an alternative to the normal case of verifying up all the parts of the domain levels, right?

Indeed. (This part is not in any RFC or DANE standard, it is my idea to improve the system further). If you want to check the current implementation, you can search for ‘tofu’ string in this file: https://git.sr.ht/~yukikoo/dane_without_root/tree/master/item/src/core/dane.rs

and key rollover

This is a case that I didn’t cover, good idea. Probably something like ‘if successfully validated with tofu, then add all the valid dnskey to the valid tofu key list and remove the old ones’. It would still be problematic if a user doesn’t connect for a very long time to a website with tofu support and miss the key rollover, but that still a good improvement over the current tofu implementation. Will do that later.

maybe that could be nice to extend with other methods for OOB verification

Something more specific in mind?

[–] irmadlad@lemmy.world 7 points 3 weeks ago (1 children)

I tried QubesOS back in the day. How has it progressed as a desktop. I was always underwhelmed visually. It just seemed rather chunky. Maybe that is intentional.

Of course, if you are going for security, that's great, but it seemed to me that security and a visually appealing desktop could be blended.

[–] neowutran@feddit.org 6 points 3 weeks ago

I haven't know that time. It is indeed now way less chunky than your screenshot. By default it use XFCE, but support also KDE, i3 and other. Before starting to use QubesOS I was on arch with i3, and I kept using i3 on QubesOS

[–] greyscale@lemmy.grey.ooo 4 points 3 weeks ago (1 children)

SSL/TLS error on main link.

[–] neowutran@feddit.org 8 points 3 weeks ago (1 children)

Yes, this part is intentional to raise questions and remark :)

The certificate on my website is not valid using the WebPKI standard, but is valid using the DANE standard. It is related to my comment for this project https://sr.ht/~yukikoo/dane_without_root/ .

My issue with the WebPKI model is that any government or big company on the planet could do a MITM on your connection, generate a certificate valid for any website, and get a read/write access to all your webpki TLS communications. The DANE model is an improvement over webpki because instead of the "anyone (every ca / intermediate certificate) can generate a certificate valid for anyone" model, it bring a hierarchical trust structure.

[–] greyscale@lemmy.grey.ooo 3 points 3 weeks ago (2 children)

You missed my point

It doesn't work for the user, so it doesn't work.

Its about equivalent to the user as installing your own cert.

[–] moonshine69@lemmy.nz 2 points 3 weeks ago (1 children)

DANE provides user friction..but as OP mentioned TLS doesn't work

[–] greyscale@lemmy.grey.ooo 0 points 2 weeks ago (1 children)

Which means I don't care because nobody except myself will be able to use it.

I'd care a lot if Firefox and Chrome supported it OOTB

[–] hirihit640@sh.itjust.works 1 points 2 weeks ago (2 children)

It works fine, just ignore the warning and don't enter any sensitive info

[–] WhyJiffie@sh.itjust.works 1 points 2 weeks ago

then why use DANE. this is just plain old TOFU

[–] greyscale@lemmy.grey.ooo 0 points 2 weeks ago (1 children)

Ah yes, the windows method "just click okay and don't read it or think too hard"

[–] hirihit640@sh.itjust.works 2 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

If you're just pushing for WebPKI without "thinking too hard" about perpretrating a security system with a large number of failure points, then you're following that windows method.

SSL/TLS have very specific benefits. None of which matter that much for reading random articles on the web. So I don't see the problem with this website doing their own thing to bring attention to the potential issues of the current system.

[–] WhyJiffie@sh.itjust.works 1 points 2 weeks ago (1 children)

SSL/TLS have very specific benefits. None of which matter that much for reading random articles on the web.

it is a huge benefit if a man in the middle cannot run scripts on your computer.

So I don't see the problem with this website doing their own thing to bring attention to the potential issues of the current system.

there is no problem with that. this could work, with the required patch to firefox, also in the repo.

[–] hirihit640@sh.itjust.works 1 points 2 weeks ago (1 children)

IMO when reading random articles on the internet you already have to worry about untrusted scripts. I just use NoScript, and if the website requires Javascript I move on

[–] WhyJiffie@sh.itjust.works 1 points 2 weeks ago (1 children)

I don't agree, I think there is a difference in likely outcomes. but even without scripts, you don't want you article's content (text, images, statements or names) be falsified by an attacker. Unless you are just reading the article to waste time, and magically what you read will not influence your views.

[–] hirihit640@sh.itjust.works 1 points 2 weeks ago (1 children)

I already considered that, and for an untrusted website I already don't trust the content or the scripts. So it doesn't matter if it was modified or not, it's still untrusted.

Facts can be verified with sources you do trust (which should be using HTTPS). Logic can be used to verify others.

[–] WhyJiffie@sh.itjust.works 1 points 2 weeks ago (1 children)

I already considered that, and for an untrusted website I already don't trust the content or the scripts. So it doesn't matter if it was modified or not, it's still untrusted.

but then why are you reading it? is it cat photos and cooking recipes only? or does it have articles about pricey things you could buy, news, life improvement tips, car and other thing repair docs/advice?

[–] hirihit640@sh.itjust.works 1 points 2 weeks ago

A lot of times its tech opinion articles. Stuff like "why AI is bad". And I read the arguments and judge them for myself.

[–] WhyJiffie@sh.itjust.works 1 points 2 weeks ago

the repo readme writes about this. Firefox does not yet support DANE, it needs a patch, included in the repo.

[–] WhyJiffie@sh.itjust.works 2 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

you are probably aware, but with DNS you are still dependent on a third party, namely the whims of the united states. check what happened with autistici.org recently

[–] neowutran@feddit.org 2 points 2 weeks ago (1 children)

Ultimatly, there are still some dependencies on third party, but I reduced them to the minimum (If you know / have idea on how to remove even more third party, please tell). And about, autistici.org, the united states were able to do that because they own the ".org" tld. My tld is ".ovh", so under the control of OVH and french state.

[–] WhyJiffie@sh.itjust.works 1 points 2 weeks ago

I remember reading about some kind of an alternate DNS root servers. they have some unique TLDs (sounds risky though, the possibility of future name clashes). not too popular, but it is being used. I think this is it: https://opennic.org/

but there are more: https://icannwiki.org/Alternative_Roots

though, it will not salvage the .org TLD. such a shame it got to that...