Ephemeral diffie-hellman is exactly that, it's part of TLS since I think 1.2
RheumatoidArthritis
At some point there was a browser extension to support DANE (and Perspectives and similar approaches against centralization) but since then, browser vendors fixed that security flaw.
No, but I have a link showing how ISPs and CAs colluded to do a MITM https://notes.valdikss.org.ru/jabber.ru-mitm/
Shorter cert lifespan would not prevent this.

Core77 in Fennec for you, with always-on Mullvad. I don't have regular Firefox installed.
Justeat and its local variations (liferando, pyszne) work just fine over VPN and can even be paid with gift cards
I access them with Cromite over VPN and on the computer with Ablaze Floorp (based on ff) but without VPN.
I have them in RSS and have no problem opening their links over Mullvad
Or just meet and maintain that friendship
Haha, server grade hardware. Impressive, actually, that it survived so many years. I have a similar one in my car and it's 10+ years old and works okay, but another one that's permanently sticked in my server with an emergency boot image died when it was needed the most.
I started with Navidrome, then looked at the disk space occupied by my library and it occured to me that 1TB MicroSD cards are a thing now, and I can listen to all my library offline.
If resource usage was low, it could also be an X11 problem solved by a wayland distro
Isn't this just melissa? A very common herb and sold as bagged tea in every grocery store around here.