Posts

Showing posts from December, 2025

RFC 08032022

 ***** RFC08032022 ***** The TLS 1.3 is not always correctly implemented on the DNS Public Key Infrastructure (PKI). We can replace it by the state-of-the-art Wireguard. There are several aspects to consider in the DNS: 1. The concentration of risk in a PKI 2. The generation of domain names certificates 3. The storage of domain names certificates 4. The access to domain names certificates 5. The DNS requests and answers 6. The access to the Web ressources 7. The DNS servers information 1.The DNS PKI has several levels and concentrates risk on very few root Certification Authorities (CAs). Also, it is said that some root certificates private keys have leaked. We shall use only one level to reduce risk. Indeed, absolute root CAs shall be seen as the top of the DNS PKI pyramid. https://cpl.thalesgroup.com/faq/public-key-infrastructure-pki/what-certification-authority-or-root-private-key-theft Also, it appears clearly that websites providing information about compromising electromagnet...

RFC 06222022

***** RFC06222022 ***** A clean internet is necessary. Physical, data link and network layers are good but we can do better. Let's use real-world language and concepts.   Light caballeros model:   Physical layer:   To be tested several days (more in case of attacks), remove or circumvent any suspicious equipment in the middle. MAC layer:   Ok if MAC randomization is implemented. A new MAC address shall be generated at each connection between two collaborative nodes. No voice call shall be used when checking the attributed MAC addresses, use telegram secret chat or communication on end-to-end tunnel.   IP layer:   Ok if encryption and circumvention of zombies are implemented.   DNS Layer:   https://cpl.thalesgroup.com/faq/public-key-infrastructure-pki/what-certification-authority-or-root-private-key-theft https://security.stackexchange.com/questions/87564/how-does-ssl-tls-pki-work https://mantellapical.blogspot.com/2025/12/rfc-08032022.html https:/...