Re: [mfv] publish your web server content securely

Stefan Claas <[email protected]> Tue, 9 Dec 2025 19:52:34 +0100
Newsgroups alt.privacy.anon-server,alt.anonymous,alt.cypherpunks
Organization To protect and to server
Message-ID <[email protected]>
Gabx wrote:
> On Tue, 9 Dec 2025 16:54:18  0100, Stefan Claas <[email protected]> wrote:
> 
> > Stefan Claas wrote:
> > > 
> > > Hi all,
> > > 
> > > in case you run a web server in the clearnet, you may like
> > > to secure your content in a way so that third parties have
> > > a hard time to tamper with your web content.
> > > 
> > > https://github.com/Ch1ffr3punk/mfv
> > 
> > v0.4.0 with --domain parameter added for mfv and strict
> > checking for mfvc added.
> 
> Just deployed mfv on my Hugo blog running as Tor hidden service. 
> Works great.

Cool! :-)

> One note: the DNS TXT record (_merkle.domain IN TXT "merkle-root=...")
> doesn't apply to .onion addresses since there's no DNS involved - 
> Tor uses its own naming system. But the dns.txt file in .well-known/mfv/ 
> still works as a static reference for verification.

Yes, I am aware of that.

> The --domain binding is actually more valuable for .onion sites than 
> clearnet: it cryptographically ties the Merkle root to a specific 
> hidden service address, preventing someone from copying your content 
> to a different .onion and claiming it as theirs.

Before that one had to put in his html code the domain etc. as comment
and I thought how can this be done without doing so, when one has already
lots of html on his server published, hence the domain binding. :-)
> 
> For anonymous publishing with provable authorship, this is exactly 
> what was missing. You can prove "I published this first" without 
> revealing who "I" actually is.

Yes. ;-)

> Thanks for the tool.

You're welcome!

Best regards
Stefan

-- 
https://oc2mx.net