A list of one’s own¶
The listing in Milan was somebody else’s list, drawn up to decide who could be cut off. This is the opposite list: the one Purple Lantern drew for itself, layer by layer, to find where it could be cut off and close the gaps it could. What follows gathers the whole exercise into boxes. A ticked box is a thing done and checked. An empty box is a thing known and not yet done, which is worth more than a thing neither known nor done. The empty boxes are the honest part, and a stack with none of them is usually a stack nobody has looked at hard enough.
The name¶
Name in a European namespace, everything moved under it, the old names no longer relied on
A replaceable European registrar, paid by transfer, with DNSSEC and a registry lock
Zone exportable and nameservers changeable without a support ticket
The DS record and the RFC 6781 move sequence kept offline, outside the registrar account
A European-made hardware key on the recovery chain, and a second one as backup
The mail¶
The address on the domain, with MX, SPF, DKIM and DMARC in the domain’s own zone
The mailbox at a European provider, replaceable by an MX change
An independent local archive of the mail, kept with the backups
A recovery route that does not pass through the mailbox it recovers
DMARC moved from
p=nonetop=quarantine, and then top=reject
The forge¶
Source at European forges, with complete local clones standing in for a mirror
Direct accounts, no OAuth, one SSH key per remote
Design notes and issues kept as Markdown in the repository, not in a platform
No build dependency on the forge: the checks run on the workstation
Deployment¶
A build reproducible on the workstation, the output committed where the build is local
Deployment replaceable without moving the source, the webhook a trigger and nothing more
TLS through standard ACME, so the host can be swapped
The escape route run once: files built, DNS ready, domain repointed, result checked from outside
Whether the host can use a certificate authority other than Let’s Encrypt, found out
Hosting¶
European ownership and hardware under the host, with no US cloud beneath it
No CDN and no reverse proxy in front of the origin
DNS independent of the host, kept at a separate company
An independent monitor watching from a different network
What the visitor pulls¶
No analytics, no embeds, no third-party JavaScript, with a
default-src 'self'policyFonts served from the site, the font provider’s cache committed to the repository
One form, to a European backend, on spam layers that need no US script
The money¶
A European bank account with SEPA, the card an extra route and not the only one
Suppliers paid by transfer where they take it, invoices kept independently and in euros
The bank’s own US dependencies mapped, and the open questions under the processor answered
The workstation¶
A locally controlled system with the administration tools present, on an encrypted disk
The password vault a local file, backed up, not behind a hosted identity
Independent backups, local and remote, encrypted, with the recovery written down
Package versions pinned and cached, so the environment can be rebuilt
Authentication¶
Direct accounts, each with a recovery address independent of the service it recovers
Recovery codes in the vault, kept out of every recovery loop
A hardware key in place of the US-owned authenticator app on every account that takes one
The supply chain¶
Dependencies pinned, lock files committed, the important inputs cached
Build tools documented per repository, and the sources of security news kept diverse
The one container image pinned by digest, not only by tag
The small print¶
For each provider: the contracting entity, jurisdiction, governing law, subprocessors and payment route known
The suspension and appeal path known for each, the recovery identity independent, a replacement identified
Granny Weatherwax does not hold with lists. Anything worth remembering, she says, has the decency to remember itself, and anything that does not was most likely put about by the other side.