implement a kill switch in case a version goes bad

Bas Rieter repo owner created an issue

If, for some reason, there is a very bad bug introduced, we don't want syncs to proceed until a new version is installed.

Perhaps we can use a TXT DNS record to specify broken versions? So they won't sync anymore?

