It's good to know we'll get notified if any CA is compromised and/or mis-issues a certificate, but also funding @agwa.name's work benefits all the WebPKI.
It's good to know we'll get notified if any CA is compromised and/or mis-issues a certificate, but also funding @agwa.name's work benefits all the WebPKI.
- Certificate revocation lists
- webpki roots without a rustls provider
- No more caching of system proxy settings
- and more 🚀
github.com/seanmonstar/...
- Certificate revocation lists
- webpki roots without a rustls provider
- No more caching of system proxy settings
- and more 🚀
github.com/seanmonstar/...
WebPKI certs don't say 'this is Alice', they say 'this is the process we used to verify the subject's claim to be Alice'.
Very critical distinction.
WebPKI certs don't say 'this is Alice', they say 'this is the process we used to verify the subject's claim to be Alice'.
Very critical distinction.
There is so much more to it now: Certificate Transparency, shorter lifespans, audits, enforcement, CRLite...
There is so much more to it now: Certificate Transparency, shorter lifespans, audits, enforcement, CRLite...
Matthew McPherrin recently shared Mozilla's Firefox telemetry data showing actual CA usage vs the Certificate Transparency issuance numbers I usually track.
👇
Matthew McPherrin recently shared Mozilla's Firefox telemetry data showing actual CA usage vs the Certificate Transparency issuance numbers I usually track.
👇
DigiCertは、Sectigoの最高コンプライアンス責任者であるティム・キャランがBugzillaのディスカッションで発言した内容に対して法的措置を取ると脅迫しています。Sectigoの法務担当者であるブライアン・ホランドは、このような脅迫がWebPKIコミュニティの自己規制と改善に不可欠なオープンな議論を損なうと主張しています。ホランドは、キャランの発言は第一修正によって保護されており、業界の議論にとって重要であると述べています。また、DigiCertの行動が批判者を威圧し、WebPKIの信頼性を損なう可能性があることを懸念しています。この状況は、 (1/2)
DigiCertは、Sectigoの最高コンプライアンス責任者であるティム・キャランがBugzillaのディスカッションで発言した内容に対して法的措置を取ると脅迫しています。Sectigoの法務担当者であるブライアン・ホランドは、このような脅迫がWebPKIコミュニティの自己規制と改善に不可欠なオープンな議論を損なうと主張しています。ホランドは、キャランの発言は第一修正によって保護されており、業界の議論にとって重要であると述べています。また、DigiCertの行動が批判者を威圧し、WebPKIの信頼性を損なう可能性があることを懸念しています。この状況は、 (1/2)
But if they load up the keys for any WebPKI cert, I will assume they are blackhats and they can expect to be spending a long time talking to feds and explaining to management why a $10million machine was seized.
But if they load up the keys for any WebPKI cert, I will assume they are blackhats and they can expect to be spending a long time talking to feds and explaining to management why a $10million machine was seized.
https://www.heise.de/news/Passwort-Folge-33-News-mit-extra-viel-WebPKI-Cybercrime-und-Onion-URLs-10419242.html?utm_source=flipboard&utm_medium=activitypub
Gepostet in c't | das Magazin für Computertechnik […]
https://www.heise.de/news/Passwort-Folge-33-News-mit-extra-viel-WebPKI-Cybercrime-und-Onion-URLs-10419242.html?utm_source=flipboard&utm_medium=activitypub
Gepostet in c't | das Magazin für Computertechnik […]
A clubcard is a membership test for an r element subset of an n element set. Size is ~1.13 log(n choose r) bits. Or (better!) ~1.13 Σ log(n_i choose r_i) where i indexes blocks of a partition.
A clubcard is a membership test for an r element subset of an n element set. Size is ~1.13 log(n choose r) bits. Or (better!) ~1.13 Σ log(n_i choose r_i) where i indexes blocks of a partition.
The WebPKI was designed to establish accountability, now all it does is verify domain names.
The WebPKI was designed to establish accountability, now all it does is verify domain names.
まずはそれぞれの脅威モデルとその対抗を分けた上で何が残るかという話をしないと始まらない
qiita.com/uturned0/ite...
まずはそれぞれの脅威モデルとその対抗を分けた上で何が残るかという話をしないと始まらない
qiita.com/uturned0/ite...
OCSP (stapling, must-staple, the never-adopted expect-staple, discontinuation from BoringSSL and Let's Encrypt)
CRLs, CRLite, and CRLSets.
Short-lived certs (ACME-STAR, Delegated Credentials, and notAfter)
Anything else I should cover?
#WebPKI #TLS
yes, exactly. to steal phrasing from @zmanian.bsky.social :
> Crypto means Ralph Merkle, Whit Diffie and David Chaum. Crypto means cryptocurrency. The "crypto means webpki" people got lost on a side quest.
yes, exactly. to steal phrasing from @zmanian.bsky.social :
> Crypto means Ralph Merkle, Whit Diffie and David Chaum. Crypto means cryptocurrency. The "crypto means webpki" people got lost on a side quest.
With BGP hijacks happening regularly, those certs could enable full man-in-the-middle attacks.
👇
With BGP hijacks happening regularly, those certs could enable full man-in-the-middle attacks.
👇