| Pretraživanje | Osvježi |
|
J.C., keeper of MiniSquish 🦊
@ciphercoffee
|
18. kol 2017. |
|
CRLs are still used by the Web PKI. It appears some CAs don't think they need to keep them online... tacticalsecret.com/the-state-of-c… #webpki pic.twitter.com/pnXtnJJs9B
|
||
|
||
|
Corey Bonnell
@GarbageTimeHero
|
12. lis |
|
The proper way to read the BRs is to interpret them with a full understanding of the history and intent of each requirement. Also, the proper way to read the BRs is to interpret them exactly as written without any regard for the intent and history of each requirement. #webpki
|
||
|
|
||
|
J.C., keeper of MiniSquish 🦊
@ciphercoffee
|
15. kol 2016. |
|
Again proving live OCSP #revocation in the #WebPKI is a nightmare (Upstream OCSP cache is stale. Seems OK elsewhere) pic.twitter.com/zwsuwEJ1M8
|
||
|
||
|
J.C., keeper of MiniSquish 🦊
@ciphercoffee
|
12. srp 2017. |
|
63,082,038 valid certs known to @CensysIO; 33,619,372 active @LetsEncrypt certs. Follows that 53% of certs in #WebPKI today are from LE.
|
||
|
|
||
|
Jaroslav Imrich
@jimrichsk
|
12. srp 2018. |
|
I had a blast on vacation with this wonderful book written by @ivanristic and published by @feistyduck. I'm currently only in the half but already cannot recommend it enough. It's a MUST-READ for anyone interested in #PKI #WebPKI #TLS #SSL or #infosec. pic.twitter.com/weffuEeqcF
|
||
|
||
|
J.C., keeper of MiniSquish 🦊
@ciphercoffee
|
5. tra 2016. |
|
Math updated: 90.4% of Registered Domains (eTLD+1) using @letsencrypt are new to the #WebPKI tacticalsecret.com/124-days-of-le… pic.twitter.com/q4lIxB5fx3
|
||
|
||
|
Ryan Hurst
@rmhrisk
|
26. ruj 2016. |
|
Mozilla has decided how to respond to WoSign and StartCom miss-issuance - docs.google.com/document/d/1C6… #ssl #webpki
|
||
|
|
||
|
Ryan Hurst
@rmhrisk
|
20. ruj 2018. |
|
Do you find cryptography and PKI interesting? Do you want to help secure and operate Google's publicly trusted CAs? Are you in Pittsburgh or New York? DM me. #WebPKI
|
||
|
|
||
|
J.C., keeper of MiniSquish 🦊
@ciphercoffee
|
9. sij |
|
Can one shrink the #WebPKI's certificate state to be as small as a photo? Mozilla Security Engineering is publishing a series of blog posts about #CRLite, a technology to compress and push revocations to @firefox users, now in @FirefoxNightly blog.mozilla.org/security/2020/… pic.twitter.com/Sz8wpj4o2H
|
||
|
||
|
J.C., keeper of MiniSquish 🦊
@ciphercoffee
|
1. stu |
|
We're about to start an experiment with the new IETF draft for Delegated Credentials in #TLS in @FirefoxNightly together with @Cloudflare, giving another path to short-lived certs on the #WebPKI @ThylaVdMerwe blog.mozilla.org/security/2019/…
|
||
|
|
||
|
J.C., keeper of MiniSquish 🦊
@ciphercoffee
|
8. kol |
|
Think that crypto means #WebPKI, #WebAuthn, #TLS13? So do we. Join our team! twitter.com/ThylaVdMerwe/s…
|
||
|
|
||
|
Ryan Hurst
@rmhrisk
|
2. lis 2018. |
|
Some things just never change hecker.org/mozilla/busine… #2004 #webpki
|
||
|
|
||
|
Ryan Hurst
@rmhrisk
|
3. velj 2017. |
|
|
||
|
|
||
|
Jaroslav Imrich
@jimrichsk
|
25. stu |
|
Domain validation support will be integrated into CT logs and CAs will no longer be needed for #webpki. CT logs already serve as root of trust anyway. twitter.com/FiloSottile/st…
|
||
|
|
||
|
Ryan Hurst
@rmhrisk
|
6. kol |
|
Looks like there is a new root CA in the Microsoft Root store, based in South Africa, TrustFactory - docs.microsoft.com/en-us/security… #webpki
|
||
|
|
||
|
Ryan Hurst
@rmhrisk
|
15. ruj 2018. |
|
|
||
|
Ryan Hurst
@rmhrisk
|
8. svi |
|
"I believe that the issues I have documented demonstrate a basic inability to operate effective issuance controls. " - groups.google.com/forum/?pli=1#!… #webpki #notagain
|
||
|
|
||
|
Jeff Hodges / =JeffH
@equalsJeffH
|
20. stu 2017. |
|
Ensuring Web PKI Integrity (EWPI) meetup Summary Report is available: docs.google.com/document/d/e/2… @PayPalInfoSec @letsencrypt #EWPI #WebPKI #TLS
|
||
|
|
||
|
ftobloke
@ftobloke
|
24. velj 2017. |
|
Again, the condescending, bullshit, "holier than thou" approach continues... cabforum.org/pipermail/publ… no wonder the #webpki is in a mess
|
||
|
|
||
|
CA Security Council
@CertCouncil
|
5. ruj 2017. |
|
Blog post: #QuantumComputing: Real or Exaggerated Threat to the #WebPKI? casecurity.org/2017/08/30/qua…
|
||
|
|
||