2017
- Positive Trust Indicators and SSL
\[Full disclosure I work at Google, I do not speak for the Chrome team, and more generically am not speaking for my employer in this or any of my posts here\]
- Let's talk about revocation checking, let's talk about you and me.
I have been having a conversation with Melhi at Comodo, this is the most recent post in that series.
- My response, to his response, to my response? or short-lived certificates part 3
The conversation on short-lived certificates and their value continues. In the most recent conversation, we have started to shift from an either or position to one where we explore what is needed to make revocation…
- It is my turn, or short-lived certificates part 2
My response to a recent post suggesting short-lived certificates were intended to remove the need to do revocation seems to have spurred a response from its author.
- How to keep a secret in Windows
Protecting cryptographic keys is always a balancing act. For the keys to be useful they need to be readily accessible, recoverable and their use needs to be sufficiently performant so their use does not slow your…
- Why bother with short-lived certificates and keys in TLS?
There seems to be a lot of confusion and misinformation about the idea of short-lived certificates and keys so I thought I would pen some thoughts about the topic in the hope of providing some clarification.
- Revocation reasons don’t make sense for the WebPKI of today
As the old saying goes, to err is human but to forgive is divine, in WebPKI you deal with errors through the concept of revocation.
- Secondary effects when encrypting the web
Effects are often classified as having primary and secondary impacts. As we evolve the Internet we can see numerous examples of secondary effects, this is especially true as we look at how we evolve the way we secure it.
- Digital Signatures and the fallacy of Good, Cheap and Fast.
It is common to hear you can choose two of the following, “Good”, “Cheap” or “Fast”. While there is clearly some truth to this, it is not an absolute truth.
- CAs and SSL and Phishing Oh My!
NOTE: This post reflects my personal beliefs and is not necessarily those of my employer Google, or Let’s Encrypt where I am a member of their Technical Advisory Board.
- How do you show someone they are important to you?
Showing someone they are important to you is not always straightforward. Hackers, on the other hand, seem to have figured this out.
- Do PDFs have to be so frustrating?
Did you know PDF format is almost as old as the internet itself? Despite its age, it is still the only true cross-platform “paper like” experience available on the web. Unfortunately, it is also one of the most…