2022
- To err is human, to forgive is divine
Every service should strive to provide perfect availability, the reality is that it's not possible to be perfect. Mistakes happen, it’s how you deal with them that is important.
- A Boy Scout is always prepared
My father always says it's not a problem to make a mistake, what is important is how you deal with it.
- Baseline requirements are just that a baseline
I’ll start by saying this post is just a collection of personal thoughts and not a statement from my employer, nor does it reflect anyone’s opinions other than my own.
- TOFU and the Web
I’ll start by saying this post is just a collection of personal thoughts and not a statement from my employer, nor does it reflect anyone's opinions other than my own.
- Top #5 CAs by issuance volume as of 09/19/22
As Google Trust Services has been available for a few weeks I thought it would be interesting to look at where it stands relative to other CAs based on its issuance volume.
- Why hasn’t SHAKEN/STIR made a big dent in the volume of robocalls?
If you live in the United States you surely get a ton of
- User-managed smart cards are an oxymoron
In an earlier post, I talked about what it is like to get an EV Code Signing Certificate in 2022 but what I didn’t talk about in that post was token management.
- Getting an EV Code Signing Certificate in 2022
The first thing you will need to do is to find a Windows machine, that is because it is only possible to enroll for an EV Code Signing certificate on Windows. The only browser that provides a way to enroll for a…
- How to keep bad actors out in open ecosystems
There is a class of problems in information security that are intractable. This is often because they have conflicting non-negotiable requirements.
- What would it look like to go back to first principles when it comes to root store management in 2022?
In the early 2000s, Microsoft mandated that all CAs in its root program would need to be audited for conformity to WebTrust For CAs (WebTrust), It was the first root program to do so and I was the root program manager…
- WebPKI, TLS, cross-signs, device compatibility, and TLS record size.
Both the Chrome and Mozilla root program have signaled the intent to substantially shorten the time we rely on roots in the WebPKI. I believe this to be a good objective but I am struggling to get my head around the…
- Why crawling is not an adequate measurement methodology for the WebPKI
The answer is simple -- It's an incomplete view of the use of the WebPKI.
- How to measure the WebPKI ecosystem
The web is dependent on there being a robust, secure, and scalable set of CAs being able to provide TLS certificates. It is unhealthy for there to be a single provider because if for any reason they have an operational…