August 2022
- Why hasn’t SHAKEN/STIR made a big dent in the volume of robocalls?
If you live in the United States you surely get a ton of
- User-managed smart cards are an oxymoron
In an earlier post, I talked about what it is like to get an EV Code Signing Certificate in 2022 but what I didn’t talk about in that post was token management.
- Getting an EV Code Signing Certificate in 2022
The first thing you will need to do is to find a Windows machine, that is because it is only possible to enroll for an EV Code Signing certificate on Windows. The only browser that provides a way to enroll for a…
- How to keep bad actors out in open ecosystems
There is a class of problems in information security that are intractable. This is often because they have conflicting non-negotiable requirements.
- What would it look like to go back to first principles when it comes to root store management in 2022?
In the early 2000s, Microsoft mandated that all CAs in its root program would need to be audited for conformity to WebTrust For CAs (WebTrust), It was the first root program to do so and I was the root program manager…
- WebPKI, TLS, cross-signs, device compatibility, and TLS record size.
Both the Chrome and Mozilla root program have signaled the intent to substantially shorten the time we rely on roots in the WebPKI. I believe this to be a good objective but I am struggling to get my head around the…
- Why crawling is not an adequate measurement methodology for the WebPKI
The answer is simple -- It's an incomplete view of the use of the WebPKI.