2023
- Effortless Certificate Lifecycle Management for S/MIME
In September 2023, the SMIME Baseline Requirements (BRs) officially became a requirement for Certificate Authorities (CAs) issuing S/MIME certificates (for more details, visit CA/Browser Forum S/MIME BRs).
- The Rise of Key Transparency and Its Potential Future in Email Security
Key Transparency has slowly become a crucial part of providing truly secure end-to-end encrypted messaging. Don't believe me? The two largest providers of messaging services, Apple and Facebook (along with their WhatsApp…
- Raising the Bar: The Urgent Need for Enhanced Firmware Security and Transparency
Firmware forms the foundation of all our security investments. Unfortunately, firmware source code is rarely available to the public and as a result is one of the least understood (and least secure) classes of software…
- Words matter in cryptography or at least they used to
I was listening to Security Cryptography Whatever today, and they were discussing a topic that has been bothering me for a while.
- Document Authenticity in the Age of Generative AI
In our rapidly evolving lives, the credibility of documents, images, and videos online has emerged as a concern. The pandemic and recent elections have helped highlight this issue. In the case of elections, one area that…
- The Scale of Consequence: Storm-0558 vs DigiNotar
When we look at the Storm-0558 and DigiNotar incidents side by side, we find striking similarities in their repercussions and severity. Both cases involve significant breaches orchestrated by nation-states - China and…
- The Evolution and Limitations of Hardware Security Modules
Hardware Security Modules (HSMs) have not substantially evolved in the last two decades. The advent of enclave technology, such as Intel SGX, TDX and AMD SEV, despite their weaknesses…
- Towards Greater Accountability: A Proposal for CA Issuance Decision Logs
It took us a long time, but objectively, Certificate Transparency is a success. We had to make numerous technology tradeoffs to make it something that the CAs would adopt, some of which introduced problems that took even…
- Exploring the Potential of Domain Control Notaries for MPDV in WebPKI
In an earlier post on the Role of Multiple Perspective Domain Control Validation (MPDV) in the WebPKI, I discussed how there was an opportunity for CAs to work together to reduce the cost of meeting the upcoming…
- Strengthening Domain Control Verification: The Role of Multiple Perspectives and Collaboration
The security and stability of encryption on the web rely on robust domain control verification. Certificate Authorities in the WebPKI are increasingly facing attacks that exploit weaknesses in the Border Gateway Protocol…
- Key Management and preparing for the Crypto Apocalypse
Today, keeping sensitive information secure is more critical than ever. Although I'm not overly concerned about the looming threat of quantum computers breaking cryptography, I do worry about our approach to key…
- The Growing Security Concerns of Modern Firmware and the Need for Change.
Today's firmware is larger and more complex than ever before. In 1981, the IBM PC BIOS was a mere 8 KB, but now UEFI, even without considering machines with BMCs, can be 32 MB or even larger! To illustrate the magnitude…
- Global Trend in Tech Regulation and its Consequences for the EU and the US
The United States has long been a leader in technological innovation, with companies such as Google, Apple, Facebook, and Amazon paving the way. As of October 2021, 62% of global tech unicorns have emerged from the US,…
- The Importance of Proper Measurement in Enterprise IT Management: Lessons from Cloud Deployments
Peter Drucker once said, "You cannot manage what you cannot measure." This quote is applicable in many aspects of technology development and business management. Neglecting measurement often leads to problems. Another…
- The Changing Landscape of Internet Protection
The United States government and big companies like Google have both played a significant role as protectors in their respective spheres. The US government, as the world's leading military power, has tried to serve as a…
- The Limitations of Audits: What You Need to Know
In recent years, the SOC2 and ISO 27001 badges have become a staple at the bottom of nearly every SaaS website. This is largely due to the growing number of startups providing solutions for SOC2 and ISO 27001 audits,…
- Using Caddy with Google Trust Services
Caddy is a powerful and easy-to-use web server that can be configured to use a variety of certificate authorities (CA) to issue SSL/TLS certificates. One popular CA is Google Trust Services, which offers an ACME endpoint…