2024
- Safeguarding Internet Trust: From Reactive to Continuous
The internet rests on a foundation of core infrastructure components that make global communication possible. Among these load-bearing elements are DNS, DNSSEC, BGP, BGPsec, WebPKI, RPKI, transparency logs, IXPs,…
- Beyond Memorization: Preparing Kids to Thrive in a World of Endless Information
What does it take to prepare our children for a tomorrow where AI shapes how they get information, robots change traditional jobs, and careers transform faster than ever—a time when what they can memorize matters far…
- Technology bias—we all have it—but it often gets in the way.
An old saying goes, "When you’re a plumber, you fix everything with a wrench." It highlights a truth: we naturally gravitate toward the tools, people, and methods we know and trust most. This tendency stems from…
- Government CAs and the WebPKI: Trust is Often the Opposite of Security
Following my recent post about another CA failing the “Turing test” with a likely MITM certificate issuance, let’s examine a troubling pattern: the role of government-run and government-affiliated CAs in the WebPKI…
- Another CA Fails the Turing Test?
In a concerning development, yet another Certificate Authority (CA) has issued what is likely a man-in-the-middle (MITM) certificate—something strictly prohibited by all root programs. This particular case is unique…
- Proactive Security: Engineering Resilience from the Ground Up
Picture discovering your house has been robbed. Like many homeowners in this situation, your first instinct might be to invest in the latest security system with cameras and motion sensors. But what if the thief simply…
- From Years to Seconds: Rethinking Public Key Infrastructure
Public Key Infrastructure was designed for a world where identities persisted for years—employees joining a company, servers running in data centers, devices connecting to networks. In this world, the deliberate pace of…
- Bundling and Unbundling in the NHI Market: Opportunities in Identity, Governance, and Cryptography
Jim Barksdale famously said "All money is made through bundling and unbundling,” and this dynamic is evident in the Non-Human Identity (NHI) market. Cryptography management, privileged access management, and certificate…
- Rethinking Authentication: “Something You Have,” “Something You Know,” and “Something You Are” for Workloads and Machines
Passwords have existed for millennia, and their weaknesses have persisted just as long. Their simplicity led to widespread adoption, but as their use expanded, so did the frequency of their abuse. To address this, we…
- The Myth of Non-Technical Product Management
A common theme in conversations about product managers is the notion that they don’t need to be technical; they just need to bridge the gap between technical and non-technical teams. In my experience, particularly with…
- The Subtle Art of Getting Your Product Deployed
Getting a security product deployed isn't just about a signed contract—it’s about execution. The difference between shelfware and success often comes down to removing roadblocks before they become deal-breakers. What are…
- From Fairways to the Cloud: Estimating Golf Balls in Flight to Tackling Cloud Workload Scale
Early in my career, I worked in quality assurance at Microsoft, analytical skills were a core trait we tried to hire for, at the time “brain teasers” were often used in interviews to assess these skills. One memorable…
- Beyond the Facade: Evaluating Long-Term Impacts of Enterprise Software Architectures
Many enterprise products these days have a core architecture that consists of placing a proxy in front of an existing service. While the facade architecture makes sense in some cases, it's usually a temporary measure…
- When Words Mislead: Cybersecurity’s Terminology Problem
At Black Hat this year, I did my usual walk around the vendor floor. I talked to lots of companies about their products. One thing that stood out to me is vendors either by accident or on purpose are redefining terms in…
- The True Essence of Secure by Design
When we discuss "secure by design," we often focus on capabilities, features, and defaults—such as logging and monitoring, default-deny, regular updates, authentication, and minimizing by default privileges—rather than…
- CA Misissuance: A Tale of Two Incident Responses
Certificate Authorities on the web are tasked with validating that the websites we visit are truly associated with the domains that serve the content that makes up that website. As a result, we gain confidence that we…
- Exploring Requirements for Timelines Certificate Problem Reports and Revocations
Today, DigiCert's mass revocation is in the news, so I thought it would be worthwhile to explore the rules for a CA when it comes to revoking a subscriber certificate and the choices and constraints a CA faces in…
- HSMs Largely Protect Keys from Theft Rather Than Abuse
HSMs were designed to protect keys from theft and to move those keys into a different security domain than the code that uses those keys. The workloads using these HSMs use credentials or, worse, shared secrets that are…
- Turning Catastrophe into Opportunity: Improving Processes and Vendor Accountability
We often hear about customers not wanting to deploy agents, usually citing the rationale that while each one may only consume a bit of memory and CPU the sum of them slowly but surely grind systems to a halt. The real…
- Reading the Tea Leaves: What Led to the Largest IT Outage in History
Last night, on July 18, 2024, a significant IT outage disrupted businesses worldwide, affecting airlines, financial services, TV broadcasters, and more. Some have described this outage as potentially the “largest IT…
- Content is King in Phishing and the Role of Publicly Trusted CAs
Phishing attacks often begin with a seemingly simple email. These emails appear to be from trusted sources and include links to fake websites or messages that create a false sense of urgency, prompting users to act…
- Global Consistency for AKD: Using Armored Witness to Prevent Split Views
By Al Cutter and Ryan Hurst
- Timeless Farm Wisdom
My father grew up on a small farm in eastern Washington. They say you can take the boy out of the farm, but you can’t take the farm out of the boy. As a kid, I was always hearing farm life sayings from my grandfather and…
- Understanding Patterns in WebPKI CA Issues
There's a saying, "where there's smoke, there's fire." This adage holds especially true in the context of WebPKI Certificate Authorities (CAs). Patterns of issues are one of the key tools that root programs use to…
- Exploring Browser Distrust
Browser distrust events of WebPKI Certificate Authorities occur on average approximately every 1.23 years. These events highlight the critical role the WebPKI plays in maintaining secure communications on the internet…
- Navigating Public Reporting Obligations in WebPKI and Beyond
Incident response is notoriously challenging, and with the rise in public reporting obligations, the stakes have never been higher. In the WebPKI world, mishandling incidents can severely damage a company’s reputation…
- Why We Trust WebPKI Root Certificate Authorities
I've always likened the WebPKI governance system to our legal system, where congress sets the laws and the judiciary ensures compliance. Justice Breyer's recent explanation on "rules" and "standards" in law, as discussed…
- Balancing Innovation and Privacy: The Risk of Government Surveillance in the Age of AI
Imagine a world where every conversation, every movement, and every interaction is tracked in real-time by unseen eyes. This isn't the plot of a dystopian novel—it's a very real possibility enabled by today's rapid…
- Speeding Up Development and Navigating Security Risks
In software development, time is often of the essence. Developers are constantly pushed to deliver faster and more efficiently. Tools like GitHub Copilot have emerged, promising to accelerate coding tasks significantly.…
- Groundhog Day: Learning from Past Key and Credential Compromises
As they say, Those who cannot remember the past are condemned to repeat it, as we look back at the last decade, it seems we are caught in our own little Groundhog Day, reexperiencing the consequences of weak…
- Integrating Security: Making Safe Software Development Seamless and Productive
As software progresses from the developer’s machine to staging and finally to production, it undergoes significant changes. Each environment presents unique challenges, and transitions between these stages often…
- From Static to Dynamic: Adapting PKI for Cloud-Native Architectures
When it comes to workload and service credential management, a common misconception is that you can simply reuse your existing Certificate Authority (CA) and Certificate Lifecycle Management (CLM) infrastructure to…
- Credential Management vs. Secret Management: Choosing the Right Approach
If we examine the contents of most secret management solutions, like HashiCorp Vault, we will find that we primarily store the logical equivalent of user IDs and passwords for services, workloads, and machines. Much like…
- ACME vs. SPIFFE: Choosing the Right One
In the world of certificate lifecycle management for workloads, two approaches often come into focus: ACME (Automated Certificate Management Environment) and SPIFFE (Secure Production Identity Framework for Everyone).…
- Building Effective Roadmaps through Mission, Vision, and Strategy Alignment
Creating a cohesive and effective roadmap requires more than just a list of tasks and deadlines; it requires a clear mission, vision, and strategy that aligns the entire organization. This alignment ensures that every…
- Transitioning from Reactive to Proactive
Building Effective, Evidence-Based Roadmaps for Business Success
- Automating Non-Human Identities: The Future of Production Key Management
Historically, key management was seen as activities involving hardware security modules (HSMs), manual tasks, and audits. This approach was part of what we termed 'responsible key management.’ However, HSMs were…
- Rethinking Security in Complex Systems
Over the last few decades, we seem to have gotten better at the micro aspects of security, such as formally verifying protocols and designing cryptographic algorithms, but have worsened, or at least failed to keep up at…
- Navigating Security and Innovation
I started my career at Microsoft in the 90s, initially working on obscure third-party networking issues, printing, and later Internet Explorer. Back then, even though I had gotten into computers through what today would…
- The Rebirth of Network Access Protection with Microsoft's Zero Trust DNS
The other day Microsoft announced something it calls Zero Trust DNS. At a high level, it is leveraging clients' underlying name resolution capabilities to establish and enforce security controls below the application.
- How TLS Certificates Can Authenticate DNS TXT Records
Have you found a use case where you think DANE and DNSSEC might be helpful? For example, the discovery of some configuration associated with a domain? Since a practically useful DNSSEC deployment, which requires…
- Restoring Memories
As the old saying goes, "You can take the boy out of the farm, but you can't take the farm out of the boy." Although I was raised in metro Seattle, my father grew up on a farm in Eastern Washington, in the city of Walla…
- Navigating Content Authentication In the Age of Generative AI
In 1995, SSL was introduced, and it took 21 years for 40% of web traffic to become encrypted. This rate changed dramatically in 2016 with Let's Encrypt and the adoption of <a href="https://www.acmeisuptime.com/"…
- Tenement Farming and Cloud HSMs
While it's fair to say that using a Cloud HSM means your keys are protected by a device meeting FIPS 140-3 standards, assuming the HSM in use has this certification, it's important to realize this doesn't guarantee the…
- Evolving Challenges in Software Security
In 2023, we observed an average month-to-month increase in CVEs of approximately 1.64%, with this rate accelerating as the year progressed. At the same time, several trends emerged that are associated with this increase.…
- Echoes of the Past and Their Impact on Security Today
When I was a boy, my parents often made me read books they thought were important. One of these was "The Republic" by Plato, written around 380 BC. After reading each book, they'd ask me to talk about what I learned.…
- Challenges in Digital Content Authentication and the Persistent Battle Against Fakes
Efforts have been made for years to detect modified content by enabling content-creation devices, such as cameras, to digitally sign or watermark the content they produce. Significant efforts in this area include the…
- Gov ID: If at First You Don't Succeed, Try, Try Again
In the eIDAS 2.0 framework, the identity wallet is central to its expanded scope, mirroring early European government efforts at smart card-based national identity cards as well as subsequent identity wallet attempts.…
- Rethinking How We Assess Risk in the Software We Rely On
Despite today’s widespread use of open-source software, most software is still delivered in binary form. This includes everything from the foundational firmware of our computers to the applications we use for work,…