June 2024
- Understanding Patterns in WebPKI CA Issues
There's a saying, "where there's smoke, there's fire." This adage holds especially true in the context of WebPKI Certificate Authorities (CAs). Patterns of issues are one of the key tools that root programs use to…
- Exploring Browser Distrust
Browser distrust events of WebPKI Certificate Authorities occur on average approximately every 1.23 years. These events highlight the critical role the WebPKI plays in maintaining secure communications on the internet…
- Navigating Public Reporting Obligations in WebPKI and Beyond
Incident response is notoriously challenging, and with the rise in public reporting obligations, the stakes have never been higher. In the WebPKI world, mishandling incidents can severely damage a company’s reputation…
- Why We Trust WebPKI Root Certificate Authorities
I've always likened the WebPKI governance system to our legal system, where congress sets the laws and the judiciary ensures compliance. Justice Breyer's recent explanation on "rules" and "standards" in law, as discussed…
- Balancing Innovation and Privacy: The Risk of Government Surveillance in the Age of AI
Imagine a world where every conversation, every movement, and every interaction is tracked in real-time by unseen eyes. This isn't the plot of a dystopian novel—it's a very real possibility enabled by today's rapid…
- Speeding Up Development and Navigating Security Risks
In software development, time is often of the essence. Developers are constantly pushed to deliver faster and more efficiently. Tools like GitHub Copilot have emerged, promising to accelerate coding tasks significantly.…
- Groundhog Day: Learning from Past Key and Credential Compromises
As they say, Those who cannot remember the past are condemned to repeat it, as we look back at the last decade, it seems we are caught in our own little Groundhog Day, reexperiencing the consequences of weak…
- Integrating Security: Making Safe Software Development Seamless and Productive
As software progresses from the developer’s machine to staging and finally to production, it undergoes significant changes. Each environment presents unique challenges, and transitions between these stages often…
- From Static to Dynamic: Adapting PKI for Cloud-Native Architectures
When it comes to workload and service credential management, a common misconception is that you can simply reuse your existing Certificate Authority (CA) and Certificate Lifecycle Management (CLM) infrastructure to…
- Credential Management vs. Secret Management: Choosing the Right Approach
If we examine the contents of most secret management solutions, like HashiCorp Vault, we will find that we primarily store the logical equivalent of user IDs and passwords for services, workloads, and machines. Much like…
- ACME vs. SPIFFE: Choosing the Right One
In the world of certificate lifecycle management for workloads, two approaches often come into focus: ACME (Automated Certificate Management Environment) and SPIFFE (Secure Production Identity Framework for Everyone).…