{"id":974,"date":"2025-02-23T11:27:55","date_gmt":"2025-02-23T19:27:55","guid":{"rendered":"https:\/\/unmitigatedrisk.com\/?p=974"},"modified":"2025-02-23T11:53:38","modified_gmt":"2025-02-23T19:53:38","slug":"how-organizational-inertia-externalizes-risk-in-the-webpki","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=974","title":{"rendered":"How Organizational Inertia Externalizes Risk in the WebPKI"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I\u2019ve been involved in the Web PKI since the mid-\u201890s, when SSL certificates carried five- or ten-year lifetimes\u2014long-lasting credentials for an internet still a wild west. Issuance was manual, threats were sparse, and long validity fit that quieter era. Thirty years later, we\u2019ve fought our way to a 398-day maximum lifetime\u2014today\u2019s standard as of 2025\u2014thanks in part to Apple\u2019s bold 2020 move to enforce 398-day certificates in Safari, dragging resistant CAs into a shared ballot after years of clinging to the status quo. Yet some certificate authorities, certificate consumers, and industry holdouts still resist shorter lifetimes and tighter data reuse policies, offloading breaches, increased risk, and eroded trust onto users, businesses, and the web\u2019s backbone. This 15-year struggle got us to 398; now it\u2019s time to push past it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Core Argument<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The journey to shorter lifetimes spans decades. The TLS Baseline Requirements set a 60-month cap in 2010, but by 2014, internal debates among browsers and CAs ignited over whether such spans were safe as threats ballooned. Progress stalled\u2014pushback was fierce\u2014until Apple threw a wrench in the works. Announced earlier in 2020, effective September 2020, they declared Safari would reject certificates issued after August 31, 2020, with lifetimes exceeding 398 days, blindsiding CAs who\u2019d dug in their heels. Only after that jolt did the CA\/Browser Forum pass Ballot SC-42 in 2021, codifying 398 days as a shared requirement\u2014proof that CAs wouldn\u2019t budge without external force. Earlier, Ballot 185 in 2017 had proposed cutting lifetimes to 27 months, Ballot SC-22 in 2019 explored short-lived certificates, and <a href=\"https:\/\/groups.google.com\/a\/groups.cabforum.org\/g\/servercert-wg\/c\/a6A2Wmu0gUw\/m\/4OadKg-sAAAJ\">Ballot SC-081<\/a> in 2025 is expected to reaffirm 398 days as the maximum, with a long-term target of 45\u201347 days by 2029 (SC-081v2). That\u2019s 15 years of incremental progress, built on 30 years of evolution\u2014Last time Apple\u2019s push broke CA inertia enough to land us at 398, and I am confident without that action we would not be where we are yet. Yet risks like \u201c<a href=\"https:\/\/insecure.design\/\">Bygone SSL<\/a>\u201d linger: valid certificates staying with old domain owners after a sale, opening doors to impersonation or chaos.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-21.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"341\" src=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-21-1024x341.png\" alt=\"\" class=\"wp-image-980\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-21-1024x341.png 1024w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-21-300x100.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-21-768x256.png 768w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-21-624x208.png 624w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-21.png 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Automation made this possible\u2014and Apple\u2019s 2020 edict accelerated it. Let\u2019s Encrypt launched in November 2014, revolutionizing issuance with free, automated certificates; the ACME protocol, drafted then and standardized as RFC 8555 in 2019, turned renewal into a background hum. Today, CAs split into camps: fully automated players like Let\u2019s Encrypt, Google Trust Services, and Amazon, versus mixed providers like DigiCert, Sectigo, and GlobalSign, who blend proprietary and ACME based automation with manual issuance for some. Data from crt.sh suggests over 90% of certificates now use automated protocols like ACME. Apple\u2019s push forced CAs to adapt or lose relevance, yet many clung to old ways, agreeing to 398 only post-ballot. That lag\u2014resisting automation and shorter spans\u2014doesn\u2019t just slow progress; it externalizes risk, burdening the WebPKI with overstretched certificates and outdated practices.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/docs.google.com\/spreadsheets\/d\/1gshICFyR6dtql-oB9uogKEvb2HarjEVLkrqGxYzb1C4\/edit?gid=1219675187\"><img loading=\"lazy\" decoding=\"async\" width=\"928\" height=\"565\" src=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-19.png\" alt=\"\" class=\"wp-image-976\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-19.png 928w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-19-300x183.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-19-768x468.png 768w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-19-624x380.png 624w\" sizes=\"auto, (max-width: 928px) 100vw, 928px\" \/><\/a><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">What Problem Are We Solving Anyway?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Well for one certificates are snapshots of a domain\u2019s status at issuance; that 13-month span lets changes\u2014like ownership shifts or domain compromises\u2014linger unreflected, while 45 days would keep them current, shrinking an attacker\u2019s window from over a year to mere weeks. \u201cBygone SSL\u201d proves the point: when domains change hands, old owners can hang onto valid certificates\u2014sometimes for years\u2014letting them spoof the new owner or, with multi-domain certs, trigger revocations that disrupt others. History teaches us that reusing stale validation data\u2014sometimes months old\u2014leads to misissuance, where certificates get issued on outdated or hijacked grounds. Tighter allowed reuse periods force regular revalidation, but when CAs or companies slack, the ecosystem bears the cost: spoofed domains impersonating legit sites, breaches exposing sensitive data, and a trust system strained by systemic hits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Browsers show us the way\u2014back in the \u201890s, updates came on floppy disks on magazine covers, a manual slog that left users exposed until the next trip to the store; today, automatic updates roll out silently, patching holes and keeping security tight without a fuss. Certificates should mirror that: automated renewal via ACME or proprietary tools manages 398 days now and could handle 45 effortlessly, shedding the old manual grind\u2014an incremental evolution already underway. Yet some cling to slower cycles, offloading risk\u2014leaving the WebPKI vulnerable to their refusal to fully embrace automation\u2019s promise. The proof\u2019s in the pudding\u2014Kerberos rotates 10-hour tickets daily in enterprise networks without a hitch; ACME brings that scalability to the web. Legacy systems? Centralized solutions like reverse proxies, certificate management platforms, or off-device automation bridge the gap\u2014technical excuses don\u2019t hold.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve hit 398 days, but Zeno\u2019s Dichotomy still grips us: advocates push for shortening, hit \u201cnot ready,\u201d and stall at the current max\u2014halving the gap to robust security without ever closing it. Each delay lets inertia shift risk onto the system.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-20.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"300\" src=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-20.png\" alt=\"\" class=\"wp-image-978\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-20.png 1000w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-20-300x90.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-20-768x230.png 768w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2025\/02\/image-20-624x187.png 624w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/a><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Critics\u2019 Refrain<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Critics cling to familiar objections. \u201cLegacy systems can\u2019t handle frequent renewals\u201d? Centralized automation\u2014proxies, management tools, off-device solutions\u2014proves otherwise; their inertia spills risk onto the ecosystem. \u201cSmaller players face a competitive burden,\u201d implying the web should shoulder that risk? Shared tools and phased transitions even the odds, yet their lag, like SHA-1\u2019s slow death, threatens everyone. \u201cWhy not focus on revocation, DNSSEC, or key management instead\u201d? Revocation\u2019s a pipe dream\u2014three decades of flops, from CRLs to OCSP, show it crumbling at scale, with privacy holes, performance drags, and spotty enforcement, as DigiNotar\u2019s failure left unpatched clients exposed. DNSSEC and key management complement, not replace\u2014shorter lifetimes cut exposure fast, while those build out. \u201cIt\u2019s too rapid\u201d? Two decades of automation\u2014from proprietary solutions to ACME\u2014and 15 years of debate say no; 398 days took effort, 45\u201347 is next. \u201cWe\u2019re not ready\u201d? That\u2019s an impossible hurdle\u2014security leaps like SHA-2 to TLS 1.3 came by diving in, not waiting, just as parents figure out diapers post-birth. Stalling at 398 doesn\u2019t shield risk\u2014it dumps it on the rest.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pushing Beyond 398 Delivers Concrete Gains When Inertia\u2019s Beaten:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>Benefit<\/td><td>Description<\/td><\/tr><tr><td>Enhanced Trustworthyness<\/td><td>Frequent renewals keep data current, cutting misissuance\u2014laggards can\u2019t dump stale risks on the WebPKI.<\/td><\/tr><tr><td>Shorter Exploitation Window<\/td><td>45 days caps attacks at weeks, not 398 days\u2014orgs can\u2019t offload longer threats.<\/td><\/tr><tr><td>Lower Misissuance Risk<\/td><td>Tight reuse forces fresh checks, slashing errors CAs push onto the system.<\/td><\/tr><tr><td>Rapid Policy Transition<\/td><td>Quick shifts to new standards dodge inertia\u2019s drag, keeping the PKI sharp.<\/td><\/tr><tr><td>Stronger Baselines<\/td><td>90%+ automated renewals set a secure norm\u2014holdouts can\u2019t undermine it.<\/td><\/tr><tr><td>Collective Accountability<\/td><td>Deadlines force modernization, ending the pass where a few\u2019s inaction risks all.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Conclusion<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Shorter lifetimes and tighter reuse periods\u2014break the cycle: fresh data, capped risk, no more offloading. A phased, deadline-driven approach, like SC-081\u2019s framework (targeting shorter spans by 2029 in SC-081v2), forces the industry to adapt, hones automation where needed, and drives security forward\u2014waiting five more years just fattens the risks we\u2019ve already outgrown.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">How does inertia externalize risk in the WebPKI? When CAs lean on stale data, companies settle for 398 days, and stragglers resist progress, they turn trust into a punching bag\u2014ripe for abuse. Thirty years in, with 398 days locked and over 90% automated, the tools sit ready\u2014only will falters.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Zeno\u2019s half-steps got us here, but \u201cnot ready\u201d is a fantasy\u2014no one masters security before the plunge, just as parents don\u2019t ace diapers pre-birth; we\u2019ve evolved through every shift this way. Browsers don\u2019t wait for floppy disks anymore\u2014certificates can\u2019t linger on yesterday\u2019s pace either. I\u2019ve watched the WebPKI battle from the Wild West to now\u2014let\u2019s rip inertia\u2019s grip off with deadlines that stick and lock in 45 days to forge a trust that outlasts the past\u2019s failures.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I\u2019ve been involved in the Web PKI since the mid-\u201890s, when SSL certificates carried five- or ten-year lifetimes\u2014long-lasting credentials for an internet still a wild west. Issuance was manual, threats were sparse, and long validity fit that quieter era. Thirty years later, we\u2019ve fought our way to a 398-day maximum lifetime\u2014today\u2019s standard as of 2025\u2014thanks [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3,4],"tags":[],"class_list":["post-974","post","type-post","status-publish","format-standard","hentry","category-security","category-thoughts"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/974","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=974"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/974\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=974"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=974"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}