Jørn · @jornane
61 followers · 1118 posts · Server ipv6.social

Yeah I feel a LOT more secure with . Few minutes after running ACME on my fresh domain, 5 bots visit me to try and exploit my site, and pays a visit.
It's a technology that's not useful for me, but one that I'm forced to use. It's useful for and criminals. That's probably why CT looks like, swims like and quacks like a .

#certificatetransparency #google #bigtech #blockchain

Last updated 1 year ago

heise online · @heiseonline
27637 followers · 542 posts · Server mastodon.social

Wordpress: Attackiert schon während der Installation

Noch bevor das System live geht, haben Angreifer es oft unbemerkt mit Hintertüren versehen. Die stehen nämlich schon nach wenigen Minuten auf der Matte.

heise.de/news/Wordpress-Attack

#backdoor #certificatetransparency #wordpress #zertifikate #news

Last updated 2 years ago

mediareloaded · @mediareloaded
37 followers · 1345 posts · Server digitalcourage.social
thorsten · @tbachner
177 followers · 1330 posts · Server ruhr.social
Saupreiss #Präparat500 · @Saupreiss
298 followers · 3594 posts · Server pfalz.social

- Das ist echt reißerisch. Natürlich kann und sollte man über fragwürdige s in berichten. Das Problem ist in Zeiten von auch bei weitem nicht so groß, wie dargestellt. Ein wenig unaufgeregtere Berichterstattung würde Euch echt gut tun.

golem.de/news/chrome-safari-fi

#golem #ca #browsern #certificatetransparency

Last updated 2 years ago

Greg Slepak 🐢 · @taoeffect
229 followers · 6083 posts · Server mstdn.io

I've been predicting this for years.

TLDR: will kill off CAs without making you much safer, eventually resulting in global Internet censorship. @letsencrypt will accelerate.

only solution out of this.

templarbit.com/blog/2018/09/07

#certificatetransparency #dpki

Last updated 7 years ago

X_Cli · @x_cli
271 followers · 1441 posts · Server infosec.exchange

Is usable? by Emily Stark (Google)

youtube.com/watch?v=e_rwG7MA5V

Good talk!

#certificatetransparency

Last updated 7 years ago

X_Cli · @x_cli
271 followers · 1441 posts · Server infosec.exchange

Startcom is no longer a trusted CA, but it managed to bring further shame onto itself by being a poor log operator. They will cease that activity shortly: groups.google.com/a/chromium.o

#certificatetransparency #infosec #tls #x509

Last updated 7 years ago

X_Cli · @x_cli
271 followers · 1441 posts · Server infosec.exchange

@jerry @JohnnyC I was referring to the more general notion of using an append-only ordered log, "à la" , where there is a trustworthy/auditable notary. The goal is not be to kick anyone out, but instead to have a centralized notary of user handles, thus avoiding merge conflicts.
The confusion comes from the fact that I should have referred to General Transparency instead of CT (github.com/google/trillian/blo)

#certificatetransparency

Last updated 7 years ago

X_Cli · @x_cli
271 followers · 1441 posts · Server infosec.exchange

@JohnnyC @jerry Nah, not really. (Let's encrypt) LE is actually one of the entities that are audited by . All certificates that LE emits are inserted in log servers for monitoring by the domain name holders and the community.

There was a very good intro to at the latest conference: media.ccc.de/v/33c3-8167-every

My own slidedeck is in French.

#certificatetransparency #infosec #ccc

Last updated 7 years ago

X_Cli · @x_cli
271 followers · 1441 posts · Server infosec.exchange

@jerry @JohnnyC Yeah. I am actually not a great fan of blockchain space heaters :) I like the idea of a centralized notary that can be audited, and which has a reputation to uphold. That's why I believe in

#certificatetransparency

Last updated 7 years ago

X_Cli · @x_cli
271 followers · 1441 posts · Server infosec.exchange

: Hey! I am network security specialist, teacher and researcher, living in . My main interests/skills are , (, , , /#GnuPG), , , , . I mainly develop in and , although I have done a fair amount of in the past.

#introduction #france #dns #securemessaging #omemo #signal #otr #openpgp #tls #certificatetransparency #web #secureprogramming #golang #python #php

Last updated 7 years ago

X_Cli · @x_cli
271 followers · 1441 posts · Server infosec.exchange

@jerry @JohnnyC A copy of the master address list at each node would be a call for merge conflicts. A centralized log, similar to notary system could do though, or a namecoin-like using a blockchain system as a decentralized notary.

#certificatetransparency

Last updated 7 years ago