David Adrian
@dadrian.io
đ¤ 531
đĽ 95
đ 224
Used to do TLS, still kind of do TLS. PM at Chrome Security. Founded Censys.
@scwpod.bsky.social
Iowa-Rutgers hitting the over? Trump ruined the B1G West.
17 days ago
0
0
0
New post! Stop trying to solve revocation, we already have the answer.
dadrian.io/blog/posts/r...
loading . . .
Revocation ain't no thang.
Adam Langley wrote about how revocation in the Web PKI doesnât work over 10 years ago. Since then, the Web PKI has drastically changed for the better, despite not appearing to âsolveâ revocation. Unfo...
https://dadrian.io/blog/posts/revocation-aint-no-thang/
26 days ago
0
4
3
Kirk Herbstreit is going to be the first person to make a Golden Retriever unlikable.
about 1 month ago
0
1
1
reposted by
David Adrian
rmhrisk
about 1 month ago
The bigger issue? Microsoftâs root program still trusts this CA, leaving Edge and Windows users exposed in ways Chrome, Firefox, and Safari users arenât. The pattern is familiar: long-lived trust, weak oversight, systemic risk. Itâs time for Microsoft to step up and fund proper root governance. đ
loading . . .
Another Sleeping Giant: Microsoftâs Root Program and the 1.1.1.1 Certificate Slip | UNMITIGATED RISK
https://unmitigatedrisk.com/?p=1092
2
2
1
If you look closely, you can see UNCâs quarterback is not Tom Brady
about 1 month ago
1
3
1
reposted by
David Adrian
Matt Bernhard
about 1 month ago
This game has me feeling like I'm watching Iowa play Iowa.
0
2
1
Sent this to a girl in California and pretty sure she thinks itâs in another language
add a skeleton here at some point
about 1 month ago
1
2
0
Come for the PGP dunks, stay for the broader discussion of why encrypted email doesnât make sense
add a skeleton here at some point
about 1 month ago
1
14
8
reposted by
David Adrian
Simon Fondrie-Teitler
about 2 months ago
The first part of this interview with my ex-colleague Alex is a great listen if you're a software engineer (or otherwise technical) and are interested in what we were working on as technologists at the Federal Trade Commission.
add a skeleton here at some point
0
3
2
reposted by
David Adrian
Security Cryptography Whatever
about 1 month ago
NEW EPISODE! An OpenPGP.js bug gave us an excuse to tear encrypted email via PGP to shreds. William Woodruff joined us to explain the vuln & indulge our gnashing of teeth on why email was never meant to be encrypted:
securitycryptographywhatever.com/2025/08/22/s...
www.youtube.com/watch?v=IoL3...
loading . . .
Stop Using Encrypted Email with William Woodruff
YouTube video by Security Cryptography Whatever
https://www.youtube.com/watch?v=IoL3LfIozJo
2
22
15
reposted by
David Adrian
Security Cryptography Whatever
about 2 months ago
NEW EPISODE! We chat with friend of the pod and special guest Alex Gaynor, former deputy chief technologist at the FTC and all around good Security Personâ˘. Join for nerdery about WebAuthn, stay for accidentally melting down GitHub APIs around November 2020!
youtu.be/gBoGvyvsSi4
loading . . .
Alex Gaynor
YouTube video by Security Cryptography Whatever
https://youtu.be/gBoGvyvsSi4
0
4
3
And then thereâs David.
add a skeleton here at some point
about 2 months ago
0
3
0
figma balls
2 months ago
0
1
0
reposted by
David Adrian
Security Cryptography Whatever
2 months ago
New episode! Come to SCWPodCon, sponsored by Teleport!
www.youtube.com/watch?v=tbnh...
loading . . .
Vegas, Baby!
YouTube video by Security Cryptography Whatever
https://www.youtube.com/watch?v=tbnhsmRZniI
1
0
3
reposted by
David Adrian
boo-randon is spooky now
3 months ago
𫡠go blue
www.michigandaily.com/opinion/edit...
#a2council
loading . . .
From The Daily: Vote yes on Ann Arbor proposals A and B
This Editorial Board endorses these proposals and believes that the development of this new, multi-use structure would offer many new opportunities to the Ann Arbor District Library and the greater lo...
https://www.michigandaily.com/opinion/editorials/from-the-daily-vote-yes-on-ann-arbor-proposals-a-and-b/
1
29
5
reposted by
David Adrian
Deirdre Connollyš ²
3 months ago
pew pew pew
www.youtube.com/watch?v=vtt8...
loading . . .
This Quantum Attack Is Live Now
YouTube video by Deirdre Connolly
https://www.youtube.com/watch?v=vtt8js8uA78
0
8
4
Just posted a deep dive on how Chrome integrates with Advanced Protection Mode on Android.
security.googleblog.com/2025/07/adva...
loading . . .
Advancing Protection in Chrome on Android
Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team Android recently announced Advanced Protection , which extend...
https://security.googleblog.com/2025/07/advancing-protection-in-chrome-on.html
3 months ago
0
1
1
Wrote some words about memory safety and JITs. Basically, there are things we want out of hardware, but it's not MTE and it still involves migrating to memory safe languages
dadrian.io/blog/posts/m...
loading . . .
Sandboxes? In my process? It's more likely than you think.
Discussions around memory safety often focus on choice of language, and how the language can provide memory safety guarantees. Unfortunately, choosing a language is a decision made at the start of a p...
https://dadrian.io/blog/posts/memory-safety-and-sandboxes/
3 months ago
0
4
3
reposted by
David Adrian
Electronic Frontier Foundation
3 months ago
Weâre not yet sure exactly what quantum computing can do yet, and thatâs exactly why we need to think about post-quantum cryptography now,
@durumcrustulum.com
tells EFFâs Cindy Cohn and
@thejasonkelley.com
on the new episode of âHow to Fix the Internet."
loading . . .
Podcast Episode: Cryptography Makes a Post-Quantum Leap
The cryptography that protects our privacy and security online relies on the fact that even the strongest computers will take essentially forever to do certain tasks, like factoring prime numbers and ...
https://www.eff.org/deeplinks/2025/06/podcast-episode-cryptography-makes-post-quantum-leap
2
42
10
Guide for
#a2council
to just do thingsâ Step 1: Ask
@sstrudeau.bsky.social
and
@akgood.bsky.social
what rules to get rid of. Step 2. Get rid of those rules.
add a skeleton here at some point
3 months ago
0
7
0
If
#a2council
would have just done things, instead of wasting time with an expensive and useless comprehensive land use plan, then John U. Bacon wouldnât be able to post boomer misinformation about it.
3 months ago
4
16
4
reposted by
David Adrian
Security Cryptography Whatever
4 months ago
Still have one more slot for a sponsor for our annual Vegas event, poke
@dadrian.io
if you have money.
0
1
2
There is literally a machine that does your laundry.
add a skeleton here at some point
4 months ago
3
8
3
reposted by
David Adrian
Ethan (not that Ethan)
4 months ago
More like Santa Ono! Disaster! What a bad idea!
add a skeleton here at some point
0
7
1
reposted by
David Adrian
Thomas Ptacek
4 months ago
Sophie Schmieg + ayahuasca =
keymaterial.net/2025/05/23/t...
loading . . .
There is no Diffie-Hellman but Elliptic Curve Diffie-Hellman
When I first learned about Diffie-Hellman and especially elliptic curve Diffie-Hellman, I had one rather obvious question: Why elliptic curves? Why use this strange group that seems rather arbitrarâŚ
https://keymaterial.net/2025/05/23/there-is-no-diffie-hellman-but-elliptic-curve-diffie-hellman/
0
11
3
reposted by
David Adrian
Amy
5 months ago
Behold my favorite weird Chrome security bug of 2025 so far! A jaw-dropping URL / omnibox spoof via ligatures, specifically the googlelogo ligature.
issues.chromium.org/issues/39178...
loading . . .
Chromium
https://issues.chromium.org/issues/391788835
1
16
10
the signatures must flow.
5 months ago
1
1
0
If you have a legitimate reason to get a publicly-trusted HTTPS certificate for a .arpa domain, speak now or forever hold your peace.
5 months ago
1
5
4
reposted by
David Adrian
Deirdre Connollyš ²
5 months ago
if you like Google Advanced Protection Program and run Android, get excited for Android 16:
security.googleblog.com/2025/05/adva...
3
20
5
reposted by
David Adrian
Deirdre Connollyš ²
5 months ago
add a skeleton here at some point
2
4
1
reposted by
David Adrian
Hector Diaz
5 months ago
A Chicago Pope implies the existence of an MLA Pope and APA Pope
38
28967
8943
Ungovernable because none of your software works and you can't get anything done.
add a skeleton here at some point
5 months ago
1
3
1
reposted by
David Adrian
Filippo Valsorda
6 months ago
Why is the latest version of uBlock Origin Lite asking permission to access all websites now? I love uBO Lite precisely because it doesn't make me trust an extension developer with all my browser security... (Let's not re-debate MV3 unnecessarily please. Will block.)
3
26
4
reposted by
David Adrian
Spooki BOOnoda, Candy Chef
6 months ago
Alright day one
#CharitibundiBowl
donation to
@newap-georgia.bsky.social
is $82 in honor of former Michigan WR #82 Amara Darboh, a refugee of the Sierra Leone Civil War. This country is better off with him in it.
@edsbs.bsky.social
@hollyanderson.bsky.social
4
158
14
Going to see A Minecraft Film to help me decide between my yearn for the mines and working in the iPhone assembly factories under the Trump tariffs.
6 months ago
0
5
0
reposted by
David Adrian
Ingrid Burrington
6 months ago
Ah yes the jobs where they had to put up suicide nets at the factory because workers were so miserable, bringing this to America is a good thing
add a skeleton here at some point
3
23
2
reposted by
David Adrian
Ethan (not that Ethan)
6 months ago
UConn leading by: 5 after 1 10 after 2 20 after 3 ... Bueckle Up for the 4th!
1
3
1
Only one response to these tariffs
6 months ago
0
2
0
Itâs okay, weâre a football school
6 months ago
0
4
1
reposted by
David Adrian
Donnell Wyche
6 months ago
Ann Arbor was meant to grow. We just didnât follow through. In the 1970s, city planners envisioned 150K residents in a compact, connected city. Instead, we built zoning walls around downtown and called it progress. Part 4 of my âDensity is Funâ series.
#a2council
thewychefamily.com/density-is-f...
loading . . .
Density is Fun: Why Ann Arborâs Future Depends on a Good Plan
Ann Arborâs future depends on smart growth. Itâs time to build more homes of all kindsâand shape a city that welcomes more neighbors.
https://thewychefamily.com/density-is-fun-why-ann-arbors-future-depends-on-a-good-plan/
3
38
9
Eventually, Rust will achieve perfect safety and security, once all CPU cycles are spent on the compiler, and none are spent actually running the compiled binary.
6 months ago
1
8
0
reposted by
David Adrian
Deirdre Connollyš ²
6 months ago
i helped slightly! đ
#realworldcrypto
1
3
1
Call the shot, make the shot from the Chrome Root Program.
security.googleblog.com/2025/03/new-...
loading . . .
New security requirements adopted by HTTPS certificate industry
Posted by Chrome Root Program, Chrome Security Team The Chrome Root Program launched in 2022 as part of Googleâs ongoing commitment to up...
https://security.googleblog.com/2025/03/new-security-requirements-adopted-by.html
6 months ago
1
2
0
reposted by
David Adrian
Jason Cox
6 months ago
Step 1: Make stupid land use decisions. Step 2: Complain things suck. Step 3: Make more stupid land use decisions. Step 4: Things suck more. Step 5: Make more stupid land use decisions. Step 6: Suck increases. Step 7: Make more stupid land use decisions.
1
12
4
reposted by
David Adrian
Real World Crypto Symposium
6 months ago
For a live summary in bite-size pieces, follow our unofficial scribe, Deirdre Connolly.
#realworldcrypto
add a skeleton here at some point
0
7
4
reposted by
David Adrian
Security Cryptography Whatever
7 months ago
Migrating the US government to quantum-resistant cryptography is hard, luckily the gamer presidents are on it. This episode is very not safe for work, nor does it reflect the political opinions of, well, anybody.
podcasts.apple.com/us/podcast/p...
securitycryptographywhatever.com/2025/03/23/p...
loading . . .
Picking Quantum Resistant Algorithms
Migrating the US government to quantum-resistant cryptography is hard, luckily the gamer presidents are on it. This episode is extremely not safe for work, n...
https://securitycryptographywhatever.com/2025/03/23/picking-quantum-resistant-algorithms/
1
10
3
reposted by
David Adrian
Daniel Garnier-Moiroux
7 months ago
Iâve been working on webauthn and passkeys on and off for > 1 year, and I canât believe I missed this
@scwpod.bsky.social
with Adam Langley from Google, dating back to ⌠2022 𤯠If youâre interested in technical details about passkeys, itâs very good!
securitycryptographywhatever.com/2022/08/11/p...
loading . . .
Passkeys with Adam Langley
Adam Langley (Google) comes on the podcast to talk about the evolution of WebAuthN and Passkeys! Davidâs audio was a little finicky in this one. Believe us,...
https://securitycryptographywhatever.com/2022/08/11/passkeys-with-adam-langley/
1
24
5
reposted by
David Adrian
Heather Adkins
7 months ago
We will have memory safety⌠it will take many steps forward, over the long haul. Hereâs an update from Chrome on replacing FreeType with a Rust based alternative.
developer.chrome.com/blog/memory-...
loading . . .
Memory safety for web fonts  | Blog  | Chrome for Developers
Learn how and why the Chrome team has replaced FreeType with Skrifa.
https://developer.chrome.com/blog/memory-safety-fonts
3
21
12
reposted by
David Adrian
Raph Levien
7 months ago
New blog post up on the Rust font loader now shipping in Chrome. I only had a small part in this personally but am proud of the team's work.
developer.chrome.com/blog/memory-...
loading . . .
Memory safety for web fonts  | Blog  | Chrome for Developers
Learn how and why the Chrome team has replaced FreeType with Skrifa.
https://developer.chrome.com/blog/memory-safety-fonts
3
108
28
Load more
feeds!
log in