Matt M
@mattm.bsky.social
š¤ 329
š„ 233
š 35
reposted by
Matt M
yomna
about 2 years ago
people are always talking about a hypothetical technologically advanced alien race ... but I always wonder, if they exist, do they also have to deal with PKI?
0
9
3
reposted by
Matt M
Dirkjan Ochtman
about 2 months ago
Earlier this year,
LWN.net
featured an excellent article named "Linux's missing CRL infrastructure", and today Canonical announced it will be working with me and
@jbp.io
over the coming weeks to start bridging the PKI infrastructure gap.
discourse.ubuntu.com/t/addressing...
loading . . .
Addressing Linux's Missing PKI Infrastructure
Earlier this year, LWN featured an excellent article titled āLinuxās missing CRL infrastructureā. The article highlighted a number of key issues surrounding traditional Public Key Infrastructure (PKI)...
https://discourse.ubuntu.com/t/addressing-linuxs-missing-pki-infrastructure/73314
3
26
5
reposted by
Matt M
deedee megabagool
5 months ago
anyone need their horse rotated?
loading . . .
35
662
321
Firefox's telemetry has data on how many times a CA is used to successfully validate certificates. This is a pretty good measure for how "big" a CA is. The data is hard to view in Mozilla's site, so I've made a script to combine a few data sources and graph it!
github.com/mcpherrinm/c...
8 months ago
1
6
0
reposted by
Matt M
apenwarr
8 months ago
Customers: We want a faster horse Henry Ford: Ah. In factā Kubernetes: Let me stop you right there. What you really need is 1000 horses that die randomly
3
108
19
Inspired by the classic xeyes program, I made a thing: ssh
teyes.fly.dev
Or go install
github.com/mcpherrinm/teyes@latest
&& teyes Give your mouse a wiggle over the terminal!
8 months ago
0
2
0
I'll be speaking at the Ontario
#Cryptography
Day!
ontario-crypto-day.github.io
Where: University of Waterloo Davis Centre (DC) 1301 and 1302 When: Friday, June 6, 2025, from 10am to approx. 4:30pm I hope anyone in the area interested in cryptography is able to attend!
loading . . .
Ontario Cryptography Day
June 6, 2025 ā¢Ā University of Waterloo
https://ontario-crypto-day.github.io/
9 months ago
1
9
4
reposted by
Matt M
Mike Sowden
9 months ago
OK, this is wild. In September 2023, geophysicists across the world started monitoring a very odd signal coming from the ground under them. It was picked up in the Arctic. And Antarctica. It was detected everywhere, every 90 seconds, as regular as a metronome, for *nine days*. What the HELL? 1/
745
22464
9213
reposted by
Matt M
James McLeod
9 months ago
A lot of Americans don't know this, but the winner of the Canadian election will be required live in a small cottage located in the backyard of the palace where the viceroy to the King of England lives. The cottage just recently got a new wifi router, which was very exciting for all Canadians.
99
1758
619
reposted by
Matt M
JF Bastien
10 months ago
Array indices start at 0 in C, but start at 32 in F.
2
55
15
Of all the things I didnāt expect to ever happen, iOS Safari actually got a certificate viewer in 18.4!
webkit.org/blog/16574/w...
10 months ago
0
7
1
We've issued our first short-lived (6 day) certificate!
letsencrypt.org/2025/02/20/f...
loading . . .
We Issued Our First Six Day Cert
Earlier this year we announced our intention to introduce short-lived certificates with lifetimes of six days as an option for our subscribers. Yesterday we issued our first short-lived certificate. Y...
https://letsencrypt.org/2025/02/20/first-short-lived-cert-issued/
12 months ago
0
1
0
Chrome has published version 1.6 of their root store policy. Notably, this includes a deadline of June 15, 2026 to get TLS Client Auth out from any intermediates under roots in Chrome's program. TLS client cert users from public CAs may need to make changes.
www.chromium.org/Home/chromiu...
loading . . .
Chrome Root Program Policy, Version 1.6
https://www.chromium.org/Home/chromium-security/root-ca-policy/#32-promote-use-of-dedicated-tls-server-authentication-pki-hierarchies
12 months ago
1
10
4
Congratulations to the Firefox team for shipping CT enforcement! > Starting in Firefox 135, Certificate Transparency is now enforced on all desktop platforms.
groups.google.com/a/mozilla.or...
loading . . .
Certificate Transparency is now enforced in Firefox on desktop platforms starting with version 135
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/OagRKpVirsA/m/Q4c89XG-EAAJ
12 months ago
1
70
16
reposted by
Matt M
Acyn
about 1 year ago
Canadian MP Charlie Angus: Our beloved Canada is under threat. The threat comes from the president of the USāa convicted felon and known predator. But the threat is also being driven by the hate algorithms of oligarchs like Elon Muskā¦.
loading . . .
965
27378
9173
reposted by
Matt M
Not That Rick Scott šØš¦
about 1 year ago
heads up for fans of the "ship is stuck" genre, the Manitoulin is currently stuck in icy Lake Erie just outside Buffalo
www.reddit.com/r/GreatLakes...
loading . . .
Manitoulin Stuck in Ice Offshore in Buffalo, NY.
https://www.reddit.com/r/GreatLakesShipping/comments/1i8h2k2/manitoulin_stuck_in_ice_offshore_in_buffalo_ny/
1
213
74
reposted by
Matt M
James Wheare
about 1 year ago
Boatify wrapped 2024! Stats, maps, timelapses and silly stuff from my AIS receiver and webcam overlooking the Firth of Forth. (recommend viewing on a grown up computer, works on phones but not optimised for them)
vessels.marinesightings.com/review/2024/
loading . . .
AIS year in review 2024
Stats and interesting ships I saw come sailing in
https://vessels.marinesightings.com/review/2024/
2
12
8
I'm speaking at
#SREcon
in Santa Clara this March! Come learn how Let's Encrypt issues millions of certificates with just a handful of staff and servers!
www.usenix.org/conference/s...
loading . . .
Improving the SRE Experience for 10 Years as a Free, Open, and Automated Certificate Authority | USENIXusenix_logo_notag_white
https://www.usenix.org/conference/srecon25americas/presentation/mcpherrin
about 1 year ago
0
8
2
reposted by
Matt M
Brendan Dawe
about 1 year ago
I hear that the Ontario Government is directing Metrolinx to start investigating 'the massing link' and if it actually amounts to anything is quite impactful project for Toronto region passenger and freight
1
26
10
reposted by
Matt M
Sam Jaques
about 1 year ago
2024 update for my chart on the landscape of quantum computing:
sam-jaques.appspot.com/quantum_land...
Not much visible on the chart, but Google's result (the one with the recent press attention) is a pretty big deal
2
39
16
reposted by
Matt M
Hydro-QuƩbec
about 1 year ago
La CÓte-Nord a connu des conditions météorologiques extrêmes ces dernières semaines. Environ 75 mm de verglas se sont accumulés sur nos lignes de transport à certains endroits et nous avons dû y dépêcher des équipes rapidement afin de déglacer les lignes.
loading . . .
11
142
46
reposted by
Matt M
Transit Toronto
about 1 year ago
The train livery for the return of the Ontario Northland Railway "Northlander" train. Source:
news.ontario.ca/en/r...
0
20
5
reposted by
Matt M
Adam Aaronson
about 1 year ago
I made a calendar where every month is also a crossword, and you can get one today! Introducing the 2025 Crossword Calendar:
crosswordcal.com/products/202...
loading . . .
2025 Crossword Calendar
What if every month was a crossword? The 2025 Crossword Calendar is a folding wall calendar where each month's grid doubles as an American-style crossword puzzle, with one letter to write in each day'...
https://crosswordcal.com/products/2025-crossword-calendar
2
42
18
reposted by
Matt M
nolen
about 1 year ago
how do you all remember every UUID? I find it really hard. so I wrote them all down on every uuid dot com the list has fast search across all 2^122 values (so you can find your favorites) - hoping to add some social features like "trending UUIDs" soon!
loading . . .
48
1170
325
reposted by
Matt M
Ken Shirriff
about 1 year ago
Intel launched the Pentium processor in 1993. Unfortunately, dividing sometimes gave a slightly wrong answer, the famous FDIV bug. Replacing the faulty chips cost Intel $475 million. I reverse-engineered the circuitry and can explain the bug. 1/9
16
711
263
Do you use Let's Encrypt certificates? Do you use the "client auth" extended key usage with them? (I.E: Do you use Let's Encrypt as a client certificate). Chrome's root program is looking to phase out its use in roots they trust. I'd love to hear from anyone who would be affected.
about 1 year ago
2
12
9
Great to see more organizations sharing their use of Rustls :)
www.memorysafety.org/blog/rustls-...
loading . . .
Security-Sensitive Industries Move to Memory Safety
Prossimo has been investing in the memory safe, high performance TLS library called Rustls for nearly four years. During that time, we've seen Rustls improve and we've seen growing adoption. Organizat...
https://www.memorysafety.org/blog/rustls-adoption-grows/
about 1 year ago
0
1
0
reposted by
Matt M
Not That Rick Scott šØš¦
about 1 year ago
pardon me as I explain why Danforth is a right bastard, because this is one of my areas of intense nerdery
add a skeleton here at some point
12
776
287
reposted by
Matt M
Ed Conway
about 1 year ago
š§µSALTš§µ It's been snowing in the UK and the road gritters are out in force, begging the question: Have you ever wondered where that grit actually COMES from? The answer is more magical, beautiful and fascinating than you probably realised. 1/14
186
3783
1928
overheard:
#homelab
is where the
#heartlab
is
about 1 year ago
1
6
1
reposted by
Matt M
jiska
about 1 year ago
How does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented.
naehrdine.blogspot.com/2024/11/reve...
loading . . .
Reverse Engineering iOS 18 Inactivity Reboot
Wireless and firmware hacking, PhD life, Technology
https://naehrdine.blogspot.com/2024/11/reverse-engineering-ios-18-inactivity.html
12
279
118
reposted by
Matt M
Ryan Castellucci š¬
about 1 year ago
Oh, I never posted my gotofail story on here. Early 2014, someone came to me about a catastrophic vulnerability in Apple's TLS implementation. I shit you not, they'd overheard someone at a bar drunkenly bragging about how they were going to sell it to a FVEY intelligence agency for six figures.
7
459
121
reposted by
Matt M
Brooke Jarvis
about 1 year ago
Today in relatable science: Gulls making a mysterious daily trip that turned out to be to a potato chip factory
248
15982
4759
reposted by
Matt M
Matthew Green
about 1 year ago
More on iPhones rebooting themselves to resist cracking.
www.404media.co/apple-quietl...
loading . . .
Apple Quietly Introduced iPhone Reboot Code Which is Locking Out Cops
On Thursday 404 Media that police were freaking out about mysteriously rebooting iPhones. Now multiple experts have found that Apple introduced code that reboots locked phones after a period of time.
https://www.404media.co/apple-quietly-introduced-iphone-reboot-code-which-is-locking-out-cops/
2
47
16
I swear there was the top of a mountain just there, but it disappeared. It must have pulled a sneak peak.
over 1 year ago
2
5
1
reposted by
Matt M
The Museum of English Rural Life
over 1 year ago
look at this absolute unit
339
16111
4080
The cross-sign of ISRG Root X1 by DST Root CA X3 has now expired. ā©It's been 10 years in the making, but Let's Encrypt is now a fully standalone certificate authority, trusted by the vast majority of browsers and other devices š
over 1 year ago
0
6
1
reposted by
Matt M
Damien Miller
over 1 year ago
OpenSSH 9.9 has just been released. New features include support for hybrid ML-KEM X25519 post-quantum key exchange (using a formally-verified implementation), improved controls to drop and penalise unwanted connections, faster NTRUPrime key exchange code and more.
www.openssh.com/releasenotes...
loading . . .
OpenSSH: Release Notes
OpenSSH release notes
https://www.openssh.com/releasenotes.html#9.9
2
24
13
If you want to use an application that uses OpenSSL like nginx with RusTLS, you can use this new compatibility layer to seamlessly switch to a modern, memory-safe TLS implementation:
www.memorysafety.org/blog/rustls-...
loading . . .
Rustls Gains OpenSSL and Nginx Compatibility
The Rustls TLS library can now be used with Nginx via an OpenSSL compatibility layer. This means that Nginx users can switch from OpenSSL to Rustls with minimal effort - users can simply swap in a new...
https://www.memorysafety.org/blog/rustls-nginx-compatibility-layer/
over 1 year ago
0
5
2
reposted by
Matt M
The New York Times
almost 2 years ago
The solar eclipse that will cast a visible shadow across the U.S. on Monday is already leaving an obvious mark on hotel prices. About 300 Super 8s are within the path of solar eclipse in totality, and 100 of those were sold out for Sunday or Monday.
nyti.ms/43KrUWe
4
52
23
reposted by
Matt M
Filippo Valsorda
almost 2 years ago
Reading the timeline of the pressure campaign to convince the xz maintainer to hand over control is⦠awful. Merciless guilt-tripping. One lesson Iām taking from this is to be even more ruthless with blocks. Whining about maintenance? Blocked. Zero chances.
research.swtch.com/xz-timeline
loading . . .
research!rsc: Timeline of the xz open source attack
https://research.swtch.com/xz-timeline
6
126
37
reposted by
Matt M
Filippo Valsorda
almost 2 years ago
Extremely excited to introduce Sunlight, a Certificate Transparency log backed by object storage, based on sumdb-style tiles, and with no merge delay. Itās designed to be cheap, easy, and safe to operate, and to bring CT into the growing tlog ecosystem.
sunlight.dev
3
69
23
reposted by
Matt M
Security Cryptography Whatever
almost 2 years ago
NEW EPISODE! iMessage is getting a big post-quantum upgrade! Douglas Stebila joined us to talk about his security analysis of the new PQ3 protocol update and not indulge our wild Apple speculations:
securitycryptographywhatever.com/2024/03/03/p...
youtu.be/ogPy5XOEj3s
loading . . .
Post-Quantum iMessage with Douglas Stebila
Apple iMessage is getting a big upgrade! Not only are they rolling out ratcheting, but theyāre going post-quantum, AND theyāre doing post-quantum ratcheting!...
https://youtu.be/ogPy5XOEj3s
0
7
3
Iām excited to share River, a plan to build a new http reverse proxy built in Rust using Cloudflareās pingora libraries:
www.memorysafety.org/blog/introdu...
loading . . .
Announcing River: A High Performance and Memory Safe Reverse Proxy Built on Pingora
Today we are announcing plans to build a new high performance and memory safe reverse proxy in partnership with Cloudflare, Shopify, and Chainguard. The new software will be built on top of Cloudflare...
https://www.memorysafety.org/blog/introducing-river/
almost 2 years ago
2
19
6
reposted by
Matt M
J.C., keeper of MiniSquish š³ļøāā§ļø
almost 2 years ago
The Open Source Cryptography Workshop will be held the Thursday after
#RWC
, on 28 March, at the University of Toronto Chestnut Conference Center. Pre-registration is required, registration is now open, and some of the sessions are announced. SeeĀ Ā
oscwork.shop/2024/
Ā Ā
#OSCW
#OSCW2024
loading . . .
OSCW 2024: Toronto, Canada :: Open Source Cryptography Workshop
OSCW 2024 will take place after RWC 2024 on 28 March 2024 at the Chestnut Conference Center in Toronto, Canada. Registration Pre-registration for attendees is required, and space is limited. Please re...
https://oscwork.shop/2024/
0
5
1
Later this week, Let's Encrypt will stop including the cross-sign from Identrust's Root CA in our API by default. Details in our blog post at
letsencrypt.org/2023/07/10/c...
If you have any questions, happy to answer them over on our Community forum:
community.letsencrypt.org/t/questions-...
almost 2 years ago
1
3
1
reposted by
Matt M
David Buchanan
over 2 years ago
picking a DNS record type to use for my new protocol
2
81
8
Are you going to be at DEFCON this year? Come see my talk at the Crypto & Privacy village, where I'll be talking about the privacy and performance trade-offs of web PKI revocation! 15:00 on Friday August 11th in the Vista room at Flamingo
over 2 years ago
0
10
3
Hello!
over 2 years ago
0
3
0
you reached the end!!
feeds!
log in