Musings about WebPKI and Public Trust

Musings about WebPKI and Public Trust

Home
Archive
About
Workload Identity: Part 1
What is it? And how does it intersect with WebPKI?
Apr 22 • 
Amir
1

September 2024

Ballot removing the WHOIS reliant domain control validation methods
Hi folks,
Sep 16, 2024 • 
Amir
Issuance Auditability: Certificate Validation Methods
With great power, comes even greater transparency requirements
Sep 15, 2024 • 
Amir

July 2024

Reflections on Entrust's Distrust
What happened, why now, and what does this mean for the future of WebPKI
Jul 1, 2024 • 
Amir
6
4

June 2024

Entrust has been distrusted
Announcement: https://security.googleblog.com/2024/06/sustaining-digital-certificate-security.html
Jun 27, 2024 • 
Amir
4

May 2024

Mozilla: Entrust Issues
What is Entrust's and WebPKI's Future?
May 6, 2024 • 
Amir
1

April 2024

Entrust considered harmful - Part 3
Two steps forward, no revokes back
Apr 29, 2024 • 
Amir
2
Entrust considered harmful - Part 2
Where Entrust chooses to continue misissuing certificates
Apr 22, 2024 • 
Amir
4
Entrust considered harmful - Part 1
A series on harmful pattern of behavior by Entrust
Apr 15, 2024 • 
Amir
6
Beyond Distrust, what can a root program do?
Moving away from the binary trust model for CAs and taking small steps to heal the ecosystem
Apr 10, 2024 • 
Amir
4

March 2024

Entrust mis-issues a certificate, Refuses To Follow CA/B Rules
Extended Validation certificates are a massive hole in web security
Mar 15, 2024 • 
Amir
3
© 2025 Amir
Privacy ∙ Terms ∙ Collection notice
Start writingGet the app
Substack is the home for great culture