Martijn Katerbarg

66 posts

Martijn Katerbarg

Martijn Katerbarg

@Martijn___

PKI, SSL, CA stuff, Programmer, Tinkerer, Datahoarder, Homelab and retro tech enthusiast, Compliance dude apparently. Work@Sectigo. Tweets are mine

Stockholm, Sweden Katılım Mart 2022
68 Takip Edilen47 Takipçiler
Martijn Katerbarg retweetledi
Ryan Hurst
Ryan Hurst@rmhrisk·
CABForum SCWG Ballot SC-081 just passed! WebPKI certificate maximum validity periods will now reduce according to this schedule:
Ryan Hurst tweet media
English
1
20
24
3.7K
Martijn Katerbarg retweetledi
Ryan Hurst
Ryan Hurst@rmhrisk·
Who wants to lose money on a browser that is so open source nearly every competing browser is just a clone with a thin veneer? I don’t see how this serves users, the Chrome team does so much more for the internet than release Chrome itself what happens to that work?
WIRED@WIRED

In its final proposed remedy filing in the Google antitrust case, the Department of Justice reiterated that Google should stop paying partners for search placement—and divest its dominant Chrome browser. wired.com/story/the-doj-…

English
0
1
8
848
Martijn Katerbarg
Martijn Katerbarg@Martijn___·
@0x4a45 Status är nu ändrat till "Uploading". Oklart om det blir publikt eller inte
Svenska
1
1
1
216
Jesper
Jesper@0x4a45·
Sportadmin-ransomhub update: Efter att i flera dygn stått som "Published" (utan någon länk till materialet). Verkar det nu pågå en Auktion, och datan verkar säljas istället för att publiceras öppet.
Jesper tweet media
Svenska
1
0
4
917
Karl Emil Nikka
Karl Emil Nikka@KarlEmilNikka·
Efter några dagars tysthet har Ransomhub uppdaterat status för Sportadmin-läckan. Utpressarna säger nu att de ska auktionera datan. Ransomhubs hantering tyder på att de tror att andra än Sportadmin är villiga att betala för den stulna datan. sakerhetskollen.se/aktuella-brott… #Sportadmin
Svenska
2
5
15
1.3K
Karl Emil Nikka
Karl Emil Nikka@KarlEmilNikka·
Ransomhubs nedräkningstimer för Sportadmin gick precis ut. Timern är utbytt mot texten ”published”. Än så länge finns det dock ingen publik nedladdningslänk till den stulna datan. #Sportadmin #Ransomhub
Karl Emil Nikka tweet media
Svenska
2
1
7
1.5K
Karl Emil Nikka
Karl Emil Nikka@KarlEmilNikka·
Utpressningsgänget Ransomhub hade ursprungligen tänkt publicera den stulna Sportadmin-datan strax efter lunch. Enligt deras webbplats har de nu gett Sportadmin drygt två dygn till. #Sportadmin #Ransomhub
Karl Emil Nikka tweet media
Svenska
4
3
14
1.9K
X
X@Totogoals·
@KarlEmilNikka Men de har väl ”bara ” mail och telefonnummer kanske personnummer som är offentligt ändå. Vilken skada kan ske?
Svenska
1
0
0
62
Martijn Katerbarg
Martijn Katerbarg@Martijn___·
@KarlEmilNikka Däremot började självaste nedräkningen i första hand med kortare tid än dom flesta. Det är möjligt att om ångrade det.
Svenska
0
0
1
73
Martijn Katerbarg retweetledi
Feisty Duck
Feisty Duck@feistyduck·
Cryptography & Security Newsletter: Sectigo has published a meta-linter called pkimetal, which unifies several other prominent linters into a single tool. buff.ly/3MtW6gk
Feisty Duck tweet media
English
0
4
9
853
Martijn Katerbarg retweetledi
Ryan Hurst
Ryan Hurst@rmhrisk·
"On numerous instances over the last three years, e-commerce monitoring GmbH fell short of the above expectations. In light of this, we have reached the conclusion that the GLOBALTRUST 2020 certificates suffer from a loss of integrity and action is required from the perspective of ensuring web security for Chrome users" groups.google.com/a/ccadb.org/g/…
English
0
3
3
533
Martijn Katerbarg retweetledi
Cryptoki
Cryptoki@Cryptoki·
CA/Browser Forum ballot SC-067 is in discussion to require Multi-Perspective Issuance Corroboration (aka MPIC) by CAs for domain validation and CAA checks to make certain attacks on #TLS validation more difficult lists.cabforum.org/pipermail/serv…
English
0
5
11
3.9K
Martijn Katerbarg retweetledi
Cryptoki
Cryptoki@Cryptoki·
Chrome updates its CA root policy at g.co/chrome/root-po…, includes term limits, key freshness etc.
English
1
4
9
818
Andree Toonk
Andree Toonk@atoonk·
@rmhrisk @DaKnObCS Interesting bug report. I wonder if there are any recommendations or requirements around BGP monitoring or DNS validation from multiple ASNs?
Vancouver, British Columbia 🇨🇦 English
1
0
0
165
Ryan Hurst
Ryan Hurst@rmhrisk·
For ages I have been advocating that all WebPKI CAs should be required to support ACME and enable third-party testing via that interface and @DaKnObCS provided an excellent example of why in this bug. MUCH RESPECT. #c13" target="_blank" rel="nofollow noopener">bugzilla.mozilla.org/show_bug.cgi?i…
English
2
7
10
2.3K
Martijn Katerbarg retweetledi
Wiz
Wiz@wiz_io·
🚨 BREAKING: Wiz Research discovers a massive 38TB data leak by Microsoft AI researchers, including 30,000+ internal Teams messages. Here's what you need to know 🧵
Wiz tweet media
English
54
853
2.6K
964.1K
Martijn Katerbarg
Martijn Katerbarg@Martijn___·
This whole AI thing, kinda made "Pics or it didn't happen" irrelevant
English
0
0
0
37
Martijn Katerbarg retweetledi
Tim Callan
Tim Callan@TimCallan·
The Root Causes podcast frequently discusses the concepts of certificate automation and Certificate Lifecycle Management (CLM). In this episode we discuss how CLM does not always entail automation and vice versa - and why it matters. soundcloud.com/tim-callan/roo…
English
0
2
2
75
Martijn Katerbarg retweetledi
Sectigo
Sectigo@SectigoHQ·
Our team had a great second day at @RSAConference yesterday! Our team is on site at booth #1327 to talk about how CA Agnostic #CLM can help with 90-day TLS. Additionally, #webby honoree @TimCallan gave a great talk on #QuantumComputing, explaining how organizations can prepare.
Sectigo tweet mediaSectigo tweet mediaSectigo tweet mediaSectigo tweet media
English
1
2
2
191
Jim Manico from Manicode Security
I’m sorry but your code is NOT self documenting. Please provide meaningful comments to help me understand what the hell you are trying to do.
English
30
12
121
22.5K