Rob Stradling

567 posts

Rob Stradling

Rob Stradling

@_robstr

Katılım Eylül 2015
78 Takip Edilen420 Takipçiler
evan j
evan j@ejcx_·
👀👀crt.sh has been down at least the last 2 days... Wondering if they need help? I'm happy to lend a hand, but haven't really seen a story or any information about it.
English
1
3
8
1.8K
Rob Stradling
Rob Stradling@_robstr·
@julianor @ic0nz1 crt.sh has fallen significantly behind on ingesting new log entries (see crt.sh/monitored-logs). However, I was finally able to deploy some performance improvements this week, and I'm hoping the ingestion backlog will disappear within the next month or so.
English
1
0
1
82
Juliano Rizzo
Juliano Rizzo@julianor·
@ic0nz1 Yes, looks like the cert is not listed in crt sh but facebook API has it.
English
1
0
0
114
Juliano Rizzo
Juliano Rizzo@julianor·
SSL/TLS Certificate Transparency logs, while valuable, may not offer comprehensive detection against hijack and interception attacks. Caution and further measures advised ⚠️🧐
English
0
0
5
905
Juliano Rizzo
Juliano Rizzo@julianor·
👋 need some help querying certificate transparency logs.
English
1
0
0
883
Rob Stradling
Rob Stradling@_robstr·
@ericlaw Ah, just saw your other tweet. Looks like it's a SHA-256 SubjectPublicKeyInfo thumbprint.
English
1
0
1
76
Rob Stradling
Rob Stradling@_robstr·
@ericlaw Is the prefix always "sha256/", or are there other options? Is the remainder of the string a base64-encoded certificate thumbprint? Or something else?
English
1
0
0
77
daniel:// stenberg://
daniel:// stenberg://@bagder·
Would you like a command line tool that can parse, manipulate and output (pieces of) URLs? Meet "urler" (which might change name soon if we agree on a better one) github.com/curl/urler
English
27
53
302
36.7K
Ryan Hurst
Ryan Hurst@rmhrisk·
@RME So the figure is less than 4283/s. To size the gap you can look at crt.sh/cert-populatio… and notice that only @letsencrypt published final certificates, the rest of the final certificates are crawler/researcher-observed certificates that were published to logs.
English
2
0
0
0
Rob Stradling
Rob Stradling@_robstr·
@Martijn___ @jschauma The certificate_identity table is a historical artifact from the original crt.sh database, which had int32 certificate IDs. As part of rebuilding the database to have int64 IDs, I switched to using postgres's Full Text Search instead.
English
1
0
1
0
Tim Perry (now mostly on 🦋 + 🦣)
WTF networking moment-of-the-day: did you know that you can have domain names with underscores in, but you can't create TLS certs for them? Totally practically possible, but since sometime after mid-2019 modern browsers now reject them outright: github.com/httptoolkit/ht…
English
1
0
2
0
Rob Stradling
Rob Stradling@_robstr·
@rmhrisk Actually, tbh I'd always assumed timstamp.dll was so named due to legacy DOS filename length restrictions (8 chars, then 3 for the extension). Turns out the truth is stranger. 🙂
English
1
0
3
0
Ryan Hurst
Ryan Hurst@rmhrisk·
Authenticode was introduced in June 1996. That is right, it is 26 years old.
English
2
1
18
0