Elektrine lite

← Feed

Matthew McPherrin

mattm@infosec.exchange

<p>SRE at Let&#39;s Encrypt, though these toots are my own.</p>

Posts

  • View post

    The headphones being used for DEFCON talks are stereo FM, easily received on your SDR of choice CH 1: 920.1Mhz CH 2: 920.7Mhz CH 3: 921.2Mhz CH 4: 921.9Mhz CH 5: 922.3Mhz CH 6: 922.8Mhz CH 7: 923.4Mhz CH 8: 924.2Mhz CH 9: 924.7Mhz CH10: 925.9Mhz CHA1: 920.5Mhz CHA2: 922.4Mhz CHA3: 926.7Mhz

  • View post

    I’m at BSidesLV and DEFCON this week. Find me and say hello!

  • View post

    Chrome has published version 1.6 of their root store policy. Notably, this contains a timeline for deprecating use of the TLS Client Auth extended-key-usage inside the PKIs included in their program. If you currently use TLS Client Auth from a publicly trusted CA, you may need to take action. &amp;gt; ... certificates issued on or after June 15, 2026 MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth. https://www.chromium.org/Home/chrom...

  • View post

    We&amp;#39;ve issued our first short-lived (6 day) certificate! https://letsencrypt.org/2025/02/20/first-short-lived-cert-issued/

  • View post

    Of all the things I didn’t expect to ever happen, iOS Safari actually got a certificate viewer in 18.4! https://webkit.org/blog/16574/webkit-features-in-safari-18-4/#connection-security

  • View post

    I&amp;#39;ll be speaking at the Ontario Cryptography Day! https://ontario-crypto-day.github.io/ Where: University of Waterloo Davis Centre (DC) 1301 and 1302 When: Friday, June 6, 2025, from 10am to approx. 4:30pm I hope anyone in the area interested in cryptography is able to attend. It&amp;#39;s a free event, but registration is required.

  • View post

    Inspired by the classic xeyes program, I made a thing: ssh teyes.fly.dev Or go install github.com/mcpherrinm/teyes@latest &amp;amp;&amp;amp; teyes Give your mouse a wiggle over the terminal!

  • View post

    Firefox&amp;#39;s telemetry has data on how many times a CA is used to successfully validate certificates. This is a pretty good measure for how &amp;quot;big&amp;quot; a CA is. The data is hard to view in Mozilla&amp;#39;s site, so I&amp;#39;ve made a script to combine a few data sources and graph it! https://github.com/mcpherrinm/cert-count

  • View post

    @cybeej Internet Security Research Group is the name of the organization that runs Let&amp;#39;s Encrypt (ie, in #3 position)

  • View post

    Firefox&amp;#39;s new &amp;quot;security alert&amp;quot; and &amp;quot;no connection&amp;quot; error page illustrations are pretty great

  • View post

    Huh, that’s a message I haven’t seen before

  • View post

    Of course the malware was only successful because of a browser exploit, but plaintext HTTP allows much wider exposure to network-based attackers who can freely inject content.

  • View post

    Have you ever needed to make sure your website has an expired or revoked certificate? No, that&amp;#39;s not a problem people have. But we do, because CAs have to run test sites with them. I just wrote a blog post post about this problem, and our new tool that we use to host ours: https://letsencrypt.org/2026/04/10/test-sites