Matthew McPherrin
mattm@infosec.exchange
<p>SRE at Let's Encrypt, though these toots are my own.</p>
Posts
-
View post
The headphones being used for DEFCON talks are stereo FM, easily received on your SDR of choice CH 1: 920.1Mhz CH 2: 920.7Mhz CH 3: 921.2Mhz CH 4: 921.9Mhz CH 5: 922.3Mhz CH 6: 922.8Mhz CH 7: 923.4Mhz CH 8: 924.2Mhz CH 9: 924.7Mhz CH10: 925.9Mhz CHA1: 920.5Mhz CHA2: 922.4Mhz CHA3: 926.7Mhz
-
View post
I’m at BSidesLV and DEFCON this week. Find me and say hello!
-
View post
Chrome has published version 1.6 of their root store policy. Notably, this contains a timeline for deprecating use of the TLS Client Auth extended-key-usage inside the PKIs included in their program. If you currently use TLS Client Auth from a publicly trusted CA, you may need to take action. &gt; ... certificates issued on or after June 15, 2026 MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth. https://www.chromium.org/Home/chrom...
-
View post
We&#39;ve issued our first short-lived (6 day) certificate! https://letsencrypt.org/2025/02/20/first-short-lived-cert-issued/
-
View post
Of all the things I didn’t expect to ever happen, iOS Safari actually got a certificate viewer in 18.4! https://webkit.org/blog/16574/webkit-features-in-safari-18-4/#connection-security
-
View post
I&#39;ll be speaking at the Ontario Cryptography Day! https://ontario-crypto-day.github.io/ Where: University of Waterloo Davis Centre (DC) 1301 and 1302 When: Friday, June 6, 2025, from 10am to approx. 4:30pm I hope anyone in the area interested in cryptography is able to attend. It&#39;s a free event, but registration is required.
-
View post
Inspired by the classic xeyes program, I made a thing: ssh teyes.fly.dev Or go install github.com/mcpherrinm/teyes@latest &amp;&amp; teyes Give your mouse a wiggle over the terminal!
-
View post
Firefox&#39;s telemetry has data on how many times a CA is used to successfully validate certificates. This is a pretty good measure for how &quot;big&quot; a CA is. The data is hard to view in Mozilla&#39;s site, so I&#39;ve made a script to combine a few data sources and graph it! https://github.com/mcpherrinm/cert-count
-
View post
@cybeej Internet Security Research Group is the name of the organization that runs Let&#39;s Encrypt (ie, in #3 position)
-
View post
Firefox&#39;s new &quot;security alert&quot; and &quot;no connection&quot; error page illustrations are pretty great
-
View post
Huh, that’s a message I haven’t seen before
-
View post
Of course the malware was only successful because of a browser exploit, but plaintext HTTP allows much wider exposure to network-based attackers who can freely inject content.
-
View post
Have you ever needed to make sure your website has an expired or revoked certificate? No, that&#39;s not a problem people have. But we do, because CAs have to run test sites with them. I just wrote a blog post post about this problem, and our new tool that we use to host ours: https://letsencrypt.org/2026/04/10/test-sites