The Difference Between Root Certificate Authorities, Intermediates and Resellers

Last week's Let's Encrypt downtime

The SSL certificate issuer field is a lie

whoarethey: Determine Who Can Log in to an SSH Server

The SSL Certificate Issuer Field is a Lie

No, Google Did Not Hike the Price of a .dev Domain from $12 to $850

Checking if a Certificate is Revoked: How Hard Can It Be?

Parsing a TLS Client Hello with Go's cryptobyte Package

I'm Using SNI Proxying and IPv6 to Share Port 443 Between Webapps

Comcast Shot Themselves in the Foot with MTA-STS

Sign arbitrary data with your SSH keys

How Certificate Transparency Logs Fail and Why It's OK

Preventing Server Side Request Forgery in Golang

Writing an SNI Proxy in 105 Lines of Go

Always Review Your Dependencies, AGPL Edition

Git-crypt – transparent file encryption in git

Thoughts on the Systemd Root Exploit

Systemd Is Not Magic Security Dust

How to Crash Systemd in One Tweet

Duplicate Signature Key Selection Attack in Let's Encrypt

STARTTLS Considered Harmful

LibreSSL's PRNG is Unsafe on Linux