Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

What a year of solar and batteries saved us in 2025

Let's Encrypt to end OCSP support in 2025

Revocation is broken

What the QWAC? An EV Certificate all over again

Scott Helme's securityheaders.com breaks through 250M scans

Can you get pwned with CSS?

When pwned passwords bloom

Working around expired root certificates

Let's Encrypt Root Expiration - Post-Mortem

Let's Encrypt's old Root Certificate is expiring

I turned on CSP and all I got was this crappy lawsuit

Another free CA as an alternative to Let's Encrypt

Running my own DoH relay and getting Pi-hole protection away from home

Another free CA as an alternative to Let's Encrypt

The Impending Doom of Expiring Root CAs and Legacy Clients

Demonstrating that revocation checking is pointless

CRLite: Finally a fix for broken revocation?

Apple caps TLS certificate lifetime at 398 days from September 2020

HPKP is no more

CSRF is really dead

I revoked $1M worth of EV certificates

Let’s Encrypt to transition to ISRG root

Alexa Top 1 Million Analysis - February 2019

A new security header: Feature Policy

HTTPS Anti-Vaxxers; dispelling common arguments against securing the web

The Power to Revoke Lies with the Certificate Authority

Thousands of sites hit by cryptojacking after 3rd party compromise

Are EV certificates worth the paper they're written on?

Report URI's journey to a permanent redirect

I'm giving up on HPKP

More →