WebPKI and You

There’s been a push over the last twelve years to move web traffic off unencrypted HTTP to encrypted HTTPS, to protect the general public from dragnet surveillance, gaping assholes on public wifi>airpwn, backhauls over unencrypted satellites, that kinda thing. HTTPS relies on a public key infrastructure to make sure only authorized servers have keys for specific websites. [>oid]: an OID or “Object IDentifier” is intended [brs]: https://cabforum.org/working-groups/server/baseline-requirements/documents/CA-Browser-Forum-TLS-BR-2.1.8.pdf [crtsh]: https://crt.sh/?q=blog.brycekerley.net [lol-diginotar]: https://en.wikipedia.org/wiki/DigiNotar#Issuance_of_fraudulent_certificates [iv-ocsp]: https://www.imperialviolet.org/2011/03/18/revocation.html [>mac-ocsp]: Jeff Johnson’s [>crlite]: these use cascading bloom filters which [>short-lived]: the CA/BF baseline requirements [trustico-chrome]: https://security.googleblog.com/2017/09/chromes-plan-to-distrust-symantec.html [trustico-gone]: https://arstechnica.com/information-technology/2018/03/trustico-website-goes-dark-after-someone-drops-critical-flaw-on-twitter/ [trustico-compromise]: https://groups.google.com/g/mozilla.dev.security.policy/c/wxX4Yv0E3Mk/m/o1cdfx2nAQAJ [>enclaves]: Amazon Web Services (AWS) and [>history]: i mean, i remember from when it happened [>parasite]: You may have realized that I don’t think [van-halen]: https://snackstack.net/2023/07/03/in-search-of-van-halens-brown-mms/ [>osi]: I’m not going to hit you with a [>responsibility]: in every part of your life! [>bloom]: [>later]: At time of publishing, it’s March 8, 2026 [hsts]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Strict-Transport-Security [>hsts]: This is generally a hardcoded value, [>cattle]: “cattle” is when there’s [ari]: https://letsencrypt.org/2025/09/16/ari-rfc [>caddy-ari]: I checked Caddy, the front-end server [>left]: there may be value in trying to renew [audits]: https://cabforum.org/about/information/auditors-and-assessors/audit-criteria/

Bryce’s Blog
Online citizenship in Spain - Negative PID

The Spanish public administration has adopted a pathway to online citizenship that allows for fast and secure communications. Here's how it all works.

Negative PID
Ex-Palantir turned politician Alex Bores says AI deepfakes are a 'solvable problem' if we bring back a free, decades-old technique | Fortune https://fortune.com/2025/12/27/alex-bores-ai-deepfakes-solvable-problem-c2pa-free-open-source-standard/ #AI #DeepFakes #DigitalCertificates #C2PA #technology

Europe has invested heavily in digital citizenship. During the last year, we experienced Quebec's withdrawal from emails and other digital services due to security concerns, and later, we got to experience a full-blown, certificate-based digital identity experience in Spain.

#digitalCitizenship #onlineAdministration #Europe #EU #digitalCertificates #authentication #onlineIdentity

https://negativepid.blog/online-citizenship-in-spain/
https://negativepid.blog/online-citizenship-in-spain/

Online citizenship in Spain - Negative PID

The Spanish public administration has adopted a pathway to online citizenship that allows for fast and secure communications. Here's how it all works.

Negative PID

Europe has invested heavily in digital citizenship. During the last year, we experienced Quebec's withdrawal from emails and other digital services due to security concerns, and later, we got to experience a full-blown, certificate-based digital identity experience in Spain.

#digitalCitizenship #onlineAdministration #Europe #EU #digitalCertificates #authentication #onlineIdentity

https://negativepid.blog/online-citizenship-in-spain/
https://negativepid.blog/online-citizenship-in-spain/

Online citizenship in Spain - Negative PID

The Spanish public administration has adopted a pathway to online citizenship that allows for fast and secure communications. Here's how it all works.

Negative PID

Europe has invested heavily in digital citizenship. During the last year, we experienced Quebec's withdrawal from emails and other digital services due to security concerns, and later, we got to experience a full-blown, certificate-based digital identity experience in Spain.

#digitalCitizenship #onlineAdministration #Europe #EU #digitalCertificates #authentication #onlineIdentity

https://negativepid.blog/online-citizenship-in-spain/
https://negativepid.blog/online-citizenship-in-spain/

Online citizenship in Spain - Negative PID

The Spanish public administration has adopted a pathway to online citizenship that allows for fast and secure communications. Here's how it all works.

Negative PID

Other People Have Lives – I Have Domains

These are just some boring update notifications from the elkemental Webiverse. The elkement blog has recently celebrated its fifth anniversary, and the punktwissen blog will turn five in December. Time to celebrate this - with new domain names that says exactly what these sites are - the 'elkement . blog' and the 'punktwissen . blog' (Edit: which now - in 2020 - point to a copy of these sites elsewhere ;-) Edit again in 2023: And now the main name of this site is elkement.art […]

https://elkement.art/2017/06/06/other-people-have-a-life-i-have-domains/

Europe has invested heavily in digital citizenship. During the last year, we experienced Quebec's withdrawal from emails and other digital services due to security concerns, and later, we got to experience a full-blown, certificate-based digital identity experience in Spain.

#digitalCitizenship #onlineAdministration #Europe #EU #digitalCertificates #authentication #onlineIdentity

https://negativepid.blog/online-citizenship-in-spain/
https://negativepid.blog/online-citizenship-in-spain/

Online citizenship in Spain - Negative PID

The Spanish public administration has adopted a pathway to online citizenship that allows for fast and secure communications. Here's how it all works.

Negative PID

Europe has invested heavily in digital citizenship. During the last year, we experienced Quebec's withdrawal from emails and other digital services due to security concerns, and later, we got to experience a full-blown, certificate-based digital identity experience in Spain.

#digitalCitizenship #onlineAdministration #Europe #EU #digitalCertificates #authentication #onlineIdentity

https://negativepid.blog/online-citizenship-in-spain/
https://negativepid.blog/online-citizenship-in-spain/

Online citizenship in Spain - Negative PID

The Spanish public administration has adopted a pathway to online citizenship that allows for fast and secure communications. Here's how it all works.

Negative PID
We've Issued Our First IP Address Certificate

Since Let’s Encrypt started issuing certificates in 2015, people have repeatedly requested the ability to get certificates for IP addresses, an option that only a few certificate authorities have offered. Until now, they’ve had to look elsewhere, because we haven’t provided that feature. Today, we’ve issued our first certificate for an IP address, as we announced we would in January. As with other new certificate features on our engineering roadmap, we’ll now start gradually rolling out this option to more and more of our subscribers.