Notably, this includes a deadline of June 15, 2026 to get TLS Client Auth out from any intermediates under roots in Chrome's program.
TLS client cert users from public CAs may need to make changes.
www.chromium.org/Home/chromiu...
Notably, this includes a deadline of June 15, 2026 to get TLS Client Auth out from any intermediates under roots in Chrome's program.
TLS client cert users from public CAs may need to make changes.
www.chromium.org/Home/chromiu...
It bypasses all (debatable) portability objections to passkeys, it’s at least as secure as email-based recovery, as fast as a password manager, it’s available to all users… and importantly, no passwords!
It bypasses all (debatable) portability objections to passkeys, it’s at least as secure as email-based recovery, as fast as a password manager, it’s available to all users… and importantly, no passwords!
"Safari 18.2 on iOS, iPadOS, and visionOS will always try to load webpages over secure connections first, i.e. HTTPS by default. Only if the secure page load fails will Safari fall back to non-secure HTTP."
webkit.org/blog/16301/w...
"Safari 18.2 on iOS, iPadOS, and visionOS will always try to load webpages over secure connections first, i.e. HTTPS by default. Only if the secure page load fails will Safari fall back to non-secure HTTP."
webkit.org/blog/16301/w...
Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out.
grayduck.mn/2024/11/21/h...
Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out.
grayduck.mn/2024/11/21/h...
One day I aspire to get as many laughs during a talk as a 90s sitcom laugh track 🤩
One day I aspire to get as many laughs during a talk as a 90s sitcom laugh track 🤩
Today it’s tldr.fail. PQ shares were already default in Chrome, but Go 1.23 is surfacing new broken middleboxes.
Last time it was X.509 SANs.
Today it’s tldr.fail. PQ shares were already default in Chrome, but Go 1.23 is surfacing new broken middleboxes.
Last time it was X.509 SANs.
the idea is to store domain name<->public key bindings in a Merkle tree, mirrored by browser vendors or other designated entities to clients and... (1/n)
the idea is to store domain name<->public key bindings in a Merkle tree, mirrored by browser vendors or other designated entities to clients and... (1/n)