rmhrisk

@rmhrisk.bsky.social

Dropout. Father. I build things. Security, Cryptography, Engineering, Entrepreneurship. @peculiarventure + x-MSFT + x-GOOG ++. Also on @rmhrisk@infosec.exchange and twitter.com/rmhrisk

Yesterday I wrote about the classical WebPKI, the certificate chains, CAs, and governance we’ve used for three decades. Today’s piece is about what ultimately replaces it.

The WebPKI has two core structures that are not the same shape. One is essentially a cryptographic graph of signed delegations. The other is a governance framework of accountability. Almost every major failure in its history sits in the gap between them.

FIPS 140-3 validations give you a narrow, well-defined assurance boundary. But the real security story often lives in the code and dependencies just outside that boundary - bootloaders, firmware parsers, and the plumbing that actually feeds the crypto.👇

We built the WebPKI around buildings, cages, ceremonies, HSMs, and audits. Most of the compromises we worry about now don't live in any of those places. 👇

One of the developers at Peculiar Ventures needed to debug some smart card APDU traces recently. I have enough trauma from the 90s and 2000s that I felt compelled to build an AI-annotated APDU trace analyzer.

BildBild

The WebPKI is something we all rely on every day, and most people do not even know it exists. What is interesting is that even those who do often do not understand it as well as they think they do. To help more people understand how it works, I put together the WebPKI Observatory.

WebPKI Observatory — Certificate Authority Trust Ecosystem Analysis

Quantitative analysis of 96 trusted CAs: market share, concentration risk, compliance incidents, distrust history, and root program governance. Updated daily.

webpki.systematicreasoning.com

There's a pattern that plays out across every regulated industry. Requirements increase. Complexity compounds. And instead of building capacity to meet the rising bar, organizations quietly lower the specificity of their commitments. ⬇️

Short-lived and IP address certificates are now generally available from Let’s Encrypt. Modern infrastructure no longer has stable hostnames, static IPs, or long-lived trust anchors. Workloads spin up before DNS exists, live briefly, and disappear. Trust has to keep up. 👇

Enron passed their audits. Wirecard passed their audits. Every distrusted CA passed their audits. Auditors are paid to confirm compliance, not to find problems. When the measure becomes the target - and the measurer is incentivized to pass you - it stops measuring anything.

I hired a director recently and this was my screening question: can you please explain the difference between public-key and symmetric-key cryptography. Virtually all the candidates, who universally claimed security engineering expertise of some kind (some cryptography-related) could not. At all.

AI can lift human dignity by opening doors to more people and adapting to how we think, letting us focus on what matters. But only if we design it right and keep monitoring its work. 👇

Researchers pointed a satellite dish at the sky for 3 years and monitored what unencrypted data it picked up. The results were shocking: They obtained thousands of T-Mobile users' phone calls and texts, military and law enforcement secrets, much more: www.wired.com/story/satell... 🧵👇

Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data

With just $800 in basic equipment, researchers found a stunning variety of data—including thousands of T-Mobile users’ calls and texts and even US military communications—sent by satellites unencrypte...

wired.com

This morning, a serious WebPKI incident surfaced: a tiny CA misissued certificates for 1.1.1.1 - Cloudflare’s DNS service. With BGP hijacks happening regularly, those certs could enable full man-in-the-middle attacks. 👇

Big milestone for email security. CA/Browser Forum just published S/MIME BR v1.0.11. Now with NIST-approved post-quantum algorithms (ML-DSA & ML-KEM). Quantum-resistant S/MIME is here. 👇

Building on the great research by Cem Paya and Matthew Ludwigs at River Financial, my new post details how attackers are exploiting fundamental assumptions in Microsoft's code signing. 👇

With Authenticode & CA/B Forum–compliant code signing, intent ≠ immunity. The Baseline Requirements define revocation conditions based on use in the wild, not the developer’s intent. Ship signed code? Design it to resist abuse — attackers can weaponize your trust, and your cert can be pulled.

The "Invitation Is All You Need" attack: AI agent poisoned through calendar, executed malicious commands days later. AI agents persist memory across sessions, and static credentials become persistent threats. 👇

One of the best parts of Black Hat is the hallway track. This week, I got to watch some great talks with friends, and one reminded me of a common pattern, the innovation–security debt cycle: 1️⃣ Rush to ship 2️⃣ Debt builds 3️⃣ Incident forces change 4️⃣ Security becomes a differentiator 👇