David Benjamin
@davidben__
Followers
1K
Following
47
Media
0
Statuses
423
There are lots of people with my name. I'm the Chromium (and cuttlefish) one. I work on TLS, privacy, and general amusements in Chrome.
Joined November 2014
Picking parameters: https://t.co/RCGoLZDsCc. (It was too long for Twitter.)
2
23
50
I look forward to all the latent X.509 bugs around 2050, as we rollover from UTCTime to GeneralizedTime. Did you think we were done with two-digit years after Y2K? Well, X.509 has some news for you!
1
2
21
1/ Are you a software engineer interested in security, PKI, applied crypto, related topics, & willing to live/work in Washington DC area? Here's a job posting: https://t.co/Aa3VsyE9sh & a ๐งต for you (read to the end for some caveats, including other roles opening up soon):
3
45
85
I'm hiring a technical lead for the team we're building in DC to work on the Privacy Sandbox. Please spread the word and feel free to ping with any questions. https://t.co/TwCaRvn2Ho
0
5
5
Chrome is starting to move towards blocking all mixed content. ๐๐ see this blog post for why and how: https://t.co/fVqJqnNzJq (cc @carlosjoan91)
security.googleblog.com
Posted by Emily Stark and Carlos Joan Rafael Ibarra Lopez, Chrome security team Update (04/06/2020): Mixed image autoupgrading was origina...
4
56
120
Apple, Google, Microsoft, and Mozilla today jointly announced a timeline for the removal of TLS 1.0 and 1.1 from their respective browsers. https://t.co/XJO6WcpWzU
https://t.co/vktF2PfpAt
https://t.co/qIYLdqR5C2
blog.mozilla.org
In March of 2020, Firefox will remove support for TLS 1.0 and TLS 1.1.
3
225
286
Hey @thedarktangent, https://t.co/HQ2feHZfWR is TLS 1.3 intolerant and will break in Chrome & Firefox soon. Are you running a prerelease OpenSSL 1.1.1? They had a version negotiation bug:
github.com
OpenSSL 1.1.1-pre6 and below fail during a handshake with an RFC TLSv1.3 implementation. These versions get confused and think they have seen the draft version that is acceptable to them (draft-26 ...
0
2
6
IT'S ALIVE! chrome 68 rolls to stable today, and with it, all HTTP pages are marked "not secure". happy "HTTP-bad" day, internet! ๐พ๐ https://t.co/ZPSWwZ3l8w
๐โ ๏ธ The moment we've all been waiting for! Chrome will mark all HTTP sites as "Not secure" in July 2018. ๐โ ๏ธ https://t.co/2eV4GuEa2y
6
254
397
After lots of incredibly hard work by a ton of folks on Chrome, full site isolation is reality on desktop: https://t.co/3KR1xdwKUk. Thank you everyone who has helped, too long of a list to include!
security.googleblog.com
Posted by Charlie Reis, Site Isolator Speculative execution side-channel attacks like Spectre are a newly discovered security risk for web...
7
88
188
check out our roadmap for the next ~6 months of Chrome security indicators! https://t.co/P2Pu2yn3n9 (h/t @emschec)
blog.chromium.org
Previously, we posted a proposal to mark all HTTP pages as definitively โnot secureโ and remove secure indicators for HTTPS pages. HTTPS us...
3
34
64
TLS 1.3 (draft 23) is rolling out with Chrome 65! Let's hope it sticks. Third time's the charm?
4
53
175
๐โ ๏ธ The moment we've all been waiting for! Chrome will mark all HTTP sites as "Not secure" in July 2018. ๐โ ๏ธ https://t.co/2eV4GuEa2y
security.googleblog.com
Posted by Emily Schechter, Chrome Security Product Manager For the past several years, weโve moved toward a more secure web by strongly adv...
33
869
1K
Dear Lazy Twitter: does anyone have a contact at Fortinet (r.e. their TLS inspection)?
1
7
6
Next steps: marking more HTTP pages as "not secure" in Chrome https://t.co/UIamPZLXC6 ๐๐
8
235
400