Feisty Duck
@feistyduck
Followers
2K
Following
131
Media
469
Statuses
2K
The place for TLS and PKI education. Publishers of Bulletproof TLS and PKI. Authors of Practical TLS and PKI training. Cryptography & Security Newsletter.
London, UK
Joined March 2009
Black Friday Discounts from Feisty Duck (No.3) - 50% off on ModSecurity Handbook (Ebook)! https://t.co/3k4RCXgU6t
0
1
1
Black Friday Discounts from Feisty Duck (No.2) - 10% off Practical TLS and PKI Training. Even on Early Bird tickets! From $1,485. One week only. https://t.co/CbXW4W87yj
@ivanristic @Scott_Helme
0
2
1
Black Friday Discounts from Feisty Duck (No.1) - 50% off on Bulletproof TLS and PKI (Ebook). Just for one week! https://t.co/RFochnkwVw
0
3
5
Cryptography & Security Newsletter is out! In this issue: - The Legend of Kipp Hickman - Short News https://t.co/GLeNGOPOjL
0
1
2
New dates! Practical TLS and PKI Training - 23-26 Feb 2026. We have a limited number of Early Bird tickets available. From @ivanristic and with @Scott_Helme, based on Bulletproof TLS and PKI. https://t.co/WoIEqEqWTH
0
2
1
One week to go and still with $500 off! Practical TLS and PKI Training, Nov 10-13 - Dive deep into @ivanristic's materials and be inspired by @Scott_Helme's passion for the subject. https://t.co/WoIEqEqp49
0
1
1
Cryptography & Security Newsletter is out! In the October issue: Web PKI Ditches TLS Client Authentication - How Many Public PKIs Are There? - Impact on Certificate Transparency Short News https://t.co/ySNMx2CiEs
0
1
2
Halloween Discount on Practical TLS and PKI Training! đ $500 off on the final training of the year, Nov 10-13. For devs and sysadmins: how to deploy secure servers and design secure web applications https://t.co/WoIEqEqp49 From @ivanristic and with @Scott_Helme!
0
2
3
Tile trackers, used by 88 million people worldwide, send critical data without encryption. https://t.co/CzToHwlc1G
archive.ph
archived 29 Sep 2025 16:21:12 UTC
0
0
2
David Adrian (who works for Google on Chrome security) doesnât think Web PKI needs revocation.
dadrian.io
Adam Langley wrote about how revocation in the Web PKI doesnât work over 10 years ago. Since then, the Web PKI has drastically changed for the better, despite not appearing to âsolveâ revocation....
0
0
1
Filippo Valsorda is looking at how to best archive CT logs for posterity.
0
0
1
Over at CA/Browser Forum, post-quantum cryptography is now part of S/MIME Basic Requirements, via ballot SMC013.
cabforum.org
The Intellectual Property Review (IPR) period for Ballot SMC013 (Enable PQC Algorithms for S/MIME) has completed. No IPR Exclusion Notices were filed, and the ballot is adopted as of August 22, 2025....
0
0
0
The previously failed attack on lattice-based cryptography is allegedly coming back after fixes.
linkedin.com
New paper that shows that the lattice attack on quantum computers from April 2024 (https://lnkd.in/eqnUknkg) may be revived: more work needed to study this. No reason to panic, but we can all agree...
0
0
1
Our final training of 2025 will take place on 10-13 November, 8am-11:30am PT. Join us! https://t.co/WoIEqEqp49 From @ivanristic and with @Scott_Helme.
0
2
2
An article from Metalhearfâs Blog has more information on the countriesâ positions.
metalhearf.fr
The EU is pushing legislation that would scan all our private messages, even in encrypted apps.
0
0
1
A whistleblower has sued Meta over alleged WhatsApp security flaws. https://t.co/74mB5T2VoS
web.archive.org
In a lawsuit filed Monday, the former head of security for the messaging app accused the social media company of putting billions of users at risk. Meta pushed back on his claim.
0
0
1
Appleâs new phones come with a new feature called Memory Integrity Enforcement, which makes exploitation more difficult.
0
0
1
Video recordings of DigiCertâs World Quantum Readiness day are now available.
0
1
3
Luke Valenta writes at length about the difference between post-quantum cryptography and quantum security technology. You need the former, not necessarily the latter.
blog.cloudflare.com
Post-quantum cryptography protects against quantum threats using todayâs hardware. Quantum tech like QKD may sound appealing, but it isnât necessary or sufficient to secure organizations.
0
1
3
The related Hacker News discussion has some additional interesting information.
0
0
0