
 Security Now (Audio)
 Security Now (Audio) SN 1042: Letters of Marque - 1.1.1.1 Certificate Snafu
 80 snips 
 Sep 10, 2025  The potential legalization of 'hack back' missions could turn companies into cyber warriors, blurring defense and retaliation lines. Google faces backlash for allegedly blackmailing security researchers. Artists encounter threats as AI seeks to use their work without consent. Misissued TLS certificates highlight trust issues in cybersecurity. Ongoing legal battles between Apple and the UK raise privacy concerns. Can the software supply chain ever be trusted? The intersection of AI and cyber threats complicates the landscape, making vigilance and ethical considerations more crucial than ever. 
 AI Snips 
 Chapters 
 Books 
 Transcript 
 Episode notes 
Email Replaced X For Real Interaction
- Steve Gibson recounts shifting his primary feedback channel from X to email after losing a blue checkmark.
- He notes email now delivers meaningful listener feedback and better interaction than X DMs.
Single CA Can Break Global Trust
- Misissued TLS certificates for 1.1.1.1 exposed how a single weak CA can undermine broad trust.
- Microsoft trusted a CA others (Google, Mozilla, Apple) did not, creating a platform-specific risk.
Actively Watch Certificate Transparency
- Monitor Certificate Transparency logs for your domains and automate alerts on unexpected entries.
- Use different test keys for internal work and never sign tests with production root keys.






