

SN 1042: Letters of Marque - 1.1.1.1 Certificate Snafu
26 snips Sep 10, 2025
The potential legalization of 'hack back' missions could turn companies into cyber warriors, blurring defense and retaliation lines. Google faces backlash for allegedly blackmailing security researchers. Artists encounter threats as AI seeks to use their work without consent. Misissued TLS certificates highlight trust issues in cybersecurity. Ongoing legal battles between Apple and the UK raise privacy concerns. Can the software supply chain ever be trusted? The intersection of AI and cyber threats complicates the landscape, making vigilance and ethical considerations more crucial than ever.
AI Snips
Chapters
Books
Transcript
Episode notes
Email Replaced X For Real Interaction
- Steve Gibson recounts shifting his primary feedback channel from X to email after losing a blue checkmark.
- He notes email now delivers meaningful listener feedback and better interaction than X DMs.
Single CA Can Break Global Trust
- Misissued TLS certificates for 1.1.1.1 exposed how a single weak CA can undermine broad trust.
- Microsoft trusted a CA others (Google, Mozilla, Apple) did not, creating a platform-specific risk.
Actively Watch Certificate Transparency
- Monitor Certificate Transparency logs for your domains and automate alerts on unexpected entries.
- Use different test keys for internal work and never sign tests with production root keys.