Security Now (Audio)

SN 1042: Letters of Marque - 1.1.1.1 Certificate Snafu

26 snips
Sep 10, 2025
The potential legalization of 'hack back' missions could turn companies into cyber warriors, blurring defense and retaliation lines. Google faces backlash for allegedly blackmailing security researchers. Artists encounter threats as AI seeks to use their work without consent. Misissued TLS certificates highlight trust issues in cybersecurity. Ongoing legal battles between Apple and the UK raise privacy concerns. Can the software supply chain ever be trusted? The intersection of AI and cyber threats complicates the landscape, making vigilance and ethical considerations more crucial than ever.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
ANECDOTE

Email Replaced X For Real Interaction

  • Steve Gibson recounts shifting his primary feedback channel from X to email after losing a blue checkmark.
  • He notes email now delivers meaningful listener feedback and better interaction than X DMs.
INSIGHT

Single CA Can Break Global Trust

  • Misissued TLS certificates for 1.1.1.1 exposed how a single weak CA can undermine broad trust.
  • Microsoft trusted a CA others (Google, Mozilla, Apple) did not, creating a platform-specific risk.
ADVICE

Actively Watch Certificate Transparency

  • Monitor Certificate Transparency logs for your domains and automate alerts on unexpected entries.
  • Use different test keys for internal work and never sign tests with production root keys.
Get the Snipd Podcast app to discover more snips from this episode
Get the app