RSSAmplifier

Blog

Insufficient.Coffee

On a mission to solve communications security issues for the whole Internet. That, and drink coffee.

insufficient.coffeeRSS feed ↗48 posts

Latest posts

Reflecting on 10 years of Let's Encrypt

My friend Christophe Brocas has just published a retrospective on the ten years since we unveiled the ACME protocol to the world . He interviewed me and some colleagues for the piece, and I recommend it!

The Open Source Cryptography Workshop is returning for 2026

After taking a year off from organizing OSCW 2025, I'm back for next year's event in Taipei .

Attending Real World Crypto and the Open Source Cryptography Workshop 2024

I'll be attending the Real World Crypto Symposium in Toronto in two weeks time, and after that, I'm once again co-organizing the Open Source Cryptography Workshop .

Make It Memory Safe: Adapting curl to use Rustls

As I mentioned in my post about attending Real World Crypto 2023 and the Open Source Cryptography Workshop , I've given a talk discussing Rustls-FFI and the work to allow curl and libcurl to use the Rust-based, memory-safe Rustls TLS library in a talk called Make It Memory Safe: Adapting Curl to use Rustls .

Nevermind about RWC and OSCW: COVID instead

At this point I'm supposed to be in Tokyo, attending the Real World Crypto Symposium in Tokyo next week, and after that, I'm co-organizing and speaking at the Open Source Cryptography Workshop . But I've gotten COVID-19 again, instead.

Attending Real World Crypto and the Open Source Cryptography Workshop 2023

I'll be attending the Real World Crypto Symposium in Tokyo next week, and after that, I'm co-organizing and speaking at the Open Source Cryptography Workshop .

Moving Human Blood Around Arizona

I'd never thought about the logistics of moving donated blood around. The actual donation part is known to be a universally good thing to do, but I'd never searched out what happens next until I heard a fellow pilot talk about volunteering to move platelets around Arizona.…

Design of the CRLite Infrastructure

Firefox is the only major browser that still evaluates every website it connects to whether the certificate used has been reported as revoked. Firefox users are notified of all connections involving untrustworthy certificates, regardless the popularity of the site. Inconveniently, checking certificate status sometimes slows down the connection to websites. Worse, the check reveals cleartext…

Auditing the CRLs in CRLite

Since Firefox Nightly is now using CRLite to determine if enrolled websites' certificates are revoked, it's useful to dig into the data to answer why a given certificate issuer gets enrolled or not.…

Querying CRLite for WebPKI Revocations

Firefox Nightly is now using CRLite to determine if websites' certificates are revoked — e.g., if the Certificate Authority published that web browsers shouldn't trust that website certificate. Telemetry shows that querying the local CRLite dataset is much faster than making a network connection for OCSP , which makes intuitive sense. It also avoids sending the website's certificate…

Austin or Bust: A Post-Y'allhands Adventure

Due to a variety of factors, Mozilla changed venues for our 2017 winter all-hands meeting to Austin, Texas, and Austin being a city with relatively poor commercial airline connectivity, ticket prices were fairly high even for me to fly there from Phoenix.…

Berlin By Air

I have had business dealings requiring me to visit Berlin regularly for the last 5 years, and in 2018 I finally made the trip outside of the city to Strausberg Airport to rent a Cessna 172SP Skyhawk.…

Returning Home and Flying in Northwest Florida

While I lived in a lot of different places as a child, I came of age along the Florida panhandle, and for that reason it'll always hold a special place in my heart.…

Watching Hawaii Boil the Pacific Ocean

I've had a lot more opportunity to travel since I joined Mozilla , and it eventually occurred to me: I could rent aircraft in some of these places I was visiting, and see those places in a different way.…

Blog upgrades and a long-awaited new domain, insufficient.coffee

I've been running this blog on an LTS version of Ubuntu that has recently halted Long Term Support, so while migrating data I'm also reworking parts of this blog, including a long-anticipated move from tacticalsecret.com (what a ... term) to the timeless domain insufficient.coffee .…

CRLite: Speeding Up Secure Browsing

CRLite pushes bulk certificate revocation information to Firefox users, reducing the need to actively query such information one by one. Additionally this new technology eliminates the privacy leak that individual queries can bring, and does so for the whole Web, not just special parts of it.…

Introducing CRLite: All of the Web PKI’s revocations, compressed

CRLite is a technology proposed by a group of researchers at the IEEE Symposium on Security and Privacy 2017 that compresses revocation information so effectively that 300 megabytes of revocation data can become 1 megabyte.

The End-to-End Design of CRLite

CRLite is a technology to efficiently compress revocation information for the whole Web PKI into a format easily delivered to Web users. It addresses the performance and privacy pitfalls of the Online Certificate Status Protocol (OCSP) while avoiding a need for some administrative decisions on the relative value of one revocation versus another.…

Web Authentication in Firefox for Android

Firefox for Android (Fennec) now supports the Web Authentication API as of version 68 .

Making HTTPS Revocations Work: CRLite (Lightning Talk)

I gave a lightning talk at our Mozilla All-Hands meeting about CRLite , a new technology for delivering revocations for the Web PKI to all clients in a very compressed form.

Trying Out Web Authentication (WebAuthn)

Web Authentication is now enabled in Firefox Nightly , with intent to ship in version 60 .

Countering Phishing with Cryptography - WebAuthn (Lightning Talk)

At Mozilla's Austin All-Hands I gave a lightning talk about Web Authentication , which is our best technical solution to the scourge of phishing today.

The State of CRLs Today

Certificate Revocation Lists (CRLs) are a way for Certificate Authorities to announce to their relying parties (e.g., users validating the certificates) that a Certificate they issued should no longer be trusted. E.g., was revoked.…

Cutting over Let's Encrypt's Statistics to Map/Reduce

We're changing the methodology used to calculate the Let's Encrypt Statistics page , primarily to better cope with the growth of Let's Encrypt. Over the past several months it's become clear that the existing methodology is less accurate than we had expected, over-counting the number of websites using Let's Encrypt, and the number of active certificates. The new…

Analyzing Let's Encrypt statistics via Map/Reduce

I've been supplying the statistics for Let's Encrypt since they've launched. In Q4 of 2016 their volume of certificates exceeded the ability of my database server to cope, and I moved it to an Amazon RDS instance.…

The end of SHA-1 on the Public Web

Our deprecation plan for the SHA-1 algorithm in the public Web, first announced in 2015 , is drawing to a close. Today a team of researchers from CWI Amsterdam and Google revealed the first practical collision for SHA-1 , affirming the insecurity of the algorithm and reinforcing our judgment that it must be retired from security use on the Web.

Demoing Let's Encrypt at the Phoenix DevOps Meetup in February

The Phoenix DevOps Meetup has asked me to do a walk-through of how to encrypt a website using Let's Encrypt for their February meetup . I don't believe this talk will be recorded, but for any locals who want to discuss PKI, I'll be available after.

A Big Tent in America

The electoral college has legitimized an agenda that seeks to tell many of my friends and colleagues that they are not welcome in America. That they are only to be tolerated in the shadows. That denigrating them is acceptable national discourse, and will be rewarded with prestige.…

Let's Encrypt's Growth to 10 Million Active Unique FQDNs

Yesterday Let's Encrypt reached a new milestone: the unique set of all fully-qualified domain names in the currently-unexpired certificates issued by Let's Encrypt is now 10,022,446 .…

Long Instrument Cross-Country Training Flight

I'm training to be able to fly in clouds and other poor visibility situations. Part of the requirements for this "Instrument Rating" is to fly cross-country, on instrument rules, and do instrument landings at three airports, a task I undertook last Friday…

Utility of an Instrument Rating

I am training right now for my instrument rating add-on to my private pilot certificate. For years I said that there was little point to me having this rating, because in Arizona, when there is weather, you don't want to fly in it.

The Road to Encrypting All The Things: RMLL 2016 (Paris)

Today at the RMLL conference's security track I'm talking about some of the challenges, decisions, and trade-offs that occurred while launching Let's Encrypt, in a talk I've called Let’s Encrypt: The Road To Encrypting All The Things .

124 Days of Let's Encrypt

This is a quick status update from the Early Impacts of Let's Encrypt post.…

Early Impacts of Let's Encrypt

During the months I worked in Let's Encrypt's operations team I got fairly used to being the go-to man for any question that a database query could solve.…

Issuance Rate for Let's Encrypt

Gathering data from Certificate Transparency logs , here's a snapshot in time of Let's Encrypt's certificate issuance rate per minute from 15-21 January 2016

Content Security Policy Enabled

I spent some time over the last week working up a safe Content Security Policy for this website

Renewing Let's Encrypt Certs (Nginx)

All the first Let's Encrypt certs for my websites from the LE private beta began expiring last week, so it was time to work through the renewal tooling

Let's Encrypt: Publicly Trusted

A bigger blog post will have to wait, but just as a brief note: Let's Encrypt is now publicly trusted . In fact, this blog is using a certificate from Let's Encrypt. And so is usr.bin.coffee , of course.

Beta Testing Let's Encrypt

One of the advantages to being part of the Let's Encrypt team is early access to the closed beta. As such, I've been able to issue a handful of certificates from the service. For example: usr.bin.coffee . There's a lot of other upsides as well, such as working with incredible people to make something super-high visibility for the public good.

GatorLUG Presentation on Let's Encrypt

GatorLUG has invited me to talk about Let's Encrypt at their April 2015 meeting. I'm honored to be playing a role in the architecture and implementation of Let's Encrypt; here are the slides I'll be presenting .

Updated JSONResume

I've posted a new version of my Bootstrap Icons theme for JsonResume

Net Neutrality

Last night I received this political cartoon in my email:…

Service Assisted Communication and Simplifying a PKI

Because many of the devices in the IoT are headless and have limited ability to interact with their owners, there needs to be a way to authenticate them without passwords, and without the shortcomings of the existing 0000 and 1234 problems in the Bluetooth world.

JSONResume

There's a quirky little project on the Internet proving once again that semi-structured data is just plain fun: JSONResume.org .

Garden Imp

Using an Electric Imp and two Vegetronix VH400 soil moisture sensors , I am now able to monitor the water content of two locations in my garden.

Different PAN Parts: Auth-Only, Confidential and No Consequence

Where the Internet of Things meets locations in the physical world, I envision scores of devices networking together to make life more efficient…

Public Authentication

The public authentication problem is one we have all learned to solve with intuition: How do I decide to trust a new person? …

Prevalence of Well Known Peers in the Internet of Things

The Internet of Things is imagined to be a interconnection of sensors and physical devices of all kinds into the world’s information systems: a collection of machine-to-machine communication devices used to gather and distribute information about the world, contrasted with the human-machine interactions making up the bulk of today’s Internet. The machine-to-machine model places new restrictions on…