The NSPW implements an excellent format:
A one-hour session is dedicated to each accepted paper, during which it is discussed jointly by all participats.
NSPW'25 will be held in Germany this year, submission deadline: April 25!
https://t.co/g2nGU0en6n
Booyah, our paper on Ethical Reviewing Procedures in CS Research was finally published at #NSPW 🥳
(although, unsure if Ethics is a thing on X...)
@SebGiessler@sahiralsaid @datenkeller
https://t.co/KxkbdOq5w8
Ethical challenges in cybersecurity conferences. Deeply disturbing and thanks @acm_ccs for sharing this openly.
This calls for action or we risk of devaluing (even more) any research: papers should be byproducts of true and honest advances, not mere numbers.
Das Bundeskabinett hat heute die Reform des #WissZeitVG beschlossen. Damit verbessern wir die Arbeitsbedingungen für #Wissenschaftlerinnen und #Wissenschaftler. 🎓
Alle Details sind hier nachzulesen: https://t.co/ED2LKMw237
Well, shit.
Encrypted traffic interception on Hetzner and Linode targeting https://t.co/wrWg1FCVNp, the largest Russian XMPP (Jabber) messaging service.
The instant messaging have been wiretapped for 3 months, on both hosting providers in Germany.
https://t.co/MIof2vET4B
Many misunderstandings surround WebPKI. A significant misconception is that the CA/Browser Forum (CABF) decides which Certificate Authorities (CAs) are trusted; in reality, each browser has its own trust criteria, usually including an audit to ensure CAs meet the CABF's requirements. How do I know? I worked with auditors to develop the original WebTrust for CA requirements, establishing it as a baseline for technical and operational standards for CAs to be trusted in the Microsoft Root Program, the first to mandate such an audit.
The CABF later emerged to streamline audit criteria maintenance, fostering a more open, transparent, and inclusive process. These third-party audits were meant to supplant the pay-for-play model used by many root programs at the time with objective standards, not to replace root program criteria. Don't believe me? Notice that no document or policy from the CABF dictates browser practices, only CAs and a valid WebTrust audit alone are insufficient for inclusion in any root program I am aware of.
CAs often claim they've championed security improvements in WebPKI through the CABF. However, these initiatives have typically been public relations responses to wider ecosystem failures. For example, the DigiNotar breach in 2011 prompted the CABF to establish the Network Security Requirements, which were basically reiterating security measures from the 1990s that DigiNotar neglected, leading to browsers' eventual distrust of this EU CA.
CAs also purport to lead industry adoption by advancing best practices, but they have actually delayed vital WebPKI security updates. SHA1 vulnerabilities persisted because CAs blocked the discontinuation of its use in the CABF. It was only when browsers stood firm and mandated the change that it occurred. The Certificate Authority Authorization (CAA) record also met with CA opposition in the CABF for nearly two years until browsers made it a requirement.
At the dawn of WebPKI, domain control verification lacked formal requirements, leading to the forced acceptance of the ambiguous "Any Other Method" as a condition of agreement with CAs in the CABF. Despite years of efforts to abandon this method, it continued until Firefox's intervention led the CABF to finally phase it out.
CAs have also resisted efforts to make the domain control verification process used in certificate issuance an attribute in certificates for longer than I can count -- opposition by CAs has made this impossible. Then there is the topic of Certificate Transparency -- is it required by the CABF guidelines? No, it is not; it is a browser requirement that started with one browser and then slowly spreads to others. It would have never been possible within the CABF. After all, the purpose of this system is to enable browsers to hold CAs accountable for misissuance and to make that issuance transparent and verifiable to the relying parties and subscribers on the web. Why would CAs vote for something like that? How could a group that takes years to make the smallest changes manage an ecosystem like CT that requires agility at its core? They couldn't.
In short, browsers—acting on behalf of users—have been the real drivers of web security advancements, often despite CAs' reluctance. Now, with regulatory "air-cover" sought by CAs, the EU, through eIDAS 2.0 revisions, aims to curb browsers from safeguarding users and to continue evolving WebPKI as the web itself evolves.
The consequences of this extend beyond the EU's 27 member states and affect the entire internet, like all the other `Brussels effect` laws that require companies that do business with Europe to comply with the various technology laws they pass.
To understand the proposal here, it is useful to understand what the WebPKI looks like today. Right now there are 7 of approximately 85 CAs that account for 99% of all certificate issuance on the web. The remaining CAs, which are broadly not engaged in the CABF at all, exist because the root programs that are operated by browsers are now based on open and objective criteria, and are run in that way because there is a desire that the web be global and inclusive. It’s important to note that despite these noble intentions, these long-tail CAs, most of which are European, arguably represent an unnecessary attack surface for everyone on the web. The reality is that once you are a trusted WebPKI CA, you can impersonate any internet website you want with near impunity; without Certificate Transparency, these impersonations would never be detected.
What the EU’s proposal does is replace the demonstrably competent browser root programs with regulators and bureaucrats; it forces them to readopt practices that have been discontinued due to their objective negative security consequences, and at the same time, sets up each member state to be in the position to add CAs for observing internet traffic if they so choose. To be clear, I do not believe that is their intent, but that is surely the consequence of what is being proposed.
While I hope this isn’t the case, and maybe you are fine with the EU having the ability to do these things, did you know there are 195 sovereign countries, each eager for similar control?
Even though this impacts every citizen on the web, the only people the EU is likely to listen to on this topic will be European citizens. If that describes you, please speak up -- the web needs you.
The fragmentation of the internet has both, its pro's and con's. Not only in times of crisis, however, the discord of key actors can risk the security of users.
Looking forward to discuss this topic at @_eurodig tomorrow during the Internet Fragmentation Session (#Resilience).
Today we present our ideas about how to integrate ethical reviewing in CS Research at @univienna @STSvienna! Looking forward to some interdisciplinary exchange 🥳 @SebGiessler@sahiralsaid
The program is finalized; we have a great line up of speakers (incl 2 fantastic keynotes) – come join us in 2 weeks to discuss the changing roles and politics of #research#infrastructures @STSvienna @univienna !
thx to Kaye, Noah and @Ulrike_Felt for this joint effort!
I am presenting our proposed extention for Certificate Transparency (LogPicker, PETS'21) on #IETF116 during Thursday's #PEARG session.
If you couldn't make it to Yokohama you can also participate online, just like me 🧙♀️
Select sessions from #IETF116 (25-31 March 2023) hosted by @WIDE_Project will be streamed live! Recordings of all sessions will be available shortly after they conclude. Registration for onsite or remote participation is still available. Learn more at: https://t.co/tMh5xdwShe
The @CensoredPlanet dashboard has updated its default view to focus on some important sites that are often blocked, giving you a quick characterization of what's going on in a country. This has never been easier! 🤩
The Domain dropdown lets you select other sites if you need.