An essay on CAs revoking Windows code-signing certs for malware, and why PKI was never meant to be a software cop.
trending3
01 02 So the question is, will Microsoft get code signing and TLS 1.3 onto post-quantum crypto before 2029?03 Deep dive on Windows revocation providers and trust validation, for when CRL/OCSP's good enough is apparently not.