Sign in

David Adrian

@dadrian.io
590 followers 101 following 264 posts

Used to do TLS, still kind of do TLS. Former Chrome Security. Founded Censys. @scwpod.bsky.social

PostsRepliesMedia
David Adrian @dadrian.io · 27/09/2026
I told yall
020
David Adrian @dadrian.io · 26/09/2026
It’s that time of the week. #GoBlue
162
David Adrian @dadrian.io · 13/09/2026
hey now score probability graphs only do this when the team is under extreme duress
020
David Adrian @dadrian.io · 13/09/2026
Texas back y’all
031
David Adrian @dadrian.io · 13/09/2026
I was told Texas was back.
010
David Adrian @dadrian.io · 13/09/2026
Ryan Day looks like the evil robot Santa Claus from Santa Clause 2
001
David Adrian @dadrian.io · 12/09/2026
Michigan football
static.klipy.com
Get The Word Out There
ALT: Get The Word Out There
050
David Adrian @dadrian.io · 06/09/2026
The horror can vote today.
000
David Adrian @dadrian.io · 27/08/2026
Since the last time Peikert was on, Michigan football and Michigan basketball both won a national championship. That's the new bar for repeat guests.
064
David Adrian @dadrian.io · 23/08/2026
I wrote a post about how security undervalues preventing problems, and how this can be exasperated by AI and the vulnpocalypse, even though AI should actually make robustness much easier for defenders. Read it here: dadrian.io/blog/posts/w...
dadrian.io
Playing whack-a-mole is losing
I want to juxtapose two classes of people in the security industry on the defender side of security engineering for products. The first are the Security as Identity people. This goes back to the secur...
092
Reposted by David Adrian
Deirdre Connolly¹ ² @durumcrustulum.com · 08/08/2026
This was very fun!! Thanks again to our sponsor Teleport 💃🕺
061
Reposted by David Adrian
Security Cryptography Whatever @scwpod.bsky.social · 27/07/2026
Are you coming to Vegas for BlackHat and DEF CON? Come to our happy hour! securitycryptographywhatever.com/events/black...
securitycryptographywhatever.com
SCWPodCon BlackHat 2026
"Security Cryptography Whatever" is hosting a party during BlackHat USA 2026, once again brought to you by Teleport!
142
David Adrian @dadrian.io · 17/07/2026
Wrote another thing dadrian.io/blog/posts/h...
dadrian.io
Hacking is Just Bugs
Movies and video games make it seem like hacking is simply whoever is smarter at computers breaking into someone else’s system. That’s not quite the case. Hacking is the act of exploiting vulnerabilit...
010
David Adrian @dadrian.io · 03/07/2026
New episode! www.youtube.com/watch?v=7ZwQ...
youtube.com
Trump's Golden Post Quantum EOs
YouTube video by Security Cryptography Whatever
021
David Adrian @dadrian.io · 28/06/2026
dadrian.io/blog/posts/t...
dadrian.io
The Late Show
The Late Show always felt like adulthood to me. Growing up, I heard about David Letterman before I was old enough to stay up late enough to watch The Late Show. One of the local radio stations syndica...
120
Reposted by David Adrian
Filippo Valsorda @filippo.abyssdomain.expert · 26/06/2026
securitycryptographywhatever.com/2026/03/25/a... is very very good. If you read my vulnerabilities post, this podcast episode is much more worth listening to.
securitycryptographywhatever.com
AI Finds Vulns You Can’t With Nicholas Carlini
Returning champion Nicholas Carlini comes back to talk about using Claude for vulnerability research, and the current vulnpocalypse. It’s all very high-brow ...
0377
Reposted by David Adrian
serena (𝑂𝑓𝑓𝑙𝑖𝑛𝑒) @serena.nz · 11/05/2026
american culture is when drink is big
181
David Adrian @dadrian.io · 15/06/2026
New episode! We talk to @lcamtuf.coredump.cx about the vulnpocalypse. www.youtube.com/watch?v=uI9C...
youtube.com
Facing the Vulnpocalypse with lcamtuf
YouTube video by Security Cryptography Whatever
172
David Adrian @dadrian.io · 01/05/2026
I poked around with @exe.dev some, and wrote up how I think their Github integration works, because it's pretty cool. dadrian.io/blog/posts/e...
dadrian.io
Proxies all the way down.
A couple of days ago, exe.dev raised a lot of money1. I decided to poke around with it a little, and signed up. Their trial is 7 days long, so despite having no actual plans, I just started doing stuf...
030
Reposted by David Adrian
PTKU Mega-Booster @emgoblue2023.bsky.social · 24/04/2026
Dad’s home $1 for every attendee of 13-10 #charitibundibowl @newap-georgia.bsky.social
$106005 wire transfer to New American Pathways
6550253
Reposted by David Adrian
Thomas Ptacek @sockpuppet.org · 30/03/2026
I wrote something: sockpuppet.org/blog/2026/03...
sockpuppet.org
Vulnerability Research Is Cooked
79639
Reposted by David Adrian
Security Cryptography Whatever @scwpod.bsky.social · 26/03/2026
NEW EPISODE! The gang learns a bitter lesson about AI and bug finding! Returning champion Nicholas Carlini is back to talk about Claude for vulnerability research. securitycryptographywhatever.com/2026/03/25/a... www.youtube.com/watch?v=_IDb...
youtube.com
AI Finds Vulns You Can't With Nicholas Carlini
YouTube video by Security Cryptography Whatever
2114
Reposted by David Adrian
Chris Peikert @chrispeikert.bsky.social · 23/03/2026
new Joy of Cryptography just dropped (feat. Post-Quantum Crypto)
Cover of “The Joy of Cryptography” by Mike RosulekPart of the table of contents including a chapter on post-quantum cryptography
1548
Reposted by David Adrian
Thomas Ptacek @sockpuppet.org · 14/03/2026
Extremely psyched about two upcoming SCW guests, one of them this week. We've got very crunch vulnerability research and cryptography stuff coming.
0243
Reposted by David Adrian
Deirdre Connolly¹ ² @durumcrustulum.com · 27/02/2026
new Merkle Tree Cert only Chrome Quantum Root Store: security.googleblog.com/2026/02/cult...
security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Posted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against ...
083
Reposted by David Adrian
Thomas Ptacek @sockpuppet.org · 28/02/2026
None of you are giving me enough credit for not participating on the TLS working group mailing list. You're welcome. Everything I don't do, I don't do it for you.
2262
David Adrian @dadrian.io · 18/02/2026
Who up losing they minds on this site?
110
Reposted by David Adrian
Security Cryptography Whatever @scwpod.bsky.social · 02/02/2026
NEW EPISODE! The maintainers of py/cryptography declared that after many years of trying to make it work, they would be moving away from OpenSSL when supporting new functionality and exploring adding other backends: securitycryptographywhatever.com/2026/02/01/p... www.youtube.com/watch?v=dEKB...
youtube.com
Python Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex Gaynor
YouTube video by Security Cryptography Whatever
5205
David Adrian @dadrian.io · 23/01/2026
Thinking about Curt Cignetti.
000
David Adrian @dadrian.io · 21/01/2026
I cannot get over how impressive it is what Curt Cignetti accomplished at Indiana
010
David Adrian @dadrian.io · 20/01/2026
Indiana shall light this holy ring, release its cleansing flame, and burn a path into the divine beyond!
011
Reposted by David Adrian
rmhrisk @rmhrisk.bsky.social · 16/01/2026
This is what zero-trust looks like at the infrastructure layer. Identity and encryption match the lifetime of the thing being secured. If your certificate strategy still assumes stable names and year-long validity, it is already behind reality. letsencrypt.org/2026/01/15/6...
letsencrypt.org
6-day and IP Address Certificates are Generally Available
Short-lived and IP address certificates are now generally available from Let’s Encrypt. These certificates are valid for 160 hours, just over six days. In order to get a short-lived certificate subscr...
021
Reposted by David Adrian
Deirdre Connolly¹ ² @durumcrustulum.com · 12/01/2026
dadrian.io/blog/posts/s...
dadrian.io
Stop inventorying keys.
If you have a reason to migrate to post-quantum cryptography (PQC), you should not be inventorying keys for the purpose of migration, and you should stop listening to anyone who suggests that you do s...
052
Reposted by David Adrian
Deirdre Connolly¹ ² @durumcrustulum.com · 12/01/2026
0104
David Adrian @dadrian.io · 10/01/2026
repent! for the day of sixteen windiana shall be upon us!
020
Reposted by David Adrian
Thomas Ptacek @sockpuppet.org · 31/12/2025
Final SCW of 2025! We had Matt Bernhard on to talk about cryptographic voting systems, in the wake of the IACR election. (Everybody I voted for in the new election won! Woo!)
093
Reposted by David Adrian
Joseph Lorenzo Hall, PhD @josephhall.org · 31/12/2025
What a fantastic present to end the year! (swear I woke up like this) @mbernhard.com @durumcrustulum.com @sockpuppet.org @dadrian.io @scwpod.bsky.social
A selfie of Joe Hall, a smiling man with a salt-and-pepper beard and glasses, standing in front of a brightly lit Christmas tree. He is wearing a black t-shirt with the text "Security. Cryptography. Whatever." in blue lettering, representing the SCW Podcast. The tree is decorated with colorful ornaments and topped with a glowing gold star.
171
Reposted by David Adrian
Filippo Valsorda @filippo.abyssdomain.expert · 24/11/2025
This Bernstein crap drives me up the wall because IT MAKES NO SENSE. Why would the NSA be picking weak crypto to protect US NatSec?! They have mathematicians and clusters in China, too! Dual_EC_DRBG was a NOBUS backdoor. There is NOWHERE to hide a NOBUS backdoor in ML-KEM.
6626
Reposted by David Adrian
Jeff Hodges @jmhodges.bsky.social · 28/10/2025
Wonderful news! The kind of thing a lot of software folks across the world have been working to make possible. So stoked the Chrome folks are pushing us forward
051
Reposted by David Adrian
Andrew Whalley @arw.me · 28/10/2025
It's time to make HTTPS the web's default, and reap the full security benefit from years worth of HTTPS adoption! security.googleblog.com/2025/10/http...
security.googleblog.com
HTTPS by default
One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secu...
38926
David Adrian @dadrian.io · 28/10/2025
One year from now, Chrome will enable "Always Use Secure Connections" and warn users before plaintext HTTP by default.
security.googleblog.com
HTTPS by default
One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secu...
0168
David Adrian @dadrian.io · 20/09/2025
Iowa-Rutgers hitting the over? Trump ruined the B1G West.
000
David Adrian @dadrian.io · 11/09/2025
New post! Stop trying to solve revocation, we already have the answer. dadrian.io/blog/posts/r...
dadrian.io
Revocation ain't no thang.
Adam Langley wrote about how revocation in the Web PKI doesn’t work over 10 years ago. Since then, the Web PKI has drastically changed for the better, despite not appearing to “solve” revocation. Unfo...
041
David Adrian @dadrian.io · 06/09/2025
Kirk Herbstreit is going to be the first person to make a Golden Retriever unlikable.
011
Reposted by David Adrian
rmhrisk @rmhrisk.bsky.social · 03/09/2025
The bigger issue? Microsoft’s root program still trusts this CA, leaving Edge and Windows users exposed in ways Chrome, Firefox, and Safari users aren’t. The pattern is familiar: long-lived trust, weak oversight, systemic risk. It’s time for Microsoft to step up and fund proper root governance. 👇
unmitigatedrisk.com
Another Sleeping Giant: Microsoft’s Root Program and the 1.1.1.1 Certificate Slip | UNMITIGATED RISK
231
David Adrian @dadrian.io · 02/09/2025
If you look closely, you can see UNC’s quarterback is not Tom Brady
131
Reposted by David Adrian
Matt Bernhard @mbernhard.com · 30/08/2025
This game has me feeling like I'm watching Iowa play Iowa.
021
David Adrian @dadrian.io · 29/08/2025
Sent this to a girl in California and pretty sure she thinks it’s in another language
120
David Adrian @dadrian.io · 23/08/2025
Come for the PGP dunks, stay for the broader discussion of why encrypted email doesn’t make sense
0127
Reposted by David Adrian
Simon Fondrie-Teitler @simon.overgrown.garden · 17/08/2025
The first part of this interview with my ex-colleague Alex is a great listen if you're a software engineer (or otherwise technical) and are interested in what we were working on as technologists at the Federal Trade Commission.
032