Sign in

Emily Stark

@estark.bsky.social
3.3K followers 273 following 32 posts

Encryption, HTTPS, certificates, web security, security UX, software engineering and management, TMI about parenting. Opinions are my own.

PostsRepliesMedia
Reposted by Emily Stark
David Adrian @dadrian.io · 28/10/2025
One year from now, Chrome will enable "Always Use Secure Connections" and warn users before plaintext HTTP by default.
security.googleblog.com
HTTPS by default
One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secu...
0168
Reposted by Emily Stark
Matt M @mattm.bsky.social · 14/02/2025
Chrome has published version 1.6 of their root store policy. Notably, this includes a deadline of June 15, 2026 to get TLS Client Auth out from any intermediates under roots in Chrome's program. TLS client cert users from public CAs may need to make changes. www.chromium.org/Home/chromiu...
chromium.org
Chrome Root Program Policy, Version 1.6
1104
Emily Stark @estark.bsky.social · 24/01/2025
Available at aftercare pickup alongside info about district protocols for immigration enforcement. This school district understood the assignment 💜
Handout of detachable cards with scripts in English and Spanish for constitutionally protected responses to immigration enforcement actions
063
Reposted by Emily Stark
Joseph Lorenzo Hall, PhD @josephhall.org · 23/01/2025
Good news, from @mozilla and @risksahead! "New ETSI draft standard on QWACs is good news for safety of European internet users"
securityriskahead.eu
021
Emily Stark @estark.bsky.social · 23/01/2025
Behold, a rare, endangered specimen: a goddamn spine secure.smore.com/n/x03zs-a-me...
secure.smore.com
A Message from Superintendent Baker
Message from Superintendent Dr. John Baker: Dear RCSD Community, Our mission, vision, and values drive the work we do every day in...
181
Reposted by Emily Stark
Filippo Valsorda @filippo.abyssdomain.expert · 02/01/2025
I am convinced 99% of websites should use magic links + passkeys. It bypasses all (debatable) portability objections to passkeys, it’s at least as secure as email-based recovery, as fast as a password manager, it’s available to all users… and importantly, no passwords!
2015431
Reposted by Emily Stark
Michal Špaček @spazef0rze.bsky.social · 12/12/2024
Safari 18.2 released 3 days ago has HTTPS-first/by-default mode: "Safari 18.2 on iOS, iPadOS, and visionOS will always try to load webpages over secure connections first, i.e. HTTPS by default. Only if the secure page load fails will Safari fall back to non-secure HTTP." webkit.org/blog/16301/w...
webkit.org
WebKit Features in Safari 18.2
Today marks the arrival of Safari 18.2.
283
Emily Stark @estark.bsky.social · 26/11/2024
TIL: quokka
110
Emily Stark @estark.bsky.social · 26/11/2024
periods are such unbelievable bullshit
130
Reposted by Emily Stark
April King @april.social · 21/11/2024
Handling Cookies is a Minefield: Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out. grayduck.mn/2024/11/21/h...
facebook errornetflix errorokta errorwhatsapp error
1216853
Reposted by Emily Stark
Bob Lord @boblord.bsky.social · 17/11/2024
Some thoughts on the quiet HTTPS revolution: medium.com/@boblord/the... 🔐
Atomic Age style poster of a man on a laptop in a coffee shop using public wi-fi. The coffee cup says Wi-Fi.
0207
Emily Stark @estark.bsky.social · 16/11/2024
Tiny, impeccable design detail: this children’s jacket is designed to be a hand-me-down
Tag on a children’s jacket showing multiple lines to write names, where each name can be removed once the jacket is handed down to another child
54911
Emily Stark @estark.bsky.social · 15/11/2024
I caught a full vomit into my hands tonight without a single drop hitting the couch, so maybe I do qualify as a medical professional after all
390
Emily Stark @estark.bsky.social · 15/11/2024
My colleague @serena.nz gave an amazing PurpleCon talk describing the behind-the-scenes experience of removing the (in?)famous lock icon from Chrome: www.youtube.com/watch?v=iUAx... One day I aspire to get as many laughs during a talk as a 90s sitcom laugh track 🤩
youtube.com
"🙋❓🙋 why❓🤔 chrome 🌐 🙅🚫 removed 🚫🙅 the 🔒 lock 😮 icon 🤷🤷" - serena chen (purplecon 2024)
YouTube video by purplecon
0152
Emily Stark @estark.bsky.social · 10/11/2024
Could you please remove me? I’m not a medical professional
110
Emily Stark @estark.bsky.social · 09/11/2024
ha, very true :)
010
Emily Stark @estark.bsky.social · 09/11/2024
I seem to have gotten added to some medical starter packs for some reason. If you're following me for medical stuff, sorry, wrong person! Feel free to stick around if you want to answer my random medical questions every time one of my children brings home some weird virus from school.
1150
Emily Stark @estark.bsky.social · 01/11/2024
Bold of you to assume I still haven’t seen Heathers after not asking me whether I’ve seen Heathers yet in at least… 3 years? (I still haven’t seen Heathers. Back to Twitter I go, I guess…)
120
Emily Stark @estark.bsky.social · 01/11/2024
Ok so I guess we’re all doing this app now?
5160
Reposted by Emily Stark
Filippo Valsorda @filippo.abyssdomain.expert · 01/11/2024
We’ve now established a pattern where Go is the first non-browser stack to implement new TLS features, so we flush out all the bugs Chrome didn’t hit. Today it’s tldr.fail. PQ shares were already default in Chrome, but Go 1.23 is surfacing new broken middleboxes. Last time it was X.509 SANs.
tldr.fail
The migration to post-quantum cryptography is being held back by buggy servers that do not correctly implement TLS. Due to a bug, these servers reject connections that use post-quantum-secure cryptography, instead of negotiating classical cryptography if they do not support post-quantum cryptography.
315624
Emily Stark @estark.bsky.social · 04/07/2023
Somehow on this vacation I’ve ended up in a chicken coop with Ron Rivest’s grandkids
050
Emily Stark @estark.bsky.social · 29/06/2023
I don’t suppose the meal is a nice breakfast waiting for you when you get up in the morning?
100
Emily Stark @estark.bsky.social · 28/06/2023
one of these days I’m going to livetweet my night because it might be the only way to convey how ridiculous nights are in my house. I haven’t even gone to bed yet and kids have woken up a combined total of 4 times already
130
Emily Stark @estark.bsky.social · 26/06/2023
I’m on an infinite loop of forgetting where my coffee is and finding it in the microwave
030
Emily Stark @estark.bsky.social · 30/05/2023
also CAA. but, I think this is subtle; it seems easy for people to go to the other extreme and misunderstand CT to be way more than it is. and it is still true that each CA is still a weak link, just a lot less weak than before
081
Emily Stark @estark.bsky.social · 18/05/2023
if I were a baby I would simply not vomit all over my mom’s bed at 1am
060
Emily Stark @estark.bsky.social · 15/05/2023
What are the most effective nonprofit orgs working against gun violence / for gun control?
120
Emily Stark @estark.bsky.social · 02/05/2023
kudos to @dadrian.io for the simpsons reference and to our marketing team for not editing it out
151
Emily Stark @estark.bsky.social · 02/05/2023
If you, like me, dislike when tiny icons lead to large misconceptions about security, you will be happy to hear that the lock icon in Chrome is going away. Come for the browser security UI news, stay for the perfect Simpson's reference: blog.chromium.org/2023/05/an-update…
2136
Emily Stark @estark.bsky.social · 02/05/2023
I have to think on that a bit but doing DV 2x might actually make sense. MTC CAs might be a different policy regime than traditional CAs, e.g. different set of allowed DV methods
110
Emily Stark @estark.bsky.social · 02/05/2023
does it have to be both in response to the same request? I was implicitly imagining that it would be two separate ACME flows, managed by the client software
100
Emily Stark @estark.bsky.social · 02/05/2023
no browsers that I know of implement DNSSEC/DANE currently though.
000
Emily Stark @estark.bsky.social · 02/05/2023
possibly, but I'd have to think that through. might have to update more frequently than typical DANE configuration today (at the very least every 2 weeks; MTCs are designed for short-lived certs). or serve the CA key in DNS instead of the Merkle tree root, which could be longer-lived.
110
Emily Stark @estark.bsky.social · 02/05/2023
wants to support. This part isn't fully fleshed out yet but it's exciting. It's a great time to give feedback on the draft. Would tag my colleagues David Benjamin and Devon O'Brien to give them credit but they're not on here yet! (n/n)
010
Emily Stark @estark.bsky.social · 02/05/2023
... explore too, like being able to negotiate trust anchors -- that is, a client can signal which CAs it supports and the server can authenticate itself in a way that works with those supported CAs. In contrast today a server has to configure a single certificate to work with all clients it... (5/n)
121
Emily Stark @estark.bsky.social · 02/05/2023
The main motivation is postquantum cryptography; PQ signatures are huge and this scheme allows a client to verify a domain name <-> public key association with 0 signatures. The Merkle tree proof is no bigger in a PQ world. There are lots of other interesting properties that MTCs lets us... (4/n)
121
Emily Stark @estark.bsky.social · 02/05/2023
... clients and certain types of situations, so the whole thing falls back to traditional X.509 certificate chains otherwise. You can think of it as a PKI designed from scratch, with CAs and CT smooshed into one system, as an optimization layer on top of today's web PKI. (3/n)
120
Emily Stark @estark.bsky.social · 02/05/2023
... other interested parties. TLS servers are authenticated via a proof of membership in one of these Merkle trees, instead of via a bunch of signatures in an X.509 certificate chain -- which are huge in a postquantum world. This new form of authentication only works for certain types of... (2/n)
120
Emily Stark @estark.bsky.social · 02/05/2023
the (very early stage) draft is worth a read if you haven't already: www.ietf.org/id/draft-davidben-tls-… the idea is to store domain name<->public key bindings in a Merkle tree, mirrored by browser vendors or other designated entities to clients and... (1/n)
3114
Emily Stark @estark.bsky.social · 01/05/2023
Chrome Security Q1 update! www.chromium.org/Home/chromium-secu…
083
Reposted by Emily Stark
David Adrian @dadrian.io · 27/04/2023
It’s the end of OCSP as we know it, and I feel fine! lists.cabforum.org/pipermail/server…
lists.cabforum.org
[Servercert-wg] Discussion Period Begins - Ballot SC-063: “Make OCSP Optional and Incentivize Automation”
265