Updates on Public Key Infrastructure - Modern PKI Changes for Security Engineers
Hack In The Box Security Conference via YouTube
Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore the evolving landscape of web public key infrastructure (PKI) in this 46-minute conference talk that examines how modern PKI systems are becoming faster, more nimble, and resilient. Learn why security engineers should prioritize understanding these changes, particularly how they can shorten compromise recovery times and streamline investigation processes. Discover the implications of Ballot SC-063 from the CA/Browser forum, which reduces TLS certificate validity periods from 90 days to 10 days (with plans for 7 days), making certificates more resistant to malicious key control. Understand how these changes, combined with updated certificate transparency (CT) log storage methods and improved certificate management practices, enable network defenders and security engineers to narrow triage periods, expand automation options, and increase confidence in transport security across growing networks. Gain insights from Alexis Hancock, who manages the Certbot project at EFF and researches the intersection of digital rights, encryption, and consumer technology, bringing over 10 years of experience in web development and application security to discuss practical implications for modern security infrastructure.
Syllabus
#OOTB2025BKK Updates On Public Key Infrastructure - Alexis Hancock
Taught by
Hack In The Box Security Conference