Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Andrew Ayer

@agwa@follow.agwa.name
pleroma 2.10.2
  • Open on follow.agwa.name
@agwa@agwa.name

Bootstrapped founder of SSLMate (https://sslmate.com) and DNS Helper (https://www.dnshelper.com). Making SSL certificates and DNS records easier. #WebPKI and #CertificateTransparency research on the side.
754 Followers
113 Following
19 Posts
Joined November 12, 2022
Website:
https://www.agwa.name
Pronouns:
he/him
Email:
andrew@agwa.name
Location:
Boston
Open post
Andrew Ayer @agwa@follow.agwa.name
· 4mo ago
Install software updates => bitten by AI-written bugs

Don't install software updates => pwned by AI-discovered vulnerabilities

Uninstall all software => inner peace
41
0
19
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 8mo ago
Before I use a third-party Go package, I like to know its transitive dependencies. I can't just look at go.mod, because it lists dependencies for all the packages in the module, not just the package I'm importing. So I made a little web page that runs `go list -deps` to get the real dependencies of a package: https://sourcespotter.com/deps/
sourcespotter.com
33
2
17
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 8mo ago
I just released govulncheck-deep, a program that recursively descends deep into archive files, S3 buckets, APT repos, etc. and runs govulncheck on every Go binary that it finds. I run it daily to make sure SSLMate's production environment stays free of known vulns.

There are other tools that do deep vulnerability scanning (e.g. Trivy), but they don't use govulncheck so they're overrun with false positives.

https://github.com/AGWA/deepscan
github.com
21
0
8
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 10mo ago
New blog post: Certificate Authorities Are Once Again Issuing Certificates That Don't Work
https://www.agwa.name/blog/post/cas_are_issuing_broken_certificates_again
agwa.name
11
0
11
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 10mo ago
Replying to
Certum, Cybertrust Japan, GlobalSign, Izenpe, NAVER, SECOM, SHECA, SSL.com, and TWCA are all issuing busted SSL certificates because instead of reading Apple and Chrome's JSON log lists which tell them exactly which Certificate Transparency logs are safe to use, they're assuming any log with "2027h1" in the name is good: https://groups.google.com/a/chromium.org/d/msgid/ct-policy/20251202114350.acbfe1173c6cad1aadfb98c7%40andrewayer.name If you got a certificate from any of these CAs in the last few days, you should test your site using SSLMate's CT Policy Analyzer: https://sslmate.com/labs/ct_policy_analyzer/
groups.google.com
8
0
3
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 7mo ago
New blog post: Why IP Address Certificates Are Dangerous and Usually Unnecessary https://www.agwa.name/blog/post/ip_address_certs
agwa.name
4
1
6
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 5mo ago
Replying to
@cks I would like SCGI more if you could reuse connections. I don't mean multiplexing but just being able to send another request after the first one finishes.
1
1
0
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 5mo ago
Replying to
@michael Curious what model/harness you're using? I tried to use Claude Code and Opus 4.6 with the prompt in https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/ to audit some software that I nervously rely on, and it kept telling me I was violating their acceptable use policy.
Vulnerability Research Is Cooked
A Final Ward

Vulnerability Research Is Cooked

Vulnerability discovery has always been gated by elite attention. Elite attention is now abundant. What happens next?

1
1
0
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 8mo ago
Replying to
@filippo Yeah, -tags any would be very useful for this!
1
0
0
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 13mo ago
Replying to
@christopherkunz Cool, thanks posting your comment in the bug. I also relayed your findings to mdsp yesterday: https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc/m/hV0LJBkUAAAJ
groups.google.com
1
1
0
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 13mo ago
Replying to
@Rairii That's what it looks like
1
0
0
0
Open post
Andrew Ayer @agwa@follow.agwa.name
· 8mo ago
Replying to
@endrift@social.treehouse.systems There are efforts underway. For TLS, people have unified around rustls, which is awesome. Unfortunately there's no clear successor for the crypto part yet; for a while there was momentum behind *ring* (which was incrementally rewriting BoringSSL) but sadly that seems to have stalled.
0
2
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:23:54 UTC