Install software updates => bitten by AI-written bugs
Don't install software updates => pwned by AI-discovered vulnerabilities
Uninstall all software => inner peace
Remote
Andrew Ayer
@agwa@follow.agwa.name
@agwa@agwa.name
Bootstrapped founder of SSLMate (https://sslmate.com) and DNS Helper (https://www.dnshelper.com). Making SSL certificates and DNS records easier. #WebPKI and #CertificateTransparency research on the side.
Bootstrapped founder of SSLMate (https://sslmate.com) and DNS Helper (https://www.dnshelper.com). Making SSL certificates and DNS records easier. #WebPKI and #CertificateTransparency research on the side.
754 Followers
113 Following
19 Posts
Joined November 12, 2022
Open post
Before I use a third-party Go package, I like to know its transitive dependencies. I can't just look at go.mod, because it lists dependencies for all the packages in the module, not just the package I'm importing. So I made a little web page that runs `go list -deps` to get the real dependencies of a package: https://sourcespotter.com/deps/
33
2
17
0
Open post
I just released govulncheck-deep, a program that recursively descends deep into archive files, S3 buckets, APT repos, etc. and runs govulncheck on every Go binary that it finds. I run it daily to make sure SSLMate's production environment stays free of known vulns.
There are other tools that do deep vulnerability scanning (e.g. Trivy), but they don't use govulncheck so they're overrun with false positives.
https://github.com/AGWA/deepscan
There are other tools that do deep vulnerability scanning (e.g. Trivy), but they don't use govulncheck so they're overrun with false positives.
https://github.com/AGWA/deepscan
21
0
8
0
Open post
New blog post: Certificate Authorities Are Once Again Issuing Certificates That Don't Work
https://www.agwa.name/blog/post/cas_are_issuing_broken_certificates_again
https://www.agwa.name/blog/post/cas_are_issuing_broken_certificates_again
11
0
11
0
Open post
Replying to
Certum, Cybertrust Japan, GlobalSign, Izenpe, NAVER, SECOM, SHECA, SSL.com, and TWCA are all issuing busted SSL certificates because instead of reading Apple and Chrome's JSON log lists which tell them exactly which Certificate Transparency logs are safe to use, they're assuming any log with "2027h1" in the name is good: https://groups.google.com/a/chromium.org/d/msgid/ct-policy/20251202114350.acbfe1173c6cad1aadfb98c7%40andrewayer.name
If you got a certificate from any of these CAs in the last few days, you should test your site using SSLMate's CT Policy Analyzer: https://sslmate.com/labs/ct_policy_analyzer/
8
0
3
0
Open post
New blog post: Why IP Address Certificates Are Dangerous and Usually Unnecessary https://www.agwa.name/blog/post/ip_address_certs
4
1
6
0
Open post
Replying to
@michael Curious what model/harness you're using? I tried to use Claude Code and Opus 4.6 with the prompt in https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/ to audit some software that I nervously rely on, and it kept telling me I was violating their acceptable use policy.
1
1
0
0
Open post
Replying to
@christopherkunz Cool, thanks posting your comment in the bug. I also relayed your findings to mdsp yesterday: https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc/m/hV0LJBkUAAAJ
1
1
0
0
Open post
Replying to
@endrift@social.treehouse.systems There are efforts underway. For TLS, people have unified around rustls, which is awesome. Unfortunately there's no clear successor for the crypto part yet; for a while there was momentum behind *ring* (which was incrementally rewriting BoringSSL) but sadly that seems to have stalled.
0
2
0
0
