Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. given the general, shall we say, unreliability of crt.sh, I've been considering doing our own CT monitor at the @mpiinf

given the general, shall we say, unreliability of crt.sh, I've been considering doing our own CT monitor at the @mpiinf

Scheduled Pinned Locked Moved Uncategorized
8 Posts 6 Posters 18 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • q@glauca.spaceQ This user is from outside of this forum
    q@glauca.spaceQ This user is from outside of this forum
    q@glauca.space
    wrote last edited by
    #1

    given the general, shall we say, unreliability of crt.sh, I've been considering doing our own CT monitor at the @mpiinf

    so, dearest security research community, what would you like to see in a CT monitor?

    pls boost!

    domi@donotsta.reD radex@social.hackerspace.plR wheresalice@woof.techW alyx@frogs.lgbtA 4 Replies Last reply
    1
    0
    • q@glauca.spaceQ q@glauca.space

      given the general, shall we say, unreliability of crt.sh, I've been considering doing our own CT monitor at the @mpiinf

      so, dearest security research community, what would you like to see in a CT monitor?

      pls boost!

      domi@donotsta.reD This user is from outside of this forum
      domi@donotsta.reD This user is from outside of this forum
      domi@donotsta.re
      wrote last edited by
      #2

      @q@glauca.space @mpiinf@wisskomm.social search that doesn't time out 3/4 of the time? 😄

      i have relatively few requirements, this would be really useful if it materializes

      q@glauca.spaceQ domi@donotsta.reD 2 Replies Last reply
      0
      • q@glauca.spaceQ q@glauca.space

        given the general, shall we say, unreliability of crt.sh, I've been considering doing our own CT monitor at the @mpiinf

        so, dearest security research community, what would you like to see in a CT monitor?

        pls boost!

        radex@social.hackerspace.plR This user is from outside of this forum
        radex@social.hackerspace.plR This user is from outside of this forum
        radex@social.hackerspace.pl
        wrote last edited by
        #3

        @q notifications (webhook) for new certificate issuances for a given domain/wildcard would be good for monitoring

        1 Reply Last reply
        0
        • q@glauca.spaceQ q@glauca.space

          given the general, shall we say, unreliability of crt.sh, I've been considering doing our own CT monitor at the @mpiinf

          so, dearest security research community, what would you like to see in a CT monitor?

          pls boost!

          wheresalice@woof.techW This user is from outside of this forum
          wheresalice@woof.techW This user is from outside of this forum
          wheresalice@woof.tech
          wrote last edited by
          #4

          @q RSS feeds that at least sometimes actually return data

          1 Reply Last reply
          0
          • domi@donotsta.reD domi@donotsta.re

            @q@glauca.space @mpiinf@wisskomm.social search that doesn't time out 3/4 of the time? 😄

            i have relatively few requirements, this would be really useful if it materializes

            q@glauca.spaceQ This user is from outside of this forum
            q@glauca.spaceQ This user is from outside of this forum
            q@glauca.space
            wrote last edited by
            #5

            @domi @mpiinf not crashing all the time is top of the list

            1 Reply Last reply
            0
            • domi@donotsta.reD domi@donotsta.re

              @q@glauca.space @mpiinf@wisskomm.social search that doesn't time out 3/4 of the time? 😄

              i have relatively few requirements, this would be really useful if it materializes

              domi@donotsta.reD This user is from outside of this forum
              domi@donotsta.reD This user is from outside of this forum
              domi@donotsta.re
              wrote last edited by
              #6

              @q@glauca.space @mpiinf@wisskomm.social after some pondering: opt-in e-mail notifs that someone generated a cert for your domain with a different CA/chain than usual would be nice. alternatively, an API which could be used to implement the same thing on my side

              eloy@hsnl.socialE 1 Reply Last reply
              0
              • domi@donotsta.reD domi@donotsta.re

                @q@glauca.space @mpiinf@wisskomm.social after some pondering: opt-in e-mail notifs that someone generated a cert for your domain with a different CA/chain than usual would be nice. alternatively, an API which could be used to implement the same thing on my side

                eloy@hsnl.socialE This user is from outside of this forum
                eloy@hsnl.socialE This user is from outside of this forum
                eloy@hsnl.social
                wrote last edited by
                #7

                @domi @q @mpiinf I'd go further: especially if you have implemented CAA records, that happening would already be a huge controversy. To prevent alert fatigue you should be getting emails only when you get a cert you have not requested yourself. But with an API, anything is possible at zombo Com Transparency

                1 Reply Last reply
                0
                • q@glauca.spaceQ q@glauca.space

                  given the general, shall we say, unreliability of crt.sh, I've been considering doing our own CT monitor at the @mpiinf

                  so, dearest security research community, what would you like to see in a CT monitor?

                  pls boost!

                  alyx@frogs.lgbtA This user is from outside of this forum
                  alyx@frogs.lgbtA This user is from outside of this forum
                  alyx@frogs.lgbt
                  wrote last edited by
                  #8

                  @q @mpiinf I loved the versatility of them literally just having an open read-only Postgres, but not so much the fact where any random user just pull the IPs of everyone connected to it

                  so really just a versatile way to query things

                  1 Reply Last reply
                  0
                  • R relay@relay.publicsquare.global shared this topic
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • World
                  • Users
                  • Groups