Emily Stark's Avatar

Emily Stark

@estark.bsky.social

Encryption, HTTPS, certificates, web security, security UX, software engineering and management, TMI about parenting. Opinions are my own.

3,243 Followers  |  272 Following  |  32 Posts  |  Joined: 28.04.2023  |  1.7697

Latest posts by estark.bsky.social on Bluesky

Preview
HTTPS by default One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable โ€œAlways Use Secu...

One year from now, Chrome will enable "Always Use Secure Connections" and warn users before plaintext HTTP by default.

28.10.2025 17:27 โ€” ๐Ÿ‘ 17    ๐Ÿ” 9    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Chrome Root Program Policy, Version 1.6

Chrome has published version 1.6 of their root store policy.

Notably, this includes a deadline of June 15, 2026 to get TLS Client Auth out from any intermediates under roots in Chrome's program.

TLS client cert users from public CAs may need to make changes.

www.chromium.org/Home/chromiu...

14.02.2025 22:02 โ€” ๐Ÿ‘ 10    ๐Ÿ” 4    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Available at aftercare pickup alongside info about district protocols for immigration enforcement. This school district understood the assignment ๐Ÿ’œ

24.01.2025 06:00 โ€” ๐Ÿ‘ 6    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Good news, from @mozilla and @risksahead! "New ETSI draft standard on QWACs is good news for safety of European internet users"

23.01.2025 15:15 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
A Message from Superintendent Baker Message from Superintendent Dr. John Baker: Dear RCSD Community, Our mission, vision, and values drive the work we do every day in...

Behold, a rare, endangered specimen: a goddamn spine secure.smore.com/n/x03zs-a-me...

23.01.2025 07:36 โ€” ๐Ÿ‘ 8    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

I am convinced 99% of websites should use magic links + passkeys.

It bypasses all (debatable) portability objections to passkeys, itโ€™s at least as secure as email-based recovery, as fast as a password manager, itโ€™s available to all usersโ€ฆ and importantly, no passwords!

02.01.2025 15:26 โ€” ๐Ÿ‘ 156    ๐Ÿ” 31    ๐Ÿ’ฌ 20    ๐Ÿ“Œ 3
Preview
WebKit Features in Safari 18.2 Today marks the arrival of Safari 18.2.

Safari 18.2 released 3 days ago has HTTPS-first/by-default mode:

"Safari 18.2 on iOS, iPadOS, and visionOS will always try to load webpages over secure connections first, i.e. HTTPS by default. Only if the secure page load fails will Safari fall back to non-secure HTTP."
webkit.org/blog/16301/w...

12.12.2024 03:45 โ€” ๐Ÿ‘ 8    ๐Ÿ” 3    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

TIL: quokka

26.11.2024 17:15 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

periods are such unbelievable bullshit

26.11.2024 16:58 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
facebook error

facebook error

netflix error

netflix error

okta error

okta error

whatsapp error

whatsapp error

Handling Cookies is a Minefield:

Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out.

grayduck.mn/2024/11/21/h...

21.11.2024 17:11 โ€” ๐Ÿ‘ 168    ๐Ÿ” 53    ๐Ÿ’ฌ 12    ๐Ÿ“Œ 8
Atomic Age style poster of a man on a laptop in a coffee shop using public wi-fi. The coffee cup says Wi-Fi.

Atomic Age style poster of a man on a laptop in a coffee shop using public wi-fi. The coffee cup says Wi-Fi.

Some thoughts on the quiet HTTPS revolution:
medium.com/@boblord/the...

๐Ÿ”

17.11.2024 04:30 โ€” ๐Ÿ‘ 20    ๐Ÿ” 7    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Tag on a childrenโ€™s jacket showing multiple lines to write names, where each name can be removed once the jacket is handed down to another child

Tag on a childrenโ€™s jacket showing multiple lines to write names, where each name can be removed once the jacket is handed down to another child

Tiny, impeccable design detail: this childrenโ€™s jacket is designed to be a hand-me-down

16.11.2024 19:34 โ€” ๐Ÿ‘ 50    ๐Ÿ” 11    ๐Ÿ’ฌ 5    ๐Ÿ“Œ 0

I caught a full vomit into my hands tonight without a single drop hitting the couch, so maybe I do qualify as a medical professional after all

15.11.2024 05:50 โ€” ๐Ÿ‘ 9    ๐Ÿ” 0    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0
"๐Ÿ™‹โ“๐Ÿ™‹ whyโ“๐Ÿค” chrome ๐ŸŒ ๐Ÿ™…๐Ÿšซ removed ๐Ÿšซ๐Ÿ™… the ๐Ÿ”’ lock ๐Ÿ˜ฎ icon ๐Ÿคท๐Ÿคท" - serena chen (purplecon 2024)
YouTube video by purplecon "๐Ÿ™‹โ“๐Ÿ™‹ whyโ“๐Ÿค” chrome ๐ŸŒ ๐Ÿ™…๐Ÿšซ removed ๐Ÿšซ๐Ÿ™… the ๐Ÿ”’ lock ๐Ÿ˜ฎ icon ๐Ÿคท๐Ÿคท" - serena chen (purplecon 2024)

My colleague @serena.nz gave an amazing PurpleCon talk describing the behind-the-scenes experience of removing the (in?)famous lock icon from Chrome: www.youtube.com/watch?v=iUAx...

One day I aspire to get as many laughs during a talk as a 90s sitcom laugh track ๐Ÿคฉ

15.11.2024 00:32 โ€” ๐Ÿ‘ 15    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Could you please remove me? Iโ€™m not a medical professional

10.11.2024 06:58 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

ha, very true :)

09.11.2024 20:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I seem to have gotten added to some medical starter packs for some reason. If you're following me for medical stuff, sorry, wrong person! Feel free to stick around if you want to answer my random medical questions every time one of my children brings home some weird virus from school.

09.11.2024 19:56 โ€” ๐Ÿ‘ 15    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

Bold of you to assume I still havenโ€™t seen Heathers after not asking me whether Iโ€™ve seen Heathers yet in at leastโ€ฆ 3 years?

(I still havenโ€™t seen Heathers. Back to Twitter I go, I guessโ€ฆ)

01.11.2024 17:22 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Ok so I guess weโ€™re all doing this app now?

01.11.2024 14:43 โ€” ๐Ÿ‘ 16    ๐Ÿ” 0    ๐Ÿ’ฌ 5    ๐Ÿ“Œ 0
The migration to post-quantum cryptography is being held back by buggy servers that do not correctly implement TLS. Due to a bug, these servers reject connections that use post-quantum-secure cryptography, instead of negotiating classical cryptography if they do not support post-quantum cryptography.

Weโ€™ve now established a pattern where Go is the first non-browser stack to implement new TLS features, so we flush out all the bugs Chrome didnโ€™t hit.

Today itโ€™s tldr.fail. PQ shares were already default in Chrome, but Go 1.23 is surfacing new broken middleboxes.

Last time it was X.509 SANs.

01.11.2024 13:03 โ€” ๐Ÿ‘ 158    ๐Ÿ” 25    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0

Somehow on this vacation Iโ€™ve ended up in a chicken coop with Ron Rivestโ€™s grandkids

04.07.2023 18:15 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I donโ€™t suppose the meal is a nice breakfast waiting for you when you get up in the morning?

29.06.2023 05:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

one of these days Iโ€™m going to livetweet my night because it might be the only way to convey how ridiculous nights are in my house. I havenโ€™t even gone to bed yet and kids have woken up a combined total of 4 times already

28.06.2023 06:36 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Iโ€™m on an infinite loop of forgetting where my coffee is and finding it in the microwave

26.06.2023 15:22 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

also CAA. but, I think this is subtle; it seems easy for people to go to the other extreme and misunderstand CT to be way more than it is. and it is still true that each CA is still a weak link, just a lot less weak than before

30.05.2023 15:27 โ€” ๐Ÿ‘ 8    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

if I were a baby I would simply not vomit all over my momโ€™s bed at 1am

18.05.2023 15:42 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

What are the most effective nonprofit orgs working against gun violence / for gun control?

15.05.2023 20:47 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

kudos to @dadrian.io for the simpsons reference and to our marketing team for not editing it out

02.05.2023 18:56 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

If you, like me, dislike when tiny icons lead to large misconceptions about security, you will be happy to hear that the lock icon in Chrome is going away. Come for the browser security UI news, stay for the perfect Simpson's reference: https://blog.chromium.org/2023/05/an-update-on-lock-icon.html

02.05.2023 18:56 โ€” ๐Ÿ‘ 13    ๐Ÿ” 6    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 1

I have to think on that a bit but doing DV 2x might actually make sense. MTC CAs might be a different policy regime than traditional CAs, e.g. different set of allowed DV methods

02.05.2023 03:22 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@estark is following 20 prominent accounts