Let's Encrypt Now Offers 6-Day and IP Address Certificates for Enhanced Security
By
jaas
Reliable enough to start your morning with. Toast it again tomorrow.
Summary
Let's Encrypt has made short-lived certificates (valid for 160 hours/6 days) and IP address certificates generally available. These certificates improve security by requiring more frequent validation and reducing reliance on unreliable revocation mechanisms. The shorter validity period reduces the vulnerability window if a certificate's private key is compromised, as traditional 90-day certificates leave relying parties vulnerable until expiration when revocation systems fail.
Key quotes
· 4 pulledShort-lived and IP address certificates are now generally available from Let's Encrypt.
These certificates are valid for 160 hours, just over six days.
Short-lived certificates improve security by requiring more frequent validation and reducing reliance on unreliable revocation mechanisms.
With short-lived certificates that vulnerability window is greatly reduced.
You might also wanna read
Why Security Through Obscurity Still Matters as a Practical Defense Layer
The article challenges the common developer mantra that "security through obscurity is bad," arguing that obscurity (like JavaScript obfusca
Scratch's ongoing security challenges with SVG sanitization
The article discusses the security challenges Scratch faces with SVG sanitization. Scratch parses user-generated (attacker-controlled) SVG c
Third-Party Service Inspector: Analyze Website Trackers and Scripts
The article describes a tool called 'Third-party service inspector' that allows users to see and analyze all third-party services, trackers,
Google Chrome Announces Quantum-Safe HTTPS Certificate Program
Google's Chrome team announces a new program to make HTTPS certificates secure against quantum computing threats, focusing on quantum-safe c
Facebook Crawler Obsessively Requests Robots.txt File Thousands of Times Per Hour
A developer reports that Facebook's crawler (facebookexternalhit) has been making thousands of requests per hour to their self-hosted Forgej
CT Log Explorer: A Tool for Browsing Certificate Transparency Logs
CT Log Explorer is a tool for browsing Certificate Transparency logs, which are public records of SSL/TLS certificates issued by Certificate
