Ivan Ristic (@ivanristic) 's Twitter Profile
Ivan Ristic

@ivanristic

Chief Scientist at Red Sift. Founder of Hardenize and author of Bulletproof TLS and PKI. Previously, founder of SSL Labs and ModSecurity.

ID: 19941586

linkhttps://www.hardenize.com calendar_today02-02-2009 23:33:03

16,16K Tweet

11,11K Followers

329 Following

Feisty Duck (@feistyduck) 's Twitter Profile Photo

Cryptography & Security Newsletter: CT logs managed by DigiCert ran into further performance problems groups.google.com/a/chromium.org…, which ultimately led to the premature death of Sphinx2025h1 and Wyvern2025h1 groups.google.com/a/chromium.org…, and

Feisty Duck (@feistyduck) 's Twitter Profile Photo

Cryptography & Security Newsletter: Pierre Barre wrote a blog post about using and optimizing Postgres for Certificate Transparency monitoring blog.transparency.dev/merklemap-scal… in Merklemap. merklemap.com

Feisty Duck (@feistyduck) 's Twitter Profile Photo

Cryptography & Security Newsletter: Frank Denis wrote an Internet-Draft about methods for IP address encryption and obfuscation datatracker.ietf.org/doc/draft-deni…, as well as several implementations. github.com/jedisct1/draft…

Feisty Duck (@feistyduck) 's Twitter Profile Photo

Cryptography & Security Newsletter: libsodium-rs is a comprehensive and idiomatic Rust wrapper for libsodium. github.com/jedisct1/libso…

Feisty Duck (@feistyduck) 's Twitter Profile Photo

New dates! Practical TLS and PKI, Sep 22-25. From Ivan Ristic, based on the Bulletproof book, with lots of exercises that will give you hands-on experience. Your teacher will be Scott Helme. And now is a good time to grab an Early Bird ticket ($300 off). feistyduck.com/training/pract…

New dates! Practical TLS and PKI, Sep 22-25. From <a href="/ivanristic/">Ivan Ristic</a>, based on the Bulletproof book, with lots of exercises that will give you hands-on experience. Your teacher will be <a href="/Scott_Helme/">Scott Helme</a>. And now is a good time to grab an Early Bird ticket ($300 off).
feistyduck.com/training/pract…
Feisty Duck (@feistyduck) 's Twitter Profile Photo

The people behind Rustls github.com/rustls/rustls, an up-and-coming TLS library written in—you guessed it—Rust, published their follow-up performance benchmark, showing excellent results under high concurrency. memorysafety.org/blog/rustls-se…

Feisty Duck (@feistyduck) 's Twitter Profile Photo

A blog post from an Amazon engineer turned up on Hacker News news.ycombinator.com/item?id=440591… and highlighted how “smart forward proxies” deal with certificate encryption in TLS 1.3.

Feisty Duck (@feistyduck) 's Twitter Profile Photo

Let’s Encrypt staff wrote about the company’s plans to remove client authentication capabilities from its certificates. letsencrypt.org/2025/05/14/end…

Feisty Duck (@feistyduck) 's Twitter Profile Photo

Cryptography & Security Newsletter is out! In this issue: - Encrypted Client Hello Approved for Publication - Short News feistyduck.com/newsletter/iss…

Cryptography &amp; Security Newsletter is out! In this issue:
- Encrypted Client Hello Approved for Publication
- Short News
feistyduck.com/newsletter/iss…
🧗‍♂️ Matt Holt (@mholt6) 's Twitter Profile Photo

Feisty Duck Ivan Ristic Re: ECH in the latest newsletter: I believe this is what ECH GREASE is for. Browsers with ECH enabled, such as Firefox and Chrome, in my testing, will disguise every ClientHello as ECH so it's difficult to know which ones are real.

<a href="/feistyduck/">Feisty Duck</a> <a href="/ivanristic/">Ivan Ristic</a> Re: ECH in the latest newsletter: I believe this is what ECH GREASE is for. Browsers with ECH enabled, such as Firefox and Chrome, in my testing, will disguise every ClientHello as ECH so it's difficult to know which ones are real.
Feisty Duck (@feistyduck) 's Twitter Profile Photo

New dates! Practical TLS and PKI Training - Nov 10-13 2025. And if you can't wait that long, we still a few tickets for the training next week. Join us! From Ivan Ristic and with Scott Helme feistyduck.com/training/pract…

New dates! Practical TLS and PKI Training - Nov 10-13 2025. 
And if you can't wait that long, we still a few tickets for the training next week. Join us! From <a href="/ivanristic/">Ivan Ristic</a> and with <a href="/Scott_Helme/">Scott Helme</a> 
feistyduck.com/training/pract…
Feisty Duck (@feistyduck) 's Twitter Profile Photo

Cryptography and Security Newsletter: Over 500 GB of source code, work logs, and internal communication records pertaining to the technology behind (or related to) the Great Firewall of China has been leaked. gfw.report/blog/geedge_an…

Feisty Duck (@feistyduck) 's Twitter Profile Photo

From February 2024 through August 2025, Fina CA issued twelve unauthorized certificates for the 1.1.1.1 IP address used by Cloudflare. blog.cloudflare.com/unauthorized-i…

Feisty Duck (@feistyduck) 's Twitter Profile Photo

There is some movement toward QWAC adoption (via Stephen Davidson); ETSI EN 319 411-2 and ETSI TS 119 411-5 are the relevant standards. linkedin.com/posts/srdavids…

Feisty Duck (@feistyduck) 's Twitter Profile Photo

Halloween Discount on Practical TLS and PKI Training! 🎃 $500 off on the final training of the year, Nov 10-13. For devs and sysadmins: how to deploy secure servers and design secure web applications feistyduck.com/training/pract… From Ivan Ristic and with Scott Helme!

Halloween Discount on Practical TLS and PKI Training! 🎃 $500 off on the final training of the year, Nov 10-13. For devs and sysadmins: how to deploy secure servers and design secure web applications feistyduck.com/training/pract…
From <a href="/ivanristic/">Ivan Ristic</a> and with <a href="/Scott_Helme/">Scott Helme</a>!