A decade of certificate transparency and what may come next (eh23)

A decade of certificate transparency and what may come next (eh23)

Author: CCC media team April 5, 2026 Duration: 1:00:45
Certificate Transparency (RFC 6962) is a protocol that aims to provide additional security to the WebPKI ecosystem, which is used as the root of trust in TLS connections of the browsers. The idea is that issued certificates must be logged in auditable certificate transparency logs, in order to be considered valid by the browser. This gives transparency into the operation of Certificate Authorities (CAs). This talk revisits the evolution of the Certificate Transparency (CT) protocol, beginning with a brief recap of the problem that motivated its design and the rollout of the protocol over the last decade. Then, I will examine the state of the ecosystem as it is today, including browser enforcement policies and current log operators, as well as recent developments such as the static CT API rollout. I'll highlight some of the remaining issues in the security of the protocol, such as issues with log list management and the lack of progress on gossip. Finally, I'll introduce (and depending on the state of progress also demonstrate) luCT, a project I am working on, which attempts to tackle some of these issues in the CT ecosystem before closing with an outlook into the future of the ecosystem and a call to action. Over the last decade, certificate transparency (CT) has become an integral part of the web's security infrastructure. However, the story of CT is far from finished. In this talk, I want to unpack where CT stands today, what has been achieved during the last 10 years, which issues the ecosystem is still struggling with today and what we may be able do about it. This work is licensed under CC BY-NC 4.0. To view a copy of this license, visit https://creativecommons.org/licenses/by-nc/4.0/ about this event: https://pretalx.eh23.easterhegg.eu/eh23/talk/8Y9ATA/

Tune into the Chaos Computer Club-recent events feed for a direct line to the forefront of digital culture and critical technology discourse. Curated by the CCC media team, this podcast channels the raw, insightful atmosphere of Europe's most influential hacker association, bringing you recordings from their major gatherings and community events. Each episode is a deep dive into talks and presentations from the last two years, covering topics from cryptography and privacy rights to hardware hacking, societal impacts of surveillance, and open-source philosophy. You'll hear from researchers, activists, and engineers who are actively shaping our digital future, offering perspectives rarely found in mainstream tech conversations. This isn't a produced show with hosts; it's an archival audio stream of genuine conference sessions, complete with audience questions and the spontaneous energy of the live event. For anyone interested in the technical details and ethical debates at the heart of modern technology, this feed serves as an essential, unfiltered resource. Subscribe to this podcast to keep your finger on the pulse of the Chaos Computer Club's ongoing dialogue, where complex ideas are broken down and the tools for a more empowered digital life are openly discussed.
Author: Episodes: 100

Chaos Computer Club - recent events feed
Podcast Episodes
Using Nix without the Nix: a Retrospective on Zilch (lixcon2026) [not-audio_url] [/not-audio_url]

Duration: 24:51
It's been a while since I last talked about Zilch; and now with Lix's existence, it's time to take another look; what's the status of this mysterious project, and what lessons can we learn from it? Licensed to the public…
Nix and buck2: from enemies to lovers with snowydeer (lixcon2026) [not-audio_url] [/not-audio_url]

Duration: 25:29
Nix does dependencies and distribution well, but has a controlling personality: it wants to build everything in the build graph. Buck2 delivers fast, user-friendly, and scalable project builds, but has an equally control…
Regiux: prototyping a fast Nix interpreter (lixcon2026) [not-audio_url] [/not-audio_url]

Duration: 30:51
The Nix expression language is challenging to evaluate due to non-strict semantics, dynamic scoping, a diverse collection of builtin operators, and tight integration with the Nix store. We give a progress report on Regiu…
The politics of language design (lixcon2026) [not-audio_url] [/not-audio_url]

Duration: 38:06
This talk is about Elpe, a mixture of ideas from Nix, Docker and Ubuntu/Debian/RHEL, with a strong focus on performance and security. I'll talk about the design choices I've made, and demo the thing and about how choices…
The untapped potential of Lix plugins (lixcon2026) [not-audio_url] [/not-audio_url]

Duration: 21:14
Lix plugins — a feature so esoteric none yet remember their existence. What power could they hold? What secrets could they unlock? Let's discover together! Licensed to the public under http://creativecommons.org/licenses…
Botanix: A Nix native CI in a forge-agnostic world (lixcon2026) [not-audio_url] [/not-audio_url]

Duration: 16:41
Botanix is a new CI software that targets a native nix integration as it builds derivations as its pipeline. It integrates natively with both Gerrit and Forgejo currently but its genericity allows for even more diversity…
Introduction to LixCon (lixcon2026) [not-audio_url] [/not-audio_url]

Duration: 7:39
Welcome to LixCon! Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.dgnum.eu/lixcon-2026/talk/38JNUB/
Privacy at the Code Level (glt26) [not-audio_url] [/not-audio_url]

Duration: 41:53
None **So you're familiar with secure coding practices, and you've taken steps to secure your devices and protect your personal privacy. But what about the privacy leaks in your code?** ___ In this talk, we'll take a whi…