A decade of certificate transparency and what may come next (eh23)

A decade of certificate transparency and what may come next (eh23)

Author: CCC media team April 5, 2026 Duration: 1:00:45
Certificate Transparency (RFC 6962) is a protocol that aims to provide additional security to the WebPKI ecosystem, which is used as the root of trust in TLS connections of the browsers. The idea is that issued certificates must be logged in auditable certificate transparency logs, in order to be considered valid by the browser. This gives transparency into the operation of Certificate Authorities (CAs). This talk revisits the evolution of the Certificate Transparency (CT) protocol, beginning with a brief recap of the problem that motivated its design and the rollout of the protocol over the last decade. Then, I will examine the state of the ecosystem as it is today, including browser enforcement policies and current log operators, as well as recent developments such as the static CT API rollout. I'll highlight some of the remaining issues in the security of the protocol, such as issues with log list management and the lack of progress on gossip. Finally, I'll introduce (and depending on the state of progress also demonstrate) luCT, a project I am working on, which attempts to tackle some of these issues in the CT ecosystem before closing with an outlook into the future of the ecosystem and a call to action. Over the last decade, certificate transparency (CT) has become an integral part of the web's security infrastructure. However, the story of CT is far from finished. In this talk, I want to unpack where CT stands today, what has been achieved during the last 10 years, which issues the ecosystem is still struggling with today and what we may be able do about it. This work is licensed under CC BY-NC 4.0. To view a copy of this license, visit https://creativecommons.org/licenses/by-nc/4.0/ about this event: https://pretalx.eh23.easterhegg.eu/eh23/talk/8Y9ATA/

Tune into the Chaos Computer Club-recent events feed for a direct line to the forefront of digital culture and critical technology discourse. Curated by the CCC media team, this podcast channels the raw, insightful atmosphere of Europe's most influential hacker association, bringing you recordings from their major gatherings and community events. Each episode is a deep dive into talks and presentations from the last two years, covering topics from cryptography and privacy rights to hardware hacking, societal impacts of surveillance, and open-source philosophy. You'll hear from researchers, activists, and engineers who are actively shaping our digital future, offering perspectives rarely found in mainstream tech conversations. This isn't a produced show with hosts; it's an archival audio stream of genuine conference sessions, complete with audience questions and the spontaneous energy of the live event. For anyone interested in the technical details and ethical debates at the heart of modern technology, this feed serves as an essential, unfiltered resource. Subscribe to this podcast to keep your finger on the pulse of the Chaos Computer Club's ongoing dialogue, where complex ideas are broken down and the tools for a more empowered digital life are openly discussed.
Author: Episodes: 100

Chaos Computer Club - recent events feed
Podcast Episodes
CT-Installserver Episode 2: The Return of the Cache (eh23) [not-audio_url] [/not-audio_url]

Duration: 20:15
Auf der Easterhegg 2025 habe ich das Konzept des Computertruhe Installations-Servers vorgestellt, seit dem Vortrag hat sich ein bisschen was getan. In diesem Mini-Vortrag möchte ich ein kleines Update geben was sich seit…
Dark Agile - Vergiftete Agilität (eh23) [not-audio_url] [/not-audio_url]

Duration: 30:43
Irgendwie sind immer noch alle heiß auf Agilität und Scrum. Irgendwie hassen es aber auch alle. Wieso ist das so? Und wer ist eigentlich daran schuld? Wie können wir das verändern? This work is licensed under CC BY-NC 4.…
Pimp my 3D Drucker (eh23) [not-audio_url] [/not-audio_url]

Duration: 33:48
es geht in diesem Vortrag um den Prozess wie ich einen 10 Jahre alten 3D Drucker den ich aus dem Schrott gezogen habe restauriert und modernisiert habe. In Diesem Vortrag möchte ich euch erzählen, wie ich einen 10 Jahre…
Open-Source-Chip-Design (eh23) [not-audio_url] [/not-audio_url]

Duration: 59:21
Open-source chip-design initiatives and EDA tools are enabling affordable, workflows from SystemVerilog to GDS-II, making custom ASICs accessible even to hobbyists. As a demonstration, a collaboration between JKU Linz an…
E-Mail selbst hosten (eh23) [not-audio_url] [/not-audio_url]

Duration: 51:31
E-Mail gilt als kompliziert und kaum selbst betreibbar. Trotzdem ist es das größte wirklich dezentrale Kommunikationsmittel. Dieser Talk ist ein Realitätscheck für technisch versierte Menschen mit Hosting-Erfahrung, die…
Designblöcke in Elektronik erkennen und verstehen (eh23) [not-audio_url] [/not-audio_url]

Duration: 51:17
Elektronik ist eigentlich gar nicht kompliziert. Eine "komplexe" Schaltung besteht aus Designblöcken die man einzeln anschauen, analysieren und verstehen kann. Wie schauen uns gemeinsam Beispiele von Platinen und Schaltp…
Dezentrales Internet durch Self-Hosting (eh23) [not-audio_url] [/not-audio_url]

Duration: 34:52
DSGVO, brennende Rechenzentren und fragwürdige AGBs – wer seine Daten in die Hände Dritter legt, gibt nicht nur Kontrolle, sondern auch Verantwortung ab. Doch es geht auch anders: Self-Hosting ermöglicht dir, eigene Dien…
Schiffsromantik (live) (eh23) [not-audio_url] [/not-audio_url]

Duration: 59:56
Wir lesen Texte vor. Es wird schlimm. Wenn du dich spoilern willst geh auf www.ihrkoenntunsallemal.de galigrü This work is licensed under CC BY-NC 4.0. To view a copy of this license, visit https://creativecommons.org/li…
Eggstracting Eastereggs from glob-top ICs (eh23) [not-audio_url] [/not-audio_url]

Duration: 9:15
Eine Ostereiersuche ausgehend von einem Flashdump bis hin zu einem kompletten Firmwaredump mit Disassembly Eine kleine Embedded-Recherche über ein Nuvoton-Mikrocontroller in älterem Spielzeug ausgehend von einem Flashdum…