# Certificate Transparency

Published articles for Certificate Transparency.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Кому верит Яндекс Браузер и как попасть в этот список: запускаем Yandex Browser Root Certificate Program

DevFeed: [Кому верит Яндекс Браузер и как попасть в этот список: запускаем Yandex Browser Root Certificate Program](<https://devfeed.tech/articles/yandex-browser-root-certificate-program-24888.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/yandex/articles/1075148/>)

Author: Ilya\_Golubtsov (Яндекс)

Published: 2026-08-28T08:00:27Z

Content type: release

Language: ru

Sources: [Яндекс - Как мы делаем Яндекс / Статьи](<https://devfeed.tech/sources/source.md>)

Topics: [browser](<https://devfeed.tech/topics/browser.md>), [яндекс](<https://devfeed.tech/topics/tag-4004cf5948d3.md>), [Certificate Transparency](<https://devfeed.tech/topics/certificate-transparency.md>), [Chromium](<https://devfeed.tech/topics/chromium.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [browser](<https://devfeed.tech/tags/browser.md>), [certificate-transparency](<https://devfeed.tech/tags/certificate-transparency.md>), [chromium](<https://devfeed.tech/tags/chromium.md>), [tag-2b4427fb2566](<https://devfeed.tech/tags/tag-2b4427fb2566.md>), [tag-4004cf5948d3](<https://devfeed.tech/tags/tag-4004cf5948d3.md>), [tag-4d5248fd6bfe](<https://devfeed.tech/tags/tag-4d5248fd6bfe.md>), [tag-d8952f30fc4a](<https://devfeed.tech/tags/tag-d8952f30fc4a.md>), [tag-dfac9042ce7b](<https://devfeed.tech/tags/tag-dfac9042ce7b.md>)

### AI overview

Yandex opens the Yandex Browser Root Certificate Program, a public process for adding root certificates to the browser's trust store. The article explains its participation requirements, auditing process, WebPKI controls, and the browser's use of Chromium-derived trust data and separate Certificate Transparency logs.

### Source excerpt

За 15 лет WebPKI -- экосистема доверия между сайтами и пользователями -- сильно выросла. Появились технологии, которые делают это доверие более прозрачным и проверяемым, изменились подходы к управлению, а многие процессы стали автоматическими: выпуск и обновление сертификатов, публичный аудит через Certificate Transparency и другие механизмы. И, конечно, в истории WebPKI были серьёзные инциденты безопасности, которые показали: правила доверия должны быть публичными, прозрачными и проверяемыми. Однако один вопрос не решается автоматически: кому браузер должен доверять и на каких условиях. Каждый вендор определяет это сам. Поэтому мы открываем Yandex Browser Root Certificate Program -- публичную программу добавления корневых сертификатов в хранилище Яндекс Браузера. В ней описаны требования к участникам, аудит и понятная процедура подачи заявки. Под катом рассказываем, какие требования нужно выполнить и как в Браузере устроены WebPKI и связанные с ними контроли безопасности. Читать далее

## Certificate Transparency Monitoring is now generally available

DevFeed: [Certificate Transparency Monitoring is now generally available](<https://devfeed.tech/articles/certificate-transparency-monitoring-is-now-generally-available-111.md>)

Original publisher: [Read original article](<https://blog.cloudflare.com/certificate-transparency-monitoring-ga/>)

Author: Pravallika Nakarikanti

Published: 2026-08-13T13:00:00Z

Content type: release

Language: en

Sources: [Cloudflare Blog](<https://devfeed.tech/sources/cloudflare-blog.md>)

Topics: [Certificate Transparency](<https://devfeed.tech/topics/certificate-transparency.md>)

Tags: [certificate-transparency](<https://devfeed.tech/tags/certificate-transparency.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

Cloudflare has made Certificate Transparency Monitoring generally available. It now filters certificates Cloudflare issued for a domain, reducing renewal-alert noise and highlighting unexpected external certificates.

### Source excerpt

Cloudflare's Certificate Transparency Monitoring is now generally available. The biggest change: we no longer email you about certificates Cloudflare issued for your domain, so when an alert lands in your inbox, it's worth a look.

## Factoring "short-sleeve" RSA keys with polynomials

DevFeed: [Factoring "short-sleeve" RSA keys with polynomials](<https://devfeed.tech/articles/factoring-short-sleeve-rsa-keys-with-polynomials-7653.md>)

Original publisher: [Read original article](<https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/>)

Author: "Keegan Ryan"

Published: 2026-06-12T11:00:00Z

Content type: article

Language: en

Sources: [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog.md>), [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog-2.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Certificate Transparency](<https://devfeed.tech/topics/certificate-transparency.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [bug](<https://devfeed.tech/tags/bug.md>), [certificate-transparency](<https://devfeed.tech/tags/certificate-transparency.md>), [code](<https://devfeed.tech/tags/code.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [internet](<https://devfeed.tech/tags/internet.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [software](<https://devfeed.tech/tags/software.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [tls](<https://devfeed.tech/tags/tls.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Researchers found hundreds of weak RSA and DSA keys whose structured zero-bit patterns made them quickly factorable with a polynomial-based cryptanalytic technique. They linked many of the keys to a type mismatch in older CompleteFTP big-integer code and recovered 603 RSA private keys and 74 DSA keys from internet scans.

### Source excerpt

What happens when the bits of an RSA private key are heavily biased toward 0 instead of being randomly generated? The public key's bits could be biased enough for us to detect these incorrectly generated keys in the wild. Together with Hanno Böck of the badkeys project, we found hundreds of unique keys that not only have this property, but can be quickly factored. We also found the bug that led to many of these keys and analyzed historical data to track the issue over time. Surprisingly, the pattern of 0 bits is often highly structured, allowing us to develop a powerful polynomial-based cryptanalytic technique that exploits the pattern. Figure 1: Two patterns of RSA moduli with repeated blocks of 0 bits seen in real-world examples. These "short-sleeve" keys, named for how the 0 bits don't fully cover the limbs of the big integers, largely fell into two patterns. Pattern 1 remains unexplained, but we traced pattern 2 to a type mismatch in big-integer code from old versions of the CompleteFTP file transfer software. The CompleteFTP bug also generated vulnerable short-sleeve DSA keys, and we recovered 603 unique RSA private keys and 74 DSA keys from internet scans. If you used CompleteFTP to generate host keys between December 2016 and December 2023, CompleteFTP has released a tool to check whether your keys need to be regenerated. How we found the weak keys The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive number of real-world keys from public sources, including Certificate Transparency logs, internet-wide TLS and SSH scans, PGP keys, and many others. By searching this dataset for unexpectedly sparse RSA moduli, we uncovered a large number of keys in the wild with the patterns in Figure 1. Both patterns include several regularly spaced blocks of all zeros interleaved with seemingly random data. Pattern 1 appears in CT logs for certificates issued to several large organ

## Chrome develops Merkle Tree Certificates for quantum-resistant HTTPS

DevFeed: [Chrome develops Merkle Tree Certificates for quantum-resistant HTTPS](<https://devfeed.tech/articles/cultivating-a-robust-and-efficient-quantum-safe-https-19812.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html>)

Author: Google (noreply@blogger.com)

Published: 2026-02-27T17:01:00Z

Content type: release

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [Chrome](<https://devfeed.tech/topics/chrome.md>), [Post-quantum cryptography](<https://devfeed.tech/topics/post-quantum-cryptography.md>), [Certificate Transparency](<https://devfeed.tech/topics/certificate-transparency.md>), [Internet Engineering Task Force (IETF)](<https://devfeed.tech/topics/ietf.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Scalability](<https://devfeed.tech/topics/scalability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [certificate-transparency](<https://devfeed.tech/tags/certificate-transparency.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [ietf](<https://devfeed.tech/tags/ietf.md>), [none](<https://devfeed.tech/tags/none.md>), [post-quantum-cryptography](<https://devfeed.tech/tags/post-quantum-cryptography.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [security](<https://devfeed.tech/tags/security.md>), [tls](<https://devfeed.tech/tags/tls.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Chrome is developing Merkle Tree Certificates with partners through the IETF PLANTS working group to support quantum-resistant HTTPS while reducing the bandwidth and performance costs of larger post-quantum certificate chains. Chrome says it has no immediate plan to add traditional post-quantum X.509 certificates to the Chrome Root Store and is experimenting with MTCs using real internet traffic.

### Source excerpt

Posted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a working group, PKI, Logs, And Tree Signatures ("PLANTS"), aiming to address the performance and bandwidth challenges that the increased size of quantum-resistant cryptography introduces into TLS connections requiring Certificate Transparency (CT). We recently shared our call to action to secure quantum computing and have written about challenges introduced by quantum-resistant cryptography and some of the steps we've taken to address them in earlier blog posts. To ensure the scalability and efficiency of the ecosystem, Chrome has no immediate plan to add traditional X.509 certificates containing post-quantum cryptography to the Chrome Root Store. Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group. MTCs replace the heavy, serialized chain of signatures found in traditional PKI with compact Merkle Tree proofs. In this model, a Certification Authority (CA) signs a single "Tree Head" representing potentially millions of certificates, and the "certificate" sent to the browser is merely a lightweight proof of inclusion in that tree. Why MTCs? MTCs enable the adoption of robust post-quantum algorithms without incurring the massive bandwidth penalty of classical X.509 certificate chains. They also decouple the security strength of the corresponding cryptographic algorithm from the size of the data transmitted to the user. By shrinking the authentication data in a TLS handshake to the absolute minimum, MTCs aim to keep the post-quantum web as fast and seamless as today's internet, maintaining high performance even as we adopt stronger security. Finally, with MTCs, transparency is a fundamental property of issuance:

## CRLite: Fast, private, and comprehensive certificate revocation checking in Firefox

DevFeed: [CRLite: Fast, private, and comprehensive certificate revocation checking in Firefox](<https://devfeed.tech/articles/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox-4145.md>)

Original publisher: [Read original article](<https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/>)

Author: John Schanck

Published: 2025-08-19T16:03:19Z

Content type: article

Language: en

Sources: [Mozilla Hacks - the Web developer blog](<https://devfeed.tech/sources/mozilla-hacks-the-web-developer-blog.md>)

Topics: [Certificate Transparency](<https://devfeed.tech/topics/certificate-transparency.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [browser](<https://devfeed.tech/tags/browser.md>), [certificate-transparency](<https://devfeed.tech/tags/certificate-transparency.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [feature](<https://devfeed.tech/tags/feature.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [http](<https://devfeed.tech/tags/http.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [performance](<https://devfeed.tech/tags/performance.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [tls](<https://devfeed.tech/tags/tls.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Firefox's CRLite locally checks revoked TLS certificates using a compact, periodically updated encoding derived from Certificate Transparency logs. The article contrasts this approach with real-time OCSP checks, emphasizing privacy, reliability, and performance.

### Source excerpt

Firefox is now the first and the only browser to deploy fast and comprehensive certificate revocation checking that does not reveal your browsing activity to anyone (not even to Mozilla). Tens of millions of TLS server certificates are issued each day to secure communications between browsers and websites. These certificates are the cornerstones of ubiquitous [...] The post CRLite: Fast, private, and comprehensive certificate revocation checking in Firefox appeared first on Mozilla Hacks - the Web developer blog.

## Real World Crypto 2024

DevFeed: [Real World Crypto 2024](<https://devfeed.tech/articles/real-world-crypto-2024-29180.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2024/05/07/real-world-crypto-2024/>)

Published: 2024-05-07T11:00:17Z

Content type: article

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Certificate Transparency](<https://devfeed.tech/topics/certificate-transparency.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Post-Quantum](<https://devfeed.tech/topics/post-quantum.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [certificate-transparency](<https://devfeed.tech/tags/certificate-transparency.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [internet](<https://devfeed.tech/tags/internet.md>), [post-quantum](<https://devfeed.tech/tags/post-quantum.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A blog post records notes from Real World Crypto 2024 in Toronto, discussing applied cryptography trends including post-quantum messaging, key transparency, and privacy-enhancing technologies. It also describes Certificate Transparency's Levchin Prize recognition and its role in improving accountability for the Web Public Key Infrastructure.

### Source excerpt

We traveled to Toronto this year to attend RWC 2024. The conference was held in TIFF Lightbox located in the city's downtown; the venue is the headquarters for the Toronto Film Festival and contains five cinema rooms. RWC is a single-tracked conference and there's no hard requirement that talks are backed by papers. Each RWC includes the Levchin prize ceremony for major achievements in applied cryptography, several invited talks and the lightning talks session.

## Chrome 99 expands Certificate Transparency on Android, affecting HTTPS interception and debugging tools

DevFeed: [Chrome 99 expands Certificate Transparency on Android, affecting HTTPS interception and debugging tools](<https://devfeed.tech/articles/android-chrome-99-expands-certificate-transparency-breaking-all-mitm-dev-tools-19047.md>)

Original publisher: [Read original article](<https://httptoolkit.com/blog/chrome-android-certificate-transparency/>)

Author: HTTP Toolkit; Tim Perry

Published: 2022-05-11T16:00:00Z

Content type: tutorial

Language: en

Sources: [HTTP Toolkit](<https://devfeed.tech/sources/http-toolkit.md>)

Topics: [Certificate Transparency](<https://devfeed.tech/topics/certificate-transparency.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [Android](<https://devfeed.tech/topics/android.md>), [Security](<https://devfeed.tech/topics/security.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [browsers](<https://devfeed.tech/tags/browsers.md>), [certificate-transparency](<https://devfeed.tech/tags/certificate-transparency.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [developer-tools](<https://devfeed.tech/tags/developer-tools.md>), [interception](<https://devfeed.tech/tags/interception.md>), [security](<https://devfeed.tech/tags/security.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

This article explains how Chrome 99's expansion of Certificate Transparency to all Android Chrome users affects HTTPS interception with trusted system CA certificates, including developer debugging tools. It describes why Certificate Transparency exists and discusses workarounds for debugging Chrome traffic on Android.

### Source excerpt

Certificate transparency is superb improvement to HTTPS certificate security on the web that's great for users and businesses, but on Android it creates a huge problem for the many developer tools like HTTP Toolkit which install trusted system certificates into Android to intercept & debug app traffic. This doesn't appear in the main announcements anywhere, but buried deep in the enterprise release notes for Chrome v99 there's a small note that says: Certificate transparency is already enforced on desktop platforms, and for some Android users. Chrome 99 expands certificate transparency to all Android Chrome users. And with that small note, Chrome on Android become uninterceptable for all HTTP Toolkit users using rooted devices, and anybody else who actively installs and trusts their own system CA certificates. If you're running into an ERR_CERTIFICATE_TRANSPARENCY_REQUIRED error in Chrome while trying to debug your HTTPS traffic with some MitM debugging proxy, then this is affecting you too. Let's talk about how certificate transparency works, why this breaks, and how you can work around it to keep debugging HTTPS from Chrome on your Android device regardless. Certificate Transparency (CT) HTTPS certificates are issued and signed by Certificate Authorities (CAs) who are trusted by your browser & OS. That's great when it works, but sometimes it doesn't. CAs can make mistakes when issuing certificates, when verifying a client's identity beforehand, or through malice somewhere, and issue fraudulent certificates to people who shouldn't have them. For example, let's say a trusted CA issues a certificate for google.com to the wrong person (this actually happened, repeatedly). That issued certificate is incredibly powerful - whoever has it can freely intercept all traffic sent by anybody to Google.com and both see & modify that traffic, whilst browsers will show all users a padlock and tell them everything is totally fine & secure. Even worse though: attacks like this were

## Firebase Realtime Database Supports SSL Certificate Transparency

DevFeed: [Firebase Realtime Database Supports SSL Certificate Transparency](<https://devfeed.tech/articles/firebase-realtime-database-supports-ssl-certificate-transparency-16313.md>)

Original publisher: [Read original article](<https://firebase.blog/posts/2019/03/rtdb-supports-certificate-transparency>)

Author: Jamie Niemasik

Published: 2019-03-12T00:00:00Z

Content type: release

Language: en

Sources: [Firebase Blog](<https://devfeed.tech/sources/firebase-blog.md>)

Topics: [Certificate Transparency](<https://devfeed.tech/topics/certificate-transparency.md>), [Firebase](<https://devfeed.tech/topics/firebase.md>), [Realtime Database](<https://devfeed.tech/topics/realtime-database.md>), [SSL](<https://devfeed.tech/topics/ssl.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [certificate-transparency](<https://devfeed.tech/tags/certificate-transparency.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [firebase](<https://devfeed.tech/tags/firebase.md>), [launch](<https://devfeed.tech/tags/launch.md>), [news](<https://devfeed.tech/tags/news.md>), [realtime-database](<https://devfeed.tech/tags/realtime-database.md>), [security](<https://devfeed.tech/tags/security.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [tls](<https://devfeed.tech/tags/tls.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Firebase announces that Realtime Database now implements Certificate Transparency. Responses always include a Signed Certificate Timestamp, helping detect mistakenly issued or maliciously issued SSL certificates. The change adds slight response-size and possible bandwidth costs.

### Source excerpt

News, tutorials, and updates from the Firebase team.