Yesterday I was pointed to a directory on a website that appeared to contain certificates and private keys for the Safe Deposit Bank of Norway.pic.twitter.com/6wixbRHA6c
You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more
This would still require a mapping from CA to twitter handle. I currently have a list of 38 different CAs that need to be contacted in some way.
Ah, ok. I guess you can use Twitter for CAs that you can find on Twitter, and mozilla-dev-security-policy for the rest. There should definitely be more standardization regarding key revocation.
Right. Given a pile of about 100 compromised keys that were issued by 38 different CAs, how would you automate the revocation process? Automation being important so as to be scalable. e.g. what if it were 1000 CAs?
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.