In March 2025, Apple published a proposal to reduce the maximum validity of TLS certificates to 45 days. The CA/B Forum had not yet voted on it. Apple announced it unilaterally, effective April 2025, before any industry consensus existed. The[…]
Author Name: Michael Carter
Blog
SSL Certificate Showing Expired for Some Visitors but Not Others: What Is Happening and How to Fix It
An SSL certificate showing as expired for some visitors but not others is always a deployment or routing issue, not a certificate validity issue. A certificate either is expired or is not , it cannot be expired for some visitors[…]
SSL Certificate for a Medical Practice Website: What HIPAA Actually Requires You to Buy
Legal note: this article explains HIPAA’s technical encryption requirements as they are interpreted by HHS OCR and applied by healthcare compliance professionals. It is not legal advice. For specific compliance questions, consult a HIPAA-specialized attorney or compliance officer. The technical[…]
A security flaw in Apache HttpClient 5.6 has raised concerns for Java applications that rely on SCRAM-SHA-256 authentication. Tracked as CVE-2026-40542, the vulnerability allows an attacker to bypass a critical part of the mutual authentication process, potentially causing a client[…]
DCV Reuse Drops to 10 Days in 2029: What Businesses Need to Know
Most coverage of CA/B Forum Ballot SC-081v3 focuses on the 47-day certificate validity headline. The equally significant change buried in the same ballot is the reduction of Domain Control Validation (DCV) reuse periods to 10 days by March 2029. For[…]
CAPTCHA Usage Statistics: Bots, Security and User Experience
CAPTCHA remains one of the most recognizable anti-bot technologies on the web, but the security problem it was designed to solve has changed dramatically.In 2026, websites are dealing with automated traffic at a scale that makes the traditional idea of[…]
In September 2023, Google removed the padlock icon from Chrome’s address bar. The icon had appeared in hundreds of billions of browser sessions, in every country, on every device, for more than a decade. It had been endorsed by the[…]
The SSL Certificate Incident Database: Every Documented Certificate Outage 2011 to 2026
This database collects every publicly documented SSL and TLS certificate expiry or misuse incident involving a named organization, a confirmed certificate root cause, and documented scope of impact. Entries are sourced from official post-mortems, confirmed company statements, and named media[…]
What this article covers and what it does not: This article documents the operational SSL behavior of major hosting platforms based on publicly available sources: official documentation, support forum threads, Let’s Encrypt community reports, and host-published knowledge bases. It is[…]
In February 2022, the extortion group LAPSUS$ breached NVIDIA’s systems and stole approximately 1 terabyte of data, including two of the company’s code-signing certificates. When NVIDIA refused to pay a ransom, LAPSUS$ published the stolen data, certificates included. Within roughly[…]
Google Trust Services Free SSL vs Let’s Encrypt in 2026: What Developers Actually Need to Know
If you found a Google Trust Services certificate on your domain and you did not configure it, you are almost certainly on Cloudflare, Firebase Hosting, or Google Cloud. GTS certificates appear automatically on these platforms. You did not switch from[…]
Evidence note: this article documents the ‘reasonable security controls’ clause, verified examples of its operation in claim denials, and the legal argument connecting certificate management failures to that clause. A specific publicly reported case of a claim denied specifically over[…]
Sectigo Market Share Surged 41% in 2026: Here Is Why It Is Now the Safest Cheap Certificate to Buy
Sectigo and its ZeroSSL brand combined surged 41.2% in certificate issuance between Q4 2025 and Q1 2026, the largest single-quarter gain of any commercial CA in the Certificate Transparency data. Sectigo now holds 11.7% of new certificate issuance globally. For[…]
A note on what this article does and does not claim: SSL bundling details below are drawn from multiple independent hosting comparison sources and cross-checked for consistency. The security incident history section includes only breaches that are publicly documented through[…]
This page tracks Certificate Authority issuance market share using the most rigorous, most frequently updated public dataset available: Certificate Transparency log analysis. It is intended to be revisited and updated each quarter as new data becomes available, rather than read[…]
Verizon’s 2026 Data Breach Investigations Report (DBIR), based on analysis of more than 31,000 security incidents and over 22,000 confirmed data breaches across 145 countries, found that third-party involvement in breaches jumped to 48% of all incidents in 2025, up[…]
Methodology note: No India-specific SSL adoption survey covering the full .in and .co.in domain population has been published as of June 2026. The estimates in this article are derived from the global baseline (11.92% of websites without HTTPS as of[…]
Every website in this list had a valid SSL certificate when it was breached. SSL encrypted the connections between users’ browsers and the servers. The padlock appeared in every visitor’s address bar. And none of that had any relevance to[…]
The US Data Breach Cost Divergence: Why American Companies Pay $10.22M While the Global Average Fell to $4.44M
IBM’s 20th annual Cost of a Data Breach Report, based on research independently compiled by the Ponemon Institute and released in 2025, found the global average cost of a data breach fell to $4.44 million, down 9% from $4.88 million[…]
94.3% of SSL Certificates Are DV: Here Is Why the Other 5.7% Drive Most of the High-Traffic Commercial Web
Netcraft’s 2025 data across hundreds of millions of active SSL certificates shows 94.3% are Domain Validation. OV accounts for 5.5%. EV, once the gold standard for high-trust sites, has fallen to 0.1% of issuance and is declining at roughly 20%[…]
North Korea Has 9 SSL Certificates. The US Has 62 Million. The Real Story Is Not a Digital Divide
The headline numbers are real and sourced. The conclusion most coverage draws from them is wrong. North Korea’s near-absence from global SSL certificate counts is overwhelmingly a function of US export sanctions law, not a story about technology adoption, encryption[…]
Does an Isolated Certificate/Encryption Breach Cost Statistic Actually Exist? An Honest Answer
The direct answer: no, a rigorously sourced, methodologically transparent statistic isolating the percentage of data breaches specifically caused by certificate or encryption failures, paired with a dedicated average cost figure, does not currently exist in any major breach research body’s[…]
Research methodology: this comparison is based on publicly available information: each reseller’s current pricing pages (verified June 2026), their support documentation and knowledge base quality, Trustpilot reviews where available, and user-reported experiences from Let’s Encrypt community forums, Reddit r/sysadmin, and[…]
The SSL Certificate Practitioner Glossary: 200 Terms Defined the Way Buyers Actually Use Them
How this glossary differs from CA-published glossaries: CA glossaries are written to make certificates sound more complex and more necessary than they are. This glossary is written to tell you exactly what each term means in practice, when it matters,[…]
No. You need one certificate. A standard single-domain SSL certificate ordered for example.com automatically includes both example.com and www.example.com as covered domains. You do not pay extra for the www variant. You do not configure anything special to get it.[…]
