Meep, Meep, ACME Comes To The Rescue of Cybersecurity

--

We all know the ACME Corporation from our youth, with Wile E. Coyote sourcing a whole range of things in order to capture that pesky road runner:

But in cybersecurity, it stands for Automated Certificate Management Environments (ACME). As you know, digital certificates, and PKI, in general, is one of the least understood areas of cybersecurity, but is also one of the most fundamental building blocks of trust on the Internet. A single certificate time-out of a certificate can cause chaos on a corporate infrastructure, and a single breach of a private key can cause a wide-spread lack of trust. In 2013, Microsoft forgot to update the certificate used in the Microsoft Auzre Cloud, and took their cloud off line for a whole day:

With ACME, we have a protocol which makes it easy to provide a certificate on a domain, and is at the core of Let’s Encrypt’s business model [here]:

--

--

Prof Bill Buchanan OBE FRSE
ASecuritySite: When Bob Met Alice

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.