Session

Hidden in Plain Sight: Certificate Transparency and the Logs Nobody Told You About

Most engineers know TLS certificates exist. Few know that every certificate ever issued is recorded in a public, searchable, append-only log, and that anyone can search it.

Certificate Transparency was designed to improve the security of the web's certificate infrastructure. As a side effect, it creates a permanent public record of infrastructure that developers often assume is private. That staging environment with no authentication. That internal tool on an obscure subdomain. That dev portal behind a domain nobody was supposed to know about.

Security by obscurity has always been a weak strategy. CT logs make it a nonexistent one.

In this session we'll cover how Certificate Transparency works, why it exists, and what it means for anything you've ever deployed behind a TLS certificate. We'll use real search tooling to find exposed infrastructure live, walk through two real examples of sensitive services discovered this way (including one that was responsibly disclosed and quietly taken down), and end with a practical framework for auditing your own domains before someone else does.

You'll leave knowing how to search CT logs, what to look for, and how to make better decisions about what should and shouldn't have a public certificate attached to it.


Talk Outline

1. What TLS certificates are (60-90 seconds, just enough context)
2. What Certificate Transparency is and why it was created
3. How CT logs work (append-only, public, monitored by browsers)
4. Live demo: searching CT logs with [driftnet.io or similar]
5. Real example 1: exposed dev portal, no authentication, sensitive data, responsible disclosure
6. Real example 2: newspaper platform, paywall-free developer version publicly accessible
7. What this means for engineers: every cert is a breadcrumb
8. Practical framework: audit your own domains now

Mike Conrad

Making software a strategic deterrent

Chattanooga, Tennessee, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top