<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Carr Digital: Writing</title>
    <link>https://carrdigital.dev/writing/</link>
    <atom:link href="https://carrdigital.dev/rss.xml" rel="self" type="application/rss+xml" />
    <description>Technical writing on cryptography, PKI, and security engineering from Carr Digital LLC. Checked against primary sources.</description>
    <language>en-us</language>
    <item>
      <title>The ring said Sent</title>
      <link>https://carrdigital.dev/writing/the-ring-said-sent/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/the-ring-said-sent/</guid>
      <pubDate>Wed, 16 Sep 2026 12:00:00 GMT</pubDate>
      <description>A dead man's switch told its owner the delivery had gone out, during the window in which he could still have stopped it. Nothing had been sent. The backend was right the whole time, and the screen could have caused the event it was falsely reporting.</description>
    </item>
    <item>
      <title>The 87-byte certificate</title>
      <link>https://carrdigital.dev/writing/the-87-byte-certificate/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/the-87-byte-certificate/</guid>
      <pubDate>Wed, 02 Sep 2026 12:00:00 GMT</pubDate>
      <description>I minted a real Merkle Tree Certificate with one of the draft authors' own tooling and measured 87 bytes, then 727 bytes in a batch of a million. The more useful finding is that the failure I captured, a verifier refusing a certificate because it had fallen behind, was designed out of the specification fourteen months before I ran it.</description>
    </item>
    <item>
      <title>The SCTs outweigh the certificates</title>
      <link>https://carrdigital.dev/writing/the-scts-outweigh-the-certificates/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/the-scts-outweigh-the-certificates/</guid>
      <pubDate>Sat, 22 Aug 2026 12:00:00 GMT</pubDate>
      <description>Swap each embedded SCT signature for SLH-DSA-128s, the conservative hash-based choice for a long-lived log key, and leaf-only ML-DSA migration projects past the initial congestion window for 99.7% of 8,151 measured sites. The overflow is a corollary of 2022 arithmetic. The per-site distribution is what's new.</description>
    </item>
    <item>
      <title>The 20% that passed for free</title>
      <link>https://carrdigital.dev/writing/the-20-percent-that-passed-for-free/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/the-20-percent-that-passed-for-free/</guid>
      <pubDate>Sat, 15 Aug 2026 12:00:00 GMT</pubDate>
      <description>A build guard reported a secret present in a bundle that did not contain it, and it was not flaky. IBM measured this failure at 20% of formulas on first runs, formal methods calls it vacuity, working programmers call it a tautological assertion, and it arrives in five distinct shapes.</description>
    </item>
    <item>
      <title>Three of five sent it anyway</title>
      <link>https://carrdigital.dev/writing/three-of-five-sent-it-anyway/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/three-of-five-sent-it-anyway/</guid>
      <pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate>
      <description>One certificate chain the client had said it would not accept, sent by three of five TLS server stacks. All three are conformant with RFC 8446, and what decides which chain goes out is the client's preference order rather than the configuration file.</description>
    </item>
    <item>
      <title>The same 985 bytes</title>
      <link>https://carrdigital.dev/writing/the-same-985-bytes/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/the-same-985-bytes/</guid>
      <pubDate>Sun, 09 Aug 2026 12:00:00 GMT</pubDate>
      <description>Certificate compression recovers a median 985 bytes on the chains real sites serve. After a drop-in ML-DSA-44 migration it recovers a median 985 bytes. The saving is structural, and migration adds no structure.</description>
    </item>
    <item>
      <title>Expiry is the only revocation that works</title>
      <link>https://carrdigital.dev/writing/expiry-is-the-only-revocation-that-works/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/expiry-is-the-only-revocation-that-works/</guid>
      <pubDate>Fri, 07 Aug 2026 12:00:00 GMT</pubDate>
      <description>Public TLS certificate lifetimes are stepping down from 398 days to 47 by March 2029, and the first cut already happened. The coverage calls it an automation chore. The primary sources say something more interesting.</description>
    </item>
    <item>
      <title>The typical chain moved</title>
      <link>https://carrdigital.dev/writing/the-typical-chain-moved/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/the-typical-chain-moved/</guid>
      <pubDate>Fri, 07 Aug 2026 12:00:00 GMT</pubDate>
      <description>The models disagree on whether a drop-in ML-DSA-44 chain fits TCP's initial congestion window, because each builds a different typical chain. Projected onto 8,151 real chains from the top 10k: 85.1% do not fit, and the deciding variable is depth.</description>
    </item>
    <item>
      <title>How much certificate can you afford?</title>
      <link>https://carrdigital.dev/writing/how-much-certificate-can-you-afford/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/how-much-certificate-can-you-afford/</guid>
      <pubDate>Sat, 01 Aug 2026 12:00:00 GMT</pubDate>
      <description>The advice is to keep your post-quantum certificate chain under about 10KB. That number is real, but it is stated on the wrong quantity, and the budget it implies moves by more than two kilobytes depending on which signature algorithm signs your handshake.</description>
    </item>
    <item>
      <title>Hybrid certificates, weighed</title>
      <link>https://carrdigital.dev/writing/hybrid-certificates-weighed/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/hybrid-certificates-weighed/</guid>
      <pubDate>Sat, 01 Aug 2026 12:00:00 GMT</pubDate>
      <description>Three shapes of post-quantum certificate, eleven client stacks, 88 measured cells. The design that works on every stack works because no deployed verifier checks its post-quantum half.</description>
    </item>
    <item>
      <title>The load-bearing word</title>
      <link>https://carrdigital.dev/writing/the-load-bearing-word/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/the-load-bearing-word/</guid>
      <pubDate>Fri, 31 Jul 2026 12:00:00 GMT</pubDate>
      <description>Two claims made the rounds this month: 'post-quantum cracked' and 'qubits can be cloned.' Both anchor to real papers by serious people. Both are false as stated, and in each case the distance between true and false is exactly one word.</description>
    </item>
    <item>
      <title>What the AI actually broke (and what it didn't)</title>
      <link>https://carrdigital.dev/writing/what-the-ai-actually-broke/</link>
      <guid isPermaLink="true">https://carrdigital.dev/writing/what-the-ai-actually-broke/</guid>
      <pubDate>Thu, 30 Jul 2026 12:00:00 GMT</pubDate>
      <description>An AI model found a real attack on HAWK, a post-quantum signature candidate, and the candidate withdrew from the NIST process. The deployed standards are fine. Here's the accurate version, with sources.</description>
    </item>
  </channel>
</rss>
