







How does a lightweight community Certification Authority ("CA") engage in the heavyweight world of PKI and secure browsing?
Content Authenticity Initiative
Join the movement for content authenticity and provenance. The CAI is a global community promoting adoption of the C2PA Content Credentials standard.

ServiceTitan and the Software-vs-PE Race
Plus! Devaluation; Browsers; Slicing Up the Capital Structure; Who Audits the Auditors; International

The Politics of Open Infrastructures: Power, Governance, and Justice in Digital Knowledge Practices
This volume examines how openness is designed, governed, contested and lived in contemporary digital knowledge infrastructures. From open source software and internet standards, to citizen science platforms, public sector data systems and alternative computing practices, the book shows that infrastructures are never neutral technical backbones.

Open Evaluation: A Vision for Entirely Transparent Post-Publication Peer Review and Rating for Science
The two major functions of a scientific publishing system are to provide access to and evaluation of scientific papers. While open access (OA) is becoming a reality, open evaluation (OE), the other side of coin, has received less attention. Evaluation steers the attention of the scientific community and thus the very course of science. It also influences the use of scientific findings in public policy. The current system of scientific publishing provides only journal prestige as an indication of the quality of new papers and relies on a non-transparent and noisy pre-publication peer review process, which delays publication by many months on average. Here I propose an OE system, in which papers are evaluated post-publication in an ongoing fashion by means of open peer review and rating. Through signed ratings and reviews, scientists steer the attention of their field and build their reputation. Reviewers are motivated to be objective, because low-quality or self-serving signed evaluations will negatively impact their reputation. A core feature of this proposal is a division of powers between the accumulation of evaluative evidence and the analysis of this evidence by paper evaluation functions (PEFs). PEFs can be freely defined by individuals or groups (e.g. scientific societies) and provide a plurality of perspectives on the scientific literature. Simple PEFs will use averages of ratings, weighting reviewers (e.g. by H-factor) and rating scales (e.g. by relevance to a decision process) in different ways. Complex PEFs will use advanced statistical techniques to infer the quality of a paper. Papers with initially promising ratings will be more deeply evaluated. The continual refinement of PEFs in response to attempts by individuals to influence evaluations in their own favor will make the system ungameable. OA and OE together have the power to revolutionize scientific publishing and usher in a new culture of transparency, constructive criticism, and collaboration.

Web of trust
In cryptography, a web of trust is a concept used in PGP, GnuPG, and other OpenPGP-compatible systems to establish the authenticity of the binding between a public key and its owner. Its decentralized trust model is an alternative to the centralized trust model of a public key infrastructure (PKI), which relies exclusively on a certificate authority. As with computer networks, there are many independent webs of trust, and any user can be a part of, and a link between, multiple webs.
CERT/CC’s VINCE Platform Enables Collaboration on Software Vulnerabilities | CMU Software Engineering Institute
The SEI’s CERT Coordination Center (CERT/CC) debuted a web-based collaboration platform for coordinated vulnerability disclosure called the Vulnerability Information and Coordination Environment (VINCE) in June.

On verification and coordination authority - Connected Places
Who verifies the atproto developer community, and why can't it be the community itself?
Trust & Safety Library - Trust & Safety Professional Association
Welcome to the Trust & Safety Library! We use this space to collect articles, blog posts, journal articles, lectures, podcasts, and websites that trust and safety professionals may find useful in developing policies, supporting moderators, building systems to detect violations, and generally deepening their practice. We welcome your submissions and feedback. This project was initially

A Post-Quantum Future for Let's Encrypt
Let’s Encrypt is committed to a post-quantum-safe Web PKI. The path we’re planning to take is Merkle Tree Certificates (“MTCs”), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. This post is about these plans and why we believe MTCs are worth pursuing as a key to a post-quantum future. An increasingly urgent problem For much of the last several years, the conversation about post-quantum cryptography has been a conversation about encryption. The reasoning was straightforward: an attacker who records encrypted traffic today might be able to decrypt it years from now once quantum computers can break the underlying math. Authentication, the part of TLS that indicates a server is who it says it is, has been a less urgent problem. A quantum computer needs to forge a signature in real time, not retroactively, so threats to authentication hinge on the existence of a cryptographically relevant quantum computer (CRQC).

Four Functional Quadrants for Trust & Safety Tools: Detection, Investigation, Review & Enforcement (DIRE) <div> <br> </div>
Public discourse and regulatory debates about online trust and safety have long been dominated by a focus on rules, not tools: preoccupied mostly by the questio
Widely Viewed Content Report: What People See on Facebook | Transparency Center
Facebook regularly publishes reports to give our community visibility into community standards enforcement, government requests and internet disruptions
On Trust Infrastructure Trust underpins civilisation. It expands the scope and complexity of the pursuits within our collective reach by allowing us to act as a…
Locked Open: Why Anyone Can Be a Broker - ATProtoFans Blog
Part 4 of our "Building Recurring Payments in Public" series where we talk about being "locked open" and what it means to be a participant in the communities we support.
Trust Conference - Thomson Reuters Foundation
Trust Conference is a global forum dedicated to tackling critical issues at the intersection of media, law and business. Apply for your free ticket today.

Something I keep thinking about is whether/how it would be possible to construct something like "trusted reviewing circles" without (1) destroying peer review's egalitarian goals, (2) accidentally enabling collusion rings, (3) recreating the same system with same issues over time.
Maria Antoniak
We are caught in such a trap. Asking good-faith community members to volunteer more when we can plainly see so much bad-faith behavior without consequences... IDK where it ends. Probably not central source of the problem, but NO ONE should be listed as an "author" on 20, let alone 40, submissions.
My thoughts on Bluesky verification as someone who was deeply involved in an analogous scheme (selecting trusted root CAs for browsers) at Mozilla many years ago. The analogy is not exact: not trusting a verifier just means no checkmark, while not trusting a root CA means nasty security warnings 1/