The Internet would be unusable without certificates and Certificates of Authority. If CAs got comprised or their private keys got stolen, we would be in big trouble. Warning! We go deep in this video and explain why certificates are critical to your online life and the Internet. This is a technical deep dive and covers a lot of detail. // Ed's TLS course // davidbombal.wiki/edtls49 Use coupon code: "BombalTLS" to get the course for $49 // Videos mentioned // TLS Handshake Deep Dive and decryption with Wireshark: kzbin.info/www/bejne/aGbCl6emf5Jlg6c She hacked me (Cori): kzbin.info/www/bejne/i2fTdaR8nbNraKs // Websites mentioned // badssl: badssl.com/ crt sh: crt.sh/ // MENU // 00:00 - Coming up 00:55 - Intro 01:00 - SSL Certificates 01:55 - How to validate website certificates 05:05 - Why certificates are important 08:10 - What is a CA? // Explanation of the Cerificate Authority 12:35 - Certificate chain 15:00 - Inspecting certificates 22:42 - Inspecting certificates // RSA Public-Keys 26:26 - Inspecting certificates // Extensions 28:07 - Wildcard certificates 29:20 - Inspecting certificates // Extensions (cont'd) 32:07 - Testing certificates // badssl.com 36:02 - Inspecting certificates 43:19 - Learn more about SSL/TLS 44:47 - Closing thoughts // TLS in the fututre // Ed's SOCIAL // Twitter: twitter.com/ed_pracnet KZbin: kzbin.info/door/KmU-GKiukM8LYjkJFb8oBQ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal KZbin: kzbin.info // Ed's TLS course // davidbombal.wiki/edtls49 Use coupon code: "BombalTLS" to get the course for $49 // More detail on Ed's KZbin channel and website // Asymmetric Encryption explained from a Practical Perspective: www.practicalnetworking.net/practical-tls/rsa-diffie-hellman-dsa-asymmetric-cryptography-explained/ RSA Algorithm: kzbin.info/www/bejne/hqKbmIGYq8uUpa8 DH Algorithm: kzbin.info/www/bejne/gYnUYWlrjtejn7c Practical TLS - Crypto & SSL/TLS foundation: kzbin.info/aero/PLIFyRwBY_4bTwRX__Zn4-letrtpSj1mzY // MY STUFF // www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
@KhayyamAbdullah2 жыл бұрын
Thanks for such videos
@davidbombal2 жыл бұрын
You're welcome!
@fulol17852 жыл бұрын
@@davidbombal brother can you please make a video on how to fix termux on Android is completely broken I can't install or update nothing please
@techwithgimhan17432 жыл бұрын
can you make a vdo about ,to disconnect a bluetooth connection
@owenknight6838 Жыл бұрын
Very informative. I learned a lot. Thank you.
@nFire2 жыл бұрын
The analysis of the certificates and (more in general) the care with which you bring this content trying to bring disclosure on these topics is really admirable. Thank you very much David, we could use more people like you in the world. An Italian software engineer - 🇮🇹
@davidbombal2 жыл бұрын
Thank you! And welcome Italy!
@techfixer15432 жыл бұрын
Yes hermano ... Please invite Ed back to go "deep deep deep" into RSA and Diffie-Hellman. Both of you have a great tech presence and chemistry with elucidating the behind the scenes stuff-- in this case with the inner workings of SSL/TLS. Thanks David, your content is always of the highest caliber!
@PracticalNetworking2 жыл бұрын
Would be glad to =)
@rockdarko4402 жыл бұрын
I took Ed's courses following the 1st time you made a collab with him and he doesn't disappoint. He even does live sessions for the newly added TLS1.3 content before he puts it into an actual online course - which is awesome because we get to ask questions. My next course with him is tomorrow actually. Great content but I mainly want to thank you for your great relevant content and putting Ed on my professional path. Like anybody here probably, I get most of my learning from free online resources as one should but Ed's course is one of the very few I consider being way above what you find for free online to easily make it worth what I consider a small price. This is content and expertise I have zero problem paying for as it translates into a big investment in myself as an IT professional.
@scottspa742 жыл бұрын
Couldn't agree more. I found his content when I was studying CCNA content at school, and then was lucky enough to win his SSL/TLS course for free. He is the best instructor I've come across, and his illustrations always help a lot.
@NeurosesGamer Жыл бұрын
I agree with both of you guys here, and had the same feeling exactly. His teaching is truly excellent and you can tell he really makes sure you know the topic in and out, had to donate $5 to him, and will definitely donate more when I finally land a decent job 😆
@MFoster3922 жыл бұрын
i learned so much from his handshake video and cory's videos. The Wireshark videos you do with ed and chris are so informative i hope you keep them up . Gotta love cory she's the best i hope you do more with her also. i have to say the people you show on your channel are the best in the buisness
@davidbombal2 жыл бұрын
Thank you! Great feedback Michael! Glad you are enjoying the videos :)
@Shubham-Mishra2 жыл бұрын
I see David Bombal Getting much fans here in India as well... Namastey 🙏 Love from India ❤️
@davidbombal2 жыл бұрын
Thank you Shubham!
@gddaredevil2 жыл бұрын
Hey David! First Comment!! BTW, the stuff you do is really great and I particularly liked the series of videos on Flipper Zero!
@davidbombal2 жыл бұрын
Glad you like them! Lots more coming :)
@olegserov6779 Жыл бұрын
It's a real pleasure to see these gurus being cooperated. I just love your courses! you're the best!
@rationalbushcraft2 жыл бұрын
Yes please. I have a basic understanding of RSA and Diffie Hellman but going deep would be fun. When I explain DH I use the glasses and colored water explanation. With RSA I always explain it the same way you guys did here but I don't really understand how the math works beyond it is a remainder of a whole number from division.
@abhiparay6454 Жыл бұрын
You're saving billions by making these useful videos. No need for coaching classes
@Cochise852 жыл бұрын
I like the way David feigns ignorance in order to elicit a more detailed explanation 👍
@davidbombal2 жыл бұрын
Thank you. My job is to bring the level down to make sure we can all understand what the experts are telling us :)
@Boolap13372 жыл бұрын
@@davidbombal I thought of this aswell, David is so good at that, keep it up!
@MohitKhare Жыл бұрын
Huge thanks to Sir David and Ed. I feel safe and blessed to have people like you. ❤
@Memespark2 жыл бұрын
Such a good explanation!!! As a network engineer we issue and renew ssl certificates everyday for bank domains and just 1 certificate costs $300
@PracticalNetworking2 жыл бұрын
"Quantum Cryptography is closer than ever" "Well yea, that's how time works" ;) 25:38
@manigandansrinivasan5194 Жыл бұрын
Ed always take complex topic and make it easier for the audience to understand . David you always rock as you do in the past and i appreciate it
@Techito25362 жыл бұрын
1st viewer from india very nice topic🤘
@davidbombal2 жыл бұрын
Thank you for your support!
@Techito25362 жыл бұрын
@@davidbombal just keep making videos on tech we all as a viewers want to be aware and gain some knowledge from your side 🤗
@vardhangoud88512 жыл бұрын
Waiting for your New year resolutions video David sir. Expecting cool stuff
@davidbombal2 жыл бұрын
Lots of cool videos coming in 2023 :)
@vyasG2 жыл бұрын
Excellent interview. Thank you both for your time and effort! Deep dive on Encryption protocols like RSA, DH, etc. would be greatly appreciated.
@CyberABE2 жыл бұрын
Wonderful, brilliant video again Thanks David, Thanks Ed !
@davidbombal2 жыл бұрын
Thank you Fabio!
@av4055 Жыл бұрын
I"m learning the ins and outs of tls, pki and certificates for my internship. This video comes in perfect time!
@JulietHaas2 жыл бұрын
Thanks!
@noizzy13062 жыл бұрын
Excellent and valuable content. Great explanation with marvellous deep-dive examples. I don't have been interested in stuff around certificates, but this video truly caught me up.
@letsgetteched2 жыл бұрын
This will be a great visual, to what I just read about the certificate process, in my Sec+ study guide. Have a lab to do- How to steal certificates. So many of your videos to catch up on.
@madison18710 Жыл бұрын
Thanks for your video ❤ I'm sorry to say that I'm unable to contribute to you because I'm under DNS attack right now among other strategies they changed them old-time so my apologies to you, you deserve so much more support I know what you do is time-consuming and it takes a lot of hard work thank you I appreciate you.
@robannmateja50002 жыл бұрын
This is awesome! I loved this video and look forward to taking Ed's course as well. Thank you!
@jean-philippeferron2 жыл бұрын
This guy is clear and concise.
@vincenzopappano16622 жыл бұрын
Damn! David Bombal and Ed Harmoush in the same video? What a treat!
@drakezen2 жыл бұрын
I had taken the Practical SSL course and found it well worthwhile to take.
@wavemakersdj2 жыл бұрын
I say this somewhat tongue-in-cheek, but I'd really love to see a video on Microsoft Domain internal cert authorities and why MS hasn't changed how they work in over 10 years. So many holes exist using default settings for a windows pki environment today but it's still nearly required for on-premise/hybrid windows domains.
@gebrielgebriel59162 жыл бұрын
Always appreciate your work
@davidbombal2 жыл бұрын
Thank you!
@tyrojames99372 жыл бұрын
I LEARN ALOT OF INFO IN THESE VIDEOS!😁😁
@davidbombal2 жыл бұрын
Glad to hear it!
@mwafulirwa12 жыл бұрын
finally i will understand Certs!....haven't watch it but i know i will learn some great stuff having bought the CCN course on udemy and am learning some great stuff
@MrNightowl19802 жыл бұрын
Wow!!! What a great great session this was! Thanks for this Dave
@DeepakRamanath Жыл бұрын
Brilliant explanation of digital certificates and deciphering each component of it.
@NicolasMaton2 жыл бұрын
Another great video! Thanks
@davidbombal2 жыл бұрын
Glad you enjoyed it!
@mwafulirwa12 жыл бұрын
i need to watch this twice....so much content in one Video
@alexthornburg71562 жыл бұрын
Loving these videos
@davidbombal2 жыл бұрын
Very happy to hear that Alex!
@alexthornburg71562 жыл бұрын
@@davidbombal I'm sure you hear this a lot, but your videos have done a TON for me to get more interested in Cyber Security. Keep being awesome!
@davidbombal2 жыл бұрын
@@alexthornburg7156 that is the best kind of feedback! I love hearing that my videos are helping people like you :)
@Oswee2 жыл бұрын
Could make some episode about "Quantum-Safe Cryptography" and why it is important to start think about it.
@mrityunjayadixit18212 жыл бұрын
I and My teammate have recently wrote a research paper on this topic and sent it to UCLA! Hoping for it get published
@daljeetbhati83532 жыл бұрын
Love your videos ❤️
@davidbombal2 жыл бұрын
Thank you Daljeet!
@daljeetbhati83532 жыл бұрын
@@davidbombal really happy to see you grow this much sir love from India
@hashimjarral5919 Жыл бұрын
Another deep-dive video about the protocols would be amazing.
@sammo78772 жыл бұрын
Thumbs up and like if you want to go deeper especially Diffie-Hellman key exchange - I do :) thanks for the great video David and Ed
@PracticalNetworking2 жыл бұрын
Glad you enjoyed it !
@sk3ffingtonai2 жыл бұрын
Chain of Trust. Great content, thank you for sharing.
@PracticalNetworking2 жыл бұрын
Still can't believe I forgot the words in the video... but yes, that's it!
@zarkomitreski29212 жыл бұрын
You both are dangerous together.. Thank you for the videos.
@SgtStarSlayer Жыл бұрын
When going to Starbucks, there is an certificate issue when logging in to their wifi network. After connecting to it, must ping/connect to hotmail in order to be rerouted to Starbucks accept confirmation page to use their internet. Done on Kali OS. Some sort TSL / CA warning issue.
@TonyAsh-rp6fp2 жыл бұрын
Hi David, I have a problem with micosoft hyper v, i installed kali and parrot but both resolution is very small. i used command and insert in grup and update reboot but nothing happen. Could you please guide me how to fix the resolution?
@dejuridico16912 жыл бұрын
Excellent content, David! keep it up. Greetings from Mexico City.
@abdelrahmanmohsen27352 жыл бұрын
yes please go deep in rsa and deffie helman . very interesting and very nice way of explaining it
@sykoteddy2 жыл бұрын
I'm sorry if my question is stupid or totally irrelevant, but how does it look like on the darkweb / darknet, is there any kind of certificates used there or what? Or is that partly why you need to use the Tor browser? I know you need to use the Tor browser because other browsers don't show it though. Another thing I just noticed near the end that I wonder, is if it's a typo in the openssl progra, because it says URl or URI before all the URL adresses, or if it stands for something else.
@ryankitching59362 жыл бұрын
This was so great!! Thank you so much for the SSL/TLS The chain or trust is so critical in todays dodgy world.
@georgetsiklauri Жыл бұрын
Is the certificate an ID card of the Internet? or a particular certificate is an ID card of a particular website? Talking about 5:17 moment.
@haphamdev211 ай бұрын
Thank you very a very helpful video. 💯 I think your channel should be a part of my weekend routine. Btw, should personal info at 30:46 be censored?
@ASecurityPro2 жыл бұрын
Very nice. thank you, David, for the content you offer.
@lexkenn2 жыл бұрын
Absolutely brilliant, thank you! I would be interested on more info in virtual networking and working with VMs. If that's in the scope of course. Thanks again!
@cybersecurityexpert477 Жыл бұрын
sir please one video on penetration testing roadmap 2023 how to start how to learn which programming we should learn which tools can be used for pen testing
@samkirubakaran74742 жыл бұрын
Hii Iam studying BCA Bachelors's of computer applications I will interested in Hacking so Next what i will do this career iam from India Tamilnadu please reply me....
@davidbombal2 жыл бұрын
All the best with your studies Sam!
@mrityunjayadixit18212 жыл бұрын
Hey Sam! Contact with me on LinkedIn maybe I can help u out or maybe point u to the right direction!
@samkirubakaran74742 жыл бұрын
@@davidbombal David sir please guide me Please teach me
@samkirubakaran74742 жыл бұрын
@@mrityunjayadixit1821 thanks for your kindly support please tell you Name in LinkedIn please
@Education-x6l2 жыл бұрын
This is good information. @David Bombal, does that mean every single client device get to be assigned a different ID for SSL?
@cacurazi Жыл бұрын
Wonderful talk. Excellent content. Thank you
@jamesdouglaswhite2 жыл бұрын
I want to go Balls Deep, haha! Really, this is awesome, finally. I've wanted to know more about this for a very long time. 20 years or so... Thanks!!!! And I'll be checking out his site...
@desert9152 жыл бұрын
Dang thought I had that 1st view on lock. Texas Cyber here!
@davidbombal2 жыл бұрын
Welcome!
@swoodc2 жыл бұрын
what if you make a hack that works after the certificate expires and before its renewed. right in the middle
@SirPeterlll2 жыл бұрын
What stops a scammer in making a scamming website and getting the certificates with the SSL? Nothing right? The hard part would be to try and make it to not link to your private info. But if you can fix that then the certificate means nothing anymore for that website.
@TheDirge692 жыл бұрын
Excellent presentation gents!
@deLuka93 Жыл бұрын
Hello, I have the same error with my certificate, on the Microsoft Edge browser (I can only use it, didn't try with other browsers). My Common Name (CN) is exactly the same as the URL I'm using, but I'm receiving a "NET::ERR_CERT_COMMON_NAME_INVALID" error, and the padlock is not secure. Could this happen because my certificate has only CN populated, but it doesn't have any SAN (Subject Alternative Name)?
@beyrekbaki Жыл бұрын
Amazing stuffs as usual
@noblessus2 ай бұрын
excellent video. more deeper dives!
@ushernleya3626 Жыл бұрын
If you are a beginner in computer programming and you want to venture in programming language where do you exactly start
@Me_Jawad5 ай бұрын
You should also make a video about how to get one of these
@lenickramone8 ай бұрын
such an amazing content!
@explorewithkhan66992 жыл бұрын
It is an amazing explanation. Thanks a lot by sharing such a deep knowledge. As we know Root-CA certificate(info of Root-CA + Public of CA etc) is pre-installed in apps/browsers and when client visits any websites then Client will get the ICA'S as well as the ID-Cert of ROOT-CA Therefore both the PUBLIC of ROOT-CA and PRIVATE of ROOT-CA gets compromised by the hacker. How come this issue will be resolved?.... Please do reply as having a serious confusion. Thanks
@THRE3KINGZStudios3kz2 жыл бұрын
David Bombal & Practical Networking in one setting🥹🥹🥹 the community is to fine! The insight stay growing, everyone has the ability to network, & love to see like minds able to reach/touch others who want to gain more knowledge. 💯
@davidbombal2 жыл бұрын
Thank you! Ed is amazing!
@THRE3KINGZStudios3kz2 жыл бұрын
@@davidbombal Absolutely! I find myself falling back on Ed’s content whenever I forget certain details. Really have that in-depth knowledge.
@alexandruszabo2 жыл бұрын
Great video! So many good info! Thank you!
@MWAKADAVIDMAXWEL Жыл бұрын
Great content ,thanks for sharing.
@scottspa742 жыл бұрын
So this is weird. I was following along in my terminal as Ed used openssl to make the cert human-readable, and on my end, the signatures don't match. 🤔😟 Curious what that means. In the terminal, the certificate ends in ff:ac like Ed got, but in the GUI (chrome) it ends in 7e:49. I even checked that I wasn't accidentally looking at the wrong cert in chrome (like Ed accidentally did), I checked/compared all 3 cert entries in chrome; the cert root, digicert CA1, and Twitter.cow). What does that mean? Close this Twitter session lol ?
@sbeckas Жыл бұрын
I think this is useful-I do wish you would show how it appears on other browsers besides Chrome
@cdcrjp2nft8672 жыл бұрын
Good thing I learn to implement before multiple failures
@Foxy10-b6n2 жыл бұрын
I love that guy for subnetting
@davidbombal2 жыл бұрын
Ed does a great job explaining subnetting!
@mrityunjayadixit18212 жыл бұрын
Can u tell me a video where he explained subnetting! I'm really struggling with this topic to understand!
@00zo182 жыл бұрын
question: on my old laptop with windows 7 en chrome i get a lot of popups that the certificate is not valid and that your connection is not secure on some trusted populair websites. But with firefox browser you dont get any of this popups. what is the difference between this 2 browsers? is chrome using more advance security or is it handled different? . thnx in advance,
@naturelovershaan19642 жыл бұрын
First viewer 💖💖💖💖😀😀😀😀😀
@davidbombal2 жыл бұрын
Thank you for watching so quickly!
@arifulislamleeton2 жыл бұрын
good Afternoon. Thanks
@mirzadzafic89992 жыл бұрын
Hello. Great video and great way of explaining this concept. I have question, am i right if i say that https request for web page is sent after client and server establish session keys?
@thomaschristensen18042 жыл бұрын
What if a fake CA made certificates for fake servers? How would a customer then tell the difference?
@thewatcher364 Жыл бұрын
but very active websites and old once like twitter , google can not be verified on this your csr
@jugoslav-milosevic2 жыл бұрын
Good interview-episode.
@GutaBayesa Жыл бұрын
Very good eduction and thanks too much
@joeyp9782 жыл бұрын
Yes bring him back for more please!!! Go over diffie helman
@Nate-vy2hi2 жыл бұрын
Deep. Thank you
@neelbhikadiya2 жыл бұрын
Can a 13.56 MHz RFID System modual Read and Write to a 125 kHzChip?
@young-aliwezzy84152 жыл бұрын
Mr David I'm Ali from Ksa please which books that you recommending me to buy in a amazon please
@Cueteman2 жыл бұрын
great content!
@harrylumsdon67732 жыл бұрын
and the pinning. major issue
@Toben901 Жыл бұрын
What do you thing about SUI NETWORK
@annelieselobo9823 Жыл бұрын
Thaankyou so very MUCH
@johnconnor24782 жыл бұрын
Packet Forensics that is trusted by TrustCor certificates to vouch for the legitimacy of websites has connections to contractors for U.S. intelligence agencies and law enforcement, according to security researchers, documents and interviews.
@hardcoregaming74672 жыл бұрын
How do people crash peoples game online?
@Merrlin Жыл бұрын
I love this content I really do but I had to come back to it a few times because his cadence damn near put me to sleep the first couple watch throughs this video
@MichaelAmen3162 жыл бұрын
Google (Chromium), Brave (Chromium), and very possibly Firefox (Mozilla) are discontinuing updates for their web browsers for Windows 7 and 8.1. Besides updating their OS, what can Windows 7 and 8.1. users do as far as having the most secure, privacy centered, internet compatible web browser and which one would it be with Brave (for example) off of the table?
@blackhat51332 жыл бұрын
💖💖💖
@rayenmerghmi56642 жыл бұрын
Keep up
@davidbombal2 жыл бұрын
Hoping to publish lots of videos!
@rayenmerghmi56642 жыл бұрын
@@davidbombal i wich you talk more about the hardware OP
@OgbewiOmorogbe Жыл бұрын
Good
@foodguy67612 жыл бұрын
Wait. Trust. VeriSign does a background check of a company prior to signing your cert. These new Mickey mouse ca concerns me. Very little is done to validate a company.