Everything you learned about SSL is deprecated - Todd Gardner - NDC Toronto 2026

Everything you learned about SSL is deprecated - Todd Gardner - NDC Toronto 2026

🎙 Todd Gardner 👥 227K 📅 July 31, 2026 ⏱ 50 min 👁 30K 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

TLSSSLcertificatesperfect forward secrecyLet's Encrypt

Summary

Todd Gardner presents a comprehensive overview of the evolution of SSL/TLS, highlighting how traditional practices have become obsolete. He begins with the historical context of SSL, including the original handshake and the role of certificate authorities (CAs). He then details major events that disrupted the old model: the DigiNotar breach, the Snowden revelations leading to the adoption of Perfect Forward Secrecy, the introduction of Certificate Transparency, and the deprecation of SHA-1. The talk covers the shift from RSA to elliptic curve cryptography, the rise of Let’s Encrypt and automated certificate management, and the push towards shorter certificate lifetimes. Gardner emphasizes the importance of automation and the changing landscape of trust on the internet. He concludes with practical advice for developers to adapt to these changes, including using ACME protocol and staying updated with browser requirements. The presentation is engaging, with a mix of technical depth and storytelling, making it accessible to a broad technical audience.

155 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides substantial value by consolidating a decade of security developments into a coherent narrative. Gardner’s argumentation is solid, backed by historical events and technical explanations. He effectively explains why old practices are deprecated and why new approaches are necessary. The use of real-world examples, such as the DigiNotar breach and Heartbleed, strengthens his points. However, some technical simplifications (e.g., the discrete logarithm explanation) could be more precise, but overall the argumentation is convincing and well-supported.

Scientific Rigor, Source Quality, Title Accuracy

The talk demonstrates strong scientific rigor, referencing real incidents, standards (RFC 6962), and industry practices. Gardner cites specific events and technologies, though he does not provide formal citations. The title accurately reflects the content, focusing on the obsolescence of traditional SSL practices. The presentation is well-researched and up-to-date, with a clear structure that enhances credibility. The lack of formal references is a minor weakness, but the speaker’s expertise and the factual accuracy of the content compensate for this.

170 words

Title / Content Match

The title accurately reflects the content, which focuses on how traditional SSL practices are outdated and what has changed in modern TLS.

Quality & Reliability

8/10

The talk is given by an expert in the field, CEO of a certificate automation company, and covers historical and current developments in TLS with accurate technical details. The presentation is well-structured and includes references to real events and standards. Minor inaccuracies in technical explanations (e.g., discrete logarithm vs. Diffie-Hellman problem) are noted but do not significantly detract from overall reliability.

Key Moments

Cited Sources

  • NDC Conferences — Conference website mentioned in the video description.
  • NDC Toronto — Conference website mentioned in the video description.

Concurring Sources

Dissenting Sources

  • Comment on discrete logarithm vs. Diffie-Hellman problem — A commenter pointed out that the talk incorrectly equates the discrete logarithm problem with the Diffie-Hellman problem. The discrete logarithm is about deriving a from g^a mod p, while the Diffie-Hellman problem is about deriving g^ab from g^a and g^b. This is a minor technical inaccuracy.

Contribution & Novelties

This talk provides a valuable synthesis of the evolution of TLS, highlighting the shift from manual, CA-centric certificate management to automated, browser-driven enforcement. It offers a clear narrative of the key events that have shaped modern web security, making it accessible to developers who may not be security experts. The talk emphasizes the importance of staying updated with current best practices and the role of automation in reducing human error.

Pour aller plus loin :

  • Certificate Transparency — Overview of the CT framework and its role in public auditing of certificates.
  • Perfect Forward Secrecy — Explanation of the concept and its importance in modern TLS.
  • Let’s Encrypt — Official site of the free certificate authority, demonstrating automated issuance.
  • ACME Protocol — The protocol enabling automated certificate management.
  • Heartbleed — Details on the OpenSSL vulnerability and its impact.

137 words

Radar Profile

The radar profile shows high scores in information quantity and quality, indicating a content-rich and accurate presentation. The technical level is moderately high, suitable for a technical audience. The overall reliability is strong, with minor inaccuracies noted. The talk is well-balanced, with a slight emphasis on information delivery over technical depth.

Reliability 8/10

💬 Très positif. Sur les 30 commentaires analysés, la grande majorité exprime un enthousiasme marqué pour la qualité du contenu et la narration, avec plusieurs commentaires soulignant que c'est l'une des meilleures vidéos techniques vues récemment.