frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Letsencrypt will kill SMTP server auth following Chrome CA policy change

https://social.wildeboer.net/@jwildeboer/114516238307785904
38•Aissen•5h ago

Comments

londons_explore•1h ago
I assume the reasoning for the policy change is that allowing a single certificate to be used for many different uses puts a greater risk of the certificate private key being leaked.

They don't want your insecure mail server software to put your secure web server at risk.

dandanio•40m ago
If you can't secure your mail server, you certainly can't secure your web server. Letsencrypt, please rethink your decision!
dlgeek•4m ago
They don't have a choice - the decision comes from Chrome's root program and if they don't comply, LetsEncrypt would be distrusted by Chrome.
arccy•42m ago
smtp servers shouldn't have been doing this anyway...

the pki separation is good.

devrandoom•37m ago
Why?
bbarnett•33m ago
This is precisely like NIST requirements to change your password frequently, which was well intended, but reduced security due to people not being able to recall their password.

(This is now reversed, of course)

Reducing certificate life to ridiculous time frames, making it difficult to obtain certificates, all for very dubious, extremely tiny and minor improvements in security. It's going to cause more harm than good, and in the end, will reduce not enhance security.

For example, many SMTP servers may revert to self-signed certs now.

Hilift•12m ago
47 days isn't ridiculous if it is automated.
bbarnett•5m ago
It's fine to allow short time frames, so those that can and will automate are able.

It's not fine to force it. There's no logic behind it. Browser and OS updates can expire certificate authorities, and that's the only real reason people claim this is to be done.

blueflow•32m ago
Why is it Google that is making these rules? A company would not have this kind of power in a fair competition market.
WorldPeas•32m ago
now I guess we understand why chrome is too dangerous for them to own from a monopolistic standpoint
jaoane•7m ago
Isn’t Let’s Encrypt basically Google? Google pushed it by punishing the ranking of search results that didn’t use ssl.
andrewaylett•30m ago
Does anyone's mail server accept (much less trust) publicly-trusted client certs anyway?
rnhmjoj•19m ago
I've read the announcement[1] and I don't see how this deprecation has anything to do with SMTP. Is it because the sending MTA will present its own server certificate as a client certificate to the receiving MTA? I thought most of this traffic was outright unencrypted or opportunistically encrypted with self-signed certs.

Do most SMTP server require, or even use, certs issued by a CA?

[1]: https://letsencrypt.org/2025/05/14/ending-tls-client-authent...

scandox•16m ago
Many systems will not deliver where encryption is not present. Some systems won't deliver without a certificate issued by a public CA. And some systems won't accept an LE cert but require something called OV(organizational validation).
gruez•13m ago
>Some systems won't deliver without a certificate issued by a public CA. And some systems won't accept an LE cert but require something called OV(organizational validation).

Which systems are these? Are they public email providers? Are they enterprises?

scandox•6m ago
Enterprises. Porsche.com corporate email for example won't deliver without an OV.

So once you're in the business of providing any kind of general email service you eventually have to deal with it.

Edit: Porsche corporate

CaptainFever•6m ago
The link is to a random Mastodon post ranting about the change. I think it would be better if it linked to the actual blog post from Let's Encrypt: https://letsencrypt.org/2025/05/14/ending-tls-client-authent...

Feather Forensics Offers a Way to Root Out Poachers

https://www.biographic.com/feather-forensics-offers-a-way-to-root-out-poachers/
1•onychomys•49s ago•0 comments

Coinbase Got Hacked a Little

https://www.bloomberg.com/opinion/newsletters/2025-05-15/coinbase-got-hacked-a-little
2•feross•3m ago•0 comments

Students shatter Guinness World Record for fastest puzzle cube-solving robot

https://engineering.purdue.edu/ECE/News/2025/purdue-ece-students-shatter-guinness-world-record-for-fastest-puzzle-cube-solving-robot
1•doener•6m ago•0 comments

Crash Test

https://www.pbs.org/wgbh/nova/video/ultimate-crash-test-countdown/
1•tzs•7m ago•1 comments

A Philosophy of Conversation

https://secondvoice.substack.com/p/a-philosophy-of-conversation
1•jger15•8m ago•0 comments

Therapeutic cargo integration into human genome with programmable type V-K CAST

https://www.nature.com/articles/s41467-025-57416-2
1•rntn•11m ago•0 comments

Lecture Notes on Linear Programming [pdf] (2007)

https://home.cs.colorado.edu/~hal/565notes.pdf
2•ibobev•11m ago•0 comments

Cloudflare Durable Objects Are Virtual Objects

https://www.lambrospetrou.com/articles/durable-objects-are-virtual-objects/
2•flashblaze•11m ago•0 comments

The Fastest Postgres Inserts

https://docs.hatchet.run/blog/fastest-postgres-inserts
2•abelanger•11m ago•0 comments

Show HN: I vibe coded an open-source Go app to back up DBs using Docker labels

https://github.com/resulgg/label-backup
1•standardresul•12m ago•0 comments

Apple has blocked our Fortnite submission

https://twitter.com/Fortnite/status/1923293522234356169
3•stephc_int13•12m ago•0 comments

Apple's Diet of Worms

https://www.joanwestenberg.com/apples-diet-of-worms/
4•tambourine_man•14m ago•0 comments

Ask HN: As a foreigner in the US, how do you find filing taxes here?

2•blackhaj7•16m ago•1 comments

2025.20: Product Dreams and Marketplace Realities

https://stratechery.com/2025/product-dreams-and-marketplace-realities/
1•feross•18m ago•0 comments

Neal Stephenson wants AIs fighting AIs so those most fit to live with us survive

https://www.theregister.com/2025/05/16/neal_stephenson_ai_evolution/
1•pseudolus•20m ago•1 comments

The Remarkable Underground Voyages of Michel Siffre

https://www.thequantumcat.space/p/the-remarkable-underground-voyages
1•verzali•20m ago•0 comments

A Critical Examination of Prayers

https://www.rxjourney.net/a-critical-examination-of-prayers
2•bertblaast•20m ago•0 comments

Show HN: The Great GitHub Nix Disk Space Heist

https://wimpysworld.com/posts/nothing-but-nix-github-actions/
1•flexiondotorg•22m ago•0 comments

Repair Time Requirements to Prevent Data Resurrection in Cassandra and Scylla

https://msun.io/cassandra-scylla-repairs/index.html
4•datahoarder•22m ago•0 comments

Banksy famed warehouse wall heart art to support heart health

https://newsroom.heart.org/news/banksy-famed-warehouse-wall-heart-art-to-support-heart-health
1•geox•24m ago•0 comments

Renewable power reversing China's emissions growth

https://arstechnica.com/science/2025/05/analysis-shows-that-chinas-emissions-are-dropping-due-to-renewables/
3•rbanffy•25m ago•0 comments

LR Scheduler Playground

https://lr-scheduler-playground.streamlit.app
1•yllberisha•26m ago•0 comments

Is AI-assisted coding an incident magnet?

https://leaddev.com/software-quality/ai-assisted-coding-incident-magnet
1•sylvainkalache•28m ago•0 comments

Men worse off than women for 20 top health problems worldwide

https://medicalxpress.com/news/2025-05-men-worse-women-health-problems.html
1•PaulHoule•29m ago•0 comments

Qwen 3 1.7B running locally on mobile at 30 tokens/s

https://twitter.com/swmansion/status/1920134833520427169
2•chmjkb•30m ago•0 comments

I built a platform to find tech conferences, discounts, and ticket giveaways

https://www.tech.tickets/
2•danthebaker•30m ago•2 comments

OSR Development Community

https://community.osr.com/
1•notepad0x90•31m ago•0 comments

Ed Smylie, Who Saved the Apollo 13 Crew with Duct Tape, Dies at 95

https://www.nytimes.com/2025/05/16/science/space/ed-smylie-dead.html
2•sohkamyung•33m ago•1 comments

Postman is logging all your secrets and environment variables

https://anonymousdata.medium.com/postman-is-logging-all-your-secrets-and-environment-variables-9c316e92d424
5•primitivesuave•34m ago•1 comments

We graded 19 LLMs on SQL. You graded us

https://www.tinybird.co/blog-posts/we-graded-19-llms-on-sql-you-graded-us
2•_peregrine_•35m ago•0 comments