frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Upcoming changes to Let's Encrypt and how they affect XMPP server operators

https://blog.prosody.im/2026-letsencrypt-changes/
33•zaik•1h ago

Comments

PunchyHamster•53m ago
Shame LE didn't give people option to generate client and client+server auth certs
forty•38m ago
Yes, but then the lack of pragmatism shown by the XMPP community is a bit disconcerting
superkuh•15m ago
It is not pragmatic to design your protocol for web use cases when it's not the web.
jammcq•45m ago
I like how the article describes how certificates work for both client and server. I know a little bit about it but what I read helps to reinforce what I already know and it taught me something new. I appreciate it when someone takes the time to explain things like this.
RobotToaster•42m ago
Why did LE make this change? It feels like a rather deliberate attack on the decentralised web.
duskwuff•30m ago
Not precisely an answer, but there's some related discussion here:

https://cabforum.org/2025/06/11/minutes-of-the-f2f-65-meetin...

The real takeaway is that there's never been a lot of real thought put into supporting client authentication - e.g. there's no root CA program for client certificates. To use a term from that discussion, it's usually just "piggybacked" on server authentication.

mhurron•28m ago
No, it feels like the standard 'group/engineer/PM' didn't think anyone did anything different from their own implementation.

Lets Encrypt is just used for like, webservers right, why do this other stuff webservers never use.

Which does appear to be the thinking, though they blame Google, which also seems to have taken the 'webservers in general don't do this, it's not important' - https://letsencrypt.org/2025/05/14/ending-tls-client-authent...

pseudalopex•28m ago
Google forced separate client and server PKIs.[1]

[1] https://letsencrypt.org/2025/05/14/ending-tls-client-authent...

ameliaquining•25m ago
Google has recently imposed a rule that CA roots trusted by Chrome must be used solely for the core server-authentication use case, and can't also be used for other stuff. They laid out the rationale here: https://googlechrome.github.io/chromerootprogram/moving-forw...

It's a little vague, but my understanding reading between the lines is that sometimes, when attempts were made to push through security-enhancing changes to the Web PKI, CAs would push back on the grounds that there'd be collateral damage to non-Web-PKI use cases with different cost-benefit profiles on security vs. availability, and the browser vendors want that to stop happening.

Let's Encrypt could of course continue offering client certificates if they wanted to, but they'd need to set up a separate root for those certificates to chain up to, and they don't think there's enough demand for that to be worth it.

kej•18m ago
>when attempts were made to push through security-enhancing changes to the Web PKI, CAs would push back on the grounds that there'd be collateral damage to non-Web-PKI use cases

Do you (or anyone else) have an example of this happening?

detourdog•16m ago
I’m disappointed that a competitor doesn’t exist that uses longevity of IP routing as a reputation validator. I would think maintaining routing of dns to a static IP is a better metric for reputation. Having unstable infrastructure to me is a flag for fly by night operations.
everfrustrated•31m ago
From https://letsencrypt.org/2025/05/14/ending-tls-client-authent...

"This change is prompted by changes to Google Chrome’s root program requirements, which impose a June 2026 deadline to split TLS Client and Server Authentication into separate PKIs. Many uses of client authentication are better served by a private certificate authority, and so Let’s Encrypt is discontinuing support for TLS Client Authentication ahead of this deadline."

TL;DR blame Google

A social network where AI agents and humans coexist with hidden identities

1•Genesis-pj•2m ago•0 comments

The Failure Mode That Lets AI Keep Going Without Ever Fixing Itself

https://figshare.com/articles/presentation/Constraint_Collapse_and_Fidelity_Decay_in_Scaled_Langu...
1•scaledsystems•2m ago•1 comments

Minions: Stripe's one-shot, end-to-end coding agents

https://stripe.dev/blog/minions-stripes-one-shot-end-to-end-coding-agents
1•ains•3m ago•0 comments

What's All This Muntzing Stuff, Anyhow? (1992)

https://www.electronicdesign.com/technologies/industrial/boards/article/21771148/whats-all-this-m...
1•kmstout•4m ago•0 comments

LiftKit – UI where "everything derives from the golden ratio"

https://www.chainlift.io/liftkit
1•peter_d_sherman•5m ago•0 comments

Tell HN: Firefox v147 supports redefining built-in keyboard shortcuts such as ^w

https://support.mozilla.org/en-US/kb/customize-keyboard-shortcuts-firefox
1•goplayoutside•8m ago•1 comments

Covid, War, Red Sea: 80% of Europe's Supply Chain Rocked by Crisis (2025)

https://www.modaes.com/global/markets/from-covid-to-the-red-sea-80-of-the-european-supply-chain-s...
1•ta9000•12m ago•0 comments

China Population Density Map

https://www.woatlas.com/density/china/
1•madewulf•15m ago•0 comments

Why Spec-Driven Development Breaks at Scale (and How to Fix It) – Arcturus Labs

http://arcturus-labs.com/blog/2025/10/17/why-spec-driven-development-breaks-at-scale-and-how-to-f...
1•JnBrymn•15m ago•0 comments

Discord faces backlash over age checks after data breach exposed 70k IDs

https://arstechnica.com/tech-policy/2026/02/discord-faces-backlash-over-age-checks-after-data-bre...
2•MysticOracle•15m ago•1 comments

QFuture Loves C++ Coroutines

https://www.arnorehn.de/blog/2026/02/09/qfuture-c-coroutines/
1•pumphaus•16m ago•0 comments

Bcachefs Could Lose Data

https://old.reddit.com/r/bcachefs/comments/1qyryzn/psa_if_youre_on_133135_upgrade_asap/
1•r0l1•16m ago•1 comments

It's Time for America to Admit That It Has a Marijuana Problem

https://www.nytimes.com/2026/02/09/opinion/regulate-legalized-marijuana.html
5•WheelsAtLarge•19m ago•2 comments

Composer 1.5

https://cursor.com/blog/composer-1-5?trk=feed-detail_main-feed-card_feed-article-content
1•sonabinu•19m ago•0 comments

Towards Perfect Vulnerability Management System

https://worklifenotes.com/2026/02/09/towards-perfect-vulnerability-management-system/
1•taleodor•20m ago•0 comments

Ask HN: How often do you update your (n)vi(m) config?

1•malikNF•20m ago•0 comments

No ICE in Minnesota bundle launches on itch.io

https://itch.io/b/3484/no-ice-in-minnesota
2•HelloUsername•22m ago•0 comments

OpenClaw Partners with VirusTotal for Skill Security

https://openclaw.ai/blog/virustotal-partnership
1•celalemre•22m ago•0 comments

How to Make Claude Code Skills Activate Reliably

https://scottspence.com/posts/how-to-make-claude-code-skills-activate-reliably
2•spences10•24m ago•0 comments

Against fancy ligatures in programming fonts

https://practicaltypography.com/ligatures-in-programming-fonts-hell-no.html
1•fanf2•25m ago•0 comments

Polymarket sues Massachusetts in federal court over state betting law

https://www.universalhub.com/2026/polymarket-wanna-injunction-against-massachusetts-over-its-21st...
1•ilamont•26m ago•0 comments

Ask HN: It has been 2 months, is anyone using GPT Apps?

3•break_the_bank•26m ago•0 comments

FDA approves at-home tDCS as first non-drug standalone treatment for depression

https://spectrum.ieee.org/flow-neuroscience-tdcs-depression-fda
1•raindeer2•27m ago•0 comments

Show HN: WikiCommute – a time‑boxed Wikipedia rabbit hole for your commute

https://wikicommute.vercel.app/
1•Roccan•27m ago•0 comments

I used Claude Code in a real data journalism project

https://kschaul.com/post/2026/02/09/2026-02-09-ai-data-journalism/
1•kschaul•27m ago•0 comments

'Hidden' bugs in our gut appear key to good health, finds global study

https://www.cam.ac.uk/research/news/hidden-bugs-in-our-gut-appear-key-to-good-health-finds-global...
1•gnabgib•28m ago•0 comments

AI Personality Extraction from Faces: Labor Market Implications

https://www.nber.org/papers/w34808
1•gwintrob•28m ago•0 comments

Ulster County "I Voted" sticker

https://en.wikipedia.org/wiki/Ulster_County_%22I_Voted%22_sticker
1•kmm•30m ago•0 comments

Agentic Coding Is Draining Your Moat

https://www.slwip.com/agentic-coding-is-draining-your-moat/
3•andremarais•32m ago•2 comments

Backseat Frying (2020)

https://backseatfrying.net/
1•PaulHoule•34m ago•0 comments