frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Parallel Reconstruction of Lawful TLS Wiretapping

https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/
10•jerrythegerbil•1h ago

Comments

TZubiri•39m ago
What LI vendors can break https?
jerrythegerbil•17m ago
The sloppy ones who want a huge headache and leave a publicly auditable trail a mile long that get analysis blogs written about their mistakes.
perching_aix•29m ago
> TLS wiretapping with root-CA-signed certificates is a thing that both happens and verifiably has happened. (...) This being a fact rather than a conspiracy theory tends to upset people.

Maybe what people get upset about is catchy misleading [0] summaries like this, which suggest [0] a CA - nation state collusion, despite the actual story going in a completely different [0] direction?

[0] in the eye of the beholder of course, as always

ranger_danger•11m ago
I could see this actually being a real parallel reconstruction for a state actor that did issue certificates from a compromised CA. If any evidence points back to them, they can just say the server was hacked with the acme RCE to generate different certs. There probably won't be a way to legally verify that such a thing never happened.
ls612•25m ago
I thought certificate transparency was the thing that was supposed to prevent exactly what this article is describing. What if anything is incorrect about my model of the world in this respect?
zinekeller•18m ago
Basically, CT did indeed worked as designed, but there was no monitoring by the domain authors (which to be fair there are a dearth of solutions of the time).

On a related note, Let's Encrypt also issued the presumably-interception certificates. This can be possibly something that requires interception at the VPS level (otherwise we already detected the BGP leaks). Presumably, Hetzner was forced to do a raw interception and then redirecting all relevant ports to a middlebox for inspection and CA issuance (and since that the ACME spec is well-defined, they can simply check if the handshake contains the TLS ALPN challenge and then redirect them to special code that will reply with the correct things).

perching_aix•18m ago
Nothing, although it's more mitigate than prevent per se. They simply did not have alerting set up against the CT logs. It is one of the lessons they highlighted in their own postmortem.
jerrythegerbil•2m ago
Certificate transparency worked exactly as designed in this case. Monitoring public certificate transparency logs for anomalies is a different story entirely.

By breaking the software facilitating https via ACME itself, no anomalous certificate transparency logs would have needed to have been created at all.

The front door is locked quite tightly with a watchful security camera, but the window has been left unlocked. Also no one is watching the camera feed.

OpenRouter raises $113M Series B

https://openrouter.ai/announcements/series-b
239•freeCandy•3h ago•107 comments

Zig ELF Linker Improvements Devlog

https://ziglang.org/devlog/2026/#2026-05-30
124•kristoff_it•3h ago•18 comments

I found a seashell in the middle of the desert

https://github.com/Hawzen/I-found-a-seashell-in-the-middle-of-the-desert
61•Hawzen•1d ago•7 comments

Show HN: 500 years of Joseon court omens as an observability dashboard

https://ajin.im/is/building/omen.ops/
38•poppypetalmask•1h ago•1 comments

Hormuz crisis side effect: a sharp rise in container shipping rates

https://www.lloydslist.com/LL1157327/Hormuz-crisis-side-effect-a-sharp-rise-in-container-shipping...
99•mooreds•2h ago•54 comments

Jef Raskin, the Visionary Behind the Mac (2013)

https://lowendmac.com/2013/jef-raskin-the-visionary-behind-the-mac/
17•tylerdane•1h ago•11 comments

Voxel Space (2017)

https://s-macke.github.io/VoxelSpace/
216•davikr•6h ago•48 comments

Microcode inside the Intel 8087 floating-point chip: register exchange

https://www.righto.com/2026/05/microcode-inside-intel-8087-floating.html
56•pwg•3h ago•14 comments

Parallel Reconstruction of Lawful TLS Wiretapping

https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/
10•jerrythegerbil•1h ago•8 comments

Openrsync: An implementation of rsync, by the OpenBSD team

https://github.com/kristapsdz/openrsync
264•sph•10h ago•121 comments

Pandoc Templates

https://pandoc-templates.org/
324•ankitg12•10h ago•45 comments

Werner Herzog in conversation with Paul Cronin (2014)

https://fsgworkinprogress.com/2014/09/26/insignificant-bullets-evil-poachers-and-l-a-culture/
53•Michelangelo11•4h ago•18 comments

EY Canada published a cybersecurity report and most citations were hallucinated

https://gptzero.me/investigations/ey
196•smartmic•1h ago•81 comments

It Takes Two Neurons to Ride a Bicycle

https://fermatslibrary.com/s/it-takes-two-neurons-to-ride-a-bicycle#email-newsletter
77•malshe•4d ago•29 comments

Navier-Stokes fluid simulation explained with Godot game engine

https://myzopotamia.dev/navier-stokes-fluid-simulation-explained-with-godot
145•myzek•3d ago•22 comments

Downdetector and Speedtest sold to Accenture for $1.2B

https://www.theverge.com/tech/889234/downdetector-ookla-speedtest-sold-accenture
151•Garbage•4h ago•79 comments

We are constantly broadcasting emotional data

https://www.tonyrice.me/emotional-intelligence/
11•tonyrice•2h ago•0 comments

A disappearing Service Processor (2025)

https://oxide.computer/blog/cosmo-sp
4•mooreds•48m ago•0 comments

IXI's autofocusing lenses are almost ready to replace multifocal glasses

https://www.engadget.com/wearables/ixis-autofocusing-lenses-multifocal-glasses-ces-2026-212608427...
126•amichail•3d ago•57 comments

An OS in pure Rust with its own TCP/IP and TLS 1.3 stack, fetching the live web

https://github.com/rfi-irfos/rusty-penguin
4•simeon-kepp•58m ago•0 comments

Leo's first encyclical attacks technological messianism

https://www.economist.com/europe/2026/05/28/leos-first-encyclical-attacks-technological-messianism
127•1vuio0pswjnm7•10h ago•163 comments

Zig: Build System Reworked

https://ziglang.org/devlog/2026/#2026-05-26
303•tosh•12h ago•193 comments

What Happened to the Locusts?

https://explosion-scratch.github.io/locusts/
179•explosion-s•4d ago•42 comments

Show HN: Helios – what plug-in solar could generate for any address in Britain

https://helios.southlondonscientific.com/
97•ruaraidh•9h ago•36 comments

SQLite is all you need for durable workflows

https://obeli.sk/blog/sqlite-is-all-you-need-for-durable-workflows/
661•tomasol•1d ago•360 comments

Stateless Actors

https://www.massicotte.org/stateless-actors/
18•frizlab•1d ago•7 comments

Searching for Birds

https://SearchingForBirds.VisualCinnamon.com/
16•robin_reala•2d ago•2 comments

WH proposes rules giving political appointees final approval on research grants

https://www.scientificamerican.com/article/white-house-proposes-new-rules-giving-political-appoin...
178•jordanpg•19h ago•442 comments

Testing the WWI concrete ships and WWII concrete barges

https://thecretefleet.com/blog/f/testing-the-wwi-concrete-ships-and-wwii-concrete-barges
36•surprisetalk•1d ago•11 comments

Memory decline after menopause linked to loss of estrogen production in brain

https://news.northwestern.edu/stories/2026/05/memory-decline-after-menopause-linked-to-loss-of-es...
124•gmays•6h ago•57 comments