Bonum Certa Men Certa

Techrights Urges Readers to Ask the Linux Foundation's Let's Encrypt (Backed by Companies That Give the NSA Back Doors) Some Hard But Legitimate Questions

Logo of Let's Encrypt



Summary: It's not impossible that the bug in Let's Encrypt was introduced by a rogue insider, if not someone further up above; Let's Encrypt must address critical questions or be widely seen as a compromised, untrustworthy CA

JUST like the Linux Foundation, Let's Encrypt is using Microsoft GitHub for their site and for their code. So much for security, eh? It's owned by Microsoft, possibly the NSA's closest partner. But putting that aside, today's certificates avalanche led us to discovering that the Foundation's executive who came there from James Clapper's office has left the Foundation (she vanished from the management's page). It's likely just a coincidence, but bringing that up isn't crazy. We wrote about half a dozen articles already about how the Linux Foundation works for 'surveillance capitalism' and the 'security state'. It's a matter of public record and it's easily provable using basic open source intelligence (OSINT).



At work last night, I actually had to step in for clients and urgently change certificates (to avert downtime of critical services). The fiasco is starting to show up in more of the media (but not much of it so far).

We have some facts. For instance, it is clear that somebody changed the code and we don't know when exactly. This article explains that "Let’s Encrypt explained on Tuesday [less than a day early] it had to revoke the 3 million certificates because of a CAA bug that impacted the way its software checked domain ownership before issuing certificates."

Here's what they told the writer: "Josh Aas, executive director of Let’s Encrypt, said in a statement to Threatpost, “A bug was introduced in our code during a feature flag update. Under certain conditions, this bug caused us to skip a check that we are required to perform before issuing a certificate. We determined that the bug affected about 3 million, or about 2.6 percent, of our active certificates. Unfortunately, we need to revoke these certificates, which we will be doing within the compliance timeline set forth by the Baseline Requirements.”"

According to this, "Let's Encrypt will be revoking 3,048,289 currently-valid certificates" (notice how they're contradicting themselves with the numbers).

"As part of the rules for this feature," it adds, "authorities must check CAA records at most 8 hours before a certificate is issued."

Also: "With only 24 hours to renew their certificates, many users are scrambling to get them done and some are running into issues."

Yes, I should know. This caused much alarm where I work. It's a fiasco.

We urge readers to ask Let's Encrypt the following questions (maybe more, maybe less)



The E-mail address to reach them on: security@letsencrypt.org

Alternative/additional E-mail: press@letsencrypt.org

Please share their answers, if any, with us.

If they fail to even respond to these questions, that will not inspire confidence, will it?

Remember Gemalto?

Recent Techrights' Posts

Links 29/04/2026: "Snowden Affair 13 Years Later" and "Landmark Data Center Pause"
Links for the day
IBM is Already Doing 'Voluntary' Layoffs This Year in Europe ('Buyouts' Ahead of Mass Layoffs)
IBM's efforts to hide or belittle layoffs is noteworthy
Like GAFAM, US Telecom Industry Has Severe Debt Problem
Maybe their real problem is true profitability
Latest Example of False Marketing by Anthropic
Like Scam Altman, they're better at buying publicity (paying for hype) than they are at delivering something of genuine value [...] That has the full make-up of fake news and a publicity stunt
IBM: From RAs to "Workforce Re-balancing" (New Names for Mass Layoffs)
Well, "workforce re-balancing" means "RAs", which is a misleading acronym IBM has devised to soften if not hide mass layoffs.
Microsoft's Grip Has Slipped, Market Share Steadily Declining
This is why Microsoft is having financial issue
 
Slop Has a Long Way to Go Before It Gets Basic Facts Right
Please do not rely on slop for anything
The Corrupt Lecture the Non-Corrupt - Part IX - European Patents That Are Illegal (But Serve Non-European Monopolists in Exchange for 'Quick Cash')
People who shamelessly violate the European Patent Convention (EPC) have the audacity to lecture workers on "ethics"
Canonical is Selling You, Ubuntu is a Data-Collecting Platform
Canonical is looking for money in the wrong places
Seems Like Only Techrights Covered IBM Laying Off About 33% of Confluent Staff
How can such a large round of layoffs evade today's media?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, April 28, 2026
IRC logs for Tuesday, April 28, 2026
Gemini Links 29/04/2026: Bad Diet, New Middle Ages, and Temperature Model
Links for the day
Tracing Back the Misuse of the Word "Buyout" to Describe Merciless Mass Layoffs
So we can assume very large Microsoft layoffs are on the way, this time not spun as "buyouts"
Growing the List of Sites That Are Rogue
It's very important to raise and spread awareness of which ones are fake
Links 28/04/2026: Uganda Criminalising ‘Foreign Agents’ and China’s Economy "Starts to Show Cracks"
Links for the day
Anthropic and Claude Are National Security Risks Not Because of Politics But False Marketing and Vandalism, Plagiarism Sold as Innovation
The slop hype is causing severe damage
Gemini Links 28/04/2026: Misfin, ELPiS, and Developing Another Gemini Client
Links for the day
US Government Sites See More Traffic From Apple Devices Than Microsoft Windows PCs
Keep this in mind when Microsoft talks about mass layoffs while calling these "buyouts"
Layoffs Versus Buyouts
Microsoft has mass layoffs and those target the most experienced people in one of the best-paid locations
Aaron Hillel Swartz Would Have Turned 40 This Year
Aaron Swartz killed himself in 2013
The Trumps Are Making Jimmy Kimmel More Famous and Popular
Comedy has long been "controversial", but trying to get people sacked for the 'wrong' joke results in having no comedians or only pseudo-comedians who are the dictator's jester/joker
Links 28/04/2026: Microsoft's GitHub Upselling After Two Leaders Jumped Ship (Losses Pile Up), "Inflation Jumps," and More
Links for the day
SLAPP Censorship - Part 60 Out of 200: Talking About Corruption at Microsoft and Arrest for Strangulation is "Malice"
At the moment Brett Wilson LLP has no new clients
The Corrupt Lecture the Non-Corrupt - Part VIII - "Red Line" When the European Patent Office (EPO) President Sleeps With Sister of "Cocaine Communication Manager" (Whom He Unconditionally Protects)
If only management took its own words (idealistic pontification) seriously
IBM Laying Off Thousands of Workers Again, Based on Q1 Earnings Call
under the guise of "workforce rebalancing" we are again seeing that IBM plans to pay people (severance) to leave
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, April 27, 2026
IRC logs for Monday, April 27, 2026
Gemini Links 28/04/2026: Good Sunrise Viewing and Self-hosting from Home
Links for the day[1;5C
Microsoft Insiders: If You Don't Take the Lousy Severance-Like Offer, They'll PIP You Out (Microsoft Signals to People Over 40 That They'd Better Vacate the Place)
Microsoft targets its most experienced (read: expensive) workers
"AI" 16 Times in One 'Article'. The Register MS Got Paid to Post This Spammy, Promotional Piece of Slop.
Pay closer attention to who pays and who gets paid
Links 27/04/2026: Chernobyl Disaster at 40, "Heartbreaking" Decline of Australia
Links for the day
Gemini Links 27/04/2026: Gopher Catchup, MNT Reform, and Injuries
Links for the day
Red Hat Circling Down the Slop Drain
IBM, governed by slop fanatics, is going to do a lot of damage
Slop is an Addiction, Its Users Find It Addictive
please do not tolerate people who slop
The Corrupt Lecture the Non-Corrupt - Part VII - Secrecy at the EPO (Regarding Cocaine and Nepotism) Has Undermined Trust in Management
If Europe's second-largest institution is run by the "Alicante Mafia", does this mean that other key European institutions are "Mafia"?
SLAPP Censorship - Part 59 Out of 200: Mentioning the Fact Alex Graveley Arrested and Charged for Strangulation in Texas is "Reckless" and "Malicious", According to His 'Hired Guns' in London
it was framed as "malicious"
Links 27/04/2026: Strikes, Corruption in Spain (Spanish PM Sanchez' Wife), and YouTuber Faces Jail Time
Links for the day
Gemini Links 27/04/2026: Gopher Catch-up, Year of Contentment, and Path to Freedom
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, April 26, 2026
IRC logs for Sunday, April 26, 2026