#LetsEncrypt has suspended issuing certificates after it identified security issues in one of its roots (!)[^1]

We temporarily disabled certificate issuance, deployed a configuration change to prevent future issuance from the cross-signed Gen Y hierarchy, and then re-enabled issuance. Certificate revocation and CRL generation remains functional for Gen Y certificates.

A few days ago #DigiCert was hacked with a Windows (!) screensaver (!)[^2]

I cannot but remind that both organisations are part of the #WebTrust cartel who had last year unrolled a massive “grassroots” smear campaign against EU #QWAC certificates, presenting them as “security and privacy threat”, whereas from both legal and technical point of view QWAC is much more secure:

https://krvtz.net/en/posts/the-real-story-behind-eu-qwac.html

[^1]: https://community.letsencrypt.org/t/2026-05-08-gen-y-cross-certified-subordinate-cas-missing-serverauth-eku/247105

[^2]: https://cybersecuritynews.com/digicert-hacked-screensaver/

The real story behind EU QWAC

In 2023 technical social media were shaken by a wave of criticism of EU QWAC (Qualified Website Authentication Certificate) which, according to the critics, was essentially tool of mass surveillance.

Infrastructure and Application Security

👮🏼‍♀️When you bake a gatekeeper right into your browser…but instead of placing that power in a transparent, representative organization (🌍 UN, W3C, etc.),
you think: “Let’s just leave that to Google Search.” 🙃

👉 Result: open-source projects like Immich get flagged as “dangerous.”

#DigitalSovereignty #OpenSource #Google #WebTrust #DecentralizeTheWeb

https://immich.app/blog/google-flags-immich-as-dangerous

Google flags Immich sites as dangerous | Immich Blog

How Google actively breaks Immich deployments, an open-source Google Photos alternative.

Immich Blog — Latest updates, announcements, and stories from the Immich team.

@danimo

This is a complete misrepresentation of both #eIDAS and the #WebTrust that Mozilla tries to defend with its manipulative campaign. I explained it in details here:

https://agora.echelon.pl/notice/AbOiM4RCpo4HpQzYzQ

Specifically, “disallowing CT” is a completely invented accusation, just as “forcing browsers to include government root CA”, “enables surveillance” and “making it illegal to fix”. There’s literally zero evidence in the regulation supporting these accusations. And when Helme writes “it’s just EV”, it just demonstrates he has literally zero clue about what EU QCA infrastructure is.

kravietz 🦇 (@[email protected])

The outcry about #eIDAS is highly manipulative and very much resembles the infamous #ACTA2 campaign, where a number of US-based companies unrolled a fake "grassroots protest" against an EU regulati...

How to Build Trust with Users on Classified Ads Websites  - Blog

Building trust with users on classified ads websites is essential for the success of any such platform. By following the tips outlined in this article, you

Blog