A Note from our Executive Director

Post Syndicated from Let's Encrypt original https://letsencrypt.org/2025/12/29/eoy-letter-2025.html

Josh Aas

This letter was originally published in our 2025 Annual Report.

This year was the 10th anniversary of Let’s Encrypt. We’ve come a long way! Today we’re serving more than 700 million websites, issuing ten million certificates on some days. Most importantly, when we started 39% of page loads on the Internet were encrypted. Today, in many parts of the world, over 95% of all page loads are encrypted. We can’t claim all the credit for that, but we’re proud of the leading role we played. Being able to help ISRG and Let’s Encrypt get to where we are today has been the opportunity of a lifetime for me.

There’s more I could talk about from the past ten years, but this 10th year was about as good as any before it so I want to focus on our most recent work. I’ll get the headline for 2025 out right away: over the past year we went from serving 492 million websites to 762 million. That’s a 50% increase in a single year, equivalent to the growth we saw over our first six years of existence combined. Our staff did an amazing job accommodating the additional traffic.

I’m also particularly proud of the things we did to improve privacy this year, across all of our projects.

At the start of 2025 we were serving over four billion Online Certificate Status Protocol (OCSP) requests per day. That’s 180 million per hour, or 50,000 per second. OCSP has been an important mechanism for providing certificate revocation information for a long time, but the way it works is bad for privacy. It requires browsers to check with certificate authorities for every website they visit, which is basically providing your browsing history to third parties. Let’s Encrypt never held onto that data; it got dropped immediately. However, there is no way to know if that was standard practice across the industry, and even well-intentioned CAs could make a mistake or be compelled to save that data. It was a system ripe for abuse, so we decided to become the first major CA to turn off our OCSP service. We couldn’t be sure what the full impact would be, but this was a way in which the Internet needed to get better. In August of 2025 we turned off our OCSP service. There was no major fallout and we haven’t looked back.

Another big privacy-focused change we made to Let’s Encrypt in 2025 was no longer storing subscriber email addresses in our CA database, associated with issuance data. In June of this year we stopped adding the optional email addresses that subscribers send to our database, and we deleted the millions of email addresses that had accumulated over the years. Making this change was not an easy thing to decide to do—it limits our ability to contact subscribers and we had to turn off our expiration reminder email service—but we feel the ecosystem has grown enough over the past ten years that the privacy implications of holding onto the email addresses outweighed the utility.

Privacy was at the forefront for the folks at ISRG researching human digital identity as well. They have been hard at work on an implementation of the Anonymous Credentials from ECDSA scheme, also known as Longfellow. This is a cryptographic library that can be used in digital identity management, including things like digital wallets, in order to improve privacy when sharing credentials. Digital identity systems should have strong privacy and compatibility requirements, but such requirements pose challenges that existing digital credential technologies are going to struggle to meet. New schemes such as Longfellow aim to address these challenges, bringing privacy improvements to systems that need to work with existing cryptographic hardware. This is exciting stuff, but not easy to build (so much math!)—watching our talented engineers make progress has been thrilling.

The last example of great privacy work I want to highlight from 2025 is our Prossimo project’s work towards encrypted recursive-to-authoritative DNS. Prossimo is focused on bringing memory safety to critical software infrastructure, but sometimes that dovetails nicely with other initiatives. DNS queries are fundamental to the operation of the Internet. Without getting into the details here too much, there are basically two types of DNS queries: stub-to-recursive and recursive-to-authoritative. A lot of work has gone into encrypting stub queries over the past decade, mostly through DNS over HTTPS (DoH) initiatives. Authoritative queries, however, remain almost entirely unencrypted. This is a particular problem for Certificate Authorities like Let’s Encrypt. During 2025, our Prossimo project started work on changing that, investing heavily in encrypted authoritative resolution by implementing RFC 9539 Unilateral Opportunistic Deployment of Encrypted Recursive‑to‑Authoritative DNS and other related improvements in Hickory DNS. Once this is ready, early in 2026, Hickory DNS will be a high performance and memory safe option that DNS operators can use to start making and receiving encrypted authoritative DNS queries. It can also be used for integration testing with other DNS implementations.

It’s wonderful, and a real responsibility, to be able to have this kind of positive impact on the lives of everyone using the Internet. Charitable contributions from people like you and organizations around the world make what we do possible. We are particularly grateful to Jeff Atwood, Betsy Burton, and Stina Ehrensvärd for their special gifts this year. Since 2015, tens of thousands of people have donated. They’ve made a case for corporate sponsorship, given through their DAFs, or set up recurring donations. If you’re one of those people, thank you. If you’re considering becoming a supporter, I hope this annual report will make the case that we’re making every dollar count.

Every year we aim to make the dollars entrusted to us go as far as possible, and next year will be no exception.

Факти за машинното гласуване

Post Syndicated from Bozho original https://blog.bozho.net/blog/4553

Продължава активната комуникационна кампания против машинното гласуване. Ето основните манипулации, които виждам:

  1. „ДБ бяха ‘против’ машините преди 21-ва, а сега са ‘за’“ (подплатено с видео, в коетонс Иво Мирчев обясняваме потенциалните проблеми). Каква е реалността: при въвеждането на машините от ГЕРБ, не бяха предвидени достатъчно гаранции за прозрачност и проследимост на процеса. Никой нямаше достъп до изходния код, а гаранците, че инсталираният софтуерът е правилният не бяха приложени в процедурата. При промените на Изборния кодекс април 21-ва по наше предложение бяха приети такива промени (чл. 213а). След редица наши писма до ЦИК, бяха реализирани много от необходимите гаранции. И затова сега процесът е много по-добър от предвидения с промените на ГЕРБ от 2020 г. В резултат на наши инициативи и промени.
  2. „Има секции със сериозни разминавания между машинния протокол и разписките“. Каква е реалността: във всички случаи на установени такива разминавания е правена проверка от ЦИК и е установявано, че грешката е в секционната комисия, която е броила или записала резултата грешно. Примерът със 77 гласа в машинния протокол и 7 гласа при броенето показа, че комисията е написала 7 вм. 77, т.е. машината е била права. След въвеждането на специалната хартия има повече разминавания заради неиздадени расписки, което се дължи изцяло на неподходящата хартия.
  3. „Възрастните хора не могат да гласуват с машина“. Това твърдение от опонентите на машините е даже обидно. Хората са възрастни, а не глупави. Няма данни, които да потвърждават това твърдение. Има обратни данни в социологически проучвания: че подкрепата за машинното гласуване е по-висока в сегмента 65+.
  4. „Зам.министърът на електронното управление снима и изнесе КОДОВЕТЕ НА МАШИНИТЕ“ – това е направо комично. Но беше част от активното мероприятие на ДАНС срещу машините на местните избори. Кодът на машините не е тайна. Той е достъпен за всеки, който заяви достъп (от името на партия или изборен наблюдател). Досъдебното производство по случая доколкото знам е прекратено. Защото няма извършено престъпление. Но беше достатъчно да се измисли тая глупост, за да се махнат машините тогава.
  5. „ПП спечелиха изборите 21-ва заради машините“. Избори при изцяло машинно гласуване са печелили три партии: ИТН, ПП и ГЕРБ. И няма сериозни разминавания между екзит полове и реалните данни.
  6. „Избирателната активност пада заради машините“ – избирателната активност спада от 2021-ва година по изцяло политически причини. След като беше върната хартията, избирателната активност не се повиши, а продължи да спада (веднага след връщането на хартията активността е с 2% под активността на първите избори с изцяло машинно гласуване)

Какви са реалните причими да не искат машини?

  1. Няма тъмна стаичка, т.е. няма снимане с телефон, няма конци, няма нишки, няма нито една от схемите за гарантиране на купения вот.
  2. Не можеш да си купиш цяла секционна комисия, която да пуска бюлетини в урната след края на изборния ден. Може на машината да се пускат гласовв, но това оставя следа, която после е проверима и се доказва манипулацията много лесно (примери има в решението на Конституционния съд).
  3. ГЕРБ и ДПС не могат да контролират машините и това ги кара да си мислят, че някой друг ги контролира. Започнали са да вярват в собствената си пропаганда и да градят конспиративни теории.

И в тази връзка припомням девет факта за машините:

  1. Машините осигуряват коректно отчитане на резултата, без човешки грешки (съзнателни или несъзнателни). С машините не може да има невалидни бюлетини (вкл. направени такива от секционната комисия)
  2. С машините пускането на бюлетини от самата секционна комисия (когато цялата е купена) е много по-трудно, защото оставя следа в лога на машината – такива проблеми установи Конституционния съд и „касира“ някои такива секции.
  3. Машините са достъпен начин за гласуване, който е толкова лесен, колкото хартията. Дори в някои случаи по-лесен, като напр. за хора със зрителни увреждания.
  4. Изборният резултат при машинно гласуване излиза много по-бързо, а не трябва да се чака до обяд на следващия ден
  5. Няма никакви проблеми с преференциите, които при броене на хартия често се пропускат – имахме случай на кандидат, който беше на ръба на прага на преференциите и не влезе, защото не всички комисии бяха броили преференции.
  6. Кодът на машините е достъпен за всяка партия, която го поиска – съгласно промени в Изборния кодекс, които ние сме предложили. Така че никой не може да го „открадне“, „снима“, „пипа“ и други глупости.
  7. В изтеклия запис от заседанието на колегите от ПП няма никъде думите „ала-бала с машините“.
  8. Може (и трябва) да бъде въведено максимално широко контролно броене на разписки – така ще отпаднат всякакви съмнения, че някакви гласове са надписани или премахнати в машинния протокол. До момента винаги, когато е имало разминаване между разписки и машина, се е оказвало, че става дума за човешка грешка при броенето.
  9. Процесът по удостоверяване и процесът по инсталиране на софтуера на машините е проследим и е под контрола на ЦИК, а не на фирмата-доставчик. Дори някой да има физически достъп до машините, не може да направи нищо без ЦИК, които държат ключа.

Рационален разговор за Изборния кодекс е възможен и както винаги ние ще го водим.

Материалът Факти за машинното гласуване е публикуван за пръв път на БЛОГодаря.

Friday Squid Blogging: Squid Camouflage

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2025/12/friday-squid-blogging-squid-camouflage.html

New research:

Abstract: Coleoid cephalopods have the most elaborate camouflage system in the animal kingdom. This enables them to hide from or deceive both predators and prey. Most studies have focused on benthic species of octopus and cuttlefish, while studies on squid focused mainly on the chromatophore system for communication. Camouflage adaptations to the substrate while moving has been recently described in the semi-pelagic oval squid (Sepioteuthis lessoniana). Our current study focuses on the same squid’s complex camouflage to substrate in a stationary, motionless position. We observed disruptive, uniform, and mottled chromatic body patterns, and we identified a threshold of contrast between dark and light chromatic components that simplifies the identification of disruptive chromatic body pattern. We found that arm postural components are related to the squid position in the environment, either sitting directly on the substrate or hovering just few centimeters above the substrate. Several of these context-dependent body patterns have not yet been observed in S. lessoniana species complex or other loliginid squids. The remarkable ability of this squid to display camouflage elements similar to those of benthic octopus and cuttlefish species might have convergently evolved in relation to their native coastal habitat.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

[$] An early look at the Graphite 2D graphics editor

Post Syndicated from jzb original https://lwn.net/Articles/1051242/

Graphite is an effort to unify
illustration, raster editing, desktop publishing, and animation in one
browser-based application. The project has been in development since
2020 and announced its first alpha release in 2022. According to creator Keavon Chambers, the project’s mission is to become
“the 2D counterpart to Blender“, by bringing a node-based,
non-destructive workflow to 2D graphics. The project, currently still in
alpha, is a long way from complete; but it is worth testing for anyone
involved with open-source-graphics production. Current
builds
, from September 2025, include vector-illustration tools, a
node-based compositor, and early brush tooling, with broader pixel-based-
and photo-editing work still in progress.

The collective thoughts of the interwebz