<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: jaas</title><link>https://news.ycombinator.com/user?id=jaas</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 15 Jun 2026 18:12:33 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=jaas" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by jaas in "Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]"]]></title><description><![CDATA[
<p>I'm not sure if you're talking generally about sanctions or specifically about Let's Encrypt, but to avoid any doubt: citizens of Crimea are free to use Let's Encrypt. We do not, however, serve government entities in occupied Crimea.</p>
]]></description><pubDate>Wed, 10 Jun 2026 02:04:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48470420</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=48470420</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48470420</guid></item><item><title><![CDATA[New comment by jaas in "Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]"]]></title><description><![CDATA[
<p>I was referring to the requirements imposed on us. When it comes to sanctions, we do not block anything more than what is required by law.</p>
]]></description><pubDate>Tue, 09 Jun 2026 23:25:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48469209</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=48469209</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48469209</guid></item><item><title><![CDATA[New comment by jaas in "Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]"]]></title><description><![CDATA[
<p>Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this.<p>Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population.<p>This subscriber agreement update was intended to better reflect our legal requirements. It does not reflect a major change in the service we provide. Our compliance program does evolve over time, and part of that is communicating about it better in our terms of service. It's clear from some of the comments here that we have more work to do to make that text more understandable, we'll work on that.<p>> That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international friendly" versions that supported 40 bit encryption, or "fancy secure" versions with 128 bit encryption.<p>It doesn't.</p>
]]></description><pubDate>Tue, 09 Jun 2026 22:58:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48468998</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=48468998</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48468998</guid></item><item><title><![CDATA[New comment by jaas in "Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]"]]></title><description><![CDATA[
<p>Sanctions compliance is unfortunately fairly complex.<p>Let's Encrypt can issue certificates for non-government entities in Iran and Russia due to statutory exemptions protecting personal communications, alongside specific Office of Foreign Assets Control (OFAC) authorizations designed to promote Internet freedom and human rights.<p>We will look into whether we can make things more easily understandable in the subscriber agreement.</p>
]]></description><pubDate>Tue, 09 Jun 2026 20:12:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48467006</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=48467006</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48467006</guid></item><item><title><![CDATA[New comment by jaas in "Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]"]]></title><description><![CDATA[
<p>Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments.<p>The terms of service update to clarify what we have always done, comply with relevant law, has not changed the situation for either country.</p>
]]></description><pubDate>Tue, 09 Jun 2026 18:51:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48465754</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=48465754</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48465754</guid></item><item><title><![CDATA[New comment by jaas in "Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved"]]></title><description><![CDATA[
<p>In that sense, prepare yourself to be bored.</p>
]]></description><pubDate>Fri, 08 May 2026 20:27:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48068356</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=48068356</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48068356</guid></item><item><title><![CDATA[New comment by jaas in "Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved"]]></title><description><![CDATA[
<p>Stopping all issuance is an pretty standard response if a CA thinks what they are issuing might be non-compliant in any way. It's an action we're required to take. It's not necessarily a sign of a more dramatic failure mode or key compromise. That said, the impact is the same for as long as the downtime lasts so it is unfortunate and we're sorry for the disruption.<p>I don't think the premise behind short lived (six day) certificates being viable is that CA issuance never goes down. Sure, the runway is shorter, but not that short. Most down time is a few hours or less, which is not a problem for six day certificates that should be renewed every three days.<p>Short lived certificates are optional though, so if it's not worth it to you there are longer lifetime options.</p>
]]></description><pubDate>Fri, 08 May 2026 20:24:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48068328</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=48068328</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48068328</guid></item><item><title><![CDATA[New comment by jaas in "Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved"]]></title><description><![CDATA[
<p>This is a compliance incident, we should be issuing again shortly.<p>Update: Issuance is back up.<p>Update: Preliminary incident report:<p><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2038351" rel="nofollow">https://bugzilla.mozilla.org/show_bug.cgi?id=2038351</a></p>
]]></description><pubDate>Fri, 08 May 2026 20:10:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48068096</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=48068096</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48068096</guid></item><item><title><![CDATA[6-Day and IP Address Certificates Are Generally Available]]></title><description><![CDATA[
<p>Article URL: <a href="https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability">https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46647491">https://news.ycombinator.com/item?id=46647491</a></p>
<p>Points: 506</p>
<p># Comments: 281</p>
]]></description><pubDate>Fri, 16 Jan 2026 15:37:19 +0000</pubDate><link>https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=46647491</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46647491</guid></item><item><title><![CDATA[New comment by jaas in "Volvo Centum is Dalton Maag's new typeface for Volvo"]]></title><description><![CDATA[
<p>Seat heat is one click in my 2022 Volvo. Or as others have noted, you can use your voice.</p>
]]></description><pubDate>Wed, 24 Dec 2025 11:43:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=46374740</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=46374740</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46374740</guid></item><item><title><![CDATA[New comment by jaas in "Palantir Thinks College Might Be a Waste. So It's Hiring High-School Grads"]]></title><description><![CDATA[
<p>It’s hard to be ready for a world you do not understand, and the world is a lot more than engineering or any other single subject.</p>
]]></description><pubDate>Sun, 02 Nov 2025 16:49:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=45791609</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=45791609</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45791609</guid></item><item><title><![CDATA[New comment by jaas in "We saved $500k per year by rolling our own "S3""]]></title><description><![CDATA[
<p>Their networking is awful in my experience. The WiFi chip is cheap crap, extremely sensitive, cuts out a lot, and doesn’t support WPA3.<p>I had to set up a dedicated Nanit-only AP in my house in order to stabilize the connection. It would not work any other way, tried many different configurations, even other APs.</p>
]]></description><pubDate>Mon, 27 Oct 2025 05:26:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=45717672</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=45717672</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45717672</guid></item><item><title><![CDATA[New comment by jaas in "Why, as a responsible adult, SimCity 2000 hits differently"]]></title><description><![CDATA[
<p>I know lots of parents in NYC (where I live with multiple kids) and their lives have not “broken down.” What an absurd statement/generalization.</p>
]]></description><pubDate>Sun, 21 Sep 2025 10:47:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=45321621</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=45321621</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45321621</guid></item><item><title><![CDATA[New comment by jaas in "Git: Introduce Rust and announce it will become mandatory in the build system"]]></title><description><![CDATA[
<p>Rust is generally a much better tool for building software than C. When your software is built with better tools, you will most likely get better software (at least eventually / long term, sometimes a transition period can be temporarily worse or at least not better).</p>
]]></description><pubDate>Sat, 20 Sep 2025 14:49:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=45313878</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=45313878</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45313878</guid></item><item><title><![CDATA[New comment by jaas in "Native ACME support comes to Nginx"]]></title><description><![CDATA[
<p>If you are using Nginx, then likely yes.</p>
]]></description><pubDate>Thu, 11 Sep 2025 18:34:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=45214687</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=45214687</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45214687</guid></item><item><title><![CDATA[New comment by jaas in "With AI Boom, Dell's Datacenter Biz Is Finally Bigger Than Its PC Biz"]]></title><description><![CDATA[
<p>We buy them because our experience is that they are extremely reliable and their iDrac management system is better than the alternatives, which saves us time (thus money). Maybe they aren’t the cheapest at initial purchase, but less maintenance and the ease of administration makes up for it.</p>
]]></description><pubDate>Wed, 03 Sep 2025 17:29:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=45118400</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=45118400</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45118400</guid></item><item><title><![CDATA[New comment by jaas in "SSL certificate requirements are becoming obnoxious"]]></title><description><![CDATA[
<p>Section 3.2.2.9 of this document:<p><a href="https://cabforum.org/working-groups/server/baseline-requirements/documents/CA-Browser-Forum-TLS-BR-2.1.7.pdf" rel="nofollow">https://cabforum.org/working-groups/server/baseline-requirem...</a><p>You can also just search the document for the word "Perspective" to find most references to it.</p>
]]></description><pubDate>Tue, 26 Aug 2025 13:29:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=45026274</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=45026274</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45026274</guid></item><item><title><![CDATA[New comment by jaas in "Go is still not good"]]></title><description><![CDATA[
<p>Go has a big, high quality standard library with most of what one might need. Means you have to bring in and manage (and trust) far fewer third party dependencies, and you can work faster because you’re not spending a bunch of time figuring out what the crate of the week is for basic functionality.</p>
]]></description><pubDate>Fri, 22 Aug 2025 12:51:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=44984003</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=44984003</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44984003</guid></item><item><title><![CDATA[New comment by jaas in "Don’t use “click here” as link text (2001)"]]></title><description><![CDATA[
<p>The idea is that some people don’t click - that refers mainly to people using a mouse, and many people are not using a mouse. So it is overstating information about what to do.</p>
]]></description><pubDate>Wed, 02 Jul 2025 12:32:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=44442966</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=44442966</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44442966</guid></item><item><title><![CDATA[New comment by jaas in "LetsEncrypt – Expiration Notification Service Has Ended"]]></title><description><![CDATA[
<p>It's not just about the money:<p>"Providing expiration notification emails means that we have to retain millions of email addresses connected to issuance records. As an organization that values privacy, removing this requirement is important to us."<p>A check to cover the cost of the system would not solve this part of the problem.</p>
]]></description><pubDate>Mon, 30 Jun 2025 13:06:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=44422816</link><dc:creator>jaas</dc:creator><comments>https://news.ycombinator.com/item?id=44422816</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44422816</guid></item></channel></rss>