/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Certificate authority Let's Encrypt says it has found a workaround that will extend older Android phones' compatibility with its certificates by three years

When you haven't been updated since 2016, expiring certificates are a problem.  —  Things were touch-and-go for a while …

Ars Technica Ron Amadeo

Context & Ripple Effects

In November, Let's Encrypt warned that phones running Android 7.1 or older would stop trusting its root certificate once it expired in 2021 — meaning those devices would suddenly fail on any site secured by what is effectively the default free CA for the web. The problem traced back to devices that haven't received updates since around 2016, part of the same long tail of unpatched Android hardware that has been exploited by malvertising and drive-by campaigns for years.

The workaround announced today buys three more years of compatibility, converting an imminent mass-breakage event into a deferred deadline. It matters because Let's Encrypt issues certificates at such scale that losing trust on old Androids would have hit site operators everywhere, not just niche services.

First-order effects

  • Operators of sites using Let's Encrypt certificates no longer face a 2021 cliff where Android 7.1-and-older visitors see connection errors; the workaround keeps those devices trusting its certs for three additional years.
  • Owners of aging Android phones keep working access to secure websites without needing an OS update they were never going to receive.

Second-order effects

  • Site operators who had begun budgeting for a switch to alternative certificate authorities — or for dropping encryption support on legacy clients — can hold off, reducing near-term churn toward commercial CAs.
  • Google and device makers face renewed scrutiny over Android's update lifecycle: the episode shows that when a major root expires, the cost of fragmented, short-lived software support lands on the entire web, not just the phone vendors.

Third-order effects

  • If root expirations keep colliding with un-updated device fleets, the web PKI will structurally need longer-lived legacy chains and cross-signing workarounds as standard practice — maintenance burden that falls on CAs like Let's Encrypt rather than on manufacturers.
  • The three-year reprieve also extends the security exposure window for devices already known to be vulnerable, since the same un-updated population targeted by drive-by exploits stays online longer instead of being forced off the modern web.

The trend: Web certificate authorities are increasingly absorbing the cost of Android's fragmented update model, patching over expired-trust cliffs for device fleets their own vendors have abandoned.

Discussion

  • @letsencrypt @letsencrypt on x
    Thanks to innovative thinking from our community and our wonderful partners @IdenTrustGov, we have a solution that allows us to maintain wide compatibility after our cross-signed intermediates expire. https://letsencrypt.org/...
  • @icing Stefan Eissing on x
    Lets Encrypt found a way to continue working on old androids. Hint: the droid thinks root certificates live forever. Nice one, LE! https://letsencrypt.org/...
  • @goretsky Aryeh Goretsky on x
    Uh... unsure of whether its better to let those 845M devices just expire. Let's Encrypt comes up with workaround for abandonware Android devices https://arstechnica.com/...
  • @charlesarthur Charles Arthur on x
    To many people, this blogpost will be complete gibberish. But it's about something essential to using the web for 700m Android devices. The deep plumbing of the web, as essential as underground pipes in our cities, and as unseen. https://twitter.com/...
  • @arw Andrew R. Whalley on x
    It was wonderful to see the collaboration and problem solving that went into this. Great work all those involved! https://twitter.com/...