• About TC
  • Affiliate Disclaimer
  • Privacy Policy
  • TOS
  • Contact
Thursday, July 3, 2025
Techcratic
  • TC
  • AI
    Artificial Intelligence

    EgoDex: Learning Dexterous Manipulation from Large-Scale Egocentric Video

    Artificial Intelligence

    Instruction-Following Pruning for Large Language Models

    Artificial Intelligence

    How to Combine Streamlit, Pandas, and Plotly for Interactive Data Apps

    Artificial Intelligence

    Tailor responsible AI with new safeguard tiers in Amazon Bedrock Guardrails

    Artificial Intelligence

    Automate Data Quality Reports with n8n: From CSV to Professional Analysis

    Artificial Intelligence

    NewDay builds A Generative AI based Customer service Agent Assist with over 90% accuracy

    Artificial Intelligence

    5 Things You Need to Know About Agentic AI

    Artificial Intelligence

    Normalizing Flows are Capable Generative Models

    Artificial Intelligence

    Update on the AWS DeepRacer Student Portal

  • App Zone
    Top 3 Launcher Apps for Apple: Features, Pros, and Cons

    Top 3 Launcher Apps for Apple: Features, Pros, and Cons

    Top 3 Launcher Apps for Android: Features, Pros, and Cons

    Top 3 Launcher Apps for Android: Features, Pros, and Cons

    Top 3 Card Game Apps of 2025: Features, Pros, and Cons

    Top 3 Card Game Apps of 2025: Features, Pros, and Cons

    Top 3 Medical Apps of 2025: Features, Pros, and Cons

    Top 3 Medical Apps of 2025: Features, Pros, and Cons

    Top 3 Travel Apps of 2025: Features, Pros, and Cons

    Top 3 Travel Apps of 2025: Features, Pros, and Cons

    Top 3 Casual Game Apps for 2025: Features, Pros, and Cons

    Top 3 Casual Game Apps for 2025: Features, Pros, and Cons

    Top 3 Food Apps for 2025: Features, Pros, and Cons

    Top 3 Food Apps for 2025: Features, Pros, and Cons

    Top 3 Sport Apps for 2025: Features, Pros, and Cons

    Top 3 Sport Apps for 2025: Features, Pros, and Cons

    Top 3 Productivity Apps for 2025: Features, Pros, and Cons

    Top 3 Productivity Apps for 2025: Features, Pros, and Cons

  • Apple
    Best MacBook Prime Day deals 2025: Early discounts

    Best MacBook Prime Day deals 2025: Early discounts

    Lost your wallet again? Track it down like an AirTag with this card-sized tracker

    These trackers go where AirTags can’t, and a 3-pack just went on sale

    M4 iPad Pro, iPad A16, Apple Pencil Pro, AirTag, more 9to5Mac

    M4 iPad Pro, iPad A16, Apple Pencil Pro, AirTag, more 9to5Mac

    iPhone expansion, Foxconn India drops Chinese experts, mystery

    Qantas data breach exposes personal details of millions

    Qantas data breach exposes personal details of millions

    July 2, 2025 – iPhone Fold, Apple vs DOJ

    Five new Apple products are launching early this year, here’s what’s coming

    Apple is launching 15+ new products this fall, here’s what’s coming

    iOS 26’s new Liquid Glass design looks like a major win for Apple

    iOS 26’s new Liquid Glass design looks like a major win for Apple

    OLED MacBook Pro still expected for 2026 release

    OLED MacBook Pro still expected for 2026 release

  • Retro Rewind
    Retro Rewind: Electronic Games April 1995

    Retro Rewind: Electronic Games April 1995

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

    Retro Rewind: Electronic Gaming Monthly Magazine Number 57 April 1994

    Retro Rewind: Blast from the Past – 35 Iconic Commercials of 1988!

    Retro Rewind: Blast from the Past – 35 Iconic Commercials of 1988!

    Retro Rewind: PC World Magazine August 1998

    Retro Rewind: PC World Magazine August 1998

    Retro Rewind: Computer Shopper Magazine September 1997

    Retro Rewind: Computer Shopper Magazine September 1997

    Retro Rewind: PC Magazine December 2015

    Retro Rewind: PC Magazine December 2015

    Retro Rewind: EDGE Magazine RETRO #1: The Guide to Classic Videogame Playing and Collecting

    Retro Rewind: EDGE Magazine RETRO #1: The Guide to Classic Videogame Playing and Collecting

    Retro Rewind: Computer Gaming World Magazine Issue 73 December 1998

    Retro Rewind: Computer Gaming World Magazine Issue 73 December 1998

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

  • Tech Deals
    Minecraft – PlayStation 3 (Renewed)

    Minecraft – PlayStation 3 (Renewed)

    Carcassonne Board Game (BASE GAME) – Classic Tile-Laying Strategy for All Ages, Medieval…

    Carcassonne Board Game (BASE GAME) – Classic Tile-Laying Strategy for All Ages, Medieval…

    SanDisk 128GB Extreme PRO SDXC UHS-I Memory Card – C10, U3, V30, 4K UHD, SD Card -…

    SanDisk 128GB Extreme PRO SDXC UHS-I Memory Card – C10, U3, V30, 4K UHD, SD Card -…

    Vantec USB 3.0 Multi-Card Reader UHS-II, SD 4.0, Multi-LUN (UGT-CR615), Black

    Vantec USB 3.0 Multi-Card Reader UHS-II, SD 4.0, Multi-LUN (UGT-CR615), Black

    TAGRY Bluetooth Headphones True Wireless Earbuds 60H Playback LED Power Display…

    TAGRY Bluetooth Headphones True Wireless Earbuds 60H Playback LED Power Display…

    SABRENT 13 Port High Speed USB 2.0 Hub with Power Adapter and 2 Control Switches…

    SABRENT 13 Port High Speed USB 2.0 Hub with Power Adapter and 2 Control Switches…

    ORICO MiniTower 2 Bay RAID Enclosure Compatible NVMe SSD 10Gbps with Expansion Hub…

    ORICO MiniTower 2 Bay RAID Enclosure Compatible NVMe SSD 10Gbps with Expansion Hub…

    Blue Yeti USB Mic for Recording and Streaming on PC and Mac with Blue VOCE Effects, 4…

    Blue Yeti USB Mic for Recording and Streaming on PC and Mac with Blue VOCE Effects, 4…

    Lenovo V15 Laptop | 15.6″ FHD Anti-Glare Display | AMD Ryzen 7 7730U | 40GB RAM | 1TB…

    Lenovo V15 Laptop | 15.6″ FHD Anti-Glare Display | AMD Ryzen 7 7730U | 40GB RAM | 1TB…

  • Tech Eats
    Cheesy Broccoli Rice Mug: 5-Minute Super Comfort Food

    Cheesy Broccoli Rice Mug: 5-Minute Super Comfort Food

    Top 10 Vegetarian Recipes for 2025: Easy and Nutritious Meals for Busy People

    Top 10 Vegetarian Recipes for 2025: Easy and Nutritious Meals for Busy People

    Bacon Mug Lasagna: 5-Minute Microwave Meat Lover’s Dream

    Bacon Mug Lasagna: 5-Minute Microwave Meat Lover’s Dream

    Bacon Fried Rice Mug: 5-Minute Microwave Meal

    Bacon Fried Rice Mug: 5-Minute Microwave Meal

    Bacon & Cheddar Mug Biscuit: 2-Minute Savory Comfort

    Bacon & Cheddar Mug Biscuit: 2-Minute Savory Comfort

    Loaded Bacon Cheesy Potato Mug: 5-Minute Comfort Food

    Loaded Bacon Cheesy Potato Mug: 5-Minute Comfort Food

    Peanut Butter Banana Mug Muffin: 5-Minute Protein Snack

    Peanut Butter Banana Mug Muffin: 5-Minute Protein Snack

    Oreo Mug Cake: 2-Minute Cookie & Cake Combo!

    Oreo Mug Cake: 2-Minute Cookie & Cake Combo!

    Tiramisu Mug Cake: Coffee Lover’s Dream in 2 Minutes!

    Tiramisu Mug Cake: Coffee Lover’s Dream in 2 Minutes!

  • Tesla
    Motor Trend Grand Prix Tire Tread Rubber Car Floor Mats for Autos SUV Truck & Van -…

    Motor Trend Grand Prix Tire Tread Rubber Car Floor Mats for Autos SUV Truck & Van -…

    Center Console Cover for Tesla Model 3 Model Y Leather Armrest Box Cushion Protector…

    Center Console Cover for Tesla Model 3 Model Y Leather Armrest Box Cushion Protector…

    Femuar Car Trunk Organizer with Large Capacity Waterproof Car Accessories for Women &…

    Femuar Car Trunk Organizer with Large Capacity Waterproof Car Accessories for Women &…

    [Replacement] 4Pcs Roof Rack Cover Cap Rail End Shell for Tesla for Model 3 2017 2018…

    [Replacement] 4Pcs Roof Rack Cover Cap Rail End Shell for Tesla for Model 3 2017 2018…

    Lower Center Console Organizer Tray for Tesla Model Y 2021-2024 & Model 3 2021-2023,…

    Lower Center Console Organizer Tray for Tesla Model Y 2021-2024 & Model 3 2021-2023,…

    Tesla unveils new cheaper, but nerfed ‘Long Range’ Cybertruck

    Tesla confirms Cybertruck sales are down to just ~5,000 units

    OEDRO Floor Mats Fit for Tesla Model 3 Highland 2024 2025, All Weather Waterproof…

    OEDRO Floor Mats Fit for Tesla Model 3 Highland 2024 2025, All Weather Waterproof…

    Tesla (TSLA) confirms 384,000 deliveries in Q2 2025, right on expectations

    Tesla (TSLA) confirms 384,000 deliveries in Q2 2025, right on expectations

    2025 Upgraded NACS to CCS Adapter, 500A/1000V, 250 kW DC Fast Charging for Ford, Rivian,…

    2025 Upgraded NACS to CCS Adapter, 500A/1000V, 250 kW DC Fast Charging for Ford, Rivian,…

  • UFO
    A Brief History Of The UFO Contactee Movement…

    A Brief History Of The UFO Contactee Movement…

    Roswell New Mexico Alien T-Shirt

    Roswell New Mexico Alien T-Shirt

    INTERGALACTIC The Heretic Prophet – TRAILER FR

    INTERGALACTIC The Heretic Prophet – TRAILER FR

    Pegasus Hobbies PEG9119 Model Kit, Multi, Standard Size

    Pegasus Hobbies PEG9119 Model Kit, Multi, Standard Size

    The Venus Mission That Shocked Soviet Scientists  – Space Exploration Missions

    The Venus Mission That Shocked Soviet Scientists – Space Exploration Missions

    Unidentified

    Unidentified

    Paranormal Activity: The Ghost Dimension | official trailer (2015)

    Paranormal Activity: The Ghost Dimension | official trailer (2015)

    Interstellar Secrets of Ancient Civilizations | Ancient Aliens

    Interstellar Secrets of Ancient Civilizations | Ancient Aliens

    UFO Shape LED Dual Purpose Lamp, Portable Adjustable Light Color and Brightness Outdoor Lamp, Motion Sensor Night Lamp, Magnetic Fixation, Rechargeable Flying Saucer Shape Lamp (White)

    UFO Shape LED Dual Purpose Lamp, Portable Adjustable Light Color and Brightness Outdoor Lamp, Motion Sensor Night Lamp, Magnetic Fixation, Rechargeable Flying Saucer Shape Lamp (White)

No Result
View All Result
  • TC
  • AI
    Artificial Intelligence

    EgoDex: Learning Dexterous Manipulation from Large-Scale Egocentric Video

    Artificial Intelligence

    Instruction-Following Pruning for Large Language Models

    Artificial Intelligence

    How to Combine Streamlit, Pandas, and Plotly for Interactive Data Apps

    Artificial Intelligence

    Tailor responsible AI with new safeguard tiers in Amazon Bedrock Guardrails

    Artificial Intelligence

    Automate Data Quality Reports with n8n: From CSV to Professional Analysis

    Artificial Intelligence

    NewDay builds A Generative AI based Customer service Agent Assist with over 90% accuracy

    Artificial Intelligence

    5 Things You Need to Know About Agentic AI

    Artificial Intelligence

    Normalizing Flows are Capable Generative Models

    Artificial Intelligence

    Update on the AWS DeepRacer Student Portal

  • App Zone
    Top 3 Launcher Apps for Apple: Features, Pros, and Cons

    Top 3 Launcher Apps for Apple: Features, Pros, and Cons

    Top 3 Launcher Apps for Android: Features, Pros, and Cons

    Top 3 Launcher Apps for Android: Features, Pros, and Cons

    Top 3 Card Game Apps of 2025: Features, Pros, and Cons

    Top 3 Card Game Apps of 2025: Features, Pros, and Cons

    Top 3 Medical Apps of 2025: Features, Pros, and Cons

    Top 3 Medical Apps of 2025: Features, Pros, and Cons

    Top 3 Travel Apps of 2025: Features, Pros, and Cons

    Top 3 Travel Apps of 2025: Features, Pros, and Cons

    Top 3 Casual Game Apps for 2025: Features, Pros, and Cons

    Top 3 Casual Game Apps for 2025: Features, Pros, and Cons

    Top 3 Food Apps for 2025: Features, Pros, and Cons

    Top 3 Food Apps for 2025: Features, Pros, and Cons

    Top 3 Sport Apps for 2025: Features, Pros, and Cons

    Top 3 Sport Apps for 2025: Features, Pros, and Cons

    Top 3 Productivity Apps for 2025: Features, Pros, and Cons

    Top 3 Productivity Apps for 2025: Features, Pros, and Cons

  • Apple
    Best MacBook Prime Day deals 2025: Early discounts

    Best MacBook Prime Day deals 2025: Early discounts

    Lost your wallet again? Track it down like an AirTag with this card-sized tracker

    These trackers go where AirTags can’t, and a 3-pack just went on sale

    M4 iPad Pro, iPad A16, Apple Pencil Pro, AirTag, more 9to5Mac

    M4 iPad Pro, iPad A16, Apple Pencil Pro, AirTag, more 9to5Mac

    iPhone expansion, Foxconn India drops Chinese experts, mystery

    Qantas data breach exposes personal details of millions

    Qantas data breach exposes personal details of millions

    July 2, 2025 – iPhone Fold, Apple vs DOJ

    Five new Apple products are launching early this year, here’s what’s coming

    Apple is launching 15+ new products this fall, here’s what’s coming

    iOS 26’s new Liquid Glass design looks like a major win for Apple

    iOS 26’s new Liquid Glass design looks like a major win for Apple

    OLED MacBook Pro still expected for 2026 release

    OLED MacBook Pro still expected for 2026 release

  • Retro Rewind
    Retro Rewind: Electronic Games April 1995

    Retro Rewind: Electronic Games April 1995

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

    Retro Rewind: Electronic Gaming Monthly Magazine Number 57 April 1994

    Retro Rewind: Blast from the Past – 35 Iconic Commercials of 1988!

    Retro Rewind: Blast from the Past – 35 Iconic Commercials of 1988!

    Retro Rewind: PC World Magazine August 1998

    Retro Rewind: PC World Magazine August 1998

    Retro Rewind: Computer Shopper Magazine September 1997

    Retro Rewind: Computer Shopper Magazine September 1997

    Retro Rewind: PC Magazine December 2015

    Retro Rewind: PC Magazine December 2015

    Retro Rewind: EDGE Magazine RETRO #1: The Guide to Classic Videogame Playing and Collecting

    Retro Rewind: EDGE Magazine RETRO #1: The Guide to Classic Videogame Playing and Collecting

    Retro Rewind: Computer Gaming World Magazine Issue 73 December 1998

    Retro Rewind: Computer Gaming World Magazine Issue 73 December 1998

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

  • Tech Deals
    Minecraft – PlayStation 3 (Renewed)

    Minecraft – PlayStation 3 (Renewed)

    Carcassonne Board Game (BASE GAME) – Classic Tile-Laying Strategy for All Ages, Medieval…

    Carcassonne Board Game (BASE GAME) – Classic Tile-Laying Strategy for All Ages, Medieval…

    SanDisk 128GB Extreme PRO SDXC UHS-I Memory Card – C10, U3, V30, 4K UHD, SD Card -…

    SanDisk 128GB Extreme PRO SDXC UHS-I Memory Card – C10, U3, V30, 4K UHD, SD Card -…

    Vantec USB 3.0 Multi-Card Reader UHS-II, SD 4.0, Multi-LUN (UGT-CR615), Black

    Vantec USB 3.0 Multi-Card Reader UHS-II, SD 4.0, Multi-LUN (UGT-CR615), Black

    TAGRY Bluetooth Headphones True Wireless Earbuds 60H Playback LED Power Display…

    TAGRY Bluetooth Headphones True Wireless Earbuds 60H Playback LED Power Display…

    SABRENT 13 Port High Speed USB 2.0 Hub with Power Adapter and 2 Control Switches…

    SABRENT 13 Port High Speed USB 2.0 Hub with Power Adapter and 2 Control Switches…

    ORICO MiniTower 2 Bay RAID Enclosure Compatible NVMe SSD 10Gbps with Expansion Hub…

    ORICO MiniTower 2 Bay RAID Enclosure Compatible NVMe SSD 10Gbps with Expansion Hub…

    Blue Yeti USB Mic for Recording and Streaming on PC and Mac with Blue VOCE Effects, 4…

    Blue Yeti USB Mic for Recording and Streaming on PC and Mac with Blue VOCE Effects, 4…

    Lenovo V15 Laptop | 15.6″ FHD Anti-Glare Display | AMD Ryzen 7 7730U | 40GB RAM | 1TB…

    Lenovo V15 Laptop | 15.6″ FHD Anti-Glare Display | AMD Ryzen 7 7730U | 40GB RAM | 1TB…

  • Tech Eats
    Cheesy Broccoli Rice Mug: 5-Minute Super Comfort Food

    Cheesy Broccoli Rice Mug: 5-Minute Super Comfort Food

    Top 10 Vegetarian Recipes for 2025: Easy and Nutritious Meals for Busy People

    Top 10 Vegetarian Recipes for 2025: Easy and Nutritious Meals for Busy People

    Bacon Mug Lasagna: 5-Minute Microwave Meat Lover’s Dream

    Bacon Mug Lasagna: 5-Minute Microwave Meat Lover’s Dream

    Bacon Fried Rice Mug: 5-Minute Microwave Meal

    Bacon Fried Rice Mug: 5-Minute Microwave Meal

    Bacon & Cheddar Mug Biscuit: 2-Minute Savory Comfort

    Bacon & Cheddar Mug Biscuit: 2-Minute Savory Comfort

    Loaded Bacon Cheesy Potato Mug: 5-Minute Comfort Food

    Loaded Bacon Cheesy Potato Mug: 5-Minute Comfort Food

    Peanut Butter Banana Mug Muffin: 5-Minute Protein Snack

    Peanut Butter Banana Mug Muffin: 5-Minute Protein Snack

    Oreo Mug Cake: 2-Minute Cookie & Cake Combo!

    Oreo Mug Cake: 2-Minute Cookie & Cake Combo!

    Tiramisu Mug Cake: Coffee Lover’s Dream in 2 Minutes!

    Tiramisu Mug Cake: Coffee Lover’s Dream in 2 Minutes!

  • Tesla
    Motor Trend Grand Prix Tire Tread Rubber Car Floor Mats for Autos SUV Truck & Van -…

    Motor Trend Grand Prix Tire Tread Rubber Car Floor Mats for Autos SUV Truck & Van -…

    Center Console Cover for Tesla Model 3 Model Y Leather Armrest Box Cushion Protector…

    Center Console Cover for Tesla Model 3 Model Y Leather Armrest Box Cushion Protector…

    Femuar Car Trunk Organizer with Large Capacity Waterproof Car Accessories for Women &…

    Femuar Car Trunk Organizer with Large Capacity Waterproof Car Accessories for Women &…

    [Replacement] 4Pcs Roof Rack Cover Cap Rail End Shell for Tesla for Model 3 2017 2018…

    [Replacement] 4Pcs Roof Rack Cover Cap Rail End Shell for Tesla for Model 3 2017 2018…

    Lower Center Console Organizer Tray for Tesla Model Y 2021-2024 & Model 3 2021-2023,…

    Lower Center Console Organizer Tray for Tesla Model Y 2021-2024 & Model 3 2021-2023,…

    Tesla unveils new cheaper, but nerfed ‘Long Range’ Cybertruck

    Tesla confirms Cybertruck sales are down to just ~5,000 units

    OEDRO Floor Mats Fit for Tesla Model 3 Highland 2024 2025, All Weather Waterproof…

    OEDRO Floor Mats Fit for Tesla Model 3 Highland 2024 2025, All Weather Waterproof…

    Tesla (TSLA) confirms 384,000 deliveries in Q2 2025, right on expectations

    Tesla (TSLA) confirms 384,000 deliveries in Q2 2025, right on expectations

    2025 Upgraded NACS to CCS Adapter, 500A/1000V, 250 kW DC Fast Charging for Ford, Rivian,…

    2025 Upgraded NACS to CCS Adapter, 500A/1000V, 250 kW DC Fast Charging for Ford, Rivian,…

  • UFO
    A Brief History Of The UFO Contactee Movement…

    A Brief History Of The UFO Contactee Movement…

    Roswell New Mexico Alien T-Shirt

    Roswell New Mexico Alien T-Shirt

    INTERGALACTIC The Heretic Prophet – TRAILER FR

    INTERGALACTIC The Heretic Prophet – TRAILER FR

    Pegasus Hobbies PEG9119 Model Kit, Multi, Standard Size

    Pegasus Hobbies PEG9119 Model Kit, Multi, Standard Size

    The Venus Mission That Shocked Soviet Scientists  – Space Exploration Missions

    The Venus Mission That Shocked Soviet Scientists – Space Exploration Missions

    Unidentified

    Unidentified

    Paranormal Activity: The Ghost Dimension | official trailer (2015)

    Paranormal Activity: The Ghost Dimension | official trailer (2015)

    Interstellar Secrets of Ancient Civilizations | Ancient Aliens

    Interstellar Secrets of Ancient Civilizations | Ancient Aliens

    UFO Shape LED Dual Purpose Lamp, Portable Adjustable Light Color and Brightness Outdoor Lamp, Motion Sensor Night Lamp, Magnetic Fixation, Rechargeable Flying Saucer Shape Lamp (White)

    UFO Shape LED Dual Purpose Lamp, Portable Adjustable Light Color and Brightness Outdoor Lamp, Motion Sensor Night Lamp, Magnetic Fixation, Rechargeable Flying Saucer Shape Lamp (White)

No Result
View All Result
Techcratic
No Result
View All Result
Home Hacker News

How We Reduced the Impact of Zombie Clients

Hacker News by Hacker News
June 4, 2025
in Hacker News
Reading Time: 11 mins read
129
A A
0

2025-06-04 11:58:00
letsencrypt.org

Every night, right around midnight (mainly UTC), a horde of zombies wakes up and clamors for … digital certificates!

The zombies in question are abandoned or misconfigured Internet servers and ACME clients that have been set to request certificates from Let’s Encrypt. As our certificates last for at most 90 days, these zombie clients’ software knows that their certificates are out-of-date and need to be replaced. What they don’t realize is that their quest for new certificates is doomed! These devices are cursed to seek certificates again and again, never receiving them.

But they do use up a lot of certificate authority resources in the process.

The Zombie Client Problem

Unlike a human being, software doesn’t give up in frustration, or try to modify its approach, when it repeatedly fails at the same task. Our emphasis on automation means that the vast majority of Let’s Encrypt certificate renewals are performed by automated software. This is great when those renewals succeed, but it also means that forgotten clients and devices can continue requesting renewals unsuccessfully for months, or even years.

How might that happen? Most often, it happens when a device no longer has a domain name pointed to it. The device itself doesn’t know that this has changed, so it treats renewal failures as transient even though they are actually permanent. For instance:

  • An organization may have allowed a domain name registration to lapse because it is no longer needed, but its servers are still configured to request certs for it.
  • Or, a home user stopped using a particular dynamic-DNS domain with a network-attached storage device, but is still using that device at home. The device doesn’t realize that the user no longer expects to use the name, so it keeps requesting certs for it.
  • Or, a web hosting or CDN customer migrated to a different service provider, but never informed the old service provider. The old service provider’s servers keep requesting certs unsuccessfully. If the customer was in a free service tier, there might not be invoices or charges reminding the customer to cancel the service.
  • Or any number of other, subtler changes in a subscriber’s infrastructure, such as changing a firewall rule or some webserver configuration.

At the scale of Let’s Encrypt, which now covers hundreds of millions of names, scenarios like these have become common, and their impact has become substantial. In 2024, we noticed that about half of all certificate requests to the Let’s Encrypt ACME API came from about a million accounts that never successfully complete any validations. Many of these had completed validations and issued certificates sometime in the past, but nowadays every single one of their validation attempts fails, and they show no signs that this will change anytime soon.

Unfortunately, trying to validate those futile requests still uses resources. Our CA software has to generate challenges, reach out and attempt to validate them over the Internet, detect and report failures, and record all of the associated information in our databases and audit logs. And over time, we’ve seen more and more recurring failures: accounts that always fail their issuance requests have been growing at around 18% per year.

In January, we mentioned that we had been addressing the zombie client problem through our rate limit system. This post provides more detail on that progress. 

Our Rate Limit Philosophy

If you’ve used Let’s Encrypt as a subscriber, you may have run into one of our rate limits at some point, maybe during your initial setup process. We have eight different kinds of rate limits in place now; as our January post describes, they’ve become more algorithmically sophisticated and grown to address a wider range of problems. A key principle for Let’s Encrypt is that our rate limiting is not a punishment. We don’t think of rate limits as a way of retaliating against a client for misbehavior. Rate limits are simply a tool to maximize the efficient use of our limited resources and prevent people and programs from using up those resources for no constructive purpose.

We’ve consistently tried to design our rate limit mechanisms in line with that philosophy. So if a misconfiguration or misunderstanding has caused excessive requests in the past, we’re still happy to welcome the user in question back and start issuing them certificates again—once the problem has been addressed. We want the rate limits to put a brake on wasteful use of our systems, but not to frustrate users who are actively trying to make Let’s Encrypt work for them.

In addition, we’ve always implemented our rate limits to err on the side of permissiveness. For example, if the Redis instances where rate limits are tracked have an outage or lose data, the system is designed to permit more issuance rather than less issuance as a result.

We wanted to create additional limits that would target zombie clients, but in a correspondingly non-punitive way that would avoid any disruption to valid issuance, and welcome subscribers back quickly if they happened to notice and fix a long-time problem with their setups.

Our Zombie-Related Rate Limits and Their Impact

In planning a new zombie-specific response, we decided on a “pausing” approach, which can temporarily limit an account’s ability to proceed with certificate requests. The core idea is that, if a particular account consistently fails to complete validation for a particular hostname, we’ll pause that account-hostname pair. The pause means that any new order requests from that account for that hostname will be rejected immediately, before we get to the resource-intensive validation phase.

This approach is more finely targeted than pausing an entire account. Pausing account-hostname pairs means that your ability to issue certs for a specific name could be paused due to repeated failures, but you can still get all of your other certs like normal. So a large hosting provider doesn’t have to fear that its certificate issuance on behalf of one customer will be affected by renewal failures related to a problem with a different customer’s domain name. The account-specificity of the pause, in turn, means that validation failures from one subscriber or device won’t prevent a different subscriber or device from attempting to validate the same name, as long as the devices in question don’t share a single Let’s Encrypt account.

In September 2024, we began applying our zombie rate limits manually by pausing about 21,000 of the most recurrently-failing account-hostname pairs, those which were consistently repeating the same failed requests many times per day, every day. After implementing that first round of pauses, we immediately saw a significant impact on our failed request rates. As we announced at that time, we also began using a formula to automatically pause other zombie client account-hostname pairs from December 2024 onward. The associated new rate limit is called “Consecutive Authorization Failures per Hostname Per Account” (and is independent of the existing “Authorization Failures per Hostname Per Account” limit, which resets every hour).

This formula relates to the frequency of successive failed issuance requests for the same domain name by the same Let’s Encrypt account. It applies only to failures that happen again and again, with no successful issuances at all in between: a single successful validation immediately resets the rate limit all the way to zero. Like all of our rate limits, this is not a punitive measure but is simply intended to reduce the waste of resources. So, we decided to set the thresholds rather high in the expectation that we would catch only the most disruptive zombie clients, and ultimately only those clients that were extremely unlikely to succeed in the future based on their substantial history of failed requests. We don’t hurry to block requesters as zombies: according to our current formula, client software following the default established by EFF’s Certbot (two renewal attempts per day) would be paused as a zombie only after about ten years of constant failures. More aggressive failed issuance attempts will get a client paused sooner, but clients will generally have to fail hundreds or thousands of attempts in a row before they are paused.

Most subscribers using mainstream client applications with default configurations will never encounter this rate limit, even if they forget to deactivate renewal attempts for domains that are no longer pointed at their servers. As described below, our current limit is already providing noticeable benefits with minimal disruption, and we’re likely to tighten it a bit in the near future, so it will trigger after somewhat fewer consecutive failures.

Self-Service Unpausing

A key feature in our zombie issuance pausing mechanism is self-service unpausing. Whenever an account-hostname pair is paused, any new certificate requests for that hostname submitted by that account are immediately rejected. But this means that the “one successful validation immediately resets the rate limit counter” feature can no longer come into effect: once they’re paused, they can’t even attempt validation anymore.

So every rejection comes with an error message explaining what has happened and a custom link that can be used to immediately unpause that account-hostname pair and remove any other pauses on the same account at the same time. The point of this is that subscribers who notice at some point that issuance is failing and want to intervene to get it working again have a straightforward option to let Let’s Encrypt know that they’re aware of the recurring failures and are still planning to use a particular account. As soon as subscribers notify us via the self-service link, they’ll be able to issue certificates again.

Currently, the user interface for an affected subscriber looks like this:

Let's Encrypt unpause interface

This link would be provided via an ACME error message in response to any request that was blocked due to a pause account-hostname pair.

As it’s turned out, the unpause option shown above has only been used by about 3% of affected accounts! This goes to show that most of the zombies we’ve paused were, in fact, well and truly forgotten about.

However, the unpause feature is there for whenever it’s needed, and there may be cases when it will become more important. A very large integration could trigger the zombie-related rate limits if a newly-introduced software bug causes what looks like a very high volume of zombie requests in a very short time. In that case, once that bug has been noticed and fixed, an integrator may need to unpause its issuance on behalf of lots of customers at once. Our unpause feature permits unpausing 50,000 domain names on a single account at a time, so even the largest integrators can get themselves unpaused expeditiously in this situation.

Conclusion

We’ve been very happy with the results of our zombie mitigation measures, and, as far as we can tell, there’s been almost no impact for subscribers! Our statistics indicate that we’ve managed to reduce the load on our infrastructure while causing no detectable harm or inconvenience to subscribers’ valid issuance requests.

Since implementing the manual pauses in September and the automated pauses in December, we’ve seen:

  • Over 100,000 account-hostname pairs have been paused for excessive failures.
  • We received zero (!) associated complaints or support requests.
  • About 3,200 people manually unpaused issuance.
  • Failed certificate orders fell by about 30% so far, and should continue to fall over time as we fine-tune the rate limit formula and catch more zombie clients.

The new rate limit and the self-service unpause system are also ready to deal with circumstances that might produce more zombie clients in the future. For instance, we’ve announced that we’re going to be discontinuing renewal reminder emails soon. If some subscribers overlook failed renewals in the future, we might see more paused clients that result from unintentional renewal failures. We think taking advantage of the existing self-service unpause feature will be straightforward in that case. But it’s much better to notice problems and get them fixed up front, so please remember to set up your own monitoring to avoid unnoticed renewal failures in the future.

If you’re a subscriber who’s had occasion to use the self-service unpause feature, we’d love your feedback on the Community Forum about your experience using the feature and the circumstances that surrounded your account’s getting paused.

Also, if you’re a Let’s Encrypt client developer, please remember to make renewal requests at a random time (not precisely at midnight) so that the load on our infrastructure is smoothed out. You can also reduce the impact of zombie renewals by repeating failed requests somewhat less frequently over time (a “back-off” strategy), especially if the failure reason makes it look like a domain name may no longer be in use at all.

Source Link


Keep your files stored safely and securely with the SanDisk 2TB Extreme Portable SSD. With over 69,505 ratings and an impressive 4.6 out of 5 stars, this product has been purchased over 8K+ times in the past month. At only $129.99, this Amazon’s Choice product is a must-have for secure file storage.

Help keep private content private with the included password protection featuring 256-bit AES hardware encryption. Order now for just $129.99 on Amazon!


Start your free Amazon Prime trial
today and unlock unlimited streaming and more!

Help Power Techcratic’s Future – Scan To Support

If Techcratic’s content and insights have helped you, consider giving back by supporting the platform with crypto. Every contribution makes a difference, whether it’s for high-quality content, server maintenance, or future updates. Techcratic is constantly evolving, and your support helps drive that progress.

As a solo operator who wears all the hats, creating content, managing the tech, and running the site, your support allows me to stay focused on delivering valuable resources. Your support keeps everything running smoothly and enables me to continue creating the content you love. I’m deeply grateful for your support, it truly means the world to me! Thank you!

BITCOIN

Bitcoin Logo

Bitcoin QR Code

bc1qlszw7elx2qahjwvaryh0tkgg8y68enw30gpvge

Scan the QR code with your crypto wallet app

DOGECOIN

Dogecoin Logo

Dogecoin QR Code

D64GwvvYQxFXYyan3oQCrmWfidf6T3JpBA

Scan the QR code with your crypto wallet app

ETHEREUM

Ethereum Logo

Ethereum QR Code

0xe9BC980DF3d985730dA827996B43E4A62CCBAA7a

Scan the QR code with your crypto wallet app

Please read the Privacy and Security Disclaimer on how Techcratic handles your support.

Disclaimer: As an Amazon Associate, Techcratic may earn from qualifying purchases.

Tags: Hacker News
Share161Share28ShareShare4ShareTweet101
Previous Post

Collaborating in Google Drive? Gemini can catch you up on changes made to your files now

Next Post

Microsoft is addressing USB-C “port confusion” with a new hardware certification program

Hacker News

Hacker News

Stay updated with Hacker News, where technology meets entrepreneurial spirit. Get the latest on tech trends, startup news, and discussions from the tech community. Read the latest updates here at Techcratic.

Related Posts

Ransomware Attacks on Organizations Surge 213% in Q1 of 2025
Hacker News

Ransomware Attacks on Organizations Surge 213% in Q1 of 2025

July 3, 2025
1.3k
Surge in LNK File Weaponization by 50%, Fueling Four Major Malware Types
Hacker News

Surge in LNK File Weaponization by 50%, Fueling Four Major Malware Types

July 3, 2025
1.3k
I’m a physicist by trade, not by training, and that matters | by Chris Ferrie | Jul, 2025
Hacker News

I’m a physicist by trade, not by training, and that matters | by Chris Ferrie | Jul, 2025

July 3, 2025
1.3k
Stop Building AI Agents: Use Smarter LLM Workflows
Hacker News

Stop Building AI Agents: Use Smarter LLM Workflows

July 2, 2025
1.3k
enumura1/chatbot-flow-editor: Visual chatbot flow editor. GUI tool for designing chatbot flows. Create, test, and export as JSON.
Hacker News

enumura1/chatbot-flow-editor: Visual chatbot flow editor. GUI tool for designing chatbot flows. Create, test, and export as JSON.

July 2, 2025
1.3k
Tesla (TSLA) Q2 vehicle deliveries report
Hacker News

Tesla (TSLA) Q2 vehicle deliveries report

July 2, 2025
1.3k
Hackers Target Linux SSH Servers to Deploy TinyProxy and Sing-box Proxy Tools
Hacker News

Hackers Target Linux SSH Servers to Deploy TinyProxy and Sing-box Proxy Tools

July 2, 2025
1.3k
Full-system emulated fuzzing of Qualcomm basebands
Hacker News

Full-system emulated fuzzing of Qualcomm basebands

July 2, 2025
1.3k
Load More
Next Post
Microsoft is addressing USB-C “port confusion” with a new hardware certification program

Microsoft is addressing USB-C "port confusion" with a new hardware certification program

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Tech Resources

  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Forbes
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo
  • Google News
  • Hacker News
  • Harvard Tech
  • I Like Cats ™
  • I Like Dogs ™
  • LifeHacker
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • PC World
  • Photofocus
  • Physics
  • Random Tech
  • Retro Rewind ™
  • Robot Report
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Art
  • Tech Careers
  • Tech Deals
  • Techcratic ™
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Wired
  • ZDNet

Tech News

  • 30 Second Tech ™
  • AI
  • Apple Insider
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • ExtremeTech
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo

Tech News

  • Harvard Tech
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • Physics
  • PC World
  • Random Tech
  • Retro Rewind ™
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Careers

Tech News​

  • Tech Art
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Wired
  • ZDNet

Site Links

  • About Techcratic
  • Affiliate Disclaimer
  • Affiliate Link Policy
  • Contact Techcratic
  • Dealors Discount Store
  • Privacy and Security Disclaimer
  • Privacy Policy
  • RSS Feed
  • Site Map
  • Support Techcratic
  • Techcratic
  • Tech Deals
  • TOS
  • 𝕏
Click For A Secret Deal

Techcratic – Your All In One Tech Hub © 2020 – 2025
All Rights Reserved
∞

No Result
View All Result
  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Gaming
  • I Like Cats ™
  • I Like Dogs ™
  • MacRumors
  • Macworld
  • Tech Deals
  • Techcratic ™
  • Techs Got To Eat ™
  • Tesla
  • UFO
  • Wired