Feisty Duck - Company updates - Q2 2026
Your quarterly catch-up: Q2’s key insights and resources.

Dear Ala

With so much information to keep track of in the field of cryptography, security, privacy, SSL/TLS, and PKI, this quarterly update will help you stay ahead. Here are the topics we covered over the last three months and what we're up to these days. We hope this will be a valuable addition to your reading list!


Introducing Newsletter Classifieds

TLS, PKI, cryptography, privacy, and security are niche fields, and hiring in this space is hard. Employers struggle to reach candidates with the right expertise, and job hunters don't always see the best openings come across their feed. To help, we're introducing a classified ads section into our Cryptography & Security Newsletter.

Looking to hire? Promote your open roles through us. Early-bird discount available, please get in touch. Applying? Please let them know you found the position through our newsletter. Your support helps us grow!

The screenshot below is from the June newsletter.

Classifieds

Key Ecosystem Events

  • In May, Let's Encrypt confirmed a phased plan to cut certificate validity to 45 days by 2028, with authorization reuse shrinking from 30 days to just 7 hours. A new DNS-PERSIST-01 validation method is meant to ease the extra renewal load. More in Let's Encrypt's announcement.
  • Web PKI is converging on Merkle Tree Certificates rather than PQC certificate chains. Google and Let's Encrypt both confirmed MTCs as their path for the public web, targeting production by 2027 to 2029. Chrome 150 will add ML-DSA certificate support too, but only for enterprise private PKI.
  • Three CAs disclosed compliance incidents this quarter. Let's Encrypt paused issuance after finding subCAs issued without the required serverAuth EKU. SSL.com revoked 1.77 million certificates after a flawed EJBCA validation setup. DigiCert revoked code-signing certificates after a support-team malware infection. All three were remediated within 24 hours.
  • Apple and Google rolled out end-to-end encrypted RCS between iPhone and Android, starting with iOS 26.5, closing a long-standing cross-platform privacy gap. More in Google's announcement.
  • Meta confirmed that 20,225 Instagram accounts were hijacked via a flaw in its AI chatbot, which let attackers send password reset links to their own email on accounts without 2FA. The campaign ran from mid-April until Meta disabled the chatbot. More in this report.
  • DNSSEC had a mixed quarter. A hijack attempt against eth.limo, an ENS gateway for ~2 million .eth domains, was blocked outright by DNSSEC. But a DNSSEC misconfiguration also broke resolution for all .de domains, an outage Cloudflare's 1.1.1.1 worked around using stale-response serving.

Cryptography & Security Newsletter

ECH Is Done, But Can We Make It Work? (#136)

Encrypted Client Hello (ECH) is a TLS upgrade that hides which website you're visiting from anyone monitoring the connection. The key challenge: unlike most encryption upgrades, ECH only works if enough of the internet adopts it — and right now that's uneven, with strong browser support but only Cloudflare really carrying it on the server side. ECH is caught between two adversaries, censoring governments and traffic-monitoring enterprises, both motivated to defeat it. It ends on the field's real unsolved puzzle: ECH connections still stick out via a giveaway placeholder domain (like cloudflare-ech.com), so blending in fully will require randomizing that domain and fixing censored DNS.

ACME CAA Extensions to Become Mandatory (#137)

The CA/Browser Forum has voted to make ACME CAA extensions mandatory starting March 2027, closing one of the last gaps in strong, cryptographically-validated domain validation for Web PKI. Today, certificate issuance relies on unauthenticated requesters and domain validation over unsecured DNS and network traffic, meaning anyone who can intercept those channels can potentially get a fraudulent certificate issued. DNSSEC already locked down the DNS side; now CAA paired with ACME finishes the job, letting domain owners name exactly which CA, which account, and which validation method gets to issue their certificates — no exceptions.

The Threat of Residential Proxies (#138)

Millions of home devices, routers, smart TVs, even digital photo frames, are quietly being used as proxy exit nodes without their owners' knowledge. We examine residential proxies, the IP addresses tied to real homes that scrapers, AI vendors, and cybercriminals alike are racing to get their hands on. Some are recruited through sketchy SDKs buried in free apps. Others come from devices with proxy malware preinstalled before they even reach the shelf. The risk isn't abstract: compromised home and enterprise networks, blocked access to your own services, and, in worst cases, unwanted attention from law enforcement because your IP was used as someone else's launchpad. We break down how these networks operate, why AI-driven scraping is accelerating the problem, and what you can actually do about it at home and at work.

Practical TLS and PKI Training

Practical TLS and PKI Training is for system administrators, developers, and IT security professionals who wish to learn how to deploy secure servers and encrypted web applications and understand the theory and practice of Internet PKI. Based on our book Bulletproof TLS and PKI. Contact us to arrange private training for your team.

Copyright © 2026 Feisty Duck Ltd

86-90 Paul Street, London EC2A 4NE, United Kingdom
www.feistyduck.com / hello@feistyduck.com

You are receiving this email because you are subscribed to Feisty Duck Quarterly News. If you'd prefer not to receive further emails on this list, please unsubscribe here. Alternatively, you can review and change all your notifications settings here.