The Expiration Of A Key Digital Encryption Service Left Millions Of People Offline

When it comes to encryption, it requires a key to encrypted and decrypt data.

And when it comes to the web, that key includes digital certificates to encrypt and decrypt data, as well as to protect connections between users' devices and the internet. One of the largest of such providers, is Let's Encrypt.

This time, the provider's digital certificates expired.

As a result, tech giants like Google, Amazon, Microsoft, Cisco and many others, were forced to remain offline for at least 2 million people.

To those people, they were seeing error messages on their phones, computers, or smart gadgets, detailing some internet connectivity problem.

In the moments they went down simultaneously to those number of users, the affected companies that raced against time to return their respective services online, realized that the problems were caused by the forced expiration of Let's Encrypt.

Let's Encrypt - revoke
A digital certificate is revoked. (Credit: Let's Encrypt)

According to Let's Encrypt, the determining factor whether or not its key can be used, is based on whether that platform trusts ISRG’s “ISRG Root X1” certificate.

"Prior to September 2021, some platforms could validate our certificates even though they don’t include ISRG Root X1, because they trusted IdenTrust’s 'DST Root CA X3' certificate. From October 2021 onwards, only those platforms that trust ISRG Root X1 will validate Let’s Encrypt certificates (with the exception of Android)," wrote Let's Encrypt on its website.

"If your certificate validates on some of the 'Known Compatible' platforms but not others, the problem may be a web server misconfiguration."

Among software and devices that should have been affected, include Windows XP computers that didn't have Automatic Root Certificate Update manually disabled, iOS older than version 10, Firefox older than version 50, 2012 Windows Live Mail mail client, PS3 game console, some PS4 game console, and more.

However, many users faced issues on despite having used the newest device on the market, and most up-to-date software on hand.

While dozens of tech companies and products were affected by this certificate expiration, the problem went under the radar to some of the companies. This is because none of them made announcements to their respective users about the issues, at least during the brief offline moment.

Regardless, this moment is considered among one of the first major digital certificates to expire since the advent of the internet in the 1980s.