6 ms·
Google Public CA is down
- microm 8mo agoAll is down in eu too
- dijit 8mo agoyoutube (recommendations/homepage) also seems down, I wonder if its relater.
- dyauspitr 8mo agoI can see all the videos and play the ones in my subscription tab though.
- tokyobreakfast 8mo ago[flagged]
- bethekidyouwant 8mo agoNever see these. Skill issue?
- tokyobreakfast 8mo agoI'm inundated with them. YT has become borderline unusable. The homepage is nightmarish. Can't search for anything without being overwhelmed with shorts in the results, many unrelated to what I'm searching.
- LPisGood 8mo agoI also never get these. It might be because you interact with them.
- tokyobreakfast 8mo agoI browse logged out. Interact when them I do not. The weight loss and solar scams are forced advertisements before every video.
- tfsh 8mo ago> I browse logged out. Interact when them I do not. The logged out experience is closer to the interests of the average person. So if you're not pruning (and savings) your interests, that's hardly surprising.
- tokyobreakfast 8mo agoThe average person wants to be served AI slop and scams?
- LPisGood 8mo agoWhat the average person says they want and what they will actually chose behaviorally will often not line up.
- antonvs 8mo ago> I browse logged out. This is like the guy who goes to the doctor complaining of eye pain whenever he drinks tea. "Have you tried taking the teaspoon out?"
- bawolff 8mo agoYT pushing videos can be annoying, but at the same time there is an element of human free will here. You can chose not to watch them.
- pvab3 8mo agoJust block them. I haven't seen a short in months.
- kidfiji 8mo agoAh, so that’s probably why YouTube is also down (at the time of this comment)
- ekr____ 8mo agoPerhaps the same underlying cause, but there's no reason why Google's public CA being temporarily down would bring YouTube down.
- silverquiet 8mo agoIf multiple services are affected, it's probably some underlying infrastructure issue.
- qmarchi 8mo agoGoogle uses mTLS for communications between systems and it could just be bad timing.
- LPisGood 8mo agoYeah companies which also operate CAs can print as many certs as they want so it’s tempting to use a bunch everywhere with very short expiry.
- thayne 8mo agoIt could prevent Google from rotating in new instances, because they aren't able to obtain a certificate. Although, if that is the case, I would expect to to impact basically every google site.
- gzread 8mo agoI am playing a YouTube video (since the time of this comment) and it has not been interrupted.
- dyauspitr 8mo agoYou can still see your subscription videos, just not the homepage.
- aaronmiler 8mo agoHeroku having service issues, dependency related?
- flaxxer 8mo agoseeing heroku issues here too, had assumed it was salesforce's fault, bc of course they are eventually going to destroy heroku somehow, right?
- rolph 8mo agohttps://status.pki.goog/ https://status.pki.goog/
- Kapura 8mo agoGood thing I have nebula.tv for when youtube breaks
- benatkin 8mo agoIsn't that the thing that a bunch of YouTube creators pitch inside their channels along with VPNs and supplements? I would never consider it because the ads rub me the wrong way. Or is it some alternative frontend for YouTube that happens to have a similar sounding name?
- qmarchi 8mo agoNot quite. It's a co-op, where the creators own the shares of the company. Supposedly a more holistic approach to video hosting with less oversight from the platform itself.
- hylaride 8mo agoIt's a place for creators to host long form content (that the google algorithm now disincentivizes) as well as history content that can't show a lot of history because of "violence" (like the holocaust). Youtube is demonetizing channels left, right, and centre.
- kittoes 8mo agoNebula is actually quite a decent alternative/supplement to YouTube and worth the subscription IMHO.
- LPisGood 8mo agoIt is a co-op where creators make videos without the threat of being demonetized or algorithmically punished - and it’s not garbage in the way you might expect people fearful of being demonetized might be. Lots of excellent legal analysis, history, logistics, engineering content there. It was initially founded by some of the most popular information YouTubers like CGPGrey, but he mysteriously left the project (I suspect one side wanted to be evil and the other side did not)
- h4ch1 8mo agoThought my Revanced patch got outdated for a second. Phew.
- ddtaylor 8mo agoHave you had to update microG yet?
- h4ch1 8mo agoYes I had to, the v20.14.43 I patched a month ago broke just today; but updating it was pretty easy; just have to update[0] and repatch 20.14.43 with an updated GMS patch. [0] https://github.com/ReVanced/GmsCore/releases/tag/v0.3.13.2.250932 https://github.com/ReVanced/GmsCore/releases/tag/v0.3.13.2.2...
- lawgimenez 8mo agoDown here in Southeast Asia
- Thaxll 8mo agoHmm why youtube does not work but google.com does. Now I'm wondering if you rely on OCSP in a TLS client and the pki is Google does it still works?
- kbelder 8mo agoInteresting. If you go to youtube.com it's all messed up; missing all the videos in the listings. But if you follow a video embedded in another site to youtube, it'll show and play fine. It'll break if you try to browse away from it.
- arkryal2 8mo agoYeah, YouTube is not one server, it's hundreds of them. The videos are served mostly from CDNs (the Content Distribution Network). It's a different set of servers than handles account logins, routing, etc. Some Google Services are also down at the moment, unrelated to YouTube, so probably a failure along some common infrastructure pipeline. Your History, Subscriptions and search should all work. You should be able to see any creator's page if you go to it directly. The videos are all still watchable. It's primarily the home page and recommended videos that are having issues. Basically any place they recommend videos you haven't seen is broken right now, but the videos are still there and accessible. I've tried via VPN from the U.S., U.K., Sweden, Germany, Russia, Colombia, etc. Same issue across the board.
- arcfour 8mo agoOCSP is deprecated and basically dead at this point. Some clients still use it but I don't think many (any?) have actually enforced OCSP for years since it was notoriously fickle anyways.
- 1970-01-01 8mo agoDid someone buy the google.com domain again?
- Shellban 8mo agoI have the domain. If you want you cat videos back, you are going to have to pay me: ONE MILLION DOLLARS!
- rvz 8mo agoEveryone loves to say they work at $FAMOUS_COMPANY, but when something like this happens, no-one will say that they did this. Looking forward to the post-mortem.
- LPisGood 8mo agoI mean, with any sufficiently large project or system it’s rarely super accurate to say one person did something.
- wbsun 8mo agoOh I am more than happy to tell people how I took down entire Google Cloud 11 years ago. I mean, of course to the level of details Google is comfortable with to share externally :)
- exikyut 8mo agoI'll bite; ok, what'd you do? :)
- tokyobreakfast 8mo agoIt's a good thing we have ever-shrinking certificate lifetimes and automation never breaks. That's what I've been told, anyway.
- bigbuppo 8mo agoYeah, this could end up as the actual root cause of The Great Oops that I've been raving about for years. And Google probably would be the right company to fuck it up in the worst way possible since Google Knows Best In All Situations.
- ocdtrekkie 8mo agoI can't wait for the Great Oops.
- LPisGood 8mo agoPlease tell me more about The Great Oops
- bigbuppo 8mo agoIt's inevitable that one of the major cloud providers will irrecoverably delete all customer data with one single fat-fingered command. Though in google's case I'll also consider the prophecy to be fulfilled if they delete their own data. It will forever be known as The Great Oops.
- tokyobreakfast 8mo agoThat seems unlikely. Is Google run by one Homer Simpson?
- bigbuppo 8mo agoYes.
- Arainach 8mo ago
- jtokoph 8mo ago> A fix to resolve the issue will roll out in about 8 hours oof
- catsquirrel28 8mo agoI guess it's good Google hasn't succeeded in forcing people to renew certificates every 8 hours (yet)
- altairprime 8mo agoThat feeling when you have to suspend production service until the time lock safe can be opened.
- altairprime 8mo agoThat feeling when you finally get the timelock safe open and have to do certificate work that shatters YouTube’s connection to the account personalization systems.
- bawolff 8mo agoIn theory 8 hours of downtime should be fine for a CA. Obviously not ideal, but the pki system is not meant to be a live system.
- SchemaLoad 8mo agoFairly sure it used to be pretty much a manual process where someone had to actually process your request for a certificate on the other side.
- Ayesh 8mo agoYes, and it's not that long ago, or I aged really quickly. For code signing certificates and EV certificates, (and OV certificates, if they are even alive), this is still the case.
- 8mo ago
- sciencesama 8mo agoNot sure but it is very strange i was served a strange tom And jerry video https://youtu.be/rilFfbm7j8k https://youtu.be/rilFfbm7j8k
- nitinreddy88 8mo agoYou can watch any YT video by directly following a link or from history/playlist etc. Its just their homepage etc is down
- PLenz 8mo agoEight hour estimated restoration time!
- deleted 8mo ago[deleted]
- TMEHpodcast 8mo agoIt is a well-known fact that the moment YouTube goes down, the collective productivity of Earth increases by approximately 4,000%, which is immediately squandered by everyone going to Hacker News to read comments about YouTube being down. I myself have taken to podcasts… an ancient medium in which people simply talk at you for ninety minutes without a single sponsorship for a mobile game, and this is considered a failure
- staticassertion 8mo agoI listen to multi-hour unsponsored content on Youtube almost exclusively.
- 14 8mo agoWell one must also argue the opposite. I myself have gained immense knowledge from YouTube. I have learned things like phone screen replacements or phone battery replacements. I call myself a mechanic from the school of YouTube and have saved myself at minimum $10k in repairs doing the work myself. I have learned to make endless food recipes or create things like giant bubbles or slime for my kids. My point is that I bet sure for some YouTube is a massive time sink waste of time. But I also wonder how much it has improved the knowledge, skills and ability of others. My dad often mentions how had he had YouTube when he was younger how much it would have done for him. He talks about having to go to the library and if lucky there was a book that could show you the knowledge you were looking for. He says but now you can find not just the knowledge but for example specific knowledge like car make model and year and how exactly to do job xyz. Ultimately I just can not imagine life without the wealth of knowledge YouTube has given me.
- TMEHpodcast 8mo agoCongratulations! You’ve successfully avoided YouTube Shorts.
- 14 8mo agoLol I laughed out loud reading this comment. When shorts first came out they annoyed me to no end. I searched for how to block them through settings or other ways to just make them go away. But now days I can admit there are a few, very few, content creators who create shorts that are very informative and straight to the point that can cover a topic and give you many facts and let you decide if you want to seek more. Sometimes it is nice to have the 30 seconds Coles notes verses a video stretched out to 10 minutes to be eligible for monetization. BUT, and this is a big but, the shorts and similar video platform trends scare me as a parent. I can see how my kids find a 1.5 hour movie boring but can scroll endlessly through shorts. It might seem harmless letting your kid just scroll on YouTube from my perspective is like an addiction and kids are getting that dopamine hit watching a clip and seconds later watching something else. I've learned that it is very important to be aware of what your kids are being accustomed to and push them in the right direction.
- edwaldojunior 8mo agoTime to go over my Watch Later list
- pkulak 8mo agoHere's a direct link to the latest Veritasium. You're welcome! https://www.youtube.com/watch?v=cMx139eTxoc https://www.youtube.com/watch?v=cMx139eTxoc
- manupati 8mo agoStill down
- bathtub365 8mo agoThe status history on the page makes it seem like this was intentional? > 17 Feb 2026 11:32 PST A rollout is going to prevent issuance from occurring. We will provide an estimate on when issuance will stop. > 17 Feb 2026 12:14 PST Issuance is beginning to stop. A fix to resolve the issue will roll out in about 8 hours
- zerocrates 8mo agoThe heading above that: "There is an ongoing incident that will force issuance to be halted." Feels like they were alerted to some current problem severe enough that "turn it off now" was the right move. Breaking the baseline requirements somehow maybe?
- agwa 8mo agoThis usually indicates that the CA was issuing non-compliant certificates and needed to prevent further non-compliance. Will be interesting to watch Bugzilla for the incident report: https://bugzilla.mozilla.org/buglist.cgi?product=CA%20Program&component=CA%20Certificate%20Compliance&resolution=--- https://bugzilla.mozilla.org/buglist.cgi?product=CA%20Progra...
- nickysielicki 8mo agoWhat qualifies as a non-compliant certificate?
- agwa 8mo agoIt doesn't comply with one or more root store policies (which all incorporate the Baseline Requirements by reference, which incorporate various specs, such as RFC5280, by reference). Mozilla root store policy: https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/ https://www.mozilla.org/en-US/about/governance/policies/secu... Chrome root store policy: https://googlechrome.github.io/chromerootprogram/ https://googlechrome.github.io/chromerootprogram/ Apple root store policy: https://www.apple.com/certificateauthority/ca_program.html https://www.apple.com/certificateauthority/ca_program.html Baseline Requirements: https://github.com/cabforum/servercert/blob/main/docs/BR.md https://github.com/cabforum/servercert/blob/main/docs/BR.md There are countless examples of non-compliant certificates documented in the Bugzilla component I linked above. A recent example: a certificate which was backdated by more than 48 hours, in violation of section 7.1.2.7 of the Baseline Requirements: https://bugzilla.mozilla.org/show_bug.cgi?id=2016672 https://bugzilla.mozilla.org/show_bug.cgi?id=2016672
- OhMeadhbh 8mo agoI worked at RSADSI when I was a kid and supported the custom spin of TIPEM Hayden and Sophia used at Verisign. This brings back some very bad memories. But... hopefully... people created overlapping windows of cert validity so there's always a valid cert available for their services and can tolerate the CA being out of action for 8(?) hours. Imagine if your TGS/Kerberos or AWS IAM IdP was down for 8 hours.
- antonvs 8mo agoFor persistent services using the affected ACME API, the window is usually 30 days. But that didn’t stop Youtube and Youtube TV from going down hard. I imagine they’re provisioning ephemeral VMs or service instances and relying on them being able to get certs immediately, or something like that.
- chiengineer 8mo agoWhile were all here does anyone want to launch a startup for a cloud security tool I built
- spyrja 8mo agoWelp, looks like they're back up. Home page and notifications are loading just fine now.
- RobRivera 8mo agoIs that what was happening with my youtube mid workout?
- arduanika 8mo agoCorrect. It's not youtube, it's themtube.
- kyledrake 8mo agoPeople went ballistic on me a few months ago for bringing this up, but this is exactly the kind of outage that makes me really, really worried about extremely short lived certificates. https://news.ycombinator.com/item?id=46118371 https://news.ycombinator.com/item?id=46118371
- codys 8mo agoI'm not sure I follow. This outage seems like it occurred for less than 1 day. The post you link to is about having certificates expire after 45 days. What's the connection you see?
- TwoNineFive 8mo agoYou didn't read it or understand it.
- jeroenhd 8mo agoSome CAs are experimenting with shorter, 7 day certificates as well. still not an outage that would endanger anyone's ability to renew in time, but for small or extremely shitty CAs (and there are a lot of those) such an outage may take enough time to cause issues in theory I guess?
- shabloney 8mo agoIt doesn't have to be small or more shitty than average. If Google has a compliance issue and can meet it in 8 hours then its a pretty clear one. They could have an issue that needs round trips of discussions with auditors before resuming. etc. I'm not familiar with 24/7 auditor services.
- philprx 8mo agothat's roughly 1/45th probable downtime window = 2.22% downtime probability (yeah, it's a figure not a real proba ;-) ) compared to say, roughly 1/365 probable downtime window for a 398 days cert lifetime = 0.25% downtime probability let's pray you don't need to rotate when it's down... Dan Geer famously said: "Dependency is the root cause of risk"... PS: even stricter shortlived durations in some context: Internal/Private 1 – 7 days Corporate VPNs, Internal apps Ephemeral 5 mins – 1 hour Docker containers, CI/CD runners
- rconti 8mo ago> The fix has been rolled out and the issuance flow has been undrained. We again apologize for the inconvenience. issuance flow has been undrained?
- aaomidi 8mo agoDraining is terminology they use for draining traffic from a service.
- andwur 8mo ago"Undrain" is not idiomatic, at least outside of Google. One might drain a tank or creek to empty it, the reverse isn't "undraining" to fill it back up. "issuance flow has been restored" might be a more widely understood phrasing. Admittedly, a nitpick, however the tech industry has a tendency to invent new words when they could say the exact same thing in plain English and be better understood by a wider audience.
- dilyevsky 8mo agogoogle sre speak
- ktaraszk 8mo agoThe CA outage is hitting a lot of services, but yeah, Heroku's been on a slow decline since the Salesforce acquisition. Free tier killed, pricing creep, stagnant innovation. Even when it's not their fault, you start wondering if it's worth the risk of being on a platform that feels like it's in maintenance mode.
- ktaraszk 8mo agoYeah, if Heroku's cert rotation depends on Google's CA and it tried to renew during the outage window, that'd definitely cause problems. The 8-hour ETA is rough. This is why multi-CA fallback configs exist, but most platforms don't bother until they get burned by something like this. Worth checking if your apps are actually affected or if it's just the dashboard/API having issues.
- philprx 8mo agoTrust is down ;-)
- deleted 8mo ago[deleted]