Internet plumbing keeps failing in surprising ways
Attackers obtained counterfeit TLS certificates for Google and other large services by compromising the registries of country-code TLDs, including American Samoa, Greenland and Sierra Leone. Google's response said its own systems weren't breached. The weak link was a third-party registry, and commenters pointed to HPKP-style pinning as the old answer. In a separate thread, Spanish football blocking via Cloudflare broke docker pull for developers in Spain, because the block hits whole Cloudflare R2 ranges. AWS showed estimated billing data of $1.7 billion, with users reporting bills from hundreds of millions to hundreds of billions of dollars on hobby accounts.
JPEG XL shipping in Chrome is the quiet good news, though people immediately asked about patents and about memory safety.
The through-line is that your dependencies sit on other people's dependencies. Your product can be hit by a registry in Greenland, a court order in Spain, or a billing bug at AWS, and none of it is your fault. Commenters keep saying the same thing: a small set of providers concentrates the risk.
So what?
Audit the invisible parts of your stack: which TLDs you rely on, which registry or CDN your image pulls go through, and whether you have billing alerts that don't depend on one dashboard. Mirror critical container images and have a fallback path for builds.
Read these
Hackers obtain counterfeit TLS certificates for Google and other large services
Tell HN: Docker pull fails in Spain due to football Cloudflare block
AWS: Inaccurate Estimated Billing Data – $1.7 billion
Shipping JPEG XL in Chrome