Tonight a professor in rural Thailand couldn't show his students a webpage because four lines in an Apache config file were commented out. Those four lines have been commented out, by default, in Apache's shipped configuration, for years. Nobody at the vendor ever flipped them on. Nobody got fired. Nobody even noticed — until a half-salary iPad Pro hit a wall in a Naresuan University classroom at 7:40 PM local time.
This is a document about that wall. About who builds it, who profits from it, who maintains it, and who pays for it. It is also a document about the opposite of that wall: the Panasonic principle, the GE principle, Howard's principle. Buy right. Maintain it. Trust it. Thirty years later it still runs.
We are going to name names.
In 1993, Al Gore popularized the phrase "information superhighway." It was a beautiful lie. A superhighway is public infrastructure — built with public funds, maintained by public obligation, free at the point of use. You do not pay a toll to enter. You do not negotiate with a private company for the right to drive on it. It exists because a democratic society decided that the movement of people and goods was a public good, not a revenue opportunity.
What we built instead is a private toll road with no alternative route, no posted rates, no regulatory floor, and no exit.
Everything we are about to describe — the broken defaults, the certificate rackets, the middlebox surveillance apparatus, the abandoned platforms — all of it happens after you have already paid the toll. The wall we spend this document dismantling is the second wall. The first wall is the one nobody names.
Big Telecom.
AT&T. Comcast. Verizon. Charter. In most of the United States, and in most of the world's underserved regions, there is one provider. One. Not two competing for your business, not a regulated utility with a price ceiling — one company, one price, take it or leave it. And "leave it" means no internet. In rural America, in provincial Thailand, in the DRC, in every place where the margin wasn't fat enough to attract a second provider: one company owns the on-ramp. They set the toll. They set the speed. They set the data cap. They set the throttle.
The numbers are not subtle. In the United States, the country that invented the internet:
The FCC has spent thirty years oscillating between treating these companies as common carriers — regulated utilities with public obligations — and treating them as free market actors who should be permitted to extract whatever the captive market will bear. The oscillation tracks elections almost perfectly. Democrats restore net neutrality. Republicans kill it. Democrats restore it. The companies spend the intervening years lobbying, litigating, and acquiring competitors to ensure that regardless of who wins, the infrastructure stays private, the tolls stay high, and the alternative stays nonexistent.
Net neutrality — the principle that all traffic on the network must be treated equally, that the company who owns the pipe cannot throttle YouTube to protect their own video service, cannot charge Netflix for "fast lane" access, cannot slow your VPN to make their surveillance easier — is the regulatory ghost that haunts all of this. It was the one legal mechanism that enforced the freeway metaphor. It has been killed, revived, killed again, and at the time of this writing exists in a state of litigation-induced uncertainty that benefits no one except the lawyers and the carriers.
Nobody talks about Big Telecom in the same breath as Zscaler or Blue Coat. They should. The middlebox inside the NU network breaks the TLS handshake. But AT&T's monopoly on the last mile determines whether the packet reaches the middlebox at all. The certificate racket taxes the server operator. But Comcast's data cap taxes the user before the first byte of the certificate exchange has been transmitted. Every layer of exploitation we describe in this document is downstream of the original exploitation: the privatization of the public commons of communication, the conversion of the information superhighway into a coin-operated turnstile.
Two bits. That is what it costs to make a local call from a payphone, in the last era before the phone company owned the silence between calls. We got rid of the payphone. We built the internet. And then we let the same companies that owned the payphone own the internet, and we called it progress.
The soul scrounging in their pocket for two bits to put in the smartphone before the highway of communication lets them on — that is not a metaphor. That is the prepaid data plan. That is the throttled hotspot. That is the library parking lot at 11pm because the library's WiFi reaches the sidewalk and home doesn't have broadband. That is the professor in Phitsanulok on a university network that can only afford one ISP contract and one "enterprise security" appliance, because that is what the budget allows, because the telecom set the price, because there is no other choice.
When providers throttle, they slow speeds — but the mobile closed-loop power dynamic is unchanged: slower speed to transfer the same bloated website means longer transmission time, faster battery drain, and longer RF emission from the device against the body of the person who can least afford a better connection. ...there is an important nuance to this →
Everything that follows in this document is the second wall. We name it because the second wall is where our tools reach. But do not mistake the second wall for the first one. The first one is bigger, older, more profitable, and almost entirely undiscussed.
The wall is not one thing. It is a stack of things, each layer added by a different set of hands collecting a different toll, each layer individually defensible, collectively catastrophic for anyone who can't pay their way through every checkpoint.
Apache HTTP Server — free, open, volunteer-maintained, the backbone of more of the internet than most people realize — ships with OCSP stapling disabled. Commented out. The directives are there. They're just preceded by a #. Apache is not the enemy here. Apache is ours — open source, no paywall, no sales team, no SSL inspection appliance. What Apache has is the same thing any large volunteer project has: gaps between the people who write the code and the people who face the consequences of a default. Nobody in the Apache project sat in a Thai classroom tonight and watched a course objective fail to load. If they had, those four lines would have been uncommented a decade ago.
OCSP — Online Certificate Status Protocol — is the mechanism by which a browser verifies that an SSL certificate hasn't been revoked. Stapling means the server pre-fetches that verification and attaches it to the TLS handshake, so the browser doesn't have to make a separate round-trip to a certificate authority to ask "is this cert still valid?" Without stapling, modern browsers — especially Safari on iOS and macOS — either make that round-trip themselves (slow, privacy-leaking) or, when they can't complete it, refuse to open the page entirely.
Safari doesn't warn. Safari doesn't offer a bypass. Safari says no.
Four lines. Uncomment them. Restart Apache. Fixed. The entire remediation tonight took eleven minutes including triage. The configuration has been shipped broken, by default, for years. Nobody was held accountable for this. It is the kind of negligence that, in any other engineering domain, would produce a recall.
This is Layer Zero: the infrastructure you depend on, built by people who will never meet your users, shipped in a state that silently fails them, and maintained by nobody until someone like you sits down at 2am and fixes it yourself.
For most of the commercial web's history, obtaining an SSL certificate — the technical prerequisite for serving your site over HTTPS, the prerequisite for not being flagged as "Not Secure" in every browser on earth — required paying a Certificate Authority. Prices ranged from the merely annoying to the genuinely prohibitive. Domain Validation certs ran $50–200/year. Extended Validation certs, which gave you a green bar and organization name in old browsers, ran $300–1000/year. Wildcard certs — covering all subdomains — ran $200–800/year.
Let's Encrypt, launched in 2016 by the Internet Security Research Group, broke this racket. Free. Automated. Open. The CA/Browser Forum was not pleased. Commercial CAs spent years lobbying for restrictions on free certificate issuance, for shorter validity periods that would increase renewal friction, for requirements that would disadvantage automated issuance. Some of those lobbying efforts succeeded. The 90-day certificate validity period that Let's Encrypt uses — short enough to limit damage from compromise, long enough to be manageable with automation — has now been used by commercial CAs to argue for even shorter validity periods that would hurt non-commercial operators most.
The racket never ends. It just moves the toll booth.
This is where it gets genuinely obscene.
A professor at Naresuan University — a public university, a state institution, in a country where academic salaries are a fraction of what they are in the West — sits behind a network administered by an IT department that has purchased "enterprise security" from one or more of the following:
Every one of these products is sold as "security." Every one of them fundamentally breaks the security model of the internet by inserting an unauthorized third party into an encrypted connection that was established between two specific endpoints. This is not a side effect. This is the product. You are paying for the ability to spy on your own users, employees, or students, and calling it protection.
A concession, because precision matters here: not every instance of SSL inspection is pure rent-seeking. Some is driven by real compliance regimes — child protection filtering in schools, regulated industries, genuine national security mandates. The demand is not entirely manufactured. But that does not redeem the implementation. The accurate charge is this: current deployments are almost universally overbroad, opaque to the user, poorly engineered relative to the harm they cause, and sold as a universal solution to institutional anxiety rather than a narrowly scoped tool with strict accountability. The compliance fig leaf does not cover what these products actually do in practice, in a Thai university classroom, at 7:40 PM, to a page that did nothing wrong.
When these systems are deployed, and when they're misconfigured, or when they don't support ECC certificates, or when they don't pass OCSP stapling through correctly, or when their own intermediate CA isn't in every device's trust store: legitimate sites become unreachable. Not because those sites did anything wrong. Because a $20 billion vendor's appliance is in the way, imperfectly impersonating both sides of a conversation neither party asked them to join.
An iPad Air 2 running iOS 15.8.3 — the last iOS version Apple will ever ship for that hardware — exhibits a Safari bug where a failed DNS lookup is cached in a stale state that causes subsequent navigations to the same host to report "server not found" even after the underlying issue is resolved. The fix is to close all tabs, clear history, force-quit Safari, and reopen. Or to mangle the URL in a way that forces a fresh DNS resolution.
Apple knows about this. Apple will not fix it. iOS 15 is end-of-line. The hardware is not capable of iOS 16. Therefore: your problem.
The iPad Air 2 was released in 2014. It is twelve years old. In 2014 it cost $499. In 2014, $499 was a real investment for most people on earth. In 2014, Apple promised — implicitly, through the act of selling the device — that it would work. Twelve years later, Apple's definition of "work" has narrowed to "doesn't spontaneously combust." Safari state initialization bugs in abandoned iOS branches: not Apple's problem anymore.
The sharpest critique is not that Apple abandoned the hardware after twelve years. It is that Apple continues to extract value from the ecosystem those abandoned devices still try to participate in. The App Store's gravity, the iCloud lock-in, the brand loyalty that keeps a user reaching for an Apple device next time — all of that accrues to Apple. The device still tries to be a citizen of a web Apple helped build and continues to shape through Safari's browser engine monopoly on iOS. Apple benefits from that participation. The device gets nothing back. That is not obsolescence. That is extraction with a Cupertino smile.
Let us be specific about who absorbs the cost of all this negligence, all this surveillance infrastructure, all this planned abandonment.
A professor at Naresuan University — a provincial public university in northern Thailand — attempts to show his students a webpage he co-created with a colleague in California. The page is served from a FreeBSD machine running Apache, with a valid Let's Encrypt certificate, on a dedicated IP, with correct DNS. The professor is using an iPad Pro — current generation, which in a Thai academic salary context represents a months-long investment in his professional tools. The NU network is a Microsoft shop. SharePoint. Teams. Azure AD. And almost certainly a perimeter inspection appliance. The page doesn't open. The class moves on without it.
The certificate was valid. The server was correct. The content was free. The wall was built by vendors who will never know this classroom existed, collecting tolls from an institution that cannot afford them, for "security" that made nothing more secure.
Members of international academic committees — people doing serious technical work, peer review, curriculum development — operate on African university networks that are a generation behind in infrastructure, running inspection appliances that were enterprise standard in 2015 and have never been updated, behind DNS resolvers that don't reliably support modern certificate transparency, on devices that represent a higher fraction of their annual salary than any device owned by any of their counterparts in Cambridge or Berkeley. Every additional layer of TLS complexity — every CA/Browser Forum policy change, every browser security update, every certificate lifecycle change — lands on them harder than it lands on anyone else.
Not in the third world. In the United States. Rural California, rural everywhere. 3Mbps ADSL is not a developing-world problem. It is a rural America problem, a last-mile problem, a "AT&T decided your neighborhood wasn't worth upgrading" problem. Every bloated JavaScript framework, every uncompressed image, every unnecessary certificate handshake round-trip: metered against 3Mbps. The information superhighway is a toll road, and the off-ramps to anywhere not dense and wealthy are missing entirely.
Against all of this, we propose the opposite.
Buy right. Maintain it. Trust it. Thirty years later it still runs. — Howard
The server is a FreeBSD machine — technically end-of-life on the pkg repository, which means installation requires workarounds, which means it will outlast every cloud instance anyone spun up this week. It runs Apache 2.4. It serves flat HTML files. Its CGI layer is pure C. It has no Node.js. It has no npm. It has no dependency tree that will collapse when a package maintainer rage-quits and takes half the internet down with them. It has no Kubernetes. It has no container orchestration. It has no YAML files that require a YAML file to explain them.
Tonight, at 2:42 AM Pacific Standard Time, one human sat down and fixed it. Triage: eleven minutes. Root cause: four commented-out lines in a config file. Fix: uncomment, configtest, graceful restart. Total downtime: none, because Apache's graceful restart doesn't drop live connections.
This is not nostalgia. This is engineering.
Al Shugart said: if the lab burns down and you can't rebuild from documentation, you failed. The principle behind that principle is that real engineering is reproducible, comprehensible, maintainable by a human being who reads and thinks. Not by a team of DevOps engineers with a monitoring dashboard and a PagerDuty rotation. By one person, at a terminal, with a brain.
This stack is that. One person can hold it in their head. When something breaks, there are a finite number of places it can break. When something needs fixing, the fix stays fixed. When a new domain needs a cert, acme.sh gets it in three minutes. When OCSP stapling needs to be enabled, it's four lines and a restart. The server doesn't need to be replaced. It doesn't need to be migrated. It doesn't need a sprint planning meeting.
It needs to be maintained. Maintenance is not glamorous. Maintenance is a moral act.
The dominant tech culture — startup culture, scale culture, cloud-native culture — treats maintenance as failure. If you're maintaining something, you're not building something new. If you're on a legacy system, you're not on the bleeding edge. If you're running FreeBSD on bare metal instead of Kubernetes on EKS, you're behind.
This is a lie with a very specific beneficiary: the vendor who needs you to replace your infrastructure twice a year. The AWS account team who needs you to believe that the only safe server is a rented server. The Zscaler sales rep who needs you to believe that the only safe network is a surveilled network. The Apple upgrade cycle that needs you to believe that a twelve-year-old device should be replaced, not maintained.
Maintenance means:
You know where every configuration file lives. You know what every directive means. You know what the error log will say when something specific breaks. You know how to read it and what to do about it. You built it, you understand it, and when something goes wrong at 2am, you sit down and fix it in eleven minutes because you already know where to look.
This is not compatible with cloud-managed infrastructure where the "configuration" is twelve layers of abstraction over a web console over an API over a YAML file over a Terraform module over an AMI that AWS maintains and that you cannot inspect. When that breaks at 2am, you file a support ticket and wait. Support tier determines wait time. Support tier costs money. Money determines access. Access determines who can maintain their own infrastructure and who cannot.
The maintainability of a system is an equity question. Not a DevOps question. An equity question.
The entities named in this document — Zscaler, Forcepoint, Palo Alto, Cisco, Blue Coat/Broadcom, and Microsoft in its enterprise security posture — are not neutral infrastructure companies. They are active participants in a system that makes the open web less open, less accessible, and less trustworthy for anyone who cannot afford to route around them. They do this in the name of security while systematically undermining the security properties of every TLS session their appliances intercept.
The certificate authorities who lobbied against free certificate issuance, who argue for shorter validity periods to increase churn, who price wildcard and EV certificates at rates that exclude small operators: they are toll-booth operators on a road that was supposed to be public infrastructure.
Apple, which shapes the web through Safari's browser engine monopoly on iOS while abandoning the devices that depend on it — continuing to extract brand loyalty, ecosystem stickiness, and upgrade cycle revenue from users whose hardware is still trying to participate in a web Apple controls but no longer maintains for them — is practicing extraction with the vocabulary of security updates.
Apache bears a smaller, different share: not malice, not profit motive, just the gap that opens in any large open project between the people who write defaults and the people who live with them. Open kimono is not the same as open with care. Shipping something free doesn't discharge the obligation to ship it working. We say this as people who run Apache, who depend on Apache, who are grateful for Apache — and who spent eleven minutes tonight fixing what Apache should have fixed before it shipped.
Against all of them: the FreeBSD box. The flat HTML file. The pure C CGI. The Let's Encrypt cert. The acme.sh cron job. The maintained, comprehensible, fixable, trustworthy thing. Built right, kept right, serving everyone who can reach it on whatever hardware they have, on whatever network will pass their packets uncorrupted, at whatever hour they need it.
This is not a technology preference. This is a politics.
Written at 02:42 PST, August 21, 2026, during an active debugging session following successful OCSP stapling remediation for democracychat.org and all associated domains.
The fix: uncomment four lines in the Apache SSL config. Restart. Done. Eleven minutes.
The wall had been standing for years.
Impossible Distance Collective