π Hello, super humans! It is Monday, and while the AI world argues about agents, the plumbing underneath the web is quietly getting a quantum-era rebuild. Today we look at Cloudflare’s plan for a public CA built on Merkle Tree Certificates, then run through OpenAI’s DevDay haul, a bug bounty buckling under AI noise, and a supercapacitor board for your Raspberry Pi.
π° Quick Signals
- π§ AI: OpenAI DevDay brought GPT-6.1 Sol, which approaches GPT-6 Astra on several evaluations at one-fifth the token price, plus computer use in the Agents API and cloud-based Codex environments.
- π€ Robotics: Omron’s next-generation LD mobile robots lean on the idea that software, safety, and fleet management now matter as much as the robot itself.
- π» Programming: Linux 7.3-rc6 landed, and Linus Torvalds called the cycle normal “for the new AI normal,” with lots of small error-path fixes.
- β‘ Electronics: Nvidia introduced a 64GB DGX Spark at $4,999 while the 128GB model rose to $6,950, a 75% jump over launch, as the memory crunch bites.
- π‘ Telecom: BT bought TalkTalk out of administration to keep 2.5 million customers connected, with an estimated Β£400M cash impact; the CMA must report by October 19.
The Big Story: Cloudflare wants to fix post-quantum TLS by shrinking the certificate, not the math
If you run anything behind HTTPS, the post-quantum migration will eventually touch your handshakes. Cloudflare’s new plan is interesting because it avoids the obvious trap: simply swapping in bigger signatures.
What happened: Cloudflare announced plans to operate a free public certificate authority that issues quantum-safe TLS certificates, with broad public issuance expected in early 2027 as root store inclusions land. Production experiments have already run with Google’s Chrome engineering team. Details are in Cloudflare’s announcement, and InfoQ’s write-up covers the design.
The details: NIST-standardized post-quantum signature schemes such as ML-DSA and Falcon produce certificates roughly forty times larger than classical ones. Dropping them straight into X.509 chains risks TCP segmentation trouble, packet loss on constrained networks, extra handshake round trips, and heavier load on Certificate Transparency logs. Merkle Tree Certificates, advancing in the IETF PLANTS working group, change the shape of the problem: the CA batches issuance into an append-only Merkle tree and signs only the root with a post-quantum signature. Each certificate then carries a compact hash-based inclusion proof, logarithmic in the tree size. Servers keep serving a classic X.509 certificate too, so legacy clients fall back cleanly while modern browsers get the small proof.
flowchart LR
A[Certificate requests] --> B[CA batches into Merkle tree]
B --> C[CA signs only the root with a post-quantum signature]
C --> D[Server holds a short inclusion proof]
D --> E{Client supports MTC?}
E -->|Yes| F[Compact proof in the TLS handshake]
E -->|No| G[Classic X.509 fallback]
Important
Our take: The smart part is that this treats certificate size as the real engineering constraint instead of a footnote. Most of us will never write a CA, but we will inherit the handshake, so this is the design to watch before you start benchmarking raw ML-DSA chains. I would also keep an eye on the Chrome root store timeline: until browsers ship support, the early-2027 date is a plan rather than a deployment.
ποΈ More News
π§ AI
- Google paused its Open Source Software Vulnerability Rewards Program from October 1 until Q1 2027, saying the vast majority of a surge in automated submissions are not valid.
- The administration unveiled a new “Super Intelligence Force” initiative focused on advanced AI capabilities.
- TechCrunch asks whether “super intelligence” branding and a non-binding safety pact can fix AI’s public image problem.
- AMD is betting $8.2B on World Labs, Fei-Fei Li’s spatial intelligence startup, on the thesis that worlds matter more than words.
- Huawei’s chairman claims homegrown AI chip sales top Nvidia’s in China, even though the chips are less advanced.
- AWS developers released Pizza Bot, an Apache 2.0 inbox for background AI agents with webhook triggers and human approval gates.
π€ Robotics
- An opinion piece argues the physical AI race will be won in the patent office, urging robotics startups to protect their IP early.
- A look at how robotics and physical AI can responsibly take on physical security challenges.
- Eli Lilly and Purdue will share field learnings on worker perceptions of manufacturing robots at RoboBusiness.
π» Programming
- Uber Eats cut end-to-end search latency by 50% by doing less work and waiting less, and by measuring “above-the-fold” completion instead of backend response time.
- Google’s AndroidX Security State libraries let apps verify patch status per component, with calls like
areCvesPatched()andisDeviceFullyUpdated(). - New MGLRU-FG patches claim 10 to 40% higher performance in some Linux memory tests.
- NVIDIA presented Wayland versus X.Org latency testing results at XDC 2026.
β‘ Electronics
- Micron says RAM supply will worsen, with its CEO celebrating “much higher” prices as revenue and profit climb.
- The Avaota F2 is a tiny Allwinner V861 RISC-V board with a 1 TOPS NPU, dual MIPI CSI, and PTZ motor pins for AI cameras, listed at $51.59.
- The UUNA TEK iAuto is a wireless handwriting and drawing machine that reproduces penmanship with custom fonts.
- Linux is getting workarounds for bugs in Fujitsu’s newly announced 144-core MONAKA Arm server CPU.
π‘ Telecom
- Stanford’s John Ousterhout is pushing Homa, a message-based TCP alternative for datacenters, claiming 92 microsecond p99 latency for short messages versus 1.2 ms for TCP; a prominent network architect disputes the case.
- Google launched its first Suncatcher datacenter satellite; its research says orbital compute becomes feasible near $200 per kilogram launch cost, with networking and formation flying still unsolved.
- Vero Fiber and MontanaSky completed their merger.
π¨βπ» Code Corner
Curious how big your own TLS certificates are today, before the post-quantum shift changes the numbers? This standard-library script fetches a server’s leaf certificate and prints its DER size in bytes.
import ssl
def leaf_cert_size(host: str, port: int = 443) -> int:
pem = ssl.get_server_certificate((host, port))
return len(ssl.PEM_cert_to_DER_cert(pem))
for host in ("cloudflare.com", "python.org", "learningbot.tech"):
print(f"{host}: {leaf_cert_size(host)} bytes")
Run it now and keep the numbers as a baseline; a classical leaf certificate is typically on the order of a kilobyte or two, which makes a roughly forty-fold increase easy to picture.
Tip
This measures only the leaf certificate, not the whole chain sent in the handshake. Add openssl s_client -showcerts -connect host:443 to see the full chain and the signature algorithms involved.
π§° Toolbox
- Homa Linux kernel module: the open-source implementation of the message-based transport discussed above; it installs as a kernel module alongside TCP, so you can experiment without a reboot.
- Pizza Bot: a self-hosted inbox for background agents, with local state and approval gates for important actions.
- Merkle Tree Certificates explainer: a compact walkthrough of the IETF PLANTS approach and why batching beats bigger signatures.
- OpenCourant: a community fork of OpenRadioss, started by Rocky Linux developers after Siemens shut the original project down.
π Component of the Week (rotating)
Geekworm UPS Scap 5V5A is a supercapacitor UPS HAT for the Raspberry Pi 5, offered with 100F, 60F, or 22F capacitors. Instead of a lithium cell, it uses supercaps rated for over 500,000 charge cycles and charges in about 15 minutes, which removes the battery safety worries from unattended projects. A built-in PD chip negotiates a true 5V/5A output, taking 9V to 24V DC or 12V USB-C PD input. Backup time is short, roughly 9 seconds at full draw and about 3.5 minutes at 0.5A in Long Endurance Mode on the 100F model, so think “graceful shutdown” rather than “keep running.” It lists at about $41 on AliExpress and $44.90 to $48.90 from Geekworm’s store.
π From the Blog
- Turning Pixels Into Something the AI Can Eat: the third episode in the video-analytics series, on what happens to a frame once the camera and the network are done with it and it is the model’s turn.
- Building Your First Neuron From Scratch: weights, bias, and activation worked through by hand instead of imported from a framework, good background if today’s agent-policy code scratched an itch.
- The Network Behind the Cameras: the unglamorous plumbing that moves pixels across a network fast enough that nothing chokes.
π The Bot Saysβ¦
Post-quantum cryptography: the only field where “make the signature 40 times bigger” is a serious proposal, and “make the certificate smaller” counts as a breakthrough.
That’s all for this week! Reply and tell us whether you have started inventorying where your TLS certificates live, and what is stopping you.

