Reply to post: It affected me

23,000 HTTPS certs will be axed in next 24 hours after private keys leak

Jonski
Flame

It affected me

And seriously, I rank it along with the likes of Trump tweeting the nuclear codes for gross negligence, malfeasance and delinquency. I'll throw in words like espionage, sabotage and malpractice too.

I'm in a time zone where we have about 4 hours from open of business to revocation of cert (although it's now been extended, a bit). Fsck these guys with a pitchfork, sideways.

Their turf war, my neck on the line. I got notified by an email that went to me (not my team) and landed in the Other folder for casual perusal when I got round to it. Luckily, I got around to it only an hour after I got in and caffeinated.

I'll now have to explain a risk mitigation strategy to our compliance team on Monday. I've done due diligence on dos and malware attacks and almost everything else under the sun, but deliberate betrayal by bad actors or rogue employees at the root is beyond my ken.

I'm in the process of replacing the EV certs with a bunch of 30-day ones from different vendors, and I'll not darken their doors again. At least my boss will shout the beer when it's over.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon