8 ms·
Does this have anything to do with the SHA1 sunset on 31 December?
by agrot3ra 11y ago
Does this have anything to do with the SHA1 sunset on 31 December?
- bigiain 11y agoThat'll be why the key expires on Dec 31 even though it was only issued back in April. It doesn't explain why Instagram has been happily using a known-compromised wildcard ssl key for two weeks now. Makes you wonder who actually values and protects Instagram's user privacy more - the researcher or the Facebook CSO...
- Phlarp 11y ago>Makes you wonder who actually values and protects Instagram's user privacy more - the researcher or the Facebook CSO... No, I don't wonder about this at all.
- secalex 11y agoDifferent key, dude. We rotated what was exposed.
- kuschku 11y agoDo you believe that after this chain of events anyone still believes your company? Additionally, I hope that the EU data privacy official is going to take a look at this, as it shows that Facebook improperly secured their systems, and not even properly handled the disclosure of exploits. EDIT: Clarification, replaced plural you with direct names and better pronouns.
- dang 11y ago> Do you believe that after this chain of events anyone still believes you? Personal attacks, which this crosses into, are not allowed on Hacker News. Please comment civilly or not at all.
- kuschku 11y agoI am not talking about the person, but the company. And I am sorry, but after these acts the company has taken, the little bit of trust that was left in the company is gone. I am sorry if it sounded like a personal attack, that was not intended.
- blazespin 11y agoOH COME ON Dang, Alex called up Wes's employer and threatened him with criminal charges and then had the balls to lie about it in his facebook post that he didn't "Threaten". Are you seriously defending this??
- dang 11y agoAsking HN users to be civil defends nothing except civility. There's a relevant general point here though. Reactions like this, and many others in this thread, are reflexive. That's really not what this site is for. Good comments for HN aren't reflexive, they're reflective. Practicing that distinction is the most important thing for being a contributor here, and it's orthogonal to one's actual views.
- zorpner 11y agoAsking HN users to be civil defends nothing except civility. This would only be true if that request were applied equally whenever HN users were uncivil. As it stands, it does generally come off as defending specific users. ...it's orthogonal to one's actual views. Believing this is going to made you a worse moderator -- this is "fair and balanced"-style thinking. There are many perspectives whose projection onto comment reflectivity are anything but zero.
- dang 11y ago> if that request were applied equally whenever HN users were uncivil That's asking us to operate like machines—supermachines, in fact, with incivility detection and moderation powers. That's unrealistic. HN users' capacity to be uncivil exceeds our capacity to ask them not to, so the latter maxes out. > it does generally come off as defending specific users We try hard not to play favorites. I'm biased, of course, but there's more than one kind of bias here. People are more likely to notice us criticizing a comment they identify with than the cases that go the other way. We're biased to notice what we dislike and assign more weight to it. > Believing this is going to made you a worse moderator In that case I'm a bad moderator already, because everything I've learned about HN is packed into what I said there.
- bigiain 11y agoSo this new rotated key I'm seeing that has an April 2015 start date is a different key to the one your team replaced after it expired and broke everything back in April? What a coincidence...
- deleted 11y ago[deleted]
- droopybuns 11y agooutstanding question.