Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Revoke everything? Everything?

I have literally done incident response I am well aware of what the investigation process is like.



Everything a potentially compromised key has signed, yes. What are we discussing here? This is standard procedure by every compliance processes I have ever had the misfortune to work with, but for quite good reasons. Hope alone won't pass an audit.


OK but "everything" and "everything the key may have signed" are obviously so insanely different.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: