Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is a brand new thing with no userbase. Seems an extremely responsible time to disclose this.

As I understand it, responsible disclosure is primarily there to protect the userbase of a piece of software, not the reputation of the producer of that software.

And surely they can't be being stupid enough to be using this same signing key on established products, can they?

On reflection, scrub that last thought.



The question isn't so much what other things Yahoo! might be using this signing key for, it's what other things bad guys might be able to sign with it.


Those two are sort of the same question however.

If this is the only thing signed with this key, then the attack surface is only people running this thing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: