|
|
|
|
|
by josteink
2599 days ago
|
|
If that is true, they should mention this in the post-mortem. Code signing is a well understood problem with a well known solution, but the blog post discusses everything except the well known solution. Right now you have a problem caused directly by lack of time stamping, and the article doesn’t even acknowledge that. That’s not inspiring confidence. I’m genuinely still not sure if they have understood what the actual problem is and how to solve it properly. |
|
They might:
> We’ll be running a formal post-mortem next week and will publish the list of changes we intend to make
The lessons noted down here are just some thoughts by the author of this blog post:
> but in the meantime here are my initial thoughts about what we need to do.