Hacker News new | ask | show | jobs
by amelius 1346 days ago
And also it is another line of defense, which can only improve security, not worsen it.
1 comments

I agree, it's defense in depth.

However, suppose I'm a famous carmaker [1]. What are the chances that I screw up and publish my CMK in a public repo, compared to the chances of my CSP screwing up and publishing my tenant's PMK on a public repo?

[1] https://news.ycombinator.com/item?id=33155138