| It never fails to amaze me how most incident mitigations seem completely oblivious to such security side effects. "We have no reason to believe that the exposed key was abused, but out of an abundance of caution, we are going to expose 50 million users to a potential MITM attack unless they are extremely careful." Not a single word in the post about whether this impact was even considered when making the decision to update the key. Just swap the key, and fuck the consequences. Same with the mass password resets after a compromise that some services have done in the past years. Each of those is any phishing operation's dream come true. |
So MITM for some of 50m users is strictly better than MITM for all of 50m users.