Hacker News new | ask | show | jobs
by dz0ny 1179 days ago
Looks like they tried to rotate the cert, maybe due to the private key leak. But instead, they rolled the wrong expired key to all content domains.
1 comments

I'm more thinking the new host key prevented SSL cert rotation from happening properly
Maybe, but only if they're refreshing certificates less than a day before expiry. Which isn't ideal.