|
|
|
|
|
by notabee
993 days ago
|
|
A lot of certificate management services for enterprise customers "helpfully" store the private key files. How many cloud or SaaS vendors automatically handle the private keys as well instead of them being generated and staying securely only on the systems using them? So there are still points of centralization to attack, potentially. |
|
But it requires a lot more steps.