Hacker News new | ask | show | jobs
by insanitybit 997 days ago
Revoke everything? Everything?

I have literally done incident response I am well aware of what the investigation process is like.

1 comments

Everything a potentially compromised key has signed, yes. What are we discussing here? This is standard procedure by every compliance processes I have ever had the misfortune to work with, but for quite good reasons. Hope alone won't pass an audit.
OK but "everything" and "everything the key may have signed" are obviously so insanely different.