• Addv4@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 month ago

    Plenty of things, but the most obvious being the two separate instances they had issues with renewing their certs.

    • Victor@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      1 month ago

      Could you please explain why not renewing their certs is such a serious betrayal? Like, if they fixed it, isn’t that okay? And even if it happened again, and they fixed it again, isn’t it human to err? Or why is it such a harsh offense?

      Serious question, I don’t know the consequences of not renewing these certs. 😊

      • Addv4@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        It’s the tls certificate that proves your website is legit. Without which, you can potentially be a malicious actor that can pose as the website, and when you download the iso, you could unknowingly download something malicious. It’s pretty hard to forget certificate renewal (most of the time there are plenty of reminders sent and warnings given), so the fact that it happened twice was very impressively bad.

        • dubyakay@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 month ago

          It’s pretty hard to forget certificate renewal (most of the time there are plenty of reminders sent and warnings given)

          Oh boy. Seems to be the opposite in real life. Especially when it comes to managing stored cert of businesses partners. It has gotten somewhat better now of course, but three years ago most of my company’s sev1 production issues were due to lapsing or unscheduled cert changes.