Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, forgetting to update the canary = safe. If you had a system that signed stuff until you stopped it, it would fail unsafe, i.e. it would keep telling people they're safe when they weren't.


You realize, that forgetting to update the canaray gives the same message as "we were hit by a big fucking NSL, don't trust us and our software and systems ever again as their security has been compromised."?

From the outside, there is just no way of knowing that it was just a forgotten update or if it was a strong message.


Hey, I'm not any happier about this than you are. I'm just saying that at least it doesn't lull users into a false sense of security, which would have been disastrous.


What's your threshold to "disastrous" in terms of a missing warrant canary then? 3 weeks? 1 month? 2 months? longer?


Not missing the canary when you were served an NSL.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: