Symantec just fired people for mis-issuing a google.com 1-day pre-cert: http://www.symantec.com/connect/blogs/tough-day-leaders
http://googleonlinesecurity.blogspot.co.uk/2015/09/improved-digital-certificate-security.html Google: "Our primary consideration in these situations is always the security and privacy of our users; we currently do not have reason to believe they were at risk." Gerv _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

